FREEDOM ON
THE NET 2021
The Global Drive to Control Big Tech
repercussions that their laws could have on internet freedom
in more closed environments. Germany’s 2018 Network
Enforcement Act (NetzDG), for example, introduced
problematic requirements for companies to expediently
remove content without a court order and establish a local
legal presence. While the law has since been amended, the
original has been mimicked and misused by backsliding
democracies and authoritarian regimes in order to force
social media providers to remove LGBT+ content and
investigative journalism. Similarly, authorities in several
countries cited the EU’s 2018 General Data Protection
Regulation (GDPR) to stymie cross-border data flows and
support vague exemptions for state surveillance.
The DSA requires large intermediaries to produce detailed
reports on a broad range of their practices, including content
moderation, algorithmic curation and recommendation
systems, and online advertising. Due process protections
would also be bolstered under the law. Users would be
notified about moderation decisions affecting their content
and provided with an appeals process. However, the
proposal builds on the controversial “notice-and-action”
framework first introduced in the US Digital Millennium
Copyright Act (DMCA) of 1998, which created a standard
mechanism for copyright owners to request the removal of
infringing materials from platforms without a court order.
The DMCA suffers from challenges in issuing counternotices
and documented abuse by politicians seeking to remove
unfavorable content. Attention is needed to ensure that the
DSA addresses these shortcomings and does not become a
global model for censoring political expression.
In the United States, revisions to the draft Platform
Accountability and Consumer Transparency Act pushed the
legislation in a positive direction following feedback from
civil society. The bipartisan measure requires companies to
publish details about their moderation practices, institute due
process protections for users, and remove content deemed
illegal by a court within four days. This bill largely avoids the
missteps of many more problematic proposals to reform
Section 230 of the Communications Decency Act, which has
long shielded providers and content hosts from legal liability
for most material created by users.
Taiwan’s draft Internet Audiovisual Service Management Act
would enhance transparency about streaming platforms’
operations in the country by mandating that certain
companies report revenue and user statistics, provide an
easy-to-use user complaint mechanism, and ensure that their
16
@freedomonthenet
terms of service clarify how data are collected and used,
among other policies. The bill was introduced amid concerns
that streaming platforms owned by China-based companies
were operating illegally in Taiwan and could facilitate the
spread of disinformation or other manipulated content
emanating from Beijing.
Forcing companies to hand
over user data
In at least 38 of the 70 countries assessed this year,
governments initiated legal or administrative reforms
affecting tech companies’ management of user data.
Major platforms have often been prohibited by their home
country’s laws from handing over data to foreign officials.
The governments seeking information are now attempting
to sidestep these jurisdictional barriers by forcing companies
to store data on servers based within their borders,
surrender personal data to law enforcement agencies with
limited oversight, and circumvent the encryption of private
communications. Particularly in countries with poor human
rights records, domestic data storage significantly expands
the potential for surveillance and the risk of abuse. These
problematic provisions are sometimes paired with more
positive requirements for companies to protect users’ data
from other threats.
Data sovereignty as an excuse for
surveillance
A draft decree released in February 2021, as part of the
implementation of Vietnam’s Cybersecurity Law, expands
requirements for large and small online platforms to store
data on Vietnamese servers, including users’ names, birth
dates, nationality, identity cards, credit card numbers,
biometric files, and health records. Authorities can access
user data under vaguely defined pretexts related to national
security and public order. Full compliance with Vietnamese
law by social media companies would put activists, journalists,
and human rights defenders at risk, given the one-party
regime’s harsh suppression of perceived political dissent.
Interim regulations published in Saudi Arabia in October
2020 aim “to ensure preservation of the digital national
sovereignty over data.” Companies and government entities
must obtain written approval from the government regulator
before processing or transferring personal data outside of
the country. Meanwhile, new data protection regulations
enacted in Dubai, in the United Arab Emirates, require the
#FreedomOnTheNet