FREEDOM ON THE NET 2021 The Global Drive to Control Big Tech repercussions that their laws could have on internet freedom in more closed environments. Germany’s 2018 Network Enforcement Act (NetzDG), for example, introduced problematic requirements for companies to expediently remove content without a court order and establish a local legal presence. While the law has since been amended, the original has been mimicked and misused by backsliding democracies and authoritarian regimes in order to force social media providers to remove LGBT+ content and investigative journalism. Similarly, authorities in several countries cited the EU’s 2018 General Data Protection Regulation (GDPR) to stymie cross-border data flows and support vague exemptions for state surveillance. The DSA requires large intermediaries to produce detailed reports on a broad range of their practices, including content moderation, algorithmic curation and recommendation systems, and online advertising. Due process protections would also be bolstered under the law. Users would be notified about moderation decisions affecting their content and provided with an appeals process. However, the proposal builds on the controversial “notice-and-action” framework first introduced in the US Digital Millennium Copyright Act (DMCA) of 1998, which created a standard mechanism for copyright owners to request the removal of infringing materials from platforms without a court order. The DMCA suffers from challenges in issuing counternotices and documented abuse by politicians seeking to remove unfavorable content. Attention is needed to ensure that the DSA addresses these shortcomings and does not become a global model for censoring political expression. In the United States, revisions to the draft Platform Accountability and Consumer Transparency Act pushed the legislation in a positive direction following feedback from civil society. The bipartisan measure requires companies to publish details about their moderation practices, institute due process protections for users, and remove content deemed illegal by a court within four days. This bill largely avoids the missteps of many more problematic proposals to reform Section 230 of the Communications Decency Act, which has long shielded providers and content hosts from legal liability for most material created by users. Taiwan’s draft Internet Audiovisual Service Management Act would enhance transparency about streaming platforms’ operations in the country by mandating that certain companies report revenue and user statistics, provide an easy-to-use user complaint mechanism, and ensure that their 16 @freedomonthenet terms of service clarify how data are collected and used, among other policies. The bill was introduced amid concerns that streaming platforms owned by China-based companies were operating illegally in Taiwan and could facilitate the spread of disinformation or other manipulated content emanating from Beijing. Forcing companies to hand over user data In at least 38 of the 70 countries assessed this year, governments initiated legal or administrative reforms affecting tech companies’ management of user data. Major platforms have often been prohibited by their home country’s laws from handing over data to foreign officials. The governments seeking information are now attempting to sidestep these jurisdictional barriers by forcing companies to store data on servers based within their borders, surrender personal data to law enforcement agencies with limited oversight, and circumvent the encryption of private communications. Particularly in countries with poor human rights records, domestic data storage significantly expands the potential for surveillance and the risk of abuse. These problematic provisions are sometimes paired with more positive requirements for companies to protect users’ data from other threats. Data sovereignty as an excuse for surveillance A draft decree released in February 2021, as part of the implementation of Vietnam’s Cybersecurity Law, expands requirements for large and small online platforms to store data on Vietnamese servers, including users’ names, birth dates, nationality, identity cards, credit card numbers, biometric files, and health records. Authorities can access user data under vaguely defined pretexts related to national security and public order. Full compliance with Vietnamese law by social media companies would put activists, journalists, and human rights defenders at risk, given the one-party regime’s harsh suppression of perceived political dissent. Interim regulations published in Saudi Arabia in October 2020 aim “to ensure preservation of the digital national sovereignty over data.” Companies and government entities must obtain written approval from the government regulator before processing or transferring personal data outside of the country. Meanwhile, new data protection regulations enacted in Dubai, in the United Arab Emirates, require the #FreedomOnTheNet

Select target paragraph3