Speech and online harassment
Regulation (EU) 2022/2065, applicable to all platforms since February 2024, imposes procedural duties: an accessible notice mechanism, a statement of reasons for every removal or suspension, a free internal complaint route, and access to out-of-court dispute settlement. Very large platforms carry additional risk-assessment obligations. What counts as illegal content remains defined by each member state's law. A closed account now gives the right to a statement of reasons, an internal appeal and out-of-court dispute settlement.
The Regulation reverses an old asymmetry: until now a user whose account was closed had no remedy. They are now entitled to reasons, an internal appeal and out-of-court arbitration.
What is illegal remains national. Insult, defamation, glorification of terrorism and hate speech are not defined identically in Ireland, France or Germany, and the same message can be lawful in one state and not in another.
Key points
| Instrument | Regulation (EU) 2022/2065, applicable to all platforms since February 2024 |
|---|---|
| Subject | Procedure, not the definition of illegality |
| Notice | Accessible reporting mechanism, mandatory |
| Reasons | Every removal or suspension must be reasoned |
| Appeal | Free internal complaint, then out-of-court settlement |
| Illegality | Defined nationally: insult, defamation, hate speech, threats |
Frequently asked questions
Does the Regulation say what I may write?
No. It governs how platforms handle reports; the definition of illegality remains national.
My account was closed without explanation — what now?
Since 2024 the platform must give reasons and provide a free internal appeal; you can then go to an out-of-court dispute settlement body.
Who supervises platforms?
A Digital Services Coordinator in each member state, and the Commission for very large platforms.
Does it apply to small forums?
Yes, with lighter obligations: the heaviest requirements apply only to very large platforms.
The general article: Speech and online harassment · Compare with another country
Copyright
Directive 2001/29/EC harmonised the rights of reproduction, communication to the public and distribution, together with a list of optional exceptions — private copying, quotation, parody. Directive (EU) 2019/790 added, in Article 17, liability for content-sharing platforms in respect of works uploaded by their users, subject to best-efforts obligations. Member states transposed both with real differences, notably on private copying. The 2019 copyright directive, and its article 17 on platforms, was one of the most contested votes in the European Parliament.
Unlike the GDPR these are directives: each state transposes them, and differences remain. Private copying, parody and educational use are not treated the same way from one country to the next.
Article 17 of the 2019 Directive was the most contested: it requires sharing platforms to obtain authorisations or prevent notified works from reappearing, which the Court of Justice upheld in 2022 subject to safeguards for freedom of expression.
Key points
| Instruments | Directive 2001/29/EC; Directive (EU) 2019/790 |
|---|---|
| Nature | Directives: transposed into national law, with variations |
| Term | Harmonised at 70 years after the author's death (Directive 2006/116/EC) |
| Exceptions | Quotation, parody, private copying, as each state chose |
| Platforms | Article 17 of the 2019 Directive: liability for uploaded content |
| Photographs | Protected once original, with no formality |
Frequently asked questions
Is copyright the same across the Union?
No. Term and the main principles are harmonised, but exceptions are transposed differently.
How long does protection last?
Seventy years after the author's death, harmonised throughout the Union.
Is a photo on a profile protected?
Yes, as soon as it is original, with no registration formality.
What does Article 17 change for platforms?
It makes them liable for works uploaded by users unless they make genuine efforts to obtain licences and prevent re-uploads.
The general article: Copyright · Compare with another country
Identity theft
The Union has not harmonised identity theft as such, but it requires the punishment of illegal access to an account, which is almost always the starting point.
Directive 2013/40/EU obliges member states to criminalise illegal access to an information system, illegal data interference and illegal interception, with harmonised minimum penalties and aggravating circumstances where the offence is committed within a criminal organisation or by misusing another person's identity. Creating a fake profile is a matter for national criminal law, which varies widely, and for data protection.
The Directive targets computer intrusion, not social imposture. A fake profile built from your photographs, without any account being hacked, falls outside it: national law and the GDPR apply.
The round-the-clock contact points required by the Directive serve cross-border investigations. For a victim the practical route remains a complaint at home, which triggers cooperation.
Key points
| Instrument | Directive 2013/40/EU of 12 August 2013 |
|---|---|
| Subject | Illegal access, data interference, illegal interception |
| Penalties | Harmonised minimum thresholds, aggravated where identity is misused |
| Fake profiles | Governed by national law and the GDPR |
| Cooperation | Round-the-clock national contact points |
| Removal | The Digital Services Act imposes notice and reasons |
Frequently asked questions
Is identity theft a European offence?
Not as such. The Union harmonises illegal access to information systems; creating a fake profile is a matter of national law.
What if my account was hacked?
Report it in your own country: illegal access is an offence throughout the Union under the 2013 Directive.
And if someone uses my photos without hacking anything?
That is an interference with your personal data and, in some states, a criminal offence. Reporting to the platform is governed by the Digital Services Act.
Does police cooperation work?
The Directive requires contact points available at all times; in practice everything starts with the complaint filed at home.
The general article: Identity theft · Compare with another country
Online shopping
Fourteen days to change your mind without giving a reason: the right of withdrawal is the best-known European consumer rule, and it comes from a directive transposed everywhere.
Directive 2011/83/EU on consumer rights requires pre-contractual information, a fourteen-day right of withdrawal for distance purchases and a ban on pre-ticked boxes. Directives (EU) 2019/770 and 2019/771 extended this to digital content and services and set a minimum two-year conformity guarantee for goods. These are largely maximum-harmonisation directives: states cannot offer less, nor much more.
The fourteen days run from delivery, not from the order, and the period is extended by twelve months if the trader failed to inform the buyer of the right.
The legal guarantee of conformity is not the seller's commercial warranty: it is statutory, lasts at least two years and binds the seller, not the manufacturer.
Key points
| Instruments | Directive 2011/83/EU; Directives (EU) 2019/770 and 2019/771 |
|---|---|
| Withdrawal | Fourteen days without reason for distance purchases |
| Guarantee | Conformity of goods for at least two years |
| Digital | Digital content and services covered since 2022 |
| Harmonisation | Largely maximum: little national leeway |
Frequently asked questions
How long do I have to withdraw?
Fourteen days from delivery, with no reason required, for a distance purchase.
What if the trader did not tell me?
The period is extended by twelve months.
Does the legal guarantee cover digital products?
Yes, since the 2019 Directives, applicable from 2022.
Is a non-EU website bound?
If it directs its activity at consumers in the Union, the protective rules apply and the consumer can sue in their own country's courts.
The general article: Online shopping · Compare with another country
Romance scams
Two instruments help victims: the one banning misleading commercial practices, and the one obliging the bank to refund an unauthorised transaction.
Directive 2005/29/EC prohibits unfair and misleading commercial practices, with a blacklist of conduct banned in all circumstances. Directive (EU) 2015/2366, known as PSD2, requires strong customer authentication and obliges the payment provider to refund an unauthorised transaction immediately, unless the payer acted fraudulently or with gross negligence, with the burden of proof on the bank. Together they underpin the remedies available after a romance scam.
The decisive distinction is between an unauthorised transaction — a payment made without your consent, refundable — and an authorised transfer made under manipulation, which is far harder to recover.
Reporting immediately matters: a refund for an unauthorised transaction requires prompt notification, and the bank must refund by the end of the following business day.
Key points
| Instruments | Directive 2005/29/EC; Directive (EU) 2015/2366 (PSD2) |
|---|---|
| Misleading practices | Prohibited, with a blacklist of always-unlawful conduct |
| Strong authentication | Required for most online payments |
| Unauthorised transaction | Immediate refund unless fraud or gross negligence |
| Burden of proof | On the payment provider, not the customer |
Frequently asked questions
Must my bank refund me?
For an unauthorised transaction, yes, by the end of the business day following your notification, unless you acted fraudulently or with gross negligence.
What if I made the transfer myself?
That is an authorised transfer: refund is not automatic, though a claim may still be possible depending on the circumstances.
Who has to prove what?
The payment provider must prove the transaction was authenticated and accurately recorded; the customer does not have to prove the negative.
Who do I report to?
The bank immediately, then the police and your national consumer protection authority.
The general article: Romance scams · Compare with another country
