ing, because the legal defenses available in the
region for alleged infringers are relatively weak.
57
At the regional level, Intellectual Property
Rights pertaining to Internet content are
addressed by two directives: the Copyright and
Related Rights in the Information Society adopted
on April 9, 2001, and the Electronic Commerce
Directive 2000/31/EC, which came into force on
June 8, 2000. Article 5(1) of the Copyright
Directive exempts ISPs from liability for copyright
infringement where “reproduction is transient or
incidental” or where copies are an integral part of
a technological process “whose sole purpose is
to enable onward transmission in a network
between third parties by an intermediary or a lawful use of a work or other subject-matter to be
made.” The Copyright Directive also exempts
ISPs from liability where the copies have “no
independent economic significance”; this is left
to be adjudged independently by courts in the
respective member states. As per the first condition, ISPs and telecommunications operators do
not need to request permission to transmit transient copies across their networks. However, the
second condition implies that ISPs still face a situation of differing degrees of liability across the
member states of the EU, and the directive has
been criticized in this regard. 58 The Electronic
Commerce Directive deals with the liability of
ISPs toward content more generally, but with
important implications for copyright. In particular,
the directive provides a “mere conduit” exception, limits liability for content associated with the
caching and hosting functions, and exempts
ISPs from any general obligation to monitor.
Security
Security concerns in Europe have resulted in legislation concerning the surveillance and monitoring of Internet use. Although distinct from filtering, these have many parallels in their potential
impact upon online freedom of speech. A recent
and controversial area of legislation at the EU
level in this regard pertains to the surveillance of
traffic data and its retention. As per the European
Data Retention Directive, which was passed in
March 2006 and must be put into effect for
Internet traffic by March 2009, 59 ISPs in the various nations are required to retain specific data
pertaining to communications—in particular, with
regard to Internet access, e-mail and telephony—for a period of at least six months but not
exceeding two years. The data to be retained do
not concern the content of communications. The
aim is to bring about a “common code” of data
retention in order to facilitate the tracing of illegal
content and the source of attacks against information systems, and to identify those who use
the electronic communications networks for terrorist activities and organized crime. 60 As the
directive is implemented across the member
states, privacy groups are concerned about the
ability of ISPs, search engines, 61 and Web companies to retain data and monitor people’s online
habits. Moreover, the retention period of up to
twenty-four months has been argued to be an
unjustifiable length of time. 62
An example of security legislation at the
country level is a proposed law drafted in March
2007 in Sweden, which would give the national
defense intelligence agency power to monitor all
cross-border phone calls and e-mail traffic without court order. This will be carried out by the
National Defence Radio Establishment in the
form of searches for sensitive key words through
the use of computer software. With some suggested amendments, the Swedish Legislative
Council has approved the proposal to go forward. Concerns for privacy have been raised,
including for communications within the country,
which are often routed via servers hosted
abroad. 63 Critics include the country’s national
security police agency, SAPO, which considers
the proposal to be in violation of “personal
integrity.”
Regional Overviews
193
region for alleged infringers are relatively weak.
57
At the regional level, Intellectual Property
Rights pertaining to Internet content are
addressed by two directives: the Copyright and
Related Rights in the Information Society adopted
on April 9, 2001, and the Electronic Commerce
Directive 2000/31/EC, which came into force on
June 8, 2000. Article 5(1) of the Copyright
Directive exempts ISPs from liability for copyright
infringement where “reproduction is transient or
incidental” or where copies are an integral part of
a technological process “whose sole purpose is
to enable onward transmission in a network
between third parties by an intermediary or a lawful use of a work or other subject-matter to be
made.” The Copyright Directive also exempts
ISPs from liability where the copies have “no
independent economic significance”; this is left
to be adjudged independently by courts in the
respective member states. As per the first condition, ISPs and telecommunications operators do
not need to request permission to transmit transient copies across their networks. However, the
second condition implies that ISPs still face a situation of differing degrees of liability across the
member states of the EU, and the directive has
been criticized in this regard. 58 The Electronic
Commerce Directive deals with the liability of
ISPs toward content more generally, but with
important implications for copyright. In particular,
the directive provides a “mere conduit” exception, limits liability for content associated with the
caching and hosting functions, and exempts
ISPs from any general obligation to monitor.
Security
Security concerns in Europe have resulted in legislation concerning the surveillance and monitoring of Internet use. Although distinct from filtering, these have many parallels in their potential
impact upon online freedom of speech. A recent
and controversial area of legislation at the EU
level in this regard pertains to the surveillance of
traffic data and its retention. As per the European
Data Retention Directive, which was passed in
March 2006 and must be put into effect for
Internet traffic by March 2009, 59 ISPs in the various nations are required to retain specific data
pertaining to communications—in particular, with
regard to Internet access, e-mail and telephony—for a period of at least six months but not
exceeding two years. The data to be retained do
not concern the content of communications. The
aim is to bring about a “common code” of data
retention in order to facilitate the tracing of illegal
content and the source of attacks against information systems, and to identify those who use
the electronic communications networks for terrorist activities and organized crime. 60 As the
directive is implemented across the member
states, privacy groups are concerned about the
ability of ISPs, search engines, 61 and Web companies to retain data and monitor people’s online
habits. Moreover, the retention period of up to
twenty-four months has been argued to be an
unjustifiable length of time. 62
An example of security legislation at the
country level is a proposed law drafted in March
2007 in Sweden, which would give the national
defense intelligence agency power to monitor all
cross-border phone calls and e-mail traffic without court order. This will be carried out by the
National Defence Radio Establishment in the
form of searches for sensitive key words through
the use of computer software. With some suggested amendments, the Swedish Legislative
Council has approved the proposal to go forward. Concerns for privacy have been raised,
including for communications within the country,
which are often routed via servers hosted
abroad. 63 Critics include the country’s national
security police agency, SAPO, which considers
the proposal to be in violation of “personal
integrity.”
Regional Overviews
193
