Subscribe on LinkedIn

Brussels Revisits Copyright –  Part 1: Why the Rush to Block Live Sports Piracy Threatens Fundamental Rights

This is the first installment in a three-part series analyzing the European Commission’s current call for evidence on EU copyright rules. This post focuses on live content piracy; subsequent pieces will explore text and data mining (TDM) and the research exception. 

The European Commission has launched a call for evidence, which closes on 25 June, to support two parallel workstreams:

  1. the review of the Directive on Copyright in the Digital Single Market (DCDSM); and,
  2. the preparatory work for a targeted legislative proposal aimed at strengthening copyright in light of AI and other market developments, which is planned for Q1 2027.

One core area under review is the fight against live content piracy, with the call asking whether the 2023 Recommendation on combating online piracy of sports and other live events has been effective and if new enforcement remedies are needed. The evidence from three EU Member States gives a clear answer: the problem is not a shortage of powers, but the systematic removal of safeguards from the powers that already exist. As a result, legislating new tools on the same design principles will simply reproduce the same failures at an EU scale. Worse, the way these tools are already being used poses a real threat to the fundamental rights of anyone in the EU.

The logic that built the Piracy Shield in Italy

To understand how this threat manifests, we need to look at the underlying logic of the current framework. The Commission’s 2023 Recommendation rested on an accurate observation: live sports content loses most of its value the moment the event ends. Enforcement that arrives 24 hours after the final whistle is useless. The urgency of live content is thus a real constraint.

What has been built on that constraint, however, is a different matter.

Italy enacted the Piracy Shield system in direct response to this logic. Under this regime, administered by the Italian communications authority, AGCOM, rightsholders report unauthorised streams directly to the regulator, which then issues blocking orders to ISPs with a 30-minute implementation window. No prior judicial authorisation is required. Affected operators have five days to lodge a complaint, and AGCOM has ten days to decide. The unblocking procedure for errors is capped at 24 hours from the time of reporting.

Consequently, the urgency of a 90-minute match has produced a permanent administrative architecture with no meaningful judicial check. The time sensitivity that justified fast-track processing was used to remove the essential oversight. The scaffolding, in other words, became the building.

The threat of speed without safeguards

A 2025 peer-reviewed study titled “90th Minute”, described as the first rigorous analysis of the Piracy Shield, worked from a leaked dataset of 10,918 IP addresses and 42,664 fully qualified domain names (FQDNs) that had been blocked. The researchers treated this count as a conservative lower bound.

Their findings were unambiguous. Hundreds of legitimate websites were affected by erroneous or over-broad blocks. Notable collateral damage included:

  • Cloudflare (February 2024): A blocked IP address disabled thousands of unrelated websites simultaneously.
  • Google Drive (October 2024): The service was rendered inaccessible across Italy for more than twelve hours.
  • Local entities: The dataset contained personal branding pages, company profiles, hotels, restaurants, retail shops, an accountant, a telehealth missionary programme, and a nunnery.
  • Cross-border impact: Nineteen Albanian websites hosted on a single IP address were blocked and remained unreachable from Italy.

The researchers identified a structural flaw specific to the way illegal streamers operate. They lease IP address space. When the lease expires and a new user takes over that address, the Piracy Shield block remains in place. Because AGCOM does not publish lists of blocked addresses, new users have no way of discovering the block and no mechanism to challenge it. The IP address is permanently polluted.

The study’s conclusion on IP-level blocking was direct: it is an indiscriminate tool. The collateral damage is widespread and difficult to predict, and outweighs the benefits. It simply should not be used.

The harms fell into three categories:

  1. Economic disruption: Measurable financial damage to legitimate businesses.
  2. Technical harm: The blocking of shared infrastructure and the systemic pollution of IP address space.
  3. Uncompensated burden: Italian ISPs face growing operational costs to implement and maintain an expanding list of permanent blocks.

The Commission’s reaction

In July 2025, the Commission wrote formally to Italy’s Minister of Foreign Affairs assessing the Piracy Shield against the EU’s Digital Services Act (DSA).

The assessment was critical on multiple grounds:

  • Lack of legal basis: The Commission noted that the DSA does not provide a legal basis for orders issued by national administrative authorities.
  • Fundamental rights: It invoked the Charter of Fundamental Rights and the obligation under Recital 39 of the DSA to balance enforcement objectives against the rights of affected third parties.
  • Inadequate redress: It found that the 24-hour unblocking window does not respond to any justified need and could allow erroneous blocks to persist unresolved.

Despite these legitimate concerns, Italy’s response was to expand the Piracy Shield, extending automatic blocking beyond live sports events to film premieres and run-of-the-mill television programming.

Spain: precision abandoned

LaLiga, Spain’s top professional football league, has operated under a dynamic injunction regime requiring ISPs and VPN providers to block IP addresses hosting unauthorised streams during match windows. The approach is technically characterised as carpet bombing: broad, fast, and indiscriminate.

The documented collateral damage includes GitHub, Docker, and Vercel experiencing intermittent outages during match windows. Freedom.gov, a US government portal built to counter internet censorship, was temporarily blocked. Even when Vercel set up a dedicated inbox giving LaLiga direct access to its site reliability engineering team, specifically to enable targeted blocking requests, LaLiga continued sending broad requests regardless.

Cloudflare’s CEO Matthew Prince warned publicly: “It’s only a matter of time before a Spanish citizen can’t access a life-saving emergency resource because the rights holder in a football match refuses to send a limited request to block one resource versus a broad request to block a whole swath of the Internet.”

In February 2026, a Córdoba court issued injunctions without hearing the affected parties in advance, ordering VPN providers including NordVPN and ProtonVPN to block IP addresses associated with pirate streams. The court classified both providers as active participants in the piracy chain rather than neutral conduits, on the basis that they marketed their ability to bypass geo-restrictions.

NordVPN contested the order and presented technical evidence. The IP addresses used for pirate streams change constantly, often within hours, and as a result, any blocking list is out of date before it can be acted upon. Meanwhile, the collateral damage is substantial, as blanket IP-level blocks render thousands of lawful websites inaccessible. The Commercial Court of Córdoba, in a ruling dated 19 May 2026, rejected LaLiga’s request for coercive fines, finding it could not conclude that NordVPN had deliberately and without justification breached the order. The technical finding is now on the record: the approach does not work.

France and the escalation pattern

France has followed the same trajectory. Canal+ and the Ligue de Football Professionnel obtained court orders requiring VPN providers to block access to pirate sites. Cloudflare was ordered to geoblock more than 400 sports streaming domains. ProtonVPN raised jurisdictional and technical objections: the measures were technically difficult to implement, costly, and unnecessarily broad; compelling a Swiss company to block content for the French market restricted cross-border trade in services; and the relevant provision of French sports law violated the EU Open Internet Regulation. All defences were rejected.

The VPN Trust Initiative warned that targeting VPN infrastructure sets a censorship precedent extending well beyond copyright. The more immediate practical consequence is clear: if reliable, audited VPN providers are forced out of a national market, users will turn to providers with weaker security records. The enforcement action protects sports rights at the cost of exposing ordinary internet users to greater risk.

Across all three jurisdictions, the progression follows a documented sequence. 

Websites → DNS Resolvers → Content Delivery Networks (CDNs) → VPN Providers

Blocking orders begin with websites. They extend to DNS resolvers. They move to content delivery networks. They now reach VPN providers. Each step extends blocking obligations deeper into core internet infrastructure, and each step is justified by the same urgency rationale that drove the first. The architecture of enforcement is being built outward from a football match, with no stated stopping point.

What the Commission should now decide

The call for evidence assessed the 2023 Recommendation as having had limited effect and asked whether new enforcement remedies are needed. The evidence from Italy, Spain, and France does not support the proposition that an absence of powers explains the problem. It supports the proposition that existing powers are being applied without the precision or safeguards the law requires, and that the documented harm is the direct consequence.

COMMUNIA, in its May 2025 response to the Commission, made the point clearly: the 2023 Recommendation already enumerates proportionate measures available under the existing EU legal framework. The enforcement gap is procedural, not legislative.

Five conclusions follow from the evidence.

1. Ban IP-Level Blocking

Academic peer review and the technical evidence presented in the Córdoba proceedings both support this conclusion. The mechanism is too blunt for the precision that enforcement against live piracy actually requires.

2. Time-Limit Domain and FQDN Blocks

Domain-level or FQDN blocking, where used at all, should be confined to time windows aligned with the duration of the live event. The urgency argument that justifies speed does not justify permanence. A block that extends indefinitely beyond the 90-minute window it was created to protect is no longer an enforcement measure calibrated to the harm.

3. Exclude Core Infrastructure

VPN providers and core internet infrastructure must remain outside the scope of blocking obligations. They are not participants in the piracy chain. Treating them as such builds a censorship architecture whose logic is not bounded by copyright.

4. Implement Safeguards by Design

Any new mechanism must include structural safeguards: mandatory proportionality requirements, prior adversarial proceedings where practicable, immediate notification for affected parties, a clear and fast unblocking mechanism, and full transparency about what is blocked. Assurances of proportionate use are not a substitute for legal requirements.

5. Protect Judicial Due Process

Procedures created for live-event enforcement must be structurally incapable of being repurposed to route around judicial due process. The Commission’s own formal assessment confirmed that the Piracy Shield does not comply with the DSA in several material respects. Extending that model to all Member States through new legislation would not improve enforcement; it would export a documented failure.

The available choice

Speed and judicial oversight are not mutually exclusive. Building both into an enforcement architecture is harder than building only speed, but the Commission has the evidence it needs to design a framework that delivers both. What the evidence does not support is designing a faster version of the same instrument that has already blocked a nunnery, taken down Google Drive for twelve hours, and been formally criticised by the Commission itself. Creating a framework that ensures the criticism is embedded in law and cannot be disregarded by Member States seems a better path.

Written by Caroline De Cock, LL.M., Head of Research