CJEU: Online Marketplaces Are Data Controllers Under GDPR
A New Era of Responsibility: EU Court Mandates Proactive Data Vetting for Online Platforms
In a digital landscape often likened to the Wild West, a landmark judgment from the European Union’s highest court has fired a clear warning shot across the bows of online platforms. The era of passive hosting, where marketplaces and classified ad sites could claim ignorance of the user-generated content on their pages, has been decisively ended. A ruling by the Court of Justice of the European Union (CJEU) has fundamentally redrawn the lines of liability, confirming that operators of such platforms can no longer hide behind a veil of neutrality. Instead, they are now considered active data controllers under the stringent General Data Protection Regulation (GDPR), saddled with formidable, proactive duties to verify, moderate, and prevent the unlawful spread of personal information.
The judgment, delivered by the Grand Chamber in the case of X v Russmedia Digital SRL, represents a seismic shift in the legal understanding of platform responsibility. It moves beyond the established ‘notice-and-takedown’ model, which placed the onus on victims to report harmful content after the fact. The court has now mandated a ‘prevent-and-protect’ approach, forcing platforms to become gatekeepers of data privacy before any potential harm is inflicted. This decision carries profound implications, not only for the business models of countless websites but also for the very nature of anonymity and free expression online.
The Case that Changed the Rules
The catalyst for this legal earthquake was a deeply distressing, yet all too common, violation of personal privacy. In 2018, an unidentified individual took a photograph and telephone number belonging to a woman, referred to in court documents simply as ‘X’, from her private social media profile without her permission. This personal information was then used to create a salacious advertisement for sexual services, which was posted on Publi24.ro, a popular online marketplace in Romania operated by Russmedia Digital SRL.
Upon discovering the egregious misuse of her data, X immediately complained to Russmedia. To its credit, the platform acted swiftly, removing the offending advertisement within an hour. However, in the fast-moving digital world, an hour is an eternity. The damaging content had already been scraped, copied, and republished across a network of other websites, amplifying the harm and making its complete erasure from the internet a near-impossible task. Facing significant distress and damage to her reputation, X launched a legal claim against Russmedia, alleging infringement of her rights to personal portrayal, honour, and privacy, and, crucially, the unlawful processing of her personal data under GDPR.
The Romanian court, grappling with the complex interplay between data protection law and the established liabilities of online service providers, referred a series of critical questions to the CJEU for a preliminary ruling. The central question was a profound one: is an online marketplace merely a passive conduit for its users’ content, or does it play an active role that makes it a ‘data controller’ with all the attendant legal responsibilities?
From Passive Host to Active Controller
The CJEU’s answer was unequivocal. The Court determined that Russmedia, and by extension other similar platform operators, qualifies as a data controller as defined in Article 4(7) of the GDPR. This classification hinges on the determination that the platform exerts a “decisive influence” over the processing of personal data and does so for its “own commercial purposes.” The Court dismantled the argument that the platform was a mere technical host, pointing to several key factors that demonstrated its active role.
Firstly, the Court established the concept of joint controllership. It ruled that from the moment an advertisement containing personal data is published, the platform operator and the user who uploaded it become joint controllers. This means they share the legal responsibility for ensuring the data is processed lawfully. The platform cannot simply shift all blame to the anonymous user who posted the content.
Secondly, the commercial purpose was deemed central to the platform’s role. Russmedia’s terms and conditions granted it the power to exploit or remove user-generated content at its discretion. The Court interpreted this as direct participation in determining the purpose of the data processing. By making personal data accessible to a vast audience of internet users, the platform was not merely hosting information; it was actively using that information to generate traffic, engagement, and, ultimately, revenue. This commercial exploitation transformed its role from passive to active.
Finally, the Court found that the platform determined the essential means of processing. It was Russmedia that designed the architecture of publication: setting the classification headings, the duration of the advertisement’s visibility, and the overall presentation. Crucially, its system facilitated the unlawful act by allowing advertisements to be placed anonymously and without any mechanism to verify the consent of the person whose data was being shared. By controlling these fundamental elements of how the data was structured and disseminated, Russmedia was found to have exerted the “decisive influence” necessary to be labelled a data controller.
The End of the E-Commerce Exemption
A key pillar of the platforms’ defence was the liability exemption found in Article 14(1) of the E-Commerce Directive. This ‘safe harbour’ provision was designed to protect information service providers that play a neutral, purely technical, and passive role in hosting content. It was intended to foster the growth of the internet by shielding intermediaries from liability for the actions of their users, provided they were unaware of the illegality and acted quickly to remove content once notified.
However, the CJEU firmly rejected this defence. The Court reasoned that applying this exemption would “interfere with the GDPR regime,” effectively undermining the higher standard of protection afforded to personal data. Since the Court had already established that Publi24.ro’s role was active and non-neutral—driven by its own commercial interests and its control over the means of publication—it could not benefit from a shield designed for passive intermediaries. The stricter, more demanding obligations of the GDPR must prevail.
A Tidal Wave of New Obligations
The classification as a data controller is not merely a change in legal terminology; it unleashes a torrent of new, practical obligations for platform operators. These duties fundamentally reshape the operational realities of running a website that hosts user-generated content.
The most significant change is the shift from reactive takedowns to proactive vetting. Platforms are now required to implement “appropriate technical and organisational measures” before content containing personal data goes live. This includes identifying advertisements that contain sensitive data, such as information revealing a person’s health, ethnic origin, or sexual life. For such content, the platform has a positive duty to verify that the advertiser is either the data subject themselves or has obtained that person’s explicit and verifiable consent for publication. If a lawful basis like consent cannot be established, the platform must refuse to publish the advertisement.
This duty extends beyond the platform’s own digital walls. The Court also stated that the operator must take all appropriate measures to prevent such advertisements from being “copied and unlawfully published on other websites.” This is a staggering requirement in an age of automated bots and rapid information sharing. It suggests a responsibility that is not discharged simply by deleting the original post, but one that may involve actively monitoring for republication or notifying data subjects of a breach so they can seek its removal elsewhere. The technical and logistical challenges of such a mandate are immense and, some would argue, almost impossible to fulfil completely.
The Far-Reaching Consequences for the Digital Sphere
This ruling will send shockwaves through the digital economy, forcing a fundamental rethink of business models and user interaction. The implications are profound and will be felt across a wide spectrum of online services. For operators of online marketplaces, classified ad sites, and similar platforms, the financial and legal risks have escalated dramatically. As joint controllers, they can be held fully liable for their users’ unlawful data processing, facing GDPR fines of up to 4% of global annual turnover or €20 million, whichever is greater.
To comply, these platforms must invest heavily in new moderation and verification systems. This will likely involve a combination of sophisticated AI tools designed to flag personal and sensitive data, alongside teams of human moderators for review. They must also develop robust mechanisms for identity and consent verification, a process that is fraught with technical complexity and privacy trade-offs. The days of instant, frictionless publishing of classifieds may be over, replaced by a slower, more deliberate process involving mandatory review steps.
This, in turn, will have a significant impact on user anonymity. The need to verify identity or consent for ads containing personal data will inevitably curtail the ability of users to post anonymously or pseudonymously. Whilst this may be welcome in tackling malicious content, it could have a chilling effect on legitimate free expression, particularly for individuals discussing sensitive topics or for whistleblowers. Furthermore, to fulfil their verification duties, platforms may need to collect more personal data from their users, creating a direct tension with the core GDPR principle of data minimisation.
While the case centred on a classifieds site for sexual services, its legal principles are broadly applicable. E-commerce sites featuring user reviews with photos, online forums where personal experiences are shared, and even dating apps that handle vast amounts of sensitive health and sexual preference data all fall within the potential scope of this judgment. They must all now reassess their processes and determine whether their level of control and commercial interest makes them a data controller. This decision firmly moves the goalposts, demanding that platforms evolve from passive hosts into active, responsible guardians of personal data.
Free Claim Assessment
Find out if you have a valid claim — free, no obligation.
Start Free Assessment