← All insights
dmca compliance7 min read

The §512 safe harbour is not automatic — and telecom operators are getting it wrong

Section 512 of the Digital Millennium Copyright Act provides internet service providers with a safe harbour from copyright infringement liability — but it comes with conditions. The most consequential condition is having adopted and reasonably implemented a policy providing for the termination of repeat infringers. Courts have consistently found that this is where most ISP programmes fail, and the litigation landscape since 2018 has made the stakes for getting it wrong very large.

What BMG v. Cox actually held

In 2018, the Fourth Circuit Court of Appeals affirmed that Cox Communications lost its §512 safe harbour protection because it failed to implement its repeat infringer policy in any consistent or meaningful way. Cox had built an automated system to process infringement notices — but it had also throttled the rate at which notices could generate action, blacklisted a major rights management firm so that nearly two million notices were rejected without processing, and allowed terminated subscribers to restore service after six months.

The court held that proving contributory infringement requires proof of at least willful blindness; negligence is insufficient. But it also found that Cox's conduct — systematically blocking notices, maintaining a policy that resulted in almost no actual terminations — crossed that line. A $25 million judgment at the district court level was followed by a $1 billion judgment on retrial in 2022, which itself has continued through appeals.

Where most carrier processes fall short

The most common failure mode is not malicious — it is structural. ISPs build notice processing systems optimised for volume management and operational efficiency, not for legal defensibility. Throttles, automated responses, escalation caps, and subscriber-friendly reinstatement policies are all rational operational choices that become legal liabilities when they are collectively read as evidence that the ISP had no serious intention of enforcing its repeat infringer policy.

A second common failure is the definition of 'repeat infringer.' Many ISP policies define the relevant threshold in terms of notices received. If the policy is never actually enforced at that threshold — if subscribers who hit 10 notices continue to receive service without consequence — the policy offers no protection. Courts look at implementation, not documentation.

The 'repeat infringer' definition that courts apply

Cox's principal argument in BMG was that 'repeat infringer' meant a subscriber adjudicated by a court to have infringed multiple times. The Fourth Circuit rejected this. The operative definition is: a subscriber who infringes, or about whom the ISP has received notices of infringement, more than once. Adjudication is not required.

This has significant implications for how ISPs must structure their policies. A policy that requires final judicial determination before any action is taken is not a policy for the purposes of §512. The statute requires that the ISP respond to the body of notices it receives — and respond in a way that a court can characterise as consistent and meaningful enforcement.

What a defensible §512 policy requires

A §512 policy that will survive judicial scrutiny has several non-negotiable characteristics. It must be documented clearly, communicated to subscribers, and actually enforced. Progressive enforcement steps — warning, service limitation, suspension, termination — need to be implemented at the thresholds the policy specifies, not as discretionary options.

Notice intake must be reliable. An ISP that blocks or throttles notices from rights holders for operational reasons is building in exactly the kind of willful blindness that the Fourth Circuit found dispositive. Notices that are received must be logged, processed, and acted upon on the policy timeline. And the audit trail that demonstrates this needs to survive the period between the infringement and when litigation is filed — which can be years.

The litigation landscape has only intensified since BMG

BMG v. Cox was not an isolated outcome. Sony Music Entertainment v. Cox Communications resulted in a $1 billion jury verdict in 2022. UMG Recordings v. Grande Communications resulted in a $46.8 million judgment. Plaintiffs have become considerably more sophisticated about identifying the specific operational failures that strip safe harbour protection — and the damages in these cases are calibrated to the scale of infringement that the ISP's policy failure enabled.

ISPs that have not reviewed their §512 implementation against the post-BMG case law are operating on assumptions about their legal exposure that the litigation record has invalidated. The safe harbour still exists, and it is still achievable — but it requires a programme that takes the implementation requirements seriously, not a policy document that stops at the point of being written.

Yaana Technologies

Ready to audit your intercept stack?

Talk to the Yaana team about secure-by-design infrastructure for your network.

Request a Meeting →