EU top court: VPNs are lawful tools, not piracy accomplices

4 min read 1 source clear_take
├── "VPNs are lawful general-purpose infrastructure and providers shouldn't be liable for user activity"
│  ├── top10.dev editorial (top10.dev) → read below

The editorial frames the ruling as a decisive win for privacy infrastructure, arguing VPNs belong in the same conceptual bucket as ISPs, DNS resolvers, and reverse proxies — general-purpose tools whose lawfulness doesn't hinge on how a subset of users misuse them. It emphasizes that liability requires more than the theoretical possibility of infringement, and celebrates that this shuts the door on rights-holder attempts to reclassify privacy infrastructure as infringement infrastructure.

│  └── @speckx (Hacker News, 303 pts) → view

By submitting the article with the framing 'VPNs are lawful technical tools,' the submitter endorses the court's mere-conduit interpretation. The 303-point score and 118 comments suggest strong community resonance with the position that VPN operators should not be treated as copyright enforcers.

└── "Targeted court-ordered blocking is still permitted — this isn't a blanket immunity"
  └── top10.dev editorial (top10.dev) → read below

The editorial carefully notes that national courts retain the power to issue specific, targeted measures like blocking known infringing destinations. What the ruling forbids is general monitoring obligations under Article 8 of the DSA — meaning VPN providers can't be compelled to police traffic they deliberately cannot see, but they aren't wholly untouchable either.

What happened

The Court of Justice of the European Union has issued a ruling that goes further than most copyright watchers expected: VPNs are lawful technical tools, and providing one does not, by itself, make an operator liable for what customers route through it. The case reached Luxembourg via a referral from a national court weighing whether rights holders could force VPN operators to block, filter, or hand over user data on the theory that VPNs are essentially piracy infrastructure.

The court's answer was a clean no. VPNs, the judgment reasons, sit in the same conceptual bucket as ISPs, DNS resolvers, and reverse proxies — general-purpose network tools whose lawfulness does not depend on the worst thing a subset of users might do with them. That framing pulls VPN providers under the same "mere conduit" logic that has protected transit networks in EU law since the e-Commerce Directive, and now under the Digital Services Act.

The practical effect: national courts can still order specific, targeted measures — blocking a known infringing destination, for example — but they cannot treat a VPN provider as a copyright cop responsible for policing traffic it deliberately cannot see. Attempts to compel general monitoring remain off the table under Article 8 of the DSA, and this ruling nails that door shut for the VPN category specifically.

Why it matters

The rights-holder lobby has spent the better part of a decade trying to reclassify privacy infrastructure as infringement infrastructure. The playbook is familiar: sue the intermediary, extract a settlement, use the settlement as precedent, repeat. It has worked, in patches, against hosting providers, CDNs, and even some DNS resolvers. A win here would have opened a wide new front.

What the court actually held is narrower and more useful than the headlines suggest: the mere provision of a VPN service is a lawful economic activity, and liability requires something more than "users could theoretically infringe." That "something more" — actual knowledge, active facilitation, refusal to comply with a specific and proportionate court order — is exactly the standard that already governs hosts and platforms. The ruling harmonizes VPNs into that framework rather than carving out a special punitive regime.

Compare this with the direction of travel in the UK, where the Online Safety Act's age-assurance rules have pushed a chunk of the population onto VPNs to escape ID checks, and Ofcom has openly mused about whether VPN use itself is a policy problem. Or the US, where the recurring KOSA / EARN IT cycle keeps floating theories of intermediary liability that would make a serious VPN business hard to run. The EU has now planted a flag in the opposite direction, and it is a flag with the weight of Court of Justice precedent behind it — meaning every member state's copyright litigation now has to route around it.

Community reaction on Hacker News (303 points and climbing on the submitting link) leaned toward cautious relief rather than celebration. The top-voted comments correctly noted that this ruling closes one attack vector but does nothing about the more insidious one: KYC-style requirements bolted onto VPN signup, payment-processor pressure, or app-store deplatforming. A ruling that VPNs are legal is a floor, not a ceiling. Mullvad can keep operating; whether Stripe will keep processing its payments is a separate question the CJEU does not answer.

There is also a quiet second-order effect for anyone building privacy-preserving infrastructure adjacent to VPNs: Tor bridges, mixnets, decentralized relays, WireGuard-based mesh networks. The court's reasoning — that a general-purpose tool is not made unlawful by the misuse of a minority — is precisely the argument these projects have needed as governments began treating protocol-level privacy as a suspicious act. Precedent from the CJEU is not binding on those adjacent categories, but it makes the analogical argument much easier to make in court.

What this means for your stack

If you operate a VPN, run a self-hosted WireGuard endpoint for a team, or ship a product that includes a tunneling component (Tailscale, Cloudflare WARP integrations, per-app VPN features in mobile apps), the immediate change is mostly negative — as in, a bad thing that isn't going to happen to you. Rights-holder demands for bulk user data or preemptive filtering can now be answered with a citation to this ruling. You are still on the hook for compliance with specific, narrowly-tailored court orders; you are not on the hook for being a VPN.

For developers building anything that touches encrypted transit — including corporate mesh networks, zero-trust overlays, or privacy-focused consumer apps — the ruling is worth reading in full before your next legal review. The court's articulation of "lawful technical tool" is broader than VPNs and gives your counsel a much stronger starting position when a European regulator or rights holder comes asking questions. It is the kind of precedent you cite once and then never have to re-litigate.

On the operational side, nothing changes about the boring parts: DMCA-equivalent notices under national implementations still require a response, subpoenas from criminal proceedings still get honored, and you still need a real abuse desk. What you do not have to do is build a filtering pipeline, log traffic you have promised users you do not log, or accept the theory that your product is fundamentally suspect.

Looking ahead

The rights-holder lobby will regroup and try again — probably at the DSA implementation level, probably via national laws that try to define VPNs out of the "technical tool" category, and probably via payment-processor and app-store pressure that bypasses the courts entirely. But for the first time in a while, the legal ground under privacy infrastructure in Europe is firmer than it was yesterday, and the burden of proof has shifted back to the people trying to break it.

Hacker News 303 pts 118 comments

'VPNs are lawful technical tools,' says EU Court in landmark copyright ruling

→ read on Hacker News

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.