Why judges need jurisprudence in cyberspace

  Chris Reed


Judges are increasingly asked to decide whether a rule of national law is applicable to a cyberspace actor who is not present in their jurisdiction, or whose activities do not clearly fall within the established understanding of the rule. They do this through interpreting the applicability and meaning of the law.

Every attempt to enforce a national law makes a claim that the law has authority over the cyberspace actor. By accepting that claim, the judge asserts that the law's claim is legitimate. This is a Hartian exercise, adopting the internal view of the national legal system as the test for legitimacy.

But in cyberspace the legitimacy of a national law claim is determined not by the internal perspective of the legal system but by the external perspective of cyberspace actors. A law will only have authority in cyberspace if it can convince cyberspace actors that its claim is legitimate. And a legal system which repeatedly makes illegitimate claims thereby weakens its status as a system which adheres to the rule of law.

Judges can help solve this problem by interpreting laws and applying public and private international law so as to reject applicability claims which are illegitimate. To do this successfully, they need to understand the jurisprudential foundations of any law's authority in cyberspace.


6 The CJEU decision in Case C-131/12 26 Google Spain v AEPD & Costeja González November 2014 did not go quite so far as to state this expressly when holding that the display of personal data in search results was subject to Spanish data protection law when it occurred ‘in the context of’ the commercial relationship between Google Inc and its Spanish advertising subsidiary, and that the Spanish data protection authority thus had power to make orders against Google Inc, a US corporation (paras 54–60). However, the Article 29 Working Party's Guidelines on the Implementation of the Court of Justice of the European Union Judgment on ‘Google Spain and Inc v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González’ C-131/12, WP255 26 November 2014 specifically assert that the law applies to protect all individuals, world-wide (para 19), and that Google Inc must comply in relation to searches via its US-based .com search service as well as in its EU-domain denominated services (para 20).

16 Devaux, CThe role of experts in the elaboration of the Cape Town Convention: between authority and legitimacy’ (2103) 19 European Law Journal 843 at 845.

17 Paiement, PParadox and legitimacy in transnational legal pluralism’ (2013) 4 Transnational Legal Theory 197 at 213–215.

18 Fuller, L The Morality of Law (New Haven: Yale University Press, Revised edn, 1969). The application of Fuller's argument to cyberspace is explored more fully in Reed, CHow to make bad law: lessons from cyberspace’ (2010) 73 MLR 903 at 914–919 and Reed, C Making Laws for Cyberspace (Oxford University Press: Oxford, 2012) ch 10.

19 Ibid, pp 33–38, under the heading ‘Eight ways to fail to make law’.

24 SFS 1998:204, the Swedish data protection law which implemented the Data Protection Directive (Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, [1995] OJ L 281/31 (Data Protection Directive)).

25 Case C-101/01 Lindqvist 6 November 2003. The ECJ also held that merely uploading personal data to a website without more did not amount to the export of that data outside the EEA, even though it was potentially accessible by persons outside the EEA, but this is not directly relevant to the discussion here and so is not considered further.

26 In particular in relation to the meaning of ‘personal and household activity’ (D Erdos ‘Data protection and the right to reputation: filling the “gaps” after the Defamation Act 2013’ (2014) CLJ 536; DB Garrie and R Wong ‘Social networking: opening the floodgates to “personal data”’ (2010) CTLR 167); meanings of the terms ‘personal data’ and ‘processing’ (H Crowther ‘Remember to forget me: the recent ruling in Google v AEPD and Costeja’ (2014) CTLR 163 at 173; P Gryffroy ‘Delisting as a part of the decay of information in the digital age: a critical evaluation of Google Spain (C-131/12) and the right to delist it has created’ (2016) CTLR 149); meaning of the Directive's data export provisions (D Kamarinou ‘International transfers of personal data and corporate compliance under Directive 95/46/EC, the draft Regulation and the international community: Part 1’ (2013) Comms Law 49).

27 D Erdos ‘Data protection confronts freedom of expression on the “new media” internet: the stance of European regulatory authorities’ (2015) EL Review 531; D Mac Sithigh ‘“I'd tell you everything if you'd pick up that telephone”: political expression and data protection’ (2011) EHRLR 166.

28 Though the Swedish Data Act (Datalagen, 1973:289), the predecessor legislation to the Personuppgiftslag, had been in force for 25 years and, at least in the UK, data protection issues were widely reported in the general press during that period (see eg ‘First data protection conviction’ (The Times 16 December 1987); ‘Protecting the people – The Data Protection Act works in the public interest, says its registrar’ (The Guardian 13 December 1990); ‘Pressing questions over personal rights’ (The Times 1 September 1994)).

29 English translation from Unfortunately no translation of the Swedish Penal Code more recent than 1999 is available, so neighbouring Norway has been used as the comparator for addressing.

30 To give some idea of the level of detailed lawmaking, in Release 6 of May 2016 the Glossary alone ran to 538 pages. The Conduct of Business Sourcebook section (a small part of the whole) was 522 pages long. The full Handbook amounts to many thousands of pages and is constantly growing in size. Each part of the Handbook contains cross-references to other parts, so that a full understanding of any part requires some mastery of the whole.

36 The International Association of Privacy Professionals has more than 12,000 members in 78 countries ( and accreditation for data protection professionals has been introduced (eg the British Computer Society's Certificate in Data Protection, Most, perhaps all, organisations of any size recognise the need to employ such professionals to assist them in complying with the law, and Art 37 of the Regulation will require all enterprises which engage in large-scale processing of personal data to appoint such a person.

39 Moberg v 33T LLC 666 F Supp 2d 415 (D Del 2009).

40 Kernal Records Oy v Mosley 694 F 3d 1294 (11th Cir 2012).

41 Moberg, above n 39, at 420.

42 17 USC §410(c), at §412.

43 ‘We will not ascribe bad faith to Plaintiff for failing to seek registration earlier in the case. Plaintiff made a calculated decision not to do so even though the issue was contested. Plaintiff's decision to hedge its bet supports our conclusion that Plaintiff has not met the good cause standard … for a tardy amendment of the pleadings’: Kernal Records, above n 40, at 1370.

48 In Lindqvist the web page was hosted on a server in Sweden, and it seems likely that the court would have decided that an export occurred had the server been situated outside the EEA. Although Facebook adheres to the US Privacy Shield (see its Data Policy (see is unclear about whether information uploaded by users falls within the scope of the Privacy Shield.

49 Defined in Data Protection Directive, above n 24, Art 8 as ‘personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and … data concerning health or sex life’. See now GDPR, above n 35, Art 9, replacing the concept of sensitive data with ‘special categories of personal data’.

52 See C Reed ‘How to make bad law: lessons from cyberspace’, above n 18, at 915–916 for examples.

54 First enunciated in the Bonn Ministerial Conference Declaration of 6–8 July 1997, which declared in its principle 22:

Ministers stress that the general legal frameworks should be applied on-line as they are off-line. In view of the speed at which new technologies are developing, they will strive to frame regulations which are technology-neutral, whilst bearing in mind the need to avoid unnecessary regulation:

57 A well-documented example is the degree of aggression and casual abuse that many users of online discussion sites engage in, which they would not show in face-to-face conversations. See A Sengupta and A Chaudhuri ‘Are social networking sites a source of online harassment for teens? Evidence from survey data’, NET Institute Working Paper #08-17 (September 2008,; T Byron SaferChildren in a Digital World: Report of the Byron Review (2008) para 3.63 (

60 For an example from the UK, see Godfrey v Demon Internet Ltd [1999] 4 All ER 342, though in that case the claim was carefully drafted to apply only to publication which occurred subsequent to the defendant receiving notice of the presence of the defamatory material in a newsgroup which it hosted.

63 929 F Supp 824 at 830–838 (ED Pa, 1996), affirmed 117 S Ct 2329 (1997).

64 See eg Zeran v America Online Inc 129 F 3d 327 (4th Cir 1997). Those few cases where an intermediary was held liable had unusual facts – see eg Barnes v Yahoo!, 570 F3d 1096 (9th Cir 2009) where liability arose from breach of an oral contract to remove offending material.

65 Tyler, above n 51, at 226.

67 Ibid, at 233.

69 Ibid, at 540.

70 Ibid, at 543.

72 A DMCA notice is required to assert ‘that the complaining party has a good faith belief that the use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law’: 17 USC §512(c)(3).

73 Each minute, 400 hours of video are uploaded to YouTube –

77 Capitol Records v MP3Tunes 611 F Supp 2d 342 at 345 (SDNY 2009).

79 ‘We note, without passing judgment, that the implementation of computer algorithms appears to be a valid and good faith middle ground for processing a plethora of content while still meeting the DMCA's requirements to somehow consider fair use’: 801 F 3d 1126 at 1135 (9th Cir 2015).

80 337 F Supp 2d 1195 at 1203 ff (ND Cal 2004).

82 Thus in 2014 a stop-motion video by a child using Lego figures received a Facebook notice which gave no details at all about the rights which were allegedly infringed –

83 Ligeri v Google, Complaint CA15-188M (District of Rhode Island 2015) –

84 Murray, ALooking back at the law of the horse: why cyberlaw and the rule of law are important’ (2013) 10 SCRIPTed 310. I am delighted to acknowledge this article as the inspiration for the line of inquiry set out in this piece.

85 Ibid, at 317–319.



