Code of Conduct for Notice-and-Take-Down

Why a Code of Conduct for Notice-and-Take-Down?

As a provider of digital infrastructure, you need to be able to act on reports about illegal content. Article 16 of the Digital Services Act (DSA) requires providers of hosting services to have a workable procedure for this.

The NTD Code of Conduct works together with the Code of Conduct for Abuse Prevention and describes how to set up that procedure. By signing the Code of Conduct for Abuse Prevention, you also commit to using it.

Both codes were drawn up by DINL, Dutch Cloud Community, NBIP and the Vereniging van Registrars (VvR). The NTD code is endorsed by twelve organizations: the Anti Abuse Netwerk (AAN), the Tax Administration, the Dutch Data Center Association, ECP, Internet Society Netherlands, the Ministry of the Interior and Kingdom Relations, the Ministry of Economic Affairs and Climate Policy, NL Digital, Offlimits, the Public Prosecution Service, SIDN and Stichting BREIN.

What does the code of conduct contain?

The code of conduct sets concrete standards on four points:

  • A public NTD procedure
    You have a publicly accessible procedure for reports, and a report contains what Article 16(2) of the DSA asks for.
  • A step-by-step approach
    A report is addressed step by step: the content provider first, then the hosting provider, then other intermediaries such as registrars or access providers, and the registry last. As a hosting provider you are the second link. You ask notifiers to explain why they are turning to you and which steps they have already taken, and you always take the least intrusive measure yourself.
  • Fixed deadlines
    You acknowledge receipt within one working day and assess the report within one working day, or within five if you explain why you need longer. If the content is manifestly unlawful or criminal, you remove it within one working day.
  • An addendum for child sexual abuse material
    Under the addendum with Offlimits you act on a report within 24 hours, and you do not assess the material yourself.

The step-by-step approach

A report should not land straight away with the most intrusive party. The code of conduct asks notifiers to work down the chain, and to move on only when an earlier link does not respond or responds inadequately. That follows the principle of proportionality and limits the risk of unintended removal.

1

Content provider

The party that posts the content. The notifier contacts them first, because that is the least intrusive step.

2

Host

If the content provider does not respond or responds inadequately, the report reaches the hosting provider. That is where you sit as a signatory, and you handle the report under your own NTD procedure.

3

Registrar

If that produces no result either, other intermediaries come into play, such as the registrar of the domain name or the access provider.

4

Registry

The final and most intrusive step, only when none of the previous links has produced a result.