Code of Conduct for Notice-and-Take-Down

Why a Code of Conduct for Notice-and-Take-Down?

As a provider of digital infrastructure, you need to be able to act on reports about illegal or harmful content. The Digital Services Act (DSA) and the Dutch Cybersecurity Act require providers to have a workable procedure in place for this.

The NTD Code of Conduct is part of the Code of Conduct for Abuse Prevention and describes how to set up that procedure. By signing the Code of Conduct for Abuse Prevention, you also commit to the NTD procedure. The code is co-endorsed by DCC, VvR, DINL, DDA and AAN.

What does the code of conduct contain?

The code of conduct sets concrete standards on five points:

  • A public NTD procedure
    You have a publicly accessible procedure for reports. You assess reports on legality and harm, and you inform the reporter of the outcome.
  • A step-by-step approach
    You approach the content provider first, then the host, then the registrar, and the registry last. That way you always take the least intrusive measure.
  • Timely acknowledgement
    You acknowledge receipt of a report within one working day, in line with DSA article 16(2). You inform the reporter of the outcome and of the right to appeal.
  • Trusted flaggers
    You give priority to reports from trusted flaggers (DSA article 22) and handle them with care.
  • Cooperation with specialised authorities
    You cooperate with Offlimits for CSAM and with ATKM for terrorist content.

The step-by-step approach

A fixed escalation order applies to an NTD report. You always start with the least intrusive step and escalate only if the previous step does not produce the desired result.

1

Content provider

The party that posts the content. You contact the content provider first. This is always the least intrusive step.

2

Host

If the content provider does not respond, or does not respond adequately, you approach the host of the content.

3

Registrar

If the host does not respond either, you involve the registrar. This is the party that registered the domain name.

4

Registry

The final and most intrusive step. You approach the registry only if all previous steps have produced no result.