TAR Lazio Upholds the Blocking Order and the Fine of Over €14 Million Imposed on Cloudflare

TAR Lazio Upholds the Blocking Order and the Fine of Over €14 Million Imposed on Cloudflare
In Judgment No. 13201 of 17 July 2026, the Regional Administrative Court for Lazio (TAR Lazio) upheld the entire framework of the Italian anti-piracy legislation, confirming AGCOM’s power to issue blocking orders against foreign service providers, the enforceability of dynamic injunctions within thirty minutes, the reliability of the Piracy Shield platform, and the causal contribution of DNS, VPN and reverse proxy services to online piracy.

The Background

By Judgment No. 13201 of 17 July 2026, the Fourth Section of TAR Lazio ruled on the merits of the proceedings brought by Cloudflare Inc. and Cloudflare Portugal challenging both the blocking order issued by the Italian Communications Authority (AGCOM) under Resolution No. 49/25/CONS pursuant to Article 2 of the Italian Anti-Piracy Law (Law No. 93 of 14 July 2023) and the penalty order (Order No. 333/25/CONS of 8 January 2026), by which the US company was fined approximately €14 million for failing to comply with the order requiring the blocking of more than 15,000 network resources used for the unlawful dissemination of live audiovisual content.

The Court declared both applications, together with the four subsequent sets of additional pleadings, to be “partly inadmissible, partly time-barred and otherwise unfounded.”

Foreign Service Providers and the Effects Doctrine

The Court first rejected the argument that jurisdiction lay exclusively with the Portuguese communications regulator, ANACOM, as the competent authority of the Member State in which Cloudflare’s European legal representative is established pursuant to Articles 13 and 56 of the Digital Services Act (DSA).

The Court distinguished between two separate issues. On the one hand, the power to issue orders aimed at preventing the dissemination of illegal content—a power which the DSA expressly leaves to national law (Recital 31 and Article 9). On the other, the supervisory powers concerning the procedural and cooperation obligations established under the Regulation itself.

Accordingly, the power to issue blocking orders derives from Article 2(3) of Law No. 93/2023, which applies to service providers—including VPN and DNS providers—“wherever resident and wherever located.”

Nor does the exercise of this power amount to an unlawful exercise of extraterritorial jurisdiction. Applying the effects doctrine, consistent with the case law of the Court of Justice of the European Union (CJEU), the Court held that the order affects only the accessibility of the unlawful content to users located in Italy, while geographically limited blocking measures constitute an appropriate and proportionate means of enforcement.

The Two-Stage Interim Procedure and Dynamic Injunctions

The Court reconstructed the two-stage structure of the interim proceedings before AGCOM.

The first stage consists of an urgent ex parte procedure, justified by the fact that the harm caused by illegal live streaming materialises during the broadcast itself. The second stage comprises an optional review procedure before AGCOM’s collegiate body, allowing full adversarial proceedings.

Dynamic injunctions generated following subsequent infringement reports—which service providers are required to implement within a maximum of thirty minutes from notification—do not constitute new autonomous administrative measures. Rather, they are merely the operational extension and technical implementation of the original blocking order.

The Court further observed that the system operates by shifting the burden of initiating adversarial proceedings onto the service provider. It was therefore incumbent upon Cloudflare to lodge an administrative challenge, irrespective of whether it had received notifications through the Piracy Shield platform, the receipt of which had become impossible as a direct consequence of the company’s “deliberate refusal to obtain accreditation.”

Cloudflare’s lack of cooperation—including its refusal to register with the platform, failure to participate in technical working groups, failure to request inclusion on the whitelist and failure to challenge the blocking order—deprived its procedural complaints of any substance and was subsequently treated as an aggravating factor for the purposes of determining the administrative penalty.

Piracy Shield and the Risk of Overblocking

The Court held that the alleged risk of overblocking remained “purely theoretical.”

Significant weight was given to the qualified forensic evidence required from reporting entities, the preventive whitelisting mechanisms protecting public, educational, healthcare and humanitarian resources, the prior validation of the Piracy Shield platform by the Italian National Cybersecurity Agency, and the platform’s automatic rejection of anomalous reports.

The factual evidence itself demonstrated that the alleged overblocking had not materialised. In particular, the platform had processed more than 119,185 blocking requests with a human error rate of only 0.0059%, while none of the resources affected by the contested order had been subject to any formal complaint.

The Burden of Proof

A central theme of the judgment concerns the allocation of the burden of proof.

Cloudflare failed to demonstrate at any stage that the blocked network resources were lawful.

Its expert report, based on investigations conducted in November 2025—approximately nine months after the blocking measures had been implemented—was considered inadequate due to its lack of temporal relevance, particularly in view of the extremely rapid rotation of domain names and IP addresses through which illegal content is disseminated.

The Court likewise declared inadmissible Cloudflare’s request for a court-appointed expert, submitted only shortly before the hearing, reiterating that expert evidence cannot serve as a means of searching for evidence or remedying a party’s failure to discharge its own evidential burden.

The Neutrality of Internet Intermediaries

The Court also rejected Cloudflare’s reliance on the principle of mere conduit neutrality.

The company was not being held liable for transmitting the infringing content itself, but rather for failing to implement the measures required by law to prevent its dissemination.

Consistently with the approach previously adopted by the Court of Milan, whose decisions the Court expressly endorsed, TAR Lazio observed that Cloudflare’ s public DNS service (1. 1.1. 1), VPN services and reverse proxy infrastructure enabled users to circumvent blocking measures imposed by AGCOM while simultaneously concealing the identity of the hosting provider

Those services therefore constituted a facilitating contribution to the unlawful transmission of protected audiovisual content, giving rise to concurrent liability within the meaning of Article 2055 of the Italian Civil Code.

Why the Judgment Matters

The judgment represents a significant milestone in two respects.

First, as regards the robustness of the Italian anti-piracy framework, it constitutes a comprehensive judicial review on the merits of the architecture established by Law No. 93/2023, confirming its validity in its entirety. The Piracy Shield platform was found to be both lawful and reliable, both in its design and in its practical operation. The requirement to implement blocking measures within thirty minutes—the cornerstone of effective protection for live broadcasts—was held to be compatible with procedural fairness, since the right to be heard is safeguarded subsequently through the review procedure, consistently with the constitutional principles long recognised by the Italian Constitutional Court under Articles 24 and 111 of the Italian Constitution. Dynamic injunctions further ensure that the rapid rotation of domain names and IP addresses cannot frustrate the effectiveness of blocking orders.

Secondly, as regards the liability of internet intermediaries, the judgment effectively closes the door on attempts to evade compliance based on foreign establishment or claims of technical neutrality. Blocking orders extend to service providers “wherever resident and wherever located.” Operators deriving commercial benefit from the infrastructure through which users access unlawful content by circumventing statutory blocking measures are subject to a heightened duty of care requiring them to implement appropriate organisational and technical arrangements—beginning with effective geo-blocking—to ensure compliance. Service providers that refuse accreditation and fail to avail themselves of the available legal remedies cannot subsequently complain of procedural deficiencies, while failure to comply with blocking orders exposes them to financial penalties calibrated to their global economic capacity and expressly intended to serve as a deterrent.

Lawyer Lorenzo Pinci

Related Posts
Newsletter

Iscriviti per ricevere i nostri aggiornamenti

* campi obbligatori