WebGroup Czech Republic & Coyote System v. France — CJEU (Grand Chamber) interprets e-Commerce Directive limits on French age-verification mandate and road-check alert ban

Case
Joined Cases C-188/24 and C-190/24, WebGroup Czech Republic, a.s. and NKL Associates s.r.o. v Ministre de la Culture and Premier ministre; Coyote System v Ministre de l’Intérieur et des Outre-mer and Premier ministre
Court
Court of Justice of the European Union, Grand Chamber (European Union)
Judge
I. Ziemele (Council of the European Union (by common accord of the governments of the EU Member States), 2020)
Date Decided
16 June 2026
Citation
ECLI:EU:C:2026:492
Topics
e-Commerce Directive, Age Verification, Country-of-Origin Principle, Minor Protection
Source
Read the full opinion

Background

These joined preliminary references were submitted by the French Conseil d’État in March 2024. Case C-188/24 involves WebGroup Czech Republic, a.s. and NKL Associates s.r.o., two Czech-established operators of pornographic websites, who challenged the legality of French Decree No 2021-1306, which implements Article 23 of Law No 2020-936. That provision directs ARCOM (France’s audiovisual and digital regulator) to issue formal notices to online service providers who allow minors to access pornographic content in breach of Article 227-24 of the French Criminal Code. The decree requires providers to put in place a technically reliable age-verification system; failure to comply within fifteen days can lead to judicial blocking orders or compulsory de-referencing from search engines. Critically, the applicants are established in the Czech Republic and contend that applying French law to their services constitutes a prohibited restriction on the free movement of information society services under Article 3(2) of Directive 2000/31/EC (the e-Commerce Directive).

Case C-190/24 involves Coyote System, operator of a GPS-assisted driving and navigation app, which challenged Decree provisions implementing Article L. 130-11 of the French Road Traffic Code. That article empowers French administrative authorities to order electronic driving assistance and geolocation navigation service providers to suppress, within a radius of two to ten kilometres for a maximum of two to twelve hours, the rebroadcasting of user-generated alerts about certain roadside checks — including drink-driving checks under Articles L. 234-9 and L. 235-2 of the Road Traffic Code, checks for persons wanted on serious criminal charges, and related law-enforcement operations. Coyote argued that this prohibition falls within the “coordinated field” governed by the e-Commerce Directive and unlawfully restricts cross-border information society services.

Both disputes raised the central question of whether the French national measures fall within the “coordinated field” as defined by Article 2(h) of Directive 2000/31 and, if so, whether they constitute justified derogations from the country-of-origin principle under Article 3(4), or are otherwise excluded from the directive’s scope. The referring court also asked the CJEU to consider Articles 1 (human dignity) and 24 (rights of the child) of the Charter of Fundamental Rights, as well as the interaction of the French age-verification obligation with Articles 14 (hosting liability) and 15 (no general monitoring obligation) of the directive.

The Court’s Holding

The Grand Chamber interpreted the scope of the “coordinated field” under Article 2(h) of Directive 2000/31 in relation to both categories of national measure. Requirements that directly regulate the pursuit of an information society service — such as mandating that a provider implement specific access controls or suppress certain content visible to users — fall within the coordinated field because they concern the behaviour of the service provider and the quality or content of the service. Accordingly, French measures of the kind at issue in both cases prima facie trigger the country-of-origin constraint of Article 3(2), which prohibits Member States from restricting information society services originating in another Member State for reasons falling within that coordinated field.

On the derogation question in C-188/24, the Court examined whether the French age-verification obligation satisfies the conditions of Article 3(4): necessity for a recognised objective, targeting a specific service presenting a risk to that objective, and proportionality. The Court acknowledged that protecting minors from pornographic content engages both the public-policy ground expressly listed in Article 3(4)(a)(i) — which explicitly references the protection of minors — and the values enshrined in Articles 1 and 24 of the Charter, including human dignity and the obligation to treat the best interests of the child as a primary consideration. Where a Member State can demonstrate that a provider’s service permits minors to access such content and that an age-verification requirement is proportionate, it may apply that requirement as a permitted derogation, provided the procedural notification conditions of Article 3(4)(b) are met. The Court further clarified that an obligation to implement a reliable age-verification mechanism is not equivalent to a general monitoring obligation prohibited by Article 15, since it targets the conditions of access rather than requiring proactive surveillance of all content transmitted.

In C-190/24, the Court addressed whether a time- and geography-limited prohibition on rebroadcasting user alerts about law-enforcement roadside checks constitutes a restriction on information society services within the coordinated field. The Court’s analysis centred on whether such a measure regulates the pursuit of the service’s activity or instead operates as a law of general application concerning public security and law enforcement — a matter that Article 3(4)(a)(i) also lists as a recognised derogation ground. The prohibition on suppressing alerts that enable users to evade specific law-enforcement checks was assessed in light of proportionality constraints, including the strict spatial and temporal limits Parliament had imposed in Article L. 130-11.

Key Takeaways

  • National age-verification mandates for pornographic online services fall within the “coordinated field” of Directive 2000/31 but may qualify as permitted derogations from the country-of-origin principle where they are necessary and proportionate to protect minors, consistent with Articles 1 and 24 of the Charter.
  • An obligation to deploy a reliable age-verification mechanism is not a “general monitoring obligation” within the meaning of Article 15 of the e-Commerce Directive; it conditions access rather than requiring content surveillance.
  • A geographically and temporally bounded prohibition on navigation-app operators rebroadcasting user alerts about specific law-enforcement roadside checks may constitute a justified derogation on public-security or public-policy grounds under Article 3(4), provided the procedural requirements of notification and proportionality are observed.
  • The explicit listing of minor protection and law enforcement in Article 3(4)(a)(i) provides a concrete basis for Member States to impose targeted obligations on cross-border information society service providers, even when those providers are established in another Member State.

Why It Matters

This Grand Chamber ruling clarifies the outer boundaries of the e-Commerce Directive’s country-of-origin principle in two practically significant contexts. For the online content industry, the judgment confirms that Member States retain meaningful regulatory power to impose age-gating obligations on foreign-established platforms that actively serve their residents with age-restricted material — a question of acute importance as national age-verification laws have proliferated across the EU in response to pressure over minors’ exposure to pornography. By distinguishing such targeted access controls from forbidden general monitoring obligations, the Court provides a workable framework for legislators and regulators drafting compliant enforcement regimes.

The Coyote strand of the judgment has broader implications for location-based and user-generated-content services. It signals that Member States may, within defined limits, require navigation and driving-assistance platforms to suppress certain user-reported alerts when public security objectives are at stake — without that automatically constituting an unlawful restriction on digital services. Together, the two rulings underscore that the internal-market principle in Directive 2000/31 is not absolute and that the Charter’s fundamental rights framework, particularly the protection of minors and human dignity, can supply the justification needed for proportionate national derogations.

✉️ Get tomorrow’s cases before your first coffee
Daily Case Law is our free morning digest — the most substantive new decisions, filtered to your jurisdictions and topics, each linking back here for the full analysis.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top