Over the past two years, Belgium’s anti-piracy blocklist has grown past 1,500 domains. This week the government’s anti-piracy department expanded its effort, ordering domain registrars and a registry to hand over names, bank accounts, crypto wallets and connection logs linked to pirate site operators. The intermediaries are not allowed to inform their customers about these efforts.
Belgium’s Department for Combating Online Infringement (BAPO) regularly issues site blocking decisions, which are grounded in orders from the Brussels Business court.
These blocking efforts yield some results but pirate sites often switch domain names quickly, frustrating the enforcement efforts.
With a series of new decisions issued this week, Belgium’s anti-piracy department is trying to tackle the piracy problem more directly. Instead of blocking the sites, they compel domain name registrars to identify the associated operators.
Domain Registrars and a Registry
As with the blocking effort, the five decisions are linked to an order from the French-speaking Business Court of Brussels. Four decisions are addressed to domain registrars, while the fifth targets a domain name registry that holds registrant records directly.
The order and the decisions are redacted and don’t mention the rightsholder or the targeted websites.
That said, the court’s reasoning refers to the need to preserve “the sports economy and the European solidarity model”, which clearly points at sports piracy. And there are more tells that allow us to name several of the targeted intermediaries.
BAPO told TorrentFreak the secrecy is not its own choice but the court’s. The judge “ordered the disclosure of information to enable the plaintiff to identify the infringer and conduct further investigations,” it said, and separately “ordered that the identity of the targeted content and intermediary may not be disclosed.”
BAPO did not say whether the domain names would be identified later, but three intermediaries are accidentally mentioned by name. One decision instructs Hosting Concepts to send the requested information to BAPO, another sets a deadline for Hostinger, while a third does the same for Key Systems. Every other mention in those documents is replaced with placeholders.
These are all EU-based domain registrars. The fourth registrar and the domain name registry are not named. The same is true for the domain names that are targeted.
Bank Details, Crypto Wallets, and Server Logs
The four registrar decisions each demand the same seven categories of information. This includes a long list of data that should be handed over, including the customer’s name, every postal address, email address and phone number ever attached to the account.
The intermediaries are also compelled to disclose “the full IBANs and the exact names of the holder(s) of the relevant bank accounts”, and card details down to the issuing bank, country of issue and card type.
Payments in cryptocurrency are covered too. The orders cover any “means of payment in crypto-assets, where applicable, including in particular the wallet addresses used, the type of crypto-asset concerned, and the transaction identifiers (hash IDs)”.

The registrars also have to check their logs for the target’s IP address, device type, operating system and browser used to create the account, followed by “all logs and connection data retained by the relevant intermediary relating to the use of the customer account over the last twelve (12) months”.

The domain registry decision is more narrow, requesting registrant details, the identity of the registrar, the nameservers in use, and the history of changes. The Brussels Business court concluded that these demands are proportionate and BAPO has relayed these to the intermediaries.
Gag Order
The decisions come with a gag order. The domain registrars and registry are not allowed to disclose the information-seeking request to their customers or any third parties, including the press.
That order covers “any information concerning the very existence of these proceedings or of the order, or of any matter connected with the proceedings”.
The EU’s Digital Services Act (DSA) normally requires a provider to inform affected users that their data has been handed over. However, BAPO notes that there is an exception when criminal investigation and prosecution are at stake, which it believes applies here.

What the criminal allegations are isn’t immediately clear. However, the order effectively means that the pirate site operators can have their identity, banking history and connection logs handed over to rightsholders without their knowledge.
Can it be Enforced?
The decisions rely on Article 10 of the DSA, which covers how an information order applies to a provider elsewhere in the EU. BAPO’s actual powers come from Belgian law, and all the named intermediaries sit outside Belgium, so whether it can enforce the measures against them has yet to be seen.
BAPO went further, telling TorrentFreak the orders aren’t even limited to the EU. Under the Belgian civil procedure and the DSA, it said, “every intermediary whose service is being used to give access to illegal content within the Belgian territory can be ordered to disclose information regarding its customer.”
That is a broad claim and has to be tested in practice.
Unfortunately, the press and the public at large are left in the dark, as it remains a mystery who requested the order, who it targets, and which other intermediaries it applies to.
Whether any of the intermediaries have complied yet is unknown and, given the gag order, they are not likely to let anyone know.
—
Copies of BAPO’s five decisions are available here (pdf), here (pdf), here (pdf), here (pdf) and here (pdf).
Source:
TorrentFreak.com

Be the first to comment