The European Union (EU) continues to be a major world player in the war on copyright infringement, and the next salvo is the EU’s updated Counterfeit and Piracy Watch List.
Rights holders have been busy submitting their input, and the European Commission (EC) published their contributions on September 24. Some of the suggestions are an open source tool, four major VPN companies, and several internet infrastructure firms.
The Commission says the list “will identify and describe the reportedly most problematic online services and marketplaces in order to encourage their operators and owners, as well as the responsible local authorities and governments to take the necessary actions and measures to reduce the availability of IPR infringing goods or services.”
However, the same page is at pains to explain that the list “does not purport to make findings of legal violations.” It’s not clear how the EC expects to prove that a site or service is “problematic” without establishing whether it is in fact breaking the law, but this is not the first time that the EU has tried to have its cake and eat it, too, on copyright.
The consultation opened on June 11 and closed on September 21. Those who wish to react to what has been submitted can do so until October 28, and the next Watch List is due in the second quarter of 2027.
One of the submissions came from the International Federation of the Phonographic Industry (IFPI), which represents the recorded music industry globally. On September 11, IFPI asked the EC to include yt-dlp, a command-line program used to download videos and audio from sites like YouTube, in the Watch List.
In fact, it is the openness of the project, and the fact it is maintained by a community of developers that makes it difficult to control, IFPI said in its submission. The document also reveals that the music industry has been keeping a close eye on the project’s development, and knows that it was originally created by a developer using the username “pukkandan”, and that the current maintainers are “coletdjnz”, “bashonly” and “Grub4K.”
IFPI also names several infrastructure companies as being “problematic” – Cloudflare, Njalla, GoDaddy, and Verisign.
On Verisign, IFPI notes that the company “is the registry for the .com and the .net top-level domains.”
Meanwhile, Spain’s top football league LaLiga has asked that four VPN providers – NordVPN, ProtonVPN, ExpressVPN, and Surfshark – be included in the Watch List.
The football league does not object to VPNs as such, but to the way they are marketed by affiliates. The submission says that these affiliates publish guides on how to use the VPNs to watch LaLiga matches for free, and that the VPN companies are aware of this and profit from it through their affiliate programs.
In fact, the guides are written by third parties who have affiliate deals with the VPNs, and who earn a commission when they sell subscriptions. The “guides” rank VPNs and link to their discounted offers.
LaLiga’s submission puts it this way: “The conduct that takes these services beyond neutral technical provision is the deliberate marketing of circumvention, conducted at arm’s length through affiliate programmes.”
LaLiga does not name or link to a single one of these guides, nor does it say that the VPN companies are behind them.
In the past, LaLiga tried to get NordVPN to pay a fine for not blocking IP addresses that were accessing its content, but a Spanish court refused the request.
The nature of the submissions made by IFPI and LaLiga also shows that the targets are now no longer only sites accused of piracy and their operators, but also perfectly legitimate and lawful technology and services – such as VPNs and open source software – that happen to be used in ways that cut into the profits of the entertainment and sports industries.




