Italy fines Cloudflare €14.2M for refusing to block pirate sites on its 1.1.1.1 DNS service; CEO Matthew Prince says he will discuss it with US officials
Italy fined Cloudflare 14.2 million euros for refusing to block access to pirate sites on its 1.1.1.1 DNS service …
Ars TechnicaJon Brodkin
Context & Ripple Effects
European piracy enforcement has increasingly reached DNS resolvers rather than remaining an ISP-only obligation. Cloudflare had already begun blocking pirate sites in the UK, while earlier orders produced divergent responses from DNS providers, including OpenDNS’s withdrawal from France and Belgium.
The Italian penalty turns that policy conflict into a material enforcement test. Cloudflare later appealed the €14.2M fine, underscoring that the dispute concerns both compliance duties and the limits of DNS-provider responsibility.
First-order effects
Cloudflare faces a €14.2M sanction over 1.1.1.1 and must choose between maintaining its refusal, changing access controls in Italy, or pursuing legal and political challenges.
Matthew Prince’s plan to raise the issue with US officials elevates an Italian enforcement action into a cross-border policy dispute affecting a US internet provider.
Second-order effects
Other public DNS operators must reassess whether country-specific blocking, legal appeals, or market exits are the least costly response; earlier EU DNS blocking orders showed those choices can differ sharply by provider.
Rights holders and regulators gain a stronger basis to press intermediaries beyond local ISPs, while providers face added operational complexity in serving jurisdictions with different blocking rules.
Third-order effects
If penalties and blocking mandates continue to expand, DNS may become a more formally regulated access-control layer, fragmenting what users experience as a globally uniform resolution service.
The dispute may sharpen US-EU friction over whether anti-piracy measures are legitimate local enforcement or barriers to foreign digital providers, a concern Cloudflare previously raised about site-blocking as a digital trade barrier.
The trend: Anti-piracy enforcement is moving upstream from access networks toward globally operated internet infrastructure, forcing DNS providers to reconcile local mandates with cross-border service models.
Yesterday a quasi-judicial body in Italy fined @Cloudflare $17 million for failing to go along with their scheme to censor the Internet. The scheme, which even the EU has called concerning, required us within a mere 30 minutes of notification to fully censor from the Internet any…
@eastdakota @Cloudflare Mr. Prince, I'm an Italian Senator and I've read your message with great concern. AGCOM is an indipendent authority, so the fine is not a government decision but I think the decision could arise from an anti-piracy law designed to crack down on illegal sit…
More of how crazy this is: the order fining us notes that Cloudflare had just under $8 million in Italy-based revenue in 2024. But the scheme allows “up to 2% of GLOBAL REVENUE” for damages. Using global revenue is further example of the extra-judicial overreach. #absurd
@ClaudioBorghi @Cloudflare We are happy to engage in a dialogue to resolve these issues. We don't want piracy on our platform: it clogs our pipes and costs us money. We work with rights holders worldwide in cooperation yo address it. Unfortunately, Italian authorities have been u…
The DSA does not empower Trusted Flaggers to do anything special about TOS-violating content. They exist for notifying platforms about *illegal* content. Also, all Trusted Flaggers get is faster review. Platforms can and do reject their flags. They've done that a LOT, histori…
AGCOM also gets that “most unhinged” title because, I am reliably informed, they insist that DSA Trusted Flaggers can flag *legal* but TOS-violating content and get special accelerated platform review for those flags under the DSA.
To be clear, this is an ITALIAN law. It isn't EU wide, it isn't part of the DSA, it isn't even part of the filtering rules from EU level copyright law. — It sounds much, much worse than any EU-level law, and also hard to reconcile with the CJEU's Telekabel Wien ruling.
Apparently AGCOM wanted Cloudflare to filter roughly 200 *billion* daily DNS requests, using a blocklist that's full of documented errors blocking legal sites. Under a law that requires blocking within *thirty minutes*. — arstechnica.com/tech-policy/ ...
Also Italy's AGCOM, the most unhinged of the national regulators enforcing the DSA + other important laws, tried to fine Cloudflare 14.2 million Euros and @eastdakota.com is NOT having it. — This is not under DSA, it's under Italy's bonkers “Piracy Shield” law. [image]