Ter­ror­ist Con­tent On­line

The internet must not be misused for radicalisation, recruitment or incitement to violence. Companies offering hosting services in the EU must therefore remove terrorist content within one hour of receiving a removal order from the national authorities.

The Bundeskriminalamt and the Bundesnetzagentur are jointly responsible for implementing the relevant EU Regulation on addressing the dissemination of terrorist content online.

Regulation (EU) 2021/784 on addressing the dissemination of terrorist content online ("Terrorist Content Online Regulation", in short: TCO Regulation) entered into force on 7 June 2021. Its provisions have been applicable since 7 June 2022. The Regulation lays down uniform rules to address the misuse of hosting services for the dissemination to the public of terrorist content online.

The provisions apply to companies offering hosting services in the EU, irrespective of whether or not their main establishment is located in an EU Member State.

Authorities which have become aware of the publication of terrorist content online will issue an order requiring the content to be removed and/or access to the content to be disabled. Providers must comply with the order within one hour of receipt. Providers failing to comply with an order and systematically and persistently failing to comply with the provisions may be liable to a penalty of up to 4% of their global turnover of the preceding business year.

Competences

The responsibilities and tasks of the competent authorities in Germany are set out in the Act addressing terrorist content online (TerrOIBG, in German).

Bundeskriminalamt

The Bundeskriminalamt (BKA) is responsible for issuing orders requiring the removal of terrorist content and for scrutinising compliance with these orders. The dissemination of terrorist content counts as a criminal offence, which is why only the BKA – and not the Bundesnetzagentur – can order the removal of the content.

Bundesnetzagentur

The Bundesnetzagentur is responsible for:

  • Overseeing the implementation of specific measures
    (pursuant to Article 5 of the TCO)

If a hosting service is repeatedly exposed to terrorist content, the provider must take specific measures to protect the service against terrorist content. Providers can essentially decide which specific measures to take, but they must act in a proportionate and non-discriminatory manner and take particular account of the fundamental rights of the users and the freedom of expression and information. This avoids the removal of legal content. The Bundesnetzagentur checks the measures taken and requests any necessary additional measures.

In order to make proportionate decisions, the Bundesnetzagentur has commissioned a study on specific measures. It provides a basic understanding of the possible and appropriate content moderation measures that a hosting service provider can take to counter the dissemination of illegal and, in particular, terrorist content via its service.

  • Imposing penalties
    (pursuant to Article 18 of the TCO Regulation/Section 6 TerrOIBG)

The Bundesnetzagentur can impose fines of up to €5mn in regulatory offence proceedings on providers failing to comply with their obligations. Legal entities with an annual turnover of more than €125mn can even be fined up to 4% of their global turnover of the preceding business year.

Designation of a legal representative

(Article 17 of the TCO Regulation)

Hosting service providers which do not have their main establishment in the EU but offer services in the EU must designate a legal representative in the EU. The legal representative is responsible for receiving, complying with and implementing decisions from authorities. If a provider's legal representative resides in Germany, notification of the designation must be sent immediately to the following E-mail adress tco@bnetza.de

Transparency reports

The information according to Article 8 TCO Regulation is available here:

Questions and answers

Aims and parties involved

What are the Terrorist Content Online Regulation and Terrorist Content Online Act about?

The EU adopted Regulation (EU) 2021/784 on addressing the dissemination of terrorist content online (Terrorist Content Online Regulation) to tackle the misuse of hosting services for the dissemination of terrorist content online. The aims of the Regulation are to:

  • address the misuse of hosting services for the dissemination of terrorist content online;
  • ensure the prompt removal of terrorist content online;
  • prevent radicalisation.

The Regulation has been applicable since 7 June 2022.

Germany's Terrorist Content Online Act (TerrOIBG) implements the Regulation, setting out the national responsibilities and the rules for financial penalties for infringements of the Regulation. The Act designates the Bundeskriminalamt, the state media authorities and the Bundesnetzagentur as the competent authorities.

Useful links:

Terrorist Content Online Act: Terroristische-Online-Inhalte-Bekämpfungs-Gesetz (TerrOIBG) (in German)
Terrorist Content Online Regulation: Regulation (EU) 2021/784

Who are the parties involved?

  • Europol
  • Bundeskriminalamt
  • Media Authority of North Rhine-Westphalia
  • Bundesnetzagentur
  • Competent authorities in EU countries
  • Hosting service providers within the meaning of the Terrorist Content Online Regulation (“TCO hosting service providers”)

Who the Terrorist Content Online Regulation is aimed at

Do you fall under the definition of a hosting service provider?

The term “hosting service provider” within the meaning of the Terrorist Content Online Regulation means something slightly different from what the term is generally taken to mean.

The Regulation defines “hosting service provider” as a provider of services consisting of the storage of information provided by and at the request of a content provider (Article 2(1)). “Content providers” are users that have provided information that is stored and disseminated to the public by a hosting service provider (Article 2(2)).

TCO hosting service providers therefore have the following three characteristics:

  • they store information,
  • they store this information at the request of a content provider,
  • they enable this information to be made available to the public.

The following chart illustrates the characteristics:

Characteristics of hosting service provider

Terms and definitions

Information” means, for example, content in the form of individual files such as text, images, sound recordings, videos and live transmissions and the compilation of individual items of content into one coherent item of content such as a website (see recital 11 of the Terrorist Content Online Regulation).

Storage” is holding data in the memory of a physical or virtual server. This includes servers of third parties. TCO hosting service providers do not themselves have to operate the technical infrastructure used for storage. (Recital 13)

Dissemination to the public” means the making available of information to a potentially unlimited number of persons (Article 2(3)). It is not relevant whether the content providers or hosting service providers actually make the information available or whether the information is made available automatically. TCO hosting service providers do not have to actively do something to disseminate the content. It is sufficient for hosting service providers to enable content providers, through their services, to make content available to the public themselves. Where access to information requires registration or admittance to a group of users, information is considered to be disseminated to the public only where users seeking to access the information are automatically registered or admitted without a human decision or selection of whom to grant access. (Recital 14 first and second sentences)

At the request of the content provider” means that information is disseminated to the public at the direct request of the content provider and not at the request of a third party.

“At the request of the content provider” serves to distinguish from services that are provided at the request of third parties and that do not involve direct contact between the hosting service provider and the content provider.
“At the request of” does not require a contractual relationship within the meaning of section 662 of the German Civil Code (BGB) between the content provider and the hosting service provider. However, a contract between a hosting service provider and a content provider is a strong indication that the hosting service provider is to be regarded as a TCO hosting service provider within the meaning of the Terrorist Content Online Regulation. It is sufficient for the storage of information at the request of a content provider for TCO hosting service providers to be able to have an influence on (and possibly access to) the information stored and to store the information at the request of the content provider. This does not solely mean technical intervention by the TCO hosting service providers themselves. For instance, it is sufficient if TCO hosting service providers can completely shut off a service (for example hosting a terrorist website) or have the service shut off (for example by contractual arrangement with a third party that has technical access). It should be noted that the possibility for TCO hosting service providers to exert influence relates only to their ability to disable access to or delete public content. It is not necessary for them to be able to edit or modify content. (By inference from Article 3(1) and (3) and Article 5(2)(a).)

Examples

The following providers are generally considered to be hosting service providers within the meaning of the Terrorist Content Online Regulation because their services enable users to store content with the hosting service provider and make the content available to the public through the services. The list includes those mentioned in recitals 13 and 14.

  • Providers of social media services
  • Providers of video, image, audio-sharing and file-sharing services
  • Providers of forums
  • Providers of gaming platforms
  • Providers of online marketplaces
  • Providers of dating sites
  • Providers of cloud infrastructure, if the services can be used to make stored information available to the public at the direct request of the content provider. For example: a direct customer of a cloud infrastructure provider is also a content provider and makes their own content available to the public through a website that runs on the cloud infrastructure provider’s infrastructure. However: recital 14 sixth sentence gives rise to exceptions (see below).

Exceptions

Providers of the following services are explicitly exempt from the scope of the Terrorist Content Online Regulation (recitals 13 and 14):

  • Interpersonal communication services as defined in Article 2(5) of Directive (EU) 2018/1972 such as:
    • providers of email services,
    • providers of private messaging services.
  • Providers of “mere conduit services”.
  • Providers of “caching services”.
  • Providers of services provided in other layers of the internet infrastructure that do not involve storage, such as:
    • registries and registrars,
    • providers of domain name systems (DNS),
    • providers of payment services,
    • providers of distributed denial of service (DdoS) protection services.
  • Providers of services, such as cloud infrastructure, if the services are provided at the request of parties other than the content providers and only indirectly benefit the latter (recital 14 fifth sentence). This means that there is a third party between the content provider and the cloud infrastructure provider that is considered to be the TCO hosting service provider on account of a service provided. The content provider does not directly use the cloud infrastructure service but uses another hosting service operated on the infrastructure to store content and make the content available to the public. For example: a direct customer of a cloud infrastructure provider does not make content available to the public itself but operates a file-sharing service for content providers, for example, on the infrastructure. The customer therefore acts solely as a TCO hosting service provider (and not as a content provider) and the cloud infrastructure provider is only indirectly involved.
Important
Classification of a provider as a TCO hosting service provider is done on a case-by-case basis. A key factor when analysing a case is whether the direct customer acts as a content provider. This means that the same service can be classified differently, depending on whether or not the customer is considered to be a content provider. A company may therefore be considered to be a TCO hosting service provider with respect to certain cases but considered to operate services that fall outside the scope of the Terrorist Content Online Regulation with respect to other cases.

Examples of possible constellations are illustrated below:

social media platform

Examples

Does company size influence classification as a TCO hosting service provider?

The size of a company (annual turnover or number of employees) does not have an influence on classification as a TCO hosting service provider.

Do hosting services that are offered free of charge fall within the scope of the Terrorist Content Online Regulation?

Services offered free of charge by hosting service providers fall within the scope of the Regulation if they are very similar to services otherwise charged for (for example by a large number of other providers in the sector) (“normally provided for remuneration” as stated in Article 1(b) first sentence of Directive (EU) 2015/1535).

What obligations do TCO hosting service providers have under the Terrorist Content Online Regulation?

The Regulation is fully applicable to TCO hosting service providers.

Under the Regulation and the Terrorist Content Online Act, TCO hosting service providers must:

  • establish a contact point for the receipt of removal orders (Article 15);
  • designate a legal representative in a Member State in which the service is offered if they do not have their main establishment in the EU (Article 17);
  • execute removal orders issued by competent authorities in the EU by the applicable deadlines (Article 3(3) and Article 4(1) and (2));
  • comply with orders issued by the Bundesnetzagentur under Article 5(4), (5) and (6);
  • report information for the administrative monitoring programme (Article 21);
  • draw up a transparency report if action under the Regulation has been or was to be taken in a given year (Article 7);
  • establish a complaint mechanism for the reinstatement of content or access to content where the removal of content or disabling of access to content as a result of a specific measure under the Regulation was unjustified (Article 10 in conjunction with Article 5);
  • inform content providers about the removal of terrorist content or disabling of access to content (Article 11);
  • inform the Bundeskriminalamt if they become aware of terrorist content involving an imminent threat to life (Article 14(5)).

What is a contact point and when does information about the contact point qualify as having been made publicly available?

Article 15 of the Terrorist Content Online Regulation requires TCO hosting service providers to designate a contact point for the receipt of removal orders by electronic means and their prompt processing.

The contact point qualifies as having been “made publicly available” in Germany when the TCO hosting service provider notifies the competent authorities (Bundeskriminalamt and Bundesnetzagentur) of an email address for the receipt of removal orders under the Regulation. The first notification should preferably be made using the online form available at the link below. The information required in the form and any changes to information already notified can alternatively be sent by email to tco@bka.bund.de and tco@bnetza.de.

Link to online form: Self-declaration for classification as indirect or hosting service provider (in german)

The contact point notified is stored by the Bundeskriminalamt at European level in Europol’s PERCI system and can be used by the relevant competent authorities in the EU to issue removal orders.

Hosting service providers can also post information about their contact point on their website.

For example:

Contact point under Regulation (EU) 2021/784 of the European Parliament and of the Council.
Email: tco-kontaktstelle@exampledomain.de.
Contact is possible in the following languages: German [English, etc].
[This email address is only intended for communications under Regulation (EU) 2021/784. No other queries will be answered.]

Which rules apply to hosting service providers that are indirectly affected?

Hosting service providers that are solely indirectly affected (recital 14 fifth sentence), that is that do not meet the above-mentioned requirements with any of their services, are not required under the Terrorist Content Online Regulation to establish a contact point for the receipt of removal orders or notify the competent authorities of the contact point.

Reporting obligations

Are you obliged to report information every year for the administrative monitoring programme?

No, only TCO hosting service providers that, in a given calendar year, have received requests from competent authorities for access to content that has been removed or access to which has been disabled and that is to be preserved (Article 6 of the Terrorist Content Online Regulation), for example for review proceedings or law enforcement purposes, or have handled complaints from content providers about the removal of content or disabling of access to content in accordance with Article 10 must report the following information to the Bundesnetzagentur at the latest by 1 March of the following year:

  1. the number of access requests issued by competent authorities regarding content stored pursuant to Article 6 of the Regulation (as per Article 21(1)(c)) in a given calendar year; and
  2. the number of complaint procedures initiated and actions taken pursuant to Article 10 (as per Article 21(1)(d)) in a given calendar year.

Reporting form: Annual notification as part of official TCO-regulation monitoring (in german)

In Germany, hosting service providers do not have to provide information if there are no cases to report, that is if they have not received any access requests from competent authorities and have not handled any complaint procedures.

What is a complaint mechanism within the meaning of Article 10 of the Terrorist Content Online Regulation?

TCO hosting service providers that take specific measures pursuant to Article 5 of the Regulation must establish an effective and accessible mechanism allowing content providers to submit a complaint concerning the removal of content or disabling of access to content.

All requests must be examined promptly. If the removal of content or disabling of access to content was unjustified, the content or access must be reinstated without undue delay. The complainant must be informed within two weeks of receipt of the complaint. If a complaint is rejected, the reasons must be given.

Do you have to draw up a transparency report every year?

No, only TCO hosting service providers that have taken specific measures to address the dissemination of terrorist content or that have been required to take measures pursuant to the Terrorist Content Online Regulation in a given calendar year are required by Article 7 of the Regulation to draw up a transparency report on those measures for that year and publish the report before 1 March of the following year.

Transparency reports must include at least the following information (Article 7(3) of the Regulation):

  • information about the TCO hosting service provider’s measures in relation to the identification and removal of or disabling of access to terrorist content;
  • information about the TCO hosting service provider’s measures to address the reappearance online of material which has previously been removed or to which access has been disabled because it was considered to be terrorist content, in particular where automated tools have been used;
  • the number of items of terrorist content removed or to which access has been disabled following removal orders or specific measures, and the number of removal orders where the content has not been removed or access to which has not been disabled pursuant to the first subparagraph of Article 3(7) and the first subparagraph of Article 3(8), together with the grounds for this;
  • the number and the outcome of complaints handled by the TCO hosting service provider in accordance with Article 10;
  • the number and the outcome of administrative or judicial review proceedings brought by the TCO hosting service provider;
  • the number of cases in which the TCO hosting service provider was required to reinstate content or access to content as a result of administrative or judicial review proceedings;
  • the number of cases in which the TCO hosting service provider reinstated content or access to content following a complaint by the content provider.

Please Note: hosting service providers must provide information even if there are no cases to report. For instance, if they have not handled any complaints in accordance with Article 10 in the reporting period, they need to report the number as zero.

You have become aware of terrorist content involving an imminent threat to life. Who do you have to inform?

If you are a TCO hosting service provider and become aware of matters/terrorist content involving an imminent threat to life, you must promptly take appropriate measures to prevent the dissemination of the content and inform the authorities responsible for the investigation and prosecution of criminal offences in the Member State concerned (in the case of Germany, the Bundeskriminalamt) (Article 14(5) of the Regulation).

A form with all the key data is available on the Bundeskriminalamt's website Notification of imminent threat to life

Please make sure that you provide as much information as possible (such as URLs, account data, media files), that the information is as accurate as possible and that you provide documentation of the terrorist content, such as screenshots. Please also provide contact details for any queries to ensure that the matter can be dealt with as quickly as possible.

Further information on the Terrorist Content Online Regulation and details of the contact point at the Bundeskriminalamt for hosting service providers are available at: Bundeskriminalamt

Bundeskriminalamt 24/7 contact point for notification of an imminent threat to life:
Email tco-threat@bka.bund.de
Tel. +49 611 55 35062

(Please make sure you state that the matter relates to Article 14(5) of the Terrorist Content Online Regulation.)

You have become aware of terrorist content not involving an imminent threat to life. Who can you inform?

If you become aware of terrorist content online not involving an imminent threat to life, please report the criminal online content to the competent police authority in the federal state where you live.

The federal states have set up special reporting portals for internet users to report criminal content: „Online-Wachen“

Please make sure that you provide as much information as possible, that the information is as accurate as possible and that you provide documentation of the content, such as screenshots. Please also provide contact details for any queries to ensure that the matter can be dealt with as quickly as possible.

Removal orders

You have received a removal order. What do you have to do?

The specified terrorist content must be removed or access to the content disabled in all EU Member States within one hour of receipt of the removal order.

The competent authority that issued the removal order and the Bundeskriminalamt must be informed when the content has been removed or access to the content has been disabled. (Article 3(3) and (6) of the Terrorist Content Online Regulation)

Please complete the template for "Feedback following removal of or disabling of access to terrorist content" set out in Annex II to the Regulation and indicate the time of the removal or disabling.

What should you do if you do not have all the necessary information to comply with the removal order or if the removal order contains "manifest" errors?

Please inform the competent authority that issued the removal order and the Bundeskriminalamt without undue delay using the template for "Information about the impossibility to execute the removal order" set out in Annex III to the Terrorist Content Online Regulation. (Article 3(8) of the Regulation).

What should you do if it is not possible for you to remove content or disable access to content?

Please complete the template for "Information about the impossibility to execute the removal order" set out in Annex III to the Terrorist Content Online Regulation. Please inform the competent authority that issued the removal order and the Bundeskriminalamt without undue delay and explain your reasons. (Article 3(7) of the Regulation)

Do you have to comply with a removal order from an authority in another country and, if so, what is the deadline?

The same applies in this case: the specified terrorist content must be removed or access to the content disabled within one hour.

Can you have a removal order from another country scrutinised?

Yes, but you first have to comply with the order and remove the content or disable access to the content.

If you receive a removal order from a competent authority in another EU Member State, you can submit a reasoned request within 48 hours of receiving the removal order for the Bundeskriminalamt to scrutinise the order.

The Bundeskriminalamt will adopt a reasoned decision within 72 hours of receiving your request as to whether or not there is an infringement of the Terrorist Content Online Regulation. (Article 4(4) of the Regulation)

Can you challenge a removal order?

Yes.

Information about redress possibilities is included in the removal order. Section G of the removal order contains information about competent bodies or courts, deadlines and procedures for challenging the removal order. This applies to both removal orders issued by the Bundeskriminalamt and to orders from authorities in other countries.

What happens if you do not comply with a removal order?

Failure by a TCO hosting service provider to comply with a removal order is a regulatory offence and is subject to a fine of up to €5mn (section 6 of the Terrorist Content Online Act).

In certain cases (hosting service providers with an annual turnover of more than €125mn) a fine of up to 4% of the global turnover of the preceding business year can be imposed for a regulatory offence that has been committed deliberately.

What do you have to do if it is not possible for you to implement a removal order?

If a TCO hosting service provider receives a removal order that is not attributable to the hosting service provider (force majeure and objectively justifiable technical or operational reasons) and that is therefore de facto impossible for the hosting service provider to execute, the hosting service provider must inform the competent authority that issued the removal order without undue delay. The hosting service provider must state why it is impossible to execute the removal order, using the template in Annex III to the Terrorist Content Online Regulation (Article 3(7)).

If a TCO hosting service provider receives a removal order that it cannot execute because it contains manifest errors or does not contain sufficient information (for example an incorrect link), the hosting service provider must inform the competent authority that issued the removal order without undue delay. The hosting service provider must request the correct and necessary information, using the template in Annex III to the Terrorist Content Online Regulation (Article 3(8)).

The deadline for implementing a removal order within one hour of receipt of the order starts to run as soon as the grounds for not being able to implement the order have ceased to exist. This means that the TCO hosting service provider does not need to fear any negative consequences from not executing the removal order on time or at all in cases where not being able to execute the order is because of one of the above-mentioned circumstances.

Referrals

What are referrals and in which cases can they be issued by whom?

Referrals are removal requests issued to hosting service providers by authorities in EU Member States or by Europol relating to specific content that is potentially terrorist content or illegal content. They enable providers to swiftly identify such content and check the content. (Recital 40 of the Terrorist Content Online Regulation)

The Bundeskriminalamt uses referrals as an additional instrument alongside removal orders. If the content notified is considered to be terrorist content online, the Bundeskriminalamt will check whether the content has been removed or access to the content has been disabled after two working days and, where necessary, will then issue a removal order under the Regulation.

Do referrals have to be implemented?

No, referrals are not a binding call for action by hosting service providers, but alert hosting service providers. The decision on whether to remove the content remains with the hosting service provider. There is no threat of negative consequences under the Terrorist Content Online Regulation if referrals are not acted upon. The content addressed by the Bundeskriminalamt is usually content that is incompatible with the provider’s terms and conditions.

You have received a referral. What should you do?

You should check the reported content and, where appropriate, take measures to remove the content or disable access to the content if the content can be considered to be illegal or terrorist content and/or the content is incompatible with the terms and conditions of your service.

Do you have to inform the content provider about the removal of content as a result of a referral, similarly to Article 11 of the Terrorist Content Online Regulation?

No. This obligation under the Regulation only applies to the implementation of removal orders.

Is there also an obligation to preserve content that has been removed or to which access has been disabled as a result of a referral, similarly to Article 6 of the Terrorist Content Online Regulation?

No. This obligation under the Regulation only applies to the implementation of removal orders.

Specific measures

Which specific measures can you take to prevent the dissemination of terrorist content?

The following downloadable table provides a non-exhaustive list of possible measures for the various provider categories with regard to what can be reasonably expected of the providers.

This serves as a starting point for providers to take their own measures. This does not mean that all the measures ticked must be taken on a cumulative basis. The TCO hosting service provider affected must itself always select the measure to be taken and adapt it to the hosting service affected. Other or different measures may also be taken that are suitable, targeted, proportionate, non-discriminatory and take the fundamental rights of the user into account while effectively curtailing the dissemination of terrorist content online.

It is incumbent on the Bundesnetzagentur to evaluate in specific individual cases whether the measures are sufficient to meet the goal within the meaning of the Terrorist Content Online Regulation. (Article 5 of the Terrorist Content Online Regulation, section 1(2) Terrorist Content Online Act)

Table of possible measures (pdf / 61 KB)

The diagram shows the interworking of the measures from the table above.

The diagram below shows the interworking of the measures from the table above.

Where can you find up-to-date information about natural or legal persons, groups and entities involved in terrorist acts (EU terrorism list)?

The following link takes you to the Decision of the Council of the European Union updating the list of persons, groups and entities covered by Common Position (CFSP) 2026/455 on the application of specific measures to combat terrorism.

Council Decision (CFSP) 2026/455 of 26 February 2026 on restrictive measures to combat terrorism

Which points are important when drawing up a report within the meaning of Article 5(5) of the Terrorist Content Online Regulation?

Please send any questions or complaints about terrorist content online to the e-mail address given below.
Mastodon