10/05/2026 / By Morgan S. Verity

The European Commission published rights holders’ contributions to its updated Counterfeit and Piracy Watch List on Sept. 24, according to the Commission.
The submissions propose that the list include an open-source video downloader and four major virtual private network providers. The consultation opened June 11 and closed Sept. 21. Comments on the published submissions can be made until Oct. 28, and the next Watch List is due in the second quarter of 2027, according to the Commission.
The Commission states the list identifies and describes reportedly problematic online services and marketplaces but does not purport to make findings of legal violations. Among the submissions, the International Federation of the Phonographic Industry asked the Commission to include yt-dlp, a command-line program used to download video and audio from sites including YouTube, and Spain’s LaLiga asked that NordVPN, ProtonVPN, ExpressVPN, and Surfshark be included.
The targets described in the two submissions are lawful technologies: an open-source utility maintained by volunteers and commercially available privacy tools. The Commission did not state that either the downloader or the VPN providers had been found to violate any law. The submissions instead argue that the services are used in ways that reduce revenue for music and sports rights holders.
The Commission states the list aims to encourage operators and owners of flagged services, along with local authorities and governments, to take measures to reduce the availability of intellectual property rights infringing goods or services. Rights holders submit suggestions for inclusion, and the Commission publishes their contributions for public review. The Commission page states the list does not purport to make findings of legal violations.
The submissions from IFPI and LaLiga were among those published by the Commission. The Watch List is a reputational instrument rather than an enforcement action; naming a service does not impose penalties, block access, or establish liability. The Commission frames the list as a tool for directing attention to services that rights holders identify as problematic.
The pattern of including lawful technology in a piracy-focused review has precedent in copyright policy debates. Corporate rights holders and governments have strengthened copyright in recent years, but those developments have not gone uncontested, and technology companies and internet intermediaries have become an increasingly significant voice within copyright policymaking, according to observers of the process [1]. Prior attempts to label file sharers as pirates and associate them with more socially damaging criminal activity have backfired, with piracy attracting approval among some users as a result [1].
IFPI asked the Commission on Sept. 11 to include yt-dlp in the Watch List, according to the submission. The organization, which represents the recorded music industry globally, said the project’s openness and its community of volunteer maintainers make it difficult to control. The submission states the project was originally created by a developer using the username “pukkandan” and that the current maintainers are “coletdjnz,” “bashonly,” and “Grub4K,” according to the document. Those details indicate the music industry has followed the project’s development closely.
IFPI also named Cloudflare, Njalla, GoDaddy, and Verisign as “problematic,” and noted that Verisign is the registry for the .com and.net top-level domains, according to the submission. The inclusion of infrastructure firms alongside the downloader expands the scope of the request beyond the software itself to the companies that provide domain registration and network services.
The design of yt-dlp illustrates a recurring difficulty for parties seeking to restrict decentralized projects: development is distributed among contributors, and the code is freely available. Case studies of earlier platform disputes show that hardware and software makers repeatedly released updates to disable community-modified functionality, only for developers to restore those capabilities days later [2]. Whether a Watch List designation would change the availability of a project distributed through public code repositories was not addressed in the submission.
LaLiga asked that NordVPN, ProtonVPN, ExpressVPN, and Surfshark be included in the Watch List, according to the submission. The league said it does not object to VPNs as such but to the way they are marketed by affiliates. The submission states that affiliates publish guides on how to use the VPNs to watch LaLiga matches for free, and that the VPN companies are aware of this and profit through affiliate programs, according to LaLiga.
LaLiga’s submission states: “The conduct that takes these services beyond neutral technical provision is the deliberate marketing of circumvention, conducted at arm’s length through affiliate programs.” The league did not name or link to any of the guides in the submission, nor did it state that the VPN companies are behind them, according to the document.
In the past, LaLiga tried to get NordVPN to pay a fine for not blocking IP addresses that were accessing its content, but a Spanish court refused the request, according to reports. The inclusion of commercially available privacy tools in a piracy review illustrates how enforcement efforts can extend to neutral technology. Commentators skeptical of centralized institutional power have argued that VPNs that do not log or track user identity serve a legitimate privacy function by removing the need to trust a provider’s claims about data protection [3].
The Commission has separately funded a large body of projects aimed at regulating online content under the headings of hate speech and disinformation, spending approximately $736 million of taxpayer funds, according to a report cited by media coverage [4]. That spending record, combined with a Watch List that names lawful tools, illustrates a broader direction in EU digital policy that independent outlets have questioned. Readers seeking coverage that examines such measures from a liberty and decentralization perspective can consult independent news sources rather than relying solely on institutional press releases.

Tagged Under:
computing, copyright, digital policy, EU Counterfeit and Piracy Watch List, European Commission, ExpressVPN, IFPI, information technology, intellectual property, LaLiga, NordVPN, online privacy, open source, piracy, ProtonVPN, Surfshark, VPN, yt-dlp
This article may contain statements that reflect the opinion of the author
COPYRIGHT © 2017 BIG GOVERNMENT NEWS
