One of the most discussed pieces on Hacker News in the last two weeks (700+ points) — the EU Court of Justice ruling that directly concerns everyone who uses VPNs and proxies. The Court of Justice of the European Union (CJEU) officially called VPNs a “lawful technical tool” and exonerated VPN providers from liability for users circumventing geo-blocks. For our audience, this is a rare case where the highest court in text directly legalizes what we use every day.
How it all started
The story grew out of a dispute around… Anne Frank’s diaries. Academic institutions in the Netherlands and Belgium published a free online edition of her manuscripts — but with geo-blocking, because copyright terms expire differently in different countries: in Belgium and roughly 60 countries the text is already in the public domain, while in the Netherlands some materials are protected until 2037.
The copyright holder (Anne Frank Fonds) filed a lawsuit with an interesting logic: since users from the Netherlands can access the “Belgian” version via VPN, the site is de facto distributing protected content to Dutch audiences — and the mechanism of VPN itself is partly to blame.
What exactly did the court decide
The CJEU rejected this logic and articulated several important theses:
- VPN is a lawful technical tool. VPN providers are not liable for copyright infringement when users circumvent restrictions via them.
- The ability to circumvent does not make the protection inadequate. The court stated that the possibility of circumvention “cannot, in itself and in all circumstances, be a decisive factor” for deeming protective measures inadequate.
- Liability lies with the publisher, not the tool. The publisher is expected to maintain geo-blocking at a state-of-the-art level with modern means, but not to provide impossible — absolute, impenetrable — protection. You cannot hold the tool liable just because a persistent user used circumvention technology.
In other words, the court drew a line between two things: territorial copyright rights can peacefully coexist with an unlimited Internet, and having VPN does not automatically make either the user or the provider a violator.
Why this matters to us specifically
GIG’s audience consists of people who run their own VPN nodes (Xray, sing-box, Remnawave, Marzban), share access with friends, and circumvent blocks. The CJEU decision is useful for several reasons:
- It creates a precedent in the largest jurisdiction: VPN as a class of technologies is recognized as legitimate, not a “piracy tool.”
- It shifts the burden from the tool to the person who wants to restrict something. Conceptually, it’s the same logic as in our craft: VPN is not to blame for someone’s weak geo-lock.
- For those who run community services, it provides an argument in debates about legitimacy: the mere fact that someone could bypass a restriction through your node is not a crime.
A sober assessment: what the decision DOES NOT do
It’s important not to read what you want into this.
- This is about the EU. The CJEU decision is binding for EU member states. It does not directly apply to Russia, the US, or other jurisdictions — there are their own laws and jurisprudence, up to outright bans on certain bypass technologies.
- It does not overturn copyright law. Territorial restrictions remain legal; the ruling only says that the publisher cannot shift the blame for circumvention onto VPNs.
- It concerns civil liability for copyright, not a blanket license for all actions. A VPN does not legalize what is illegal in itself (fraud, access to forbidden content, etc.).
- It does not imply a practical “we can do anything now” — it’s about clarifying boundaries of liability, not granting permission.
What to do
- Note it as an argument. If you’re discussing the legality of VPNs, this is a fresh and authoritative precedent from the EU top court (July 2026).
- Don’t extrapolate to your jurisdiction. If you’re not in the EU, consult local law; this ruling sets a direction of thought, not defense in your court.
- Keep the tool and the action separate. Legally, a VPN is clean, but that does not protect you from liability for what it’s used for.
Sources
- TechRadar: Analysis of the CJEU ruling in the Anne Frank Fonds case
- Discussion on Hacker News (700+ points)
What do you think — will the EU precedent influence VPN attitudes outside its borders, or does every jurisdiction take its own path? And do you feel a difference in the “legitimacy” of a self-hosted node versus a commercial VPN?
