In a significant and aggressive escalation of its ongoing crusade against digital piracy, Belgium has pivoted away from traditional website-blocking tactics toward a direct, hard-hitting approach aimed at unmasking the individuals behind illegal streaming and downloading hubs. Rather than playing an endless game of whack-a-mole with ever-shifting domain names, the nation’s Department for Combating Online Infringement (BAPO)—acting under the judicial authority of the French-speaking Business Court of Brussels—has issued a series of sweeping information-disclosure orders.
These new directives compel domain name registrars and registries to hand over an unprecedented volume of private user data. The targets of these legal maneuvers are operators of illicit websites, with particular emphasis on sports piracy networks threatening the financial integrity of the European sports economy. However, what makes this legal campaign extraordinary is not merely the scope of the demanded data—which ranges from traditional banking records and cryptocurrency wallet addresses to granular server connection logs—but the shroud of strict secrecy under which it operates.
Bound by comprehensive gag orders, the targeted intermediaries are legally prohibited from notifying their customers or the public. This effectively deprives targeted operators of their rights under the European Union’s Digital Services Act (DSA) to be informed when their data is compromised. As Belgium attempts to assert extraterritorial jurisdiction over European and potentially global intermediaries, the legal community is left questioning the enforceability, proportionality, and civil liberties implications of BAPO’s latest strategy.
Detailed Chronology and Legal Mechanics
From Site-Blocking Frustrations to Direct Identification
For years, Belgium’s anti-piracy framework heavily relied on reactive site-blocking decisions grounded in orders from the Brussels Business Court. While these measures occasionally yielded temporary disruptions, they suffered from an inherent structural flaw: domain hopping. Pirate networks proved exceptionally adept at quickly circumventing blocks by rapidly migrating to fresh domain names, leaving enforcement agencies constantly chasing moving targets.
Recognizing the ultimate futility of relying solely on DNS-level blocks, BAPO shifted its strategic horizon this week by issuing five newly uncovered legal decisions. Instead of targeting network access providers to block traffic, these decisions directly compel domain name registrars and a domain name registry to identify the human operators pulling the strings behind the scenes.
The legal architecture underpinning these actions stems directly from the Business Court of Brussels. Four of the newly enacted decisions target prominent domain name registrars, while a fifth focuses specifically on a top-level domain name registry that directly houses registrant records.
Uncovering the Intermediaries: Slip-Ups in Redacted Documents
While the official text of the court orders and BAPO decisions is heavily redacted—omitting the identities of the rightsholders, the specific domains targeted, and several key intermediaries—careful textual analysis of the documents reveals significant clues.
The court’s explicit reasoning points heavily toward the preservation of "the sports economy and the European solidarity model," a phrasing that universally signals a crackdown on unauthorized live sports streaming operations. Furthermore, despite rigorous redactions, administrative oversights within the published documents accidentally expose three major European-based domain registrars:
Hosting Concepts
Hostinger
Key Systems
When queried about the heavy veil of secrecy surrounding the cases, BAPO clarified to investigators that the redactions were mandated directly by the court. A representative for BAPO stated that the presiding judge "ordered the disclosure of information to enable the plaintiff to identify the infringer and conduct further investigations," while separately mandating "that the identity of the targeted content and intermediary may not be disclosed."
While a fourth domain registrar and the specific domain name registry remain entirely anonymous, the identity of the targeted domains themselves continues to be kept under wraps.
Supporting Context, Data Demands, and the Anatomy of an Information Order
The Sweeping Seven-Category Data Mandate
The four registrar decisions are remarkable for their expansive and invasive demands. Each order requires the targeted intermediaries to hand over seven distinct categories of personal and technical data, transforming standard domain registrars into de facto forensic investigators.
The required disclosures include:
Personal Identification Data: The customer’s legal name alongside every historical postal address, email address, and telephone number ever associated with the account.
Traditional Banking Details: Full International Bank Account Numbers (IBANs), the exact names of the account holders, credit and debit card details down to the specific issuing bank, country of origin, and card type.
Cryptocurrency Transaction Records: Recognizing the digital economy’s shift toward decentralized finance, the orders demand comprehensive cryptocurrency payment data. This includes specific wallet addresses used, the exact type of crypto-assets involved, and immutable transaction identifiers (hash IDs).
Account Creation Footprints: Technical logs detailing the IP address, device type, operating system, and web browser utilized by the target when initially establishing the account.
Historical Connection Logs: Twelve months’ worth of comprehensive connection data and server logs detailing every interaction the customer had with their account over the past year.
By contrast, the fifth decision—directed at the undisclosed domain name registry—is slightly more focused. It explicitly requests baseline registrant details, the identity of the registrar managing the domain, active nameservers, and a complete chronological history of any modifications made to the domain records. The Brussels Business Court concluded that these extensive demands are proportionate under European law, prompting BAPO to relay the binding directives to the respective companies.
The Gag Order and the DSA Controversy
Perhaps the most legally contentious aspect of BAPO’s new strategy is the imposition of an absolute gag order. The targeted registrars and registry are strictly forbidden from notifying their customers—or any external third parties, including the press—that their data has been subpoenaed or handed over. The prohibition covers any mention of the proceedings, the existence of the order, or related administrative matters.
This provision sits in direct tension with the European Union’s Digital Services Act (DSA). Under normal circumstances, the DSA explicitly mandates that digital service providers notify affected users when their private data is surrendered to authorities or third parties. However, BAPO relies on a narrow statutory exception embedded within the regulatory framework: provisions related to criminal investigations and prosecutions.
While BAPO has invoked this criminal exception to justify blinding the targeted operators, the precise nature of the criminal allegations underpinning the civil court orders remains ambiguous. The practical consequence, however, is absolute: pirate site operators face the silent dismantling of their anonymity, with banking histories, crypto trails, and personal connection logs funneled directly to rightsholders without a single warning.
Official Statements and Jurisdictional Ambitions
The legal backbone of BAPO’s aggressive stance relies heavily on Article 10 of the Digital Services Act, which governs how information orders apply to digital providers operating outside a domestic jurisdiction. Because all currently identified intermediaries—Hosting Concepts, Hostinger, and Key Systems—are based outside of Belgium, questions regarding cross-border enforcement are front and center.
When pressed on whether Belgian administrative and judicial bodies possess the legal authority to compel compliance from foreign EU companies, BAPO adopted an uncompromising posture. Speaking to press outlets, BAPO representatives asserted that the reach of these orders is not even strictly limited to the borders of the European Union.
According to BAPO’s interpretation of Belgian civil procedure rules combined with the DSA:
"Every intermediary whose service is being used to give access to illegal content within the Belgian territory can be ordered to disclose information regarding its customer."
This assertion represents an expansive, borderless theory of digital jurisdiction. Legal scholars note that while this interpretation makes logical sense from an enforcement perspective, it remains entirely untested on a European scale. If challenged in higher European courts, this expansive claim could trigger significant friction regarding the sovereignty of digital service providers operating under differing national jurisdictions across the EU single market.
Furthermore, because of the strict confidentiality requirements enforced by the Brussels Business Court, the public and independent journalism remain entirely in the dark. It is impossible to verify which rightsholder initiated the litigation, precisely which websites are caught in the crosshairs, or whether the foreign intermediaries have already quietly complied with the sweeping data handovers.
Future Outlook: Implications for Privacy, Piracy, and European Jurisprudence
Belgium’s latest maneuvers signal a profound evolution in how modern intellectual property enforcement is conducted across Europe. By shifting focus from fleeting web domains to the deep-seated financial rails of illegal operations—banking details, cryptocurrency wallets, and historical connection logs—rightsholders and anti-piracy agencies are targeting the lifeblood of commercial-scale piracy networks.
However, this aggressive strategy opens a Pandora’s box of legal and ethical concerns:
Erosion of Due Process: The systematic use of gag orders to bypass the notification mandates of the Digital Services Act weakens established user protections. If routine copyright enforcement can routinely leverage criminal investigation exceptions to operate in total secrecy, the foundational transparency principles of the DSA risk being hollowed out.
Extraterritorial Overreach: BAPO’s belief that Belgian courts can compel data disclosures from any global intermediary servicing Belgian internet users sets the stage for major jurisdictional clashes. If foreign registrars push back against these orders, the matter will likely be elevated to the Court of Justice of the European Union (CJEU) to establish definitive boundaries on cross-border investigative powers.
The Collateral Damage of Anonymity: While the immediate goal is the unmasking of profit-driven sports piracy rings, the broad legal precedent established by these five decisions creates a powerful template for future surveillance. The mandatory logging of IP addresses, browser fingerprints, and crypto wallet hashes creates an intrusive data trail that could easily be repurposed for other regulatory or investigative agendas.
As the dust settles on these newly revealed BAPO decisions, the immediate future remains clouded in enforced silence. Whether the targeted foreign registrars will comply voluntarily, contest the orders in court, or quietly surrender the requested files is a mystery locked behind judicial redactions. What is abundantly clear, however, is that the battlefield in the war on digital piracy has shifted permanently from the domain name system to the confidential ledgers of financial and technical intermediaries.