Content Moderation Checklist: Policy Scope and Drafting, Notice and Appeal Design, Enforcement Records, Transparency Reporting, and Jurisdictional Overlays
By Casey Scott McKay ·
This checklist audits a content moderation programme in the order the work has to be done, which begins with the decision record rather than with the policy. A platform that cannot say what it decided and why cannot defend any policy however well drafted, and fixing the record is an engineering project with a long lead time. The checklist then covers the immunity scope that most programmes misread, the policy audit and the separation of public rules from enforcement guidance, notice generation, appeal design, account actions, the copyright queue and the other notice regimes, reviewer and vendor governance, transparency methodology, coordinated behaviour, minors, and regulatory inquiry handling. Gate items mark where work should stop.
IP and Technology > Internet | Checklist | Published 20 March 2026 - Updated 2 May 2026 | Casey Scott McKay - marksy.us
Summary. This checklist audits a content moderation programme in the order the work has to be done, which begins with the decision record rather than with the policy. A platform that cannot say what it decided and why cannot defend any policy however well drafted. It then covers the immunity scope most programmes misread, the policy audit and the separation of public rules from enforcement guidance, notice generation, appeal design, account actions, the copyright queue and the other notice regimes, reviewer and vendor governance, transparency methodology, coordinated behaviour, minors, and regulatory inquiry handling. Gate items mark where work should stop.
Keywords: moderation checklist · immunity scope · policy audit · undefined terms · enforcement guidance · decision record audit · notice generation · appeal service standard · account actions · copyright queue compliance · trusted flagger governance · reviewer agreement · transparency methodology · coordinated behaviour · minors obligations
How to use this checklist
| Phase | What it produces | Who runs it | Gate | |---|---|---|---| | 1. Record audit | The truth about what the systems retain | Counsel and engineering | Ten real records produced | | 2. Immunity scope | A written correction of the common misreading | Counsel | Product team told in writing | | 3. Policy audit | Findings ranked by enforcement volume | Counsel | Audit before any rewrite | | 4. Policy architecture | Public rules and enforcement guidance, separated | Counsel and policy | Agreement tested before publishing | | 5. Notice | Specific, generated, and retained as sent | Engineering | Rule and consequence stated | | 6. Appeals | A different reviewer, a deadline, and metrics | Operations | Overturn rates tracked | | 7. Copyright queue | Full statutory compliance, separated | Counsel | Repeat infringers actually terminated | | 8. Reviewers | Agreement measured; vendors contracted properly | Operations and counsel | Escalation path written | | 9. Transparency | Stable definitions and retained underlying data | Counsel and data | Figures reconstructable | | 10. Overlays | One process accommodating every regime | Counsel | Built for convergence, not one forum |
The matter. A platform with eighty million users, four hundred moderators split between staff and a vendor, community standards last revised three years ago, a transparency report whose categories changed twice, and regulatory inquiries opening in two jurisdictions. Nobody has asked whether the systems retain the basis for an enforcement decision or only the outcome.
Phase 1. Audit the decision record
-
[ ] Ask for the complete record of ten randomly selected enforcement actions from six months ago.
- Why. What comes back is what the platform actually has, which is invariably less than what its systems were designed to keep, and everything else in the programme depends on this answer.
-
[ ] Confirm the record contains the item as it existed at the time, since content changes and gets deleted.
-
[ ] Confirm it contains the rule applied, by version, because policies are rewritten and the question later is always what the rule said then.
-
[ ] Confirm it identifies the decision-maker specifically, human or automated, since automated decisions carry different obligations in several regimes.
-
[ ] Confirm it contains the basis — what the reviewer saw or what the classifier scored — because an outcome without a reason answers nothing.
-
[ ] Confirm it retains the notice as sent, since what the user was told is a question that arises and reconstruction from templates is unreliable.
-
[ ] Confirm it records appeals, outcomes, and any reversal with its reason.
-
[ ] Set retention deliberately, long enough for a regulatory inquiry, a litigation demand, and a user access request, and bounded enough for data minimisation. Those pull in opposite directions and someone should reconcile them explicitly.
-
[ ] [Gate] No policy rewrite begins before the record audit is complete.
Phase 2. Correct the immunity misreading
-
[ ] State the hosting half in writing: 47 U.S.C. § 230 provides that no provider or user of an interactive computer service shall be treated as the publisher or speaker of information provided by another content provider.
-
[ ] State the moderation half: the same provision protects action voluntarily taken in good faith to restrict access to material the provider considers objectionable, whether or not constitutionally protected.
-
[ ] Correct the misapprehension explicitly.
- Trap. The belief that curation converts a host into a publisher of everything it hosts is a misreading of a statute enacted to reject exactly that proposition, and platforms acting on it under-moderate for no legal benefit.
-
[ ] Identify the limits: material contribution to the alleged unlawfulness; the carve-outs for federal criminal law, intellectual property, and trafficking; the platform's own statements; and product design claims framing liability as arising from design rather than content.
-
[ ] Tell the product team in writing, since the misreading is held most firmly by people who have never read the statute and who make the design decisions.
-
[ ] [Gate] The written position exists before the moderation policy is revised.
Phase 3. Audit the existing policy set
-
[ ] Count the undefined terms. List every word in the published standards carrying an operative meaning that is not defined. In most policy sets the count exceeds twenty, and each is a source of inconsistent enforcement.
-
[ ] Find rules with no stated consequence, since a prohibition without a specified action is applied differently by every reviewer who reads it.
-
[ ] Find rules the platform cannot enforce, since aspirational language no system detects and no reviewer applies is a commitment the platform is measured against and does not meet.
-
[ ] Compare the public rules against the internal guidance side by side.
- Trap. Where the guidance permits what the rule prohibits, or prohibits what the rule permits, the divergence is the exposure — and in most platforms nobody has ever read the two documents together.
-
[ ] Check the version history. If the platform cannot produce the policy as it stood eighteen months ago, that is a finding that blocks any defence of a past decision.
-
[ ] Sample notices actually sent against the rules supposedly applied, since templates drift from policy language and the mismatch is visible to any user who compares them.
-
[ ] Test agreement on the current rules before rewriting, because the results identify which rules are broken and prevent a rewrite that fixes the ones that were working.
-
[ ] Rank findings by enforcement volume, since a defective rule applied a million times a month matters more than an elegant one applied twice.
-
[ ] [Gate] No rewrite starts before the audit findings are ranked.
Phase 4. Rebuild the policy architecture
-
[ ] Separate the public rule from the enforcement guidance. The public rule states the principle; the guidance states what a reviewer looks for, with examples on both sides of the line. The guidance is the operative document.
-
[ ] Define every operative term — harassment, hate, misinformation, coordinated behaviour, impersonation — since none carries operational meaning without one.
-
[ ] State the consequence for each rule: removal, restriction, downranking, labelling, age-gating, demonetisation, or account action.
-
[ ] Write the exceptions: newsworthiness, education, documentation, counter-speech, and satire. Every rule needs them and the exceptions are where the hardest calls live.
-
[ ] Write for the actual decision time. A reviewer handling hundreds of decisions a shift decides in seconds, so the guidance needs short tests and clear examples rather than principles.
-
[ ] Test before publishing: fifty real items, three reviewers applying the draft independently, agreement measured. Disagreement above a threshold means the rule is not written well enough to enforce.
-
[ ] Do not publish what cannot be enforced.
-
[ ] Version everything and retain the versions.
-
[ ] Confirm the terms of service are actually enforceable: clickwrap rather than browsewrap; a modification clause providing notice plus continued use rather than an unfettered right to change; and an arbitration position that accounts for AT&T Mobility LLC v. Concepcion and for mass arbitration economics.
-
[ ] [Gate] No policy publishes without defined terms, stated consequences, and tested agreement.
Phase 5. Build notice generation
-
[ ] Generate the specific rule, by version, not a category. "This violated our community standards" is inadequate under several regimes and useless to the user.
-
[ ] Explain how, not just which, which is a real engineering problem where the decision came from a classifier and is the one that has to be solved.
-
[ ] State the consequence applied, since users frequently do not know whether content was removed, restricted, or downranked.
-
[ ] State the appeal route and the deadline.
-
[ ] Handle the cases where specifics cannot be given by saying that specifics are withheld and why, rather than issuing a vague notice that reads as arbitrary.
-
[ ] Retain the notice as sent.
-
[ ] Design for translation, since a notice regime operating in forty languages is a localisation problem arriving on a statutory deadline.
-
[ ] [Gate] Notice generation ships before any commitment is made to a regulator about individualised explanation.
Automated enforcement
-
[ ] Identify every decision made without human review, at what volume, and with what consequence, since several regimes require human review where the consequence is significant and a platform that cannot answer this cannot comply with them.
-
[ ] Test classifier performance by language and register, since classifiers err systematically rather than randomly and one trained on a single linguistic register performs worse on others, producing disparate outcomes visible in aggregate and difficult to defend.
-
[ ] Distinguish hash matching from classification in policies, notices, and reports, since matching known material and assessing new material are different capabilities with different error profiles and describing them alike overstates the system.
-
[ ] Set a threshold above which a human reviews before action, and record where it sits and who set it.
-
[ ] Generate a usable explanation from the classifier output. A notice saying content violated a policy without saying how is inadequate under several regimes and useless to the user, and this is an engineering problem rather than a drafting one.
-
[ ] Measure the automated layer by appeal outcomes. A high overturn rate indicates the automation is wrong often; a low appeal volume with a high overturn rate indicates users have given up, which is worse.
-
[ ] Retain the score or signal, not just the label, since a decision recorded as "removed: policy 4.2" cannot be reviewed and a decision recorded with its basis can.
-
[ ] Re-test after every model change, and record the version of the model that made each decision alongside the version of the rule.
Phase 6. Design appeals and account actions
-
[ ] Route appeals to a different decision-maker who sees the item rather than the classification.
-
[ ] Publish a service standard and meet it, since an appeal process with no deadline becomes a queue nobody works.
-
[ ] Do not make the user guess, because an appeal against an unexplained decision is not an appeal.
-
[ ] Handle repeat appellants sensibly, since a small number of users generate a large share of appeals.
-
[ ] Track overturn rates by policy and by reviewer, which is the only reliable signal of systematic error.
-
[ ] Hold account actions to a higher standard: human review, a named reviewer, a specific statement of the basis, and a real deadline.
- Why. Account loss is a commercial catastrophe for a seller, creator, or small business in a way a post removal is not, and the response is correspondingly determined.
-
[ ] Record reinstatement decisions and their reasons, since unexplained reinstatement of some accounts and not others is the inconsistency evidence a claimant seeks.
-
[ ] Address data after termination, since a removed user may be entitled to their data and immediate deletion creates a compliance problem alongside the commercial one.
-
[ ] Screen for the adjacent claims account terminations attract — tortious interference where the account carried business relationships, unfair competition where the platform competes with the holder, and state unfair trade practice claims.
-
[ ] [Gate] No account termination proceeds without human review and a recorded basis.
The user-facing surfaces
Several artefacts sit between the programme and the people it affects, and each carries its own exposure.
-
[ ] Audit the help centre against the policy. Explanatory pages drift from the rules they explain, they are read far more than the policies themselves, and a help page describing a rule the platform no longer applies is a published inconsistency.
-
[ ] Check the reporting flow's categories against the enforcement categories, since users report into buckets that determine routing, and a reporting taxonomy that does not map to the policy taxonomy misroutes at the first step.
-
[ ] Review the in-product messaging — strikes, warnings, and status indicators — since these communicate enforcement decisions and are frequently written by product without reference to the notice requirements.
-
[ ] Confirm the appeal interface is reachable from the notice, in the same language, without an account action blocking access to it. A suspended user who cannot log in to appeal a suspension is a recurring and entirely avoidable design failure.
-
[ ] Check that status pages and account dashboards show a history the user can see, since a user who cannot see what happened to their content cannot meaningfully challenge it.
-
[ ] Test the flow end to end as a user, periodically, since nobody inside the platform experiences it and the failures are invisible from the inside.
-
[ ] Retain the user-facing text by version, alongside the policies, because what a user was told about the rules is a question that arises alongside what the rules said.
Phase 7. Separate and comply with the notice regimes
-
[ ] Keep the copyright queue separate and fully compliant. 17 U.S.C. § 512 requires a designated and published agent, a repeat infringer policy reasonably implemented, accommodation of standard technical measures, and expeditious removal on proper notice — cumulatively, with failure on any of them putting the safe harbour at risk for everything.
-
[ ] Confirm repeat infringers have actually been terminated.
- Trap. A published policy never applied is not implemented, litigation has turned on whether a platform ever terminated anyone, and the termination record is the evidence.
-
[ ] Assess notices for sufficiency, since a notice missing required elements does not trigger the obligation and acting on defective notices trains complainants to send them.
-
[ ] Handle counter-notices mechanically: forward, wait the statutory period, restore absent a court action.
-
[ ] Understand the knowledge standard from Viacom International, Inc. v. YouTube, Inc., which distinguished general awareness that infringement occurs from knowledge of specific infringing material, with wilful blindness remaining live.
-
[ ] Watch the misrepresentation exposure under 17 U.S.C. § 512(f), noting that Lenz v. Universal Music Corp. requires a rights holder to consider fair use under 17 U.S.C. § 107 before sending — an exposure a platform running notices for rights holders inherits.
-
[ ] Note what a complainant can actually do, since a registration must have issued before suit after Fourth Estate Public Benefit Corp. v. Wall-Street.com, LLC.
-
[ ] Treat trademark complaints as voluntary, with liability governed by contributory principles from Inwood Laboratories, Inc. v. Ives Laboratories, Inc. and substantive claims at 15 U.S.C. § 1114 and 15 U.S.C. § 1125.
-
[ ] Route illegal content categories to a separate compliance function, since they carry mandatory reporting and sit outside any immunity.
-
[ ] Govern trusted flagger programmes with admission criteria, accuracy monitoring, and a route to removal, because a flagger's error rate becomes the platform's.
-
[ ] Distinguish counterfeit from grey market complaints on marketplaces, since a queue treating them alike removes lawful listings and provokes counter-notices.
-
[ ] Document government referrals — what was received, from whom, and what the platform decided independently — since the line between informing and coercing is legally significant.
-
[ ] [Gate] The copyright queue is separated and audited before any general moderation redesign ships.
Phase 8. Govern reviewers and vendors
-
[ ] Measure agreement, not just throughput, by routing the same items to multiple reviewers periodically. It is the only way to know whether a policy is applied consistently and the first measurement cut when volumes rise.
-
[ ] Treat reviewer wellbeing as a legal exposure, with rotation, limits, support, and tooling that blurs or mutes by default, since repeated exposure to violent material has produced employment claims and settlements.
-
[ ] Contract properly for outsourced review: training, accuracy measurement, record retention and access, and audit rights.
- Why. The work moves to a vendor and the responsibility does not, and the platform's policies are then applied by people it does not employ, generating records it may not hold.
-
[ ] Expect internal materials to be produced. Guidance, training decks, escalation threads, and reviewer notes are what a regulator or claimant asks for, and they say what the published policy does not.
-
[ ] Write down the escalation path for hard cases, since every platform has one in practice and almost none has documented it.
-
[ ] Address language and regional coverage explicitly, since enforcement quality varies by market in ways visible in aggregate data and hard to defend.
-
[ ] [Gate] No vendor contract renews without record access and audit rights.
Phase 9. Fix the transparency methodology
-
[ ] Define every category before reporting it, and keep definitions stable, since a series whose basis changes is useless and invites the allegation that the change improved the figures.
-
[ ] Distinguish proactive from reactive action, since conflating them overstates the system's capability.
-
[ ] Report appeals honestly — volume, outcomes, and time to resolution — because a high overturn rate is embarrassing and publishing it is the only way to show the process functions.
-
[ ] Separate government requests from user reports, and distinguish legal orders from informal referrals within them.
-
[ ] Publish the methodology and understand that a published metric is a commitment the platform is measured against.
-
[ ] Anticipate mandatory reporting on statutory schemas, since a data model that does not map to one produces an engineering exercise on a deadline.
-
[ ] Retain the underlying data, since a figure that cannot be reconstructed cannot be defended when it is challenged.
-
[ ] Describe hash matching and classification differently, since matching known material and classifying new material are not the same capability.
-
[ ] [Gate] No figure publishes that cannot be reconstructed from retained data.
Phase 10. Handle the overlays, the hard categories, and the inquiry
-
[ ] Build for converging procedural obligations — individualised notice, an appeal route, retained records, and periodic reporting — rather than optimising for one jurisdiction's substantive rules.
-
[ ] Track the constitutional layer without building on it. Moody v. NetChoice, LLC addressed facial challenges to state moderation statutes, declined to resolve them on the records presented, and indicated that curation of third-party content is itself expressive activity, drawing on Miami Herald Publishing Co. v. Tornillo and Hurley v. Irish-American Gay, Lesbian & Bisexual Group of Boston.
-
[ ] Reconcile the overlays into one operational process rather than running parallel programmes per jurisdiction.
-
[ ] Handle coordinated behaviour honestly: a stated category, an acknowledgement that specifics are withheld, a genuine review path, retained analysis rather than just outcomes, and caution about public attribution to a named actor, which is a factual statement carrying defamation risk.
-
[ ] Address minors as substantive obligations, covering age assurance, design duties on defaults and recommendations, advertising and profiling restrictions, and a segmented content standard — and build for the strictest applicable regime deliberately.
-
[ ] Prepare the regulatory inquiry response: answer with the record rather than the policy, establish what the systems can produce before promising anything, disclose known problems before they are found, coordinate across jurisdictions, preserve against the ordinary retention policy, and assign one owner.
-
[ ] Write the crisis plan while nothing is happening: who decides, how the decision is separated from the communication, that existing rules are applied and named, that the record is fuller rather than thinner, and how a reversal is explained.
-
[ ] [Gate] The inquiry response owner is named and the preservation instruction issued on the day a request arrives.
Crisis handling
-
[ ] Name the decision-maker in advance. In a crisis the question of who decides is otherwise answered by whoever is loudest, and the resulting decision is made by someone with no authority to make it and no record of having done so.
-
[ ] Separate the decision from the communication, since a communications position adopted before the enforcement decision is settled commits the platform to an outcome nobody has assessed.
-
[ ] Apply existing rules and name which.
- Trap. A crisis decision that invents a rule is a decision the platform will be asked to apply consistently ever afterwards, to cases it has not imagined.
-
[ ] Record more, not less. The instinct under pressure is to decide in a call and document nothing, and the record of a crisis decision is the one most certain to be requested.
-
[ ] Expect the decision to become precedent, cited by every subsequent complainant and regulator as evidence of what the platform is capable of and willing to do.
-
[ ] Plan how a reversal is explained, since reversing without a stated reason converts an error into an allegation of inconsistency.
-
[ ] Debrief in writing afterwards: whether the rules covered the situation, whether the escalation path worked, and what should change. Most platforms handle three crises before anyone writes down what was learned from the first.
A note on order
The phases are ordered by dependency, and the ordering is the single most useful thing in this checklist because it inverts the way the work is normally commissioned.
Every platform starts with the policy. The policy is the visible artefact, the thing the regulator's letter names, and the thing a communications team can point to. It is nonetheless the wrong place to start, because a policy applied through a system that cannot say what was decided or why answers no question anyone is asking and defends no decision anyone challenges.
The record audit is first for that reason, and because it is the phase with the longest lead time. Fixing an enforcement data model is an engineering project measured in quarters, and starting it in month one means it is finished when the rest of the programme needs it.
The immunity correction is second because it is nearly free and because it unblocks decisions the product team is currently making badly. It takes an afternoon and a memorandum.
The policy audit precedes the policy rewrite because an audit produces ranked findings and a rewrite without them fixes whichever rules the drafter found irritating. Agreement testing on the current rules is the part most often skipped and the part that identifies which rules are actually broken.
Notice and appeals sit in the middle because they are what users and regulators see, because they are the common denominator across every regime, and because they can ship while the record work continues underneath.
The copyright queue is separated at Phase 7 rather than earlier only because it is usually already running; where a platform has no designated agent or has never terminated a repeat infringer, it moves to Phase 1.
Reviewer governance, transparency, and the overlays are continuous programmes rather than projects. Each needs an owner and a cadence rather than a completion date, and each degrades silently when the owner changes role.
What the programme is for
Worth stating to the client at the outset, because it changes what the programme is measured against and what the budget buys.
A platform of any scale is making millions of decisions about speech, applying rules it wrote, through processes it designed, with no external adjudication and no meaningful consent from most of the people affected. That is a governance function performed by a commercial entity whose incentives are not those of a regulator, and everyone involved knows it. No amount of procedural refinement stops the criticism, and a programme designed to stop it will fail on its own terms.
-
[ ] Set the objective as defensibility rather than agreement. Nobody agrees with every decision. What is defensible is that the rule was published, the definition stated, the decision recorded, the user told what was applied, and a route to challenge provided. Those five things are the whole of the external defence.
-
[ ] Build for the converging procedural obligations rather than for a particular jurisdiction's substantive rules, since notice, appeal, records, and reporting appear in every regime while the substantive positions diverge and change.
-
[ ] Direct the budget to infrastructure over prose. The policy is rewritten every eighteen months; the notice system, the appeal queue, the decision record, and the reporting pipeline are what the business relies on in a decade.
-
[ ] Resist the pressure to fix individual outcomes. A function that spends its time relitigating particular decisions is a function that has stopped improving the system that produces them, and it is the system a regulator, a court, and a plaintiff all examine.
-
[ ] Confirm insurance cover reaches moderation-related claims, since media liability, technology errors and omissions, and employment practices policies each cover part of this exposure and none covers all of it.
-
[ ] Check whether the platform's own recommendation and ranking outputs are characterised as its speech in any published material, since a description adopted for one purpose is read against the platform in litigation about another.
-
[ ] Record which enforcement decisions were made at the request of a commercial partner, since advertiser and partner pressure is a real input to moderation decisions and an undocumented one is the version that surfaces badly.
- [ ] Diarise a twice-yearly review of the whole checklist. The regimes change, the product changes, the vendor changes, and the people who built the programme move on — and every one of the continuous phases degrades silently rather than failing visibly, which means nothing announces that the review is overdue.
- [ ] Confirm one person owns each continuous phase by name, and that the ownership is recorded somewhere other than in that person's head, since the transparency methodology, the reviewer agreement testing, and the overlay tracking are all abandoned within a year of a reorganisation and nobody notices until an inquiry asks.
Outcome. A platform that has run this checklist can produce the complete basis for any enforcement decision, show that its published rules and its enforcement guidance say the same thing, demonstrate that its appeal process functions by publishing its own overturn rate, and answer a regulator with records rather than with policy documents. That is what defensibility looks like in a function where nobody agrees with the outcomes and never will.
Marketplace variants
Where the content is a listing rather than a post, several phases change and a platform applying a social media framework gets it wrong in both directions.
-
[ ] Recognise that the hosting protection covers less, since intellectual property claims are carved out of 47 U.S.C. § 230 and a marketplace's exposure is largely intellectual property exposure.
-
[ ] Manage accumulating knowledge. A marketplace receiving repeated notices about the same seller and continuing to provide services is in a different position from one acting on isolated complaints, which is why the repeat-seller policy has to be applied rather than published.
-
[ ] Treat control as a design question, since fulfilment, pricing, payment, presentation, and promotion each move the platform closer to a direct liability argument, and the design decisions that improve the product increase the exposure.
-
[ ] Make seller verification the leverage point, because a platform that does not know who its sellers are removes listings while the same operator re-registers.
-
[ ] Expect product safety and regulatory duties in the same queue — recalled goods, restricted products, age-gated categories, and items requiring certification.
-
[ ] Govern brand owner programmes with criteria, accuracy monitoring, and a route to removal.
-
[ ] Handle counter-notices with more care than on a social platform, since a wrongly removed listing is lost revenue for a business that will pursue it.
Running it as an engineering programme
-
[ ] Translate every obligation into a testable requirement. "Individualised notice" is not a requirement; a specification naming the fields, the language, and the retention is.
-
[ ] Get the data model right before it is in production, since remodelling a live enforcement system is a year of work and most compliance pain in this field originates there.
-
[ ] Put legal in the room when features are designed, because recommendation changes, engagement features, defaults for young users, and marketplace fulfilment decisions never arrive at legal as legal questions.
-
[ ] Accept staged delivery, since a notice system shipping for three categories this quarter beats a complete design that ships never, and regulators respond better to demonstrable progress than to a plan.
-
[ ] Budget the reporting pipeline separately, since transparency reporting is a data engineering exercise that is invisible until a deadline.
-
[ ] Instrument the appeal path as dashboards rather than quarterly extracts, since volume, resolution time, and overturn rate by policy and reviewer are the programme's only early warning.
-
[ ] Version the written requirements, because an obligation communicated in a meeting cannot be evidenced when an inquiry asks how it was implemented.
Key Authorities at a Glance
| Authority | What it settles | Phase | |---|---|---| | 47 U.S.C. § 230 | Hosting protection and good faith restriction protection | 2 | | Moody v. NetChoice, LLC | State moderation statutes; curation as expressive activity | 10 | | Miami Herald Publishing Co. v. Tornillo | Right-of-reply statute unconstitutional | 10 | | Hurley v. Irish-American Gay, Lesbian & Bisexual Group of Boston | Organiser may choose participants in an expressive event | 10 | | AT&T Mobility LLC v. Concepcion | Arbitration clauses and class waivers enforceable | 4 | | 17 U.S.C. § 512 | Safe harbour conditions, notice, counter-notice, misrepresentation | 7 | | Viacom International, Inc. v. YouTube, Inc. | General awareness distinguished from specific knowledge | 7 | | Lenz v. Universal Music Corp. | Fair use must be considered before sending a notice | 7 | | 17 U.S.C. § 107 | Fair use | 7 | | 17 U.S.C. § 106 | Exclusive rights | 7 | | Fourth Estate Public Benefit Corp. v. Wall-Street.com, LLC | Registration must issue before a copyright suit | 7 | | Inwood Laboratories, Inc. v. Ives Laboratories, Inc. | Contributory liability standard | 7 | | 15 U.S.C. § 1114 | Infringement of a registered mark | 7 | | 15 U.S.C. § 1125 | False designation of origin | 7 | | 15 U.S.C. § 1116 | Injunctive relief and seizure in counterfeiting | 7 |
The five things people get wrong
One: starting with the policy. The policy is the visible artefact and the thing a regulator's letter mentions, so it is where every programme begins. It is the wrong place. A beautifully drafted rule applied through a system that cannot say what was decided or why answers no question anyone is asking. The record audit takes a fortnight, produces the most alarming findings in the whole exercise, and determines whether anything else in the programme is worth doing.
Two: under-moderating out of fear of losing immunity. The statute protects good faith restriction of objectionable material expressly, and the belief that curation converts a host into a publisher is a misreading of a provision enacted to reject that proposition. Platforms nonetheless act on it, producing a worse product and no legal benefit, and the belief is held most firmly by the people making design decisions rather than by anyone who has read the section.
Three: publishing rules nobody can apply. Undefined terms, unstated consequences, and aspirational prohibitions the platform lacks the capacity to enforce. Each of them produces inconsistent enforcement, and inconsistency — not any individual wrong decision — is the exposure. The test that catches it costs a day: fifty real items, three reviewers, agreement measured.
Four: running the copyright queue as a moderation category. The framework is a statutory bargain with cumulative conditions and a forfeiture consequence, not a general immunity. The failure is almost always the same one: a published repeat infringer policy that nobody has ever applied, in a platform that cannot produce a list of accounts it terminated on that basis.
Five: promising a regulator something the systems cannot produce. The response to an inquiry is drafted by people who have not asked engineering what data exists, commits to a data set on a deadline, and delivers something different and worse two months later. Establish what can be produced first, disclose what is wrong before it is found, and answer with the record rather than with the policy.
Related Documents
Articles
- Deciding What Stays Up: Content Moderation, Platform Policy, and the Rules Nobody Voted For
- The DMCA Safe Harbor: How Section 512 Shields Platforms and Binds Rights Holders
- The Sentence That Costs You: Defamation, Publisher Risk, and the Liability That Copyright Does Not Cover
- Fair Use After Warhol: Transformative Purpose, Market Harm, and the Four Factors
Guides
- Running a Content Moderation Programme: Policy Drafting, Appeals, Transparency, and Regulatory Exposure
- Managing Defamation and Content Liability: Pre-Publication Review, Retraction, Anti-SLAPP, and Insurance
- Sending and Fighting a DMCA Takedown: Notices, Counter-Notices, and Misrepresentation Claims
- Enforcing Against Platforms, Landlords, and Service Providers: Secondary Trademark Liability
- Managing Platform Account Risk: Verification, Appeals, and Continuity
Checklists
- Platform Content Liability Checklist: Section 230 Elements, Carve-Outs, Moderation Records, and Escalation
- Content Liability Checklist: Pre-Publication Review, Source and Substantiation Records, Retraction and Correction Handling, Anti-SLAPP Assessment, and Insurance Tender
- Platform Account Risk Checklist: Ownership, Verification, Backups, and Appeal Readiness
- Fair Use Risk Assessment Checklist: Four Factors, Documentation, and Escalation
Toolkits
- Platform Liability and Section 230 Toolkit
- Marketplace and Platform Liability Toolkit: Intermediaries, Sellers, and Accounts
- Fair Use and Permissions Toolkit: Clearing Copyright, Trademark, and Publicity Rights
- Online Brand Protection Toolkit: Domains, Marketplaces, Platforms, and Search Ads
This checklist is general information about platform and internet practice, not legal advice, and it does not create a lawyer-client relationship. Marksy is not a law firm. Content moderation sits at the intersection of federal immunity, contract, constitutional law, and a rapidly changing body of state and international regulation, and the correct answer depends on the jurisdictions in which a platform operates and the nature of the service. Consult qualified counsel before acting.