Belgium’s Department for Combating Online Infringement (BAPO) is intensifying its battle against digital piracy by moving beyond traditional website-blocking measures. While site-blocking decisions grounded in orders from the Brussels Business Court have long been a cornerstone of Belgian enforcement efforts, authorities have frequently found themselves frustrated by the persistent domain-hopping habits of pirate operators who quickly migrate to new addresses.
In a strategic shift designed to tackle the root of the problem rather than merely playing a game of digital whack-a-mole, BAPO has issued a series of new legal decisions this week. Instead of simply ordering internet service providers to block access to illicit domains, these sweeping directives compel domain name registrars to strip away the veil of anonymity and identify the individuals and entities operating the targeted platforms.
Domain Registrars and a Registry Targeted in Secrecy
Mirroring previous site-blocking initiatives, the five newly issued decisions stem directly from legal orders handed down by the French-speaking Business Court of Brussels. Four of these decisions are specifically directed at domain name registrars, while the fifth targets a domain name registry that holds registrant records directly.

Despite the broad scope of these legal maneuvers, the official documentation remains heavily redacted. The published orders omit both the identities of the rightsholders who initiated the legal actions and the specific websites targeted by the enforcement measures. Nevertheless, the court’s foundational reasoning provides clear clues regarding the nature of the operations. The text explicitly references the urgent necessity to preserve "the sports economy and the European solidarity model," pointing squarely toward the multi-million-euro ecosystem of unauthorized live sports streaming and illegal broadcasting platforms.
Furthermore, careful examination of the documents reveals the names of several key intermediaries caught up in the proceedings. BAPO explained to TorrentFreak that the pervasive secrecy surrounding the targets is a mandate imposed by the court rather than an agency choice. According to BAPO, the presiding judge explicitly "ordered the disclosure of information to enable the plaintiff to identify the infringer and conduct further investigations," while separately mandating "that the identity of the targeted content and intermediary may not be disclosed."
While BAPO officials declined to clarify whether these domain names will eventually be made public, three specific intermediaries were accidentally left unredacted in the paperwork. One decision explicitly instructs Hosting Concepts to hand over the requested user data to BAPO, another establishes a strict compliance deadline for Hostinger, and a third directs Key Systems to fulfill identical demands. Every other mention of the remaining intermediaries and target domains in those specific documents has been replaced with blacked-out placeholders or generic references.
All three named entities are prominent EU-based domain registrars. However, the identity of the fourth registrar, the domain name registry, and the exact domain names under investigation remain shrouded in complete secrecy.
Bank Details, Crypto Wallets, and Server Logs Demanded

The administrative burden placed upon the four targeted domain registrars is exceptionally heavy, with each decision demanding an identical catalog of seven distinct categories of sensitive information. The requested data encompasses a comprehensive dossier on the account holders, requiring the handover of the customer’s legal name alongside every historical postal address, email address, and phone number ever linked to the account.
Beyond basic contact details, the legal orders compel the intermediaries to disclose full International Bank Account Numbers (IBANs), the exact names of the account holders, and precise credit or debit card details down to the issuing bank, the country of origin, and the specific card type used for transactions.
Recognizing the modern financial mechanisms frequently employed by digital enterprises, the scope of the orders extends deeply into the realm of cryptocurrency. The directives mandate the exposure of any payment methods executed through crypto-assets where applicable. This includes specific wallet addresses utilized by the operators, the exact type of cryptocurrency involved, and all transaction identifiers, commonly known as hash IDs, which could potentially trace funds across blockchain ledgers.
The investigative net widens even further into technical infrastructure. Registrars are ordered to thoroughly examine their server logs to unearth the target’s original IP address, the specific device type, the operating system, and the web browser utilized when the account was originally created. This must be supplemented by "all logs and connection data retained by the relevant intermediary relating to the use of the customer account over the last twelve months."
In contrast to the exhaustive data demands levied against the registrars, the decision targeting the domain name registry is comparatively narrow. It primarily requests core registrant details, the identity of the registrar managing the domain, the specific nameservers currently in active use, and a detailed historical record of any changes made to the domain configuration. The Brussels Business Court ultimately concluded that these sweeping demands are both necessary and proportionate, prompting BAPO to officially relay the orders to the respective intermediaries.

Gag Orders and the Digital Services Act Exception
Adding a layer of profound controversy to the proceedings, the decisions are accompanied by strict gag orders. The domain registrars and the registry are legally prohibited from disclosing the existence of these information-seeking requests to their customers or to any external third parties, including members of the press.
The blanket restriction covers any information concerning the very existence of the legal proceedings, the judicial orders themselves, or any matter even remotely connected to the case. This restriction directly challenges standard data protection expectations, particularly under the European Union’s Digital Services Act (DSA). The DSA typically mandates that digital service providers promptly inform affected users whenever their personal data or account records are handed over to authorities or third parties.
However, BAPO highlights a crucial statutory exception embedded within the regulatory framework: providers are legally exempt from notification requirements when criminal investigations, public security, or the prevention and prosecution of criminal offenses are actively at stake—a threshold authorities believe has been met in this instance.
While the exact nature of the criminal allegations remains undisclosed to the public, the practical implication is stark. Operators of pirate platforms could find their real-world identities, extensive banking histories, cryptocurrency transaction trails, and historical connection logs transferred directly to private rightsholders completely behind their backs and without their knowledge.

Enforcement Challenges Across Borders
The legal foundation for these sweeping demands rests largely upon Article 10 of the European Union’s Digital Services Act, which governs how information-seeking orders apply to digital providers operating in other EU member states. Because BAPO derives its statutory powers strictly from Belgian national law, and all of the identified intermediaries are headquartered outside of Belgium, the ultimate viability of enforcing these measures across international borders remains an open question.
Undeterred by geographical boundaries, BAPO insists that its reach extends even further. Representatives told TorrentFreak that the judicial orders are not strictly confined to the borders of the European Union. Citing Belgian civil procedure codes alongside the broad provisions of the DSA, the agency argued that any intermediary whose services are utilized to grant access to illegal content within Belgian territory can theoretically be ordered to disclose customer information, regardless of where that intermediary is physically incorporated.
This assertion represents an exceptionally broad claim of extraterritorial jurisdiction that has yet to be thoroughly tested in practice or scrutinized by higher European courts. For now, the general public and the press are left entirely in the dark, unable to determine who filed the original complaint, which specific platforms are being targeted, or how many other intermediaries may have received similar confidential instructions. Whether any of the compelled companies have already complied with the directives remains unknown, and given the severity of the accompanying gag orders, those intermediaries are unlikely to break their silence anytime soon.
Leave a Reply