Position papers

Against Hate Speech and Bot Networks

Background and Issues

The digital landscape is increasingly marked by hate speech, disinformation, and massive bot attacks that threaten democratic discourse. Insults, threats, and the targeted spread of fake news are commonplace on platforms such as Facebook, X, TikTok, and YouTube. Many of these attacks are carried out under the guise of supposed anonymity or by automated bot accounts.

At the same time, there are security challenges posed by criminal groups’ use of encrypted communications and by the sharp rise in cyberattacks.

Policymakers face the dilemma of having to, at the same time:

  • to protect freedom of speech,
  • to strengthen digital security,
  • and to enable measures against digital crime that can be enforced in accordance with the rule of law.

On the one hand, there is a legitimate need to take effective action against digital threats. On the other hand, freedom of expression, data protection, and the openness of the Internet must continue to be safeguarded.

To this end, FOKUS would like to bring the following proposals into the discussion.

An EU-wide process for digital identity verification

FOKUS proposes the introduction of a Europe-wide system for digital identity and age verification, based on the upcoming eIDAS 2.0 standard and the Digital Identity Wallet. Such a system would allow users to verify their identity and age with social networks once, in a data-minimal waywithout the platform itself gaining access to sensitive identification data.

How it works:

  • Verification is carried out by a government-certified trust authority that does not itself collect or store any data beyond what is necessary for the purpose of identity verification and that does not provide any means for mass surveillance.
  • The platform only receives confirmation of a user’s identity and age, but not their actual name, place of residence, or other personal information.
  • Users can continue to post under a pseudonym —but accountability for content that is relevant under criminal law remains in place.
  • This makes it much more difficult to create bot accounts and carry out mass registrations without real identities.

Why this makes sense:

  • Curbing Hate Speech
  • In the digital space, the perceived anonymity often lowers the threshold for insults and hate speech. A verified but pseudonymous system raises this threshold, as users are aware that their real identity could be traced if they cross criminal boundaries. This fosters a culture of digital responsibility and helps improve the tone of online discussions without restricting freedom of expression.
  • Stop Bots and Fake Profiles
  • The technical hurdle of identity verification reduces the effectiveness of bot networks. Platforms could prioritize the visibility of verified content.
  • Protect Privacy
  • Unlike a system that requires users to upload identification documents, this system offers the highest possible level of data security. No platform stores any identity information, making misuse virtually impossible.
  • Protect Freedom of Speech
  • The pseudonym remains in place. Only in cases involving content relevant to criminal law could investigative authorities request the user’s real identity from the certification authority via a court order.
  • These improvements create a more trustworthy and pleasant online environment for all users by shifting the focus away from toxic disputes and back toward constructive dialogue.

What demands this entails:

FOKUS is advocating at the national and European levels for the introduction of mandatory certification when opening social media accounts through a European certification authority.

  • As a result, the provider receives an identification token that confirms the person’s existence and age, but does not disclose the user’s identity or any other personal data to the provider.
  • Only the certification authority can link this token to a specific person, and it may do so only pursuant to a court order.

In addition to enabling the unique identification of social media users, an EU-wide standard for data protection-compliant identity verification also provides a process that allows other platforms (such as banks or government agencies) to use a solution for identity verification —across the EU and for all EU citizens.

And the best part is that this isn’t some far-fetched, theoretical vision of the future —it’s reality. All the specifications for this certification authority are already in place. The system is called eIDAS, and an initial version (which, however, is insufficient for the proposals here) has been in existence since 2016. With eIDAS 2.0 and the Digital Identity Wallet, it is expected that starting in 2027, it will be possible to implement digital identity verification on social networks voluntarily, in a data-minimal and secure manner—without a real-name requirement or surveillance risks.

While the eIDAS 2.0 wallet enables voluntary, data-minimal verification, FOKUS advocates for the mandatory use of this technology when opening new accounts on social networks. This is necessary because voluntary participation alone would not be sufficient to effectively combat bot networks or to raise the threshold for hate speech across the board. Requiring a verified identity for new registrations creates the structural change needed for a safer Internet, while allowing users to remain anonymous ensures freedom of speech.

With the eIDAS wallet and its associated interfaces, social media verification can be implemented securely, anonymously, and in a privacy-friendly manner in the near future. This offers advantages for providers, who do not have to set up their own verification systems but can instead rely on a government-certified infrastructure. Above all, however, it offers enormous advantages for users, who will not have to verify their identities with data-collecting tech giants like META, Apple, Google, or TikTok, but can instead trust a government-certified organization.

Access to IT Data Under the Rule of Law in Accordance with Fundamental Rights

Background & Current Security Policy Context

The EU is currently planning extensive measures to enable law enforcement agencies to have more meaningful and legally compliant access to digital data. This is part of the ProtectEU initiative within the framework of the EU’s internal security strategy. The aim is to combat terrorism, organized crime, online fraud, child pornography, cyber ransomware , and similar threats more effectively – because around 85 % of all investigations today rely on electronic evidence ( home-affairs.ec.europa.eu ).

Key Elements of the Roadmap of June 24, 2025

  • Data Retention & Access: Modernizing EU Data Retention Requirements and Strengthening Cooperation with Providers
  • Lawful Surveillance: Improving Cross-Border Cooperation for the Lawful Interception of Data Between Government Agencies and Service Providers
  • Digital Forensics & Decryption: Expanding Technical and Legal Capabilities for the Analysis and Preservation of Digital Evidence Stored on Electronic Devices
  • Standardization & Interoperability: EU-wide Technical Standards with Industry Partners (utimaco.com)
  • Cross-Border Investigative Tools: In addition to the e-Evidence Regulation, the European Investigation Order (EIO) is an EU-wide mechanism that enables law enforcement authorities to carry out court-authorized investigative measures—such as searches of premises, interrogations, or orders to preserve evidence— across borders and in accordance with the rule of law.

The approach to digital identity verification proposed by FOKUS fits seamlessly into these EU efforts by offering a path to digital accountability that is consistent with fundamental rights, thereby supporting the roadmap’s goals without jeopardizing digital freedom.

The Tension Between Internal Security and Data Protection

The EU strategy aims to grant law enforcement agencies expedited access to digital data as part of the fight against crime. Data privacy advocates, however, warn of backdoor mass surveillance and an erosion of encryption security.

The implementation of the verification model proposed in the proposal can help resolve this conflict. This is because an eIDAS-based solution enables secure identity verification without the automatic transfer of sensitive personal data. This makes automated, mass access to personal data impossible, while preserving the possibility of individual access following a court order.

Such a system therefore ensures that judicial oversight is maintained when accessing private digital communications, that such access is transparent and traceable, and that it leaves open the possibility for those affected to challenge the access through legal channels.

FOKUS welcomes these efforts because we want a digital Europe with backbone and an open, free, and fair Internet —one that must not, however, be defenseless against contempt, hatred, and organized manipulation. The protection of democracy and human dignity does not end at digital borders. With a smart, data-efficient identity verification system, we can lay the groundwork for digital responsibility without sacrificing the freedom that has made the internet great.

FOKUS’s proposed solution offers a privacy-friendly way to establish identity-based accountability—without the far-reaching risks associated with automated, mass access rights.

Our approach:

  • complements ongoing EU efforts in the area of internal security,
  • strengthens digital law enforcement,
  • safeguards fundamental rights to encryption,
  • and ensures that oversight, transparency, and the rule of law are always upheld.

Encryption must not be sacrificed

Another key issue in the security debate is access to encrypted communications in messaging services such as Signal, WhatsApp, and Threema.

FOKUS strongly warns against hasty political decisions in this regard, noting that laws require “backdoors” that would erode trust to a tremendous extent and would also be counterproductive from a security policy perspective.

This is simply because highly complex and virtually unbreakable encryption algorithms such as AES, RSA, or ECC—as well as the protocols used by messaging apps like Signal—are publicly documented and freely available. Even groups with little technical expertise can build their own encryption tools at any time (and they do—EncroChat, Sky ECC, and Anom are examples of encrypted communication platforms used by organized crime that were compromised through infiltration).

Legally mandated “backdoors” in popular messaging apps would therefore not do much harm to criminals, but would instead introduce a vulnerability into the systems that could sooner or later be exploited by criminals or hackers to compromise communications—for example, those of journalists.

FOKUS stands for a security strategy, not a false sense of security. We therefore firmly oppose laws that mandate backdoors in messaging services. The protection of digital communication is a fundamental prerequisite for democracy, freedom of the press, and civil rights. Security is not achieved through blanket surveillance, but through targeted intelligence, technical expertise, and the protection of our digital infrastructure.

Potential Challenges During Implementation and Possible Solutions

While the introduction of an EU-wide system for digital identity verification—such as eIDAS 2.0 and the Digital Identity Wallet—holds enormous potential, it also presents challenges that must be addressed:

  • Coordination and harmonization among member states: Although eIDAS provides a framework, the actual implementation and interoperability of national digital identity wallets across the various EU member states must be ensured. This requires close cooperation and common technical standards to avoid a fragmented landscape.
  • Adoption by Users and Platforms: The system’s success depends largely on its widespread adoption by citizens as well as major social networks and online platforms. In addition to intensive outreach efforts highlighting the benefits in terms of data protection, security, and the preservation of freedom of expression, clear laws from the EU are needed to make the integration of the eIDAS system for identity verification mandatory. Furthermore, the EU must provide legal clarity so that platforms are relieved of liability for identity verification when they use the government-certified system.
  • Technical Implementation and Scalability: Building and operating an infrastructure capable of processing billions of verification requests in a data-efficient and secure manner poses significant technical challenges. It is essential to ensure that the systems are robust, fail-safe, and scalable to withstand the expected volume of use.
  • Protection Against Abuse and Discrimination: Although the system is data-minimal, mechanisms must be established to prevent abuse of the verification function or discrimination against users without a digital identity. Voluntary use and the preservation of pseudonymity are crucial here, but they must not undermine the ability to hold users accountable for content that is relevant under criminal law.
  • Handling Existing User Accounts: A key challenge will be how to handle existing user accounts. A mandatory verification process for new registrations is an important first step. For existing accounts, platforms could offer incentives (such as greater visibility for verified content or access to special features) or gradually introduce verification requirements for certain actions (such as mass posting or creating groups) to increase acceptance and facilitate the transition.

Through forward-looking planning, close cooperation between EU institutions, member states, and industry, and transparent communication with the public, these challenges can be overcome to create a safe and free Internet for everyone.

An Overview of Our Policy Demands

For a Safe and Responsible Internet

  • Introduction of an EU Interface for Digital Verification
  • Requirement to verify age and identity without sharing personal data with platforms

For Effective and Law-Based Criminal Prosecution

  • Link to the existing EU legal framework (E-Evidence, EIO, GDPR)
  • Access to data only with a court order
  • No mass data retention

For the Protection of Digital Fundamental Rights

  • Ban on Legal Backdoors in End-to-End-Encrypted Services
  • Promoting Secure Communication for All Citizens
  • Expanding technical investigative capabilities (forensics, AI, metadata analysis) rather than widespread intrusions

Conclusion

A strong, democratic Europe needs accountability in the digital sphere, clear boundaries against hate and manipulation, and the technological courage to protect freedom through security—not to replace it with control.

FOKUS stands for an Internet that upholds freedom of expression, curbs hate, protects privacy, and ensures safety.

FOKUS.

Think digitally. Act fairly. Protect democracy.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button