Perfect 10 v. CCBill: The Ninth Circuit's Baseline for DMCA Notices, Red Flags, and Repeat Infringers
The Ninth Circuit held that defective DMCA notices cannot create knowledge, salacious site names are not red flags, and a tracked policy satisfies 512(i).
Nearly every fight over the Digital Millennium Copyright Act’s safe harbors is fought on ground the Ninth Circuit staked out in Perfect 10, Inc. v. CCBill LLC, 488 F.3d 1102 (9th Cir. 2007). The panel first issued its opinion on March 29, 2007, then amended it on May 31, 2007, and the Supreme Court denied certiorari later that year, 552 U.S. 1062 (2007). Writing for a unanimous panel that included Judges Stephen Reinhardt and Alex Kozinski, Judge Milan D. Smith, Jr. answered three questions that 17 U.S.C. § 512 had left open since 1998: what a takedown notice must contain before it counts, what a “red flag” of infringement actually looks like, and how well a service provider must run its repeat infringer policy to keep the safe harbor.
The answers were provider-friendly across the board, and they remain the baseline for DMCA compliance programs. For good measure, the court added a separate holding on Section 230 of the Communications Decency Act that shields providers from state law intellectual property claims, a rule that still divides the circuits.
At a glance
- Case: Perfect 10, Inc. v. CCBill LLC, 488 F.3d 1102 (9th Cir. 2007), amending 481 F.3d 751 (9th Cir. Mar. 29, 2007), cert. denied, 552 U.S. 1062 (2007).
- Decided: March 29, 2007; amended opinion issued May 31, 2007; opinion by Judge Milan D. Smith, Jr.; affirmed in part, reversed in part, and remanded.
- Holding: Deficient takedown notices cannot be combined to create knowledge of infringement, provocative site names and password-hacking pages are not red flags, and a repeat infringer policy tracked through a working DMCA log is reasonably implemented under § 512(i).
- Significance: Final. The decision remains the foundational Ninth Circuit gloss on § 512’s notice, knowledge, and repeat infringer requirements, and its CDA holding still governs state law claims against intermediaries in the circuit.
The safe harbor bargain and its three pressure points
Congress built Title II of the DMCA, codified at 17 U.S.C. § 512, as a bargain. Service providers that meet threshold conditions receive immunity from monetary liability for their users’ infringement; in exchange, they must respond expeditiously to proper takedown notices, act when infringement is apparent, and terminate repeat infringers “in appropriate circumstances” under § 512(i). Each duty contains a pressure point that litigation would have to resolve.
First, § 512(c)(3) lists six elements a notification must contain, including identification of the infringed work, identification of the infringing material, and a signed statement of good faith belief. The statute says a notice that fails to comply substantially “shall not be considered” in determining whether the provider has knowledge. Second, § 512(c)(1)(A) removes the safe harbor when a provider is “aware of facts or circumstances from which infringing activity is apparent,” the so-called red flag test. Third, § 512(i) conditions every safe harbor on adopting and reasonably implementing a repeat infringer policy, without defining reasonable implementation. CCBill was the first appellate decision to work through all three.
An adult magazine, a payment processor, and a web host
Perfect 10, Inc. published an adult magazine and operated a subscription website, perfect10.com. It was also one of the most prolific copyright plaintiffs of the 2000s; its companion case against Google, Perfect 10, Inc. v. Amazon.com, Inc., 508 F.3d 1146 (9th Cir. 2007), produced the server test for the display right. In this suit, filed in the Central District of California, Perfect 10 alleged that images stolen from its magazine and site appeared on third-party websites, and it sued the companies that kept those websites in business: CWIE (Cavecreek Wholesale Internet Exchange), which provided web hosting and connectivity, and CCBill, which processed subscription payments.
Perfect 10’s theory was that the defendants had forfeited the § 512 safe harbors. It argued that its own notices, along with notices from other copyright owners, gave the defendants knowledge; that the sites the defendants served waved red flags, with names like illegal.net and stolencelebritypics.com and pages offering password-hacking tips; and that the defendants’ repeat infringer policies were shams. The district court largely sided with the defendants, and both sides appealed.
Notice must be complete, and defective notices cannot be stacked
The court’s first holding concerned Perfect 10’s takedown notices, which arrived in pieces: one communication identified the works, another identified the infringing locations, another supplied the required statements. The Ninth Circuit held that substantial compliance with § 512(c)(3) must be assessed notice by notice. A copyright owner cannot cobble adequate notice together from separately defective communications, because the statute puts the burden of policing infringement, in the first instance, squarely on the owner, and service providers are not required to assemble a compliant notice from scattered fragments.
The consequence is severe for careless senders. Under § 512(c)(3)(B)(i), a noncompliant notice cannot even be used as evidence that the provider knew of the infringement. A defective takedown is therefore worse than useless in later litigation: it neither obligates the provider to act nor counts toward its knowledge. Every takedown program built since CCBill, on either side of the notice, is designed around that rule.
Red flags that were not: illegal.net and password hackers
Perfect 10’s red flag argument fared no better. The court reasoned that a website’s decision to call itself illegal.net or stolencelebritypics.com does not make infringement apparent, because lurid names may be marketing rather than confession; describing content as stolen can be an attempt to increase its salacious appeal. Nor did pages offering password-hacking assistance raise a red flag, since a provider would have to investigate whether the passwords actually unlocked infringing content before infringement became apparent, and § 512(m) makes clear that providers have no duty to monitor or affirmatively seek out facts.
The practical upshot is that red flag knowledge, as construed in CCBill, is a very high bar: the infringement must be apparent without investigation. Later Ninth Circuit decisions, including Mavrix Photographs, LLC v. LiveJournal, Inc., 873 F.3d 1045 (9th Cir. 2017), have worked within that framework rather than loosening it, and the Second Circuit adopted a similarly demanding objective standard in Viacom International, Inc. v. YouTube, Inc., 676 F.3d 19 (2d Cir. 2012).
Reasonable implementation, plus an unexpected CDA holding
On § 512(i), the court held that a provider implements a repeat infringer policy if it has a working notification system, a procedure for dealing with DMCA-compliant notifications, and does not actively prevent copyright owners from collecting the information needed to complain. CCBill and CWIE kept a DMCA log tracking webmasters and complaints, and the court found that gaps in the log, such as missing names on a single page, did not show a failure to reasonably implement the policy. Perfection is not the standard; a tracked, functioning process is.
The panel did not hand the defendants a complete victory. It remanded for consideration of notices and red flags arising from communications by copyright owners other than Perfect 10, of whether CCBill qualified under § 512(a) as a transitory network provider for payment transmission, and of Perfect 10’s direct infringement allegations concerning a site called hornybees.com. But the framework it announced governed the remand and every case since.
Finally, the court held that the Communications Decency Act’s exclusion for “any law pertaining to intellectual property,” 47 U.S.C. § 230(e)(2), covers only federal intellectual property law. State law claims, including Perfect 10’s right of publicity claim, were therefore preempted by CDA immunity. National providers, the court reasoned, should not face liability that varies with each state’s idiosyncratic IP regimes.
Open questions
CCBill left the substance of “appropriate circumstances” for termination undefined, and later cases had to fill the gap; the Fourth Circuit’s decision in BMG Rights Management (US) LLC v. Cox Communications, Inc., 881 F.3d 293 (4th Cir. 2018), showed that a policy honored only on paper forfeits the safe harbor, thirteen-strike log or not. The CDA holding remains contested: the Third Circuit expressly disagreed in Hepp v. Facebook, 14 F.4th 204 (3d Cir. 2021), holding that state intellectual property claims survive Section 230, so the treatment of publicity rights claims against platforms still depends on the forum as of July 2026. And CCBill predates the modern debates over automated detection; how its no-investigation rule applies to providers who voluntarily run fingerprinting tools remains largely untested at the appellate level.
Implications for creators and businesses
- Send complete notices or send nothing. A takedown that omits a § 512(c)(3) element does not trigger a duty to act and cannot later prove knowledge. Copyright owners should treat the six statutory elements as a hard checklist in a single communication.
- Keep a DMCA log that actually works. For providers, CCBill rewards a documented pipeline: a registered agent, a procedure for compliant notices, and records of terminations. Imperfect execution is survivable; the absence of a working system is not.
- Do not rely on red flags to shift the burden. Owners who expect providers to infer infringement from context will lose in the Ninth Circuit. If you want action, identify the works and the URLs with precision.
- Publicity and other state law claims depend on the forum. Within the Ninth Circuit, Section 230 blocks state IP claims against intermediaries; in the Third Circuit it does not. Platform-side counsel should treat choice of forum as outcome-determinative on these claims.
Frequently asked questions
What did Perfect 10 v. CCBill hold about DMCA takedown notices? The Ninth Circuit held that a takedown notice must substantially comply with all of Section 512(c)(3)‘s requirements in a single communication before it can create knowledge of infringement. Courts may not combine several defective notices into one adequate notice, and a notice that fails the statute cannot be used to show the provider knew about the infringement.
What counts as red flag knowledge after CCBill? Very little short of obvious, apparent infringement. The court held that website names like illegal.net and stolencelebritypics.com were not red flags because they could be sales puffery rather than admissions, and that hosting password-hacking instructions did not make infringement apparent without further investigation the statute does not require.
Why does CCBill matter for repeat infringer policies? The decision gave the first workable definition of a reasonably implemented policy under Section 512(i): the provider needs a working notification system, a procedure for responding to compliant notices, and no active interference with copyright owners’ ability to collect the information needed to complain. Imperfect record-keeping alone did not defeat the safe harbor.
Authorities and sources
- Perfect 10, Inc. v. CCBill LLC, 488 F.3d 1102 (9th Cir. 2007) (opinion text)
- Amended opinion, 488 F.3d 1102 (Berkeley Law archive PDF)
- 17 U.S.C. § 512 (Cornell LII)
- 47 U.S.C. § 230 (Cornell LII)
- Perfect 10, Inc. v. CCBill, LLC, Wikipedia case summary
- Electronic Frontier Foundation, case page for Perfect 10 v. CCBill