The repeat-infringer policy — written, applied, provable.
Every DMCA safe harbor rests on one policy the statute requires but does not write for you: what your service does about subscribers who keep infringing. The statute asks for three things — adopt it, implement it reasonably, tell subscribers — and leaves the content to the provider.
Adopt it. Implement it. Say so.
Adopted
A written policy that provides for termination, in appropriate circumstances, of subscribers who are repeat infringers. The provider defines the circumstances and the stages.
Reasonably implemented
Notices are matched to accounts, the stages happen, and the provider can show they happened. Adoption without implementation does not meet the condition.
Subscribers informed
The policy, or a plain statement of it, in the terms subscribers agreed to — where they can find it, not where a lawyer would.
Repeat infringers, answered.
What does the DMCA require in a repeat-infringer policy?
Section 512(i)(1)(A) conditions every § 512 safe harbor on the provider having adopted and reasonably implemented a policy that provides for termination, in appropriate circumstances, of subscribers and account holders who are repeat infringers — and having informed subscribers of it.
How many notices make someone a "repeat infringer"?
The statute does not say. It does not define "repeat", set a number, or prescribe the steps. The provider writes the policy — what counts, how notices are matched to accounts, what happens at each stage, and what "appropriate circumstances" means for its service — and then follows what it wrote.
What does "reasonably implemented" mean in practice?
That the policy exists, subscribers can find it, notices are actually tracked against accounts, the stages in the policy actually happen, and the provider can show all of that. A policy that lives in the terms of service and is never applied is the classic failure.
Does the policy have to be public?
Subscribers must be informed of it. In practice that means the policy — or a plain statement of it — in the terms of service and the acceptable-use policy, where a subscriber agreed to it.
What records should a provider keep?
Each notice received, the account it was matched to and how, the date the subscriber was notified, any counter-notice, and each stage of the policy applied to that account. It is the same discipline as any other legal-process file: the record is what shows the policy was implemented, not just adopted.
The policy is the end of the chain.
Designated agent registration → · The notice-and-takedown process → · DMCA records production at Subsentio →