Europe Questions LaLiga’s Mass IP Blocking Over Its Collateral Damage

The system Spain uses to block pirated football broadcasts is back under scrutiny, this time from an angle that matters a great deal to cloud providers, CDNs, operators, and system administrators. A study commissioned by the European Parliament argues that dynamic blocking is necessary to fight live piracy, but it uses Spain’s case as a warning about a technical problem: blocking IP addresses on shared infrastructure can knock hundreds of thousands of legitimate domains offline.

LaLiga overblocking in 20 seconds

  • The European Parliament is studying faster measures against illegal sports broadcasts.
  • The report cites Spain’s case as an example of the risks of IP-based blocking.
  • OONI identified 554,507 domains affected at some point during LaLiga matches.
  • Cloudflare, Amazon, Akamai, and Microsoft are among the infrastructure providers caught up in it.
  • Europe is weighing how to pair dynamic blocking with oversight, proportionality, and unblocking mechanisms.

The document, Countering online piracy of sports and broadcast in the EU, was written by Giovanni Maria Riccio, a comparative law professor at the University of Salerno, together with Fabiola Iraci Gambazza and Gianmarco Marani. It sets out to assess how effective current European measures are and what changes might be needed to fight illegal broadcasts while events are still live.

The conclusion isn’t opposed to blocking. The study argues for a faster, more harmonized European response and even looks at mechanisms similar to Italy’s Piracy Shield. The warning shows up when it examines how the infrastructure that needs to be made inaccessible is technically identified.

And Spain offers a particularly telling case study.

The technical problem with targeting an IP address

IP blocking looks simple on paper: identify the address serving illegal content, and access providers stop their customers from reaching it.

The problem is that today’s internet architecture means the IP = server = website relationship no longer holds in many cases.

A content delivery network (CDN), a reverse proxy, or a cloud platform can use a single IP address to serve numerous domains. Technologies like Server Name Indication (SNI) and virtual hosting sort out the individual services further down the chain, even though connections initially land on shared infrastructure.

That’s why an IP address can be far too broad an identifier for certain kinds of blocking.

The European Parliament’s study draws on research published on 06/30/2026 by the Open Observatory of Network Interference (OONI) on blocks recorded during LaLiga matches.

OONI analyzed measurements taken between January and June 2026, running checks against roughly 9.2 million domains.

Its researchers identified 554,507 domains affected at some point during LaLiga broadcasts, around 5.8% of the domains examined.

The effects observed were tied to 7,441 IP addresses belonging to 36 infrastructure organizations.

Among the providers affected are names fundamental to how today’s internet runs, including Cloudflare, Amazon, Akamai, and Microsoft.

From 20 IP addresses to over 400,000 domains affected

One of OONI’s findings illustrates the problem particularly well.

During certain time windows, blocking between 4 and 20 IP addresses could end up affecting more than 400,000 unique domains.

There’s no contradiction between those two figures. It’s precisely a consequence of how concentrated modern web infrastructure has become.

A CDN can advertise the same address via Anycast from numerous points of presence and serve a huge number of domains from it. Similarly, cloud platforms and distributed denial-of-service (DDoS) protection services sit shared infrastructure between users and origin servers.

From the outside, you can observe a single IP even though thousands of completely independent services sit behind it.

That’s why blocking a Cloudflare IP, for example, doesn’t necessarily mean blocking only whoever is responsible for an illegal broadcast.

The European study describes the scope detected in Spain as disproportionate and notes that the restrictions reached legitimate resources, including services tied to non-governmental organizations, media outlets, government bodies, and messaging platforms.

OONI documented affected domains linked to Amnesty International, Greenpeace, Cáritas Argentina, and the Australian Senate, along with services such as WeChat and Session.

Blocks follow the match schedule

The research also found a clear temporal correlation between the blocks and football matches.

Restrictions would appear shortly before or during certain matches and disappear afterward. OONI observed these patterns, with differences by network, on operators including Telefónica, Orange, Vodafone, MásMóvil, MasOrange, and Euskaltel.

On Telefónica, researchers counted 144 measurement windows in which more than 400,000 domains were affected. The peak reached 478,052 domains in a single hour.

Orange España racked up another 103 windows above the 400,000-domain mark.

OONI also warns that its results shouldn’t be read as a complete list of every affected site. The study depends on where measurements were taken from and which set of domains was examined, so its authors treat the figures as a lower bound.

The report commissioned by the European Parliament treats this data as empirical evidence of the collateral effects of Spain’s measures.

From a legal standpoint, it also raises questions of necessity and proportionality when a measure meant to protect audiovisual rights simultaneously restricts access to information or services that aren’t committing any infringement.

DNS, VPNs, and CDNs could also be pulled into the European system

The response the European study proposes isn’t to drop dynamic blocking.

It actually proposes strengthening it.

Illegal sports broadcasts present a specific challenge: blocking a server hours or days later has limited use once the match is already over. Those responsible can also switch domains, IP addresses, or providers quickly.

That’s why the report examines a European system capable of executing orders within minutes, taking some features of Italy’s Piracy Shield as a reference point.

A future regulation could also widen the pool of intermediaries required to cooperate. Beyond internet access providers, it could bring in DNS resolvers, VPN providers, CDNs, and hosting companies.

That would substantially change the technical scope of these measures.

A block applied at the DNS resolver acts on a different layer than one carried out via IP routes. A CDN also has information about domains and customers that an access operator may not have. And a hosting provider can act directly on the responsible server without necessarily affecting the rest of the infrastructure.

There is, in other words, no single blocking mechanism, and their consequences aren’t equivalent either.

The challenge is blocking the service, not the shared infrastructure

The European Commission had already flagged the specific risk of IP-based blocking. Its assessment of Recommendation (EU) 2023/1018 notes that this method can cause overblocking when an address is tied to multiple websites.

Possible safeguards include lists of resources that must be excluded, systems for quickly correcting false positives, and oversight mechanisms to assess how proportionate the orders are.

From a technical standpoint, the LaLiga case shows just how much the precision of the chosen identifier shapes the outcome.

A domain, a URL, an IP, an ASN, and an origin server represent different layers of infrastructure. Blocking any one of them can have very different consequences.

The challenge gets even harder with CDNs, reverse proxies, shared addressing, Anycast, and hyperscale cloud platforms. The infrastructure visible from the user’s side may not be owned or directly controlled by whoever is responsible for the content that’s meant to be removed.

The European study doesn’t turn these recommendations into new obligations. It isn’t a law passed by the European Parliament, but rather a commissioned study assessing the current framework and possible future changes.

But it does introduce an important technical element into Europe’s debate over sports piracy: making blocks faster will have to come with an equivalent improvement in their accuracy.

Because on an internet built on shared infrastructure, an IP address can be a technically easy target to block, and at the same time too big a target to block without consequences.

Frequently asked questions

Why can an IP block affect thousands of websites?

Because many cloud platforms and CDNs use shared infrastructure and IP addresses to serve multiple domains. Blocking the whole IP can also cut off connections to services that have no relation to the targeted content.

How many domains did OONI find affected?

OONI identified 554,507 domains affected at some point during the broadcasts it analyzed. The research ran checks against roughly 9.2 million domains.

Which infrastructure providers appear in the study?

The research mentions infrastructure from companies including Cloudflare, Amazon, Akamai, and Microsoft, among others.

Does Europe want to eliminate anti-piracy blocks?

No. The study actually proposes faster mechanisms against illegal broadcasts, but argues that safeguards are needed to reduce overblocking and protect legitimate services.

Scroll to Top