Bots and trolls in comment sections: what legal risks do social media account managers take?
- Mar 25
- 5 min read

The Law on Public Information of the Republic of Lithuania defines criticism of a person as the examination and assessment of a person or his/her activities, without offending honor and dignity, without violating private life and without diminishing professional reputation. The right to criticize is an important means of ensuring the public's right to public information. Article 10 of the European Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR) protects not only acceptable or neutral ideas, but also those that offend, shock or disturb. However, freedom of speech is not absolute - it does not grant the right to humiliate people, spread hatred, discriminate or call for violence. It is extremely difficult to determine the line between permissible criticism and impermissible expression. So where is that line?
In the social media space, this boundary is a gray area, where speech, by its intensity and impact, is no longer free expression or neutral opinion. Transgressive speech prevails – deliberately provocative, vulgar and socially norm-breaking expression, the purpose of which is not discussion, but destruction and a strong emotional reaction. It is precisely this kind of language that is massively used by bots and trolls: “nakhui”, “bl”, “padugnė”, “nyuchas”, “glušius”, “debilas”, “gis”, “lesbianė”, “pedophile”, “Nazi”, “Russian” and similar epithets designed to polarize discussion, incite tension and pollute the comments section.
An illustrative example from personal practice: after three statements by a public figure on a media outlet's social network account, out of 602 comments, as many as 39 percent are attributable to hate speech, defamation or insults. More important than the numbers is the structure of the content: one-word epithets without any argument, just to humiliate the addressee; defamatory statements formulated as an established fact - "stealing", "taking bribes" fall into the category of defamation, not opinion, without a trial, and there is already a risk of criminal liability. Some comments even note that the comments are no longer made by people, but by bots and trolls. However, regardless of who is commenting, it is obvious that too many comments generally fall within the limits of self-expression no longer protected by the Constitution and Article 10 of the ECHR.
This aspect is particularly relevant for large media outlets. They publish material every day that attracts hundreds of comments, including a large number of hate speech, defamation or coordinated bot and troll attacks. In such accounts, comments often contain data of clearly identifiable persons (names, surnames, accusations, discriminatory epithets). If the account manager (editor's office) sees clearly illegal content and does not take any action, he can no longer claim to properly fulfill the obligations set out in Articles 24 and 25 of the General Data Protection Regulation (hereinafter - GDPR) - to ensure adapted and standardized data protection. In such a case, there is a real risk not only of data protection violations, but also of joint liability for damage to the honor and dignity of a person.
The account owner is no longer a neutral observer. The first and most often ignored fact: the manager of a social network account is not just a technical user of the channel. The Court of Justice of the European Union (hereinafter referred to as the CJEU) made it clear in a 2018 case 1 that Facebook and the administrator of a fan page are joint data controllers. This means that the news portal, institution or politician who manages the account where content is created and a comment space is opened, also assumes responsibility along with the platform.
The case law of the European Court of Human Rights (hereinafter referred to as the ECtHR) on this issue is consistent. In the case of Delfi AS v. Estonia 2 the Court recognised that a commercial platform which itself initiates publications and profits from the flow of comments cannot limit itself to the "notice and takedown" model when abuse is clearly foreseeable. In the case of Sanchez v. France 3 The Court further stated that the administrator of a public account who had a real opportunity to remove clearly hateful comments and failed to do so may be held liable without violating the guarantees of freedom of expression. Deliberate inaction in relation to clearly illegal content negates the status of a neutral intermediary. This logic of the ECtHR decisions is closely linked to the aforementioned CJEU case, and it means that liability for data protection violations caused by the content of comments cannot be transferred solely to the platform – it also falls on the account owner himself.
Social media algorithms count comments, reactions and reply threads as signals of engagement – regardless of whether the content is accurate and legitimate. When coordinated activity by fake accounts generates hundreds of comments, the reputation-destroying campaign receives algorithmic reinforcement from the platform itself. Legally, this means that the platform and the account owner are no longer just a “technical conduit” – they actively contribute to the dissemination of harmful content through tailored and standardized data protection. The Digital Services Act enshrines this logic at the regulatory level: Article 16 requires not only to have a mechanism for reporting illegal content, but to ensure its real effectiveness – a mechanism that is structurally incapable of dealing with automated bot traffic fails to meet this requirement. Article 34 treats coordinated inauthentic activity as a systemic risk that very large platforms must identify and mitigate.
If account owners were to actually implement their GDPR obligations to systematically moderate comment content and document the extent of harmful content, they would inevitably face a structural problem: the content they manually remove is algorithmically re-raised as a high-engagement post, further encouraging commenting. A manual reporting mechanism will never win against a coordinated automated bot farm. While an account manager removes a few comments, in the same time the bots generate dozens of new ones, and the algorithm pushes them even further into the audience’s sights. This situation is a clear indicator of a violation of Article 16 of the Digital Services Act: a reporting mechanism formally exists, but the platform structurally sabotages its effectiveness against a massive, automated attack. Systematically recorded and reported such cases could become the basis for fines procedures that reach up to 6% of annual turnover and platforms cannot ignore them so easily. But in practice, most editorial teams fear that active moderation will reduce engagement and revenue, so they choose to “turn a blind eye.” The clickbait economy is winning over free speech that transcends boundaries, for now.

Prepared by:
Angele Aliukonyte
APB Zaleckas Partners
Lawyer
1 Wirtschaftsakademie Schleswig Holstein – Judgment of the Grand Chamber of the CJEU, 5 June 2018 , Case C 210/16;
2 Delfi AS v. Estonia – ECtHR Grand Chamber judgment, 16 June 2015, application no. 64569/09;
3 Sanchez v. France – ECtHR Grand Chamber judgment, 15 September 2023, application no. 45581/15;


