Why GitHub publishes this data
GitHub’s 2019 transparency report covers the full calendar year and reflects the company’s position that public disclosure of government requests and content removals is a core part of its user commitment. The report is the sixth in a series that dates back to 2014, and it arrives at a moment when the industry trend is moving in the opposite direction: as of October 2019, 70 companies worldwide had published transparency reports, yet many are scaling back their reporting—particularly around government requests for user data.
Content moderation remains a growing area of scrutiny, and GitHub’s approach is shaped by a core tension: removals, whether initiated by a government or another user, can implicate free expression. The company’s stated policy is to limit content restrictions to specific, illegal content where possible rather than blocking entire repositories, and to enforce takedowns only in the jurisdiction where the content is deemed illegal. GitHub also follows United Nations free expression guidance, which recommends that platforms engage users in policy development, explain policy decisions, notify users when content is restricted, offer an appeals process, and publish takedown requests in real time in a public repository.
Reported categories
The report is organized around three request types:
- Requests to disclose user information, including subpoenas, court orders, search warrants, national security letters and orders, and cross-border requests.
- Government requests to remove or block content, whether under local law or under GitHub’s Terms of Service.
- Copyright takedown notices, covering both DMCA notices filed in the U.S. and court-ordered takedowns.
GitHub focuses on these three areas because they represent the primary channels through which governments and other parties seek to compel the company to act on user data or content. The third category is particularly relevant due to GitHub’s role as a host of software source code, which is often copyrightable. Even so, only a tiny fraction of hosted content—roughly one in ten thousand repositories—is ever subject to a DMCA notice.
Final 2019 numbers were updated on February 25, 2021, to reflect data processed after the report’s initial publication.
User Data Disclosure Requests: 2019 in Review
GitHub processed 261 requests to disclose user information in 2019, more than triple the volume seen in 2018. The breakdown of those requests was 114 subpoenas (106 criminal, 8 civil), 102 court orders, and 37 search warrants. Court orders and search warrants each roughly quadrupled year-over-year. Eight of the 261 requests were cross-border data requests, discussed in more detail below. These figures count every request processed for user information, regardless of whether any data was ultimately disclosed.
The overwhelming majority of requests — 96.9 percent — came from law enforcement. Civil requests made up just 3.1 percent of the total, and all of those came from civil litigants seeking information about another party. This differs from 2018, when GitHub also received civil requests from government agencies.

Disclosure and Notification Outcomes
GitHub did not disclose user information in response to every request. In some cases, a request was not specific enough and the requester withdrew it after clarification was sought. In others, GitHub was able to narrow the scope of overly broad requests. Of the 261 requests processed, GitHub disclosed information 189 times, affecting 557 accounts. Had all requests met the criteria for processing, 1,252 accounts would have been potentially affected. Four of the requests each related to more than 100 accounts.
Requests affecting a large number of users typically arise when a court order seeks information about access to a specific piece of content posted on GitHub, rather than targeting identifiable users. In those scenarios, GitHub shares log data — including usernames and IP addresses — tied to access during a defined timeframe. GitHub does not typically share additional private details, such as email addresses, for every user who accessed the content without a specific request for that information.

GitHub notifies users when their information is disclosed in response to a legal request, unless prohibited by law or court order — commonly a gag order. In 2019, of the 189 disclosures, GitHub was able to notify users only seven times; gag orders accompanied the remaining 182 requests.
The rising percentage of requests carrying gag orders tracks closely with the percentage of criminal requests processed. Criminal investigations frequently come with gag orders because notification could compromise the investigation. Civil matters, by contrast, are typically public record, and the subject of the legal process is often a party to the litigation itself, making secrecy unnecessary. None of the civil requests in 2019 included a gag order, and GitHub notified the affected users in each case.
Given that only 3.1 percent of requests in 2019 were civil, the 3.7 percent notification rate is unsurprising. Historical data shows a similar correlation between notification rates and the share of civil requests:
- 2018: 9.1 percent notified, 11.6 percent civil requests
- 2017: 18.6 percent notified, 23.5 percent civil requests
- 2016: 20.6 percent notified, 8.8 percent civil requests
- 2015: 41.7 percent notified, 41.7 percent civil requests
- 2014: 40 percent notified, 43 percent civil requests
National Security Requests
Reporting on national security letters and Foreign Intelligence Surveillance Act (FISA) orders is constrained by U.S. Department of Justice (DOJ) guidelines, which permit disclosure only in ranges of 250 starting at zero. For 2019, GitHub received 0–249 such notices, affecting 0–249 accounts.

Cross-Border Data Requests
Foreign governments seeking user information can route requests through the DOJ via a mutual legal assistance treaty (MLAT) or similar international process. GitHub directs such governments to the DOJ, which determines whether the request satisfies U.S. legal protections. If it does, the DOJ issues a subpoena, court order, or search warrant that GitHub processes like any other U.S. government request. These requests do not always arrive with enough context to identify their foreign origin; when they do, that information is captured in the statistics above. In 2019, GitHub knows that one court order and one search warrant originated as cross-border requests.
GitHub also received eight requests directly from foreign governments in 2019 — from Germany and India — up from two requests in 2018, which also came from two countries. Consistent with established practice, those governments were referred to the DOJ to use the MLAT process.
Takedown Requests and Content Removal
Requests to remove or block user content fall into several categories: government takedown requests, DMCA takedown notices, and — new to this report — court-ordered takedowns.
Government Takedown Requests
GitHub receives requests from governments to remove content deemed unlawful in their local jurisdiction. When content is blocked at a government's request, the official request is posted to a public gov-takedowns repository. Before acting, GitHub verifies that the request came from an official government agency, that an official sent an actual notice identifying the content, and that the source of illegality under that country's law was specified. Content is blocked in the narrowest way possible, typically restricted to the jurisdiction where it is illegal.
In 2019, GitHub processed 16 government takedown requests: eight from Russia, six from China, and two from Spain. These resulted in 54 projects being blocked in the respective countries — all or part of 48 repositories, one gist, and five GitHub Pages sites. Though the number of notices is still relatively small, it is up from nine requests in 2018, all from Russia. The affected projects increased sixfold year-over-year. Additionally, GitHub processed one request from France to take down content as a Terms of Service violation related to phishing, which disabled five projects.
DMCA Takedown Notices
Most content removal requests arrive under the DMCA, which lets copyright holders ask GitHub to remove content they believe infringes their copyright. The affected user can respond with a counter notice seeking reinstatement if they believe the takedown was a mistake or misidentification. Each complete DMCA takedown notice is redacted of personal information and posted to a public dmca repository.
GitHub received and processed 1,762 complete DMCA takedown notices and 37 complete counter notices or retractions in 2019, for a total of 1,799 notices. No notices of legal action related to a DMCA takedown were received this year.

Content taken down can be restored either through a counter notice — where the content owner provides sufficient information to allege the takedown was a mistake — or through a retraction, where the original claimant withdraws the request. Monthly takedown notice totals generally ranged from 120 to 185, with December as the low point at 104. Monthly counter notices and retractions combined ranged from zero to nine.

A single takedown notice can span multiple projects — repositories, gists, or GitHub Pages sites. Monthly reinstatement totals ranged from zero to nine projects, with counter notices and retractions amounting to only two to four percent of DMCA-related notices each month. Overall in 2019, GitHub took down 14,366 projects and reinstated 46, leaving 14,320 projects down. While that number may seem substantial, it represents only about one one-hundredth of a percent of all repositories on GitHub at the end of 2019.

Historical DMCA data shows a general increase in notices received that tracked with user growth over recent years, until this year. Comparing the number of repositories affected by DMCA notices against the approximate number of registered users over the same period reveals an increase in 2019 that correlates with the growth of the GitHub community.

Court-Ordered Takedowns
A new category for 2019 is court-ordered takedowns. GitHub received one such request this year, which — interestingly — concerned copyright but did not fall under the DMCA. Because it arrived as a gagged court order, GitHub could not offer the usual transparency of posting or sharing the notice, but the fact that a takedown was processed on this basis is reported here.
Beyond the Report
GitHub positions itself against the trend of companies scaling back their disclosure efforts. The platform remains focused on limiting how much user data it hands over legally and how much content it is forced to remove, treating those constraints as part of its user commitment. The annual reporting is intended to make its internal processes more visible and to feed into the wider conversation on how platforms govern content.
Readers with feedback on what should appear in future editions are invited to reach out to [email protected]. The company's approach to developing policy and procedure is openly documented in its site policy repository, where updates and changes are tracked. More details on this year's findings are available in the report's previous sections.



