GitHub’s 2021 Transparency Report: New Metrics and Policy Refinements

GitHub has published transparency reports for seven years, documenting how the platform handles content moderation and government requests for user data. The latest edition covers the full calendar year 2021, building on data first released in the January–June 2021 installment.

The 2021 reporting cycle arrives amid an important external development: the update of the Santa Clara Principles on Transparency and Accountability in Content Moderation. GitHub contributed to that revision and has since made corresponding changes to its own reporting forms, policy language, and disclosure categories. The company says it continues to follow the UN’s guidance on content moderation, which emphasizes transparency and the most narrow approach possible when restricting content.

How GitHub Approaches Content Restriction

GitHub’s stated strategy for minimizing disruption and protecting developer privacy rests on several public commitments. The company develops its site policies in the open, hosting them in a public repository where users can track changes and offer input. When content must be restricted, GitHub says it explains its reasoning, notifies affected users whenever possible, and allows appeals of removal decisions.

On the legal-process side, every DMCA and government takedown request GitHub processes is posted in real time to a public repository, and DMCA notices are also sent to the Lumen database. This transparency is paired with an effort to limit how much content actually gets taken down:

  • Acceptable Use Policies are aligned with restrictions on expression—such as hate speech—under international human rights law.
  • When possible, users are given the chance to remediate or remove specific content rather than having an entire repository blocked.
  • Illegal content may be geoblocked only in the jurisdictions where it violates the law, rather than removed worldwide.
  • For claims involving circumvention of copyright controls under Section 1201 of the US DMCA or similar laws elsewhere, GitHub reviews both legal and technical arguments carefully before acting, and sponsors a Developer Defense Fund to provide legal resources to developers.

What’s New in the 2021 Report

Copyright-related takedowns remain a primary focus, given the nature of the content hosted on GitHub. Software code is frequently eligible for copyright protection, making DMCA requests particularly relevant. Still, only a tiny fraction of repositories are affected—fewer than one in ten thousand is subject to a DMCA notice.

The report adds a new dimension this year: automated detection metrics for two of the most egregious categories of Terms of Service violations. For the first time, GitHub is disclosing data on automated detection of child sexual exploitation and abuse imagery, as well as terrorist and violent extremist content. Government requests—both for user information and for content removal—remain a headline category.

GitHub’s Guidelines for Legal Requests of User Data lay out the bar it applies to legally authorized requests, whether they come from law enforcement, civil litigants, or national security channels. Some request types, such as subpoenas and national security letters, compel production without requiring review by a judge or magistrate. Search warrants and court orders, by contrast, both require judicial review. National security orders are a specialized form of court order issued by the Foreign Intelligence Surveillance Court.

GitHub’s policy thresholds are:

  • User information is released to third parties only when legal requirements are satisfied, or to prevent an emergency involving danger of death or serious physical injury.
  • A subpoena is required to disclose basic account identifiers such as a name, email address, or IP address — outside rare, exigent circumstances.
  • A court order or search warrant is required for anything else, including user access logs or the contents of a private repository.
  • Affected users are notified about requests for their data, except where a law or court order bars it.

In 2021, GitHub received and processed 335 requests to disclose user information, up from 303 in 2020. The breakdown: 195 subpoenas (183 criminal, 12 civil), 94 court orders, and 22 search warrants. That total includes six requests under exigent circumstances and 18 cross-border data requests covered later in this report. The count captures every request received regardless of outcome, with one legal caveat: GitHub is prohibited from confirming even the existence or number of national security letters or orders it receives.

Law enforcement accounted for the overwhelming majority of traffic — 96.4% of requests. The other 3.6% were civil requests, all from litigants seeking information about an opposing party.

Pie chart showing the different types of legal requests for user information processed: criminal subpoena (54.6%; 183 requests), criminal court order (28.1%; 94 requests), criminal search warrant (6.57%; 22 requests), civil subpoena (3.58%; 12 requests), cross-border request (5.37%; 18 requests), and exigent circumstances (1.79%; 6 requests). Green indicates criminal requests, and blue indicates civil requests.

What gets disclosed, and who gets told

GitHub reviews every request against its policies and pushes back where requests fall short. Some requesting parties withdrew their demands after GitHub asked for clarification; in other cases, overly broad requests were narrowed before any data was released. Notably, private content data — such as content in private repositories — is never shared except in response to a search warrant. All other requests yield only non-content data: basic account information like username and email, metadata such as account usage or permissions, and log data about account activity or access history.

Of the 335 requests received, GitHub disclosed information in response to 269. Those comprised responses to 178 subpoenas (170 criminal, 8 civil), 64 court orders, 22 search warrants, and five exigent-circumstances requests.

Pie chart showing the user information disclosed by different types of legal requests: criminal subpoena (63.2%; 170 requests), criminal court order (23.8%; 64 requests), criminal search warrant (8.18%; 22 requests), civil subpoena (2.97%; 8 requests), and exigent circumstances (1.86%; 5 requests). Green indicates criminal requests, and blue indicates civil requests.

Those 269 disclosures affected 1,671 accounts.

Table showing the number of total requests for disclosure of user information processed (335), accounts affected (1,671), total requests where information was disclosed (269), and percentage of requests where information was disclosed (80.3%).

GitHub notifies users after disclosing their data in response to a legal request — unless a law or gag order prohibits it. In practice, gag orders are common. Of the 269 disclosures in 2021, users were notified only nine times. Gag orders blocked notification in 255 cases, and the remaining five were exigent-circumstances disclosures where notification was delayed to prevent death, serious harm, or interference with an ongoing investigation.

Combined bar chart of user notifications of legal request disclosures broken out by notification sent and gag order (no notification sent) over time. The 2021 bar shows 255 gag orders, 9 notifications, and 5 requests where notification is delayed due to exigent circumstances. Note: prior to 2021, we tracked exigent circumstances requests as part of requests where we disclosed but could not notify.

The rising share of gag orders tracks the composition of the request pipeline: criminal matters routinely carry gag orders, since law enforcement typically asserts that notification would compromise an investigation. Civil matters are generally public record, and the target of the process is often already a party to the litigation. None of the civil requests processed in 2021 carried a gag order, so GitHub notified all affected users in those cases.

The correlation between civil request volume and notification ability holds across recent years:

  • 2021: 3.3% notified, 3.0% civil requests
  • 2020: 3.3% notified, 3.0% civil requests
  • 2019: 3.7% notified, 3.1% civil requests
  • 2018: 9.1% notified, 11.6% civil requests
  • 2017: 18.6% notified, 23.5% civil requests
  • 2016: 20.6% notified, 8.8% civil requests
  • 2015: 41.7% notified, 41.7% civil requests
  • 2014: 40% notified, 43% civil requests

National security letters and orders

What GitHub may publicly report about national security letters and Foreign Intelligence Surveillance Act (FISA) orders is tightly constrained. US Department of Justice guidelines permit reporting only in ranges of 250, starting at zero. GitHub reports that it received 0–249 such notices in 2021, affecting 0–249 accounts.

Table of national security and orders received (0-249) and affected accounts (0-249)

Cross-border data requests

Foreign governments seeking user data from GitHub are directed to the DOJ, which assesses whether the request meets US legal protections under a mutual legal assistance treaty (MLAT) or similar process. If the DOJ determines it does, it issues a subpoena, court order, or search warrant that GitHub then processes like any other US government request. These DOJ-issued requests don’t always carry enough context to reveal their foreign origin, but when they do, GitHub records it. In 2021, GitHub knows that four processed legal requests originated as cross-border requests.

GitHub also received eighteen requests directly from foreign governments this year — up from eight in 2020. Those direct requests came from five countries: ten from India, three from Germany, and one each from Nepal, Brazil, and Japan. All were referred to the DOJ for the MLAT process, consistent with GitHub’s guidelines.

Government takedown requests

When a government asks GitHub to remove content judged unlawful in its jurisdiction, GitHub aims to restrict the block to the jurisdiction(s) where the content is illegal. GitHib publishes the official request behind every block in its public government takedown repository. There are three conditions before GitHub acts:

  • The request came from an official government agency.
  • An official submitted an actual notice identifying the content.
  • The official specified the source of illegality in that country.

Only if all three are met does GitHub block content, and then in the narrowest way possible — for example, by geoblocking access only in the local jurisdiction.

In 2021, GitHub received and processed 26 government takedown requests based on local laws, coming from Russia, China, and Hong Kong. Those takedowns blocked 69 projects: five gists, all or part of 46 repositories, and 18 GitHub Pages sites. The volume was down from 44 takedown requests in 2020 — all from Russia — but the affected-project count was higher. Notably, only four takedowns were processed in the first half of 2021 before activity accelerated later in the year.

GitHub denied two government requests based on local laws, both from Russia, because the requests were incomplete or the targeted content had already been removed. The denial count doesn’t include a separate category: nine requests from governments to take down content as a Terms of Service violation. Those affected four accounts, 98 repositories, and four gists, covering phishing (US), malware (US), personal information removal (Netherlands), GitHub Pages violations (UK and Brazil), and copyright matters handled under GitHub’s DMCA takedown policy (US and China). One further government request alleging a Terms of Service violation — from the US — was denied for lack of evidence that GitHub’s Terms had been breached.

DMCA takedowns

GitHub's DMCA process is designed to keep code available wherever possible. Under the DMCA Takedown Policy, copyright holders can request removal of content they believe infringes on their rights. Users who believe a takedown was a mistake can file a counter notice to request reinstatement. When a valid notice identifies only part of a repository as infringing—or when a notice alleges circumvention of a technical protection measure—GitHub gives users the option to address the specific claims first. If the user removes the targeted content, GitHub avoids disabling anything else in the project.

GitHub posts processed takedown notices to a public DMCA repository, with personal information and unverified URLs redacted. In 2021, GitHub began adding annotations to certain notices to explain how they were processed—for instance, noting when a user was given a chance to resolve claims before action. Starting now, these notices are also sent to the Lumen database, Harvard University's independent research project that catalogs content removal requests, making them searchable there as well. The DMCA Takedown Policy details the requirements for valid requests, including consideration of fair use.

Notices received and processed

In 2021, GitHub received and processed 1,828 valid DMCA takedown notices. Alongside those, GitHub handled 38 valid counter notices, seven retractions, one reversal, and three counter notice reversals, totaling 1,877 notices for the year. Three notices of legal action related to takedown requests were also received.

Table of DMCA notice totals by number of takedown notices and counter notice reversals (1,828), counter notices, retractions, and reversals (46), and notices of legal actions filed (3).

Content can be reinstated after a takedown through three mechanisms:

  • Counter notice: the content owner submits information alleging the takedown was a mistake or misidentification.
  • Retraction: the original filer withdraws the request.
  • Reversal: GitHub later learns the takedown request was invalid and reverses its decision.

These definitions apply to takedown requests, but similar actions can occur for counter notices—GitHub processed three counter notice reversals in 2021. Monthly valid takedown notices ranged from 115 to 218, while counter notices, retractions, and reversals combined ranged from one to eight per month.

Combined bar chart of DMCA takedown notices processed and retractions, reversals, and counter notices processed by month.

Combined bar chart of DMCA projects taken down and reinstated by month

Projects affected

Each takedown notice can affect multiple projects—repositories, gists, and GitHub Pages sites. GitHub tracked the total number of projects taken down and reinstated in 2021. Monthly reinstatements ranged from negative one (a counter notice that GitHub reversed as invalid) to 34. Counter notices, retractions, and reversals accounted for anywhere from less than one percent to over five percent of DMCA notices in a given month, meaning most valid takedown notices result in content that stays down. In total, GitHub took down 19,276 projects and reinstated 85, leaving 19,191 projects down.

That figure is less than 0.01% of the more than 200 million repositories hosted on GitHub in 2021. The "stayed down" count includes projects where a user modified content in response to a notice—if the reported content was removed, the project is counted even if the rest of the repository remains available online.

Circumvention claims

GitHub separately tracks takedown requests alleging circumvention of a technical protection measure under section 1201 of the DMCA. Such notices require additional information to be considered complete. In 2021, GitHub updated its DMCA Takedown Policy to outline how circumvention claims are reviewed, and updated the copyright claims form to clearly state the extra information needed for these reports. Estimating from keyword searches of processed notices, 92 of the 1,828 notices (5.0%) related to circumvention. Though circumvention claims have increased over the years, they remain a small share of the total:

  • 92 or 5.03% of all notices in 2020
  • 49 or 2.78% of all notices in 2019
  • 33 or 1.83% of notices in 2018
  • 25 or 1.81% of notices in 2017
  • 36 or 4.74% of notices in 2016
  • 18 or 3.56% of notices in 2015

Pie chart breaking out takedown notices received by copyright infringement only (95.0%; 1,736 notices) and circumvention (5.0%; 92 notices).

The numbers above reflect only valid notices. GitHub also receives many incomplete copyright claims that do not lead to content removal; these are not presently counted, and GitHub doesn't track how often users resolve issues without a formal takedown.

Over the past several years, DMCA notice volume has generally scaled with repository growth. In 2021, GitHub processed a similar number of notices (1,828) as in 2018 (1,802), despite roughly doubling the number of repositories from 96+ million to 200+ million. GitHub also took down significantly fewer projects in 2021 than in 2020. While the exact cause is unclear, GitHub attributes part of the decline to its continued work on developers' rights, including changes to the DMCA review process introduced in late 2020.

Chart of DMCA takedown notices processed as compared to projects affected over time, grouped by calendar year half. H1-2021 saw 7,860 projects affected by 982 notices, and H2-2021 saw 11,416 projects affected by 846 notices. The number of notices processed is similar to previous periods from 2018 through 2019. The number of projects affected is greater than it was in the period from 2018 through 2019, but less than it was in 2020.

Chart of DMCA takedown notices processed as compared to projects affected over time, grouped by month. The number of projects affected per month generally increases with the number of takedown notices per month, with a couple of outliers in September 2015 and October 2020.

Chart of DMCA takedown notices processed by month over time, with regression line showing increase of roughly two takedowns per month.

Chart of projects taken down due to DMCA takedown processed by month over time, with regression line showing increase of over 24 takedowns per month, excluding outliers in October 2020 and September 2015.

Automated detection

In a new category for this report, GitHub now shares data on automated detection of the most severe content types: child sexual exploitation and abuse imagery (CSEAI) and terrorist and violent extremist content (TVEC). Detection relies on robust hash matching with the PhotoDNA tool. Every automated hit is verified through human review, and users can appeal automated moderation decisions.

In 2021, out of millions of scanned images, GitHub confirmed automated detection of one account with CSEAI, which was reported to the National Center for Missing & Exploited Children (NCMEC). No scanned images contained TVEC. These figures do not include staff actions in response to user reports of CSEAI or TVEC, which resulted in four additional reports to NCMEC.

Account and Project Reinstatements

Restoring access is a core part of fairness on GitHub. Reinstatements happen when GitHub undoes an enforcement action, whether after a user’s appeal or after the user removes violating content and commits to future compliance. The data below covers reinstatements related to abuse (violations of Acceptable Use Policies, excluding spam, phishing, and malware) and trade controls.

When GitHub identifies an abuse violation, it attempts the narrowest possible fix. Often, disabling a single repository resolves the issue. More serious or repeated violations require account-level action. GitHub may hide a user’s public account content while still allowing them to log in, or it may restrict a repository owner’s access to their account while keeping shared content available to other collaborators. This distinction matters for collaborative development, where others may depend on code within a restricted account.

Reported by action type, GitHub’s 2021 abuse enforcement included:

  • 4,585 accounts hidden; 341 subsequently reinstated.
  • 69 accounts with restricted owner access; access reinstated for 23.
  • 4,240 accounts both hidden and with restricted owner access. Full reinstatement occurred for 28; partial reinstatement (only one action lifted) for eight.
  • 2,257 projects disabled at the repository level; 55 reinstated. These figures exclude DMCA-related takedowns and counter-notice reinstatements.

Table showing the number of total restrictions and reinstatements for account hidden (4,585 restricted; 341 reinstated), account access restricted (69; 23), account hidden and access restricted (2,257; 28; and 8 partial), projects disabled (2,267; 55).

Pie chart breaking out aggregated abuse-related restrictions and reinstatements by outcome: remaining restricted (95.9%), reinstated (4.01%), and partially reinstated (0.07%).

Trade Controls Compliance

US sanctions restrict GitHub’s availability in Crimea, Cuba, Iran, North Korea, and Syria. GitHub continues to pursue regulatory approval for broader access, securing a license in January 2021 to make all services fully available to developers in Iran. Appeals data shows all remaining appeals from Iran were granted. GitHub’s services are generally available in Cuba except for designated nationals and certain government officials.

Trade controls require account-level restrictions, unlike the repository-level actions used for abuse. Appeals are reviewed individually, and accounts are often restored when users have only traveled temporarily to restricted regions or were flagged in error. GitHub began tracking sanctions-related appeals in July 2019.

In 2021, 1,504 users appealed trade-control restrictions, compared to 2,500 in 2020. Of those, 1,312 were approved, 137 denied, and eight required further information. Another 47 appeals came from users not subject to trade controls and were excluded. The lower volume marked a 60 percent decrease, but the approval rate increased year over year.

Pie chart breaking out trade control appeal by outcome: approved (90.0%; 1,312 appeals), denied (9.4%; 137 appeals), and more information requested (0.5%; 8 appeals).

Appeals varied widely by geography: over one thousand related to Crimea, one to North Korea, and none to Cuba. In 102 cases, the region could not be determined and was marked “Unknown,” excluded from the regional chart below. Appeals from Crimea and Syria grew versus 2020, while Iranian appeals dropped sharply since the new license meant almost all were approved.

Table showing the outcome of trade control appeals by region. Crimea: 1,069 approved, 119 denied, 4 other action taken.. Iran: 76, 0, 0. Syria: 152, 17, 2. Unknown: 58, 1, 2

Report Summary

GitHub’s approach to content moderation balances enforcement with free expression. This year’s report adds detail on automated detection usage and an updated abuse reporting form, which should support deeper reporting in future cycles. GitHub states its commitment to minimizing user data disclosure and limiting legitimate content removal to what the law requires.

Feedback on future reporting is welcome via the developer policy repository, and GitHub’s broader policy development process is documented in its public site policy repository. Data from this period was updated on February 7, 2022, and continues to be available in the DMCA repository’s data folder.