GitHub’s First Half of 2022: Moderation and Disclosure Data

GitHub has released its transparency report covering January through June 2022, continuing a practice now in its ninth year. The report details how the platform handles government requests for user data, content removal demands, and copyright enforcement. The company frames its approach around keeping code available unless there is clear legal justification for removal, and it points to its open-source policy development and public takedown repositories as evidence of that commitment.

The reporting period shows that GitHub continues to refine how it categorizes requests. Alongside the traditional categories of government information requests and copyright takedowns, the company now includes more granular data on automated detection of severe Terms of Service violations. GitHub stresses that only a very small share of its repositories—fewer than two in 10,000—are affected by DMCA notices in a given period.

Principles Behind the Numbers

GitHub’s moderation playbook is built on several explicit commitments. The company develops its policies in public via its site-policy repository, explains its reasoning for policy decisions, and notifies users when content is restricted, with opportunities to appeal. All DMCA and government takedown requests are posted in real time to a public repository.

When content must be addressed, GitHub says it tries to limit the impact:

  • Its Acceptable Use Policies are aligned with international human rights law, particularly around hate speech.
  • Users are typically given the chance to fix or remove specific content before an entire repository is blocked.
  • When content is illegal only in certain jurisdictions, GitHub uses geoblocking rather than a worldwide takedown.
  • For claims involving circumvention of copyright controls under Section 1201 of the US DMCA or similar laws, GitHub reviews both the legal and technical merits and funds a Developer Defense Fund to support developers facing legal challenges.

Categories Covered

The report for January to June 2022 includes statistics on the following areas:

  • Requests to disclose user information: subpoenas, court orders, search warrants, national security letters and orders, and cross-border data requests.
  • Government requests to remove or block content: actions taken under local law or under GitHub’s Terms of Service.
  • DMCA takedowns: notices alleging copyright infringement and notices alleging circumvention of technical protection measures.
  • Automated detection: enforcement actions for child sexual exploitation and abuse imagery and for terrorist or extremist content.
  • Appeals: user appeals of Acceptable Use Policies violations and trade sanctions compliance decisions.

The full report includes detailed data for each of these areas, with definitions of the legal instruments involved in each category of request.

User information disclosure requests

GitHub’s Guidelines for Legal Requests of User Data define the company’s handling of legally authorized requests, including law enforcement demands, subpoenas, court orders, search warrants, and national security matters. The company states that it follows the law and enforces the highest legal standards for user data requests, noting that some legal requests do not require judicial review — for instance, subpoenas and national security letters — while search warrants and court orders do require review by a judge or magistrate. National security orders are issued by the Foreign Intelligence Surveillance Court.

  • Information is only released to third parties when appropriate legal requirements are satisfied, when required to comply with legal obligations, or to prevent an emergency involving danger of death or serious physical injury.
  • A subpoena is required to disclose certain user information, such as a name, email address, or IP address linked to an account, except under rare, exigent circumstances.
  • A court order or search warrant is required for other types of user information, including user access logs or contents of a private repository.
  • Affected users are notified about requests for their account information, except when prohibited by law or court order.

From January to June 2022, GitHub received and processed 212 requests to disclose user information, compared with 172 in the first half of 2021 and 163 in the second half of 2021. Of these, 122 were subpoenas (118 criminal or government agency, 4 civil), 56 were court orders, and 10 were search warrants. The count also includes 22 cross-border data requests, with the total excluding national security letters or orders, for which disclosure is prohibited. Most requests (98.1%) came from law enforcement or government agencies, with the remaining 1.9% being civil requests from litigants seeking information about another party.

Pie chart showing the different types of legal requests for user information processed: criminal or government agency subpoena (56.2%; 118 requests), criminal court order (26.7%; 56 requests), cross-border request (10.5%; 22 requests), criminal search warrant (4.76%; 10 requests), and civil subpoena (1.90%; four requests)

Disclosure and notification

Each request is reviewed for adherence to policies and legal requirements; GitHub pushes back when a request does not meet standards. Some requests are withdrawn after clarification, and broad requests are limited in scope. Information is disclosed only in response to valid requests, and private content data — such as content in private repositories — is never shared except in response to a search warrant. Non-content data, including basic account details, metadata, and log data, may be shared with other request types.

Of the 212 requests received, information was disclosed in response to 169 — including 112 subpoenas (109 criminal and 3 civil), 46 court orders, and 10 search warrants — affecting 1,361 accounts total.

Pie chart showing the user information disclosed by different types of legal requests: criminal or government agency subpoena (64.9%; 109 requests), criminal court order (27.4%; 46 requests), criminal search warrant (5.95%; 10 requests), and civil subpoena (1.79%; 3 requests).

Table showing the number of total requests for disclosure of user information processed (212), accounts affected (1,361), total requests where information was disclosed (169), and percentage of requests where information was disclosed (79.7%).

Users are notified when information is disclosed in response to a legal request, unless a law or court order prevents notification (commonly via a gag order). Of the 169 disclosures, notification was possible only three times; gag orders blocked notification in 166 cases.

Combined bar chart of user notifications of legal request disclosures broken out by notification sent and gag order (no notification sent) over time. The H1-2022 bar shows 166 gag orders and 3 notifications. Note: prior to 2021, we tracked exigent circumstances requests as part of requests where we disclosed but could not notify.

The rising percentage of gag orders correlates with the number of criminal requests processed; legal requests in criminal matters frequently include gag orders to prevent interference with investigations. Civil matters are typically public record, so none of the civil requests processed in this period came with gag orders, allowing notification of all affected users. Data from past years reflects this trend of notification percentages correlating with the percentage of civil requests:

  • 2.7% notified and 2.4% civil requests in 2021
  • 3.3% notified and 3.0% civil requests in 2020
  • 3.7% notified and 3.1% civil requests in 2019
  • 9.1% notified and 11.6% civil requests in 2018
  • 18.6% notified and 23.5% civil requests in 2017
  • 20.6% notified and 8.8% civil requests in 2016
  • 41.7% notified and 41.7% civil requests in 2015
  • 40% notified and 43% civil requests in 2014

National security letters and orders

Legal restrictions limit disclosure about national security letters and Foreign Intelligence Surveillance Act (FISA) orders; GitHub reports these requests in ranges of 250, starting from zero. In January to June 2022, GitHub received 0–249 such requests, affecting 0–249 accounts.

Table of national security and orders received (0-249) and affected accounts (0-249).

Cross-border data requests

Foreign governments can request user information through the Department of Justice (DOJ) via a mutual legal assistance treaty (MLAT) or similar international legal process. GitHub directs such requests to the DOJ, which determines compliance with US legal protections. If the request passes review, the DOJ issues a subpoena, court order, or search warrant that GitHub processes like any other US government request. When a request indicates foreign origin, it is captured in statistics — this year, four legal requests originated as cross-border requests.

Additionally, GitHub received 22 requests directly from foreign governments in this period, coming from eight countries: Argentina (one), Brazil (two), Estonia (one), France (one), India (15), the Republic of San Marino (one), Spain (one), and Switzerland (one). This is an increase from 2021, when eighteen requests from five countries were received; in each case, the foreign government was referred to the DOJ to use the MLAT process.

Government takedowns

GitsHub occasionally receives requests from governments to remove content deemed unlawful in their jurisdiction. When content is removed at a government's request, GitHub limits action to the jurisdiction(s) where the content is illegal whenever possible, and posts the official request in a public government takedown repository to maintain a public record. Each request is reviewed to confirm that it came from an official government agency, that an official sent an actual notice identifying the content, and that the source of illegality in that country was specified. If all three conditions are met, content is blocked in the narrowest possible way, such as geoblocking in the local jurisdiction.

In January to June 2022, GitHub processed one government takedown request from Russia based on local laws, resulting in one project (a GitHub Pages site) being blocked in Russia. This compares with four takedowns affecting 39 projects from Russia and China in the first half of 2021; the number of government takedown requests has been significantly lower in the first halves of 2021 and 2022 compared to similar periods in 2020. Additionally, GitHub processed two requests from governments to take down content as Terms of Service violations, affecting five accounts, eight repositories, and one GitHub Pages site. These requests concerned misinformation (Australia) and GitHub Pages violations (Russia).

DMCA takedowns

GitHub’s handling of Digital Millennium Copyright Act (DMCA) claims is designed to limit disruption for legitimate projects. The DMCA Takedown Policy aims to protect developers against overreaching or ambiguous requests. Most removal requests are submitted under the DMCA, and users who believe their content was removed by mistake can submit a counter notice asking for reinstatement.

When a valid takedown notice alleges that only part of a repository is infringing, GitHub gives the user a chance to address those specific claims before acting. The same opportunity is now offered for valid notices alleging circumvention of a technical protection measure. This approach often allows the issue to be resolved without disabling any content, which is critical given how much developers rely on shared code.

For every valid takedown notice, GitHub redacts personal information and any URLs where a violation could not be confirmed, then posts the notice to the public DMCA repository. Since 2021, certain notices include annotations that explain how the request was processed—for example, when a user got the chance to address claims first. This practice continued through 2022 with additional annotations added where they improve transparency.

The DMCA Takedown Policy details the full process, including the difference between takedown notices and counter notices, and lists the requirements for a valid request, which includes consideration of fair use.

Takedown notices received and processed

Between January and June 2022, GitHub received and processed 1,200 valid DMCA takedown notices—each one resulting in content being taken down or the user being asked to remove it. During the same period, the company also processed 17 counter notices and three retractions, for 1,220 total notices. No legal actions related to a DMCA takedown request were reported in this period.

Table of DMCA notice totals by number of takedown notices and counter notice reversals (1,200), counter notices, retractions, and reversals (20), and notices of legal actions filed (0).

Content taken down can be restored through three channels:

  • Counter notice: the affected user provides information alleging the takedown was a mistake or misidentification.
  • Retraction: the original filer withdraws their request.
  • Reversal: GitHub later learns the original takedown request was invalid and reverses its decision.

These definitions apply to takedown requests, but the same outcomes can occur with counter notices. Monthly takedown notice totals ranged from 137 to 267, while combined monthly counter notices, retractions, and reversals ranged from zero to eight.

Combined bar chart of DMCA takedown notices processed and retractions, reversals, and counter notices processed by month.

Projects affected

A single takedown notice can affect more than one project—repositories, gists, or GitHub Pages sites. Monthly reinstatements (via counter notice, retraction, or reversal) ranged from zero to 58 projects. The proportion of counter notices, retractions, and reversals relative to DMCA notices was less than one to more than five percent. In total, 15,883 projects were taken down and 82 were reinstated, leaving 15,801 projects down.

That figure represents less than .01% of the more than 200 million repositories on GitHub in 2022. It also overstates fully disabled projects: when a user changes code in response to a notice, that project is counted in the "stayed down" number even if the rest of the repository remains available. Those partially resolved projects are counted separately from reinstatements.

Combined bar chart of DMCA projects taken down and reinstated by month.

Circumvention claims

GitHub tracks notices alleging circumvention of a technical protection measure under section 1201 of the DMCA separately. These notices require additional information before they can be processed. The circumvention-specific policy was added to the DMCA Takedown Policy in 2021, and the copyright claims form was updated to make the extra reporting requirements clearer.

By searching processed notices for relevant keywords, GitHub estimates that 154 of the 1,200 notices (12.8%) involved circumvention claims. The number and share of such notices in prior years:

  • 92 or 5% of all notices in 2021
  • 63 or 3% of all notices in 2020
  • 49 or 2.78% of all notices in 2019
  • 33 or 1.83% of notices in 2018
  • 25 or 1.81% of notices in 2017
  • 36 or 4.74% of notices in 2016
  • 18 or 3.56% of notices in 2015

Pie chart breaking out takedown notices received by copyright infringement only (87.2%; 1,046 notices) and circumvention (12.8%; 154 notices).

Incomplete DMCA takedown notices

The numbers above cover only valid notices. GitHub also receives many incomplete or insufficient copyright infringement notices, but because these do not lead to content removal, the company does not currently track how many are received or how often users resolve the issue without a formal notice.

Trends in DMCA data

Based on the DMCA data compiled over recent years, notice volume has generally tracked repository growth. That trend held in the first half of 2022: GitHub processed more notices than in previous six-month periods, and those notices affected more projects than in most earlier periods. Monthly notices increased by roughly two on average, while monthly projects taken down increased by 27 on average, excluding youtube-dl and one other outlier.

Chart of DMCA takedown notices processed as compared to projects affected over time, grouped by calendar year half. H1-2022 saw 15,883 projects affected by 1,200 notices. The number of notices processed in H1-2022 is greater than it was in previous periods. The number of projects affected is greater than it was in previous periods, with the exception of H2-2020.

Chart of DMCA takedown notices processed as compared to projects affected over time, grouped by month. The number of projects affected per month generally increases with the number of takedown notices per month, with a couple of outliers in September 2015 and October 2020.

Chart of DMCA takedown notices processed by month over time, with regression line showing increase of roughly two takedowns per month.

Chart of projects taken down due to DMCA takedown processed by month over time, with regression line showing increase of 27 takedowns per month, excluding outliers in October 2020 and September 2015.

Automated detection

Automated scanning is used to detect some of the most serious categories of platform abuse: child sexual exploitation and abuse imagery (CSEAI) and terrorist and violent extremist content (TVEC). Detection relies on robust hash matching with the PhotoDNA tool, followed by human review to confirm initial hits. Users can appeal automated content moderation decisions.

In January to June 2022, out of millions of images scanned, automated detection confirmed one account with CSEAI, which was reported to the National Center for Missing & Exploited Children (NCMEC). No TVEC was found in scanned images. The low volume of this content does not reduce the importance of these resources, which help safeguard survivors and the community. These figures exclude other staff actions taken in response to CSEAI or TVEC reports; five additional CSEAI reports were made to NCMEC based on such cases.

Reinstatements and Appeals

Reinstatement is a key part of GitHub's enforcement process, allowing the company to undo actions taken against accounts or repositories. This can happen either after a user successfully appeals a decision or after they remove violating content and commit to following the Terms of Service going forward. The report covers reinstatements related to two categories: abuse violations (excluding spam, phishing, and malware) and trade controls violations.

When GitHub identifies an abuse-related Terms of Service violation, it can take action at different levels. The approach is designed to restrict content as narrowly as possible: disabling a single repository when one project is the problem, or acting at the account level when violations are repeated across multiple repositories. Account-level actions can also vary: hiding a user's content while still allowing them access to their account (useful when the violation involves publicly posted content), or restricting a user's access to their own account while leaving shared content available to others — an important option for a collaborative platform where other users may depend on that content.

The data for January to June 2022 shows a wide range of enforcement actions and reinstatements:

  • 4,913 accounts were hidden; 356 were reinstated.
  • 268 accounts had the repository owner's access restricted; 16 were reinstated.
  • 2,617 accounts had both restrictions applied; 54 were fully reinstated and 18 were partially reinstated (one restriction lifted but not the other).
  • 1,766 projects were disabled; 4 were reinstated.

These numbers do not include DMCA-related takedowns or reinstatements, such as those resulting from counter-notices, which are covered separately in the DMCA section of this report.

Table showing the number of total restrictions and reinstatements for account hidden (4,913 restricted; 356 reinstated), account access restricted (268 restricted; 16 reinstated), account hidden and access restricted (2,617 hidden and restricted; 54 full reinstated; and 18 partially reinstated), projects disabled (1,766 disabled; four re-enabled).

Pie chart breaking out aggregated abuse-related restrictions and reinstatements by outcome: remaining restricted (95.3%), reinstated (4.5%), and partially reinstated (0.188%).

Trade controls compliance

US sanctions require GitHub to restrict access for developers in certain regions: Crimea, the separatist regions of Donetsk and Luhansk, Cuba, Iran, North Korea, and Syria. GitHub has stated it will continue advocating for broader access, noting that it secured a US government license in January 2021 to make all services fully available to developers in Iran, and is working toward similar outcomes for Crimea and Syria. Services are generally available in Cuba, with exceptions for specially designated nationals, other denied or blocked parties, and certain government officials.

While trade control laws force account-level restrictions — GitHub cannot simply disable a repository in these cases — users are able to appeal. Reinstatement can occur when a user was temporarily traveling in a restricted region or when the account was flagged in error. GitHub began tracking sanctions-related appeals in July 2019.

In January to June 2022, 464 users appealed trade-control related account restrictions, down from 591 in the same period in 2021. The outcome breakdown for these 464 appeals was as follows:

  • 355 approved
  • 103 denied
  • 6 required further information

An additional 78 appeals were excluded from analysis because they were filed by users who were not actually subject to trade controls.

Pie chart breaking out trade control appeal by outcome: approved (76.5%; 355 appeals), denied (22.2%; 103 appeals), and more information requested (1.29%; six appeals).

Appeals varied significantly by region, from 173 related to Crimea to six related to the Luhansk People's Republic. In 85 cases, GitHub could not assign a region and marked them as "Unknown." Compared to 2021, appeals from Crimea decreased while appeals from Syria increased.

Table showing the outcome of trade control appeals by region. Crimea: 173 approved, 28 denied, one other action taken. Donetsk People’s Republic: 48 approved, 55 denied, one other action taken. Luhansk People’s Republic: six approved, 14 denied, one other action taken. Syria: 120 approved, six denied, two other action taken. Unknown: 85 approved, 0 denied, one other action taken.”

Looking ahead

GitHub frames its transparency reporting as part of a broader commitment to free expression and user privacy. The company says it aims to limit the disclosure of user data and the removal of legitimate content to the minimum required by law, while still providing detailed explanations of its content moderation practices. GitHub also invites feedback on its reports and points to its public site policy repository as a resource for understanding how its policies are developed.