Why DMCA circumvention claims jumped—and what it really means
GitHub has published its full 2023 transparency reporting data on the transparency center and in the public repository. This is the first release since the transparency center launched, and it gives us a chance to dig into notable patterns in the numbers. The one we’re starting with: the sharp rise in DMCA notices alleging circumvention that first showed up in the 2022 report.
The numbers behind the spike


The jump is stark. We processed 92 notices alleging circumvention in all of 2021, then 365 in 2022 and 406 in 2023. On a monthly basis, that’s a jump from roughly 7.67 notices per month to 33.83 per month—more than four times the previous volume.
A form change explains the timing
If you’re looking at the chart and wonder why the trend line bends so sharply at the end of September 2021, it’s not a coincidence.

On September 29, 2021, we added circumvention-related questions to our DMCA takedown submission form. The reasoning was operational: circumvention claims generally require more in-depth review, and flagging them at submission lets us route them to the right team from the start.

We anticipated this might lead more submitters to label their requests as circumvention claims. To keep the data meaningful, we started annotating notices shortly before the form change when a circumvention-alleging takedown was processed for reasons other than circumvention.

Breaking the data down that way shows a clear divergence: many more notices now allege circumvention, but the number we actually act on because of a valid circumvention claim has not accelerated in the same way. In many cases, content is removed on other grounds—for example, a traditional copyright infringement claim or a violation of our Acceptable Use Policies.
What the increase actually costs
Under our developer-focused approach to the DMCA, any takedown notice containing a credible circumvention claim that cannot be resolved on other grounds is reviewed by a team of lawyers and engineers.

The form change has increased the number of alleged circumvention claims we have to triage, and that takes time. But the review process itself is central to how we handle DMCA notices: we aim to keep legitimate projects online and limit disruption from overreaching or ambiguous requests. Every valid takedown notice we process has personal information redacted, along with any URLs where we couldn’t confirm a violation. The redacted notices are then posted to the public DMCA repository, where anyone can inspect them—or run regexes over them to build charts like the ones in this analysis. We also plan to add circumvention classification directly to the transparency center in a future update.
For context on the legal landscape: the DMCA prohibits circumventing technological measures that control access to copyrighted works, but it also provides a triennial rulemaking process for temporary exemptions for noninfringing uses. GitHub has previously filed comments advocating for a broader safe harbor for good-faith security research. The ninth triennial proceeding is underway and is considering exemptions related to software preservation, text and data mining, and generative AI research. Developers interested in DMCA reform can follow along and participate as stakeholders.
Questions about our data or ideas for future deep dives? Open an issue in the transparency center repository.



