DMCA Rulemaking and the Developer Stake
The Digital Millennium Copyright Act (DMCA) is now over two decades old, and its anti-circumvention provisions—Section 1201—are again under review by the U.S. Copyright Office. The agency is soliciting public comments on a new set of proposed exemptions to the rule that forbids bypassing technical measures like encryption or DRM. For developers, this process is not academic: the Copyright Office weighs real-world testimony about how these restrictions affect legitimate software work when deciding which uses to permit.
The exemption mechanism is the only legal pathway for circumvention in cases that do not constitute infringement, such as certain security research, accessibility adaptations, or device repair. Without it, those activities would be flatly illegal. The current cycle includes proposals to renew and expand existing exemptions, and the Copyright Office is listening for developer input on how DRM interferes with innovation and lawful use of software.
There are two structural limitations to keep in mind. First, exemptions are not permanent; they expire and must be re-petitioned every three years. Second, even where circumvention is allowed for a specific purpose, the law does not permit distributing tools designed for that circumvention. Each person must build the tool themselves, which effectively limits the benefit to those with sufficient technical skill.
The Push for a Broader Right to Tinker
A recurring theme in the proposals is the freedom to tinker—repairing, modifying, and understanding the devices we own. The Copyright Office has grouped these under three classes.
Repair and Diagnosis Exemptions
Currently, circumvention is permitted for diagnosis and repair of smartphones, home appliances, and motor vehicles, with software modification allowed only for vehicles. Petitioners argue this is too narrow as software-enabled devices become ubiquitous. The Electronic Frontier Foundation and the Repair Association with iFixit each propose blanket exemptions allowing owners to diagnose, repair, and modify any software-enabled device. More targeted petitions from Summit Imaging and Transtate Equipment seek to extend existing repair exemptions to medical devices, citing situations where hospitals were forced to rely on approved contractors during the COVID-19 ventilator crisis. Prior rulemaking rounds have seen opposition to broad exemptions on safety, health, and privacy grounds—concerns the Copyright Office acknowledges may exceed the scope of copyright law.
Jailbreaking Beyond Consumer Electronics
Renewed exemptions currently permit jailbreaking for application interoperability, but only on smartphones, smart TVs, and voice assistants. The Software Freedom Conservancy has proposed extending this to routers and networking devices, allowing owners to install alternate firmware to address security flaws. The EFF has also asked the Copyright Office to clarify that the existing smart TV exemption covers set-top streaming boxes, arguing the line between the two has blurred.
Unlocking Modern Wireless Devices
Current rules allow circumvention to unlock devices for use on alternate wireless carriers, but only for cellphones, tablets, and mobile hotspots. The Institute of Scrap Recycling has filed two proposals to account for the growing market of 4G and 5G devices. One petition asks for a broad exemption covering any 4G or 5G connected device, while the other is narrower, targeting only cellular connected computers.
Clarifying the Boundaries of Security Research
Security researchers often must break encryption and other protections to find vulnerabilities. While the DMCA has a permanent statutory exception for this work, researchers say its ambiguous language has a chilling effect, deterring funding and inviting legal threats when flaws are reported. GitHub has its own Bug Bounty Legal Safe Harbor to protect researchers, but the Code’s rulemaking could provide better federal clarity.
The current exemption limits protection to research conducted in "good faith" and "solely" for testing or fixing bugs, where findings are used "primarily to promote the security or safety" of the device. Petitioners identify two problem areas with this language.
First, does publishing or speaking about research after completion retroactively invalidate the exemption? A coalition including J. Alex Halderman, the Center for Democracy and Technology, and the ACM proposes removing these subjective terms to protect researchers who share their findings. The Copyright Office has noted it may lack authority to impose disclosure requirements, such as responsible reporting procedures, on research outcomes.
Second, does testing whether devices respect user privacy count as security research? The Software Freedom Conservancy argues it should, proposing to clarify that "good-faith security research" includes investigating and correcting privacy-related issues and permits modifications that protect personal data.
Other Proposals From the Current Cycle
The Copyright Office has categorized proposals into 17 distinct classes. Beyond the core tinkering and security research categories, three more are relevant to the engineering community.
Accessibility for Copyrighted Works
Existing exemptions allow circumvention to make media accessible to people with disabilities, but they apply only to specific work categories and use cases. A coalition of disability and library organizations argues this patchwork is burdensome, requiring individuals to understand the legal nuances of each exemption. They propose a single, comprehensive exemption for circumvention to "enable equitable access to copyrighted works for people who have disabilities."
Text and Data Mining
The Authors Alliance, American Association of University Professors, and Library Copyright Alliance petition for an exemption covering computational analysis of copyrighted works. This is critical for building and testing machine learning models, where the ability to process large text corpora is fundamental to AI development.
License Investigation and Preservation
- License compliance checks: A Software Freedom Conservancy petition seeks to allow circumvention to investigate whether a computer program infringes copyright, including violations of free and open source license terms.
- Archival access: The Software Preservation Network and Library Copyright Alliance have filed two petitions to broaden access to archival copies beyond the physical premises of the archive itself.
The comment period is open, and developer testimony on the real-world impact of these technical measures is essential. Those interested in submitting comments can do so through the Copyright Office’s dedicated page for the 2021 proceeding.
Submitting comments to the Copyright Office
The Copyright Office is currently accepting comments from developers who wish to support proposed exemptions. For each class of exemption you want to weigh in on, you must submit a separate comment that includes evidence tied to the need for—or harm caused by—the exemption. The Office has noted that concrete, real-world examples carry more weight than hypothetical scenarios, and it has published guidance on what information would be useful for each class. You may also propose specific language for the Office to adopt.
The first round of comments in favor of the proposals is due December 14. The second round, for opposing comments, closes February 9, 2021. You can review the full process timeline and file your comment directly here.



