How Prepared Are EU Host Countries to Stem FIMI Campaigns Against Diaspora Communities?

17/03/2026

How prepared are EU countries to protect members of diaspora communities who are targets of Foreign Information Manipulation and Interference (FIMI)? This is the core question addressed in RESONANT’s Deliverable D3.3, Report on Awareness and Preparation in Host Countries to Stem FIMIs against Diaspora Communities. To answer this question, the report analyses the existing legal frameworks and gauges, with the aid of expert interviews, the level of awareness and preparedness of public institutions and legal practitioners. The legal analysis and empirical research focus on four areas in which FIMI tactics and techniques have been applied: gendered disinformation, deepfakes, online platforms, and the misuse of personal data.

Accordingly, readers will find in this document:

(a) an outline of EU legal frameworks and selected national laws relevant to the four thematic areas (e.g., DSA, GDPR, AI Act, Directive on violence against women, AVMSD, EMFA, and national criminal and civil laws);

(b) a review of case law from the EU Court of Justice (CJEU), the European Court of Human Rights (ECtHR), and national courts concerning, either directly or indirectly, the four thematic areas;

(c) insights from semi-structured interviews with experts, including lawyers, academics, data protection authorities, law enforcement agencies, journalists, and policy specialists, across five EU countries on the four thematic areas.

The legal analysis and interviews indicate that EU law offers multiple avenues of action in the areas investigated. There are, however, limits and conditions on the practical reach of the law, particularly in light of the relatively recent adoption of several relevant instruments and differences in their implementation across Member States (MS).

In general, the research highlights three key findings.

First, there are no diaspora-specific legal instruments in EU states. Members of diaspora communities are protected against FIMI through general legal frameworks, such as fundamental rights, anti-discrimination law, personal data protection, platform regulation, civil and criminal law. To be effective, equal protection requires that diaspora-specific vulnerabilities, such as language barriers, cultural nuances, and the potential exposure of family members in the country of origin, be taken into account.

Second, the elusive place of FIMI and disinformation in legal frameworks, in the sense that their legal status remains ambiguous. The challenge lies in the borderline legal status of many information manipulation and disinformation practices. Any legal intervention requires a careful, context-specific balancing of competing fundamental rights and legitimate interests. Authorities must weigh freedom of expression, access to information, and media pluralism against the protection of privacy, non-discrimination, human dignity, and, in some cases, public health, as well as the imperative to safeguard democratic processes and pluralism within the Union. This balancing exercise, inherent to the EU human rights framework, often constrains the scope, speed, and form of legal

interventions, particularly in cases where harm is diffuse, collective, or not clearly unlawful at the content level.

Third, legal remedies are predominantly reactive, individualised, and local, whereas FIMI operations are coordinated, cross-platform, and transnational. Across all investigated areas, protection is highly dependent on victims’ awareness, resources, and ability to navigate complex procedures and evidentiary requirements. Burdens of proof fall on claimants, and remedies and compensation thresholds remain high, particularly for non-material or diffuse harm. Courts must balance freedom of expression, public interest, and individual rights, leading to cautious interventions that prioritise proportionality but limit preventive impact.

Specifically, gendered disinformation can be addressed using existing criminal and civil law tools designed to counter gender-based attacks. The recently adopted Directive to prevent Violence against Women is a promising instrument as it draws attention to gender-based attacks in the digital environment. This could lead to a more systematic assessment of gendered disinformation, for instance through inclusion in the recent DSA. A major limitation of legal responses to gendered disinformation is that they are suited to individual cases rather than campaigns targeting women and gender-diverse people as a group. Furthermore, victims, particularly women and LGBTIQ+ individuals, may self-censor or withdraw from public life rather than pursue litigation, given the risk of re-exposure and the emotional cost of initiating legal proceedings.

Deepfakes and synthetic media are addressed through the AI Act’s transparency and labelling obligations, the DSA’s risk-mitigation requirements, the GDPR when personal data are involved, and national criminal provisions on non-consensual synthetic images. However, assigning responsibility requires attribution through forensic proof, and the cross-platform replication of content means that most interventions occur, if at all, after the synthetic material has already circulated.

Platform manipulation and user protection are governed by the DSA’s layered duties on notice-and-action, transparency reporting, recommender systems and systemic risk assessment, complemented by the strengthened Code of Practice on Disinformation.While promising, systemic duties placed on very large platforms, such as disinformation‑related risk assessments, trusted‑flagger schemes and researcher data access, are still in early stages of implementation, leaving users reliant on individual complaints and strategic cases brought by civil-society organisations..

Personal data misuse in manipulation campaigns and investigations is regulated by the GDPR and, for law enforcement purposes, the Law Enforcement Directive (LED), with case law clarifying when platforms act as controllers and how rights to erasure, rectification, and compensation operate. The GDPR provides rights to rectification, erasure, and compensation where personal data are misused; however, these mechanisms were not designed for large, coordinated operations that blend factual information with opinion and often involve multiple controllers. Courts increasingly recognise reputational harm, impersonation, harassment, and the circulation of inaccurate information as falling within the scope of the GDPR. This establishes a role for data protection authorities, which can investigate, order removals or corrections, and impose fines. However, interviews indicate that data protection authorities and law enforcement bodies possess a general awareness of the applicable legal instruments but have limited impact on disinformation. Institutional capacity constraints, such as under-resourced authorities, limited technical expertise in AI-generated content, and fragmented responsibilities across regulators and jurisdictions, are among the primary reasons for this.

In conclusion, the challenge facing EU host states is not the absence of legal norms, but the current difficulty of applying them effectively in complex, fast-moving, and transnational information environments, a challenge that may evolve as recently adopted regulatory frameworks are implemented and institutional capacities develop.

Written by: Afroditi Papathanasopoulou and Eugenio Mantovani (VUB)