Regulation (EU) 2022/2065 set the EU's horizontal framework for all online intermediaries. A directly applicable regulation, it replaces the 2000 e-Commerce Directive's liability regime with four tiers of tiered, asymmetric due diligence obligations, culminating in an annual systemic risk assessment for the platforms that reach 45 million or more monthly users in the EU.
the EU's horizontal framework for all online intermediaries, applicable from 17 February 2024
By 2020, the liability framework of the 2000 e-Commerce Directive had remained largely unchanged for two decades, while the online environment had transformed beyond recognition. Social networks, search engines, app stores and online marketplaces had become central infrastructure for public discourse, commerce and access to information. At the same time, Member States were beginning to legislate diverging national rules on content moderation and disinformation, threatening to fragment the internal market. The Commission's December 2020 proposal addressed both concerns: harmonise the rules, update the obligations, and ensure that the size of a platform's impact on society is matched by the scale of its accountability.
The result is a regulation, not a directive. It is directly applicable in all Member States from 17 February 2024 (with VLOPs and VLOSEs subject earlier) and fully harmonises the areas it covers. Member States may not impose additional requirements on matters the DSA regulates (Article 1(5) and recital 9).
The DSA rests on Article 114 TFEU (internal market approximation). It was adopted by co-decision on 19 October 2022 and published in OJ L 277 on 27 October 2022. It entered into force on 16 November 2022. The text runs to 93 recitals and 93 articles organised across five Chapters. Chapter II establishes the liability framework. Chapter III sets out the four-tier due diligence obligations. Chapter IV governs implementation, cooperation and enforcement. Chapter V contains final provisions including the supervisory fee for VLOPs/VLOSEs.
The DSA expressly absorbs the liability provisions (Articles 12-15) of the e-Commerce Directive, which it amends. The country-of-origin principle and the derogation rules of Article 3 of the e-Commerce Directive continue to apply. The DSA is without prejudice to the GDPR, the AVMS Directive, copyright law and consumer protection law, all of which continue to apply in parallel.
The DSA applies to providers of intermediary services offering their services to recipients located in the Union, regardless of where the provider is established (Art 2(1)). The key jurisdictional concept is a "substantial connection to the Union": a significant number of recipients in one or more Member States, or activities targeted at the Union. Non-EU providers must appoint a legal representative in a Member State. Three types of intermediary service are covered: mere conduit, caching and hosting. Within hosting, the DSA further distinguishes online platforms (hosting that also disseminates to the public) and online marketplaces (platforms facilitating consumer-trader contracts). Very large online platforms (VLOPs) and very large online search engines (VLOSEs) are the highest tier.
a four-tier framework where each tier inherits all obligations from the tier below
Online platforms that allow consumers to conclude distance contracts with traders (online marketplaces such as e-commerce platforms, app stores functioning as retail channels, and peer-to-peer sales platforms) carry an extra set of obligations under Arts 29-32, on top of the online platform tier. The most significant is trader traceability (Art 30): before allowing a trader to sell to EU consumers, the marketplace must collect and use best efforts to verify the trader's identity information (name, address, ID document, payment account, trade register number, self-certification of product compliance). Existing traders must be verified within 12 months of 17 February 2024. If a trader cannot be verified, its service must be suspended.
The DSA does not cover services that are not intermediary services (e.g. providers of original content under editorial responsibility). Interpersonal communication services between a finite group (private messaging, email) are not online platforms because they do not disseminate to a potentially unlimited public. Public groups and open channels on messaging apps may qualify if they are accessible to an unlimited audience. Infrastructure providers such as cloud computing or web hosting services are not online platforms merely because a platform they host disseminates content to the public.
conditional exemptions carried over from the e-Commerce Directive, with updated notice-and-action rules
A provider whose service consists of transmitting information in a communication network or providing access to one is not liable for that information, provided it: (a) does not initiate the transmission; (b) does not select the recipient; and (c) does not select or modify the content. Automatic, intermediate and transient storage for the sole purpose of carrying out the transmission is permitted and does not affect the exemption. The exemption does not affect the possibility for a court or authority to require termination or prevention of an infringement.
A provider performing automatic, intermediate and temporary storage for the purpose of making onward transmission more efficient is not liable, provided it: does not modify the information; complies with conditions on access; complies with industry-standard updating rules; does not interfere with lawful technology for obtaining usage data; and acts expeditiously to remove cached content once it knows the source has removed it or been ordered to do so.
A provider storing information at a user's request is not liable for that information if it: (a) does not have actual knowledge of illegal content or is not aware of circumstances from which illegality is apparent; or (b) upon obtaining such knowledge, acts expeditiously to remove or disable access. The exemption is lost if the recipient acts under the provider's authority or control. For online marketplaces, the exemption is also lost if the platform presents third-party product information in a way that leads an average consumer to believe the platform itself is providing the product or service (Art 6(3)). A notice meeting the requirements of Art 16 gives rise to "actual knowledge or awareness" of the specific item notified.
Providers do not lose their liability exemptions merely because they carry out voluntary proactive investigations into illegal content or take other compliance measures in good faith and in a diligent manner. This removes the disincentive that plagued the e-Commerce Directive era: platforms feared that content moderation activity would give them "knowledge" and strip their immunity. The Good Samaritan clause reverses that chilling effect.
No general obligation to monitor all content transmitted or stored, and no general active fact-finding obligation, may be imposed on any intermediary service provider. This prohibition applies to legislation and to individual orders. Only specific, targeted orders aimed at identified content or identified users are permitted. This provision preserves the foundation of EU intermediary liability law.
All hosting services must provide an easy-to-access, user-friendly electronic mechanism for any individual or entity to report allegedly illegal content. A valid notice must include: (a) a substantiated explanation of why the content is allegedly illegal; (b) the exact URL (and any additional locating information); (c) the notifier's name and email address (except for child sexual abuse material); and (d) a statement confirming good-faith belief in the accuracy of the notice. A notice meeting these requirements gives rise to "actual knowledge or awareness" for the Art 6 hosting exemption. The provider must: acknowledge receipt without undue delay; and notify its decision (and available redress options) to the notifier. Where automated means are used to process notices, the notification must state this.
When a hosting provider restricts content visibility, removes content, disables access, suspends or terminates a user's account, or restricts monetary payments, it must give the affected recipient a clear, specific statement of reasons. The statement must be given at the latest at the time the restriction takes effect and must cover: the factual and legal or contractual ground for the decision; whether automated means were used; and available redress options including internal complaints, out-of-court settlement and judicial redress. This obligation applies regardless of how the provider became aware of the issue, except that it does not apply to authority orders under Art 9 (which carry their own reasoning requirement). The obligation does not apply to deceptive high-volume commercial content (spam).
dark patterns ban, advertising transparency, recommender transparency and minor protection apply to all online platforms except micro and small enterprises
Online platforms must provide an effective, free, electronic complaints system. Users may challenge any content restriction decision for at least six months from the decision. Complaints must be handled in a timely, non-arbitrary, non-discriminatory way. Final decisions must be taken under the supervision of qualified staff and may not be made solely by automated means.
Platforms must inform users of access to certified out-of-court dispute settlement bodies. Settlement is not binding. If the body decides in the user's favour, the platform bears all fees. Bodies are certified by Digital Services Coordinators for up to five years and must be impartial, expert and accessible at nominal or no cost to users.
Platforms must prioritise and process without undue delay notices from trusted flaggers designated by Digital Services Coordinators. Trusted flaggers must demonstrate particular expertise in detecting illegal content, independence from platforms, and diligent and objective conduct. Status can be suspended or revoked for significant numbers of inaccurate notices.
Online platforms must not design, organise or operate their interfaces in a way that deceives, manipulates or materially distorts users' ability to make free and informed decisions. This is a broad, outcome-based standard. The Commission has specifically identified the following practices as examples covered by the prohibition:
The dark patterns prohibition is additional to, not instead of, the Unfair Commercial Practices Directive (2005/29/EC) and the GDPR. The Commission may issue guidelines on specific practices.
For every advertisement displayed to a user, the platform must present clearly and in real time: (a) a clear label identifying it as an advertisement; (b) the natural or legal person on whose behalf the advertisement is presented; (c) the natural or legal person who paid for the advertisement, if different from (b); and (d) meaningful information about the main parameters used to determine that specific advertisement was targeted to that specific user, including how to change those parameters. Platforms must also provide a functionality for users to declare that their own content is or contains a commercial communication.
Ban on special-category data targeting (Art 26(3)): Platforms must not present advertisements based on profiling using GDPR Article 9(1) special categories of personal data: health data, religious or philosophical beliefs, racial or ethnic origin, political opinions, trade union membership, genetic data, biometric data, sexual orientation. This prohibition applies regardless of user consent, and is additional to GDPR obligations.
Online platforms using recommender systems must explain in plain, intelligible language in their terms and conditions the main parameters of those systems, including the criteria most significant in determining what is suggested and why they are important. Where multiple recommendation options exist, users must be offered a selection functionality directly accessible from the interface where content is being prioritised.
Online platforms accessible to minors must put in place appropriate and proportionate measures for a high level of privacy, safety and security for minors. Platforms must not present targeted advertisements based on profiling using personal data when they are aware with reasonable certainty that the recipient is a minor. Platforms are not required to process additional personal data to determine whether a user is a minor. The Commission may issue guidelines on implementing paragraph 1.
systemic risk assessment, independent audits, researcher data access and crisis response for platforms reaching 45 million EU users
Online platforms and online search engines with an average of 45 million or more monthly active recipients in the Union (Art 33(1)) are designated VLOPs or VLOSEs by the Commission, after consulting the Member State of establishment. The 45 million figure represents approximately 10% of the Union population. Providers must publish their monthly active user data every six months. Designation is followed by a four-month implementation period. Supervisory fees are charged annually, proportionate to active recipients and capped at 0.05% of worldwide annual net income (Art 43(5)(c)).
The first 19 VLOPs and 2 VLOSEs were designated on 25 April 2023. Their additional obligations took effect from 25 August 2023.
VLOPs and VLOSEs must diligently identify, analyse and assess at least once per year any systemic risks in the Union stemming from their services. The assessment covers four categories:
The assessment must analyse how recommender systems, advertising systems, content moderation, terms enforcement, data practices and intentional manipulation (bots, fake accounts, coordinated inauthentic behaviour) contribute to each risk. Providers must preserve supporting documentation for at least three years. On completing the assessment, they must put in place reasonable, proportionate and effective risk mitigation measures (Art 35).
The Commission, on a Board recommendation, may order one or more VLOPs/VLOSEs to take specific measures for serious threats to public security or public health in the Union. Measures are limited to three months (renewable). The service provider chooses which specific measures to apply from among those set out in the order. The mechanism does not create a general monitoring obligation.
At own expense, at least once per year. Auditors must be independent (no non-audit services in the preceding 12 months; no continuous audit relationship exceeding 10 years; no contingent fees), have proven risk-management expertise and professional objectivity. The audit covers Chapter III obligations and any code/crisis protocol commitments. Platforms must act on non-positive opinions within one month and provide an audit implementation report.
VLOPs/VLOSEs must grant data access to researchers vetted by Digital Services Coordinators, for systemic risk research. Publicly accessible data must be provided without undue delay, including real-time data where technically possible. Vetted researchers must be affiliated to a research organisation, independent from commercial interests, data-secure, and committed to publishing results publicly.
In addition to the standard recommender transparency rules (Art 27), VLOPs and VLOSEs must offer at least one option for each recommender system that is not based on profiling within the meaning of GDPR Art 4(4). This option must be directly accessible from the interface where content is being recommended.
VLOPs and VLOSEs must maintain a publicly searchable repository of all advertisements displayed on their interfaces, retained for one year after the last display. The repository must include: the advertisement content, advertiser, payer (if different), period of display, targeting parameters and reach. No personal data of users may appear in the repository.
VLOPs and VLOSEs must establish an independent compliance function separate from operational functions, staffed by qualified compliance officers. The head of the compliance function reports directly to the management body, has the right to raise concerns without prior approval, and may not be removed without management body approval. Compliance officers must cooperate with the DSC of establishment and the Commission, ensure risks are identified and reported, organise independent audits, and monitor compliance with codes of conduct and crisis protocols.
Digital Services Coordinators for all intermediaries; the Commission directly supervises VLOPs and VLOSEs
| Actor | What it supervises | Penalty power |
|---|---|---|
| Digital Services Coordinators (DSCs) | All intermediary services established in their territory, except VLOP/VLOSE systemic-risk obligations | Effective, proportionate and dissuasive penalties set by Member State law |
| European Board for Digital Services | Advisory; coordinates cross-border enforcement; recommends crisis response; publishes annual systemic risk reports | No direct penalty power; opinions and recommendations addressed to DSCs and the Commission |
| European Commission | Exclusive supervision of VLOPs/VLOSEs on systemic-risk obligations; shared competence for other VLOP/VLOSE obligations | Up to 6% of total worldwide annual turnover (Art 74(1)); up to 1% for procedural infringements (Art 74(2)); periodic penalties up to 5% of average daily worldwide annual turnover per day (Art 76) |
The Commission may: request information from VLOPs/VLOSEs and from any other natural or legal person who may hold relevant information; conduct interviews; perform on-site inspections (including of algorithmic systems, data-handling practices and business conduct); appoint independent external experts and auditors; and impose interim measures in cases of urgency where there is a risk of serious damage to users. Before adopting a non-compliance decision, the Commission must communicate preliminary findings and give the provider at least 14 days to submit observations. All Commission decisions are subject to review by the Court of Justice of the European Union, which has unlimited jurisdiction to cancel, reduce or increase fines (Art 81).
When fixing fines, the Commission takes into account the nature, gravity, duration and recurrence of the infringement. Relevant factors include whether the platform systematically or recurrently failed to comply; the number of affected recipients; the intentional or negligent character of the infringement; the delay caused to proceedings; and whether the provider is active in multiple Member States.
The Commission's power to impose fines is subject to a five-year limitation period from the day the infringement was committed (or ceased, for continuing or repeated infringements). The power to enforce fine decisions is also subject to a five-year period from the day the decision becomes final. Limitation is interrupted by investigatory actions.
For intermediary services below the VLOP/VLOSE level, the competent authority is that of the Member State where the provider has its main establishment (head office or registered office where principal financial functions and operational control are exercised). Non-EU providers are supervised by the Member State where their legal representative resides. If a provider has no EU establishment and no legal representative, any DSC may exercise competence. For VLOPs/VLOSEs, the Commission has exclusive competence for systemic-risk obligations, while the DSC of establishment retains competence for other obligations unless the Commission exercises its shared competence.
from Commission proposal to full application
the DSA Article 3 definitions that matter most in practice
common questions from compliance teams, policy professionals and digital service providers
Yes, if the forum qualifies as a hosting service, the DSA applies from 17 February 2024. However, the most burdensome obligations (the online platform tier covering dark patterns, ad transparency, internal complaints, etc.) do not apply to micro and small enterprises as defined in Commission Recommendation 2003/361/EC. The basic obligations: responding to authority orders, designating a point of contact, and publishing an annual transparency report on content moderation, do not carry the SME exemption and apply to all hosting services.
Yes. A valid notice under Art 16 gives rise to "actual knowledge or awareness" of the notified item. But actual knowledge triggers the obligation to assess and act expeditiously if the content is indeed illegal. The provider may conclude the content is not illegal, and in that case must notify the notifier of its decision with reasons and available redress options. The hosting liability exemption (Art 6) is not automatically lost merely because a notice was received; it is lost if the provider fails to act expeditiously after actually knowing of illegal content.
The DSA (Regulation 2022/2065) governs the duties of online intermediaries towards users and public authorities, focusing on content moderation, transparency, liability and systemic risk management. It applies to all intermediary services, with extra obligations scaling up by tier. The Digital Markets Act (Regulation 2022/1925) governs the competitive conduct of "gatekeepers": designated platforms that act as key access points to the online economy. DMA obligations include interoperability, data portability, fair access and non-discrimination in self-preferencing. Both regulations may apply simultaneously to the same large platform.
It depends on the feature. Interpersonal communication services exchanging messages between a finite group determined by the sender (private messages, closed group chats) are not online platforms under the DSA because they do not disseminate to "a potentially unlimited number of third parties." However, if a messaging app also hosts public groups, open channels or broadcast features accessible to an unlimited audience, those specific features may qualify as online platform activity. The same app can simultaneously be a hosting service for its private messaging functionality and an online platform for its public broadcasting features.
The Art 6 hosting exemption is lost in three ways: (a) the provider has actual knowledge of illegal content and fails to act expeditiously to remove or disable it; (b) the recipient who provided the content acts under the provider's authority or control; or (c) for online marketplaces, the platform presents third-party product information in a way that leads an average consumer to believe the platform is itself providing the product or service. Voluntary content moderation under Art 7 does not in itself give rise to actual knowledge sufficient to lose the exemption.
No, if the platform has a "substantial connection to the Union": either through an EU establishment, a significant number of EU recipients in relation to the Member State population, or by targeting EU users (accepting EU payment currencies, using EU languages or domain names, offering localised services). Non-EU providers without an EU establishment must designate a legal representative in a Member State. Failure to do so is itself an infringement. If a non-EU VLOP/VLOSE refuses to comply, the Commission can request DSCs to restrict access to the infringing service in their territory as an enforcement measure of last resort.
primary references for the Digital Services Act
Background photo: ThisIsEngineering via Pexels
AI-powered EU policy intelligence for advocacy professionals