Brubru
EU policy intelligence
Try Brubru free
EU Canon / Digital Single Market

The Digital Services Act

Regulation (EU) 2022/2065 set the EU's horizontal framework for all online intermediaries. A directly applicable regulation, it replaces the 2000 e-Commerce Directive's liability regime with four tiers of tiered, asymmetric due diligence obligations, culminating in an annual systemic risk assessment for the platforms that reach 45 million or more monthly users in the EU.

Adopted 19 October 2022 OJ L 277, 27.10.2022 CELEX 32022R2065 Art 114 TFEU
Person using a smartphone to browse social media, representing the digital services environment governed by the DSA
Photo: cottonbro studio via Pexels | The DSA governs the duties of all online intermediaries towards EU users, from small web hosts to the world's largest social networks
45 million
VLOP/VLOSE threshold
Art 33(1): platforms and search engines reaching 45 million or more average monthly active recipients in the Union (approx. 10% of EU population) are designated Very Large Online Platforms or Search Engines.
6%
Maximum fine
Art 74(1): fines for substantive non-compliance by VLOPs/VLOSEs can reach 6% of total worldwide annual turnover in the preceding financial year.
17 Feb 2024
General application
Art 93: the DSA applies to all intermediary service providers from 17 February 2024; VLOPs/VLOSEs were subject to their extra obligations from four months after designation (first batch: 25 August 2023).
4 tiers
Asymmetric obligations
The DSA distinguishes: all intermediaries, hosting services, online platforms, and VLOPs/VLOSEs. Each tier inherits all obligations of the tier below it, plus its own additional requirements.

Overview

the EU's horizontal framework for all online intermediaries, applicable from 17 February 2024

Why the DSA was needed

By 2020, the liability framework of the 2000 e-Commerce Directive had remained largely unchanged for two decades, while the online environment had transformed beyond recognition. Social networks, search engines, app stores and online marketplaces had become central infrastructure for public discourse, commerce and access to information. At the same time, Member States were beginning to legislate diverging national rules on content moderation and disinformation, threatening to fragment the internal market. The Commission's December 2020 proposal addressed both concerns: harmonise the rules, update the obligations, and ensure that the size of a platform's impact on society is matched by the scale of its accountability.

The result is a regulation, not a directive. It is directly applicable in all Member States from 17 February 2024 (with VLOPs and VLOSEs subject earlier) and fully harmonises the areas it covers. Member States may not impose additional requirements on matters the DSA regulates (Article 1(5) and recital 9).

Legal basis and structure

The DSA rests on Article 114 TFEU (internal market approximation). It was adopted by co-decision on 19 October 2022 and published in OJ L 277 on 27 October 2022. It entered into force on 16 November 2022. The text runs to 93 recitals and 93 articles organised across five Chapters. Chapter II establishes the liability framework. Chapter III sets out the four-tier due diligence obligations. Chapter IV governs implementation, cooperation and enforcement. Chapter V contains final provisions including the supervisory fee for VLOPs/VLOSEs.

The DSA expressly absorbs the liability provisions (Articles 12-15) of the e-Commerce Directive, which it amends. The country-of-origin principle and the derogation rules of Article 3 of the e-Commerce Directive continue to apply. The DSA is without prejudice to the GDPR, the AVMS Directive, copyright law and consumer protection law, all of which continue to apply in parallel.

Scope: who is bound

The DSA applies to providers of intermediary services offering their services to recipients located in the Union, regardless of where the provider is established (Art 2(1)). The key jurisdictional concept is a "substantial connection to the Union": a significant number of recipients in one or more Member States, or activities targeted at the Union. Non-EU providers must appoint a legal representative in a Member State. Three types of intermediary service are covered: mere conduit, caching and hosting. Within hosting, the DSA further distinguishes online platforms (hosting that also disseminates to the public) and online marketplaces (platforms facilitating consumer-trader contracts). Very large online platforms (VLOPs) and very large online search engines (VLOSEs) are the highest tier.


Who the DSA applies to

a four-tier framework where each tier inherits all obligations from the tier below

T1
All intermediary services
Mere conduit, caching and hosting providers. Includes ISPs, DNS resolvers, CDNs, cloud infrastructure, web hosts and social networks. Basic obligations: authority order compliance, transparency reporting, terms and conditions, points of contact, legal representative for non-EU providers.
T2
Hosting services
Services storing user-submitted content, including cloud storage, web hosts, file-sharing services, social media, app stores and marketplaces. Additional: notice-and-action mechanism (Art 16), statement of reasons for content restrictions (Art 17), notification of life-threatening criminal content to law enforcement (Art 18).
T3
Online platforms
Hosting services that also disseminate stored content to the public: social networks, video platforms, app stores, online marketplaces, travel booking sites. Additional: internal complaints, out-of-court dispute settlement, trusted flagger prioritisation, dark patterns ban, advertising transparency, recommender transparency, minor protection. Micro and small enterprises exempt (except VLOPs).
T4
VLOPs and VLOSEs
Online platforms and search engines with 45 million or more average monthly active recipients in the Union, designated by Commission decision. Additional: annual systemic risk assessment, risk mitigation, crisis response, independent annual audit, non-profiling recommender option, ad repository, researcher data access, compliance function, enhanced transparency reporting, supervisory fees.

Online marketplaces: an additional layer

Online platforms that allow consumers to conclude distance contracts with traders (online marketplaces such as e-commerce platforms, app stores functioning as retail channels, and peer-to-peer sales platforms) carry an extra set of obligations under Arts 29-32, on top of the online platform tier. The most significant is trader traceability (Art 30): before allowing a trader to sell to EU consumers, the marketplace must collect and use best efforts to verify the trader's identity information (name, address, ID document, payment account, trade register number, self-certification of product compliance). Existing traders must be verified within 12 months of 17 February 2024. If a trader cannot be verified, its service must be suspended.

What is not covered

The DSA does not cover services that are not intermediary services (e.g. providers of original content under editorial responsibility). Interpersonal communication services between a finite group (private messaging, email) are not online platforms because they do not disseminate to a potentially unlimited public. Public groups and open channels on messaging apps may qualify if they are accessible to an unlimited audience. Infrastructure providers such as cloud computing or web hosting services are not online platforms merely because a platform they host disseminates content to the public.


The liability regime and notice-and-action

conditional exemptions carried over from the e-Commerce Directive, with updated notice-and-action rules

Mere conduit (Art 4)

A provider whose service consists of transmitting information in a communication network or providing access to one is not liable for that information, provided it: (a) does not initiate the transmission; (b) does not select the recipient; and (c) does not select or modify the content. Automatic, intermediate and transient storage for the sole purpose of carrying out the transmission is permitted and does not affect the exemption. The exemption does not affect the possibility for a court or authority to require termination or prevention of an infringement.

Caching (Art 5)

A provider performing automatic, intermediate and temporary storage for the purpose of making onward transmission more efficient is not liable, provided it: does not modify the information; complies with conditions on access; complies with industry-standard updating rules; does not interfere with lawful technology for obtaining usage data; and acts expeditiously to remove cached content once it knows the source has removed it or been ordered to do so.

Hosting (Art 6)

A provider storing information at a user's request is not liable for that information if it: (a) does not have actual knowledge of illegal content or is not aware of circumstances from which illegality is apparent; or (b) upon obtaining such knowledge, acts expeditiously to remove or disable access. The exemption is lost if the recipient acts under the provider's authority or control. For online marketplaces, the exemption is also lost if the platform presents third-party product information in a way that leads an average consumer to believe the platform itself is providing the product or service (Art 6(3)). A notice meeting the requirements of Art 16 gives rise to "actual knowledge or awareness" of the specific item notified.

Good Samaritan clause (Art 7)

Providers do not lose their liability exemptions merely because they carry out voluntary proactive investigations into illegal content or take other compliance measures in good faith and in a diligent manner. This removes the disincentive that plagued the e-Commerce Directive era: platforms feared that content moderation activity would give them "knowledge" and strip their immunity. The Good Samaritan clause reverses that chilling effect.

No general monitoring (Art 8)

No general obligation to monitor all content transmitted or stored, and no general active fact-finding obligation, may be imposed on any intermediary service provider. This prohibition applies to legislation and to individual orders. Only specific, targeted orders aimed at identified content or identified users are permitted. This provision preserves the foundation of EU intermediary liability law.

Notice-and-action mechanism (Art 16)

All hosting services must provide an easy-to-access, user-friendly electronic mechanism for any individual or entity to report allegedly illegal content. A valid notice must include: (a) a substantiated explanation of why the content is allegedly illegal; (b) the exact URL (and any additional locating information); (c) the notifier's name and email address (except for child sexual abuse material); and (d) a statement confirming good-faith belief in the accuracy of the notice. A notice meeting these requirements gives rise to "actual knowledge or awareness" for the Art 6 hosting exemption. The provider must: acknowledge receipt without undue delay; and notify its decision (and available redress options) to the notifier. Where automated means are used to process notices, the notification must state this.

Statement of reasons (Art 17)

When a hosting provider restricts content visibility, removes content, disables access, suspends or terminates a user's account, or restricts monetary payments, it must give the affected recipient a clear, specific statement of reasons. The statement must be given at the latest at the time the restriction takes effect and must cover: the factual and legal or contractual ground for the decision; whether automated means were used; and available redress options including internal complaints, out-of-court settlement and judicial redress. This obligation applies regardless of how the provider became aware of the issue, except that it does not apply to authority orders under Art 9 (which carry their own reasoning requirement). The obligation does not apply to deceptive high-volume commercial content (spam).


Obligations for online platforms

dark patterns ban, advertising transparency, recommender transparency and minor protection apply to all online platforms except micro and small enterprises

Internal complaints (Art 20)

Online platforms must provide an effective, free, electronic complaints system. Users may challenge any content restriction decision for at least six months from the decision. Complaints must be handled in a timely, non-arbitrary, non-discriminatory way. Final decisions must be taken under the supervision of qualified staff and may not be made solely by automated means.

Out-of-court dispute settlement (Art 21)

Platforms must inform users of access to certified out-of-court dispute settlement bodies. Settlement is not binding. If the body decides in the user's favour, the platform bears all fees. Bodies are certified by Digital Services Coordinators for up to five years and must be impartial, expert and accessible at nominal or no cost to users.

Trusted flaggers (Art 22)

Platforms must prioritise and process without undue delay notices from trusted flaggers designated by Digital Services Coordinators. Trusted flaggers must demonstrate particular expertise in detecting illegal content, independence from platforms, and diligent and objective conduct. Status can be suspended or revoked for significant numbers of inaccurate notices.

Prohibition on dark patterns (Art 25)

Online platforms must not design, organise or operate their interfaces in a way that deceives, manipulates or materially distorts users' ability to make free and informed decisions. This is a broad, outcome-based standard. The Commission has specifically identified the following practices as examples covered by the prohibition:

  • Giving undue prominence to certain choices when presenting a decision to the user
  • Repeatedly requesting a choice when the user has already decided, especially through pop-ups that interfere with the user experience
  • Making the procedure for terminating a service significantly more difficult than subscribing to it
  • Using default settings that are very difficult to change and that unreasonably bias decision-making
  • Nudging users into transactions through deceptive design or interface architecture

The dark patterns prohibition is additional to, not instead of, the Unfair Commercial Practices Directive (2005/29/EC) and the GDPR. The Commission may issue guidelines on specific practices.

Advertising transparency (Art 26)

For every advertisement displayed to a user, the platform must present clearly and in real time: (a) a clear label identifying it as an advertisement; (b) the natural or legal person on whose behalf the advertisement is presented; (c) the natural or legal person who paid for the advertisement, if different from (b); and (d) meaningful information about the main parameters used to determine that specific advertisement was targeted to that specific user, including how to change those parameters. Platforms must also provide a functionality for users to declare that their own content is or contains a commercial communication.

Ban on special-category data targeting (Art 26(3)): Platforms must not present advertisements based on profiling using GDPR Article 9(1) special categories of personal data: health data, religious or philosophical beliefs, racial or ethnic origin, political opinions, trade union membership, genetic data, biometric data, sexual orientation. This prohibition applies regardless of user consent, and is additional to GDPR obligations.

Recommender system transparency (Art 27)

Online platforms using recommender systems must explain in plain, intelligible language in their terms and conditions the main parameters of those systems, including the criteria most significant in determining what is suggested and why they are important. Where multiple recommendation options exist, users must be offered a selection functionality directly accessible from the interface where content is being prioritised.

Protection of minors (Art 28)

Online platforms accessible to minors must put in place appropriate and proportionate measures for a high level of privacy, safety and security for minors. Platforms must not present targeted advertisements based on profiling using personal data when they are aware with reasonable certainty that the recipient is a minor. Platforms are not required to process additional personal data to determine whether a user is a minor. The Commission may issue guidelines on implementing paragraph 1.


The VLOP and VLOSE regime

systemic risk assessment, independent audits, researcher data access and crisis response for platforms reaching 45 million EU users

Designation and threshold

Online platforms and online search engines with an average of 45 million or more monthly active recipients in the Union (Art 33(1)) are designated VLOPs or VLOSEs by the Commission, after consulting the Member State of establishment. The 45 million figure represents approximately 10% of the Union population. Providers must publish their monthly active user data every six months. Designation is followed by a four-month implementation period. Supervisory fees are charged annually, proportionate to active recipients and capped at 0.05% of worldwide annual net income (Art 43(5)(c)).

The first 19 VLOPs and 2 VLOSEs were designated on 25 April 2023. Their additional obligations took effect from 25 August 2023.

Annual systemic risk assessment (Art 34)

VLOPs and VLOSEs must diligently identify, analyse and assess at least once per year any systemic risks in the Union stemming from their services. The assessment covers four categories:

  • Illegal content: dissemination of child sexual abuse material, hate speech, terrorist content, counterfeit products, illegal services and other illegal activities through the service
  • Fundamental rights: actual or foreseeable negative effects on human dignity, freedom of expression, media pluralism, privacy, data protection, non-discrimination, children's rights or consumer protection
  • Civic discourse and elections: actual or foreseeable negative effects on democratic processes, electoral integrity, civic discourse and public security
  • Public health and well-being: negative effects on public health, protection of minors, gender-based violence, and physical and mental well-being, including through coordinated disinformation campaigns

The assessment must analyse how recommender systems, advertising systems, content moderation, terms enforcement, data practices and intentional manipulation (bots, fake accounts, coordinated inauthentic behaviour) contribute to each risk. Providers must preserve supporting documentation for at least three years. On completing the assessment, they must put in place reasonable, proportionate and effective risk mitigation measures (Art 35).

Crisis response (Art 36)

The Commission, on a Board recommendation, may order one or more VLOPs/VLOSEs to take specific measures for serious threats to public security or public health in the Union. Measures are limited to three months (renewable). The service provider chooses which specific measures to apply from among those set out in the order. The mechanism does not create a general monitoring obligation.

Independent annual audit (Art 37)

At own expense, at least once per year. Auditors must be independent (no non-audit services in the preceding 12 months; no continuous audit relationship exceeding 10 years; no contingent fees), have proven risk-management expertise and professional objectivity. The audit covers Chapter III obligations and any code/crisis protocol commitments. Platforms must act on non-positive opinions within one month and provide an audit implementation report.

Researcher data access (Art 40)

VLOPs/VLOSEs must grant data access to researchers vetted by Digital Services Coordinators, for systemic risk research. Publicly accessible data must be provided without undue delay, including real-time data where technically possible. Vetted researchers must be affiliated to a research organisation, independent from commercial interests, data-secure, and committed to publishing results publicly.

Non-profiling recommender option (Art 38)

In addition to the standard recommender transparency rules (Art 27), VLOPs and VLOSEs must offer at least one option for each recommender system that is not based on profiling within the meaning of GDPR Art 4(4). This option must be directly accessible from the interface where content is being recommended.

Ad repository (Art 39)

VLOPs and VLOSEs must maintain a publicly searchable repository of all advertisements displayed on their interfaces, retained for one year after the last display. The repository must include: the advertisement content, advertiser, payer (if different), period of display, targeting parameters and reach. No personal data of users may appear in the repository.

Compliance function (Art 41)

VLOPs and VLOSEs must establish an independent compliance function separate from operational functions, staffed by qualified compliance officers. The head of the compliance function reports directly to the management body, has the right to raise concerns without prior approval, and may not be removed without management body approval. Compliance officers must cooperate with the DSC of establishment and the Commission, ensure risks are identified and reported, organise independent audits, and monitor compliance with codes of conduct and crisis protocols.


Enforcement and fines

Digital Services Coordinators for all intermediaries; the Commission directly supervises VLOPs and VLOSEs

Actor What it supervises Penalty power
Digital Services Coordinators (DSCs) All intermediary services established in their territory, except VLOP/VLOSE systemic-risk obligations Effective, proportionate and dissuasive penalties set by Member State law
European Board for Digital Services Advisory; coordinates cross-border enforcement; recommends crisis response; publishes annual systemic risk reports No direct penalty power; opinions and recommendations addressed to DSCs and the Commission
European Commission Exclusive supervision of VLOPs/VLOSEs on systemic-risk obligations; shared competence for other VLOP/VLOSE obligations Up to 6% of total worldwide annual turnover (Art 74(1)); up to 1% for procedural infringements (Art 74(2)); periodic penalties up to 5% of average daily worldwide annual turnover per day (Art 76)
Commission investigatory and enforcement powers (Arts 65-85)

The Commission may: request information from VLOPs/VLOSEs and from any other natural or legal person who may hold relevant information; conduct interviews; perform on-site inspections (including of algorithmic systems, data-handling practices and business conduct); appoint independent external experts and auditors; and impose interim measures in cases of urgency where there is a risk of serious damage to users. Before adopting a non-compliance decision, the Commission must communicate preliminary findings and give the provider at least 14 days to submit observations. All Commission decisions are subject to review by the Court of Justice of the European Union, which has unlimited jurisdiction to cancel, reduce or increase fines (Art 81).

Fine calibration factors (Art 74(4))

When fixing fines, the Commission takes into account the nature, gravity, duration and recurrence of the infringement. Relevant factors include whether the platform systematically or recurrently failed to comply; the number of affected recipients; the intentional or negligent character of the infringement; the delay caused to proceedings; and whether the provider is active in multiple Member States.

Limitation periods (Arts 77-78)

The Commission's power to impose fines is subject to a five-year limitation period from the day the infringement was committed (or ceased, for continuing or repeated infringements). The power to enforce fine decisions is also subject to a five-year period from the day the decision becomes final. Limitation is interrupted by investigatory actions.

Jurisdiction and country of main establishment

For intermediary services below the VLOP/VLOSE level, the competent authority is that of the Member State where the provider has its main establishment (head office or registered office where principal financial functions and operational control are exercised). Non-EU providers are supervised by the Member State where their legal representative resides. If a provider has no EU establishment and no legal representative, any DSC may exercise competence. For VLOPs/VLOSEs, the Commission has exclusive competence for systemic-risk obligations, while the DSC of establishment retains competence for other obligations unless the Commission exercises its shared competence.


Timeline

from Commission proposal to full application

15 December 2020
Commission proposal for the Digital Services Act, alongside the Digital Markets Act proposal. The DSA package described as "the biggest reform of online rules in the EU in 20 years."
23 April 2022
Political agreement between the European Parliament and the Council at trilogue. Key points negotiated: the 45 million threshold for VLOPs/VLOSEs, the dark patterns prohibition, the advertising ban for minors, and the 6% fine ceiling.
5 July 2022
European Parliament adopts the text in plenary by 539 votes to 54.
4 October 2022
Council adopts the text.
19 October 2022
Regulation signed by the Presidents of the European Parliament and the Council.
27 October 2022
Publication in the Official Journal of the European Union, OJ L 277, pp. 1-102.
16 November 2022
Entry into force (20 days after publication in the OJ).
17 February 2023
Deadline for Member States to designate their Digital Services Coordinators and notify the Commission.
25 April 2023
Commission designates 17 VLOPs and 2 VLOSEs in the first batch: Alibaba AliExpress, Amazon Store, Apple AppStore, Booking.com, Facebook, Google Maps, Google Play, Google Search, Google Shopping, Instagram, LinkedIn, Pinterest, Snapchat, TikTok, Twitter/X, Wikipedia, YouTube, Zalando; plus Bing and Google Search (VLOSE). Zalando successfully challenged its designation in August 2023.
25 August 2023
VLOP/VLOSE obligations take effect for the first batch (four months after designation). Systemic risk assessments, independent audits, ad repositories and compliance functions now required.
17 February 2024
General application date: all Tier 1, Tier 2 and Tier 3 obligations apply to all intermediary service providers (not only VLOPs/VLOSEs). End of the transitional period.

Key definitions

the DSA Article 3 definitions that matter most in practice

Intermediary service
One of three types of information society service: mere conduit, caching or hosting (Art 3(g)). The category determines which tier of obligations applies.
Online platform
A hosting service that, at the request of a recipient, both stores and disseminates information to the public (Art 3(i)). The public dissemination element distinguishes it from a simple web host.
Online search engine
A service allowing users to input queries to perform searches of, in principle, all websites (or all in a particular language), returning results in any format (Art 3(j)).
Illegal content
Information that, in itself or in relation to an activity (including the sale of products or services), is not in compliance with Union law or Member State law in compliance with Union law (Art 3(h)). Determined by other laws; the DSA provides the procedural framework.
Active recipient
For an online platform: a recipient who has engaged by requesting the platform to host information or being exposed to hosted information on the interface (Art 3(p)). For a search engine: a recipient who has submitted a query and been exposed to indexed results (Art 3(q)).
Recommender system
A fully or partially automated system used to suggest specific information to recipients or to prioritise it, including following a search or determining relative prominence of information displayed (Art 3(s)).
Content moderation
Activities, whether automated or not, aimed at detecting, identifying and addressing illegal content or information incompatible with terms and conditions, including demotion, demonetisation, access disabling or removal (Art 3(t)).
Trusted flagger
An entity awarded trusted flagger status by a Digital Services Coordinator, having demonstrated particular expertise, independence from platforms, and diligent and objective conduct in notifying illegal content (Art 22(2)).
Digital Services Coordinator
The single national authority in each Member State designated as the primary contact point for DSA supervision and enforcement, responsible for coordinating among national authorities and cooperating at EU level (Art 49(2)).

Frequently asked questions

common questions from compliance teams, policy professionals and digital service providers

Does the DSA apply to a small EU start-up running a forum?

Yes, if the forum qualifies as a hosting service, the DSA applies from 17 February 2024. However, the most burdensome obligations (the online platform tier covering dark patterns, ad transparency, internal complaints, etc.) do not apply to micro and small enterprises as defined in Commission Recommendation 2003/361/EC. The basic obligations: responding to authority orders, designating a point of contact, and publishing an annual transparency report on content moderation, do not carry the SME exemption and apply to all hosting services.

Can a hosting provider refuse to take down content after receiving a notice?

Yes. A valid notice under Art 16 gives rise to "actual knowledge or awareness" of the notified item. But actual knowledge triggers the obligation to assess and act expeditiously if the content is indeed illegal. The provider may conclude the content is not illegal, and in that case must notify the notifier of its decision with reasons and available redress options. The hosting liability exemption (Art 6) is not automatically lost merely because a notice was received; it is lost if the provider fails to act expeditiously after actually knowing of illegal content.

What is the difference between the DSA and the Digital Markets Act?

The DSA (Regulation 2022/2065) governs the duties of online intermediaries towards users and public authorities, focusing on content moderation, transparency, liability and systemic risk management. It applies to all intermediary services, with extra obligations scaling up by tier. The Digital Markets Act (Regulation 2022/1925) governs the competitive conduct of "gatekeepers": designated platforms that act as key access points to the online economy. DMA obligations include interoperability, data portability, fair access and non-discrimination in self-preferencing. Both regulations may apply simultaneously to the same large platform.

Does the DSA cover private messaging apps?

It depends on the feature. Interpersonal communication services exchanging messages between a finite group determined by the sender (private messages, closed group chats) are not online platforms under the DSA because they do not disseminate to "a potentially unlimited number of third parties." However, if a messaging app also hosts public groups, open channels or broadcast features accessible to an unlimited audience, those specific features may qualify as online platform activity. The same app can simultaneously be a hosting service for its private messaging functionality and an online platform for its public broadcasting features.

When does a platform lose its hosting liability exemption?

The Art 6 hosting exemption is lost in three ways: (a) the provider has actual knowledge of illegal content and fails to act expeditiously to remove or disable it; (b) the recipient who provided the content acts under the provider's authority or control; or (c) for online marketplaces, the platform presents third-party product information in a way that leads an average consumer to believe the platform is itself providing the product or service. Voluntary content moderation under Art 7 does not in itself give rise to actual knowledge sufficient to lose the exemption.

Can a non-EU platform ignore the DSA?

No, if the platform has a "substantial connection to the Union": either through an EU establishment, a significant number of EU recipients in relation to the Member State population, or by targeting EU users (accepting EU payment currencies, using EU languages or domain names, offering localised services). Non-EU providers without an EU establishment must designate a legal representative in a Member State. Failure to do so is itself an infringement. If a non-EU VLOP/VLOSE refuses to comply, the Commission can request DSCs to restrict access to the infringing service in their territory as an enforcement measure of last resort.


Official sources

primary references for the Digital Services Act

Navigate the DSA with Brubru
Ask about notice-and-action obligations, VLOP compliance, ad transparency rules or systemic risk assessment requirements. Brubru knows EU digital policy.
Start a free trial

Background photo: ThisIsEngineering via Pexels

Explore the DSA with Brubru

AI-powered EU policy intelligence for advocacy professionals

DSA Chat
Ask Brubru about notice-and-action requirements, VLOP obligations, the dark patterns prohibition, ad transparency rules, or any other DSA provision. Get answers grounded in the full text.
Try Chat
EU Law Comply
Check your organisation's compliance with DSA obligations. Brubru maps your service type to the applicable tier and highlights gaps against the regulation's requirements.
Try Comply
My EU Bubble
Track DSA enforcement actions, Commission investigations, VLOP designations and European Board for Digital Services publications through your personalised EU news feed.
Try Bubble