Skip to content

EU Digital Services Act Compliance: What Platforms Must Actually Do

Digital Services Act compliance: notice-and-action obligations, VLOP systemic-risk assessments, ad transparency repositories, and minors protection rules.

Concept diagram explaining EU DSA: illegal content, transparency, vlop duties, audits.

The Digital Services Act is a European Union regulation that sets tiered legal obligations for online intermediaries operating in the EU, requiring platforms to implement notice-and-action systems, content moderation transparency, and user redress mechanisms at a scale proportional to their reach. Where the earlier e-Commerce Directive established a baseline liability shield for passive intermediaries, the DSA builds on it with an affirmative compliance architecture that imposes concrete operational requirements on the majority of platforms that accept user-generated content, run recommender systems, or serve advertisements in EU markets. The regulation sits alongside GDPR's impact on US tech platforms as one of the two structural pillars of EU platform governance, and the two instruments interact directly where transparency reporting intersects with cross-border data transfer obligations for non-EU-established operators.

How the DSA Tiers Platform Obligations

The Digital Services Act divides regulated entities into four tiers, each inheriting the obligations of the tier below it plus additional requirements proportional to scale. The regulation covers all providers of intermediary services with users in the EU, regardless of where those providers are incorporated. That means a US-based hosting company serving EU customers is in scope from the moment the regulation's provisions applied to its tier.

Access and caching providers
Conduit and caching services that transmit or temporarily store data on behalf of users. These providers face the lightest obligations under the tiered compliance framework: principally, they must designate a single point of contact for regulatory authorities.
Hosting services
Services that store information at users' request, including cloud storage and web hosting providers. Hosting providers must implement a notice-and-action mechanism for illegal content and publish basic transparency reports on content removals.
Online platforms
Hosting services that also disseminate content to the public, covering social networks, marketplaces, app stores, and collaborative platforms. This tier carries the full standard set of obligations: content moderation transparency, user redress, ad labeling, and restrictions on targeting minors.
Very large online platforms and search engines (VLOPs / VLOSEs)
Online platforms and search engines that exceed the scale threshold set in the regulation. These providers face the most demanding tier, including annual systemic-risk assessments, independent audits, and mandatory ad repositories.

The tiering means a small startup hosting user-generated content has a manageable compliance surface, while a global social network carries a substantially heavier operational load. Because the obligations attach to the type of intermediary services a provider supplies, platforms should map their service against each tier's criteria before scoping their compliance program.

Notice-and-Action: The Illegal Content Pipeline

Every platform in scope must operate a notice-and-action mechanism that accepts user reports of illegal content, processes them in a timely manner, and communicates the outcome back to the reporter. The obligation applies from the hosting-services tier upward, so a platform does not need to be a social network to be covered. A cloud storage provider that accepts public uploads falls within the same requirement. The DSA's approach here contrasts with the Section 230 platform liability framework in the United States, which grants a broad immunity to platforms for third-party content rather than mandating a defined removal pipeline.

The notice-and-action pipeline must handle reports from ordinary users and from trusted flaggers: bodies officially recognized by EU member-state Digital Services Coordinators as having particular expertise in identifying specific categories of illegal content. Notices submitted by a trusted flagger must be processed with priority, which means the platform's intake architecture needs a separate routing queue for flagged submissions.

  1. Receive: accept a sufficiently precise report identifying the specific content and the legal basis for treating it as illegal.
  2. Assess: review the report against the platform's terms and applicable law, without any general monitoring obligation.
  3. Act: remove, disable access to, or restrict the visibility of the content if the report is substantiated, or reject the report with a reasoned explanation.
  4. Notify reporter: communicate the decision to the person who submitted the notice, including the grounds for the outcome.
  5. Log: record each notice and the action taken in the platform's transparency database for inclusion in transparency reporting.

Platforms that receive high volumes of notices from trusted flaggers must build processing queues that handle priority routing without degrading response time for standard user reports. The regulation does not set a universal processing deadline in hours, but enforcement authorities have treated undue delay as a compliance failure in early supervisory activity.

VLOP Obligations: Risk Assessments and Audits

Very large online platforms (VLOPs) face a distinct upper tier of obligations built around annual systemic-risk assessments, independent audits, and mandatory mitigation plans submitted to the European Commission. The threshold that triggers VLOP designation is 45 million monthly active users in the EU, a figure set at approximately 10 percent of the EU's population (European Commission, Digital Services Act policy overview). Platforms approaching that level should track their EU monthly active user count continuously, because designation carries systemic risk obligations that require significant lead time to build.

The systemic risk framework requires VLOPs to assess four categories of risk: dissemination of illegal content, adverse effects on fundamental rights, interference with civic and electoral processes, and negative effects on public health and safety. Risk assessments are not self-reporting exercises; they feed mitigation plans that the European Commission can review and, where inadequate, require revision. Independent audits carried out by accredited external auditors verify whether the platform's mitigation measures match its stated risk profile. The algorithmic accountability in AI systems framework connects directly to this tier: recommender systems operated by very large online platforms are one of the explicitly risk-assessed components under the regulation.

  • Annual systemic-risk assessment covering illegal content, fundamental rights, civic processes, and public health.
  • Independent audit by an accredited third party verifying that mitigation measures address identified risks.
  • Crisis-response protocol enabling the European Commission to order rapid action in the event of a threat to public security or health.
  • Non-personalized feed option giving users access to the platform's primary content surface without algorithmic ranking based on personal data.
  • Publicly searchable ad repository containing all advertisements served on the platform during the preceding year.
  • Data access for vetted researchers under defined conditions, enabling academic and regulatory scrutiny of the platform's systemic effects.

Transparency and User Redress Requirements

The DSA requires platforms to explain every content-moderation decision to affected users with a clear statement of reasons identifying the specific rule, the specific content, and the enforcement action taken. A statement of reasons must go to both the person who reported the content and the person whose content was actioned. The transparency reporting obligation extends beyond individual decisions: platforms must submit aggregated data on content removals, notice volumes, appeal rates, and automated detection use to the European Commission's Transparency Database (European Commission, DSA impact on platforms).

The redress chain is structured as a four-stage escalation path, and platforms must make each stage accessible from within their interface.

  1. Statement of reasons: the platform issues a written explanation of the content-moderation decision at the moment the action is taken or the notice outcome is communicated.
  2. Internal complaint mechanism: the user may challenge the decision through an in-platform complaints system, which the platform must resolve within a reasonable period.
  3. Out-of-court dispute settlement: if the internal complaint fails to resolve the matter, the user may escalate to a certified out-of-court dispute settlement body recognized by the relevant Digital Services Coordinator.
  4. National DSC escalation: users who exhaust the settlement process retain the right to file a complaint directly with the national Digital Services Coordinator in their member state, which may investigate and refer the matter to the European Commission for cross-border or systemic concerns.

Automated content moderation systems that affect significant volumes of users draw particular scrutiny under transparency reporting rules. Platforms using automated means to detect or remove content must disclose the accuracy and recall rates of those systems in their public transparency reports.

Advertising Rules: Labeling, Targeting Bans, and the Ad Repository

The DSA introduces a three-part advertising framework that requires all platforms to label every ad, bans targeted advertising to minors on all platforms, and requires VLOPs to maintain a publicly searchable ad repository. Ad transparency operates at two levels under the regulation: a baseline disclosure obligation that applies to every in-scope platform, and an extended ad repository requirement that applies only to very large online platforms. The labeling requirement covers any commercial communication presented to EU users: the label must identify the content as an advertisement, name the advertiser, and disclose the principal parameters that caused that specific ad to be shown to that specific user (European Commission, Digital Services Act policy overview). Additional guidelines on minors protections in advertising have been published by the Commission as non-binding guidance for platforms (European Commission, DSA Guidelines).

Advertising obligationApplies to all platformsApplies to VLOPs only
Ad labeling (identify as ad, name advertiser, disclose targeting parameters)YesYes (plus repository feed)
Ban on targeted advertising to minorsYesYes
Ban on targeting based on sensitive categories (health data, political views, religion, sexual orientation)YesYes
Publicly searchable ad repository (all ads served, last 12 months)NoYes
Recommender system opt-out (non-personalized feed option)NoYes

The ad transparency requirement for VLOPs goes beyond labeling. The repository must be machine-readable, publicly accessible without registration, and updated in near-real time. Researchers and civil-society organizations have explicit rights to query it. Engineering teams at VLOPs typically build a dedicated data pipeline from their ad-serving infrastructure to the public repository endpoint (European Commission, DSA impact on platforms).

Enforcement: Who Supervises and What Fines Apply

DSA enforcement is split between the European Commission, which directly supervises very large online platforms (VLOPs) and very large online search engines (VLOSEs), and national Digital Services Coordinators (DSCs), which supervise all other in-scope services established in their jurisdiction. The Digital Services Coordinator is the single competent authority designated by each EU member state under the regulation; platforms must register with the DSC in the member state where they have their main EU establishment (European Commission, Digital Services Act Q&A).

Non-compliance with the regulation's provisions can result in fines set out in the regulation as a share of global annual turnover per violation, with repeated or systemic failures carrying additional escalation options including temporary service restrictions for the most severe cases (Regulation (EU) 2022/2065, Official Journal). The escalation path from initial complaint to Commission action follows a defined sequence.

  1. User complaint to national DSC: any user or entity may file a complaint with the DSC in their member state if they believe a platform has violated its DSA obligations.
  2. DSC investigation: the national DSC assesses the complaint, may request information from the platform, and can issue binding orders requiring specific remedial action.
  3. Cross-border coordination: where the platform is established in a different member state, DSCs coordinate through the European Board for Digital Services, which may issue opinions and recommendations.
  4. Commission proceedings for VLOPs: the European Commission can open formal proceedings directly against a VLOP or VLOSE, appoint external experts to conduct an independent audit, and impose fines or interim measures pending the outcome.
  5. Commission enforcement decision: a final Commission decision may require the platform to terminate the infringement, pay a fine calculated as a share of global annual turnover, or accept behavioral commitments under the regulation.

Compliance Checklist: What Platforms Must Build or Document

Translating DSA obligations into engineering and legal deliverables requires platforms to identify their tier, build the required mechanisms, and maintain the documentation that auditors and regulators will request. The list below separates core deliverables, which apply to all in-scope online platforms, from VLOP-specific additions that apply only after designation. A compliance program that conflates the two tiers risks either over-building for a small platform or under-delivering for a large one.

  • Notice-and-action API or intake form: a structured mechanism that accepts sufficiently precise user reports, timestamps them, routes trusted flagger submissions to a priority queue, and records outcomes for transparency reporting.
  • Statement-of-reasons template: a structured output that populates the specific rule, specific content reference, enforcement action, and user-facing explanation for every content-moderation decision at the moment the decision is taken.
  • Internal complaint tool: a dedicated in-platform interface allowing affected users to challenge content-moderation decisions without leaving the service.
  • DSC registration filing: a point-of-contact designation and registration with the Digital Services Coordinator in the platform's primary EU member-state jurisdiction.
  • Privacy policy update: amendments to the platform's user-facing policy explaining the new data uses associated with ad transparency disclosures and transparency reporting.
  • Ad label implementation: front-end changes to every ad placement identifying the advertiser name and the principal targeting parameters used to select that ad for that user.
  • Terms-of-service update: revisions to reflect the platform's content moderation policies, trusted-flagger relationships, and the user redress path through to out-of-court dispute settlement.
  • [VLOPs only] Systemic-risk assessment document: an annual written assessment covering the four statutory risk categories, with a mitigation plan and evidence base that can be shared with the European Commission and independent auditors.
  • [VLOPs only] Independent audit trail: documentation package prepared for the accredited third-party auditor, including moderation decision logs, automated system accuracy metrics, and evidence that mitigation measures were implemented.
  • [VLOPs only] Ad repository data feed: a machine-readable, publicly accessible endpoint updated in near-real time with all advertisements served to EU users, including advertiser name, dates active, targeting parameters, and impression counts.
  • [VLOPs only] Researcher data-access portal: a defined access mechanism granting vetted academic and civil-society researchers access to platform data under the conditions set in the regulation.
  • [VLOPs only] Non-personalized feed toggle: a user-facing control allowing EU users to switch the platform's primary content surface to a chronological or non-personalized recommender system view.

Engineering and legal teams should treat this checklist as a minimum viable compliance surface, not a ceiling. Enforcement authorities have indicated in early supervisory guidance that platforms are expected to demonstrate good-faith effort to meet both the letter and the operational intent of each obligation.

References

Frequently Asked Questions

Which providers does the Digital Services Act cover?

The DSA covers all providers of intermediary services operating in the EU, regardless of where they are established. Coverage scales with size: basic hosting and access services face lighter obligations, online platforms face a standard set of transparency and redress requirements, and very large online platforms (VLOPs) and very large online search engines (VLOSEs) with over 45 million monthly EU users face the full tier of systemic-risk and audit obligations. A small startup hosting user content is in scope; a social network with 46 million EU monthly users is a VLOP.

What is the DSA enforcement timeline?

The DSA entered into force in November 2022 as Regulation (EU) 2022/2065. VLOP and VLOSE obligations began applying in 2023 for the first designated platforms; the remaining rules for smaller platforms applied from early 2024. Non-compliance exposes platforms to fines of up to 6 percent of global annual turnover per violation, with repeat infringements potentially triggering temporary access restrictions.

Does the Digital Services Act replace the e-Commerce Directive?

No. The DSA does not replace the 2000 e-Commerce Directive, which governed liability and transparency for online intermediaries. The DSA incorporates the liability exemption rules of that directive and adds substantial new obligations around content moderation transparency, user redress, ad labeling, recommender system controls, and risk assessments that the e-Commerce Directive never required.

Which authorities enforce the Digital Services Act?

Enforcement is split. The European Commission directly supervises VLOPs and VLOSEs and can open formal proceedings, impose fines, and require interim measures. National Digital Services Coordinators (DSCs), designated by each EU member state, supervise smaller platforms established in their jurisdiction and coordinate cross-border cases. Users who believe a platform has violated its obligations can file complaints with the relevant national DSC.

Share this guide

Sofía Reyes

Sofía Reyes edits techshooked's tech-policy and regulation coverage: privacy law, the EU AI Act, antitrust, platform liability, and online-safety rules. She reads regulatory text the way an engineer reads source code, asking what the rule actually requires, where it conflicts with other instruments, and which concrete steps satisfy it without theater.