Digital Services Act
The EU's horizontal rulebook for online intermediaries, setting notice-and-action, statement-of-reasons, complaint-handling and marketplace trader-traceability duties for in-scope services, with added systemic-risk assessment, audit and recommender-transparency obligations for designated very large platforms and search engines.
Overview
Obligations stack by service type rather than applying uniformly: every intermediary owes baseline terms-and-conditions and reporting duties, hosting services add notice-and-action and statements of reasons, online platforms add complaint handling, advertising and minors rules, and only designated very large online platforms and search engines carry the systemic-risk regime in Chapter III Section 5. Designation is the trigger for that top tier, not self-assessment: providers publish their average monthly active EU recipients every six months, and the Commission designates a service that reaches 45 million or more, with the section applying four months after designation (Art. 24(2), Art. 33). Algorithmic accountability operates at two levels, with all platforms disclosing the main recommender parameters and the reasons for their relative importance in their terms, and designated services additionally offering a feed option not based on profiling and submitting to yearly independent audit (Art. 27, Art. 38, Art. 37). Supervision is likewise split: the Commission polices designated services directly and can fine up to 6 percent of worldwide turnover, while national Digital Services Coordinators handle everyone else (Art. 74(1)).
Key dates
- Nov 16, 2022Entered into force
- Aug 25, 2023Obligations apply to very large platforms & search engines
- Feb 17, 2024Fully applicable to all in-scope services
Risk areas addressed
Who it applies to
The Regulation binds providers of intermediary services offered to recipients established or located in the Union, irrespective of where the provider itself is established, covering mere conduit and caching services, hosting providers, online platforms, marketplaces allowing distance contracts with traders, and online search engines (Art. 2(1)). Micro and small enterprises as defined in Recommendation 2003/361/EC are exempt from the online platform section apart from the duty to report user numbers on request, and keep that exemption for 12 months after losing the status, unless they are designated as a very large online platform (Art. 19). The systemic-risk chapter applies only to services on the Commission's published designation list at or above 45 million average monthly active EU recipients, and note that the marketplace section has its own separate micro and small enterprise exclusion (Art. 33(1), (4), Art. 29).
Key obligations
- Set out in your terms and conditions every restriction you impose on user content, including the policies, procedures, measures and tools used for content moderation, any algorithmic decision-making and human review, and the rules of your internal complaint-handling system, in clear machine-readable form (Art. 14(1)).
- Give affected users a clear and specific statement of reasons for any content removal, demotion, visibility restriction, payment restriction, service suspension or account termination, and submit those statements without undue delay to the Commission's public machine-readable database (Art. 17(1), Art. 24(5)).
- Explain in plain and intelligible language the main parameters of each recommender system, why particular information is suggested, the reasons for the relative importance of those parameters, and any options users have to change them (Art. 27(1) to (3)).
- Mark each advertisement as such, identify the advertiser and the payer, make the main targeting parameters directly accessible in real time, and never serve profiling-based ads using special category data or using the data of users you are reasonably certain are minors (Art. 26(1), (3), Art. 28(2)).
- Publish average monthly active EU recipients at least every six months, and publish transparency reports covering moderation activity, out-of-court dispute outcomes and account suspensions (Art. 15, Art. 24(1), (2)).
- If designated, identify and assess systemic risks stemming from your service and its algorithmic systems at least once a year and before launching functionalities likely to have a critical impact on those risks, keep the supporting documents for three years, and put tailored mitigation measures in place (Art. 34, Art. 35(1)).
- If designated, commission an independent annual audit at your own expense, and where the opinion is not positive adopt an audit implementation report within one month setting out the measures taken or justifying the alternatives (Art. 37(1), (6)).
- If designated, offer at least one non-profiling option for each recommender system, maintain a searchable ad repository with API access for one year after last display, run a compliance function independent of operations whose head reports directly to the management body, and give vetted researchers access to data on systemic risks (Art. 38, Art. 39(1), Art. 41, Art. 40).
How to prepare
- Determine which tier you occupy, from mere conduit through hosting to online platform, marketplace or search engine, then check whether the Art. 19 micro and small enterprise exclusion removes the platform section for you.
- Calculate and publish average monthly active EU recipients on the Commission methodology, and track the figure against the 45 million designation threshold so designation does not arrive as a surprise.
- Rewrite terms and conditions to describe moderation policies, algorithmic decision-making, human review and the internal complaint procedure, then align the actual tooling and workflows to what you have published.
- Wire statements of reasons into every enforcement action so each restriction automatically produces a user-facing explanation and a record fit for the Commission's transparency database.
- Document recommender parameters, expose the user-facing controls, and add a non-profiling option if you are designated or expect to be.
- If designated, run the annual cycle as a programme: systemic risk assessment, mitigation plan, independent audit, audit implementation report, ad repository upkeep, researcher data access and a compliance function with a direct line to the board.
Penalties & enforcement
Up to 6% of global annual turnover.
Enforced by: European Commission & national Digital Services Coordinators
EU DSA is enforced by European Commission & national Digital Services Coordinators. Its obligations are already live, so a gap is a present exposure rather than a future one. In practice that means knowing which of your AI systems fall in scope in online platforms and search, holding assessments that speak to transparency, governance & accountability and fundamental rights, and being able to produce that evidence on request, including for systems built outside the jurisdiction.