Mechanism
The DSA replaces the EU's 2000 E-Commerce Directive (Directive 2000/31/EC) intermediary-liability safe-harbour framework with a modern four-tier graduated obligations structure, calibrated by the intermediary's role and scale.
Tier 1 — All intermediary service providers (mere conduits, caching services, hosting services):
- Preservation of the no-general-monitoring principle (liability safe harbour maintained)
- Single point of contact designation for competent authorities
- Legal representative in the EU required for non-EU-established providers
- Annual transparency reports on content-moderation volumes, categories, and decision times
- Compliance with judicial or administrative orders to remove specific illegal content or provide user data
Tier 2 — Online platforms (hosting services that allow third-party content to be accessed by the public):
- Notice-and-action mechanisms: must process notices of alleged illegal content promptly and notify reporters of decisions
- Internal complaint-handling and access to certified out-of-court dispute settlement bodies
- Trusted Flaggers: platforms must prioritise and process notices from Commission-certified Trusted Flaggers with sectoral expertise
- Prohibition on deceptive dark patterns in interface design (Article 25)
- Age-appropriate design safeguards: must not display advertising targeted at minors based on profiling
- Prohibition on targeting based on sensitive personal data (health, religion, ethnicity, political opinion, sexual orientation) — applies to all platforms
- Online advertising transparency: real-time, accessible disclosure of advertiser identity, targeting parameters, and funding basis for each advertisement
Tier 3 — Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) (≥45m monthly active EU users, roughly 10% of EU population):
Additional obligations above Tier 2:
- Annual systemic-risk assessments covering: dissemination of illegal content, fundamental-rights impacts (privacy, freedom of expression, non-discrimination, child rights), electoral-integrity impacts, gender-based violence facilitation, public-health and civic-discourse harms
- Risk mitigation measures reasonably proportionate to identified systemic risks
- Annual independent third-party audit of risk assessments and mitigation measures (cost borne by the platform)
- Vetted-researcher data access (Article 40): VLOPs/VLOSEs must provide real-time and retrospective data access to researchers vetted by Digital Services Coordinators — first binding academic/civil-society scrutiny mandate in EU digital regulation
- Recommender-system transparency: at least one non-profiling-based content recommendation option must be offered and clearly labelled; parameters of recommender systems must be disclosed
- Advertising transparency register: publicly searchable, real-time repository of all advertisements served, including targeting parameters, duration, and reach estimates — archived for 12 months
- Crisis-response cooperation mechanism (Article 36): Commission may activate coordination with VLOPs during acute crises (elections, pandemics, public-order events) requiring temporary algorithmic or content-distribution changes
- Supervisory fee: Commission levies an annual supervisory fee capped at 0.05% of worldwide net income on designated VLOPs/VLOSEs
Enforcement architecture:
- Commission: exclusive enforcement authority over VLOPs/VLOSEs. Fines up to 6% of global annual turnover for substantive breach; up to 1% for procedural non-compliance (failure to provide information, provide incorrect information, failure to submit to audit); periodic penalty payments up to 5% of average daily global turnover. For systematic infringement (three adjudicated breaches in five years), structural remedies including temporary prohibition of service access in the EU are available.
- Digital Services Coordinators (DSCs): national supervisory bodies in each Member State with authority over all intermediaries below VLOP/VLOSE threshold; coordinated through the European Board for Digital Services (EBDS).
- Joint investigation teams: DSCs may request Commission to open proceedings; Commission and DSCs cooperate on cross-border enforcement.
VLOP/VLOSE designation timeline:
| Date | Action |
|---|
| Feb 2023 | Commission sends formal designation letters to 19 VLOP candidates and 2 VLOSE candidates |
| 25 Apr 2023 | Commission formally designates 17 VLOPs and 2 VLOSEs; Zalando and X contest designation |
| 25 Aug 2023 | VLOP/VLOSE-specific obligations (Tier 3) become applicable |
| Sep 2023 | X (formerly Twitter) files General Court appeal contesting VLOP designation |
| Oct 2023 | Commission opens formal DSA non-compliance proceedings against X (risk assessment gaps, dark patterns, deceptive interfaces, researcher data access) |
| 17 Feb 2024 | DSA applies in full to all covered intermediaries (not only VLOPs/VLOSEs) |
| Mar 2024 | Commission opens formal DSA proceedings against TikTok (recommender systems, researcher data access, risk assessments for minors) |
| Apr 2024 | Commission opens formal DSA proceedings against Meta/Facebook and Meta/Instagram (election-integrity risk assessment gaps, systemic-risk mitigation deficiencies) |
| Sep 2024 | Zalando removed from VLOP designation following General Court annulment ruling on threshold methodology |
| Jan 2025 | Commission opens formal DSA proceedings against Shein (risk assessment completeness, advertising transparency) |
| Mar 2025 | Temu (PDD Holdings) designated as VLOP after exceeding 45m monthly active EU user threshold |
Designated VLOPs (as of 2025): AliExpress (Alibaba), Amazon Store (Amazon), Apple App Store (Apple), Booking.com (Booking Holdings), Facebook (Meta), Google Play (Alphabet), Google Maps (Alphabet), Google Shopping (Alphabet), Instagram (Meta), LinkedIn (Microsoft), Pinterest, Snapchat (Snap), TikTok (ByteDance), X/Twitter, Wikipedia (Wikimedia Foundation), YouTube (Alphabet), Temu (PDD Holdings), Shein. Designated VLOSEs: Bing (Microsoft), Google Search (Alphabet).
Downstream implications
- US Big Tech compliance cost escalation: Designated VLOPs (Alphabet, Amazon, Apple, Meta, Microsoft, ByteDance, Snap) face annual independent audit costs (estimated €1–5m per entity per cycle), systemic-risk assessment governance infrastructure (dedicated internal teams + external risk consultants), and architectural changes to recommender and advertising targeting systems. Aggregate DSA compliance expenditure across the VLOP cohort is estimated at €500m–€1.5bn annually at steady state.
- Advertising-stack restructuring: Prohibitions on targeting based on sensitive personal data and on targeting minors via profiling materially constrain Meta's and Alphabet's EU programmatic-advertising yield per user. Meta introduced an EU subscription monetisation tier ("Meta ad-free subscription") in late 2023 partly in response to this constraint — a structural response that reduces the addressable EU ad audience size.
- Content-moderation governance lever: The crisis-response mechanism (Article 36) and systemic-risk assessment mandates give the Commission structural authority to require VLOPs to modify algorithmic amplification policies during EU electoral periods — a regulatory tool with no prior equivalent in EU media or communications law. Applied during the European Parliament elections of June 2024 and expected to be invoked for the next major Member State election cycle.
- Researcher data access as global precedent: Article 40's vetted-researcher data access mechanism is the first legally binding mandate for external academic and civil-society scrutiny of platform algorithmic systems at scale. The UK Online Safety Act's Section 101 researcher-access provisions and US KOSA-adjacent proposals explicitly cite the DSA Article 40 model as a reference architecture.
- Chinese e-commerce platform extraterritorial reach: Shein, Temu, and AliExpress are subject to the full VLOP obligations despite being Chinese-headquartered, Chinese-capital-backed, and operating without EU establishment at the time of DSA adoption. DSA enforcement against these platforms creates structural compliance costs on Chinese consumer platforms seeking EU market access — a non-tariff barrier functionally equivalent to the prior E-Commerce Directive but with significantly higher ongoing compliance burden.
- NIS2 interface and dual reporting: Hosting services that are both DSA-covered intermediaries and NIS2-covered essential/important entities face parallel incident-reporting obligations under Article 19 DSA and Articles 23–24 NIS2 (Directive 2022/2555). The Commission and ENISA have issued joint guidance on avoiding double-reporting, but the coordination overhead is material for mid-tier cloud/hosting providers.
Open questions
- X/Twitter enforcement trajectory: Commission formal proceedings opened October 2023; preliminary findings issued July 2024 include risk-assessment inadequacy on illegal content dissemination, recommender-system non-compliance, and interface dark-pattern violations. Potential fines up to 6% of global turnover (~€280–350m at 2023 revenue) and the precedent-setting question of whether structural suspension (temporary EU access ban) will be invoked for repeated/systemic non-compliance.
- TikTok DSA × national-security nexus: Whether DSA enforcement findings (researcher access refusal, minors-safety risk assessment gaps) become linked to the parallel EU-level review of ByteDance's data governance and potential TikTok divestiture pressure from EU Member State governments — and whether a forced divestiture of TikTok-EU operations from ByteDance would trigger a new VLOP designation process.
- Meta content-moderation rollback: Meta's January 2025 decision to discontinue third-party fact-checking on Facebook and Instagram in the US may constitute a breach of DSA Article 35 systemic-risk mitigation obligations if applied uniformly — Commission DSA team monitoring whether EU-facing content-moderation architecture diverges from global rollback.
- DSA → DMA evidentiary pipeline: If Article 40 researcher-access data produces empirical documentation of algorithmic self-preferencing or amplification of harmful content by VLOPs that are also DMA-designated gatekeepers, those findings could be used as evidence in parallel DMA enforcement proceedings — creating a regulatory feedback loop between the two instruments.
- Recommender-system default obligations: The scope of the "not based on profiling" recommender-system option (Article 38) is under contested interpretation — whether a purely chronological timeline satisfies the obligation or whether more substantive de-personalisation is required. Commission implementing guidance expected 2025–2026.