DSAEU Platform Regulation

EU Digital Services Act Scope, Platform Duties, and VLOP Readiness

This DSA hub helps decide whether a particular service is in scope, classify its intermediary tier, and find the duties that follow for hosting, platform, marketplace, search, and designated very-large-service features.

By Sorena AIUpdated 2026-05No signup required
DSA quick scan
Regulation 2022/2065
Scope and service boundary
The DSA covers intermediary functions that transmit, temporarily store, or host recipient-provided information when offered to recipients in the EU. Classify each service surface separately; the same product can contain several DSA tiers.
Core operating duties
Hosting and platform teams need operational records for Article 16 notices, Article 17 statements of reasons, Article 15 transparency reports, Article 24 user numbers, Article 26 ads, Article 27 recommenders, and Article 30 trader traceability where relevant.
Enhanced VLOP/VLOSE layer
Designated services at or above 45 million average monthly active EU recipients must handle systemic-risk assessment and mitigation, annual independent audits, researcher and regulator data access, non-profiling recommender options, and searchable ad repositories.

Follow the grouped guides in order: establish EU scope and service tier, assign the matching operating duties, then add reporting, marketplace, VLOP/VLOSE, and enforcement evidence only where the classification supports it.

Key dates
2022/2065
Regulation
Art. 16-17
Moderation
45M
VLOP/VLOSE
6%
Fine cap
DSA questions this hub helps answer
Which service tier applies?
Start with the function performed for recipients: mere conduit, caching, or hosting. Then test public dissemination, marketplace distance-contract flows, online search, enterprise-size exclusions, EU recipient counts, and Commission designation because each layer changes the obligation set.
Which trust-and-safety controls are required?
Map notice and action, trusted-flagger priority, statement-of-reasons delivery, internal complaints, out-of-court dispute links, repeat-abuse suspension, and transparency reporting.
Is the service in VLOP or VLOSE territory?
Publishing at least 45 million average monthly active EU recipients does not itself complete designation. Track the Commission decision and notification date because the enhanced VLOP/VLOSE duties attach to the designated service on its four-month application clock.
Service classification
Notice and action
Transparency reports
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Feb 23, 2026
Updated
Jul 16, 2026

The DSA applies service by service to intermediary services offered to recipients in the EU, regardless of where the provider is established. Mere technical accessibility from the EU is not enough by itself: document establishment, targeting, or significant EU use before assigning duties.

DSA Milestones

Track cited-source DSA applicability and reporting events

Use the DSA milestones for regulation application, VLOP/VLOSE designation effects, average monthly active recipient publication, transparency-reporting templates, audit outputs, and enforcement events only where the source material supports the date and affected service category.

Loading timeline...
Recommended reading path

Choose the next DSA decision

New to the DSA? Start by classifying one service and its EU connection. If that record already exists, jump to the operating duty, disclosure, very-large-service control, enforcement question, or comparison you need.

1

Start here: scope and service tier

Decide whether the DSA applies to the service, then separate mere conduit, caching, hosting, platform, marketplace, search, and Commission-designated VLOP/VLOSE layers.

2

Moderation, reasons, and redress

Map the tier result into notice handling, moderation decisions, statements of reasons, internal complaints, dispute routes, operating controls, and retained evidence.

EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
Read guide
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
Read guide
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
Read guide
DSA notice and action plus statements of reasons guide
An official source Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
Read guide
DSA Notice and Action Workflow for Hosting Services and Online Platforms
An official source DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
Read guide
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
Read guide
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
Read guide
3

Product, advertising, and marketplace duties

Review user-facing design and data flows for ads, recommenders, minors, manipulative interfaces, and trader or product traceability where the relevant platform layer applies.

4

Transparency and recurring deadlines

Separate fixed application dates, event-driven statement submissions, six-month user-number updates, annual or VLOP/VLOSE reporting cycles, and template transition rules.

5

VLOP and VLOSE assurance

For a Commission-designated service, connect systemic-risk work to mitigation, independent audit, data access, governance, and crisis-response evidence.

7

Compare regimes or answer a focused question

Keep the DSA distinct from the DMA, GDPR, P2B Regulation, Terrorist Content Online Regulation, and UK Online Safety Act, or go directly to a concise DSA answer.

DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
Read guide
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
Read guide
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
Read guide
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
Read guide
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.
Read guide
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
Read guide
Next step

Turn DSA scope into controls, disclosures, and evidence

This hub is the shared starting point for DSA implementation. Confirm the service tier first, then assign article-level work to trust and safety, policy, legal, marketplace, ads, recommender, data, reporting, and engineering owners who can change the service and maintain the public evidence.

What this unlocks
  • Start with one service boundary: EU targeting or establishment, intermediary role, hosting function, online-platform features, marketplace distance-contract flows, online search, average monthly active EU recipients, and any Commission designation status.
  • For hosting and online-platform workflows, operationalize intake and user remedies: Article 16 notices, trusted-flagger priority, Article 17 statements of reasons, internal complaint handling, out-of-court dispute signposting, repeat-abuse suspension, and DSA Transparency Database submissions where applicable.
  • For ads, recommenders, and marketplace flows, check the user interface: ad labels and sponsor/payment information, recommender main parameters and choice controls, profiling restrictions for minors, trader identity checks, product or service information fields, and consumer notices for illegal offers.
  • For VLOPs and VLOSEs, build a standing evidence pack: user-number methodology, systemic-risk assessment, mitigation measures, compliance function governance, independent audit, audit implementation report, regulator and vetted-researcher data access process, non-profiling recommender option, and ad repository.
EU DSA artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.