EU Digital Services Act Scope, Platform Duties, and VLOP Readiness
This DSA hub helps decide whether a particular service is in scope, classify its intermediary tier, and find the duties that follow for hosting, platform, marketplace, search, and designated very-large-service features.
Follow the grouped guides in order: establish EU scope and service tier, assign the matching operating duties, then add reporting, marketplace, , and enforcement evidence only where the classification supports it.
The DSA has applied generally since 17 February 2024. It applies service by service to offered to recipients in the EU, regardless of where the provider is established. Mere technical accessibility from the EU is not enough by itself: document establishment, targeting, or significant EU use before assigning duties. supervise providers established in their Member State, while the Commission has the DSA's specified powers for VLOPs and VLOSEs.
Track cited-source DSA applicability and reporting events
Use the DSA milestones for regulation application, designation effects, average monthly active recipient publication, transparency-reporting templates, audit outputs, and enforcement events only where the source material supports the date and affected service category.
Choose the next DSA decision
New to the DSA? Start by classifying one service and its EU connection. If that record already exists, jump to the operating duty, disclosure, very-large-service control, enforcement question, or comparison you need.
Start here: scope and service tier
Decide whether the DSA applies to the service, then separate mere conduit, caching, hosting, platform, marketplace, search, and Commission-designated VLOP/VLOSE layers.
Moderation, reasons, and redress
Map the tier result into notice handling, moderation decisions, statements of reasons, internal complaints, dispute routes, operating controls, and retained evidence.
Product, advertising, and marketplace duties
Review user-facing design and data flows for ads, recommenders, minors, manipulative interfaces, and trader or product traceability where the relevant platform layer applies.
Transparency and recurring deadlines
Separate fixed application dates, event-driven statement submissions, six-month user-number updates, annual or VLOP/VLOSE reporting cycles, and template transition rules.
VLOP and VLOSE assurance
For a Commission-designated service, connect systemic-risk work to mitigation, independent audit, data access, governance, and crisis-response evidence.
Supervision and enforcement
Understand the different roles of Digital Services Coordinators and the Commission, the relevant investigation powers, and the conditions behind penalty caps.
Compare regimes or answer a focused question
Keep the DSA distinct from the DMA, GDPR, P2B Regulation, Terrorist Content Online Regulation, and UK Online Safety Act, or go directly to a concise DSA answer.
Turn DSA scope into controls, disclosures, and evidence
This hub is the shared starting point for DSA implementation. Confirm the service tier first, then assign article-level work to trust and safety, policy, legal, marketplace, ads, recommender, data, reporting, and engineering owners who can change the service and maintain the public evidence.
- Start with one service boundary: EU targeting or establishment, intermediary role, hosting function, online-platform features, marketplace distance-contract flows, online search, average monthly active EU recipients, and any Commission designation status.
- For hosting and online-platform workflows, operationalize intake and user remedies: Article 16 notices, trusted-flagger priority, Article 17 statements of reasons, internal complaint handling, out-of-court dispute signposting, repeat-abuse suspension, and DSA Transparency Database submissions where applicable.
- For ads, recommenders, and marketplace flows, check the user interface: ad labels and sponsor/payment information, recommender main parameters and choice controls, profiling restrictions for minors, trader identity checks, product or service information fields, and consumer notices for illegal offers.
- For VLOPs and VLOSEs, build a standing evidence pack: user-number methodology, systemic-risk assessment, mitigation measures, compliance function governance, independent audit, audit implementation report, regulator and vetted-researcher data access process, non-profiling recommender option, and ad repository.
