DSA Complaint Workflow GuideEU

DSA complaint and dispute workflows for online platforms

This page helps structure the user-facing and back-office process for moderation complaints, notice/action appeals, statements of reasons, and certified out-of-court dispute settlement under the EU Digital Services Act.

The workflow is written for trust and safety, policy, legal, support, product, and reporting teams that need a concrete operating record for DSA Article 17, Article 20, Article 21, and Article 24(5) work.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The DSA workflow applies when an online platform decides whether to act on an Article 16 notice or makes a covered decision affecting content visibility, service access, an account, or monetisation because information is alleged to be illegal or incompatible with its terms. The platform must keep the complaint route open for at least six months after informing the recipient or notice submitter. The workflow connects the original notice or moderation decision, the , the complaint record, the reasoned outcome, out-of-court dispute information, and the data needed for transparency reporting.

Section 1

Scope: which moderation decisions belong in the workflow

This workflow supports online platform decisions covered by the DSA -handling rules: whether to remove, disable access to, restrict visibility of, or leave up information after a notice; whether to suspend or terminate a service or account; and whether to suspend, terminate, or otherwise restrict monetisation. The complaint channel must also cover individuals or entities that submitted notices when the platform decided not to act on the notice.

Before building the queue, confirm the service role and enterprise-size treatment. The DSA Article 20 rules sit in the online-platform section, which Article 19 excludes for qualifying micro and small online-platform providers subject to its 12-month post-loss and VLOP rules. Recommendation 2003/361/EC sets the size tests: fewer than 10 staff and no more than EUR 2 million annual turnover or balance-sheet total for a microenterprise, and fewer than 50 staff and no more than EUR 10 million for a small enterprise, after counting partner and linked enterprises as required. Article 17 statements of reasons sit in the hosting section and are not removed by that platform-section exclusion.

  • Trigger record: original notice, own-initiative moderation event, terms-enforcement event, account/service restriction, or monetisation restriction.
  • Eligibility record: affected recipient or notice submitter, decision date, electronic contact details where known, and whether the six-month complaint access period is still open.
  • Decision basis: alleged illegality, terms-and-conditions incompatibility, or both, with the legal or contractual ground used in the .
  • Exclusion check: do not force non-Article 20 issues into this workflow; route general DSA infringement complaints to the relevant Digital Services Coordinator process instead.
Section 2

Internal complaint-handling workflow

The system should be an electronic, free-of-charge path that is easy to access and user-friendly. It should help users submit sufficiently precise and adequately substantiated complaints without requiring them to understand internal policy taxonomies.

Treat the appeal as a review of the original moderation decision, not as a customer-support message. Article 20 requires timely, non-discriminatory, diligent, and non-arbitrary handling, and the final complaint decision must be supervised by appropriately qualified staff rather than made solely by automated means.

  • Intake fields: complainant type, affected content or account, original decision identifier, notice identifier if any, submitted evidence, requested outcome, language, and contact channel.
  • Reviewer fields: policy/legal ground, terms clause, illegal-content category where relevant, automation used in the original decision, human reviewer, escalation owner, and conflict-of-interest check.
  • Outcome fields: uphold, reverse, partly reverse, or reject; reasoned explanation; implementation action; date the complainant was informed; and redress information provided.
  • Reversal trigger: if the complaint gives sufficient grounds that the original refusal to act was unfounded, the information is not illegal or terms-incompatible, or the complainant's conduct did not warrant the measure, reverse without undue delay.
  • Procedural control: keep the complaint pathway available for at least six months from the date the recipient was informed of the relevant decision.
Section 3

Statements of reasons and notice/action appeal records

The user must be able to understand the original moderation decision. For each covered restriction, the should identify the measure, territorial scope and duration where relevant, the facts and circumstances relied on, any automated means used, the legal or contractual ground, and the available redress options.

Notice/action appeals need two linked records: the notifier-facing decision after the Article 16 notice and the affected-recipient when content or account restrictions are imposed. Keeping those records linked avoids losing the reason why a notice was rejected, why content was restricted, or why a later complaint reversed the outcome.

  • Statement-of-reasons link: moderation decision ID, content or account ID, affected recipient, restriction type, territorial scope, duration, facts, legal ground, terms ground, automation flag, and redress text.
  • Notice/action link: notice ID, notifier contact if supplied, notice receipt confirmation, decision on the notice, redress information sent to the notifier, and any affected-recipient .
  • Database submission check: online platforms covered by Article 24(5) submit Article 17 decisions and statements of reasons to the Commission's public machine-readable database without personal data; record any Article 19 exclusion.
  • Privacy check: remove personal data before DSA Transparency Database submission and do not include redress options in public database exports when those options are relevant only to the statement recipient.
Section 4

Out-of-court dispute settlement hand-off

The user-facing response should clearly explain certified and other redress options. Article 21 does not require the recipient to exhaust the platform's system first: eligible disputes include complaints that were not resolved internally, and the recipient may select any certified body whose expertise and language coverage fit. The body does not need to be based in the recipient's country.

The hand-off should not suggest that out-of-court dispute bodies bind the parties. Under Article 21, both parties must engage in good faith with the selected certified body, but the certified body cannot impose a binding settlement. Court proceedings remain available under applicable law.

  • ODS information block: link to the Commission list of certified bodies, how to check expertise, covered platforms or dispute types, languages, fees, and rules of procedure.
  • Platform response record: selected body, dispute scope, whether the same information and same grounds were already resolved, good-faith engagement steps, documents sent, and final outcome.
  • Cost rule checkpoint: if the body decides in favour of the recipient or notice submitter, the online platform bears the body fees and reimburses reasonable expenses paid in relation to the dispute settlement.
  • Adverse-outcome checkpoint: if the body decides in favour of the platform, the recipient or notice submitter does not reimburse the platform's fees or expenses unless the body finds manifest bad faith. The dispute route must otherwise be free of charge or available for a nominal fee, disclosed before the process begins.
  • Resolution timing checkpoint: certified bodies must make decisions available to the parties within a reasonable period and no later than 90 calendar days after receiving the complaint, extendable by up to another 90 days for highly complex disputes.
Section 5

Operational records and quality checks

A durable DSA complaint workflow should produce records that explain what happened to the user, what the platform reviewed, who supervised the decision, what was changed, and what was reported. These records should be specific enough for transparency reporting, regulator questions, user follow-up, and internal quality sampling.

Review the workflow periodically against real cases. The most important quality signals are reversals, late responses, unsupported legal or terms grounds, automation-only outcomes, missing redress text, missing DSA Transparency Database submissions, and repeat disputes sent to certified bodies.

  • Complaint register fields: original decision type, complaint eligibility, complaint submission date, review owner, human supervision, outcome, reversal reason, user notification, ODS information provided, and closure action.
  • ODS reporting fields: number of disputes submitted to certified bodies, outcomes, median completion time, and share of disputes where the platform implemented the body's decision.
  • Misuse control: record any suspension of processing for manifestly unfounded notices or complaints only after the case-by-case assessment, prior warning, and terms-policy basis required by Article 23.
  • Quality sample: compare statements of reasons against complaint outcomes to find vague terms references, missing facts, unexplained automation, or redress wording that does not match the user journey.
Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Commission FAQ explains what statements of reasons contain, public database access, removal of personal data, and database retention behavior.
"publicly accessible and machine-readable"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission transparency page explains that online-platform transparency reports include out-of-court dispute settlement information and misuse suspensions.
"out-of-court dispute settlements"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission overview explaining that users can appeal content moderation decisions through the platform or a certified out-of-court body.
"Options to appeal to content moderation decisions"
eur-lex.europa.eu
Referenced sections
  • Articles 23 and 24 support records for misuse suspensions, out-of-court dispute metrics, and statement-of-reasons database submissions.
"the number of disputes submitted"
Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA Article 28 minors protection guide for online platforms
EU Digital Services Act guide to Article 28 minors protection: platform scope, child-safety measures, targeted ads limits, recommender controls, and official source evidence.
DSA average monthly active recipients: what platforms must publish
An official source FAQ on average monthly active recipients under the EU Digital Services Act, including publication, EU recipient scope, the 45 million VLOP/VLOSE threshold, and evidence records.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA Enforcement and Penalties in the EU
How Digital Services Act enforcement works: Commission and Digital Services Coordinator roles, VLOP and VLOSE investigations, fines, periodic penalty payments, and evidence readiness.
DSA illegal content notices: what must be included?
An official source FAQ on EU Digital Services Act illegal-content notices: Article 16 notice elements, acknowledgement, decision notices, trusted flagger priority, statements of reasons, and records.
DSA Marketplace Trader Traceability FAQ
Answer to what EU Digital Services Act Article 30 requires online marketplaces to collect, verify, display, retain, and evidence for trader traceability.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA recommender transparency FAQ: Article 27 and VLOP options
What EU Digital Services Act recommender transparency requires: main parameters, user options, VLOP/VLOSE non-profiling choices, and evidence to keep.
DSA researcher data access for VLOPs and VLOSEs
Article 40 DSA guide to vetted researcher access for VLOPs and VLOSEs under Regulation (EU) 2025/2050: requests, data catalogues, security, deadlines, and records.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons FAQ
When DSA statements of reasons are required, what they must contain, when online platforms submit them to the DSA Transparency Database, and what appeal records to keep.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits
What VLOPs and VLOSEs must assess under the EU Digital Services Act, when to reassess, how Article 35 mitigation and annual audit evidence fit together, and what records to keep.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
EU Digital Services Act penalties and fines: caps and enforcement roles
DSA penalty caps and enforcement roles: Member State fines, Commission fines for VLOPs and VLOSEs, 1% procedural fines, and 5% periodic penalty payments.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA deadlines and compliance calendar: application dates, reporting cycles, and VLOP clocks
Calendar view of cited EU Digital Services Act dates: full application, user-number publication, VLOP/VLOSE designation clocks, statements of reasons, and transparency reporting cycles.
EU DSA Transparency Calendar: reporting, SoR database, AMAR updates
Build a DSA transparency calendar for annual reports, statement-of-reasons database submissions, active-recipient updates, and VLOP/VLOSE audit touchpoints.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.