Calendar GuideEU DSA

EU Digital Services Act deadlines and compliance calendar

Track the DSA dates that change operating work: application, user-number publication, VLOP/VLOSE designation, transparency reports, and statement-of-reasons submissions.

This page maps official DSA clocks to calendar records for legal, trust and safety, product, marketplace operations, data, and compliance teams.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this DSA calendar by service, not by company alone. First classify each service as an intermediary service, hosting service, online platform, online search engine, or designated , and calendar its publication where applicable. Then apply the fixed dates, recurring reporting periods, designation-triggered deadlines, and event-driven submissions that match that service. Micro and small enterprise exclusions can remove some duties, but they do not remove every DSA obligation.

Section 1

Fixed DSA application dates to anchor the calendar

The DSA applies generally from 17 February 2024. A defined set of provisions applied earlier from 16 November 2022, including Article 24(2), (3), and (6) and Article 33(3) to (6). Those provisions enabled active-recipient publication, information requests, and designation before full application.

For providers within Article 15, the first annual content-moderation reporting cycle began with full application. Article 15(2) excludes providers that qualify as micro or small enterprises under Recommendation 2003/361/EC unless they are designated VLOPs. That exemption must be tested separately from Article 19, which excludes qualifying micro and small online platforms from most online-platform-specific duties but preserves Article 24(3) authority requests.

  • 16 November 2022: selected DSA provisions began to apply, including Article 24(2), Article 24(3), Article 24(6), and Article 33(3) to (6).
  • 17 February 2023: providers had to publish average monthly active recipient information for each online platform or online search engine, calculated over the previous six months, and update it at least once every six months.
  • 17 February 2024: the DSA applied generally, and Member States had to designate their Digital Services Coordinators by this date.
  • Calendar evidence: record the legal basis, affected service, provider role, any size-based exclusion, Article 24 publication URL, calculation period, and next review date.
Section 2

VLOP and VLOSE designation clocks

A service falls within the Article 33 designation test when it has at least 45 million in the Union and the Commission designates it. Crossing the numerical threshold does not by itself complete designation. The Commission may rely on published figures, requested information, or other available information and must notify its decision.

The Section 5 obligations for a designated VLOP or VLOSE apply four months after notification to the provider. The first cohort comprised 17 VLOPs and 2 VLOSEs designated on 25 April 2023; the Commission stated that their additional obligations applied from the end of August 2023.

  • Trigger: the service has at least 45 million in the Union and receives a Commission designation decision.
  • Clock: the Section 5 obligations apply four months after notification of the designation; calculate the due date from the service's actual notification record.
  • First designation cohort: 25 April 2023 designation of 17 VLOPs and 2 VLOSEs.
  • Evidence to retain: designation decision or Commission list entry, service name, provider entity, notified date, four-month due date, systemic-risk workstream, audit plan, data-access owner, ad-repository owner, and recommender-system owner.
  • Ongoing watch: the Commission must terminate designation if the service remains below the threshold for an uninterrupted year; the Section 5 obligations cease four months after notification of that termination.
Section 3

Transparency-report calendar and reporting periods

Providers subject to Article 15 must publish content-moderation reports at least annually. The first cycle after full application ended when the provider published its first report, no later than 16 February 2025. A shortened transitional cycle then ran from the end of that provider's first reporting period through 31 December 2025.

Implementing Regulation (EU) 2024/2835 requires the Annex I CSV or XLSX templates for information covering content moderation from 1 July 2025. For the earlier part of the transitional cycle, template use was encouraged but not required. From 1 January 2026, the ordinary annual period is 1 January to 31 December, with publication no later than two months after period end.

  • By 16 February 2025: publish the first Article 15 annual transparency report after full DSA application, if Article 15 applies to the provider.
  • After the first report through 31 December 2025: run the provider-specific shortened transitional cycle.
  • 1 July 2025: begin collecting and reporting content-moderation information under the Annex I instructions and templates; template use for the earlier part of the transitional cycle was voluntary.
  • 31 December 2025: the transitional reporting cycle ends.
  • 1 January 2026 to 31 December 2026: first full harmonised annual reporting cycle for intermediary, hosting, and online-platform providers.
  • Publication clock: publish transparency reports at the latest two months after the relevant reporting period concludes.
  • Retention evidence: keep every published version publicly available for at least five years. Mark corrections as updated versions, identify the changes and reasons, and retain the earlier versions.
  • Exemption check: Article 15 reporting does not apply to a provider that qualifies as a micro or small enterprise unless it is a designated VLOP.
Section 4

Additional six-month reporting cadence for VLOPs and VLOSEs

Article 42 requires a VLOP or VLOSE to publish its first Article 15 report no later than two months after its Section 5 application date and then at least every six months. Implementing Regulation (EU) 2024/2835 now aligns those periods to 1 January through 30 June and 1 July through 31 December, with reports due no later than two months after each period.

The first cycle under the Annex I templates covered 1 July through 31 December 2025. From 2026, calendar two data-close and publication workstreams each year rather than calculating a rolling six-month date from an older report.

  • Designation calendar entry: record the notification date and the four-month application date for the service.
  • First report clock: two months from the service's DSA application date under the designation rule.
  • Recurring periods from 2026: 1 January through 30 June and 1 July through 31 December.
  • Publication clock: no later than two months after each half-year period ends.
  • Template transition: collect Annex I template data from 1 July 2025 for content moderation engaged in from that date.
  • First harmonised template cycle: 1 July 2025 to 31 December 2025.
  • Evidence fields: reporting period, publication date, service, EU active-recipient count, moderator resources, language coverage, automated-moderation metrics, risk-assessment link, audit-report link, and owner sign-off.
Section 5

Statement-of-reasons and Transparency Database calendar evidence

work is event driven. Article 17 requires a hosting service to notify an affected recipient at the latest when it imposes a covered restriction, but only when the provider knows the relevant electronic contact details. Article 17 does not apply to deceptive high-volume commercial content or to Article 9 orders. Article 24(5) separately requires covered online platforms to submit the Article 17 decisions and statements to the Commission database without undue delay and without personal data.

Article 19 can exclude a qualifying micro or small online platform from Article 24(5), but not from the underlying Article 17 hosting duty. The operating control should reconcile covered moderation decisions, user notices, personal-data removal, and database submission status on a frequency proportionate to moderation volume.

  • Trigger event: a hosting service with the recipient's electronic contact details restricts visibility, monetary payments, service access, or an account because recipient-provided information is allegedly illegal or incompatible with its terms, subject to the Article 17 exclusions.
  • Submission event: online platforms subject to Article 24(5) submit Article 17 decisions and statements of reasons to the Commission database without undue delay and without personal data.
  • Daily evidence: moderation decision ID, restriction type, legal or terms basis, user-notice timestamp, personal-data scrub check, database submission timestamp, failed-submission retry status, and reconciliation owner.
  • Database retention awareness: the Commission FAQ says statements are available from the following day, removed from search after 180 days, retained in downloadable daily dumps for 540 days, and included in dashboard aggregates for five years. The FAQ says this operational retention policy may change, so do not treat it as a statutory provider-retention period.
  • Calendar review: reconcile provider moderation logs against database submissions at a frequency that matches the platform's moderation volume.
Section 6

Practical DSA calendar records to maintain

Keep separate records for fixed legal dates, repeating reporting periods, designation-triggered deadlines, and event-driven submissions. The provider-level entity is not enough when different services fall into different DSA categories or only one service has been designated.

Use one line per service and legal clock. Record each exclusion decision and its evidence. Apply deadlines only to designated services, and keep the Commission database's operational retention policy separate from the provider's legal record-retention rules.

  • Service profile: service name, provider entity, DSA category, Member State of establishment or legal-representative route, Digital Services Coordinator, enterprise-size assessment where relevant, and designation status.
  • AMAR record: six-month measurement period, Article 24(2) publication date, public URL, EU count, Member State breakdown if prepared, methodology owner, and next update date.
  • Designation record: Commission designation date, notification date, four-month application date, designation status, and link to Commission list or decision.
  • Transparency-report record: Article 15 applicability, reporting period start and end, template version, CSV or XLSX publication due date, public URL, five-year retention end date, and correction/version history.
  • record: Article 17 applicability, user-notice timestamp, Article 24(5) applicability, reconciliation period, submission count, rejected-submission count, personal-data scrub outcome, and issue owner.
  • Evidence rule: every calendar line should cite an official external source URL and state whether the date is fixed by law, repeated by cadence, triggered by designation, or triggered by a moderation event.
Recommended next step

Track DSA dates as service-level evidence records

Use the calendar structure on this page to track which DSA dates apply to each service, which clocks repeat, and which evidence proves publication, reporting, designation, and database submission.

Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Supports statement-of-reasons reconciliation fields and identifies the database retention periods as an operational policy that may change.
"Search data will be retained for six months (180 days)."
digital-strategy.ec.europa.eu
Referenced sections
  • Commission overview confirming the 45 million monthly-user threshold, six-month user-number updates, and four-month compliance period after designation.
"has 4 months to comply with the DSA"
eur-lex.europa.eu
Referenced sections
  • Articles 17, 19, and 24(5) support the covered restrictions, contact-detail and content exclusions, timing of the user notice, micro and small online-platform exclusion, and database submission without personal data.
"submit to the Commission the decisions and the statements of reasons"
Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA Article 28 minors protection guide for online platforms
EU Digital Services Act guide to Article 28 minors protection: platform scope, child-safety measures, targeted ads limits, recommender controls, and official source evidence.
DSA average monthly active recipients: what platforms must publish
An official source FAQ on average monthly active recipients under the EU Digital Services Act, including publication, EU recipient scope, the 45 million VLOP/VLOSE threshold, and evidence records.
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA Enforcement and Penalties in the EU
How Digital Services Act enforcement works: Commission and Digital Services Coordinator roles, VLOP and VLOSE investigations, fines, periodic penalty payments, and evidence readiness.
DSA illegal content notices: what must be included?
An official source FAQ on EU Digital Services Act illegal-content notices: Article 16 notice elements, acknowledgement, decision notices, trusted flagger priority, statements of reasons, and records.
DSA Marketplace Trader Traceability FAQ
Answer to what EU Digital Services Act Article 30 requires online marketplaces to collect, verify, display, retain, and evidence for trader traceability.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA recommender transparency FAQ: Article 27 and VLOP options
What EU Digital Services Act recommender transparency requires: main parameters, user options, VLOP/VLOSE non-profiling choices, and evidence to keep.
DSA researcher data access for VLOPs and VLOSEs
Article 40 DSA guide to vetted researcher access for VLOPs and VLOSEs under Regulation (EU) 2025/2050: requests, data catalogues, security, deadlines, and records.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons FAQ
When DSA statements of reasons are required, what they must contain, when online platforms submit them to the DSA Transparency Database, and what appeal records to keep.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits
What VLOPs and VLOSEs must assess under the EU Digital Services Act, when to reassess, how Article 35 mitigation and annual audit evidence fit together, and what records to keep.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
EU Digital Services Act penalties and fines: caps and enforcement roles
DSA penalty caps and enforcement roles: Member State fines, Commission fines for VLOPs and VLOSEs, 1% procedural fines, and 5% periodic penalty payments.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA Transparency Calendar: reporting, SoR database, AMAR updates
Build a DSA transparency calendar for annual reports, statement-of-reasons database submissions, active-recipient updates, and VLOP/VLOSE audit touchpoints.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.