The Digital Services Act and GDPR often apply to the same feature, but compliance with one does not satisfy the other. The DSA classifies the service and governs platform processes such as illegal-content handling, moderation explanations, advertising and recommender transparency, trader traceability, and systemic-risk governance. GDPR governs each processing operation involving , including its lawful basis, transparency, rights, security, retention, transfers, and controller or processor accountability.
Side-by-side comparison
DSA vs GDPR: practical differences for online services
Use these rows to decide which law controls the workstream, what evidence belongs on each side, and where the same product feature needs both.
The DSA side focuses on intermediary-service and online-platform governance: illegal-content processes, content moderation, marketplace duties, ads, recommenders, transparency, complaint routes, and VLOP/VLOSE systemic risks.
Second framework
GDPR
The GDPR side focuses on personal-data processing: lawful basis, transparency, rights, controller and processor roles, security, breach response, DPIAs, transfers, retention, and accountability.
DSA vs GDPR: practical differences for online services
Intermediary services offered to recipients in the Union, with duties increasing for hosting services, online platforms, marketplaces, and VLOPs/VLOSEs.
DSA advertising work covers ad labelling, information about who presented and paid for the ad, targeting parameters, restrictions on certain profiling-based ads, and VLOP/VLOSE ad repositories where applicable.
GDPR advertising work covers the lawful basis for processing, consent or legitimate-interest analysis where used, profiling transparency, special-category limits, objection rights, and automated-decision safeguards where applicable.
DSA recommender work covers clear terms explaining main parameters, user options to modify or influence those parameters, and for VLOPs/VLOSEs at least one option not based on profiling.
GDPR recommender work covers whether the system processes , whether it profiles users, what lawful basis applies, what transparency is given, and whether it makes a decision based solely on automated processing that produces legal or similarly significant effects under Article 22. Profiling alone does not automatically trigger Article 22.
The DSA has applied generally since 17 February 2024. Other clocks depend on the event: content or account decisions, statement-of-reasons submission, transparency reporting, six-monthly AMAR publication, regulator requests, and the four-month period after VLOP/VLOSE designation.
A GDPR rights request normally has a one-month response period, extendable by two months for complexity or volume with timely notice. A qualifying breach notification is due without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to create a risk. DPIAs and any required prior consultation occur before the high-risk processing starts.
DSA enforcement involves Digital Services Coordinators and Commission powers for VLOPs/VLOSEs. The DSA permits Commission fines up to 6% of worldwide annual turnover for relevant VLOP/VLOSE infringements and lower caps for certain information failures.
GDPR enforcement involves supervisory authorities, cooperation and consistency mechanisms, corrective powers, and administrative fines. Serious GDPR infringements can reach EUR 20 million or 4% of total worldwide annual turnover, whichever is higher.
Escalate to the regulator route tied to the actual issue: platform governance under DSA, personal-data processing under GDPR, or both when the facts overlap.
DSA work focuses on high levels of privacy, safety, and security for minors on online platforms, plus limits on presenting ads based on profiling when the provider knows with reasonable certainty that the recipient is a minor.
GDPR work focuses on child-specific transparency, child consent rules for information-society services when consent is the lawful basis, and special care when legitimate interests may be overridden by a child's rights and freedoms.
Age assurance, default settings, ad limits, and child notices should be reviewed together, but the DSA safety file and the GDPR child-data file should remain distinct.
DSA transparency includes platform terms, content-moderation explanations, statement-of-reasons records, transparency reports, ad disclosures, recommender explanations, AMAR publication, and VLOP/VLOSE risk and audit publication where applicable.
GDPR transparency includes Articles 12 to 14 notices, information about purposes, lawful basis, recipients, retention, rights, complaint routes, profiling, and international transfers where applicable.
Intermediary services offered to recipients in the Union, with duties increasing for hosting services, online platforms, marketplaces, and VLOPs/VLOSEs.
DSA advertising work covers ad labelling, information about who presented and paid for the ad, targeting parameters, restrictions on certain profiling-based ads, and VLOP/VLOSE ad repositories where applicable.
GDPR advertising work covers the lawful basis for processing, consent or legitimate-interest analysis where used, profiling transparency, special-category limits, objection rights, and automated-decision safeguards where applicable.
DSA recommender work covers clear terms explaining main parameters, user options to modify or influence those parameters, and for VLOPs/VLOSEs at least one option not based on profiling.
GDPR recommender work covers whether the system processes , whether it profiles users, what lawful basis applies, what transparency is given, and whether it makes a decision based solely on automated processing that produces legal or similarly significant effects under Article 22. Profiling alone does not automatically trigger Article 22.
The DSA has applied generally since 17 February 2024. Other clocks depend on the event: content or account decisions, statement-of-reasons submission, transparency reporting, six-monthly AMAR publication, regulator requests, and the four-month period after VLOP/VLOSE designation.
A GDPR rights request normally has a one-month response period, extendable by two months for complexity or volume with timely notice. A qualifying breach notification is due without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to create a risk. DPIAs and any required prior consultation occur before the high-risk processing starts.
DSA enforcement involves Digital Services Coordinators and Commission powers for VLOPs/VLOSEs. The DSA permits Commission fines up to 6% of worldwide annual turnover for relevant VLOP/VLOSE infringements and lower caps for certain information failures.
GDPR enforcement involves supervisory authorities, cooperation and consistency mechanisms, corrective powers, and administrative fines. Serious GDPR infringements can reach EUR 20 million or 4% of total worldwide annual turnover, whichever is higher.
Escalate to the regulator route tied to the actual issue: platform governance under DSA, personal-data processing under GDPR, or both when the facts overlap.
DSA work focuses on high levels of privacy, safety, and security for minors on online platforms, plus limits on presenting ads based on profiling when the provider knows with reasonable certainty that the recipient is a minor.
GDPR work focuses on child-specific transparency, child consent rules for information-society services when consent is the lawful basis, and special care when legitimate interests may be overridden by a child's rights and freedoms.
Age assurance, default settings, ad limits, and child notices should be reviewed together, but the DSA safety file and the GDPR child-data file should remain distinct.
DSA transparency includes platform terms, content-moderation explanations, statement-of-reasons records, transparency reports, ad disclosures, recommender explanations, AMAR publication, and VLOP/VLOSE risk and audit publication where applicable.
GDPR transparency includes Articles 12 to 14 notices, information about purposes, lawful basis, recipients, retention, rights, complaint routes, profiling, and international transfers where applicable.
Start with the activity. If the issue is content moderation, marketplace traceability, platform terms, notices about illegal content, recommender choices, ad labelling, transparency reports, or VLOP/VLOSE systemic-risk files, the DSA workstream is likely in view.
If the issue is collecting, using, disclosing, storing, profiling, securing, deleting, transferring, or responding to requests about , the GDPR workstream is in view. Many ad, recommender, safety, and moderation systems need both workstreams because the DSA governs platform behaviour while GDPR governs the personal-data processing behind it.
DSA evidence should show the service category, moderation workflow, user-facing explanations, complaint route, transparency report inputs, advertising or recommender disclosure, and VLOP/VLOSE risk controls where applicable.
GDPR evidence should show the controller or processor role, lawful basis, notice content, data-subject rights handling, RoPA entry, security measures, DPIA where required, breach assessment, transfer safeguard, and retention rule.
Do not treat DSA transparency as a substitute for GDPR transparency. A statement of reasons for moderation and a privacy notice for personal-data processing serve different legal functions.
Overlap is common in ads, recommenders, age assurance, anti-abuse tooling, account enforcement, trusted flagger queues, research access, and transparency reporting. The same event can create a DSA record and a GDPR record: for example, a content demotion may need a DSA moderation explanation and a GDPR assessment if profiling, special-category data, automated decision-making, or user-rights requests are involved.
A useful operating model keeps one product inventory but two legal views. The DSA view classifies the service and platform obligation. The GDPR view classifies the processing purpose, lawful basis, role, data categories, recipients, retention, and data-subject impact.
For advertising, keep DSA ad-label and repository evidence separate from GDPR lawful-basis, consent, legitimate-interest, profiling, and transparency evidence.
For recommender systems, keep DSA parameter and non-profiling-option evidence separate from GDPR profiling, transparency, and automated-decision evidence.
For minors, keep DSA safety-by-design and age-assurance evidence separate from GDPR child-consent, child-specific transparency, and data-minimisation evidence.
Under the DSA, an online-platform user may be dealing with notice-and-action, a moderation restriction, an internal complaint system, an out-of-court dispute settlement body, or a complaint to a Digital Services Coordinator. The evidence should show what action the platform took on content, accounts, goods, services, ads, or platform terms.
Under GDPR, the person is asserting rights over or complaining that processing infringes GDPR. The evidence should show identity checks where needed, the request or complaint type, deadline handling, data located, exemptions considered, response given, and any supervisory-authority correspondence.
A DSA appeal file should explain the platform decision and the DSA route offered to the recipient of the service.
A GDPR rights file should show the data-subject request, the controller response, and the basis for any refusal or restriction.
If one user message includes both a moderation appeal and a data-access request, split it into both queues instead of forcing one route to absorb the other.
DSA enforcement evidence usually starts with the provider's service category and the obligation tier. For VLOPs and VLOSEs, the record expands to user-number evidence, risk assessments, mitigation measures, audits, data-access handling, recommender options, advertising transparency, and Commission or Digital Services Coordinator communications.
GDPR enforcement evidence starts with the processing operation. A controller or processor should be able to show why processing is lawful, what notice was given, how rights are handled, what security measures exist, how breaches are assessed and notified, how processors are instructed, and how transfers and retention are controlled.
Keep DSA content-moderation logs and statement-of-reasons exports with platform-policy, notice, action, complaint, and report fields.
Keep GDPR RoPA, DPIA, data-rights, breach, processor, transfer, and retention records with processing-purpose and lawful-basis fields.
Where a shared system feeds both regimes, add obligation labels to the evidence so a reviewer can see which record supports DSA, GDPR, or both.
DSA timing is driven by service launch, platform-status changes, content or account decisions, statement-of-reasons submission, transparency reporting, average monthly active recipient (AMAR) updates, VLOP/VLOSE designation, risk assessment, audit, and regulator requests. The DSA has applied generally since 17 February 2024; designated VLOPs and VLOSEs must comply with the enhanced layer four months after notification of the designation decision.
GDPR does not use one platform deadline. A controller normally answers a data-subject request within one month, with a possible two-month extension for complexity or volume if the person is told within the first month. A controller must notify the competent supervisory authority of a personal-data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to risk individuals' rights and freedoms. A DPIA must occur before processing likely to result in high risk, and prior consultation is required if residual high risk remains.
6
Section 6
Enforcement
DSA enforcement involves Digital Services Coordinators and Commission powers for VLOPs/VLOSEs. The DSA permits Commission fines up to 6% of worldwide annual turnover for relevant VLOP/VLOSE infringements and lower caps for certain information failures.
GDPR enforcement involves supervisory authorities, cooperation and consistency mechanisms, corrective powers, and administrative fines. Serious GDPR infringements can reach EUR 20 million or 4% of total worldwide annual turnover, whichever is higher.
7
Section 7
Overlap and reuse
DSA work focuses on high levels of privacy, safety, and security for minors on online platforms, plus limits on presenting ads based on profiling when the provider knows with reasonable certainty that the recipient is a minor.
GDPR work focuses on child-specific transparency, child consent rules for information-society services when consent is the lawful basis, and special care when legitimate interests may be overridden by a child's rights and freedoms.
8
Section 8
Practical decision rule
DSA transparency includes platform terms, content-moderation explanations, statement-of-reasons records, transparency reports, ad disclosures, recommender explanations, AMAR publication, and VLOP/VLOSE risk and audit publication where applicable.
GDPR transparency includes Articles 12 to 14 notices, information about purposes, lawful basis, recipients, retention, rights, complaint routes, profiling, and international transfers where applicable.
Recommended next step
Build one inventory with two legal views
Sorena can help turn a shared platform, ad, recommender, or moderation system into separate DSA and GDPR evidence views without merging the underlying duties.