DSA comparisonTerrorist content online

DSA vs Terrorist Content Online Regulation

Separate the DSA's general content-governance duties from the Terrorist Content Online Regulation's removal-order workflow for hosting services.

This comparison helps route notices, authority orders, user explanations, evidence preservation, transparency reporting, and escalation ownership without merging two different legal tests.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The Digital Services Act and Terrorist Content Online Regulation can both govern one moderation event, but the trigger and clock differ. Use the DSA for the hosting service's general notice-and-action, explanation, complaint, transparency, and systemic-risk duties. Use Regulation (EU) 2021/784, which has applied since 7 June 2022, when a competent authority issues a : the provider must remove the identified content or disable access in all Member States as soon as possible and within one hour of receipt, subject to the Regulation's impossibility, clarification, review, and redress safeguards.

Side-by-side comparison

DSA vs Terrorist Content Online Regulation

Use these rows to decide which regime controls the work, what evidence proves compliance, and which team should own the next action.

Review all sources
First framework
Digital Services Act

Horizontal EU framework for intermediary services, including hosting and online platforms. It governs content-moderation process design, user-facing explanations, complaint routes, transparency reporting, and systemic-risk governance for very large services.

Second framework
Terrorist Content Online Regulation

Targeted EU framework for hosting service providers that receive terrorist-content removal orders. It requires an authority-order workflow, fast action, evidence preservation, complaint handling, and competent-authority communication.

Comparison row 1

Scope boundary

Digital Services Act

Intermediary services, hosting services, online platforms, online marketplaces, and very large online platforms or search engines, depending on the service feature and DSA tier.

Terrorist Content Online Regulation

Hosting service providers in relation to terrorist content covered by the TCO Regulation and removal orders issued by competent authorities.

Operational implication

A service can be in DSA scope without receiving TCO removal orders; TCO readiness becomes critical when the service hosts user content and may receive authority orders.

Comparison row 2

Covered actors

Digital Services Act

A DSA workflow is triggered by the service tier, user notices, trusted flagger notices, own-initiative moderation, user complaints, transparency-report cycles, or VLOP/VLOSE designation.

Terrorist Content Online Regulation

A TCO workflow is triggered by a competent-authority removal order, and may also require follow-up around preservation, complaint handling, and specific measures where the Regulation applies.

Operational implication

Treat user notices and authority orders as different intake types even when they concern the same item of content.

Comparison row 3

Trigger

Digital Services Act

DSA timing depends on the obligation: notices and complaints need prompt operational handling, statements of reasons follow moderation restrictions, transparency reports follow reporting cycles, and VLOP/VLOSE duties follow designation and recurring risk-governance work.

Terrorist Content Online Regulation

TCO removal orders are incident-speed work; the regulation is designed around removal or disabling of access within one hour after receipt of a valid removal order.

Operational implication

A daily or weekly DSA moderation review cadence is not enough for TCO; the removal-order channel needs on-call coverage and timestamped deadline calculation.

Comparison row 4

Core obligations

Digital Services Act

The DSA requires hosting providers to provide clear statements of reasons when they restrict user content, and online platforms must support internal complaint handling for covered moderation decisions.

Terrorist Content Online Regulation

TCO has its own notification and complaint context around removed or disabled terrorist content, subject to the Regulation's safeguards and authority constraints.

Operational implication

Use separate message templates: DSA statements of reasons are not automatically sufficient for a TCO removal-order notice or complaint record.

Comparison row 5

Evidence record

Digital Services Act

DSA records should show service classification, notice source, moderation facts, legal or terms basis, statement of reasons, complaint outcome, transparency-report metrics, and VLOP/VLOSE risk evidence where applicable.

Terrorist Content Online Regulation

TCO records should show the authenticated removal order, issuing authority, receipt time, deadline, exact content locator, action in all Member States, authority response, six-month preservation period or extension, content-provider notice, complaint handling, cross-border scrutiny, and court correspondence.

Operational implication

Shared moderation tooling is acceptable only if it exports a record that preserves the legal basis, authority source, timestamp, action, reviewer, and appeal or complaint route.

Comparison row 6

Timing and deadlines

Digital Services Act

Digital Services Coordinators supervise DSA matters at Member State level, with the Commission directly supervising designated VLOPs and VLOSEs for the enhanced duties.

Terrorist Content Online Regulation

Competent authorities under the TCO Regulation issue removal orders and handle related authority communications.

Operational implication

Route authority correspondence by legal framework so a DSA supervisory inquiry and a TCO removal order do not land in the same unresolved queue.

Comparison row 7

Enforcement

Digital Services Act

A platform or search engine with average monthly active recipients in the Union equal to or higher than 45 million can be designated as a VLOP or VLOSE and must then manage enhanced DSA risks, audits, data access, advertising, recommender, and transparency obligations.

Terrorist Content Online Regulation

TCO does not become a VLOP/VLOSE risk program; it remains a removal-order and terrorist-content workflow even for very large services.

Operational implication

Use VLOP/VLOSE governance to test moderation-system resilience, but keep a separate TCO incident log for each authority order.

Comparison row 8

Overlap and reuse

Digital Services Act

DSA ownership usually spans legal, trust and safety, policy, product, marketplace operations, transparency reporting, data governance, and VLOP/VLOSE risk owners where applicable.

Terrorist Content Online Regulation

TCO ownership needs legal escalation, trust-and-safety operations, incident response, authority-response owners, and engineering support for fast removal, disabling, preservation, and audit logging.

Operational implication

Name two accountable owners: one for DSA governance and reporting, and one for TCO removal-order execution and evidence retrieval.

Comparison row 9

Practical decision rule

Digital Services Act

Intermediary services, hosting services, online platforms, online marketplaces, and very large online platforms or search engines, depending on the service feature and DSA tier.

Terrorist Content Online Regulation

Hosting service providers in relation to terrorist content covered by the TCO Regulation and removal orders issued by competent authorities.

Operational implication

A service can be in DSA scope without receiving TCO removal orders; TCO readiness becomes critical when the service hosts user content and may receive authority orders.

Practical decision rule

Decision rule for DSA and TCO work

  • Use the DSA track for service classification, notice-and-action design, statements of reasons, internal complaints, transparency reporting, trusted flagger handling, and VLOP/VLOSE systemic-risk governance.
  • Use the TCO track for competent-authority removal orders, one-hour response readiness, evidence preservation, TCO complaint handling, and authority communication.
  • Reuse moderation tooling only when each exported record identifies the legal basis, trigger source, authority or notice sender, timestamp, action, reviewer, notification status, and complaint route.
  • Escalate immediately when a moderation item is both a DSA content decision and a TCO authority order, because the TCO clock and evidence duties are separate.
Section 1

Use the DSA for content-governance design, not as a substitute for removal-order readiness

A DSA notice can tell a hosting provider that a user or trusted flagger believes content is illegal. A is different: it is an authority order under a separate Regulation and needs a response workflow that can authenticate the order, verify the addressee and deadline, locate the exact content, remove it or disable access in all Member States, preserve the required material, notify the authority, and record what was done.

The TCO Regulation covers hosting services that store and disseminate user-provided material to the public at the content provider's request and have a substantial connection to the EU. It does not cover mere conduit or caching services, infrastructure layers that do not store the material, email or private messaging, or cloud infrastructure that is not used to make stored material public at the content provider's direct request. A social network, public video or image-sharing service, public file-sharing service, or public-facing cloud feature can be in scope; classify each service surface on its actual use.

One moderation queue is not enough. DSA notice-and-action records, statement-of-reasons templates, and complaint outcomes are useful evidence, but they do not prove that the service can receive and execute a within the required clock.

  • Keep DSA notices, DSA own-initiative moderation, and TCO removal orders as separate intake categories.
  • Require every moderation record to show the legal basis, source of the trigger, reviewer, action, timestamp, user notice status, and appeal or complaint route.
  • Escalate authority orders to legal and trust-and-safety operations immediately; do not wait for ordinary DSA complaint or transparency-report cycles.
  • For the first removal order from an authority, expect information about procedures and deadlines at least 12 hours in advance unless the authority identifies a duly justified emergency. The one-hour clock still runs from receipt of the order.
Section 2

Evidence should prove which regime controlled the action

For DSA moderation, evidence normally starts with service classification, terms-and-conditions rules, notice intake, moderation decision facts, statement-of-reasons delivery, internal complaint outcomes, transparency-report inputs, and any VLOP or VLOSE risk-assessment material.

For TCO, the minimum useful record is different: the removal order, authenticated receiving channel, authority details, receipt timestamp, exact URL or other locator, deadline calculation, removal or disabling action across Member States, response to the authority, preservation period, content-provider notification handling, complaint handling, and any cross-border scrutiny or court challenge.

Preserve removed terrorist content and related data needed for review, complaints, or terrorism investigations for six months. A competent authority or court may request a further specified period when relevant proceedings are still underway. If force majeure or a de facto impossibility prevents action, or the order has manifest errors or insufficient information, notify the issuing authority without undue delay using the Regulation's process; do not silently treat the order as an ordinary moderation ticket.

  • Do not cite a DSA statement of reasons as the only evidence for a TCO removal order.
  • Do not bury TCO authority correspondence inside ordinary user-notice queues.
  • Use shared tooling only if the exported record keeps the DSA and TCO legal bases separate.
  • For a cross-border order, preserve the ability to reinstate content. The provider or content provider may request scrutiny by the authority in the provider's Member State of main establishment within 48 hours, but that safeguard does not pause the one-hour action requirement.
Section 3

Authorities and ownership should stay separate

The DSA supervision model uses Digital Services Coordinators, the European Commission, and the European Board for Digital Services, with direct Commission supervision for designated VLOPs and VLOSEs. That points ownership toward legal, trust and safety, policy, product, compliance, transparency reporting, data governance, and risk teams.

The TCO workflow needs an incident-style owner as well as legal oversight. The receiving team must be able to authenticate the authority channel, act on the content, preserve required records, respond to complaints, and brief leadership without disrupting ordinary DSA user-notice and complaint operations.

  • Assign one accountable owner for DSA service classification and transparency reporting.
  • Assign a separate on-call owner for TCO removal-order intake, verification, action logging, and authority response.
  • Give product and engineering owners shared responsibility for moderation tooling fields that both regimes need, such as timestamps, action type, legal basis, and reviewer identity.
Section 4

Very large service duties add governance, not a replacement for TCO

Platforms and search engines with average monthly active recipients in the Union equal to or higher than 45 million can be designated as VLOPs or VLOSEs and then face additional DSA obligations, including systemic-risk assessment, mitigation, independent audit, advertising and recommender-system transparency, and researcher data-access duties.

Those duties can improve terrorist-content risk governance, especially where content moderation systems or recommender systems amplify illegal content. They still do not replace the separate TCO order-handling workflow: a VLOP risk file and a removal-order action log answer different questions.

TCO can also require a separate prevention workstream. When a competent authority establishes that a hosting provider is exposed to terrorist content, Article 5 requires the provider to take specific measures that are diligent, proportionate, non-discriminatory, and protective of fundamental rights. The provider chooses the measures, and the authority cannot impose a general monitoring obligation or require automated tools. If the provider took or was required to take TCO action during a calendar year, Article 7 requires a public transparency report before 1 March of the following year.

  • Use VLOP/VLOSE risk assessment to evaluate content-moderation process risks, automation, resourcing, and escalation gaps.
  • Use the TCO register to prove receipt, action, preservation, complaint handling, and authority communication for each removal order.
  • Review both workstreams after material product launches, moderation automation changes, new EU market entries, or authority escalations.
Section 5

Terrorist content is a defined category, not a label for controversial speech

The TCO Regulation covers material that meets its definition of terrorist content, including material that incites or solicits terrorist offences, solicits participation in a terrorist group, provides instruction for terrorist offences, or threatens a terrorist offence under the stated conditions. The order must explain why the identified material qualifies and provide an exact URL plus any other information needed to locate it.

Material disseminated to the public for educational, journalistic, artistic, research, or terrorism-prevention purposes is not terrorist content under the Regulation when that is its true purpose. Polemic or controversial views in public debate are not enough on their own. Preserve the authority's classification and the content context instead of asking moderators to infer terrorist status from a topic, speaker, or keyword.

  • Check the order's legal basis, statement of reasons, content locator, timestamp, authentication, and redress information.
  • Keep contextual evidence needed for a complaint, cross-border scrutiny, or judicial review, subject to access controls and the six-month preservation rule.
  • Do not use TCO handling to bypass the DSA explanation and complaint duties that independently apply to the service's own moderation decision.
Primary sources

References and citations

Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA Article 28 minors protection guide for online platforms
EU Digital Services Act guide to Article 28 minors protection: platform scope, child-safety measures, targeted ads limits, recommender controls, and official source evidence.
DSA average monthly active recipients: what platforms must publish
An official source FAQ on average monthly active recipients under the EU Digital Services Act, including publication, EU recipient scope, the 45 million VLOP/VLOSE threshold, and evidence records.
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA Enforcement and Penalties in the EU
How Digital Services Act enforcement works: Commission and Digital Services Coordinator roles, VLOP and VLOSE investigations, fines, periodic penalty payments, and evidence readiness.
DSA illegal content notices: what must be included?
An official source FAQ on EU Digital Services Act illegal-content notices: Article 16 notice elements, acknowledgement, decision notices, trusted flagger priority, statements of reasons, and records.
DSA Marketplace Trader Traceability FAQ
Answer to what EU Digital Services Act Article 30 requires online marketplaces to collect, verify, display, retain, and evidence for trader traceability.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA recommender transparency FAQ: Article 27 and VLOP options
What EU Digital Services Act recommender transparency requires: main parameters, user options, VLOP/VLOSE non-profiling choices, and evidence to keep.
DSA researcher data access for VLOPs and VLOSEs
Article 40 DSA guide to vetted researcher access for VLOPs and VLOSEs under Regulation (EU) 2025/2050: requests, data catalogues, security, deadlines, and records.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons FAQ
When DSA statements of reasons are required, what they must contain, when online platforms submit them to the DSA Transparency Database, and what appeal records to keep.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits
What VLOPs and VLOSEs must assess under the EU Digital Services Act, when to reassess, how Article 35 mitigation and annual audit evidence fit together, and what records to keep.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
EU Digital Services Act penalties and fines: caps and enforcement roles
DSA penalty caps and enforcement roles: Member State fines, Commission fines for VLOPs and VLOSEs, 1% procedural fines, and 5% periodic penalty payments.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA deadlines and compliance calendar: application dates, reporting cycles, and VLOP clocks
Calendar view of cited EU Digital Services Act dates: full application, user-number publication, VLOP/VLOSE designation clocks, statements of reasons, and transparency reporting cycles.
EU DSA Transparency Calendar: reporting, SoR database, AMAR updates
Build a DSA transparency calendar for annual reports, statement-of-reasons database submissions, active-recipient updates, and VLOP/VLOSE audit touchpoints.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.