DSA enforcementEU

Digital Services Act Enforcement, penalties, and investigations

An official source guide to who enforces the DSA, how Commission investigations of VLOPs and VLOSEs work, and which fine and periodic penalty payment caps are stated in official sources.

Use it to prepare investigation response ownership, evidence retrieval, RFI handling, inspection support, and escalation files before a regulator asks for them.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Start a DSA enforcement assessment with three facts: the service category, the provider's main EU establishment or legal-representative route, and whether the service is a designated VLOP or VLOSE. Those facts determine the competent authority and procedure. The 6% and 1% figures cap fines for different legal triggers; the 5% figure caps a used to compel a specified act. None is a tariff or a prediction of the amount an authority will impose.

Section 1

Who enforces the Digital Services Act?

The Member State of the provider's main establishment has exclusive national powers unless an Article 56 exception applies. Its Digital Services Coordinator coordinates national supervision, although the Member State may assign specific tasks or sectors to other competent authorities. For a provider without an EU establishment, competence can follow the Member State where its Article 13 legal representative resides or is established. If a provider required to appoint a representative fails to do so, all Member States, and the Commission for a VLOP or VLOSE within its competence, may act subject to safeguards against duplicate proceedings.

For designated VLOPs and VLOSEs, the Commission has exclusive powers over the Section 5 enhanced obligations. It also has powers over the service's other DSA obligations. The main-establishment Member State may enforce those other obligations only while the Commission has not initiated proceedings for the same infringement; initiation of Commission proceedings relieves the national authority of those powers for that infringement.

  • Record the provider's Member State of establishment or, for a non-EU provider, its legal representative and the resulting Article 56 jurisdiction route.
  • Separate baseline intermediary-service duties from VLOP/VLOSE enhanced due diligence duties.
  • For a designated VLOP or VLOSE, route Section 5 issues to Commission-facing owners.
  • For other VLOP/VLOSE duties, check whether the Commission has initiated proceedings for the same infringement before assigning the regulator-response route.
  • For other intermediary services, keep the Digital Services Coordinator and any sector-specific national competent-authority contacts current.
Section 2

How Commission investigations of VLOPs and VLOSEs start and progress

The Commission may investigate a VLOP or VLOSE before formally initiating proceedings. It can act on its own initiative or after a reasoned request from a Digital Services Coordinator and may use information requests, consent-based interviews, inspections, and other powers to test a suspected infringement.

Formal proceedings are a separate procedural step. If the Commission intends to adopt a non-compliance decision, a fine, or a , Article 79 requires it to communicate preliminary findings and allow observations for a reasonable period of at least 14 days. The final decision may rely only on objections on which the parties could comment.

  • Keep an investigation intake log covering the alleged DSA obligation, service, market, product feature, and competent authority.
  • Prepare a request-for-information owner who can distinguish a simple request from a request imposed by decision, coordinate legal review, product facts, data exports, and technical explanations, and track the stated response period.
  • Maintain a chronology of notices, statements of reasons, complaints, moderation actions, advertising records, recommender-system changes, audit findings, and risk-mitigation decisions relevant to the issue.
  • Preserve the opening notice, preliminary findings, access-to-file record, observations, interim-measure or commitment decision, remedy evidence, and final decision.
Section 3

Commission investigative powers that teams should be ready for

The Commission can request information by simple request or decision. A simple request states the legal basis, purpose, requested information, period, and possible fines for incorrect, incomplete, or misleading information. A decision also indicates or imposes possible periodic penalty payments and states the right to EU court review. The addressee remains responsible for the completeness and accuracy of an answer submitted by an authorised representative or lawyer.

Commission interviews require consent. During premises inspections, authorised officials may enter relevant premises and transport, examine and copy records, obtain access to and explanations about IT systems, algorithms, data handling, and business practices, seal premises or records where necessary, and question representatives or staff. An inspection decision must identify the subject matter, purpose, start date, penalties, and review right; national judicial authorisation may be required when the provider opposes the inspection.

  • Maintain an RFI response protocol with the request type, legal basis, deadline, source systems, data owners, sign-off authority, privilege or confidentiality review, and a completeness and correction check.
  • Keep data and algorithm access maps for recommender systems, advertising systems, moderation tooling, risk assessment evidence, audit evidence, and logs relevant to the DSA duty under review.
  • Prepare an interview protocol that records consent, subject matter, participants, and who is authorised to speak; do not describe a voluntary Article 68 interview as compulsory.
  • Prepare an inspection support file covering the authorisation or decision, premises access, secure workspaces, staff availability, system demonstrations, confidentiality claims, sealed materials, copy logs, recorded answers, and correction routes.
Section 4

Fines, periodic penalty payments, and last-resort measures

For a VLOP or VLOSE, Article 74 allows a Commission fine of up to 6% of total worldwide annual turnover in the preceding financial year when the provider intentionally or negligently infringes the DSA, disobeys an interim-measures decision, or breaches a commitment made binding by decision. The Commission must consider the infringement's nature, gravity, duration, and recurrence.

Article 74 separately allows a fine of up to 1% of total annual income or worldwide turnover in the preceding financial year for listed intentional or negligent procedural failures. These include incorrect, incomplete, or misleading information; failure to reply, rectify, or provide complete information; refusal of an inspection; failure to comply with Article 72 monitoring measures; and breach of access-to-file conditions.

Article 76 periodic penalty payments compel performance rather than punish the underlying infringement. The statutory ceiling is 5% of the average daily income or worldwide annual turnover in the preceding financial year per day from the date set in the decision. They can compel a complete information response, an inspection, interim measures, binding commitments, or a non-compliance decision. Once the obligation is satisfied, the Commission may set a lower definitive amount.

Temporary access restriction is a last-resort judicial route, not a fine. It requires exhausted powers, a persistent infringement, serious unavoidable harm, and, for the national restriction request, a criminal offence involving a threat to life or safety. The Commission must first allow at least 14 working days for written observations, then ask the Digital Services Coordinator of establishment to seek a national judicial order.

  • Do not quote a cap without its trigger, denominator, and reference period: 6% for the Article 74(1) categories, 1% for the Article 74(2) procedural categories, and 5% per day for compelled performance under Article 76.
  • Keep total worldwide annual turnover, total annual income, and the Article 76 daily calculation inputs separately controlled; do not substitute the Commission overview's shorthand for the wording of the binding provision.
  • Track whether the issue is an alleged substantive DSA breach, failure to comply with interim measures, breach of commitments, or failure to cooperate with an investigation.
  • For urgent or serious-harm scenarios, preserve the user-harm analysis, criminal-offence assessment, prior measures exhausted, written-observation record, and DSC/judicial authority communications.
Section 5

Evidence readiness checklist for DSA investigations

An enforcement file should let a reviewer reconstruct the service classification, competent authority, alleged obligation, procedural stage, evidence source, response owner, and submitted answer. Keep the original evidence, the reproducible extraction method, and the narrative prepared for the regulator.

For a VLOP or VLOSE, state whether the matter concerns a Section 5 obligation and whether the Commission has initiated proceedings for the same infringement. Those facts control the authority route.

Who supervises DSA compliance for very large online platforms and search engines?

The Commission has exclusive powers for the Section 5 enhanced obligations imposed on designated VLOPs and VLOSEs. It also has powers over their other DSA obligations. The main-establishment Member State may supervise those other obligations only while the Commission has not initiated proceedings for the same infringement; initiation of Commission proceedings removes the national authority's powers for that infringement.

What are the Commission's DSA penalty caps?

Article 74 caps fines for its substantive categories at 6% of total worldwide annual turnover in the preceding financial year. It caps fines for listed procedural failures at 1% of total annual income or worldwide turnover in that year. Article 76 caps periodic penalty payments at 5% of the average daily income or worldwide annual turnover in the preceding financial year per day from the date set in the decision. These are ceilings, not automatic amounts.

Does an investigation mean the Commission has found a DSA infringement?

No. The Commission may use investigatory powers before it initiates formal proceedings, and opening proceedings is not a final infringement finding. Before a non-compliance, fine, or periodic-payment decision, the Commission must communicate preliminary findings and allow the addressee at least 14 days to comment. A published investigatory step should not be described as a final breach decision.

  • Service and authority file: intermediary-service category, Member State of establishment, DSC contact route, and VLOP/VLOSE designation status.
  • Obligation file: DSA article or obligation area, affected feature, product owner, legal owner, evidence owner, and current control status.
  • Investigation file: RFIs, access requests, interview records, inspection notices, preliminary findings, responses, confidentiality markings, and deadlines.
  • Technical evidence file: data exports, algorithm or recommender-system documentation, moderation logs, statement-of-reasons records, complaint handling data, advertising records, audit materials, and risk-mitigation records when relevant.
  • Penalty-risk file: cap category, statutory trigger, financial reference period, intent or negligence issue where Article 74 applies, cooperation status, completeness checks, corrected answers, interim measures, commitments, remedies, action plans, and proof of timely completion.
Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Supports the practical investigation and sanctioning events that evidence files should answer and expressly distinguishes investigatory steps from final infringement findings.
"collect a reliable and consistent body of evidence"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission source for identifying designated VLOPs and VLOSEs and the threshold concept used for very large service supervision.
"over 45 million users in the EU"
eur-lex.europa.eu
Referenced sections
  • Primary source for Commission powers, fines, periodic penalty payments, hearings, inspections, and last-resort access-restriction procedure.
"subject matter and purpose of the inspection"
Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA Article 28 minors protection guide for online platforms
EU Digital Services Act guide to Article 28 minors protection: platform scope, child-safety measures, targeted ads limits, recommender controls, and official source evidence.
DSA average monthly active recipients: what platforms must publish
An official source FAQ on average monthly active recipients under the EU Digital Services Act, including publication, EU recipient scope, the 45 million VLOP/VLOSE threshold, and evidence records.
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA illegal content notices: what must be included?
An official source FAQ on EU Digital Services Act illegal-content notices: Article 16 notice elements, acknowledgement, decision notices, trusted flagger priority, statements of reasons, and records.
DSA Marketplace Trader Traceability FAQ
Answer to what EU Digital Services Act Article 30 requires online marketplaces to collect, verify, display, retain, and evidence for trader traceability.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA recommender transparency FAQ: Article 27 and VLOP options
What EU Digital Services Act recommender transparency requires: main parameters, user options, VLOP/VLOSE non-profiling choices, and evidence to keep.
DSA researcher data access for VLOPs and VLOSEs
Article 40 DSA guide to vetted researcher access for VLOPs and VLOSEs under Regulation (EU) 2025/2050: requests, data catalogues, security, deadlines, and records.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons FAQ
When DSA statements of reasons are required, what they must contain, when online platforms submit them to the DSA Transparency Database, and what appeal records to keep.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits
What VLOPs and VLOSEs must assess under the EU Digital Services Act, when to reassess, how Article 35 mitigation and annual audit evidence fit together, and what records to keep.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
EU Digital Services Act penalties and fines: caps and enforcement roles
DSA penalty caps and enforcement roles: Member State fines, Commission fines for VLOPs and VLOSEs, 1% procedural fines, and 5% periodic penalty payments.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA deadlines and compliance calendar: application dates, reporting cycles, and VLOP clocks
Calendar view of cited EU Digital Services Act dates: full application, user-number publication, VLOP/VLOSE designation clocks, statements of reasons, and transparency reporting cycles.
EU DSA Transparency Calendar: reporting, SoR database, AMAR updates
Build a DSA transparency calendar for annual reports, statement-of-reasons database submissions, active-recipient updates, and VLOP/VLOSE audit touchpoints.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.