Artifact GuideEU

EU Digital Services Act FAQ

Direct answers to recurring DSA questions about service scope, online platform duties, VLOP and VLOSE designation, content moderation notices, statements of reasons, trader traceability, recommenders, risk assessments, transparency reports, penalties, and complaints.

Use the cited EU sources to separate baseline intermediary duties from extra obligations for hosting services, online platforms, marketplaces, and designated very large services.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
FAQ modules
6

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

This EU Digital Services Act FAQ explains which services are covered, when platform-specific rules apply, what and VLOSE status changes, how illegal-content notices and statements of reasons work, what marketplaces must collect from traders, what recommender disclosures must say, what designated very large services must assess and report, how penalties are capped, and how users can complain. The DSA has applied generally since 17 February 2024.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items24
Focused FAQ modules
6
Showing 6 of 6
Question 1

Which services are covered by the EU Digital Services Act?

The DSA applies to providers of intermediary services offered to recipients in the EU where there is a substantial connection to the Union. The core service categories are mere conduit, caching, and hosting services.

The duties then build by service type. Hosting services store information provided by users. Online platforms are a subset of hosting services that also disseminate that information to the public at a user's request, such as marketplaces, app stores, and social networks. A public-comments feature that is minor and purely ancillary to another service may fall outside the online-platform definition. Very large online platforms and very large online search engines have additional obligations only after Commission designation.

The DSA has applied generally since 17 February 2024. It does not replace sector-specific or subject-specific EU rules on matters such as copyright, consumer protection, product safety, audiovisual media, terrorist content, or personal data; those rules can still determine whether content, a product, or an activity is illegal.

The liability exemptions for mere conduit, caching, and hosting are conditional defenses for third-party information, not exemptions from every DSA duty. The DSA also bars a general monitoring or active fact-finding obligation, while allowing specific legal orders and voluntary good-faith investigations. Keep liability analysis, due-diligence obligations, and the legality of the underlying content as separate questions.

  • Do not treat every website or SaaS product as an online platform; first identify whether the service is an intermediary service and then whether it is hosting, an online platform, a marketplace, an online search engine, a , or a VLOSE.
  • Micro and small enterprise carve-outs can remove some online-platform duties, but designated VLOPs and VLOSEs remain subject to the very-large-service regime.
  • Mere technical accessibility from the EU is not enough by itself; the regulation points to establishment, significant recipient numbers, or targeting of activities toward one or more Member States.
Question 2

When does a service become a VLOP or VLOSE under the DSA?

An online platform or online search engine reaches the DSA very-large-service threshold when it has average monthly active recipients in the EU equal to or higher than 45 million. The Commission designates qualifying services as very large online platforms or very large online search engines.

Once designated, the service has four months after notification of the designation decision to comply with the enhanced DSA duties. Providers covered by Article 24(2) publish average monthly active recipient numbers for each service at least every six months; Article 19 can exclude qualifying micro and small online-platform providers from that publication duty while retaining Article 24(3) authority requests.

  • Count active recipients per online platform or online search engine service, not at company group level alone.
  • Keep the published methodology, reporting period, and service boundary consistent enough for Commission or Digital Services Coordinator review.
  • A designation can be terminated if the service stays below the threshold for an uninterrupted year.
Question 3

What must hosting services and online platforms do for illegal-content notices and statements of reasons?

Hosting providers must provide easy-to-access electronic notice-and-action mechanisms for information that a person or entity considers illegal content. A sufficiently precise and substantiated notice can give the provider actual knowledge or awareness for the specific item of information concerned.

An Article 16 notice alleges that specific information is illegal under applicable EU or Member State law. A report that alleges only a breach of platform terms is not, on that basis alone, an illegal-content notice, although the provider may still handle it under its terms and moderation process.

When a hosting provider removes, disables access to, demotes, demonetises, suspends, terminates, or otherwise restricts content, service access, payments, visibility, or accounts because of alleged illegality or terms-and-conditions incompatibility, it must give the affected recipient a clear and specific statement of reasons where Article 17 applies. Online platforms covered by Article 24(5) must also send those decisions and statements of reasons to the Commission's public, machine-readable DSA Transparency Database without personal data; Article 19 can exclude qualifying micro and small providers from that platform-section duty.

  • A notice should identify the alleged illegal content, explain why it is illegal, provide the exact electronic location where possible, and include the notifier's contact details except where special DSA exceptions apply.
  • A statement of reasons should explain the restriction, facts and circumstances, whether automation was used, the legal or terms basis, and available redress.
  • Trusted flagger notices submitted through Article 16 mechanisms receive priority handling by online platforms, but all notices must still be processed in a timely, diligent, non-arbitrary, and objective way.
Question 4

What DSA duties apply to marketplaces, recommender systems, and user complaints?

Online platforms that let consumers conclude distance contracts with traders have trader-traceability duties. Before allowing traders to offer products or services, they must collect specified trader information, make best efforts to assess whether it is complete, design the interface so traders can provide required product and compliance information, and take steps when they become aware of illegal products or services.

Online platforms using recommender systems must explain the main parameters used by those systems and any options for recipients to modify or influence them. VLOPs and VLOSEs that use recommender systems must also provide at least one option that is not based on profiling.

Recipients can contest qualifying online-platform moderation decisions through internal complaint-handling systems. They can also use certified out-of-court dispute settlement bodies for content moderation disputes, and they retain access to courts.

  • Trader traceability records should cover the trader's identity and contact details, payment account details where applicable, trade register details where applicable, self-certification to offer only compliant products or services, and supporting checks required by Article 30.
  • If a marketplace becomes aware that a trader offered an illegal product or service, Article 32 covers consumers who bought it through the marketplace in the preceding six months. The notice must identify the illegal product or service, the trader, and relevant redress; if the marketplace lacks every affected consumer's contact details, it must make that information public and easily accessible on its interface.
  • Complaint handling must be accessible, timely, non-discriminatory, non-arbitrary, and subject to human review where automated means were used.
Question 5

What extra risk, audit, transparency reporting, and penalty rules matter most under the DSA?

Designated VLOPs and VLOSEs must identify, analyse, and assess systemic risks linked to their service design, functioning, algorithmic systems, and use. The DSA names systemic-risk areas including illegal content, fundamental rights, civic discourse and electoral processes, public security, gender-based violence, public health, minors, and serious effects on physical and mental well-being.

Those very large services must put in place reasonable, proportionate, and effective mitigation measures, maintain an internal compliance function, undergo independent audits at least annually, provide data access where required, publish transparency reports at least every six months, and make public risk assessment, mitigation, audit, and audit implementation reports within the Article 42 framework.

For penalties, Member States must set effective, proportionate, and dissuasive penalties for providers within their competence. The DSA caps maximum fines for obligation failures at 6% of annual worldwide turnover, caps certain information or inspection failures at 1% of annual income or worldwide turnover, and caps periodic penalty payments at 5% of average daily worldwide turnover or income per day. The Commission has separate enforcement powers for designated VLOPs and VLOSEs.

Who enforces the EU Digital Services Act?

Digital Services Coordinators supervise and enforce DSA compliance for providers of intermediary services established in their territory, while the European Commission has exclusive competence for the enhanced due-diligence obligations imposed on designated VLOPs and VLOSEs.

What is the maximum DSA fine for failing to comply with an obligation?

For providers within Member State competence, the DSA requires Member States to ensure that the maximum fine for failure to comply with an obligation is 6% of the provider's annual worldwide turnover in the preceding financial year. Separate 1% and daily 5% caps apply to specified information, inspection, and periodic penalty-payment situations.

  • Baseline transparency reporting under Article 15 covers moderation, notices, complaints, automation, and other required metrics, subject to DSA scope limits and carve-outs.
  • Article 42 adds more frequent and more detailed reporting for VLOPs and VLOSEs, including moderation resources by EU language and public versions of risk and audit materials.
  • Recipients of intermediary services can lodge a DSA infringement complaint with the Digital Services Coordinator in the Member State where they are located or established.
Recommended next step for the EU Digital Services Act

Turn DSA FAQ answers into implementation evidence

Sorena can help translate DSA scope, notice handling, statement-of-reasons, marketplace, recommender, VLOP/VLOSE, reporting, complaint, and penalty questions into cited controls and review records.

Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Commission source explaining how users can contest online-platform content moderation decisions through certified out-of-court dispute settlement bodies.
"Users can contest moderation decisions by online platforms"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission FAQ explaining what statements of reasons are, which providers submit them, and what is excluded from public database publication.
"clear and specific information, called statements of reasons"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission overview explaining that DSA obligations differ across intermediary services, hosting services, online platforms, and very large services.
"The Digital Services Act"
eur-lex.europa.eu
Referenced sections
  • Articles 15, 34, 35, 37, 42, 52, 53, 74, and 76 support transparency reporting, VLOP/VLOSE systemic-risk duties, audit duties, complaint rights, and penalty caps.
"maximum amount of fines"
Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA Article 28 minors protection guide for online platforms
EU Digital Services Act guide to Article 28 minors protection: platform scope, child-safety measures, targeted ads limits, recommender controls, and official source evidence.
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA Enforcement and Penalties in the EU
How Digital Services Act enforcement works: Commission and Digital Services Coordinator roles, VLOP and VLOSE investigations, fines, periodic penalty payments, and evidence readiness.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA researcher data access for VLOPs and VLOSEs
Article 40 DSA guide to vetted researcher access for VLOPs and VLOSEs under Regulation (EU) 2025/2050: requests, data catalogues, security, deadlines, and records.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act penalties and fines: caps and enforcement roles
DSA penalty caps and enforcement roles: Member State fines, Commission fines for VLOPs and VLOSEs, 1% procedural fines, and 5% periodic penalty payments.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA deadlines and compliance calendar: application dates, reporting cycles, and VLOP clocks
Calendar view of cited EU Digital Services Act dates: full application, user-number publication, VLOP/VLOSE designation clocks, statements of reasons, and transparency reporting cycles.
EU DSA Transparency Calendar: reporting, SoR database, AMAR updates
Build a DSA transparency calendar for annual reports, statement-of-reasons database submissions, active-recipient updates, and VLOP/VLOSE audit touchpoints.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.