FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
24of24items
Across 6 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
DSA average monthly active recipients: what platforms must publish

What does average monthly active recipients mean under the DSA?

For this FAQ, average monthly active recipients means the Article 24(2) user-number publication for an online platform or online search engine: information on the average monthly active recipients of the service in the Union, calculated as an average over the past six months.

The relevant population covers recipients in the Union and goes beyond registered accounts. Recital 77 treats recipients as active when they engage with the service at least once during the period, including by being exposed to information disseminated on an online platform, providing information for dissemination, or submitting a query to an online search engine. Consumers, traders, advertisers, and users who are not registered can therefore be relevant to the service-specific count.

The DSA does not prescribe one universal analytics query in Article 24. Providers should document how their data identifies active recipients in the Union, avoids unsupported precision, and produces a six-month average for the particular platform or search service.

  • Measure and publish per online platform or online search engine, not as a single corporate group total.
  • Keep the service boundary clear where one product contains multiple platform, search, retail, marketplace, or third-party-content surfaces.
  • Do not use login, account creation, or a completed transaction as the only activity test when unregistered recipients can be exposed to disseminated information or use the search service.
  • Do not treat a public figure as final proof of non-designation; Article 33 allows the Commission to assess reported data, requested information, or other information available to it.
  • Do not publish personal data as part of the Article 24 calculation support; Article 24(3) says requested calculation substantiation must not include personal data.

What is the DSA average monthly active recipients figure?

It is the information that providers covered by Article 24(2) publish about the average monthly active recipients of the service in the Union, calculated over the past six months. Qualifying micro and small online-platform providers can fall within Article 19's exclusion, but Article 24(3) can still support an authority request for current recipient information and substantiation.

Citations
Regulation (EU) 2022/2065 (Digital Services Act)

Article 24(2) sets the publication duty, Article 24(3) addresses authority requests for calculation explanations and substantiation, and Recital 77 explains the forms of service engagement relevant to identifying active recipients.

DSA average monthly active recipients: what platforms must publish

When and where must the number be published?

Article 24(2) required covered providers to publish the first information by 17 February 2023 and to update it at least once every six months thereafter. The publication must be in a publicly available section of the online interface for each covered online platform or online search engine. Article 19 excludes qualifying micro and small online-platform providers from Article 24(2), subject to its post-loss and VLOP rules; Article 24(3) is expressly retained.

The publication duty is separate from authority-response duties. Under Article 24(3), the Digital Services Coordinator of establishment or the Commission may request the published information updated to the moment of the request, and may require additional calculation information, explanations, and substantiation about the data used.

  • Retain the public URL or interface location where the number was published.
  • Record the six-month measurement period used for the average.
  • Record when the figure was published or updated.
  • Keep a response pack that can be sent without undue delay if the Digital Services Coordinator of establishment or the Commission asks for updated information or substantiation.
  • Separate the public number from non-public calculation support, especially where that support contains sensitive operational data.

How often should DSA average monthly active recipient numbers be updated?

Article 24(2) requires publication at least once every six months after the first publication deadline. Article 24(3) also lets the Digital Services Coordinator of establishment or the Commission request updated information and substantiation without undue delay.

Citations
DSA average monthly active recipients: what platforms must publish

How does the number affect VLOP and VLOSE designation?

Article 33 applies the very large online platform and very large online search engine regime to online platforms and online search engines with average monthly active recipients in the Union equal to or higher than 45 million, once designated by the Commission.

Designation is a Commission decision. The Commission can base the decision on Article 24(2) data reported by the provider, information requested under Article 24(3), or other information available to it. If designated, the additional VLOP/VLOSE obligations apply from four months after notification to the provider. The Commission terminates a designation if the service remains below the threshold for an uninterrupted period of one year.

  • Treat 45 million as the Article 33 threshold for average monthly active recipients in the Union, not as a global user threshold.
  • Escalate services that are near, at, or above the threshold before publication so legal, data, and platform leads can review the basis for the figure.
  • Keep a record of any Commission or Digital Services Coordinator correspondence about the number.
  • For designated services, connect the figure to VLOP/VLOSE obligations such as systemic risk assessment, independent audit, data access, recommender-system choices, and advertisement repository obligations.
  • For designated services, Article 42 also requires transparency reports to include average monthly recipients of the service for each Member State.

Does crossing 45 million EU active recipients automatically make a service a VLOP or VLOSE?

No. Article 33 sets the threshold at average monthly active recipients in the Union equal to or higher than 45 million, but the service becomes a very large online platform or very large online search engine through a Commission designation decision.

Citations
DSA average monthly active recipients: what platforms must publish

What evidence should support the published number?

The DSA does not require teams to publish their full internal calculation workbook on the public page. It does, however, let the Digital Services Coordinator of establishment and the Commission ask for explanations and substantiation about the calculation and the data used, without personal data.

A defensible evidence record should therefore explain the service boundary, the Union recipient population, the six-month averaging period, the data sources used, the assumptions applied, the publication location, and the authority-response owner. Keep methodology caveats visible in the evidence record rather than turning them into unsupported precision in the public copy.

  • Service name, provider entity, and whether the service is an online platform, online search engine, or both.
  • Union-recipient inclusion rule used by the data team and any known country or Member State limitations in the dataset.
  • Six-month period used for the average and the date the figure was generated.
  • Source systems, query versions, data-quality checks, and reviewers who approved the number.
  • Known exclusions, deduplication assumptions, or split-service assumptions, stated without inventing a universal DSA formula.
  • Public interface URL, publication date, update history, and copies of any authority requests or responses.
  • Confirmation that substantiation prepared for authorities does not include personal data.

What records help explain a DSA average monthly active recipients calculation?

Keep the service boundary, EU recipient scope, six-month measurement period, data sources, assumptions, publication URL, update dates, reviewers, and any authority correspondence. The record should be detailed enough to substantiate the number if requested, but it should not add personal data to the Article 24(3) support pack.

Citations
DSA illegal content notices: what must be included?

What must a DSA illegal-content notice contain?

Article 16 requires providers of hosting services to offer easy-to-access, user-friendly electronic mechanisms for notices about specific items of information that a person or entity considers illegal content.

Illegal content means information that is itself unlawful or is unlawful because it relates to an illegal activity, including the sale of products or provision of services that do not comply with EU law or Member State law consistent with EU law. A report alleging only that content violates platform terms is not an Article 16 illegal-content notice unless it also alleges illegality.

A notice gives rise to actual knowledge or awareness for the specific item only when it is precise and substantiated enough for a diligent hosting provider to identify the illegality without a detailed legal examination. That rule does not turn the notice mechanism into a general monitoring duty.

  • Capture the reasoned explanation of why the notifier alleges the information is illegal content.
  • Capture the exact electronic location, such as the URL or URLs, plus any content-type-specific details needed to identify the item.
  • Capture the notifier's name and email address unless the Article 16 exception for certain child sexual abuse or exploitation offences applies.
  • Capture the notifier's statement that they believe, in good faith, that the information and allegations are accurate and complete.
  • Record whether the notice is sufficiently precise and adequately substantiated, because only sufficiently specific notices can create actual knowledge or awareness for the specific item.

How should a DSA Article 16 illegal-content notice be handled?

Handle it as a structured notice-and-action record: verify that the notice identifies a specific hosted item, includes a substantiated illegality explanation, gives the exact electronic location, includes required notifier details and good-faith confirmation, then process the notice in a timely, diligent, non-arbitrary, and objective way.

Does every user report become DSA actual knowledge of illegal content?

No. Under the DSA, a notice gives rise to actual knowledge or awareness only for the specific item of information when it allows a diligent hosting provider to identify the illegality without a detailed legal examination.

Can a notifier omit their name and email address?

Usually no. Article 16 requires the notifier's name and email address, but it makes an exception for information considered to involve offences covered by Articles 3 to 7 of Directive 2011/93/EU on child sexual abuse and exploitation. The exception removes those two required fields; it does not reduce the need to identify the content and substantiate the alleged illegality.

Citations
DSA illegal content notices: what must be included?

What must happen after the notice is submitted?

If the notice contains the notifier's electronic contact information, the hosting service must confirm receipt without undue delay and later notify the notifier of the decision on the reported information, including available redress routes.

If automated means are used for processing or decision-making, that use must be disclosed in the decision notification. If the provider restricts content because it is illegal or incompatible with terms, Article 17 may also require a clear and specific statement of reasons to the affected recipient. An Article 9 authority order to act against illegal content follows a separate DSA route and should not be processed as an ordinary Article 16 notice.

  • Send a receipt acknowledgement without undue delay when electronic contact details are available.
  • Decide the notice in a timely, diligent, non-arbitrary, and objective manner.
  • Tell the notifier the decision and redress possibilities without undue delay.
  • Tell the notifier when automated means were used for processing or decision-making.
  • When restricting content, prepare the Article 17 statement of reasons for the affected recipient, including restriction type, facts and circumstances, legal or contractual ground, automation use where applicable, and redress information.

Does a DSA notice decision also require a statement of reasons?

Often, yes. Article 16 requires the provider to notify the notifier of its decision on the reported information. Separately, Article 17 requires a clear and specific statement of reasons to the affected recipient when the provider removes, disables, demotes, restricts visibility, suspends payments, limits service access, or suspends an account because the recipient's information is illegal content or violates terms.

What redress route should be recorded for a DSA illegal-content notice decision?

At minimum, record the redress information sent with the Article 16 decision notification. For online platforms, Article 20 also requires an internal complaint-handling system for at least six months after certain notice and moderation decisions, and Article 17 statements of reasons must include clear redress information.

Citations
DSA illegal content notices: what must be included?

How do trusted flaggers and records change the workflow?

A trusted flagger notice is still submitted through the Article 16 mechanism, but Article 22 requires online platforms to give priority to notices from trusted flaggers acting within their designated area of expertise and to process and decide them without undue delay.

Trusted flagger status does not transfer the moderation decision to the flagger. The Commission explains that trusted flaggers notify platforms of content they consider illegal, while providers remain responsible for deciding on notices and removing content where justified.

  • Tag whether the notifier is a designated trusted flagger and whether the notice falls within the flagger's area of expertise.
  • Route qualifying trusted flagger notices for priority processing and decision without undue delay.
  • Keep support for any escalation to the awarding Digital Services Coordinator when a trusted flagger submits a significant number of insufficiently precise, inaccurate, or inadequately substantiated notices.
  • For transparency reporting, preserve counts of Article 16 notices by type of alleged illegal content, trusted flagger notices, actions taken under law versus terms, automated processing, and median action time.
  • For online platforms, preserve statement-of-reasons submission status and ensure submissions to the Commission database do not contain personal data.

Do DSA trusted flagger notices automatically require content removal?

No. Trusted flagger notices receive priority handling when submitted within the flagger's designated expertise, but the provider still decides the notice and removes or restricts content only where justified under law or its terms.

What records should a DSA illegal-content notice file keep?

Keep the notice text and required Article 16 fields, sufficiency assessment, acknowledgement timestamp, review owner, decision and rationale, automation use, notifier decision message, affected-recipient statement of reasons where applicable, redress information, complaint outcome where applicable, trusted flagger status, and transparency-reporting categories.

Citations
DSA Marketplace Trader Traceability

What does DSA marketplace trader traceability require?

For an online marketplace in scope of Article 30, first record whether Article 29 excludes the marketplace section because the provider qualifies as micro or small. Where Article 30 applies, a trader should not be able to promote messages about products or services, or offer products or services to consumers located in the Union, until the platform has obtained the required trader information.

The marketplace also has to make best efforts to assess whether the information is reliable and complete before the trader uses the service. That assessment can use freely accessible official databases or online interfaces made available by a Member State or the Union, or supporting documents from reliable sources requested from the trader.

Article 30 gave covered marketplaces 12 months from 17 February 2024 to obtain the required information from traders already using the service. That transition ended on 17 February 2025, so a covered marketplace should not treat a pre-existing trader as exempt from the current onboarding and maintenance control.

  • Collect the trader's name, address, telephone number, and email address where applicable.
  • Collect a copy of the trader's identification document or qualifying electronic identification.
  • Collect payment account details and, where applicable, trade-register details and registration number or equivalent identifier.
  • Collect the trader's self-certification committing to offer only products or services that comply with applicable Union law.
  • Block marketplace use for EU consumer offers until the Article 30 information has been obtained and checked for reliability and completeness through best efforts.

How should an online marketplace handle trader traceability under the EU Digital Services Act?

Treat it as a seller-onboarding and seller-maintenance control. Before a trader can offer products or services to consumers in the Union, collect the Article 30 identity, contact, payment, register, and self-certification information; make best efforts to check that the information is reliable and complete; show the required trader identity, register, and compliance self-certification information where the product or service is presented; store the collected information securely during the trader relationship and for six months afterward; and suspend the trader if missing or inaccurate information is not remedied.

Citations
DSA Marketplace Trader Traceability

What must be visible to consumers?

Article 30 separates internal collection from consumer-facing disclosure. The marketplace does not publish every collected item, but it must make the trader's name and contact information, trade-register information where applicable, and the trader's compliance self-certification available to recipients of the service in a clear, easily accessible, and comprehensible way.

The marketplace must make that information available on the online interface where the product or service is presented. Identification documents and payment-account details belong in the internal traceability record, not the Article 30(7) consumer disclosure.

  • Show the trader name, address, telephone number, and email address in the product or service flow where consumers can find it before buying.
  • Show the trade register and registration number or equivalent identifier when the trader is registered in such a register.
  • Show the trader's self-certification that products or services offered through the marketplace comply with applicable Union law.
  • Do not expose identification documents or payment account details to consumers unless another applicable law requires disclosure.
Citations
DSA Marketplace Trader Traceability

What should the marketplace do when information is missing or unreliable?

If the marketplace has sufficient indications or reason to believe that Article 30 trader information is inaccurate, incomplete, or not up to date, it must ask the trader to remedy the problem without delay or within the period set by Union and national law.

If the trader does not correct or complete the information, the marketplace must swiftly suspend the service for that trader in relation to products or services offered to consumers located in the Union. A refusal or suspension decision also connects to the DSA complaint routes available to the trader.

  • Log the signal that made the trader data appear inaccurate, incomplete, or stale.
  • Send a remediation request that identifies the exact missing or defective Article 30 field.
  • Pause or prevent EU consumer offers where the required information is not supplied or corrected.
  • Keep evidence of the request, trader response, suspension decision, and any complaint handling.
Citations
DSA Marketplace Trader Traceability

How do Article 31 and Article 32 connect to traceability?

Trader traceability should be implemented together with Article 31 marketplace interface controls. The interface must let traders provide required pre-contractual, compliance, and product safety information, including product or service identification, trader signs such as a trademark or logo, and applicable labelling and marking information.

After a trader is allowed to offer products or services, the marketplace must make reasonable efforts to randomly check official, freely accessible, machine-readable databases or interfaces to see whether offered products or services have been identified as illegal.

If the marketplace becomes aware that a trader offered an illegal product or service through the service, Article 32 covers consumers who bought it during the preceding six months. Where their contact details are available, the marketplace must inform them of the illegality, the trader's identity, and relevant redress. If it lacks contact details for all affected consumers, it must make the same information public and easily accessible on its interface.

  • Design listing forms so traders can provide product or service identification, economic-operator details, trader signs, and applicable labelling or marking information.
  • Before listing, make best efforts to assess whether traders have provided the Article 31 information.
  • After listing, make reasonable random checks against official accessible databases or interfaces for illegal products or services.
  • When an illegal product or service is identified, determine the preceding six-month purchaser population and keep evidence of the illegality notice, trader identity, relevant redress, direct notices sent, and any public interface notice.
Citations
DSA Marketplace Trader Traceability

What evidence should teams keep?

Keep evidence showing how the marketplace enforced Article 30 in seller onboarding and live seller maintenance. Store the collected trader data securely, document how reliability and completeness were assessed, and tie each trader status change to the relevant product or service flow.

Article 30 requires secure storage during the contractual relationship and for six months after it ends, followed by deletion. Disclosure to third parties should be limited to cases required by applicable law, including DSA orders and competent-authority or Commission orders.

  • Seller onboarding record with each Article 30 field, collection timestamp, source, verifier, and result.
  • Reliability check evidence, such as official database lookup result, electronic identification check, or supporting document request and response.
  • Consumer-facing disclosure screenshot or rendered-page capture showing the trader information on the product or service interface.
  • Issue log for incomplete, inaccurate, or outdated trader information, including remediation request, deadline, suspension, reinstatement, and complaint handling.
  • Retention and deletion record showing secure storage through the trader relationship and deletion after the six-month post-relationship period.
Citations
DSA recommender transparency FAQ: Article 27 and VLOP options

What does DSA Article 27 require for recommender system transparency?

Article 27 applies to providers of online platforms that use recommender systems. The DSA defines a recommender system as a fully or partly automated system that suggests information, prioritises it, or determines the relative order or prominence of information in the platform interface.

The platform must set out, in its terms and conditions and in plain, intelligible language, the main parameters used by the recommender system and any options recipients have to modify or influence those parameters. Article 19 can exclude qualifying micro and small online-platform providers from Article 27, subject to the post-loss transition and the rule that designated VLOPs remain covered.

  • Identify every recommender surface: feed, search results, marketplace ordering, content suggestions, ranking modules, or other interface areas that suggest or prioritise information.
  • Describe the most significant criteria used to determine what information is suggested to a user.
  • Explain why those parameters have their relative importance; do not replace this with an unexplained formula, model name, or generic personalization statement.
  • List the user options that can modify or influence the main parameters, or state clearly when no such option is offered for that recommender surface.

Does the EU Digital Services Act require platforms to publish the full recommender algorithm?

No. Article 27 is framed around plain-language disclosure of the main parameters and user options, not publication of source code, model weights, or a technical formula. The explanation should let a recipient understand why certain information is suggested and which criteria matter most.

Citations
DSA recommender transparency FAQ: Article 27 and VLOP options

What user controls must be available for DSA recommender choices?

Article 27 distinguishes between disclosure of options and in-product functionality. If several options are available for a recommender system that determines the relative order of information, the platform must let the recipient select and modify the preferred option at any time.

That control must be directly and easily accessible from the specific part of the online interface where information is being prioritised. A buried account setting is weak evidence if the ranking choice is presented somewhere else.

  • Map each terms-and-conditions option to the exact UI control where the recipient can select or change it.
  • Record whether the control changes ranking order, recommendation source, personalization settings, chronological ordering, popularity ordering, location, language, seller, or another main parameter.
  • Keep screenshots or product specs showing the control in the interface section where prioritised information appears.
  • Retest the disclosure after recommender releases, ranking-signal changes, UI redesigns, or changes to terms and conditions.

Under the DSA, is it enough to describe recommender settings only in a help article?

Article 27 specifically requires the main parameters and modification options to be set out in the terms and conditions. Help-centre or in-product text can make the explanation easier to find, but it should not replace the terms-and-conditions disclosure.

Citations
DSA recommender transparency FAQ: Article 27 and VLOP options

What extra recommender choice applies to VLOPs and VLOSEs?

Article 38 adds a separate requirement for providers of very large online platforms and very large online search engines that use recommender systems. In addition to Article 27, they must provide at least one option for each recommender system that is not based on profiling under the GDPR definition referenced by the DSA.

Profiling here means automated processing of personal data to evaluate personal aspects of a natural person, including analysis or prediction of interests, behaviour, location, or other listed characteristics. A provider should test the actual data and logic behind the option; a label such as 'chronological' or 'non-personalised' does not by itself establish that the option is not based on profiling.

The 45 million average-monthly-active-recipient threshold informs designation, but Article 38 applies after the Commission designates the service as a VLOP or VLOSE. For those designated services, the recommender inventory should show each recommender system and its matching non-profiling option.

  • Confirm whether the service is designated as a VLOP or VLOSE before applying Article 38 as an extra obligation.
  • For each recommender system, identify the default option, any alternative options, and the option that is not based on profiling.
  • Check that the non-profiling choice is not limited to one surface if multiple recommender systems are used.
  • Keep product and legal sign-off that the option described as non-profiling is implemented consistently in the live ranking service.

Do all DSA online platforms need a non-profiling recommender option?

Article 38 creates the explicit non-profiling option requirement for very large online platforms and very large online search engines that use recommender systems. Other online platforms using recommender systems still need the Article 27 disclosure of main parameters and any recipient options to modify or influence those parameters.

Citations
Page 1 of 2
Previous12Next