FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
24of24items
Across 6 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
DSA recommender transparency FAQ: Article 27 and VLOP options

What evidence should teams keep for DSA recommender transparency?

Keep evidence showing that the public disclosure, live user interface, and recommender implementation describe the same system. For VLOPs and VLOSEs, DSA risk assessment, mitigation, audit, and data-access provisions can require explanations of algorithmic-system design, logic, functioning, and testing.

Use the product's actual criteria and records rather than an assumed scoring formula: the criteria that matter most, why they have their relative importance, the UI choices available to recipients, and the releases that changed the disclosure.

  • Recommender inventory with surface name, owner, recipient group, ranking objective, main criteria, and whether the surface determines relative order or prominence.
  • Terms-and-conditions extract showing the Article 27 main-parameter explanation and the options to modify or influence those parameters.
  • UI screenshots, design specs, or QA evidence showing where each choice is directly available to recipients.
  • For VLOPs and VLOSEs, evidence for the Article 38 non-profiling option for each recommender system and testing records for algorithmic changes.
  • Change log tying recommender releases, terms updates, and interface changes to legal, product, and data-science review.

What should a DSA recommender transparency review verify before launch?

Before launch, verify that the platform has identified the recommender system, described the most significant criteria and their relative importance in plain language, disclosed recipient options in the terms and conditions, exposed any required choice control in the relevant interface, and, for VLOPs or VLOSEs, provided a non-profiling option for each recommender system.

Citations
DSA statement of reasons

When is a DSA statement of reasons required?

A statement of reasons is triggered by the moderation decision, not by the label a team gives the workflow. Article 17 applies to providers of hosting services when they impose one of the listed restrictions because information provided by a recipient of the service is considered illegal content or incompatible with the provider's terms and conditions.

The covered restrictions include removing, disabling access to, demoting, or otherwise restricting visibility of specific information; suspending, terminating, or otherwise restricting monetary payments; suspending or terminating all or part of the service; and suspending or terminating the recipient's account.

Article 17 applies only where the provider knows the relevant electronic contact details, and it applies at the latest from the date the restriction is imposed. It does not apply to deceptive high-volume commercial content, and it does not apply to orders covered by Article 9.

  • Trigger: a hosting-service restriction based on illegal content or terms-and-conditions incompatibility.
  • Recipient: any affected recipient of the service whose relevant electronic contact details are known.
  • Timing: provide the statement at the latest when the restriction is imposed.
  • Exclusions to check: deceptive high-volume commercial content and Article 9 orders.

Does every content moderation decision need a DSA statement of reasons?

No. The Article 17 duty is tied to specific restrictions imposed by a hosting service because recipient-provided information is illegal content or incompatible with the provider's terms. The provider should first confirm the actor is a hosting service, the affected recipient's electronic contact details are known, the action is one of Article 17's listed restrictions, and no Article 17 exclusion applies.

Citations
DSA statement of reasons

What must the statement contain?

Article 17 requires enough detail for the affected recipient to understand the decision and exercise available redress rights. The statement should identify the moderation measure, the territorial scope and duration where relevant, the facts and circumstances relied on, and whether the decision followed an Article 16 notice or voluntary own-initiative investigation.

If automated means were used, the statement should say so where applicable, including whether the moderated content was detected or identified using automated means. If the ground is alleged illegality, cite the legal ground and explain why the information is illegal on that ground. If the ground is terms incompatibility, cite the contractual ground and explain why the information conflicts with it.

Redress information is part of the statement itself. For platform decisions, that means the recipient-facing notice should connect the user to the internal complaint-handling route where available, out-of-court dispute settlement where applicable, and judicial redress.

  • Decision type: removal, disabling access, demotion, visibility restriction, payment restriction, service restriction, or account restriction.
  • Scope and duration: territory and time period where relevant.
  • Basis: facts, circumstances, notice source or own-initiative review, and legal or contractual ground.
  • Automation: whether automated means were used where applicable.
  • Redress: clear, user-friendly complaint, out-of-court dispute settlement, and court options where applicable.

Can a statement of reasons use only a policy label or rule number?

A bare label is not enough. Article 17 requires the statement to be clear, easily comprehensible, and as precise and specific as reasonably possible. It should explain the facts and circumstances relied on and why the content falls under the legal or contractual ground used for the restriction.

Citations
DSA statement of reasons

What changes for online platforms and the Transparency Database?

The DSA Transparency Database does not collect every hosting-service statement of reasons. The Commission FAQ explains that it collects statements of reasons from online platforms, which are a subset of hosting services that store user-provided information and disseminate it publicly, such as online marketplaces, app stores, or social networks.

For online platforms, Article 24(5) requires submission of the Article 17 decisions and statements of reasons to the Commission without undue delay for inclusion in a publicly accessible, machine-readable database. The submitted information must not contain personal data. Article 19 can exclude qualifying micro and small online-platform providers from Article 24(5), subject to its post-loss transition and VLOP rule; it does not remove the underlying Article 17 recipient-notice duty for hosting services.

The Commission FAQ says redress options are not included in the public database because they are relevant only for the addressee of the statement of reasons. Operationally, keep the recipient-facing statement with redress information separately from the public database payload, and keep a personal-data removal check before submission.

  • Determine whether the service is an online platform, not only a hosting service.
  • Check whether the Article 19 micro or small enterprise exclusion applies to the platform-level database duty.
  • Submit Article 17 decisions and statements of reasons to the Commission without undue delay where Article 24(5) applies.
  • Remove personal data from the database submission.
  • Do not rely on the public database record as the full recipient notice, because redress options are not published there.
  • Use the Commission onboarding, sandbox, API, webform, and batch API paths where applicable to the provider's submission volume.

Is sending the statement to the user the same as submitting it to the DSA Transparency Database?

No. Article 17 is the recipient-facing statement duty for hosting services. Article 24(5) is the separate online-platform duty to submit Article 17 decisions and statements of reasons to the Commission database without undue delay and without personal data.

Citations
DSA statement of reasons

What appeal, complaint, and record links should the workflow preserve?

For online platforms, Article 20 requires an effective internal complaint-handling system for at least six months after the recipient is informed about covered moderation decisions. Complaints must be handled in a timely, non-discriminatory, diligent, and non-arbitrary manner, and complaint decisions must be supervised by appropriately qualified staff rather than made solely by automated means.

Users can also turn to certified out-of-court dispute settlement bodies for covered platform moderation disputes, without losing the ability to go to court. The Commission's dispute-settlement page states that users may select any certified body whose expertise covers the dispute and whose language coverage fits the case.

Keep records that let reviewers connect the original moderation decision, the recipient-facing statement, the Transparency Database submission where required, and any complaint or dispute outcome. The Commission database FAQ also gives retention context for public database access: statements become available from the following day after successful insertion, search retains them for six months, daily dumps retain them for 18 months, and dashboard aggregate statistics cover the last five years.

  • Store the delivered recipient statement and delivery timestamp.
  • Store the moderation action, legal or contractual basis, facts and circumstances, automation flag, scope, duration, and redress text.
  • For online platforms, store the database submission status, submission channel, payload version, personal-data removal check, and any submission errors.
  • Store internal complaint intake, review owner, reasoned outcome, reversal if any, and notice of out-of-court dispute settlement options.
  • Store out-of-court dispute settlement body, dispute scope, language, outcome, implementation decision, and related fee handling where relevant.

What should a team keep after sending a DSA statement of reasons?

Keep records for both duties: the recipient-facing Article 17 statement and, for online platforms, the Article 24(5) database submission without personal data. Also preserve complaint and dispute-settlement records showing how the user could challenge the moderation decision.

Citations
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits

What does a DSA VLOP risk assessment have to cover?

Article 34 requires designated VLOPs and VLOSEs to assess systemic risks that are specific to their services and proportionate to the severity and probability of those risks. The risk categories include dissemination of illegal content, negative effects on fundamental rights, negative effects on civic discourse, electoral processes and public security, and negative effects involving gender-based violence, public health, minors, and physical or mental well-being.

The first assessment is due by the date the enhanced obligations begin to apply to the designated service, which Article 33 sets at four months after notification of the designation decision. The provider must reassess at least once every year thereafter and before deploying functionality likely to have a critical impact on the identified risks.

The assessment also has to examine how the design and operation of the service influence those risks. For a practical record, map each risk to the affected surface, such as search ranking, recommender systems, ads delivery, content moderation, notice handling, marketplace listings, user reporting, account creation, age assurance, or high-reach sharing features.

  • Record the designated service, VLOP or VLOSE status, and the service surfaces covered by the assessment.
  • Create one line per Article 34 risk category and explain whether the risk is present, foreseeable, not applicable, or still under investigation.
  • For each present or foreseeable risk, capture the triggering product feature, user group, geography or language market, data source, severity, probability, and uncertainty.
  • Include intentional manipulation, inauthentic use, automated exploitation, and rapid amplification where they can influence the risk profile.

Does the DSA require a VLOP or VLOSE to run an Article 34 systemic risk assessment every year?

Yes. Article 34 requires VLOPs and VLOSEs to carry out the risk assessment at least once every year and also before deploying functionalities that are likely to have a critical impact on the identified systemic risks.

Citations
Regulation (EU) 2022/2065 (Digital Services Act)

Articles 33 and 34 set the initial application date, annual risk-assessment duty, systemic risk categories, critical-functionality reassessment trigger, and three-year supporting-document retention rule.

DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits

How should the risk assessment connect to Article 35 mitigation?

The assessment should not stop at a risk register. Article 35 requires reasonable, proportionate, and effective mitigation measures tailored to the specific Article 34 risks, with particular consideration for fundamental-rights impacts.

Useful mitigation records show why a control was selected or rejected. Examples supported by the DSA include adapting service design or functioning, recommender systems, terms enforcement, content moderation processes, notice-processing resources, advertising systems, crisis response, and child-protection tools such as age verification, parental controls, abuse-signalling tools, or support tools where appropriate.

  • Link each material Article 34 risk to one or more Article 35 mitigation measures and a control owner.
  • State whether the mitigation changes the product interface, ranking or recommendation logic, ads process, moderation workflow, staffing model, policy enforcement, user support, or child-safety control.
  • Document residual risk after mitigation and explain why the measure is proportionate to the risk and to affected fundamental rights.
  • For election-related risks, align the assessment with Commission Article 35 guidance on electoral-process mitigation where the service can affect civic discourse or elections.
Citations
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits

What evidence should the VLOP or VLOSE keep?

Keep evidence that lets the provider, auditor, Commission, and Digital Services Coordinator understand how the assessment was performed and why the mitigation response fits the risk. Article 34 requires supporting documents to be preserved for at least three years and communicated to the Commission and the Digital Services Coordinator of establishment on request.

A practical evidence pack should include the risk-assessment report, risk register, source data, internal controls, product and policy change logs, governance approvals, consultations used to design mitigations, and links to audit workpapers or audit implementation actions where available.

  • Assessment inputs: incident trends, notice and action data, statement-of-reasons data, user complaints, moderation quality results, recommender or ranking metrics, ad repository checks, integrity investigations, and relevant researcher findings.
  • Methodology records: risk definitions, severity and probability scoring, impacted groups, regional or linguistic factors, assumptions tested, and uncertainty notes.
  • Mitigation records: selected controls, rejected alternatives, deployment dates, owner, control tests, residual-risk rationale, and management-body or compliance-function approvals.
  • Audit records: auditor information requests, internal-control evidence, algorithmic-system tests where relevant, audit conclusions, operational recommendations, and implementation-report actions.
Citations
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits

How do audits, supervision, and publication fit into the assessment cycle?

The risk assessment feeds a public accountability cycle. VLOPs and VLOSEs are subject to independent audits at least once a year. After receiving an audit report, they must make public the risk-assessment report, mitigation measures, audit report, audit implementation report, and information about consultations no later than three months after receipt, subject to the DSA rules on confidential information. Taken together, the annual audit requirement and the three-month publication deadline place the first publication no later than 15 months after the enhanced obligations begin to apply to the service.

Supervision is not limited to public reports. The DSA also links the assessment to the compliance function, management-body oversight, Commission and Digital Services Coordinator access to supporting documents, data access for vetted researchers, and independent audit testing of internal controls and mitigation effectiveness.

  • Plan the Article 34 assessment, Article 35 mitigation record, audit evidence, and Article 42 public-reporting package as one annual control cycle.
  • Keep a versioned non-confidential report path separate from confidential evidence used by auditors and regulators.
  • Track audit recommendations by obligation, owner, due date, implementation status, evidence link, and whether the recommendation changes the next risk assessment.
  • Use Commission guidance, European Board material, public reports from comparable services, and vetted-research outputs as external signals when updating audit-risk and systemic-risk assumptions.
Citations
Page 2 of 2