What does a DSA VLOP risk assessment have to cover?
Article 34 requires designated VLOPs and VLOSEs to assess that are specific to their services and proportionate to the severity and probability of those risks. The risk categories include dissemination of illegal content, negative effects on fundamental rights, negative effects on civic discourse, electoral processes and public security, and negative effects involving gender-based violence, public health, minors, and physical or mental well-being.
The first assessment is due by the date the enhanced obligations begin to apply to the designated service, which Article 33 sets at four months after notification of the designation decision. The provider must reassess at least once every year thereafter and before deploying functionality likely to have a critical impact on the identified risks.
The assessment also has to examine how the design and operation of the service influence those risks. For a practical record, map each risk to the affected surface, such as search ranking, recommender systems, ads delivery, content moderation, notice handling, marketplace listings, user reporting, account creation, age assurance, or high-reach sharing features.
- Record the designated service, or VLOSE status, and the service surfaces covered by the assessment.
- Create one line per Article 34 risk category and explain whether the risk is present, foreseeable, not applicable, or still under investigation.
- For each present or foreseeable risk, capture the triggering product feature, user group, geography or language market, data source, severity, probability, and uncertainty.
- Include intentional manipulation, inauthentic use, automated exploitation, and rapid amplification where they can influence the risk profile.
Does the DSA require a or VLOSE to run an Article 34 systemic risk assessment every year?
Yes. Article 34 requires VLOPs and VLOSEs to carry out the risk assessment at least once every year and also before deploying functionalities that are likely to have a critical impact on the identified .
Articles 33 and 34 set the initial application date, annual risk-assessment duty, systemic risk categories, critical-functionality reassessment trigger, and three-year supporting-document retention rule.
Commission overview confirming the 45 million monthly EU user threshold, designation effect, and the enhanced systemic-risk duties for VLOPs and VLOSEs.