Penalty CapsEU DSA

Digital Services Act penalties and fines

The DSA sets EU-wide maximum penalty caps, but the enforcing authority depends on the service and obligation: national Digital Services Coordinators enforce within their competence, while the Commission has direct enforcement powers for very large online platforms and very large online search engines.

This page helps separate the 6% substantive fine cap, the 1% procedural fine cap, and the 5% daily periodic penalty-payment cap before estimating enforcement exposure.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A DSA penalty assessment needs four inputs before any percentage is useful: the enforcing authority, the service and provider covered, the legal trigger, and the financial denominator for the preceding financial year. The 6% and 1% figures cap fines; the 5% figure caps a used to compel compliance. None is an automatic fine or a reliable estimate without the case facts and applicable national or Commission procedure.

Section 1

DSA fine caps to use in penalty exposure planning

Article 52 requires Member States to set a maximum fine of 6% of the provider's annual worldwide turnover in the preceding financial year for failure to comply with a DSA obligation. It separately requires a 1% maximum, based on annual income or worldwide turnover in that year, for incorrect, incomplete, or misleading information, failure to reply or rectify, and failure to submit to an inspection. National law supplies the specific penalty rules and procedure within those ceilings.

Article 74 gives the Commission different but related powers over VLOPs and VLOSEs. It may impose a fine up to 6% of total worldwide annual turnover in the preceding financial year when the provider intentionally or negligently infringes the DSA, disobeys interim measures, or breaches a commitment made binding by decision. A Commission fine up to 1% of total annual income or worldwide turnover applies to the procedural failures listed in Article 74(2), which also include non-compliance with Article 72 monitoring measures and access-to-file conditions.

  • Member State substantive cap: 6% of annual worldwide turnover in the preceding financial year for failure to comply with a DSA obligation.
  • Member State procedural cap: 1% of annual income or worldwide turnover in the preceding financial year for the Article 52(3) information and inspection failures.
  • Commission substantive cap: 6% of total worldwide annual turnover in the preceding financial year for the intentional or negligent Article 74(1) categories.
  • Commission procedural cap: 1% of total annual income or worldwide turnover in the preceding financial year for the intentional or negligent Article 74(2) categories.
  • The cap is not the fine amount. National penalties must be effective, proportionate, and dissuasive. The Commission must consider nature, gravity, duration, and recurrence and, for Article 74(2), delay caused to the proceedings.
  • Do not use case-specific euro amounts unless they come from a published enforcement decision for the specific provider and facts.
Section 2

Who can enforce the Digital Services Act?

Member States designate competent authorities and a Digital Services Coordinator. The Digital Services Coordinator is responsible for all matters relating to DSA supervision and enforcement in that Member State unless specific tasks are assigned to another competent authority; it remains responsible for national coordination.

The Member State of a provider's main establishment has exclusive national powers unless an Article 56 exception applies. For a provider without an EU establishment, competence can follow the Member State of its Article 13 legal representative. If the required representative is missing, all Member States may act subject to coordination and safeguards against duplicate sanctions.

The Commission has exclusive powers over Section 5 obligations of designated VLOPs and VLOSEs and also has powers over their other DSA obligations. The Member State of main establishment may enforce those other obligations only until the Commission initiates proceedings for the same infringement. Commission proceedings then relieve the national authority of its powers for that infringement.

  • Use the provider's main establishment or Article 13 legal-representative route and the service type to identify the national authority path.
  • Route VLOP or VLOSE Section 5 issues to the Commission enforcement track.
  • Keep the Digital Services Coordinator route visible for complaints, national investigations, inspection powers, and national penalty procedures.
  • For other VLOP/VLOSE duties, record whether the Commission has initiated proceedings for the same infringement; that event changes the competence split.
Section 3

Commission enforcement process for VLOPs and VLOSEs

The Commission may investigate a VLOP or VLOSE before formal proceedings through information requests, consent-based interviews, inspections, and access to data, IT systems, algorithms, and business-practice explanations. An information request may be simple or imposed by decision; the latter can carry periodic penalty payments for delay.

Before a non-compliance, fine, or periodic-payment decision, the Commission must communicate preliminary findings and allow the addressee a reasonable period of at least 14 days to comment. A final decision may rely only on objections on which the parties could comment. If the Commission establishes a breach, it can order corrective measures and, where the statutory conditions are met, impose a fine.

  • Evidence to keep: request-for-information responses, inspection readiness records, data-access logs, interview records, and legal review of response completeness.
  • Hearing rights matter: preserve the preliminary findings, access-to-file terms, response period, submitted observations, and final decision record.
  • For non-compliance decisions, track the ordered remedy, deadline, owner, implementation evidence, and any follow-up requests.
  • The Court of Justice of the European Union has unlimited jurisdiction to cancel, reduce, or increase a Commission fine or .
Section 4

Periodic penalty payments and last-resort enforcement measures

Periodic penalty payments are daily coercive payments. Under Article 52, Member State rules must cap them at 5% of average daily worldwide turnover or income in the preceding financial year per day from the date in the decision. A Digital Services Coordinator can use them to compel the end of an infringement or compliance with an investigative order, subject to national procedure.

Under Article 76, the Commission may impose up to 5% of average daily income or worldwide annual turnover in the preceding financial year per day to compel a correct and complete information response, an ordered inspection, interim measures, binding commitments, or a non-compliance decision. The decision sets the calculation start date. Once the obligation is satisfied, the Commission may fix the definitive amount below the original decision's amount.

Temporary access restriction is a separate last-resort judicial measure. It requires exhausted enforcement powers, a persistent infringement, serious harm that other powers cannot avoid, and the detailed conditions in Articles 51(3) and 82. Track it separately from monetary penalties.

  • Do not combine periodic penalty payments with ordinary fines as if they are the same sanction.
  • For each daily penalty exposure, record the authority, Article 52 or Article 76 basis, denominator, preceding financial year, decision date, calculation start date, compelled act, and proof of satisfaction.
  • For information requests and inspections, response completeness and timeliness are separate enforcement risks from the underlying DSA obligation.
  • Treat access restriction as exceptional and procedure-heavy, not as a normal monetary penalty.
Section 5

Records to maintain before a DSA enforcement question arrives

A penalty record should tie each possible sanction to the authority, service classification, statutory trigger, financial denominator, procedural stage, and evidence. A percentage without those fields can overstate exposure or apply the wrong regime.

Keep separate entries for the alleged DSA infringement and any cooperation failure. An information defect or missed inspection can create procedural exposure even when the underlying infringement remains unproven.

What is the highest DSA fine cap for failing to comply with an obligation?

Article 52 requires Member State rules to set a maximum fine of 6% of annual worldwide turnover in the preceding financial year for failure to comply with a DSA obligation. Article 74 separately allows the Commission to fine a VLOP or VLOSE provider up to 6% of total worldwide annual turnover in that year for an intentional or negligent DSA infringement, failure to comply with interim measures, or breach of a binding commitment. These are ceilings, not automatic amounts.

What DSA fine cap applies to incorrect information or refusal to submit to inspection?

Article 52 requires a 1% maximum under Member State rules for incorrect, incomplete, or misleading information, failure to reply or rectify, and failure to submit to inspection, based on annual income or worldwide turnover in the preceding financial year. Article 74 uses 1% of total annual income or worldwide turnover for its listed intentional or negligent procedural failures in Commission cases. Check the exact list because the Commission provision also covers Article 72 monitoring measures and access-to-file conditions.

Who enforces DSA fines: the Commission or Digital Services Coordinators?

Digital Services Coordinators and other national competent authorities enforce providers within their national competence. The Commission has exclusive powers over Section 5 obligations of designated VLOPs and VLOSEs and powers over their other DSA obligations. For those other obligations, the main-establishment Member State may act only until the Commission initiates proceedings for the same infringement.

Can the 6%, 1%, and 5% DSA percentages be added together?

Do not add the headline percentages as a generic maximum. They apply to different triggers and calculations: 6% and 1% cap fines, while 5% caps a daily payment that compels a specified act. Determine the authority, decision, legal basis, denominator, reference year, daily period, and whether multiple sanctions are legally and factually applicable before calculating any exposure.

  • Service classification: intermediary service, hosting service, online platform, VLOP, or VLOSE.
  • Authority path: Digital Services Coordinator or other national competent authority, Commission, and whether Commission proceedings have displaced national powers for the same VLOP/VLOSE infringement.
  • Obligation involved: DSA obligation, interim measure, legally binding commitment, information request, inspection, access-to-file condition, or remedial decision.
  • Cap category: Article 52 national fine or periodic payment, Article 74 Commission fine, or Article 76 Commission periodic payment.
  • Financial basis: applicable income or turnover measure, preceding financial year, source record, currency treatment, and calculation owner.
  • Response evidence: timely answer, completeness review, correction log, preliminary-findings response, remedy plan, audit report where required, and proof of implementation.
Recommended next step

Build a DSA penalty record around authority, cap, and evidence

Sorena can help build a source-cited DSA enforcement record that separates national and Commission authority, 6% fines, 1% procedural fines, and 5% daily periodic penalty-payment exposure.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Articles 51, 52, 56, 66, 74, and 76 support the authority route, distinct cap categories, financial denominators, Commission-proceeding effect, and daily-payment calculations.
"effective, proportionate and dissuasive"
Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA Article 28 minors protection guide for online platforms
EU Digital Services Act guide to Article 28 minors protection: platform scope, child-safety measures, targeted ads limits, recommender controls, and official source evidence.
DSA average monthly active recipients: what platforms must publish
An official source FAQ on average monthly active recipients under the EU Digital Services Act, including publication, EU recipient scope, the 45 million VLOP/VLOSE threshold, and evidence records.
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA Enforcement and Penalties in the EU
How Digital Services Act enforcement works: Commission and Digital Services Coordinator roles, VLOP and VLOSE investigations, fines, periodic penalty payments, and evidence readiness.
DSA illegal content notices: what must be included?
An official source FAQ on EU Digital Services Act illegal-content notices: Article 16 notice elements, acknowledgement, decision notices, trusted flagger priority, statements of reasons, and records.
DSA Marketplace Trader Traceability FAQ
Answer to what EU Digital Services Act Article 30 requires online marketplaces to collect, verify, display, retain, and evidence for trader traceability.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA recommender transparency FAQ: Article 27 and VLOP options
What EU Digital Services Act recommender transparency requires: main parameters, user options, VLOP/VLOSE non-profiling choices, and evidence to keep.
DSA researcher data access for VLOPs and VLOSEs
Article 40 DSA guide to vetted researcher access for VLOPs and VLOSEs under Regulation (EU) 2025/2050: requests, data catalogues, security, deadlines, and records.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons FAQ
When DSA statements of reasons are required, what they must contain, when online platforms submit them to the DSA Transparency Database, and what appeal records to keep.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits
What VLOPs and VLOSEs must assess under the EU Digital Services Act, when to reassess, how Article 35 mitigation and annual audit evidence fit together, and what records to keep.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA deadlines and compliance calendar: application dates, reporting cycles, and VLOP clocks
Calendar view of cited EU Digital Services Act dates: full application, user-number publication, VLOP/VLOSE designation clocks, statements of reasons, and transparency reporting cycles.
EU DSA Transparency Calendar: reporting, SoR database, AMAR updates
Build a DSA transparency calendar for annual reports, statement-of-reasons database submissions, active-recipient updates, and VLOP/VLOSE audit touchpoints.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.