- Grounds gap-free annual audit sequencing, auditor independence checks, cooperation, evidence access, audit methodology, and audit and implementation report templates.
"at least once per year"
Track recurring DSA transparency duties across moderation, user-count, database, audit, and public reporting records.
This page helps build a control calendar for Article 15 reports, Article 24 active-recipient publications, Article 24(5) statement-of-reasons database submissions, and VLOP/VLOSE reporting and audit touchpoints.
Structured answer sets in this page tree.
Cited legal and guidance references.
Build the DSA transparency calendar service by service. Classify each service first, record any micro or small enterprise exclusion, and confirm / designation from a Commission decision or current official list. Then calendar each applicable , six-month active-recipient publication, event-driven statement-of-reasons submission, and annual audit workstream for a designated service.
Use four lanes: Article 15 and Article 42 reports, Article 17 notices and (Article 24(5)) database submissions, (Article 24(2)) active-recipient publications, and / audit-related reporting. Keep them separate because a hosting service can owe an Article 17 notice without owing an Article 24(5) database submission, and an ordinary service does not inherit VLOP deadlines.
For every entry, store the covered service, legal trigger, exclusion test, reporting period or event, deadline rule, submission channel, evidence source, owner, and public URL or database receipt. Mark whether the date is fixed, period-end based, designation based, or event driven.
Article 15 requires covered providers to report at least annually on content moderation. It does not apply to providers that qualify as micro or small enterprises unless they are designated VLOPs. The first report after full application was due no later than 16 February 2025, followed by a provider-specific shortened cycle ending 31 December 2025. From 2026, the ordinary annual period runs from 1 January through 31 December and publication is due no later than two months after period end.
Use the Annex I CSV or XLSX templates for content-moderation information from 1 July 2025. The first harmonised reports were published in February 2026. Report content varies by service category: authority orders and own-initiative moderation can apply broadly; notice-and-action data applies to hosting services; Article 24(1) adds dispute and suspension information for online platforms; Article 42 adds / detail. Preserve all published versions for five years and explain corrections or methodology changes.
Article 17 applies when a hosting service knows the recipient's electronic contact details and imposes a covered restriction because recipient-provided information is allegedly illegal or incompatible with its terms. The provider must give the statement at the latest when it imposes the restriction. Article 17 excludes deceptive high-volume commercial content and Article 9 orders. Article 24(5) separately requires covered online platforms to submit those decisions and statements to the Commission database without undue delay and without personal data.
Article 19 can exclude a qualifying micro or small online platform from Article 24(5), but it does not remove the Article 17 hosting duty. Track user-notice delivery and database submission as separate events. The Commission FAQ's search and download periods are an operational policy, not a statutory provider-retention rule, and the FAQ says they may change.
Article 24(2) applies to providers of online platforms and online search engines even when the service is not designated. Publish the average monthly active recipients in the Union for each service, calculated over the previous six months, and update the figure at least every six months. Article 19 can exclude a qualifying micro or small online platform from Article 24(2), but it does not exclude an online search engine and preserves Article 24(3) authority requests.
Article 33 requires both a numerical condition and a Commission decision: at least 45 million average monthly active recipients in the Union and designation as a or . The Section 5 duties apply four months after notification. If the service remains below the threshold for an uninterrupted year, the Commission must terminate designation, and the duties cease four months after termination is notified.
Article 37 requires each designated and to undergo an independent audit at its own expense at least once a year. The delegated audit regulation requires the audited period to follow the previous period without a gap and the schedule to allow completion at least annually. If the audit opinion is not positive, the provider has one month after receiving the recommendations to adopt an audit implementation report; if it rejects a recommendation, it must explain why and state its alternative measures.
Article 42 requires the provider to transmit the risk assessment, mitigation measures, audit report, audit implementation report, and applicable consultation information to the Digital Services Coordinator of establishment and the Commission without undue delay upon completion. It must publish them no later than three months after receiving the audit report. Limited information may be removed from the public versions for the stated confidentiality, service-security, public-security, or recipient-harm grounds, but the complete reports and reasons go to the authorities.
Sorena can help maintain an evidence calendar for DSA reporting, statement-of-reasons, active-recipient, and VLOP/VLOSE audit work.
Ask questions tied to cited sources about DSA transparency reporting, statement-of-reasons submissions, active-recipient updates, and VLOP/VLOSE audit evidence.
Review your DSA transparency calendar, owner model, data sources, and publication controls with Sorena.
"at least once per year"
"average monthly active recipients"
"publicly accessible and machine-readable"
"audited by an independent auditor"
"remain publicly available"
"at the latest three months"