Transparency CalendarEU DSA

EU DSA Transparency Calendar

Track recurring DSA transparency duties across moderation, user-count, database, audit, and public reporting records.

This page helps build a control calendar for Article 15 reports, Article 24 active-recipient publications, Article 24(5) statement-of-reasons database submissions, and VLOP/VLOSE reporting and audit touchpoints.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Build the DSA transparency calendar service by service. Classify each service first, record any micro or small enterprise exclusion, and confirm / designation from a Commission decision or current official list. Then calendar each applicable , six-month active-recipient publication, event-driven statement-of-reasons submission, and annual audit workstream for a designated service.

Section 1

Calendar lanes to maintain

Use four lanes: Article 15 and Article 42 reports, Article 17 notices and (Article 24(5)) database submissions, (Article 24(2)) active-recipient publications, and / audit-related reporting. Keep them separate because a hosting service can owe an Article 17 notice without owing an Article 24(5) database submission, and an ordinary service does not inherit VLOP deadlines.

For every entry, store the covered service, legal trigger, exclusion test, reporting period or event, deadline rule, submission channel, evidence source, owner, and public URL or database receipt. Mark whether the date is fixed, period-end based, designation based, or event driven.

  • Content-moderation report lane: Article 15 or Article 42 applicability, CSV or XLSX template, reporting period, two-month publication clock, version control, and at least five-year public retention.
  • Statement-of-reasons lane: Article 17 user-notice timing and exceptions, Article 24(5) database applicability, personal-data removal, submission receipts, and failed-record reconciliation.
  • Active-recipient lane: Article 24(2) publication for each online platform or online search engine, using a six-month average and updating at least every six months; record the Article 19 exclusion only for qualifying online platforms.
  • / lane: notification and four-month application date, half-year Article 42 reports, Member State active-recipient breakdowns, at-least-annual independent audits, one-month audit implementation report where required, and three-month public reporting.
Section 2

Annual transparency report controls

Article 15 requires covered providers to report at least annually on content moderation. It does not apply to providers that qualify as micro or small enterprises unless they are designated VLOPs. The first report after full application was due no later than 16 February 2025, followed by a provider-specific shortened cycle ending 31 December 2025. From 2026, the ordinary annual period runs from 1 January through 31 December and publication is due no later than two months after period end.

Use the Annex I CSV or XLSX templates for content-moderation information from 1 July 2025. The first harmonised reports were published in February 2026. Report content varies by service category: authority orders and own-initiative moderation can apply broadly; notice-and-action data applies to hosting services; Article 24(1) adds dispute and suspension information for online platforms; Article 42 adds / detail. Preserve all published versions for five years and explain corrections or methodology changes.

  • Create a recurring data-close task for the fields applicable to the service: authority orders, notices, moderation decisions, complaint outcomes, median-time measures, automated processing, and categorisation by illegal-content or terms-and-conditions ground.
  • Add a pre-publication review for Article 15 applicability, service-category fields, reporting period, Annex I template completeness, ODF CSV publication, UTF-8 encoding, public accessibility, source-system reconciliation, and owner sign-off.
  • If a published report is corrected, mark it as an updated version, identify the changes, explain the reason and correction method, state the change date, and keep every earlier published version available.
  • Keep transparency reports publicly available for at least five years after publication, matching the implementing regulation's retention control.
Section 3

Statement-of-reasons database controls

Article 17 applies when a hosting service knows the recipient's electronic contact details and imposes a covered restriction because recipient-provided information is allegedly illegal or incompatible with its terms. The provider must give the statement at the latest when it imposes the restriction. Article 17 excludes deceptive high-volume commercial content and Article 9 orders. Article 24(5) separately requires covered online platforms to submit those decisions and statements to the Commission database without undue delay and without personal data.

Article 19 can exclude a qualifying micro or small online platform from Article 24(5), but it does not remove the Article 17 hosting duty. Track user-notice delivery and database submission as separate events. The Commission FAQ's search and download periods are an operational policy, not a statutory provider-retention rule, and the FAQ says they may change.

  • Before go-live: confirm Article 24(5) applicability, register for onboarding through the Digital Services Coordinator, test the API or webform in the sandbox, and approve personal-data removal.
  • Per decision or batch: record the restriction timestamp, user-notice delivery, database applicability, submission timestamp, receipt, retry, and any excluded personal data.
  • At a frequency proportionate to volume: reconcile covered Article 17 decisions against successful Article 24(5) submissions and investigate rejected, delayed, duplicate, or malformed records.
  • Operational visibility: the current Commission FAQ says successful statements appear the following day, search retains them for 180 days, downloadable daily dumps for 540 days, and dashboard aggregates for five years. Recheck the FAQ before relying on those windows.
  • Evidence to retain: scope decision, user-facing statement template, Article 17 field mapping, submission logs, redaction checks, API or webform errors, and correction notes.
Section 4

Active-recipient publication and VLOP/VLOSE triggers

Article 24(2) applies to providers of online platforms and online search engines even when the service is not designated. Publish the average monthly active recipients in the Union for each service, calculated over the previous six months, and update the figure at least every six months. Article 19 can exclude a qualifying micro or small online platform from Article 24(2), but it does not exclude an online search engine and preserves Article 24(3) authority requests.

Article 33 requires both a numerical condition and a Commission decision: at least 45 million average monthly active recipients in the Union and designation as a or . The Section 5 duties apply four months after notification. If the service remains below the threshold for an uninterrupted year, the Commission must terminate designation, and the duties cease four months after termination is notified.

  • Every six months: refresh the public active-recipient figure, archive the calculation workbook, source-system extraction, bot or duplicate-account treatment, and publication screenshot or URL.
  • After each active-recipient update: test whether the service has at least 45 million average monthly active recipients in the Union and prepare to substantiate the calculation if the Commission or Digital Services Coordinator requests it.
  • If designated: calculate the Section 5 application date from actual notification, not the public announcement date, and add the four-month implementation workstream.
  • For / transparency reports: include average monthly active recipients for each Member State when Article 42 applies, not only a Union-level number.
Section 5

VLOP/VLOSE audit and evidence calendar

Article 37 requires each designated and to undergo an independent audit at its own expense at least once a year. The delegated audit regulation requires the audited period to follow the previous period without a gap and the schedule to allow completion at least annually. If the audit opinion is not positive, the provider has one month after receiving the recommendations to adopt an audit implementation report; if it rejects a recommendation, it must explain why and state its alternative measures.

Article 42 requires the provider to transmit the risk assessment, mitigation measures, audit report, audit implementation report, and applicable consultation information to the Digital Services Coordinator of establishment and the Commission without undue delay upon completion. It must publish them no later than three months after receiving the audit report. Limited information may be removed from the public versions for the stated confidentiality, service-security, public-security, or recipient-harm grounds, but the complete reports and reasons go to the authorities.

  • Before auditor selection: collect independence, conflict-of-interest, expertise, subcontractor, and non-audit-service checks for the auditing organisation.
  • During the audit: preserve evidence for each audited obligation, including risk assessments, mitigation measures, transparency reporting controls, content moderation systems, recommender controls, ad repository controls, and data-access processes.
  • After a non-positive report: adopt the audit implementation report within one month, identify implemented recommendations, explain any rejected recommendation, and record alternative measures.
  • After completion and report receipt: transmit the complete Article 42 package without undue delay, prepare public versions, record removals and reasons, and publish no later than three months after report receipt.
  • Evidence calendar fields: audited service, audit period, prior-period end, auditor and independence checks, obligations covered, opinion, recommendation date, one-month implementation-report deadline, regulator transmission date, three-month public deadline, and removal rationale.
Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Explains Article 17 and Article 24(5) context, Digital Services Coordinator onboarding, API and webform submission, personal-data removal, and the changeable operational retention windows.
"publicly accessible and machine-readable"
eur-lex.europa.eu
Referenced sections
  • Articles 37 and 42 set the at-least-annual audit, one-month implementation report after a non-positive opinion, regulator transmission, three-month public deadline, and permitted public-information removals.
"at the latest three months"
Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA Article 28 minors protection guide for online platforms
EU Digital Services Act guide to Article 28 minors protection: platform scope, child-safety measures, targeted ads limits, recommender controls, and official source evidence.
DSA average monthly active recipients: what platforms must publish
An official source FAQ on average monthly active recipients under the EU Digital Services Act, including publication, EU recipient scope, the 45 million VLOP/VLOSE threshold, and evidence records.
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA Enforcement and Penalties in the EU
How Digital Services Act enforcement works: Commission and Digital Services Coordinator roles, VLOP and VLOSE investigations, fines, periodic penalty payments, and evidence readiness.
DSA illegal content notices: what must be included?
An official source FAQ on EU Digital Services Act illegal-content notices: Article 16 notice elements, acknowledgement, decision notices, trusted flagger priority, statements of reasons, and records.
DSA Marketplace Trader Traceability FAQ
Answer to what EU Digital Services Act Article 30 requires online marketplaces to collect, verify, display, retain, and evidence for trader traceability.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA recommender transparency FAQ: Article 27 and VLOP options
What EU Digital Services Act recommender transparency requires: main parameters, user options, VLOP/VLOSE non-profiling choices, and evidence to keep.
DSA researcher data access for VLOPs and VLOSEs
Article 40 DSA guide to vetted researcher access for VLOPs and VLOSEs under Regulation (EU) 2025/2050: requests, data catalogues, security, deadlines, and records.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons FAQ
When DSA statements of reasons are required, what they must contain, when online platforms submit them to the DSA Transparency Database, and what appeal records to keep.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits
What VLOPs and VLOSEs must assess under the EU Digital Services Act, when to reassess, how Article 35 mitigation and annual audit evidence fit together, and what records to keep.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
EU Digital Services Act penalties and fines: caps and enforcement roles
DSA penalty caps and enforcement roles: Member State fines, Commission fines for VLOPs and VLOSEs, 1% procedural fines, and 5% periodic penalty payments.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA deadlines and compliance calendar: application dates, reporting cycles, and VLOP clocks
Calendar view of cited EU Digital Services Act dates: full application, user-number publication, VLOP/VLOSE designation clocks, statements of reasons, and transparency reporting cycles.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.