Skip to main content
Category: Privacy Regulations

Digital Services Act

Also known as: DSA, Regulation (EU) 2022/2065, Single Market for Digital Services Regulation
Simply put

The Digital Services Act is a European Union law that sets rules for online services such as social media platforms, marketplaces, and other online intermediaries. It aims to make these services take more responsibility for illegal and harmful content and to improve the safety of users online. It is a regulation adopted by the EU, so its treatment is specific to the European Union rather than being a universal standard.

Formal definition

The Digital Services Act is Regulation (EU) 2022/2065 of the European Parliament and of the Council, adopted 19 October 2022, on a Single Market for Digital Services. It establishes a harmonized EU framework governing online intermediaries and platforms, including marketplaces, addressing the legal responsibilities of platforms with respect to user-generated and third-party content, illegal content, and user safety measures. As an EU regulation it applies within the European Union context; this entry defines the instrument's scope and purpose and does not cover enforcement mechanics, penalty structures, tiered obligations for specific platform categories, or how comparable matters are treated outside the EU. The DSA is a content and platform-governance instrument and is distinct from EU data protection law such as the GDPR.

Why it matters

The Digital Services Act, Regulation (EU) 2022/2065, represents a significant shift in how the European Union approaches the responsibilities of online intermediaries and platforms. Rather than leaving content-related obligations to fragmented national rules, the DSA establishes a harmonized EU framework addressing the legal responsibilities of platforms with respect to user-generated and third-party content, illegal content, and user safety. For organizations operating online services within the EU context, this means platform governance is no longer purely a matter of internal policy but a regulated area with defined expectations.

The DSA is directed at online services such as social media platforms, marketplaces, and other online intermediaries, and it aims to make these services take more responsibility for illegal and harmful content while improving user safety. Because it is an EU regulation, its treatment is specific to the European Union rather than being a universal standard, and organizations should not assume that comparable matters are handled the same way in other jurisdictions.

It is important for compliance and governance professionals to keep the DSA conceptually distinct from EU data protection law such as the GDPR. The DSA is a content and platform-governance instrument concerned with how platforms handle content and user safety, whereas the GDPR governs the processing of personal data. Treating them as interchangeable can lead to misaligned compliance efforts. This entry does not cover enforcement mechanics, penalty structures, tiered obligations for specific platform categories, or how these matters are treated outside the EU.

Who it's relevant to

Online platforms and intermediaries operating in the EU
Social media platforms, marketplaces, and other online intermediaries that make user-generated or third-party content available fall within the general scope of the DSA. These services are the primary subjects of the regulation's expectations around illegal content and user safety, and their specific obligations typically depend on their role and category, which are outside the scope of this entry.
Legal and compliance teams
Legal and compliance professionals supporting online services need to understand the DSA as a distinct EU content and platform-governance instrument, separate from data protection law such as the GDPR. This distinction matters when mapping obligations, as conflating the two can misdirect compliance effort.
Information governance and policy leads
Those responsible for platform content policies and governance frameworks should note that the DSA introduces regulated expectations around how platforms address illegal content and user safety within the EU. Demonstrable governance practices are generally more defensible than stated intent alone, though this entry does not cover the specific evidentiary or enforcement requirements.

Inside DSA

Scope and Subject Matter
The Digital Services Act (DSA) is an EU regulation governing intermediary services, including online platforms and hosting services, with a focus on the moderation of illegal content and the transparency of online services. It is distinct from data protection instruments such as the EU GDPR; the DSA does not itself set out a general framework for processing personal data, and its interaction with data protection law is governed by the respective instruments rather than being merged into one.
Tiered Obligations by Service Type
The DSA generally applies obligations in a layered manner depending on the type and size of the service, with additional obligations for larger online platforms compared with smaller intermediaries. Practitioners should confirm which tier a given service falls into, as obligations differ, and this glossary entry does not attempt to enumerate every category or every threshold.
Illegal Content and Notice Mechanisms
The DSA addresses how intermediary services handle illegal content, including mechanisms for users to notify services of such content and for services to act on those notices. The DSA's concept of illegal content is defined by reference to applicable EU or national law rather than being defined uniformly within the instrument itself.
Transparency and Accountability Requirements
The DSA emphasizes transparency regarding content moderation practices and, more broadly, accountability for how covered services operate. Consistent with governance principles, accountability here typically requires demonstrable evidence of compliance rather than merely stated intent. The precise transparency deliverables vary by service tier.
Relationship to Other EU Instruments
The DSA operates alongside, and does not replace, other EU instruments such as the EU GDPR. Where a service processes personal data, data protection obligations continue to apply independently. The DSA and the GDPR should not be treated as interchangeable, and obligations under one do not automatically satisfy obligations under the other.

Common questions

Answers to the questions practitioners most commonly ask about DSA.

Is the Digital Services Act a data protection law like the GDPR?
No. The Digital Services Act (DSA) is an EU regulation focused on online intermediary services, content moderation, transparency, and the handling of illegal content and systemic risks online. It is distinct from the EU GDPR, which governs the processing of personal data. The two instruments can apply in parallel to the same organisation, but the DSA does not replace or restate data protection obligations, and it should not be treated as a privacy law. Where personal data is processed in the course of complying with DSA obligations, the GDPR continues to apply separately. This entry does not address the detailed intersection of DSA and GDPR obligations.
Does the Digital Services Act apply uniformly to every online service?
Not uniformly. The DSA generally sets tiered obligations that vary by the type and scale of intermediary service, with lighter requirements for some categories and more extensive requirements for larger platforms. Treating all in-scope services as bearing identical duties is a common mistake. The specific classification of a given service, and the precise obligations attaching to it, depend on how the service is characterised under the regulation and require case-by-case assessment. This entry does not enumerate the full set of tiers, thresholds, or the criteria used to designate services.
How should an organisation determine whether it falls within the scope of the DSA?
Scope generally depends on whether the organisation provides an intermediary service to recipients in the EU and how that service is characterised under the regulation, rather than solely on where the organisation is established. Organisations typically begin by mapping their services against the categories the DSA recognises and then assessing which tier of obligations applies. Because classification drives obligations, this analysis is usually a legal and compliance exercise rather than a purely technical one. This entry does not cover the detailed scoping tests, territorial criteria, or any designation processes.
What kinds of transparency practices does the DSA generally expect?
The DSA generally emphasises transparency around content moderation decisions, terms of service, and how services handle illegal content and complaints, with more detailed expectations for larger platforms. In practice, organisations typically need to be able to demonstrate their practices with evidence, consistent with an accountability posture, rather than merely stating intent. The precise form, frequency, and content of any transparency outputs depend on the service category and are not fully specified in this entry.
How does DSA compliance relate to an organisation's existing data governance and security functions?
DSA compliance is primarily a governance and legal accountability matter concerning how a service handles content, complaints, and transparency, and it should not be collapsed into information security controls, which address confidentiality, integrity, and availability. There is typically overlap where DSA processes generate records or handle user data, at which point governance responsibilities such as ownership, policy, and evidence-keeping, and separately security controls, both become relevant. Organisations generally assign clear ownership for DSA obligations rather than assuming an existing security or privacy team automatically covers them. This entry does not detail the operational mechanics of that allocation.
What evidence should an organisation maintain to demonstrate DSA-related accountability?
As with governance frameworks generally, demonstrable accountability typically requires documented evidence of practices rather than stated intent alone. For DSA-related purposes this generally means being able to show how relevant processes operate and how obligations are met on an ongoing basis. The specific records expected depend on the service category and applicable obligations, and this entry does not enumerate required documentation, retention periods, or any reporting timelines.

Common misconceptions

The DSA is a data protection law and effectively overlaps with or replaces the EU GDPR.
The DSA and the EU GDPR are distinct instruments addressing different subject matter. The DSA focuses on intermediary services, content moderation, and transparency, while the GDPR governs the processing of personal data. A service subject to the DSA that also processes personal data remains separately bound by applicable data protection law; compliance with one does not guarantee compliance with the other.
The DSA imposes the same obligations on every online service.
The DSA generally applies obligations in a tiered manner according to the type and, in most cases, the size of the service. Larger platforms typically face additional obligations that do not apply to smaller intermediaries, so practitioners must determine the applicable tier before assuming a given requirement applies.
Complying with the DSA's transparency requirements means an organization can demonstrate compliance through stated policies alone.
Consistent with accountability principles, demonstrating compliance generally requires documented, demonstrable evidence rather than merely stated intent. Written policies without supporting records of how they are implemented are typically insufficient.

Best practices

Determine which DSA service tier applies to your organization before mapping obligations, since requirements differ by service type and, in most cases, by size.
Maintain the DSA and applicable data protection obligations, such as those under the EU GDPR, as separate compliance workstreams, and confirm that satisfying one is not assumed to satisfy the other.
Establish and document notice mechanisms for illegal content, referencing the applicable EU or national law that defines the relevant illegal content rather than assuming a single uniform definition.
Keep demonstrable evidence of content moderation and transparency practices, recognizing that accountability generally requires records of implementation rather than stated intent alone.
Use qualified internal assessments that account for jurisdiction and service type, and avoid treating any single control or process as guaranteeing DSA compliance.
Engage legal counsel to confirm precise article-level obligations, thresholds, and enforcement details, which are out of scope for this entry and depend on the current text of the regulation.