Every statement this site makes about DSA, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.
Primary lawlaw
The DSA stacks obligations cumulatively across four tiers — all intermediary services, hosting services, online platforms, and VLOPs/VLOSEs — with each tier inheriting the one below.
Primary lawlaw
The VLOP and VLOSE designation threshold is 45 million average monthly active recipients in the Union.
Primary lawlaw
Micro and small enterprises are exempt from most online-platform obligations of the DSA (Art. 19) unless they are designated as very large online platforms.
Primary lawlaw
A delegated act on DSA Article 40 data access entered into force on 29 October 2025, establishing a centralised DSA Data Access Portal, procedural safeguards and platform data catalogues.
Primary lawlaw
The Commission supervises the DSA only for VLOPs and VLOSEs; national Digital Services Coordinators supervise every tier below that.
Primary lawlaw
The DSA deleted the intermediary-liability provisions of the e-Commerce Directive (Articles 12 to 15 of Directive 2000/31/EC) and replaced them with its own conditional exemptions.
Primary lawlaw
Article 34 DSA requires providers of very large online platforms and search engines to identify, analyse and assess systemic risks stemming from the design or functioning of their service, including algorithmic systems, at least once a year and before deploying functionalities likely to have a critical impact: illegal content; negative effects on fundamental rights; on civic discourse, electoral processes and public security; and in relation to gender-based violence, public health, minors and physical and mental well-being — taking into account recommender and other algorithmic systems and intentional manipulation, including inauthentic use.
Primary lawlaw
Article 35 DSA requires reasonable, proportionate and effective mitigation measures tailored to the systemic risks identified; the measures it lists are examples of what they may include.
Official sourcefact
In the X proceedings the Commission recorded that X had three employees working part-time on assessing data access requests.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III
Official sourcefact
After X withdrew its free academic API, the Commission found researchers left with X's commercial developer API, whose 'Pro' tier cost USD 5,000 per month.
Official sourcefact
On 5 December 2025 the Commission fined X EUR 120 million under the DSA for deceptive design in the paid blue checkmark, a non-functional ad repository, and obstruction of researcher access.
Tier 2 · regulatorstates this
Commission fines X EUR 120 million under the Digital Services Act — European Commission 5 December 2025 "a fine of €120 million … The breaches include the deceptive design of its 'blue checkmark', the lack of transparency of its advertising repository, and the failure to provide access to public data for researchers"
Official sourcefact
On 28 May 2026 the Commission fined Temu EUR 200 million under the DSA for failing to diligently identify, analyse and assess the systemic risks from the sale of illegal products on its platform.
Official sourcefact
Platform challenges to the DSA supervisory-fee decisions succeeded before the General Court for both TikTok and Meta.
Official sourcefact
On 20 July 2026 the Commission fined AliExpress EUR 550 million under the DSA for failure to adequately assess and mitigate systemic risks from the sale of illegal, unsafe and counterfeit products — the largest DSA fine to date.
Secondary onlyfact
In January 2026 the Polish President vetoed the national law implementing the DSA; in September 2026 he signed a narrower replacement making the head of UKE the Digital Services Coordinator, while a second bill, on blocking illegal content, was still before parliament.
Interpretationinterpretationunverified
Almost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I
Interpretationinterpretation
The instruments following the GDPR reproduce the same institutional shape — a specialised vocabulary, principles, case-specific rights and a supervisory apparatus — a pattern described as act-ification and GDPR mimesis.
Interpretationcritique
The recurring objection across every instrument is a capacity-ambition gap: broad obligations assigned either to a single Commission directorate with a few hundred staff or to twenty-seven national authorities of radically unequal resource.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I, Part IX
Interpretationinterpretationunverified
The operative standards of the EU digital rulebook — systemic risk, high-impact capabilities, effective interoperability, genuinely equivalent alternative — are almost all open-textured, so the law's effective content is set by Commission guidelines, delegated acts, codes of practice and harmonised standards rather than by the legislature.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX
Interpretationinterpretationunverified
A single recommender system can engage the GDPR, the DSA, the AI Act and, for a gatekeeper, the DMA at once, so the rational compliance strategy is one control set mapped to several regimes.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX
Interpretationinterpretationunverified
Because every designated gatekeeper undertaking and nearly every VLOP is non-European, the rulebook is a foreign-policy object: this shapes the timing of decisions, the choice between fines and commitments, and the political viability of expanding scope.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX
Interpretationinterpretationunverified
GDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties; an organisation running all three separately duplicates work regulators themselves acknowledge is duplicated.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Interpretationcritique
Because DSA Art. 16(3) makes a compliant notice give rise to actual knowledge and therefore liability exposure, while over-removal carries no equivalent liability — Article 14(4)'s duty to act diligently, objectively and proportionately gives it a legal cost only in principle — the rational response to a borderline notice is removal.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III
Interpretationcritique
DSA Art. 34–35 systemic risk is deliberately open-textured, and both failure modes are live: overly specific criteria risk platforms optimising for metrics rather than real harms, while overly vague ones leave the concept unadministrable.
Interpretationcritique
DSA Article 40 researcher data access is underperforming in practice, with a documented playbook of available refusals grounded in the purpose limitation.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III
Interpretationinterpretation
The Commission's stated priority in DSA enforcement is compliance rather than revenue: TikTok's ad-repository failings were cured by binding commitment rather than fine.
Interpretationinterpretation
The February 2026 TikTok preliminary findings were among the first enforcement actions targeting platform architecture — infinite scroll, autoplay, personalised recommenders — rather than illegal content.
Interpretationinterpretation
DSA enforcement escalated across 2025–2026, from the X and Temu fines to preliminary findings against TikTok and Meta on addictive design and minors' safety.
Interpretationcritiqueunverified
Announcing preliminary findings with detailed proposed remedies before publishing reasoning risks findings that are less responsive to debate and less likely to survive court challenge.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III
Interpretationinterpretationunverified
The DSA–GDPR interface is unresolved: the DSA tells platforms to be transparent while the GDPR tells them to minimise, and EDPB guidance mediates the conflict without dissolving it.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III
Interpretationcritique
The AI Act is one instrument in a system that already regulated most of its subject matter: automated decision-making by GDPR Art. 22 since 2018, algorithmic recommender risk by DSA Arts. 34–35, product liability by the revised PLD — while the proposed AI Liability Directive was abandoned, leaving a gap in the fault-based route.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V
Interpretationcritiqueunverified
This body of law restrains corporate power far more effectively than it restrains state power, and the enforcement asymmetry between corporate and state addressees is not seriously disputable.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part XI
Unresolvedattributedunverified
Practitioner analysis argues the blue-checkmark finding may have been routed through DSA Article 25 in a way that ignores the Article 25(2) exclusion for practices covered by the Unfair Commercial Practices Directive, making it vulnerable to annulment.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III