1. Digital Policy
  2. Instruments
  3. DSA

Regulation · directly applicable · CELEX 32022R2065

DSA

Regulation (EU) 2022/2065 on a Single Market For Digital Services

Known as the Digital Services Act. Official text: Regulation (EU) 2022/2065 (Digital Services Act)Tier 1 · primary law

Status
Applicable as of 19 August 2026
Competent authority
Digital Services Coordinatorsand 4 more — see below
Sanction ceiling
6% of global turnover

What it does

A single market for digital services, replacing the liability core of the 2000 e-Commerce Directive with a graduated due-diligence regime.

How it allocates obligations

Systemic risk (Art. 34), assessed by the provider and mitigated proportionately.

Regulated actor
Intermediary service · Hosting service · Online platform · Very large online platform · Very large online search engine
Protected party
Recipient of the service
Territorial reach
Established in the EU · Outside the EU, serving EU users
Implementation model
Directly applicable
Enforcement mechanism
Commission for VLOPs and VLOSEs; national Digital Services Coordinators for all lower tiers.

Key dates

Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.

  1. 19 October 2022AdoptionAdoption
  2. 27 October 2022Publication in the Official JournalPublication in the Official Journal
  3. 16 November 2022Entry into forceEntry into force
  4. 25 August 2023Application dateThe VLOP and VLOSE obligation set begins to apply to designated services.What it requires: Complete the first annual systemic risk assessment and mitigation.
  5. 17 February 2024Application dateGeneral application of the DSA to all intermediary services.
  6. 29 October 2025Delegated actCommission Delegated Regulation (EU) 2025/2050 on data access enters into force, establishing a centralised DSA Data Access Portal, procedural safeguards and platform data catalogues.What it requires: Designated platforms must publish data catalogues and process vetted-researcher requests through the portal.

The whole compliance calendar, filterable →

Who it applies to

5 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.

Yes

actor Online platform or Very large online platformactivity Operating an online platform or Operating an online marketplace or Operating recommender systems

Obligations stack cumulatively across four tiers. An online platform owes the intermediary and hosting duties below it as well as the platform tier: notice and action, statements of reasons, internal complaint handling, the dark-pattern ban, advertising transparency and recommender-parameter disclosure.

Exemptions: Micro and small enterprises are exempt from the Section 3 online-platform obligations unless designated as a VLOP.

Last verified 27 August 2026

Yes

actor Very large online platformactivity Operating an online platform or Operating recommender systems or Operating an online marketplace

Designation brings the heaviest tier: annual systemic risk assessment, proportionate mitigation, independent audit, an enhanced advertisement repository, a recommender option not based on profiling, vetted-researcher data access and a supervisory fee. The Commission supervises this tier directly.

Last verified 27 August 2026

Potentially applicable

actor Online platform or Large companyactivity Operating recommender systems

The systemic-risk regime for recommender design reaches only designated VLOPs and VLOSEs. A platform below that threshold owes recommender-parameter transparency but not the Article 34 assessment — unless and until it is designated.

Exemptions: Below the 45 million threshold and absent designation, Articles 33–43 do not apply.

Last verified 27 August 2026

Yes

activity Operating an online marketplace

A platform allowing consumers to conclude distance contracts with traders must obtain and check specified trader information before allowing use of the service, and must design its interface so that the trader's identity is visible.

Exemptions: Micro and small enterprises are exempt from the online-platform section unless designated as a VLOP.

Last verified 27 August 2026

Potentially applicable

actor Researcher

Article 40 gives researchers a route to platform data rather than an obligation. Access to non-public data runs through the Digital Services Coordinator of establishment, not the platform, and is purpose-limited to the detection and understanding of systemic risks. The brief records that route as underperforming in practice.

Exemptions: Article 40 reaches only VLOPs and VLOSEs. Smaller platforms are outside it entirely.

Last verified 27 August 2026

Run these against your situation →

Key provisions

13 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.

ArticleHeadingBindsApplies
Art. 16load-bearingNotice and action mechanismsElectronic notice mechanisms for sufficiently precise and adequately substantiated notices. Art. 16(3) provides that a compliant notice gives rise to actual knowledge or awareness for the Art. 6 liability exemption where it allows a diligent provider to identify the illegality without a detailed legal examination.Hosting serviceApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 25Online interface design and organisationBan on dark patterns. Art. 25(2) excludes practices covered by the Unfair Commercial Practices Directive.Online platformApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 28Online protection of minorsMeasures to ensure a high level of privacy, safety and security for minors, including a prohibition on advertising based on profiling where the recipient is known to be a minor.Online platformApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 30Traceability of tradersOnline platforms allowing consumers to conclude distance contracts with traders must obtain and check specified trader information before allowing use of the service.Online platformApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 33Very large online platforms and very large online search enginesDesignation threshold of 45 million average monthly active recipients in the Union.not recordedApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 34load-bearingRisk assessmentVLOPs and VLOSEs must diligently identify, analyse and assess systemic risks stemming from the design or functioning of their service, at least annually and before deploying functionalities likely to have a critical impact.Very large online platform · Very large online search engineApplies from 25 August 2023
Art. 35load-bearingMitigation of risksProportionate, effective mitigation, with the choice of measures left to the provider.Very large online platform · Very large online search engineApplies from 25 August 2023
Art. 38Recommender systemsAt least one recommender option not based on profiling.Very large online platform · Very large online search engineApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 39Additional online advertising transparencyEnhanced advertisement repository.Very large online platform · Very large online search engineApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 40load-bearingData access and scrutinyArt. 40(12) access to publicly available data; Art. 40(4) access to non-public data for vetted researchers, requested through the Digital Services Coordinator of establishment. Both purpose-limited to research on systemic risks.Very large online platform · Very large online search engineApplies from 25 August 2023
Art. 49Competent authorities and Digital Services CoordinatorsMember StateApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 56CompetencesAllocates supervision between the Commission (VLOPs and VLOSEs) and national Digital Services Coordinators.not recordedApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded
Art. 74FinesUp to 6% of global annual turnover.not recordedApplies from 17 February 2024the instrument’s general date; nothing specific to this article is recorded

Enforcement

EUR 870mannounced across 8 records
unknowndemonstrably collected

3 of 8 records cannot settle whether money moved. That is not zero, and the announced figure is not a total of anything that has been paid.

TikTok

Announced
—announced
Not applicablepayment
24 July 2026decision
Authority
European Commission
Issue
Preliminary findings
Legal basis
Art. 34 · Art. 35
Full record and derivation →Last verified 27 August 2026

AliExpress

Imposed
EUR 550mannounced
Unknownpayment
20 July 2026decision
Authority
European Commission
Issue
Non-compliance decision and fine (risk assessment and mitigation, Arts 34 and 35); action plan due by 20 October 2026
Legal basis
Art. 34 · Art. 35 · Art. 74
Full record and derivation →Last verified 27 September 2026

Meta (Instagram and Facebook)

Announced
—announced
Not applicablepayment
10 July 2026decision
Authority
European Commission
Issue
Preliminary findings
Legal basis
Art. 34 · Art. 35
Full record and derivation →Last verified 27 August 2026

Temu

Imposed
EUR 200mannounced
Unknownpayment
28 May 2026decision
Authority
European Commission
Issue
Non-compliance decision and fine (risk assessment, Art. 34); action plan due by 28 August 2026 under Art. 75
Legal basis
Art. 34 · Art. 74
Full record and derivation →Last verified 27 September 2026

TikTok

Announced
—announced
Not applicablepayment
6 February 2026decision
Authority
European Commission
Issue
Preliminary findings
Legal basis
Art. 34 · Art. 35
Full record and derivation →Last verified 27 August 2026

X (Twitter)

Imposed
EUR 120mannounced
Unknownpayment
5 December 2025decision
Authority
European Commission
Issue
Non-compliance decision and fine
Legal basis
Art. 25 · Art. 39 · Art. 40 · Art. 74
Full record and derivation →Last verified 27 September 2026

TikTok

Closed by binding commitments
—announced
Not applicablepayment
5 December 2025decision
Authority
European Commission
Issue
Commitments made binding
Legal basis
Art. 39
Full record and derivation →Last verified 27 August 2026

Meta Platforms Ireland and TikTok Technology

Annulled
—announced
Not applicablepayment
10 September 2025decision
Authority
General Court
Issue
Annulment of the DSA supervisory-fee implementing decisions
Legal basis
not recorded

General Court of the European Union, 10 September 2025. The implementing decisions setting the supervisory fee were annulled because the methodology should have been adopted by delegated act. Effects provisionally maintained for up to twelve months. This is an annulment of the fee decisions, not of the fee mechanism as such.

Full record and derivation →Last verified 27 September 2026

Evidence and sources

Every statement this site makes about DSA, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.

The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.

8 Primary law6 Official source1 Secondary only17 Interpretation1 Unresolved
Primary lawlaw

The DSA stacks obligations cumulatively across four tiers — all intermediary services, hosting services, online platforms, and VLOPs/VLOSEs — with each tier inheriting the one below.

Tier 1 · primary lawstates this

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Chapter III

Read it in the brief →Last verified 27 August 2026
Primary lawlaw

The VLOP and VLOSE designation threshold is 45 million average monthly active recipients in the Union.

Tier 1 · primary lawstates this

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Art. 33

Read it in the brief →Last verified 27 August 2026
Primary lawlaw

Micro and small enterprises are exempt from most online-platform obligations of the DSA (Art. 19) unless they are designated as very large online platforms.

Tier 1 · primary lawstates this

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Art. 19(1)–(2)

Tier 4 · press / advocacysupports in part

The Digital Services Act — Article 14 (Terms and conditions) and Article 19 (Exclusion for micro and small enterprises) — eu-digital-services-act.com (unofficial reproduction of the DSA text) Art. 19

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

A delegated act on DSA Article 40 data access entered into force on 29 October 2025, establishing a centralised DSA Data Access Portal, procedural safeguards and platform data catalogues.

Tier 1 · primary lawstates this

Commission Delegated Regulation (EU) 2025/2050 of 1 July 2025 on data access under the Digital Services Act — EUR-Lex 1 July 2025 Art. 3 (DSA data access portal); Art. 6(4)(c) (DSA data catalogues); Art. 16 (entry into force), OJ L series, 2025/2050, 9.10.2025

Tier 2 · regulatorstates this

New measures unlock access to data of the largest online platforms to support research — European Commission 29 October 2025 "As of 29 October 2025, new rules under the Digital Services Act (DSA) will allow researchers to gain unprecedented access"

Tier 2 · regulatorstates this

Commission adopts delegated act on data access under the Digital Services Act — European Commission 2 July 2025 "On 2 July 2025, the Commission published a delegated act"; "testing of the DSA Portal"

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The Commission supervises the DSA only for VLOPs and VLOSEs; national Digital Services Coordinators supervise every tier below that.

Tier 1 · primary lawstates this

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Arts. 49, 56

Read it in the brief →Last verified 27 August 2026
Primary lawlaw

The DSA deleted the intermediary-liability provisions of the e-Commerce Directive (Articles 12 to 15 of Directive 2000/31/EC) and replaced them with its own conditional exemptions.

Tier 1 · primary lawstates this

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Art. 89(1)–(2); Arts. 4–6, 8

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 34 DSA requires providers of very large online platforms and search engines to identify, analyse and assess systemic risks stemming from the design or functioning of their service, including algorithmic systems, at least once a year and before deploying functionalities likely to have a critical impact: illegal content; negative effects on fundamental rights; on civic discourse, electoral processes and public security; and in relation to gender-based violence, public health, minors and physical and mental well-being — taking into account recommender and other algorithmic systems and intentional manipulation, including inauthentic use.

Tier 1 · primary lawstates this

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Art. 34(1)(a)–(d); Art. 34(2)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 35 DSA requires reasonable, proportionate and effective mitigation measures tailored to the systemic risks identified; the measures it lists are examples of what they may include.

Tier 1 · primary lawstates this

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Art. 35(1)

Read it in the brief →Last verified 27 September 2026
Official sourcefact

In the X proceedings the Commission recorded that X had three employees working part-time on assessing data access requests.

Tier 2 · regulatorstates this

Commission Decision C(2025) 8630 final of 5.12.2025, Cases DSA.100101, DSA.100102 and DSA.100103 — X (formerly Twitter) — US House Judiciary Committee (release of the European Commission's decision) January 2026 Recital 320

Tier 2 · regulatorsupports in part

Commission fines X EUR 120 million under the Digital Services Act — European Commission 5 December 2025

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III

Read it in the brief →Last verified 26 September 2026
Official sourcefact

After X withdrew its free academic API, the Commission found researchers left with X's commercial developer API, whose 'Pro' tier cost USD 5,000 per month.

Tier 2 · regulatorstates this

Commission Decision C(2025) 8630 final of 5.12.2025, Cases DSA.100101, DSA.100102 and DSA.100103 — X (formerly Twitter) — US House Judiciary Committee (release of the European Commission's decision) January 2026 Recital 302 and Figure 13

Read it in the brief →Last verified 26 September 2026
Official sourcefact

On 5 December 2025 the Commission fined X EUR 120 million under the DSA for deceptive design in the paid blue checkmark, a non-functional ad repository, and obstruction of researcher access.

Tier 2 · regulatorsupports in part

Commission Decision C(2025) 8630 final of 5.12.2025, Cases DSA.100101, DSA.100102 and DSA.100103 — X (formerly Twitter) — US House Judiciary Committee (release of the European Commission's decision) January 2026 Articles 4-6; signature page 183

Tier 2 · regulatorstates this

Commission fines X EUR 120 million under the Digital Services Act — European Commission 5 December 2025 "a fine of €120 million … The breaches include the deceptive design of its 'blue checkmark', the lack of transparency of its advertising repository, and the failure to provide access to public data for researchers"

Tier 4 · press / advocacysupports in part

EU fines X 120 million in first DSA non-compliance decision — eucrim December 2025

Read it in the brief →Last verified 27 September 2026
Official sourcefact

On 28 May 2026 the Commission fined Temu EUR 200 million under the DSA for failing to diligently identify, analyse and assess the systemic risks from the sale of illegal products on its platform.

Tier 2 · regulatorstates this

Commission fines Temu EUR 200 million for breaching the Digital Services Act — European Commission 28 May 2026 IP/26/1178: "The company failed to diligently identify, analyse, and assess the systemic risks of illegal products being offered on its platform"; Next steps: the action plan must "remedy the breach of its risk-assessment obligations"

Tier 4 · press / advocacysupports in part

EU tests limits of platform risk assessments with 200 million Temu fine — Tech Policy Press May 2026

Read it in the brief →Last verified 27 September 2026
Official sourcefact

Platform challenges to the DSA supervisory-fee decisions succeeded before the General Court for both TikTok and Meta.

Tier 2 · regulatorstates this

Press Release No 114/25 — Cases T-55/24 Meta Platforms Ireland and T-58/24 TikTok Technology — General Court of the European Union 10 September 2025 Press Release No 114/25: "The General Court annuls the implementing decisions, while maintaining their effects for a provisional period"

Tier 4 · press / advocacysupports in part

Meta, TikTok facing EU Commission appeal against supervisory fee court ruling — MLex 24 November 2025

Tier 4 · press / advocacysupports in part

Meta and TikTok supervisory fee wins appealed by EU Commission — MLex 12 January 2026

Read it in the brief →Last verified 27 September 2026
Official sourcefact

On 20 July 2026 the Commission fined AliExpress EUR 550 million under the DSA for failure to adequately assess and mitigate systemic risks from the sale of illegal, unsafe and counterfeit products — the largest DSA fine to date.

Tier 2 · regulatorstates this

Commission fines AliExpress EUR 550 million for breaching the Digital Services Act — European Commission 20 July 2026 Headline: "Commission fines AliExpress €550 million"; "fell short of its obligation … to diligently assess the risk of dissemination of illegal, unsafe, or counterfeit products"

Read it in the brief →Last verified 27 September 2026
Secondary onlyfact

In January 2026 the Polish President vetoed the national law implementing the DSA; in September 2026 he signed a narrower replacement making the head of UKE the Digital Services Coordinator, while a second bill, on blocking illegal content, was still before parliament.

Tier 4 · press / advocacystates this

President's veto further delays the implementation of the DSA in Poland — European Digital Rights (EDRi) 21 January 2026 Title and dateline: "President's veto delays the implementation of the DSA in Poland", 21 January 2026

Tier 4 · press / advocacystates this

Prezydent podpisał 5 ustaw, w tym pierwszą wdrażającą DSA — 300polityka 25 September 2026 25 September 2026: "Prezydent podpisał 5 ustaw, w tym pierwszą wdrażającą DSA"

Tier 4 · press / advocacysupports in part

Nawrocki podpisał ustawę. Polska będzie mogła karać platformy internetowe — Interia Biznes September 2026

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretationunverified

Almost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretation

The instruments following the GDPR reproduce the same institutional shape — a specialised vocabulary, principles, case-specific rights and a supervisory apparatus — a pattern described as act-ification and GDPR mimesis.

Tier 3 · researchstates this

The Regulation of Digital Technologies in the EU: the law-making phenomena of “act-ification”, “GDPR mimesis” and “EU law brutality” — Papakonstantinou and De Hert 21 May 2022 Abstract: "three basic phenomena common to all, or most, EU new technology-relevant regulatory initiatives, namely (a) act-ification, (b) GDPR mimesis, and (c) regulatory brutality"

Read it in the brief →Last verified 27 September 2026
Interpretationcritique

The recurring objection across every instrument is a capacity-ambition gap: broad obligations assigned either to a single Commission directorate with a few hundred staff or to twenty-seven national authorities of radically unequal resource.

Tier 4 · press / advocacysupports in part

The case for a European Union digital enforcement authority — Bruegel 5 March 2026

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I, Part IX

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretationunverified

The operative standards of the EU digital rulebook — systemic risk, high-impact capabilities, effective interoperability, genuinely equivalent alternative — are almost all open-textured, so the law's effective content is set by Commission guidelines, delegated acts, codes of practice and harmonised standards rather than by the legislature.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX

Read it in the brief →no verification date recorded
Interpretationinterpretationunverified

A single recommender system can engage the GDPR, the DSA, the AI Act and, for a gatekeeper, the DMA at once, so the rational compliance strategy is one control set mapped to several regimes.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX

Read it in the brief →no verification date recorded
Interpretationinterpretationunverified

Because every designated gatekeeper undertaking and nearly every VLOP is non-European, the rulebook is a foreign-policy object: this shapes the timing of decisions, the choice between fines and commitments, and the political viability of expanding scope.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX

Read it in the brief →no verification date recorded
Interpretationinterpretationunverified

GDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties; an organisation running all three separately duplicates work regulators themselves acknowledge is duplicated.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 27 August 2026
Interpretationcritique

Because DSA Art. 16(3) makes a compliant notice give rise to actual knowledge and therefore liability exposure, while over-removal carries no equivalent liability — Article 14(4)'s duty to act diligently, objectively and proportionately gives it a legal cost only in principle — the rational response to a borderline notice is removal.

Tier 1 · primary lawsupports in part

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Art. 16(3)

Tier 4 · press / advocacysupports in part

The Digital Services Act — Article 14 (Terms and conditions) and Article 19 (Exclusion for micro and small enterprises) — eu-digital-services-act.com (unofficial reproduction of the DSA text) Art. 14(4)

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III

Read it in the brief →Last verified 26 September 2026
Interpretationcritique

DSA Art. 34–35 systemic risk is deliberately open-textured, and both failure modes are live: overly specific criteria risk platforms optimising for metrics rather than real harms, while overly vague ones leave the concept unadministrable.

Tier 3 · researchstates this

Researching Systemic Risks under the Digital Services Act (interim report) — AlgorithmWatch 26 July 2024

Tier 1 · primary lawsupports in part

Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex 27 October 2022 Arts. 34–35

Read it in the brief →Last verified 27 August 2026
Interpretationcritique

DSA Article 40 researcher data access is underperforming in practice, with a documented playbook of available refusals grounded in the purpose limitation.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III

Tier 2 · regulatorsupports in part

Commission fines X EUR 120 million under the Digital Services Act — European Commission 5 December 2025

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretation

The Commission's stated priority in DSA enforcement is compliance rather than revenue: TikTok's ad-repository failings were cured by binding commitment rather than fine.

Tier 2 · regulatorsupports in part

Commission accepts TikTok's commitments on advertising transparency under the Digital Services Act (IP/25/2940) — European Commission 5 December 2025 Executive Vice-President's quotation

Tier 2 · regulatorsupports in part

Commission accepts TikTok's commitments on advertising transparency under the Digital Services Act — European Commission 5 December 2025

Read it in the brief →Last verified 26 September 2026
Interpretationinterpretation

The February 2026 TikTok preliminary findings were among the first enforcement actions targeting platform architecture — infinite scroll, autoplay, personalised recommenders — rather than illegal content.

Tier 2 · regulatorsupports in part

Commission preliminarily finds TikTok's addictive design in breach of the Digital Services Act — European Commission 6 February 2026

Read it in the brief →Last verified 26 September 2026
Interpretationinterpretation

DSA enforcement escalated across 2025–2026, from the X and Temu fines to preliminary findings against TikTok and Meta on addictive design and minors' safety.

Tier 2 · regulatorsupports in part

Commission fines X EUR 120 million under the Digital Services Act — European Commission 5 December 2025

Tier 2 · regulatorsupports in part

Commission fines Temu EUR 200 million for breaching the Digital Services Act — European Commission 28 May 2026

Tier 2 · regulatorsupports in part

Commission preliminarily finds TikTok's addictive design in breach of the Digital Services Act — European Commission 6 February 2026

Read it in the brief →Last verified 26 September 2026
Interpretationcritiqueunverified

Announcing preliminary findings with detailed proposed remedies before publishing reasoning risks findings that are less responsive to debate and less likely to survive court challenge.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretationunverified

The DSA–GDPR interface is unresolved: the DSA tells platforms to be transparent while the GDPR tells them to minimise, and EDPB guidance mediates the conflict without dissolving it.

Tier 2 · regulatorcontext only

EDPB Guidelines 3/2025 on the interplay between the DSA and the GDPR — European Data Protection Board 17 September 2026 Guidelines 3/2025 v2 (final, 17 September 2026) on the EDPB's site; v1 consulted 12 September – 31 October 2025

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III

Read it in the brief →Last verified 27 September 2026
Interpretationcritique

The AI Act is one instrument in a system that already regulated most of its subject matter: automated decision-making by GDPR Art. 22 since 2018, algorithmic recommender risk by DSA Arts. 34–35, product liability by the revised PLD — while the proposed AI Liability Directive was abandoned, leaving a gap in the fault-based route.

Tier 1 · primary lawsupports in part

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 22

Tier 1 · primary lawsupports in part

Directive (EU) 2024/2853 on liability for defective products — EUR-Lex 18 November 2024

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V

Read it in the brief →Last verified 27 August 2026
Interpretationcritiqueunverified

This body of law restrains corporate power far more effectively than it restrains state power, and the enforcement asymmetry between corporate and state addressees is not seriously disputable.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part XI

Read it in the brief →Last verified 27 August 2026
Unresolvedattributedunverified

Practitioner analysis argues the blue-checkmark finding may have been routed through DSA Article 25 in a way that ignores the Article 25(2) exclusion for practices covered by the Unfair Commercial Practices Directive, making it vulnerable to annulment.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III

Read it in the brief →Last verified 27 September 2026

The full bibliography and the evidence method →

How it interacts

3 recorded interactions with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.

DSA In tension with GDPR

Content moderation is processing; ad repositories publish targeting data; Art. 40 access almost always entails personal data. The DSA tells platforms to be transparent while the GDPR tells them to minimise. EDPB guidance mediates the conflict but does not dissolve it.

Carried byDSA Art. 40DSA Art. 39
What the brief argues
  • InterpretationThe DSA–GDPR interface is unresolved: the DSA tells platforms to be transparent while the GDPR tells them to minimise, and EDPB guidance mediates the conflict without dissolving it.

Recorded as at August 27, 2026

DSA Complements DMA

Both regulate large platforms but on different axes: the DSA on systemic risk and due diligence, the DMA on contestability and fairness. Designation under one does not imply designation under the other.

Carried byDSA Art. 33DMA Art. 3

Recorded as at August 27, 2026