Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →EU Digital Services Act, AI and Algorithmic Accountability Provisions
Issued by
European Parliament and Council of the European Union; enforced by Digital Services Coordinators (DSCs) in each Member State and by the European Commission for Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs)
The Digital Services Act regulates online intermediaries’ recommender systems, targeted advertising, and systemic risks. Duties cover transparency, accountability, and risk management. Requirements increase with platform size, with the strictest applying to very large online platforms and search engines (VLOPs and VLOSEs).
Applies To
Overview
Regulation (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act, DSA) entered into force on 16 November 2022. Obligations for very large online platforms and search engines (VLOPs and VLOSEs) became applicable on 25 August 2023; those for all other in-scope providers on 17 February 2024. The DSA sets layered rules for online intermediary services, with AI-related duties in three areas: recommender systems (tools that pick what users see), targeted advertising, and systemic risk management. Online platforms must explain the main factors behind any recommender system they use and offer users alternatives, including at least one not based on profiling (tailoring from personal data). All online platforms are prohibited from using dark patterns (designs that trick or pressure users into choices) in their interfaces. For VLOPs and VLOSEs, which the European Commission designates once they reach at least 45 million average monthly active recipients in the EU, the obligations are much stricter. Designated platforms must conduct annual systemic risk assessments covering risks from algorithmic amplification (automated boosting) of illegal content, fundamental rights impacts, civic discourse, electoral processes, and gender-based violence. They must adopt reasonable mitigation measures, undergo annual independent audits, give vetted researchers data access, appoint a compliance officer, and share data with the Commission and Digital Services Coordinators. Advertising transparency requirements prohibit targeting minors or using sensitive personal data categories for micro-targeted advertising. The Commission alone polices VLOPs and VLOSEs, with fines up to six percent of global annual turnover and, for repeated infringement, periodic penalty payments and eventually temporary access restriction. Member State Digital Services Coordinators enforce obligations applicable to smaller platforms, with fines up to six percent of national turnover.
Key Requirements
- •All online platforms: Provide clear, accessible information about the main parameters of any recommender system and allow users to modify or opt out of profiling-based recommendations (Article 27).
- •All online platforms: Maintain an advertisement repository disclosing information about each advertisement served, including targeting parameters used (Article 39, applies to platforms with more than one million average monthly active EU recipients).
- •All online platforms: Prohibit the use of interface design that obscures choices or manipulates user behavior (dark patterns prohibition, Article 25).
- •VLOPs and VLOSEs: Conduct annual systemic risk assessments covering algorithmic amplification of illegal content, fundamental rights, democratic processes, and public health risks (Article 34).
- •VLOPs and VLOSEs: Design and implement proportionate risk mitigation measures and document those measures (Article 35).
- •VLOPs and VLOSEs: Submit to independent audits at least annually and publish audit reports (Article 37).
- •VLOPs and VLOSEs: Provide vetted researchers with access to data necessary for systemic risk research (Article 40).
- •VLOPs and VLOSEs: Appoint a DSA compliance officer at senior management level (Article 41).
- •VLOPs and VLOSEs: Prohibit targeted advertising directed at minors and advertising based on sensitive personal data categories (Article 26).
- •VLOPs and VLOSEs: Publish annual transparency reports and submit enhanced transparency reports to the Commission (Articles 15 and 42).
- •All in-scope providers: Publish terms of service in plain language describing content moderation policies and any use of automated means in enforcement.
What Your Organization Must Do
- →Determine your platform's classification immediately by calculating average monthly active EU recipients. Confirm whether you meet the 45 million VLOP/VLOSE (very large online platform or search engine) threshold or the 1 million threshold for the ad repository (public ad archive) obligation. Document that analysis with your legal and data teams.
- →Audit all recommender systems (tools that choose what content users see) in use. Assign your Chief Compliance Officer or a designated DSA Compliance Officer to map every factor used to rank content. Ensure user-facing explanations and at least one alternative not based on profiling (tailoring from personal data) are live and accessible.
- →Commission an annual systemic risk assessment (VLOPs and VLOSEs only) covering algorithmic amplification (automated boosting) of illegal content, fundamental rights impacts, electoral processes, and public health risks. Complete the first cycle and submit findings to the European Commission before any Commission-imposed deadline or audit cycle begins.
- →Engage an accredited independent auditor to conduct the annual DSA audit required under Article 37. Sign the engagement letter and define the audit scope early enough to publish a report within each annual cycle.
- →Implement advertising controls to block all targeting of minors and any targeting based on special categories of sensitive personal data (such as health, religion, or sexual orientation). Configure your ad repository to log and disclose targeting criteria for every ad served to EU recipients with more than 1 million average monthly active users.
- →Review all platform interface designs against the Article 25 prohibition on dark patterns (designs that trick or pressure users), and document fixes to any manipulative designs found. Set up a recurring user experience review, owned by product and compliance teams, to catch backsliding before inquiries from Digital Services Coordinators (national regulators) arise.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Governance Controls
Operational controls that implement requirements from this regulation.
Frequently Asked Questions
- Which platforms are classified as VLOPs under the DSA and subject to the strictest algorithmic accountability rules?
- The European Commission designates platforms as VLOPs when they reach at least 45 million average monthly active recipients in the EU. Current designees include major social media networks, large e-commerce marketplaces, and app stores. Designation triggers the full set of obligations including systemic risk assessments, independent audits, and researcher data access.
- When did DSA obligations become enforceable for platforms that are not VLOPs or VLOSEs?
- Baseline obligations for all other in-scope online intermediaries became applicable on 17 February 2024. VLOP and VLOSE obligations were already enforceable from 25 August 2023 following Commission designation decisions issued that year.
- What are the maximum fines for violating the DSA algorithmic transparency and risk management provisions?
- The European Commission can impose fines of up to 6 percent of a VLOP or VLOSE's global annual turnover for violations. For repeated infringement, periodic penalty payments and temporary access restrictions are also available. Member State DSCs can fine smaller platforms up to 6 percent of national annual turnover.
- Does the DSA require platforms to offer users a non-algorithmic feed or recommendation option?
- Yes. Under Article 27, all online platforms using recommender systems must offer users at least one option not based on profiling. The alternative must be clearly accessible and meaningfully distinct from personalized ranking, and platforms must explain the main parameters used in any recommender system they operate.
- How do the DSA's algorithmic risk assessment obligations differ from those under the EU AI Act?
- The DSA requires VLOPs and VLOSEs to conduct annual systemic risk assessments focused on societal harms such as electoral interference, illegal content amplification, and public health risks. The EU AI Act imposes conformity assessments on high-risk AI systems at the product level. A VLOP deploying a high-risk AI recommender system may need to satisfy both frameworks independently.
- Does the DSA prohibit all targeted advertising on VLOPs, or only certain types?
- The DSA does not ban targeted advertising broadly. It prohibits targeting minors and targeting based on sensitive personal data categories such as health, religion, or sexual orientation. All platforms above 1 million average monthly active EU recipients must also maintain a public ad repository disclosing targeting parameters used for each advertisement served.
