Caching Services under DSA
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal β legal information, not advice.Caching is a specific intermediary service category under DSA Article 5 with distinct liability conditions and technical requirements that warrant dedicated topic coverage separate from general intermediary liability frameworks.
Overview
9 sources Β· Jul 23, 2026Legal Framework
Caching is one of three intermediary service categories recognised under the DSA, alongside mere conduit and hosting. Article 5 DSA defines caching as the automatic, intermediate and temporary transmission of information in a service provider's information system, performed for the sole purpose of making the onward transmission of that information more efficient to other recipients upon their request. The provision builds directly on the legacy framework of Articles 12β15 of Directive 2000/31/EC (the E-Commerce Directive), which established the original safe harbour for caching intermediaries. Those rules were transposed into national law β for example, through Article 6:196c of the Dutch Civil Code β and the DSA now supersedes and refines that regime at the EU level.
Recital 5 DSA confirms the regulation's scope covers intermediary services as defined in Directive (EU) 2015/1535, specifically including caching. The rationale for a distinct caching category is technical: caching providers do not initiate or select the cached content but do exercise a degree of automatic, system-level control over what is stored and for how long, which justifies liability conditions distinct from both mere conduit (no storage) and hosting (storage at the provider's discretion).
The DSA's territorial scope, governed by Article 3, applies to caching providers that have a substantial connection to the EU β whether through an establishment or by offering services to recipients in the Union. The concept of establishment, as developed in the CJEU's Google Spain ruling under the predecessor Privacy Directive, requires effective and actual exercise of activity through stable arrangements, even if minimal in scale. A commercial agent collecting payments related to an internet service may qualify as an establishment where processing arrangements are tied to that presence.
Key Developments
The E-Commerce Directive's caching safe harbour, now carried forward into the DSA, has been interpreted by the CJEU to require strict neutrality of the technical process. In cases such as Scarlet Extended v. SABAM and SABAM v. Netlog, the Court emphasised that intermediary safe harbours depend on the provider not playing an active role in selecting or modifying cached content. Where a caching provider adopts information that alters the transmitted data or selects recipients based on individualised criteria, the safe harbour is forfeited.
The DSA preserves this distinction but adds layered obligations: caching providers must not modify the information they transmit, must comply with conditions on access to the cached information, and must remove or disable access to particular cached items upon obtaining actual knowledge of their unlawful nature. The standard for "actual knowledge" aligns with the framework established under the E-Commerce Directive, where awareness must be specific rather than general.
Practical Guidance
Verify technical neutrality: Ensure caching processes are fully automatic, do not alter cached content, and do not select recipients based on individualised profiling β any active intervention risks reclassification as a hosting provider with broader obligations.
Establish notice-and-action mechanisms: Implement accessible channels through which unlawful cached content can be reported, and document the internal process for assessing and acting on such notices to demonstrate compliance with Article 5 conditions.
Audit territorial connections: Determine whether your caching infrastructure or commercial arrangements create an EU establishment under the Google Spain standard, triggering full DSA obligations regardless of where servers are physically located.
Preserve the integrity of cached data: Maintain technical safeguards preventing any modification of cached information during storage and onward transmission, and log evidence of these safeguards for regulatory inspection.
Coordinate with GDPR consent requirements: Where caching involves processing personal data, ensure that any consent obtained meets the standard of genuine free choice β bundled or coerced consent invalidates the lawful basis under Article 3 GDPR as interpreted through Recital 42.