# Caching Services under DSA — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/caching-services-dsa
> Sources are cited per item. Verify against the official texts before relying on them.

Caching is a specific intermediary service category under DSA Article 5 with distinct liability conditions and technical requirements that warrant dedicated topic coverage separate from general intermediary liability frameworks.

## Overview

## Legal Framework

Caching is one of three intermediary service categories recognised under the DSA, alongside mere conduit and hosting. Article 5 DSA defines caching as the automatic, intermediate and temporary transmission of information in a service provider's information system, performed for the sole purpose of making the onward transmission of that information more efficient to other recipients upon their request. The provision builds directly on the legacy framework of Articles 12–15 of Directive 2000/31/EC (the E-Commerce Directive), which established the original safe harbour for caching intermediaries. Those rules were transposed into national law — for example, through Article 6:196c of the Dutch Civil Code — and the DSA now supersedes and refines that regime at the EU level.

Recital 5 DSA confirms the regulation's scope covers intermediary services as defined in Directive (EU) 2015/1535, specifically including caching. The rationale for a distinct caching category is technical: caching providers do not initiate or select the cached content but do exercise a degree of automatic, system-level control over what is stored and for how long, which justifies liability conditions distinct from both mere conduit (no storage) and hosting (storage at the provider's discretion).

The DSA's territorial scope, governed by Article 3, applies to caching providers that have a substantial connection to the EU — whether through an establishment or by offering services to recipients in the Union. The concept of establishment, as developed in the CJEU's Google Spain ruling under the predecessor Privacy Directive, requires effective and actual exercise of activity through stable arrangements, even if minimal in scale. A commercial agent collecting payments related to an internet service may qualify as an establishment where processing arrangements are tied to that presence.

## Key Developments

The E-Commerce Directive's caching safe harbour, now carried forward into the DSA, has been interpreted by the CJEU to require strict neutrality of the technical process. In cases such as *Scarlet Extended v. SABAM* and *SABAM v. Netlog*, the Court emphasised that intermediary safe harbours depend on the provider not playing an active role in selecting or modifying cached content. Where a caching provider adopts information that alters the transmitted data or selects recipients based on individualised criteria, the safe harbour is forfeited.

The DSA preserves this distinction but adds layered obligations: caching providers must not modify the information they transmit, must comply with conditions on access to the cached information, and must remove or disable access to particular cached items upon obtaining actual knowledge of their unlawful nature. The standard for "actual knowledge" aligns with the framework established under the E-Commerce Directive, where awareness must be specific rather than general.

## Practical Guidance

- **Verify technical neutrality**: Ensure caching processes are fully automatic, do not alter cached content, and do not select recipients based on individualised profiling — any active intervention risks reclassification as a hosting provider with broader obligations.

- **Establish notice-and-action mechanisms**: Implement accessible channels through which unlawful cached content can be reported, and document the internal process for assessing and acting on such notices to demonstrate compliance with Article 5 conditions.

- **Audit territorial connections**: Determine whether your caching infrastructure or commercial arrangements create an EU establishment under the Google Spain standard, triggering full DSA obligations regardless of where servers are physically located.

- **Preserve the integrity of cached data**: Maintain technical safeguards preventing any modification of cached information during storage and onward transmission, and log evidence of these safeguards for regulatory inspection.

- **Coordinate with GDPR consent requirements**: Where caching involves processing personal data, ensure that any consent obtained meets the standard of genuine free choice — bundled or coerced consent invalidates the lawful basis under Article 3 GDPR as interpreted through Recital 42.

## Legislation (full text of key provisions)

### ‘Caching’

*Source: DSA, dsa-art-5-en, 2022-10-19 — https://overview.legal/posts/94113*

### Recital 5 — scope covering intermediary service providers

*Source: DSA, dsa-rec-5-en, 2022-10-19 — https://overview.legal/posts/95407*

This Regulation should apply to providers of certain information society services as defined in Directive (EU) 2015/1535 of the European Parliament and of the Council (5), that is, any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient. Specifically, this Regulation should apply to providers of intermediary services, and in particular intermediary services consisting of services known as ‘mere conduit’, ‘caching’ and ‘hosting’ services, given that the exponential growth of the use made of those services, mainly for legitimate and socially beneficial purposes of all kinds, has also increased their role in the intermediation and spread of unlawful or otherwise harmful information and activities.

### Recital 28 — new online technologies intermediary services

*Source: DSA, dsa-rec-28-en, 2022-10-19 — https://overview.legal/posts/95453*

Since 2000, new technologies have emerged that improve the availability, efficiency, speed, reliability, capacity and security of systems for the transmission, ‘findability’ and storage of data online, leading to an increasingly complex online ecosystem. In this regard, it should be recalled that providers of services establishing and facilitating the underlying logical architecture and proper functioning of the internet, including technical auxiliary functions, can also benefit from the exemptions from liability set out in this Regulation, to the extent that their services qualify as ‘mere conduit’, ‘caching’ or ‘hosting’ services. Such services include, as the case may be, wireless local area networks, domain name system (DNS) services, top-level domain name registries, registrars, certificate authorities that issue digital certificates, virtual private networks, online search engines, cloud infrastructure services, or content delivery networks, that enable, locate or improve the functions of other providers of intermediary services. Likewise, services used for communications purposes, and the technical means of their delivery, have also evolved considerably, giving rise to online services such as Voice over IP, messaging services and web-based email services, where the communication is delivered via an internet access service. Those services, too, can benefit from the exemptions from liability, to the extent that they qualify as ‘mere conduit’, ‘caching’ or ‘hosting’ services.

### Recital 29 — online intermediary service categories and examples

*Source: DSA, dsa-rec-29-en, 2022-10-19 — https://overview.legal/posts/95455*

Intermediary services span a wide range of economic activities which take place online and that develop continually to provide for transmission of information that is swift, safe and secure, and to ensure convenience of all participants of the online ecosystem. For example, ‘mere conduit’ intermediary services include generic categories of services, such as internet exchange points, wireless access points, virtual private networks, DNS services and resolvers, top-level domain name registries, registrars, certificate authorities that issue digital certificates, voice over IP and other interpersonal communication services, while generic examples of ‘caching’ intermediary services include the sole provision of content delivery networks, reverse proxies or content adaptation proxies. Such services are crucial to ensure the smooth and efficient transmission of information delivered on the internet. Examples of ‘hosting services’ include categories of services such as cloud computing, web hosting, paid referencing services or services enabling sharing information and content online, including file storage and sharing. Intermediary services may be provided in isolation, as a part of another type of intermediary service, or simultaneously with other intermediary services. Whether a specific service constitutes a ‘mere conduit’, ‘caching’ or ‘hosting’ service depends solely on its technical functionalities, which might evolve in time, and should be assessed on a case-by-case basis.

### Recital 19 — differentiated intermediary service activity rules

*Source: DSA, dsa-rec-19-en, 2022-10-19 — https://overview.legal/posts/95435*

In view of the different nature of the activities of ‘mere conduit’, ‘caching’ and ‘hosting’ and the different position and abilities of the providers of the services in question, it is necessary to distinguish the rules applicable to those activities, in so far as under this Regulation they are subject to different requirements and conditions and their scope differs, as interpreted by the Court of Justice of the European Union.

### Recital 21 — liability exemptions for intermediary services

*Source: DSA, dsa-rec-21-en, 2022-10-19 — https://overview.legal/posts/95439*

A provider should be able to benefit from the exemptions from liability for ‘mere conduit’ and for ‘caching’ services when it is in no way involved with the information transmitted or accessed. This requires, among other things, that the provider does not modify the information that it transmits or to which it provides access. However, this requirement should not be understood to cover manipulations of a technical nature which take place in the course of the transmission or access, as long as those manipulations do not alter the integrity of the information transmitted or to which access is provided.

## Related topics

- **Intermediary Liability Framework under DSA** — https://overview.legal/topics/intermediary-liability-framework-dsa
  This topic is needed to comprehensively cover the broader intermediary liability framework under the DSA, of which mere conduit is one component, including the 
- **DSA Scope and Digital Services Coverage** — https://overview.legal/topics/dsa-scope-digital-services
  The content is from the DSA (Digital Services Act), not the AI Act. A dedicated topic for DSA scope is needed to distinguish it from AI Act scope provisions and
- **Recipient** — https://overview.legal/topics/recipient
  A person or body to which personal data are disclosed (Art 4(9) GDPR).
- **Hosting Services under DSA** — https://overview.legal/topics/hosting-services-dsa
  While intermediary liability and DSA scope topics exist, there is no dedicated topic specifically for hosting services, their liability conditions, exemptions, 
- **Cloud Computing** — https://overview.legal/topics/cloud-computing
  Use of cloud services and associated data protection requirements
- **Child Consent** — https://overview.legal/topics/child-consent-information-society-services
  This new topic is needed because the content specifically addresses the unique conditions and requirements for obtaining valid consent from children in the cont

---
Generated by overview.legal · https://overview.legal/topics/caching-services-dsa · 2026-08-22
