Competent Authorities Designation and Powers under DSA
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The content is titled 'Competences' from the DSA and discusses the allocation and scope of authority powers under the Digital Services Act. This requires a dedicated topic covering DSA-specific competent authority designation, powers, and responsibilities.
Overview
6 sources · Jul 23, 2026Legal Framework
Article 49 of the Digital Services Act (DSA) establishes the foundational architecture for competent authority designation within each Member State. It requires every Member State to designate one or more authorities responsible for supervising and enforcing the Regulation's obligations. Where a Member State appoints more than one competent authority, it must designate a single authority as its Digital Services Coordinator (DSC), who then serves as the sole contact point for the Commission, the Board, and other Member States' authorities.
Recital 110 explains the rationale: given the cross-border nature of intermediary services and the horizontal scope of DSA obligations, a centralized supervisory entry point in each Member State is essential for effective coordination. The DSC must be equipped with adequate resources and technical expertise, and Member States must ensure its independence from external influence, including from providers of intermediary services.
Article 84 addresses the enforcement toolkit, specifically administrative fines. It provides that fines may be imposed up to 6% of global annual turnover, depending on the severity and duration of the infringement. The provision accommodates constitutional divergences: in Denmark and Estonia, where administrative fines as described in the Regulation are not available under national law, the equivalent sanction may be imposed through criminal proceedings by a competent court (Denmark) or within a criminal procedure framework by the supervisory authority (Estonia), provided the application achieves an equivalent effect.
Key Developments
The DSA's enforcement architecture is still maturing, but several practical thresholds are emerging. The designation of DSCs across Member States has been uneven, with some states consolidating authority in existing data protection or media regulators and others creating new bodies. This fragmentation means that providers operating across borders must identify the correct DSC for each jurisdiction where they offer services.
The Commission's direct enforcement role over Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) under Article 56 creates a bifurcated enforcement landscape. National DSCs handle supervision of all other intermediary services, while the Commission retains exclusive competence for systemic risk assessments, audits, and corresponding enforcement against designated VLOPs and VLOSEs.
The adaptation mechanisms in Article 84 for Denmark and Estonia illustrate a broader principle: enforcement must produce equivalent deterrent effect regardless of national procedural frameworks. Practitioners advising clients in those jurisdictions should expect criminal-law procedural protections to apply, including heightened evidentiary standards.
Practical Guidance
Map your supervisory landscape: Identify the designated DSC in every Member State where you offer services, as enforcement jurisdiction follows service availability, not establishment alone. Track designation notices published by each Member State under Article 49.
Establish a single liaison channel with the DSC: Since the DSC is the sole contact point under Recital 110, internal escalation procedures should route all regulatory communications through one designated function to avoid inconsistent positions being communicated to authorities.
Prepare for dual-track enforcement risk: If you operate a VLOP or VLOSE, anticipate Commission-led enforcement under Article 56 alongside potential DSC coordination. Maintain separate compliance documentation for systemic risk obligations versus general DSA duties.
Account for jurisdiction-specific fine exposure in financial planning: In Denmark and Estonia, sanctions may follow criminal procedures with different evidentiary and procedural standards. Factor these distinctions into risk assessments for operations in those markets.
Verify DSC independence and resource mandates when challenging enforcement: Article 49 requires Member States to guarantee DSC independence. Where a DSC's institutional setup raises questions about impartiality—particularly where it shares functions with sector-specific regulators—this may provide a basis for procedural challenges to enforcement actions.