Skip to content
Topic Developing

Competent Authorities Designation and Powers under DSA

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content is titled 'Competences' from the DSA and discusses the allocation and scope of authority powers under the Digital Services Act. This requires a dedicated topic covering DSA-specific competent authority designation, powers, and responsibilities.

42 linked items 40 Laws2 News

Overview

6 sources · Jul 23, 2026

Legal Framework

Article 49 of the Digital Services Act (DSA) establishes the foundational architecture for competent authority designation within each Member State. It requires every Member State to designate one or more authorities responsible for supervising and enforcing the Regulation's obligations. Where a Member State appoints more than one competent authority, it must designate a single authority as its Digital Services Coordinator (DSC), who then serves as the sole contact point for the Commission, the Board, and other Member States' authorities.

Recital 110 explains the rationale: given the cross-border nature of intermediary services and the horizontal scope of DSA obligations, a centralized supervisory entry point in each Member State is essential for effective coordination. The DSC must be equipped with adequate resources and technical expertise, and Member States must ensure its independence from external influence, including from providers of intermediary services.

Article 84 addresses the enforcement toolkit, specifically administrative fines. It provides that fines may be imposed up to 6% of global annual turnover, depending on the severity and duration of the infringement. The provision accommodates constitutional divergences: in Denmark and Estonia, where administrative fines as described in the Regulation are not available under national law, the equivalent sanction may be imposed through criminal proceedings by a competent court (Denmark) or within a criminal procedure framework by the supervisory authority (Estonia), provided the application achieves an equivalent effect.

Key Developments

The DSA's enforcement architecture is still maturing, but several practical thresholds are emerging. The designation of DSCs across Member States has been uneven, with some states consolidating authority in existing data protection or media regulators and others creating new bodies. This fragmentation means that providers operating across borders must identify the correct DSC for each jurisdiction where they offer services.

The Commission's direct enforcement role over Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) under Article 56 creates a bifurcated enforcement landscape. National DSCs handle supervision of all other intermediary services, while the Commission retains exclusive competence for systemic risk assessments, audits, and corresponding enforcement against designated VLOPs and VLOSEs.

The adaptation mechanisms in Article 84 for Denmark and Estonia illustrate a broader principle: enforcement must produce equivalent deterrent effect regardless of national procedural frameworks. Practitioners advising clients in those jurisdictions should expect criminal-law procedural protections to apply, including heightened evidentiary standards.

Practical Guidance

  • Map your supervisory landscape: Identify the designated DSC in every Member State where you offer services, as enforcement jurisdiction follows service availability, not establishment alone. Track designation notices published by each Member State under Article 49.

  • Establish a single liaison channel with the DSC: Since the DSC is the sole contact point under Recital 110, internal escalation procedures should route all regulatory communications through one designated function to avoid inconsistent positions being communicated to authorities.

  • Prepare for dual-track enforcement risk: If you operate a VLOP or VLOSE, anticipate Commission-led enforcement under Article 56 alongside potential DSC coordination. Maintain separate compliance documentation for systemic risk obligations versus general DSA duties.

  • Account for jurisdiction-specific fine exposure in financial planning: In Denmark and Estonia, sanctions may follow criminal procedures with different evidentiary and procedural standards. Factor these distinctions into risk assessments for operations in those markets.

  • Verify DSC independence and resource mandates when challenging enforcement: Article 49 requires Member States to guarantee DSC independence. Where a DSC's institutional setup raises questions about impartiality—particularly where it shares functions with sector-specific regulators—this may provide a basis for procedural challenges to enforcement actions.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 40
Art. 1(2)(c) rules on the implementation and enforcement of this Regulation, including as regards the cooperation of and coordination between the competent authori… DSA Art. 3(n) ‘Digital Services Coordinator of establishment’ means the Digital Services Coordinator of the Member State where the main establishment of a provider … DSA Art. 3(o) ‘Digital Services Coordinator of destination’ means the Digital Services Coordinator of a Member State where the intermediary service is provided; DSA Art. 9(3) The authority issuing the order or, where applicable, the authority specified therein, shall transmit it, along with any information received from the… DSA rec 114 Recital 114 — competent authorities enforcement powers and means DSA Oct 2022 rec 110 Recital 110 — national Digital Services Coordinator designation DSA Oct 2022 rec 111 Recital 111 — regulatory authority resources and expertise DSA Oct 2022 rec 118 Recital 118 — complaints to digital services coordinator DSA Oct 2022 rec 122 Recital 122 — Digital Services Coordinator activity reporting DSA Oct 2022 rec 125 Recital 125 — shared supervision and enforcement powers DSA Oct 2022 rec 113 Recital 113 — Digital Services Coordinator designation DSA Oct 2022 rec 119 Recital 119 — Digital Services Coordinator enforcement safeguards DSA Oct 2022 rec 112 Recital 112 — competent authorities independence and accountability DSA Oct 2022 art 49 Competent authorities and Digital Services Coordinators DSA Oct 2022 rec 140 Recital 140 — Commission enforcement powers for very large platforms DSA Oct 2022 rec 109 Recital 109 — Member States competent authorities designation DSA Oct 2022 rec 116 Recital 116 — fundamental rights procedural safeguards enforcement powers DSA Oct 2022 rec 127 Recital 127 — cross-border digital services cooperation DSA Oct 2022 rec 148 Recital 148 — secure information sharing system DSA Oct 2022 rec 139 Recital 139 — Commission enforcement discretion over very large platforms DSA Oct 2022 rec 123 Recital 123 — supervision by member state of establishment DSA Oct 2022 rec 124 Recital 124 — Commission supervision of very large platforms DSA Oct 2022 rec 128 Recital 128 — cross border enforcement cooperation requests DSA Oct 2022 rec 129 Recital 129 — Board referral to Commission DSA Oct 2022 Show 20 more →
News 2
GDPRhub UODO (Poland) - DKE.561.1.2026 GDPRhub Aug 2026 European Data Protection Board EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint European Data Protection Board Jul 2026