# Competent Authorities Designation and Powers under DSA — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/dsa-competent-authorities-designation
> Sources are cited per item. Verify against the official texts before relying on them.

The content is titled 'Competences' from the DSA and discusses the allocation and scope of authority powers under the Digital Services Act. This requires a dedicated topic covering DSA-specific competent authority designation, powers, and responsibilities.

## Overview

## Legal Framework

Article 49 of the Digital Services Act (DSA) establishes the foundational architecture for competent authority designation within each Member State. It requires every Member State to designate one or more authorities responsible for supervising and enforcing the Regulation's obligations. Where a Member State appoints more than one competent authority, it must designate a single authority as its Digital Services Coordinator (DSC), who then serves as the sole contact point for the Commission, the Board, and other Member States' authorities.

Recital 110 explains the rationale: given the cross-border nature of intermediary services and the horizontal scope of DSA obligations, a centralized supervisory entry point in each Member State is essential for effective coordination. The DSC must be equipped with adequate resources and technical expertise, and Member States must ensure its independence from external influence, including from providers of intermediary services.

Article 84 addresses the enforcement toolkit, specifically administrative fines. It provides that fines may be imposed up to 6% of global annual turnover, depending on the severity and duration of the infringement. The provision accommodates constitutional divergences: in Denmark and Estonia, where administrative fines as described in the Regulation are not available under national law, the equivalent sanction may be imposed through criminal proceedings by a competent court (Denmark) or within a criminal procedure framework by the supervisory authority (Estonia), provided the application achieves an equivalent effect.

## Key Developments

The DSA's enforcement architecture is still maturing, but several practical thresholds are emerging. The designation of DSCs across Member States has been uneven, with some states consolidating authority in existing data protection or media regulators and others creating new bodies. This fragmentation means that providers operating across borders must identify the correct DSC for each jurisdiction where they offer services.

The Commission's direct enforcement role over Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) under Article 56 creates a bifurcated enforcement landscape. National DSCs handle supervision of all other intermediary services, while the Commission retains exclusive competence for systemic risk assessments, audits, and corresponding enforcement against designated VLOPs and VLOSEs.

The adaptation mechanisms in Article 84 for Denmark and Estonia illustrate a broader principle: enforcement must produce equivalent deterrent effect regardless of national procedural frameworks. Practitioners advising clients in those jurisdictions should expect criminal-law procedural protections to apply, including heightened evidentiary standards.

## Practical Guidance

- **Map your supervisory landscape**: Identify the designated DSC in every Member State where you offer services, as enforcement jurisdiction follows service availability, not establishment alone. Track designation notices published by each Member State under Article 49.

- **Establish a single liaison channel with the DSC**: Since the DSC is the sole contact point under Recital 110, internal escalation procedures should route all regulatory communications through one designated function to avoid inconsistent positions being communicated to authorities.

- **Prepare for dual-track enforcement risk**: If you operate a VLOP or VLOSE, anticipate Commission-led enforcement under Article 56 alongside potential DSC coordination. Maintain separate compliance documentation for systemic risk obligations versus general DSA duties.

- **Account for jurisdiction-specific fine exposure in financial planning**: In Denmark and Estonia, sanctions may follow criminal procedures with different evidentiary and procedural standards. Factor these distinctions into risk assessments for operations in those markets.

- **Verify DSC independence and resource mandates when challenging enforcement**: Article 49 requires Member States to guarantee DSC independence. Where a DSC's institutional setup raises questions about impartiality—particularly where it shares functions with sector-specific regulators—this may provide a basis for procedural challenges to enforcement actions.

## Legislation (full text of key provisions)

### Competent authorities and Digital Services Coordinators

*Source: DSA, dsa-art-49-en, 2022-10-19 — https://overview.legal/posts/94884*

### Right to lodge a complaint

*Source: DSA, dsa-art-53-en, 2022-10-19 — https://overview.legal/posts/94952*

Recipients of the service and any body, organisation or association mandated to exercise the rights conferred by this Regulation on their behalf shall have the right to lodge a complaint against providers of intermediary services alleging an infringement of this Regulation with the Digital Services Coordinator of the Member State where the recipient of the service is located or established. The Digital Services Coordinator shall assess the complaint and, where appropriate, transmit it to the Digital Services Coordinator of establishment, accompanied, where considered appropriate, by an opinion. Where the complaint falls under the responsibility of another competent authority in its Member State, the Digital Services Coordinator receiving the complaint shall transmit it to that authority. During these proceedings, both parties shall have the right to be heard and receive appropriate information about the status of the complaint, in accordance with national law.

### Professional secrecy

*Source: DSA, dsa-art-84-en, 2022-10-19 — https://overview.legal/posts/95314*

Without prejudice to the exchange and to the use of information referred to in this Chapter, the Commission, the Board, Member States’ competent authorities and their respective officials, servants and other persons working under their supervision, and any other natural or legal person involved, including auditors and experts appointed pursuant to Article 72(2), shall not disclose information acquired or exchanged by them pursuant to this Regulation and of the kind covered by the obligation of professional secrecy.

### Recital 114 — competent authorities enforcement powers and means

*Source: DSA, dsa-rec-114-en, 2022-10-19 — https://overview.legal/posts/95625*

Member States should provide the Digital Services Coordinator, and any other competent authority designated under this Regulation, with sufficient powers and means to ensure effective investigation and enforcement, in accordance with the tasks conferred on them. This includes the power of competent authorities to adopt interim measures in accordance with national law in case of risk of serious harm. Such interim measures, which may include orders to terminate or remedy a given alleged infringement, should not go beyond what is necessary to ensure that serious harm is prevented pending the final decision. The Digital Services Coordinators should in particular be able to search for and obtain information which is located in its territory, including in the context of joint investigations, with due regard to the fact that oversight and enforcement measures concerning a provider under the jurisdiction of another Member State or the Commission should be adopted by the Digital Services Coordinator of that other Member State, where relevant in accordance with the procedures relating to cross-border cooperation, or, where applicable, by the Commission.

### Recital 110 — national Digital Services Coordinator designation

*Source: DSA, dsa-rec-110-en, 2022-10-19 — https://overview.legal/posts/95617*

Given the cross-border nature of the services at stake and the horizontal range of obligations introduced by this Regulation, one authority appointed with the task of supervising the application and, where necessary, enforcing this Regulation should be identified as a Digital Services Coordinator in each Member State. Where more than one competent authority is appointed to supervise the application of, and enforce, this Regulation, only one authority in that Member State should be designated as a Digital Services Coordinator. The Digital Services Coordinator should act as the single contact point with regard to all matters related to the application of this Regulation for the Commission, the Board, the Digital Services Coordinators of other Member States, as well as for other competent authorities of the Member State in question. In particular, where several competent authorities are entrusted with tasks under this Regulation in a given Member State, the Digital Services Coordinator should coordinate and cooperate with those authorities in accordance with the national law setting their respective tasks and without prejudice to the independent assessment of the other competent authorities. While not entailing any hierarchical supraordination over other competent authorities in the exercise of their tasks, the Digital Services Coordinator should ensure effective involvement of all relevant competent authorities and should timely report their assessment in the context of cooperation on supervision and enforcement at Union level. Moreover, in addition to the specific mechanisms provided for in this Regulation as regards cooperation at Union level, Member State should also ensure cooperation among the Digital Services Coordinator and other competent authorities designated at national level, where applicable, through appropriate tools, such as by pooling of resources, joint task forces, joint investigations and mutual assistance mechanisms.

### Recital 111 — regulatory authority resources and expertise

*Source: DSA, dsa-rec-111-en, 2022-10-19 — https://overview.legal/posts/95619*

The Digital Services Coordinator, as well as other competent authorities designated under this Regulation, play a crucial role in ensuring the effectiveness of the rights and obligations laid down in this Regulation and the achievement of its objectives. Accordingly, it is necessary to ensure that those authorities have the necessary means, including financial and human resources, to supervise all the providers of intermediary services falling within their competence, in the interest of all Union citizens. Given the variety of providers of intermediary services and their use of advanced technology in providing their services, it is also essential that the Digital Services Coordinator and the relevant competent authorities are equipped with the necessary number of staff and experts with specialised skills and advanced technical means, and that they autonomously manage financial resources to carry out their tasks. Furthermore, the level of resources should take into account the size, complexity and potential societal impact of the providers of intermediary services falling within their competence, as well as the reach of their services across the Union. This Regulation is without prejudice to the possibility for Member States to establish funding mechanisms based on a supervisory fee charged to providers of intermediary services under national law in compliance with Union law, to the extent that it is levied on providers of intermediary services having their main establishment in the Member State in question, that it is strictly limited to what is necessary and proportionate to cover the costs for the fulfilment of the tasks conferred upon the competent authorities pursuant to this Regulation, with the exclusion of the tasks conferred upon the Commission, and that adequate transparency is ensured regarding the levying and the use of such a supervisory fee.

### Recital 118 — complaints to digital services coordinator

*Source: DSA, dsa-rec-118-en, 2022-10-19 — https://overview.legal/posts/95633*

In order to ensure effective enforcement of the obligations laid down in this Regulation, individuals or representative organisations should be able to lodge any complaint related to compliance with those obligations with the Digital Services Coordinator in the territory where they received the service, without prejudice to this Regulation’s rules on allocation of competences and to the applicable rules on handling of complaints in accordance with national principles of good administration. Complaints could provide a faithful overview of concerns related to a particular intermediary service provider’s compliance and could also inform the Digital Services Coordinator of any more cross-cutting issues. The Digital Services Coordinator should involve other national competent authorities as well as the Digital Services Coordinator of another Member State, and in particular the one of the Member State where the provider of intermediary services concerned is established, if the issue requires cross-border cooperation.

### Recital 122 — Digital Services Coordinator activity reporting

*Source: DSA, dsa-rec-122-en, 2022-10-19 — https://overview.legal/posts/95641*

The Digital Services Coordinator should regularly publish, for example on its website, a report on the activities carried out under this Regulation. In particular, the report should be published in a machine-readable format and include an overview of complaints received and of their follow-up, such as the overall number of complaints received and the number of complaints that led to the opening of a formal investigation or to the transmission to other Digital Services Coordinators, without referring to any personal data. Given that the Digital Services Coordinator is also made aware of orders to take action against illegal content or to provide information regulated by this Regulation through the information sharing system, the Digital Services Coordinator should include in its annual report the number and categories of such orders addressed to providers of intermediary services issued by judicial and administrative authorities in its Member State.

### Recital 125 — shared supervision and enforcement powers

*Source: DSA, dsa-rec-125-en, 2022-10-19 — https://overview.legal/posts/95647*

The powers of supervision and enforcement of due diligence obligations, other than the additional obligations to manage systemic risks imposed on providers of very large online platforms and of very large online search engines by this Regulation, should be shared by the Commission and by the national competent authorities. On the one hand, the Commission could in many instances be better placed to address systemic infringements committed by those providers, such as those affecting multiple Member States or serious repeated infringements or concerning a failure to establish effective mechanisms required by this Regulation. On the other hand, the competent authorities in the Member State where the main establishment of a provider of very large online platform or of very large online search engine is located could be better placed to address individual infringements committed by those providers, that do not raise any systemic or cross-border issues. In the interest of efficiency, to avoid duplication and to ensure compliance with the principle of ne bis in idem, it should be for the Commission to assess whether it deems it appropriate to exercise those shared competences in a given case and, once it has initiated proceedings, Member States should no longer have the ability to do so. Member States should cooperate closely both with each other and with the Commission, and the Commission should cooperate closely with the Member States, in order to ensure that the system of supervision and enforcement set up by this Regulation functions smoothly and effectively.

### Recital 113 — Digital Services Coordinator designation

*Source: DSA, dsa-rec-113-en, 2022-10-19 — https://overview.legal/posts/95623*

Member States can designate an existing national authority with the function of the Digital Services Coordinator, or with specific tasks to supervise the application and enforce this Regulation, provided that any such appointed authority complies with the requirements laid down in this Regulation, such as in relation to its independence. Moreover, Member States are in principle not precluded from merging functions within an existing authority, in accordance with Union law. The measures to that effect may include, inter alia, the preclusion to dismiss the president or a board member of a collegiate body of an existing authority before the expiry of their terms of office, on the sole ground that an institutional reform has taken place involving the merger of different functions within one authority, in the absence of any rules guaranteeing that such dismissals do not jeopardise the independence and impartiality of such members.

## Recent developments

### UODO (Poland) - DKE.561.1.2026

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291290 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKE.561.1.2026*

The DPA reprimanded a company for refusing to cooperate with the supervisory authority: the controller had failed to provide information on the processing of personal data in two pending cases against it. English Summary. Facts. The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned processing that had taken place in January 2025, while the events giving rise to the second complai

### EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

*Source: European Data Protection Board, 2026-07-14 — https://overview.legal/posts/96831 — original: https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en*

Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*. The decision concerns a dispute submitted by the Belgian Data Protection Authority (DPA) about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT) – a public broadcasting company based in Belgium.The complaint was lodged with the Austrian DPA by the Austrian-based NGO Noyb on behalf of an individual. It concerns the use of cookie banners on the website of VRT.The Belgian DPA,

## Related topics

- **Digital Services Coordinators under DSA** — https://overview.legal/topics/digital-services-coordinators-dsa
  This new topic is needed because Digital Services Coordinators are a distinct institutional role under DSA with specific designation procedures, responsibilitie
- **Digital Services Coordinator** — https://overview.legal/topics/digital-services-coordinator-establishment-role
  While 'digital-services-coordinators-dsa' exists, a more specific topic on the establishment, institutional framework, and foundational role of DSCs would bette
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **DSA Scope and Digital Services Coverage** — https://overview.legal/topics/dsa-scope-digital-services
  The content is from the DSA (Digital Services Act), not the AI Act. A dedicated topic for DSA scope is needed to distinguish it from AI Act scope provisions and
- **VLOP/VLSE Framework** — https://overview.legal/topics/vlop-vlse-regulatory-framework-overview
  The content title specifically focuses on 'Very large online platforms and very large online search engines' as a distinct regulatory category under the DSA. A 
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/dsa-competent-authorities-designation · 2026-08-22
