Skip to content
Topic Developing

DSA Scope and Digital Services Coverage

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal β€” legal information, not advice.

The content is from the DSA (Digital Services Act), not the AI Act. A dedicated topic for DSA scope is needed to distinguish it from AI Act scope provisions and to properly categorize DSA-specific regulatory coverage.

67 linked items 66 Laws1 News

Overview

9 sources Β· Jul 23, 2026

Legal Framework

The DSA establishes a tiered regulatory architecture that scales obligations based on the nature, type, and size of the intermediary service provided. Recital 41 articulates the core design principle: due diligence obligations must be adapted to the specific category of service. The Regulation therefore distinguishes between four escalating tiers of providers, each attracting progressively heavier obligations.

At the base level, Article 2 brings all "intermediary services" within scope β€” encompassing mere conduit, caching, and hosting services as defined under Article 3. Recital 29 illustrates the breadth of this category, expressly identifying internet exchange points, wireless access points, VPNs, DNS services and resolvers, top-level domain name registries, registrars, certificate authorities, and VoIP services as falling within mere conduit. Hosting services attract additional obligations, and online platforms β€” a subset of hosting services that store and disseminate information to the public at the recipient's request β€” face a further layer of requirements. At the apex, very large online platforms (VLOPs) and very large online search engines (VLOSEs), defined as those reaching 45 million average monthly active users in the EU, bear the most stringent obligations.

Article 15 imposes transparency reporting duties on all providers of intermediary services, requiring periodic publication of reports on content moderation activities. Article 4 carves out specific exclusions, notably for services subject to the AI Act's scope and certain sectoral regimes, which is critical for delineating DSA coverage from overlapping regulatory frameworks.

Key Developments

The Commission's designation of the first cohort of VLOPs and VLOSEs in April 2023 β€” including major platforms and search engines β€” established the practical threshold for the highest tier of obligations. Designations turned on self-reported user metrics, and subsequent enforcement has scrutinized whether providers accurately calculate their EU recipient numbers.

Early enforcement signals have focused on transparency reporting compliance under Article 15, with the Commission issuing formal proceedings against designated VLOPs for inadequate risk assessment methodologies under Article 34 and insufficient mitigation measures under Article 35. The Digital Services Coordinators, designated by Member States under Article 36, have begun exercising supervisory powers over non-VLOP providers, creating a bifurcated enforcement landscape where the Commission handles VLOPs/VLOSEs and national authorities handle all others.

Practical Guidance

  • Classify your service accurately at the outset. Determine whether your offering constitutes mere conduit, caching, hosting, or an online platform under Article 3 definitions, as this classification determines your entire obligation set. Misclassification carries significant enforcement risk.

  • Calculate EU recipient numbers systematically. If your service approaches 45 million average monthly active EU users, establish robust measurement methodologies under Article 33(2), as this figure triggers VLOP/VLOSE designation and the associated obligations including systemic risk assessments and independent audits.

  • Implement Article 15 transparency reporting from day one. All intermediary service providers must publish annual reports detailing content moderation decisions, including numbers of orders acted on and categories of restrictions applied. Non-compliance with transparency obligations has been an early enforcement priority.

  • Map overlaps with adjacent regimes. Article 4 exclusions and recital language must be analyzed alongside the AI Act, GDPR, and sectoral legislation to identify where the DSA does not apply and where multiple regimes converge, particularly for services combining AI-driven content moderation with intermediary functions.

  • Establish a compliance governance structure calibrated to your tier. VLOPs require dedicated compliance officers and independent audit arrangements, while smaller providers can adopt proportionate measures β€” but all tiers must document their risk mitigation approach to demonstrate accountability to the relevant Digital Services Coordinator.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 66
Art. 1(1) The aim of this Regulation is to contribute to the proper functioning of the internal market for intermediary services by setting out harmonised rules… DSA Art. 1(2) This Regulation lays down harmonised rules on the provision of intermediary services in the internal market. In particular, it establishes: DSA Art. 1(2)(a) a framework for the conditional exemption from liability of providers of intermediary services; DSA Art. 1(2)(b) rules on specific due diligence obligations tailored to certain specific categories of providers of intermediary services; DSA rec 29 Recital 29 β€” online intermediary service categories and examples DSA Oct 2022 art 15 Transparency reporting obligations for providers of intermediary services DSA Oct 2022 rec 6 Recital 6 β€” intermediary services scope and exclusions DSA Oct 2022 rec 40 Recital 40 β€” harmonised due diligence obligations intermediary services DSA Oct 2022 rec 49 Recital 49 β€” intermediary services annual transparency reporting DSA Oct 2022 rec 9 Recital 9 β€” full harmonisation of intermediary services rules DSA Oct 2022 rec 1 Recital 1 β€” evolution of intermediary services economy DSA Oct 2022 rec 28 Recital 28 β€” new online technologies intermediary services DSA Oct 2022 rec 31 Recital 31 β€” cross-border orders for intermediary services DSA Oct 2022 rec 21 Recital 21 β€” liability exemptions for intermediary services DSA Oct 2022 rec 41 Recital 41 β€” tailored due diligence obligations DSA Oct 2022 art 53 Right to lodge a complaint DSA Oct 2022 art 54 Compensation DSA Oct 2022 rec 10 Recital 10 β€” relationship with other union law DSA Oct 2022 rec 13 Recital 13 β€” online platform subcategory definition and scope DSA Oct 2022 rec 16 Recital 16 β€” conditional intermediary liability exemptions framework DSA Oct 2022 rec 17 Recital 17 β€” intermediary service provider liability exemptions DSA Oct 2022 rec 18 Recital 18 β€” Active role liability exemption exclusion DSA Oct 2022 rec 20 Recital 20 β€” collaboration in illegal activities exclusion DSA Oct 2022 rec 22 Recital 22 β€” hosting service exemption liability conditions DSA Oct 2022 Show 46 more β†’
News 1
IAPP Overview of EU Strategy for Data: Digital Services Act IAPP Oct 2022