# DSA Scope and Digital Services Coverage — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/dsa-scope-digital-services
> Sources are cited per item. Verify against the official texts before relying on them.

The content is from the DSA (Digital Services Act), not the AI Act. A dedicated topic for DSA scope is needed to distinguish it from AI Act scope provisions and to properly categorize DSA-specific regulatory coverage.

## Overview

## Legal Framework

The DSA establishes a tiered regulatory architecture that scales obligations based on the nature, type, and size of the intermediary service provided. Recital 41 articulates the core design principle: due diligence obligations must be adapted to the specific category of service. The Regulation therefore distinguishes between four escalating tiers of providers, each attracting progressively heavier obligations.

At the base level, Article 2 brings all "intermediary services" within scope — encompassing mere conduit, caching, and hosting services as defined under Article 3. Recital 29 illustrates the breadth of this category, expressly identifying internet exchange points, wireless access points, VPNs, DNS services and resolvers, top-level domain name registries, registrars, certificate authorities, and VoIP services as falling within mere conduit. Hosting services attract additional obligations, and online platforms — a subset of hosting services that store and disseminate information to the public at the recipient's request — face a further layer of requirements. At the apex, very large online platforms (VLOPs) and very large online search engines (VLOSEs), defined as those reaching 45 million average monthly active users in the EU, bear the most stringent obligations.

Article 15 imposes transparency reporting duties on all providers of intermediary services, requiring periodic publication of reports on content moderation activities. Article 4 carves out specific exclusions, notably for services subject to the AI Act's scope and certain sectoral regimes, which is critical for delineating DSA coverage from overlapping regulatory frameworks.

## Key Developments

The Commission's designation of the first cohort of VLOPs and VLOSEs in April 2023 — including major platforms and search engines — established the practical threshold for the highest tier of obligations. Designations turned on self-reported user metrics, and subsequent enforcement has scrutinized whether providers accurately calculate their EU recipient numbers.

Early enforcement signals have focused on transparency reporting compliance under Article 15, with the Commission issuing formal proceedings against designated VLOPs for inadequate risk assessment methodologies under Article 34 and insufficient mitigation measures under Article 35. The Digital Services Coordinators, designated by Member States under Article 36, have begun exercising supervisory powers over non-VLOP providers, creating a bifurcated enforcement landscape where the Commission handles VLOPs/VLOSEs and national authorities handle all others.

## Practical Guidance

- **Classify your service accurately at the outset.** Determine whether your offering constitutes mere conduit, caching, hosting, or an online platform under Article 3 definitions, as this classification determines your entire obligation set. Misclassification carries significant enforcement risk.

- **Calculate EU recipient numbers systematically.** If your service approaches 45 million average monthly active EU users, establish robust measurement methodologies under Article 33(2), as this figure triggers VLOP/VLOSE designation and the associated obligations including systemic risk assessments and independent audits.

- **Implement Article 15 transparency reporting from day one.** All intermediary service providers must publish annual reports detailing content moderation decisions, including numbers of orders acted on and categories of restrictions applied. Non-compliance with transparency obligations has been an early enforcement priority.

- **Map overlaps with adjacent regimes.** Article 4 exclusions and recital language must be analyzed alongside the AI Act, GDPR, and sectoral legislation to identify where the DSA does not apply and where multiple regimes converge, particularly for services combining AI-driven content moderation with intermediary functions.

- **Establish a compliance governance structure calibrated to your tier.** VLOPs require dedicated compliance officers and independent audit arrangements, while smaller providers can adopt proportionate measures — but all tiers must document their risk mitigation approach to demonstrate accountability to the relevant Digital Services Coordinator.

## Legislation (full text of key provisions)

### Transparency reporting obligations for providers of intermediary services

*Source: DSA, dsa-art-15-en, 2022-10-19 — https://overview.legal/posts/94226*

### Right to lodge a complaint

*Source: DSA, dsa-art-53-en, 2022-10-19 — https://overview.legal/posts/94952*

Recipients of the service and any body, organisation or association mandated to exercise the rights conferred by this Regulation on their behalf shall have the right to lodge a complaint against providers of intermediary services alleging an infringement of this Regulation with the Digital Services Coordinator of the Member State where the recipient of the service is located or established. The Digital Services Coordinator shall assess the complaint and, where appropriate, transmit it to the Digital Services Coordinator of establishment, accompanied, where considered appropriate, by an opinion. Where the complaint falls under the responsibility of another competent authority in its Member State, the Digital Services Coordinator receiving the complaint shall transmit it to that authority. During these proceedings, both parties shall have the right to be heard and receive appropriate information about the status of the complaint, in accordance with national law.

### Compensation

*Source: DSA, dsa-art-54-en, 2022-10-19 — https://overview.legal/posts/94954*

Recipients of the service shall have the right to seek, in accordance with Union and national law, compensation from providers of intermediary services, in respect of any damage or loss suffered due to an infringement by those providers of their obligations under this Regulation.

### Voluntary own-initiative investigations and legal compliance

*Source: DSA, dsa-art-7-en, 2022-10-19 — https://overview.legal/posts/94136*

Providers of intermediary services shall not be deemed ineligible for the exemptions from liability referred to in Articles 4, 5 and 6 solely because they, in good faith and in a diligent manner, carry out voluntary own-initiative investigations into, or take other measures aimed at detecting, identifying and removing, or disabling access to, illegal content, or take the necessary measures to comply with the requirements of Union law and national law in compliance with Union law, including the requirements set out in this Regulation.

### No general monitoring or active fact-finding obligations

*Source: DSA, dsa-art-8-en, 2022-10-19 — https://overview.legal/posts/94138*

No general obligation to monitor the information which providers of intermediary services transmit or store, nor actively to seek facts or circumstances indicating illegal activity shall be imposed on those providers.

### Recital 29 — online intermediary service categories and examples

*Source: DSA, dsa-rec-29-en, 2022-10-19 — https://overview.legal/posts/95455*

Intermediary services span a wide range of economic activities which take place online and that develop continually to provide for transmission of information that is swift, safe and secure, and to ensure convenience of all participants of the online ecosystem. For example, ‘mere conduit’ intermediary services include generic categories of services, such as internet exchange points, wireless access points, virtual private networks, DNS services and resolvers, top-level domain name registries, registrars, certificate authorities that issue digital certificates, voice over IP and other interpersonal communication services, while generic examples of ‘caching’ intermediary services include the sole provision of content delivery networks, reverse proxies or content adaptation proxies. Such services are crucial to ensure the smooth and efficient transmission of information delivered on the internet. Examples of ‘hosting services’ include categories of services such as cloud computing, web hosting, paid referencing services or services enabling sharing information and content online, including file storage and sharing. Intermediary services may be provided in isolation, as a part of another type of intermediary service, or simultaneously with other intermediary services. Whether a specific service constitutes a ‘mere conduit’, ‘caching’ or ‘hosting’ service depends solely on its technical functionalities, which might evolve in time, and should be assessed on a case-by-case basis.

### Recital 6 — intermediary services scope and exclusions

*Source: DSA, dsa-rec-6-en, 2022-10-19 — https://overview.legal/posts/95409*

In practice, certain providers of intermediary services intermediate in relation to services that may or may not be provided by electronic means, such as remote information technology services, transport, accommodation or delivery services. This Regulation should apply only to intermediary services and not affect requirements set out in Union or national law relating to products or services intermediated through intermediary services, including in situations where the intermediary service constitutes an integral part of another service which is not an intermediary service as recognised in the case-law of the Court of Justice of the European Union.

### Recital 40 — harmonised due diligence obligations intermediary services

*Source: DSA, dsa-rec-40-en, 2022-10-19 — https://overview.legal/posts/95477*

In order to achieve the objectives of this Regulation, and in particular to improve the functioning of the internal market and ensure a safe and transparent online environment, it is necessary to establish a clear, effective, predictable and balanced set of harmonised due diligence obligations for providers of intermediary services. Those obligations should aim in particular to guarantee different public policy objectives such as the safety and trust of the recipients of the service, including consumers, minors and users at particular risk of being subject to hate speech, sexual harassment or other discriminatory actions, the protection of relevant fundamental rights enshrined in the Charter, the meaningful accountability of those providers and the empowerment of recipients and other affected parties, whilst facilitating the necessary oversight by competent authorities.

### Recital 49 — intermediary services annual transparency reporting

*Source: DSA, dsa-rec-49-en, 2022-10-19 — https://overview.legal/posts/95495*

To ensure an adequate level of transparency and accountability, providers of intermediary services should make publicly available an annual report in a machine-readable format, in accordance with the harmonised requirements contained in this Regulation, on the content moderation in which they engage, including the measures taken as a result of the application and enforcement of their terms and conditions. However, in order to avoid disproportionate burdens, those transparency reporting obligations should not apply to providers that are micro or small enterprises as defined in Commission Recommendation 2003/361/EC (25) and which are not very large online platforms within the meaning of this Regulation.

### Recital 9 — full harmonisation of intermediary services rules

*Source: DSA, dsa-rec-9-en, 2022-10-19 — https://overview.legal/posts/95415*

This Regulation fully harmonises the rules applicable to intermediary services in the internal market with the objective of ensuring a safe, predictable and trusted online environment, addressing the dissemination of illegal content online and the societal risks that the dissemination of disinformation or other content may generate, and within which fundamental rights enshrined in the Charter are effectively protected and innovation is facilitated. Accordingly, Member States should not adopt or maintain additional national requirements relating to the matters falling within the scope of this Regulation, unless explicitly provided for in this Regulation, since this would affect the direct and uniform application of the fully harmonised rules applicable to providers of intermediary services in accordance with the objectives of this Regulation. This should not preclude the possibility of applying other national legislation applicable to providers of intermediary services, in compliance with Union law, including Directive 2000/31/EC, in particular its Article 3, where the provisions of national law pursue other legitimate public interest objectives than those pursued by this Regulation.

## Recent developments

### Overview of EU Strategy for Data: Digital Services Act

*Source: IAPP, 2022-10-28 — https://overview.legal/posts/6249 — original: https://iapp.org/news/a/overview-of-eu-strategy-for-data-digital-services-act#entry-1195*

> The Digital Services Act was published in the Official Journal of the European Union Oct. 27. The DSA, which harmonizes conditions for the provision of intermediary services and increases transparency requirements for online intermediaries, will enter into force Nov. 16. In the latest installment of a multipart series, the IAPP Research and Insights team provides privacy professionals with an overview of the DSA, including the law's objectives, key requirements and enforcement.

## Related topics

- **Hosting Services under DSA** — https://overview.legal/topics/hosting-services-dsa
  While intermediary liability and DSA scope topics exist, there is no dedicated topic specifically for hosting services, their liability conditions, exemptions, 
- **Competent Authorities Designation and Powers under DSA** — https://overview.legal/topics/dsa-competent-authorities-designation
  The content is titled 'Competences' from the DSA and discusses the allocation and scope of authority powers under the Digital Services Act. This requires a dedi
- **DSA Terms and Conditions Requirements** — https://overview.legal/topics/dsa-terms-conditions-requirements
  This new topic is needed to specifically address the requirements for terms and conditions documents under the DSA, including transparency, accessibility, and m
- **Digital Services Coordinator** — https://overview.legal/topics/digital-services-coordinator-establishment-role
  While 'digital-services-coordinators-dsa' exists, a more specific topic on the establishment, institutional framework, and foundational role of DSCs would bette
- **Recipient** — https://overview.legal/topics/recipient
  A person or body to which personal data are disclosed (Art 4(9) GDPR).
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/dsa-scope-digital-services · 2026-08-22
