# Hosting Services under DSA — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/hosting-services-dsa
> Sources are cited per item. Verify against the official texts before relying on them.

While intermediary liability and DSA scope topics exist, there is no dedicated topic specifically for hosting services, their liability conditions, exemptions, and specific obligations under DSA Article 6, which represents a distinct regulatory category requiring focused coverage.

## Overview

## Legal Framework

Hosting services constitute a distinct category of intermediary services under the DSA, defined in Article 3(g) as services consisting of the storage of information provided by, and at the request of, a recipient of the service. Article 6 establishes the conditional liability exemption: hosting providers are not liable for illegal information stored at the request of a recipient, provided they lack actual knowledge of the illegal activity or information and, upon obtaining such knowledge or awareness, act expeditiously to remove or disable access to that information. This exemption does not apply where the recipient of the service is acting under the authority or control of the provider.

Recital 29 situates hosting within a broad spectrum of intermediary services that continue to evolve, encompassing everything from DNS services to cloud storage. The liability shield in Article 6 is conditioned on compliance with the general obligations in Article 5 (transparency reporting, designated points of contact, and cooperation with authorities) and the hosting-specific obligations in Articles 14 and 15. Article 14 requires providers to implement notice-and-action mechanisms allowing any individual or entity to notify them of the presence of allegedly illegal content. Recital 52 emphasizes that these mechanisms must be harmonized at Union level, ensuring notices are processed timely, diligently, and non-arbitrarily, with robust safeguards for fundamental rights of all affected parties.

Article 15 obliges hosting providers to inform recipients about their content moderation decisions, including the grounds for removal or restriction and available redress mechanisms.

## Key Developments

The DSA's hosting framework builds directly on the e-Commerce Directive's safe harbor concept but introduces materially stricter procedural obligations. The European Commission's designation decisions under Article 33 have clarified the boundary between hosting services and online platforms—providers whose services store and disseminate information to the public fall under the heightened Article 14–17 regime, while private hosting (such as enterprise cloud storage) remains subject only to the baseline hosting obligations. The Commission's guidance on VLOP designations has reinforced that the Article 6 safe harbor is not self-executing: providers must affirmatively demonstrate compliance with notice-and-action requirements to benefit from the exemption.

## Practical Guidance

- Implement a structured notice-and-action mechanism under Article 14 that acknowledges receipt of notices, provides clear reasons for decisions, and includes appeal procedures—failure to maintain this mechanism jeopardizes the Article 6 liability shield.
- Establish internal content moderation policies with documented thresholds for what constitutes "actual knowledge" or "awareness" of illegal content, as these concepts trigger the expeditious removal obligation under Article 6(1)(b).
- Provide recipients with clear, accessible information about content moderation decisions and available redress pathways as required by Article 15, including notification of removal or access restriction with specific grounds.
- Maintain transparency reports under Article 5(1) detailing content moderation volumes, notice processing times, and outcomes—these serve as evidence of compliance during regulatory audits.
- Assess whether your hosting service qualifies as an online platform under Article 3(h), as this triggers additional obligations including internal complaint-handling (Article 16) and out-of-court dispute settlement participation (Article 17).

## Legislation (full text of key provisions)

### Recital 50 — hosting service notice and action mechanisms

*Source: DSA, dsa-rec-50-en, 2022-10-19 — https://overview.legal/posts/95497*

Providers of hosting services play a particularly important role in tackling illegal content online, as they store information provided by and at the request of the recipients of the service and typically give other recipients access thereto, sometimes on a large scale. It is important that all providers of hosting services, regardless of their size, put in place easily accessible and user-friendly notice and action mechanisms that facilitate the notification of specific items of information that the notifying party considers to be illegal content to the provider of hosting services concerned (‘notice’), pursuant to which that provider can decide whether or not it agrees with that assessment and wishes to remove or disable access to that content (‘action’). Such mechanisms should be clearly identifiable, located close to the information in question and at least as easy to find and use as notification mechanisms for content that violates the terms and conditions of the hosting service provider. Provided the requirements on notices are met, it should be possible for individuals or entities to notify multiple specific items of allegedly illegal content through a single notice in order to ensure the effective operation of notice and action mechanisms. The notification mechanism should allow, but not require, the identification of the individual or the entity submitting a notice. For some types of items of information notified, the identity of the individual or the entity submitting a notice might be necessary to determine whether the information in question constitutes illegal content, as alleged. The obligation to put in place notice and action mechanisms should apply, for instance, to file storage and sharing services, web hosting services, advertising servers and paste bins, in so far as they qualify as hosting services covered by this Regulation.

### Recital 52 — harmonised notice and action mechanisms

*Source: DSA, dsa-rec-52-en, 2022-10-19 — https://overview.legal/posts/95501*

The rules on such notice and action mechanisms should be harmonised at Union level, so as to provide for the timely, diligent and non-arbitrary processing of notices on the basis of rules that are uniform, transparent and clear and that provide for robust safeguards to protect the right and legitimate interests of all affected parties, in particular their fundamental rights guaranteed by the Charter, irrespective of the Member State in which those parties are established or reside and of the field of law at issue. Those fundamental rights include but are not limited to: for the recipients of the service, the right to freedom of expression and of information, the right to respect for private and family life, the right to protection of personal data, the right to non-discrimination and the right to an effective remedy; for the service providers, the freedom to conduct a business, including the freedom of contract; for parties affected by illegal content, the right to human dignity, the rights of the child, the right to protection of property, including intellectual property, and the right to non-discrimination. Providers of hosting services should act upon notices in a timely manner, in particular by taking into account the type of illegal content being notified and the urgency of taking action. For instance, such providers can be expected to act without delay when allegedly illegal content involving a threat to life or safety of persons is being notified. The provider of hosting services should inform the individual or entity notifying the specific content without undue delay after taking a decision whether or not to act upon the notice.

### Recital 53 — notice and action mechanism requirements

*Source: DSA, dsa-rec-53-en, 2022-10-19 — https://overview.legal/posts/95503*

The notice and action mechanisms should allow for the submission of notices which are sufficiently precise and adequately substantiated to enable the provider of hosting services concerned to take an informed and diligent decision, compatible with the freedom of expression and of information, in respect of the content to which the notice relates, in particular whether or not that content is to be considered illegal content and is to be removed or access thereto is to be disabled. Those mechanisms should be such as to facilitate the provision of notices that contain an explanation of the reasons why the individual or the entity submitting a notice considers that content to be illegal content, and a clear indication of the location of that content. Where a notice contains sufficient information to enable a diligent provider of hosting services to identify, without a detailed legal examination, that it is clear that the content is illegal, the notice should be considered to give rise to actual knowledge or awareness of illegality. Except for the submission of notices relating to offences referred to in Articles 3 to 7 of Directive 2011/93/EU of the European Parliament and of the Council (26), those mechanisms should ask the individual or the entity submitting a notice to disclose its identity in order to avoid misuse.

### Recital 54 — hosting service content restriction notification obligations

*Source: DSA, dsa-rec-54-en, 2022-10-19 — https://overview.legal/posts/95505*

Where a provider of hosting services decides, on the ground that the information provided by the recipients is illegal content or is incompatible with its terms and conditions, to remove or disable access to information provided by a recipient of the service or to otherwise restrict its visibility or monetisation, for instance following receipt of a notice or acting on its own initiative, including exclusively by automated means, that provider should inform in a clear and easily comprehensible way the recipient of its decision, the reasons for its decision and the available possibilities for redress to contest the decision, in view of the negative consequences that such decisions may have for the recipient, including as regards the exercise of its fundamental right to freedom of expression. That obligation should apply irrespective of the reasons for the decision, in particular whether the action has been taken because the information notified is considered to be illegal content or incompatible with the applicable terms and conditions. Where the decision was taken following receipt of a notice, the provider of hosting services should only reveal the identity of the person or entity who submitted the notice to the recipient of the service where this information is necessary to identify the illegality of the content, such as in cases of infringements of intellectual property rights.

### Recital 55 — restrictions visibility monetisation statement reasons

*Source: DSA, dsa-rec-55-en, 2022-10-19 — https://overview.legal/posts/95507*

Restriction of visibility may consist in demotion in ranking or in recommender systems, as well as in limiting accessibility by one or more recipients of the service or blocking the user from an online community without the user being aware (‘shadow banning’). The monetisation via advertising revenue of information provided by the recipient of the service can be restricted by suspending or terminating the monetary payment or revenue associated to that information. The obligation to provide a statement of reasons should however not apply with respect to deceptive high-volume commercial content disseminated through intentional manipulation of the service, in particular inauthentic use of the service such as the use of bots or fake accounts or other deceptive uses of the service. Irrespective of other possibilities to challenge the decision of the provider of hosting services, the recipient of the service should always have a right to effective remedy before a court in accordance with the national law.

### Recital 56 — hosting service criminal threat reporting obligation

*Source: DSA, dsa-rec-56-en, 2022-10-19 — https://overview.legal/posts/95509*

A provider of hosting services may in some instances become aware, such as through a notice by a notifying party or through its own voluntary measures, of information relating to certain activity of a recipient of the service, such as the provision of certain types of illegal content, that reasonably justify, having regard to all relevant circumstances of which the provider of hosting services is aware, the suspicion that that recipient may have committed, may be committing or is likely to commit a criminal offence involving a threat to the life or safety of person or persons, such as offences specified in Directive 2011/36/EU of the European Parliament and of the Council (27), Directive 2011/93/EU or Directive (EU) 2017/541 of the European Parliament and of the Council (28). For example, specific items of content could give rise to a suspicion of a threat to the public, such as incitement to terrorism within the meaning of Article 21 of Directive (EU) 2017/541. In such instances, the provider of hosting services should inform without delay the competent law enforcement authorities of such suspicion. The provider of hosting services should provide all relevant information available to it, including, where relevant, the content in question and, if available, the time when the content was published, including the designated time zone, an explanation of its suspicion and the information necessary to locate and identify the relevant recipient of the service. This Regulation does not provide the legal basis for profiling of recipients of the services with a view to the possible identification of criminal offences by providers of hosting services. Providers of hosting services should also respect other applicable rules of Union or national law for the protection of the rights and freedoms of individuals when informing law enforcement authorities.

### Recital 62 — trusted flaggers reporting on notices

*Source: DSA, dsa-rec-62-en, 2022-10-19 — https://overview.legal/posts/95521*

Trusted flaggers should publish easily comprehensible and detailed reports on notices submitted in accordance with this Regulation. Those reports should indicate information such as the number of notices categorised by the provider of hosting services, the type of content, and the action taken by the provider. Given that trusted flaggers have demonstrated expertise and competence, the processing of notices submitted by trusted flaggers can be expected to be less burdensome and therefore faster compared to notices submitted by other recipients of the service. However, the average time taken to process may still vary depending on factors including the type of illegal content, the quality of notices, and the actual technical procedures put in place for the submission of such notices. For example, while the Code of conduct on countering illegal hate speech online of 2016 sets a benchmark for the participating companies with respect to the time needed to process valid notifications for removal of illegal hate speech, other types of illegal content may take considerably different timelines for processing, depending on the specific facts and circumstances and types of illegal content at stake. In order to avoid abuses of the trusted flagger status, it should be possible to suspend such status when a Digital Services Coordinator of establishment opened an investigation based on legitimate reasons. The rules of this Regulation on trusted flaggers should not be understood to prevent providers of online platforms from giving similar treatment to notices submitted by entities or individuals that have not been awarded trusted flagger status under this Regulation, from otherwise cooperating with other entities, in accordance with the applicable law, including this Regulation and Regulation (EU) 2016/794 of the European Parliament and of the Council (29). The rules of this Regulation should not prevent the providers of online platforms from making use of such trusted flagger or similar mechanisms to take quick and reliable action against content that is incompatible with their terms and conditions, in particular against content that is harmful for vulnerable recipients of the service, such as minors.

### Recital 51 — targeted hosting service actions on illegal content

*Source: DSA, dsa-rec-51-en, 2022-10-19 — https://overview.legal/posts/95499*

Having regard to the need to take due account of the fundamental rights guaranteed under the Charter of all parties concerned, any action taken by a provider of hosting services pursuant to receiving a notice should be strictly targeted, in the sense that it should serve to remove or disable access to the specific items of information considered to constitute illegal content, without unduly affecting the freedom of expression and of information of recipients of the service. Notices should therefore, as a general rule, be directed to the providers of hosting services that can reasonably be expected to have the technical and operational ability to act against such specific items. The providers of hosting services who receive a notice for which they cannot, for technical or operational reasons, remove the specific item of information should inform the person or entity who submitted the notice.

### Recital 13 — online platform subcategory definition and scope

*Source: DSA, dsa-rec-13-en, 2022-10-19 — https://overview.legal/posts/95423*

Considering the particular characteristics of the services concerned and the corresponding need to make the providers thereof subject to certain specific obligations, it is necessary to distinguish, within the broader category of providers of hosting services as defined in this Regulation, the subcategory of online platforms. Online platforms, such as social networks or online platforms allowing consumers to conclude distance contracts with traders, should be defined as providers of hosting services that not only store information provided by the recipients of the service at their request, but that also disseminate that information to the public at the request of the recipients of the service. However, in order to avoid imposing overly broad obligations, providers of hosting services should not be considered as online platforms where the dissemination to the public is merely a minor and purely ancillary feature that is intrinsically linked to another service, or a minor functionality of the principal service, and that feature or functionality cannot, for objective technical reasons, be used without that other or principal service, and the integration of that feature or functionality is not a means to circumvent the applicability of the rules of this Regulation applicable to online platforms. For example, the comments section in an online newspaper could constitute such a feature, where it is clear that it is ancillary to the main service represented by the publication of news under the editorial responsibility of the publisher. In contrast, the storage of comments in a social network should be considered an online platform service where it is clear that it is not a minor feature of the service offered, even if it is ancillary to publishing the posts of recipients of the service. For the purposes of this Regulation, cloud computing or web-hosting services should not be considered to be an online platform where dissemination of specific information to the public constitutes a minor and ancillary feature or a minor functionality of such services. Moreover, cloud computing services and web-hosting services, when serving as infrastructure, such as the underlying infrastructural storage and computing services of an internet-based application, website or online platform, should not in themselves be considered as disseminating to the public information stored or processed at the request of a recipient of the application, website or online platform which they host.

### Recital 22 — hosting service exemption liability conditions

*Source: DSA, dsa-rec-22-en, 2022-10-19 — https://overview.legal/posts/95441*

In order to benefit from the exemption from liability for hosting services, the provider should, upon obtaining actual knowledge or awareness of illegal activities or illegal content, act expeditiously to remove or to disable access to that content. The removal or disabling of access should be undertaken in the observance of the fundamental rights of the recipients of the service, including the right to freedom of expression and of information. The provider can obtain such actual knowledge or awareness of the illegal nature of the content, inter alia through its own-initiative investigations or through notices submitted to it by individuals or entities in accordance with this Regulation in so far as such notices are sufficiently precise and adequately substantiated to allow a diligent economic operator to reasonably identify, assess and, where appropriate, act against the allegedly illegal content. However, such actual knowledge or awareness cannot be considered to be obtained solely on the ground that that provider is aware, in a general sense, of the fact that its service is also used to store illegal content. Furthermore, the fact that the provider automatically indexes information uploaded to its service, that it has a search function or that it recommends information on the basis of the profiles or preferences of the recipients of the service is not a sufficient ground for considering that provider to have ‘specific’ knowledge of illegal activities carried out on that platform or of illegal content stored on it.

## Related topics

- **DSA Scope and Digital Services Coverage** — https://overview.legal/topics/dsa-scope-digital-services
  The content is from the DSA (Digital Services Act), not the AI Act. A dedicated topic for DSA scope is needed to distinguish it from AI Act scope provisions and
- **DSA Terms and Conditions Requirements** — https://overview.legal/topics/dsa-terms-conditions-requirements
  This new topic is needed to specifically address the requirements for terms and conditions documents under the DSA, including transparency, accessibility, and m
- **Recipient** — https://overview.legal/topics/recipient
  A person or body to which personal data are disclosed (Art 4(9) GDPR).
- **Intermediary Liability Framework under DSA** — https://overview.legal/topics/intermediary-liability-framework-dsa
  This topic is needed to comprehensively cover the broader intermediary liability framework under the DSA, of which mere conduit is one component, including the 
- **Automated Decision-Making** — https://overview.legal/topics/geautomatiseerde-besluitvorming
  Processing involving automated decisions without human involvement
- **Profiling** — https://overview.legal/topics/profiling
  Automated processing to evaluate personal aspects

---
Generated by overview.legal · https://overview.legal/topics/hosting-services-dsa · 2026-08-22
