Skip to content
Topic Developing

Intermediary Liability Framework under DSA

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal β€” legal information, not advice.

This topic is needed to comprehensively cover the broader intermediary liability framework under the DSA, of which mere conduit is one component, including the conditions, standards, and exemptions that apply to different types of digital services.

19 linked items 18 Laws1 News

Overview

9 sources Β· Sep 25, 2026

Legal Framework

The DSA establishes a horizontal framework of conditional liability exemptions for intermediary services, incorporating and clarifying the principles previously set out in Directive 2000/31/EC (the E-commerce Directive). The core exemptions address three categories of service: mere conduit, caching, and hosting. Articles 3 through 6 of the DSA govern these exemptions, building on the foundational principle that the Regulation establishes only when a provider cannot be held liable β€” not when liability affirmatively attaches.

As Recital 17 makes clear, the DSA's exemptions are defensive in nature:

"Those rules should not be understood to provide a positive basis for establishing when a provider can be held liable, which is for the applicable rules of Union or national law to determine."
β€” DSA Rec. 17

The framework preserves the conditional exemptions from the E-commerce Directive while clarifying their application in light of CJEU case law. For mere conduit and caching, the provider must not be involved with the information transmitted β€” specifically, it must not modify the content, though technical manipulations during transmission that do not alter information integrity remain permissible. For hosting, the exemption turns on the provider's response upon obtaining actual knowledge or awareness of illegal content.

Key Developments

The DSA recitals reflect accumulated CJEU jurisprudence on what constitutes "actual knowledge" and when a hosting provider loses exemption protection. The threshold is deliberately high: general awareness that a service may be used for illegal content is insufficient. Recital 22 sets the standard:

"such actual knowledge or awareness cannot be considered to be obtained solely on the ground that that provider is aware, in a general sense, of the fact that its service is also used to store illegal content."
β€” DSA Rec. 22

Recital 22 further clarifies that automated indexing, search functionality, or recommendation algorithms based on user profiles do not, by themselves, generate specific knowledge of illegal content. This directly addresses the tension between algorithmic content distribution and the hosting exemption β€” a question that was actively litigated under the E-commerce Directive and has now been codified.

The DSA also introduces layered obligations: very large online platforms (VLOPs) face additional due-diligence requirements under Articles 33–43 that operate alongside, not in place of, the liability exemptions. Compliance with these systemic obligations does not automatically forfeit exemption status, but failure to meet them may inform liability analysis under national law.

Status of the Debate

This topic is developing. The DSA has codified key clarifications from CJEU case law β€” particularly on actual knowledge and algorithmic recommendation β€” but no dominant doctrinal pattern has yet emerged on how the exemptions interact with the new due-diligence obligations. The central open question is whether proactive content moderation undertaken to comply with DSA risk-mitigation duties (Articles 34–35) transforms a passive hosting provider into an active participant, potentially forfeiting the Article 6 exemption. The recitals suggest not, but this has not been tested before the CJEU under the DSA. A preliminary reference on this interaction would resolve the ambiguity.

Practical Guidance

  • Document the boundary between transmission and modification: Ensure that any technical processing of content (compression, formatting, caching) does not alter information integrity, preserving mere conduit or caching exemption eligibility under Recital 21.

  • Establish a notice-and-action mechanism with precise thresholds: Notices must be "sufficiently precise and adequately substantiated" to trigger actual knowledge β€” vague or unsubstantiated reports should not automatically activate the duty to act expeditiously.

  • Avoid conflating algorithmic features with specific knowledge: Automated indexing, search, and recommendation functions do not, standing alone, establish knowledge of specific illegal content. Maintain this distinction in internal compliance documentation.

  • Separate risk-mitigation duties from liability analysis: DSA due-diligence obligations (risk assessments, mitigation measures) operate in a distinct regulatory lane from the liability exemptions. Track compliance with both frameworks independently to avoid inadvertently waiving exemption arguments.

  • Preserve the defensive character of exemptions: Remember that DSA exemptions establish immunity, not a positive liability standard. Liability questions remain governed by applicable Union or national law, so assess exposure under both regulatory regimes in parallel.

Everything on this topic ranked by relevance Β· links go to the exact provision / paragraph / section