Intermediary Liability Framework under DSA
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is needed to comprehensively cover the broader intermediary liability framework under the DSA, of which mere conduit is one component, including the conditions, standards, and exemptions that apply to different types of digital services.
Overview
9 sources · Jul 23, 2026Legal Framework
The DSA establishes a graduated intermediary liability framework that preserves and builds upon the conditional exemptions first introduced in the E-Commerce Directive (2000/31/EC), Articles 12–15. The DSA does not displace those exemptions; rather, it layers additional due diligence obligations on top of them. The core sheltered categories remain mere conduit (DSA Article 4), caching (DSA Article 5), and hosting (DSA Article 6), each with distinct conditions that must be satisfied for the liability shield to apply.
Under Article 4, a mere conduit provider is exempt from liability for transmitted information provided it does not initiate the transmission, does not select the recipient, and does not select or modify the information. Caching providers under Article 5 must not modify the data, comply with access conditions, and update or remove cached content upon notification. Hosting providers under Article 6 benefit from exemption only when they lack actual knowledge of illegal activity and, upon obtaining such knowledge, act expeditiously to remove or disable access.
DSA Article 16 introduces a mandatory notice-and-action mechanism: all hosting providers must enable any individual or entity to notify them of presence on their service of specific items of information considered illegal. Upon receiving a notice, the provider must assess it and act expeditiously. Article 16 also requires providers to process statements of reasons and provide complainants with a decision and the rationale for it.
The DSA's territorial scope turns on whether processing occurs "in the context of the activities" of an establishment in the Union. The doctrinal commentary confirms that this requires effective and actual exercise of activities through stable arrangements, even if those activities are limited. A commercial agent collecting payments for an online service may qualify as an establishment. CJEU jurisprudence on the analogous provision in the 1995 Privacy Directive confirms that a subsidiary promoting and selling advertising space in the Union can anchor the parent company's activities within EU jurisdiction.
Key Developments
The E-Commerce Directive's intermediary liability principles were transposed into national law across Member States—in the Netherlands, for example, through Article 6:196c of the Civil Code. The DSA now codifies and modernises these principles at the regulation level, removing inconsistencies in national implementation. The CJEU's establishment jurisprudence, rooted in the Google Spain reasoning, sets a practical threshold: the presence of a sales or promotion subsidiary in the Union is sufficient to bring a non-EU provider within the DSA's scope, even if technical infrastructure remains outside the EU.
Practical Guidance
Classify your service accurately under the DSA's categories (mere conduit, caching, hosting, or hybrid). The liability exemption available depends entirely on correct classification and satisfaction of that category's specific conditions under Articles 4–6.
Implement a compliant notice-and-action mechanism per Article 16, including clear channels for submitting notifications, internal procedures for assessing illegality, and obligations to inform notifiers of decisions and reasoning.
Maintain neutrality conditions strictly: for mere conduit, do not initiate transmissions, select recipients, or modify content. Any deviation risks forfeiting the Article 4 exemption and exposing the provider to full liability.
Act expeditiously upon actual knowledge: hosting providers must remove or disable access to illegal content immediately upon obtaining actual knowledge. Delayed or inconsistent takedown responses undermine the Article 6 shield.
Assess establishment status for territorial scope: if your organisation has any stable operational presence in the Union—even a limited commercial agent or subsidiary handling payments or advertising—assume the DSA applies and ensure full compliance with its intermediary obligations.