Skip to content
Topic Developing

Intermediary Liability Framework under DSA

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic is needed to comprehensively cover the broader intermediary liability framework under the DSA, of which mere conduit is one component, including the conditions, standards, and exemptions that apply to different types of digital services.

19 linked items 18 Laws1 News

Overview

9 sources · Jul 23, 2026

Legal Framework

The DSA establishes a graduated intermediary liability framework that preserves and builds upon the conditional exemptions first introduced in the E-Commerce Directive (2000/31/EC), Articles 12–15. The DSA does not displace those exemptions; rather, it layers additional due diligence obligations on top of them. The core sheltered categories remain mere conduit (DSA Article 4), caching (DSA Article 5), and hosting (DSA Article 6), each with distinct conditions that must be satisfied for the liability shield to apply.

Under Article 4, a mere conduit provider is exempt from liability for transmitted information provided it does not initiate the transmission, does not select the recipient, and does not select or modify the information. Caching providers under Article 5 must not modify the data, comply with access conditions, and update or remove cached content upon notification. Hosting providers under Article 6 benefit from exemption only when they lack actual knowledge of illegal activity and, upon obtaining such knowledge, act expeditiously to remove or disable access.

DSA Article 16 introduces a mandatory notice-and-action mechanism: all hosting providers must enable any individual or entity to notify them of presence on their service of specific items of information considered illegal. Upon receiving a notice, the provider must assess it and act expeditiously. Article 16 also requires providers to process statements of reasons and provide complainants with a decision and the rationale for it.

The DSA's territorial scope turns on whether processing occurs "in the context of the activities" of an establishment in the Union. The doctrinal commentary confirms that this requires effective and actual exercise of activities through stable arrangements, even if those activities are limited. A commercial agent collecting payments for an online service may qualify as an establishment. CJEU jurisprudence on the analogous provision in the 1995 Privacy Directive confirms that a subsidiary promoting and selling advertising space in the Union can anchor the parent company's activities within EU jurisdiction.

Key Developments

The E-Commerce Directive's intermediary liability principles were transposed into national law across Member States—in the Netherlands, for example, through Article 6:196c of the Civil Code. The DSA now codifies and modernises these principles at the regulation level, removing inconsistencies in national implementation. The CJEU's establishment jurisprudence, rooted in the Google Spain reasoning, sets a practical threshold: the presence of a sales or promotion subsidiary in the Union is sufficient to bring a non-EU provider within the DSA's scope, even if technical infrastructure remains outside the EU.

Practical Guidance

  • Classify your service accurately under the DSA's categories (mere conduit, caching, hosting, or hybrid). The liability exemption available depends entirely on correct classification and satisfaction of that category's specific conditions under Articles 4–6.

  • Implement a compliant notice-and-action mechanism per Article 16, including clear channels for submitting notifications, internal procedures for assessing illegality, and obligations to inform notifiers of decisions and reasoning.

  • Maintain neutrality conditions strictly: for mere conduit, do not initiate transmissions, select recipients, or modify content. Any deviation risks forfeiting the Article 4 exemption and exposing the provider to full liability.

  • Act expeditiously upon actual knowledge: hosting providers must remove or disable access to illegal content immediately upon obtaining actual knowledge. Delayed or inconsistent takedown responses undermine the Article 6 shield.

  • Assess establishment status for territorial scope: if your organisation has any stable operational presence in the Union—even a limited commercial agent or subsidiary handling payments or advertising—assume the DSA applies and ensure full compliance with its intermediary obligations.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 18
Art. 3(g)(i) a ‘mere conduit’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, or the prov… DSA Art. 5(1)(e) acts expeditiously to remove or to disable access to the information it has stored upon obtaining actual knowledge of the fact that the information at… DSA Art. 6(1)(a) does not have actual knowledge of illegal activity or illegal content and, as regards claims for damages, is not aware of facts or circumstances from … DSA Art. 16(3) Notices referred to in this Article shall be considered to give rise to actual knowledge or awareness for the purposes of Article 6 in respect of the … DSA rec 53 Recital 53 — notice and action mechanism requirements DSA Oct 2022 rec 16 Recital 16 — conditional intermediary liability exemptions framework DSA Oct 2022 rec 17 Recital 17 — intermediary service provider liability exemptions DSA Oct 2022 rec 52 Recital 52 — harmonised notice and action mechanisms DSA Oct 2022 rec 21 Recital 21 — liability exemptions for intermediary services DSA Oct 2022 rec 22 Recital 22 — hosting service exemption liability conditions DSA Oct 2022 rec 50 Recital 50 — hosting service notice and action mechanisms DSA Oct 2022 rec 27 Recital 27 — beyond intermediary service provider liability DSA Oct 2022 rec 121 Recital 121 — intermediary service provider liability for damages DSA Oct 2022 art 16 Notice and action mechanisms DSA Oct 2022 art 4 ‘Mere conduit’ DSA Oct 2022 rec 89 Recital 89 — protection of minors on large platforms DSA Oct 2022 rec 58 Recital 58 — internal complaint handling systems DSA Oct 2022 rec 61 Recital 61 — trusted flagger status priority content notices DSA Oct 2022 rec 19 Recital 19 — differentiated intermediary service activity rules DSA Oct 2022 rec 29 Recital 29 — online intermediary service categories and examples DSA Oct 2022 rec 5 Recital 5 — scope covering intermediary service providers DSA Oct 2022 rec 28 Recital 28 — new online technologies intermediary services DSA Oct 2022
News 1
Electronic Frontier Foundation EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines Electronic Frontier Foundation Jul 2026