# Intermediary Liability Framework under DSA — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/intermediary-liability-framework-dsa
> Sources are cited per item. Verify against the official texts before relying on them.

This topic is needed to comprehensively cover the broader intermediary liability framework under the DSA, of which mere conduit is one component, including the conditions, standards, and exemptions that apply to different types of digital services.

## Overview

## Legal Framework

The DSA establishes a graduated intermediary liability framework that preserves and builds upon the conditional exemptions first introduced in the E-Commerce Directive (2000/31/EC), Articles 12–15. The DSA does not displace those exemptions; rather, it layers additional due diligence obligations on top of them. The core sheltered categories remain **mere conduit** (DSA Article 4), **caching** (DSA Article 5), and **hosting** (DSA Article 6), each with distinct conditions that must be satisfied for the liability shield to apply.

Under Article 4, a mere conduit provider is exempt from liability for transmitted information provided it does not initiate the transmission, does not select the recipient, and does not select or modify the information. Caching providers under Article 5 must not modify the data, comply with access conditions, and update or remove cached content upon notification. Hosting providers under Article 6 benefit from exemption only when they lack actual knowledge of illegal activity and, upon obtaining such knowledge, act expeditiously to remove or disable access.

DSA Article 16 introduces a mandatory **notice-and-action mechanism**: all hosting providers must enable any individual or entity to notify them of presence on their service of specific items of information considered illegal. Upon receiving a notice, the provider must assess it and act expeditiously. Article 16 also requires providers to process statements of reasons and provide complainants with a decision and the rationale for it.

The DSA's territorial scope turns on whether processing occurs "in the context of the activities" of an establishment in the Union. The doctrinal commentary confirms that this requires effective and actual exercise of activities through stable arrangements, even if those activities are limited. A commercial agent collecting payments for an online service may qualify as an establishment. CJEU jurisprudence on the analogous provision in the 1995 Privacy Directive confirms that a subsidiary promoting and selling advertising space in the Union can anchor the parent company's activities within EU jurisdiction.

## Key Developments

The E-Commerce Directive's intermediary liability principles were transposed into national law across Member States—in the Netherlands, for example, through Article 6:196c of the Civil Code. The DSA now codifies and modernises these principles at the regulation level, removing inconsistencies in national implementation. The CJEU's establishment jurisprudence, rooted in the Google Spain reasoning, sets a practical threshold: the presence of a sales or promotion subsidiary in the Union is sufficient to bring a non-EU provider within the DSA's scope, even if technical infrastructure remains outside the EU.

## Practical Guidance

- **Classify your service accurately** under the DSA's categories (mere conduit, caching, hosting, or hybrid). The liability exemption available depends entirely on correct classification and satisfaction of that category's specific conditions under Articles 4–6.

- **Implement a compliant notice-and-action mechanism** per Article 16, including clear channels for submitting notifications, internal procedures for assessing illegality, and obligations to inform notifiers of decisions and reasoning.

- **Maintain neutrality conditions strictly**: for mere conduit, do not initiate transmissions, select recipients, or modify content. Any deviation risks forfeiting the Article 4 exemption and exposing the provider to full liability.

- **Act expeditiously upon actual knowledge**: hosting providers must remove or disable access to illegal content immediately upon obtaining actual knowledge. Delayed or inconsistent takedown responses undermine the Article 6 shield.

- **Assess establishment status for territorial scope**: if your organisation has any stable operational presence in the Union—even a limited commercial agent or subsidiary handling payments or advertising—assume the DSA applies and ensure full compliance with its intermediary obligations.

## Legislation (full text of key provisions)

### Notice and action mechanisms

*Source: DSA, dsa-art-16-en, 2022-10-19 — https://overview.legal/posts/94239*

### ‘Mere conduit’

*Source: DSA, dsa-art-4-en, 2022-10-19 — https://overview.legal/posts/94102*

### Recital 50 — hosting service notice and action mechanisms

*Source: DSA, dsa-rec-50-en, 2022-10-19 — https://overview.legal/posts/95497*

Providers of hosting services play a particularly important role in tackling illegal content online, as they store information provided by and at the request of the recipients of the service and typically give other recipients access thereto, sometimes on a large scale. It is important that all providers of hosting services, regardless of their size, put in place easily accessible and user-friendly notice and action mechanisms that facilitate the notification of specific items of information that the notifying party considers to be illegal content to the provider of hosting services concerned (‘notice’), pursuant to which that provider can decide whether or not it agrees with that assessment and wishes to remove or disable access to that content (‘action’). Such mechanisms should be clearly identifiable, located close to the information in question and at least as easy to find and use as notification mechanisms for content that violates the terms and conditions of the hosting service provider. Provided the requirements on notices are met, it should be possible for individuals or entities to notify multiple specific items of allegedly illegal content through a single notice in order to ensure the effective operation of notice and action mechanisms. The notification mechanism should allow, but not require, the identification of the individual or the entity submitting a notice. For some types of items of information notified, the identity of the individual or the entity submitting a notice might be necessary to determine whether the information in question constitutes illegal content, as alleged. The obligation to put in place notice and action mechanisms should apply, for instance, to file storage and sharing services, web hosting services, advertising servers and paste bins, in so far as they qualify as hosting services covered by this Regulation.

### Recital 53 — notice and action mechanism requirements

*Source: DSA, dsa-rec-53-en, 2022-10-19 — https://overview.legal/posts/95503*

The notice and action mechanisms should allow for the submission of notices which are sufficiently precise and adequately substantiated to enable the provider of hosting services concerned to take an informed and diligent decision, compatible with the freedom of expression and of information, in respect of the content to which the notice relates, in particular whether or not that content is to be considered illegal content and is to be removed or access thereto is to be disabled. Those mechanisms should be such as to facilitate the provision of notices that contain an explanation of the reasons why the individual or the entity submitting a notice considers that content to be illegal content, and a clear indication of the location of that content. Where a notice contains sufficient information to enable a diligent provider of hosting services to identify, without a detailed legal examination, that it is clear that the content is illegal, the notice should be considered to give rise to actual knowledge or awareness of illegality. Except for the submission of notices relating to offences referred to in Articles 3 to 7 of Directive 2011/93/EU of the European Parliament and of the Council (26), those mechanisms should ask the individual or the entity submitting a notice to disclose its identity in order to avoid misuse.

### Recital 16 — conditional intermediary liability exemptions framework

*Source: DSA, dsa-rec-16-en, 2022-10-19 — https://overview.legal/posts/95429*

The legal certainty provided by the horizontal framework of conditional exemptions from liability for providers of intermediary services, laid down in Directive 2000/31/EC, has allowed many novel services to emerge and scale up across the internal market. That framework should therefore be preserved. However, in view of the divergences when transposing and applying the relevant rules at national level, and for reasons of clarity and coherence, that framework should be incorporated in this Regulation. It is also necessary to clarify certain elements of that framework, having regard to the case-law of the Court of Justice of the European Union.

### Recital 17 — intermediary service provider liability exemptions

*Source: DSA, dsa-rec-17-en, 2022-10-19 — https://overview.legal/posts/95431*

The rules on liability of providers of intermediary services set out in this Regulation should only establish when the provider of intermediary services concerned cannot be held liable in relation to illegal content provided by the recipients of the service. Those rules should not be understood to provide a positive basis for establishing when a provider can be held liable, which is for the applicable rules of Union or national law to determine. Furthermore, the exemptions from liability established in this Regulation should apply in respect of any type of liability as regards any type of illegal content, irrespective of the precise subject matter or nature of those laws.

### Recital 52 — harmonised notice and action mechanisms

*Source: DSA, dsa-rec-52-en, 2022-10-19 — https://overview.legal/posts/95501*

The rules on such notice and action mechanisms should be harmonised at Union level, so as to provide for the timely, diligent and non-arbitrary processing of notices on the basis of rules that are uniform, transparent and clear and that provide for robust safeguards to protect the right and legitimate interests of all affected parties, in particular their fundamental rights guaranteed by the Charter, irrespective of the Member State in which those parties are established or reside and of the field of law at issue. Those fundamental rights include but are not limited to: for the recipients of the service, the right to freedom of expression and of information, the right to respect for private and family life, the right to protection of personal data, the right to non-discrimination and the right to an effective remedy; for the service providers, the freedom to conduct a business, including the freedom of contract; for parties affected by illegal content, the right to human dignity, the rights of the child, the right to protection of property, including intellectual property, and the right to non-discrimination. Providers of hosting services should act upon notices in a timely manner, in particular by taking into account the type of illegal content being notified and the urgency of taking action. For instance, such providers can be expected to act without delay when allegedly illegal content involving a threat to life or safety of persons is being notified. The provider of hosting services should inform the individual or entity notifying the specific content without undue delay after taking a decision whether or not to act upon the notice.

### Recital 21 — liability exemptions for intermediary services

*Source: DSA, dsa-rec-21-en, 2022-10-19 — https://overview.legal/posts/95439*

A provider should be able to benefit from the exemptions from liability for ‘mere conduit’ and for ‘caching’ services when it is in no way involved with the information transmitted or accessed. This requires, among other things, that the provider does not modify the information that it transmits or to which it provides access. However, this requirement should not be understood to cover manipulations of a technical nature which take place in the course of the transmission or access, as long as those manipulations do not alter the integrity of the information transmitted or to which access is provided.

### Recital 22 — hosting service exemption liability conditions

*Source: DSA, dsa-rec-22-en, 2022-10-19 — https://overview.legal/posts/95441*

In order to benefit from the exemption from liability for hosting services, the provider should, upon obtaining actual knowledge or awareness of illegal activities or illegal content, act expeditiously to remove or to disable access to that content. The removal or disabling of access should be undertaken in the observance of the fundamental rights of the recipients of the service, including the right to freedom of expression and of information. The provider can obtain such actual knowledge or awareness of the illegal nature of the content, inter alia through its own-initiative investigations or through notices submitted to it by individuals or entities in accordance with this Regulation in so far as such notices are sufficiently precise and adequately substantiated to allow a diligent economic operator to reasonably identify, assess and, where appropriate, act against the allegedly illegal content. However, such actual knowledge or awareness cannot be considered to be obtained solely on the ground that that provider is aware, in a general sense, of the fact that its service is also used to store illegal content. Furthermore, the fact that the provider automatically indexes information uploaded to its service, that it has a search function or that it recommends information on the basis of the profiles or preferences of the recipients of the service is not a sufficient ground for considering that provider to have ‘specific’ knowledge of illegal activities carried out on that platform or of illegal content stored on it.

### Recital 121 — intermediary service provider liability for damages

*Source: DSA, dsa-rec-121-en, 2022-10-19 — https://overview.legal/posts/95639*

Without prejudice to the provisions on the exemption from liability provided for in this Regulation as regards the information transmitted or stored at the request of a recipient of the service, a provider of intermediary services should be liable for the damages suffered by recipients of the service that are caused by an infringement of the obligations set out in this Regulation by that provider. Such compensation should be in accordance with the rules and procedures set out in the applicable national law and without prejudice to other possibilities for redress available under consumer protection rules.

## Recent developments

### EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines

*Source: Electronic Frontier Foundation, 2026-07-16 — https://overview.legal/posts/122886 — original: https://www.eff.org/deeplinks/2026/07/eff-and-article-19-submission-european-commission-dsa-trusted-flagger-guidelines*

EFF and ARTICLE 19 have submitted joint comments to the European Commission on draft guidelines for the Digital Services Act’s trusted flagger mechanism. Having long advocated for a DSA that protects freedom of expression while preserving intermediary liability protections and the prohibition on general monitoring, we welcome the Commission's effort to provide practical guidance on how the trusted flagger system should operate. The DSA’s trusted flagger system can help platforms identify illegal

## Related topics

- **DSA Scope and Digital Services Coverage** — https://overview.legal/topics/dsa-scope-digital-services
  The content is from the DSA (Digital Services Act), not the AI Act. A dedicated topic for DSA scope is needed to distinguish it from AI Act scope provisions and
- **Caching Services under DSA** — https://overview.legal/topics/caching-services-dsa
  Caching is a specific intermediary service category under DSA Article 5 with distinct liability conditions and technical requirements that warrant dedicated top
- **Hosting Services under DSA** — https://overview.legal/topics/hosting-services-dsa
  While intermediary liability and DSA scope topics exist, there is no dedicated topic specifically for hosting services, their liability conditions, exemptions, 
- **Recipient** — https://overview.legal/topics/recipient
  A person or body to which personal data are disclosed (Art 4(9) GDPR).
- **DSA Terms and Conditions Requirements** — https://overview.legal/topics/dsa-terms-conditions-requirements
  This new topic is needed to specifically address the requirements for terms and conditions documents under the DSA, including transparency, accessibility, and m
- **Cloud Computing** — https://overview.legal/topics/cloud-computing
  Use of cloud services and associated data protection requirements

---
Generated by overview.legal · https://overview.legal/topics/intermediary-liability-framework-dsa · 2026-08-22
