Online Interface Design and Organization
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is needed to specifically address DSA requirements regarding how online service providers must design and organize their interfaces to ensure transparency, accessibility, and compliance with content moderation and user information obligations. It bridges interface design principles with regulatory compliance requirements.
Overview
9 sources · Jul 23, 2026Legal Framework
Online interface design is governed by two complementary regulatory regimes. Under the Digital Services Act, Article 25 DSA imposes specific obligations on providers of online platforms regarding the design and organisation of their online interfaces. Providers must not design, organise, or operate their online interfaces in a way that deceives or manipulates recipients, or otherwise distorts or impairs their ability to make free, informed decisions. Recital 67 DSA elaborates that so-called "dark patterns"—practices that materially distort autonomous choice, whether intentionally or in effect—are prohibited. Recital 83 DSA extends the risk framework to very large online platforms, identifying interface design that may stimulate behavioural addictions as a systemic risk requiring mitigation.
In parallel, Article 25 GDPR establishes the principles of data protection by design and by default. The controller must implement appropriate technical and organisational measures—both at the design stage and during processing—so that only personal data necessary for the specific purpose are processed. Technical measures may include disabling default software functionalities; organisational measures may involve strict access-right allocation. The data protection officer must be involved early and properly in all matters relating to data protection, facilitating compliance from the outset rather than as a corrective afterthought.
Key Developments
Enforcement activity is converging on two fronts. First, the European Commission's preliminary findings against TikTok (February 2025) target addictive platform design under the DSA's very large online platform framework, signalling that interface features—such as infinite scroll, personalised recommender triggers, and reward-loop mechanics—will be assessed for their actual or foreseeable negative effects on minors and mental well-being. This represents the first major application of Recital 83's behavioural addiction risk category.
Second, the ongoing debate over cookie consent banners illustrates the intersection of GDPR Article 25 defaults and DSA interface design rules. Member States and major platforms have resisted removing cookie banners, despite criticism that many implementations constitute dark patterns under DSA Article 25—pre-ticked boxes, obstructive "reject" button placement, and nagging repetition all potentially impair autonomous decision-making. The tension between legitimate consent collection and manipulative interface design is now an active enforcement frontier.
Practical Guidance
Audit interface elements for dark pattern compliance. Map every user-facing choice point—consent flows, subscription prompts, content recommendations—against the DSA Article 25 prohibition on distortion or impairment of autonomous decision-making. Pre-ticked boxes, asymmetric button styling, and forced continuity all carry enforcement risk.
Implement data protection by default at the architecture level. Under GDPR Article 25(2), disable non-essential data-processing functionalities in default configurations. Only activate additional data collection when the user takes affirmative action, and ensure the default state processes the minimum personal data necessary for the stated purpose.
Involve the DPO at design inception, not at launch. GDPR Article 25 requires early and proper involvement of the data protection officer in all interface design decisions with data protection implications. This means embedding DPO review into sprint planning and design review gates.
For very large online platforms, conduct systemic risk assessments of addictive design features. Under DSA Recital 83, features that may stimulate behavioural addiction must be identified, assessed, and mitigated. Document the rationale for retaining or modifying features such as infinite scroll, push notifications, and gamified reward structures.
Align consent interfaces across both regimes. Cookie banners and consent mechanisms must satisfy GDPR lawfulness requirements while simultaneously avoiding DSA Article 25 manipulation prohibitions. A compliant banner requires equally prominent "accept" and "reject" options, no pre-selection, and no repeated prompting after a user decision.