Skip to content
Topic Developing

Online Interface Design and Organization

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This topic is needed to specifically address DSA requirements regarding how online service providers must design and organize their interfaces to ensure transparency, accessibility, and compliance with content moderation and user information obligations. It bridges interface design principles with regulatory compliance requirements.

14 linked items 12 Laws2 News

Overview

9 sources · Jul 23, 2026

Legal Framework

Online interface design is governed by two complementary regulatory regimes. Under the Digital Services Act, Article 25 DSA imposes specific obligations on providers of online platforms regarding the design and organisation of their online interfaces. Providers must not design, organise, or operate their online interfaces in a way that deceives or manipulates recipients, or otherwise distorts or impairs their ability to make free, informed decisions. Recital 67 DSA elaborates that so-called "dark patterns"—practices that materially distort autonomous choice, whether intentionally or in effect—are prohibited. Recital 83 DSA extends the risk framework to very large online platforms, identifying interface design that may stimulate behavioural addictions as a systemic risk requiring mitigation.

In parallel, Article 25 GDPR establishes the principles of data protection by design and by default. The controller must implement appropriate technical and organisational measures—both at the design stage and during processing—so that only personal data necessary for the specific purpose are processed. Technical measures may include disabling default software functionalities; organisational measures may involve strict access-right allocation. The data protection officer must be involved early and properly in all matters relating to data protection, facilitating compliance from the outset rather than as a corrective afterthought.

Key Developments

Enforcement activity is converging on two fronts. First, the European Commission's preliminary findings against TikTok (February 2025) target addictive platform design under the DSA's very large online platform framework, signalling that interface features—such as infinite scroll, personalised recommender triggers, and reward-loop mechanics—will be assessed for their actual or foreseeable negative effects on minors and mental well-being. This represents the first major application of Recital 83's behavioural addiction risk category.

Second, the ongoing debate over cookie consent banners illustrates the intersection of GDPR Article 25 defaults and DSA interface design rules. Member States and major platforms have resisted removing cookie banners, despite criticism that many implementations constitute dark patterns under DSA Article 25—pre-ticked boxes, obstructive "reject" button placement, and nagging repetition all potentially impair autonomous decision-making. The tension between legitimate consent collection and manipulative interface design is now an active enforcement frontier.

Practical Guidance

  • Audit interface elements for dark pattern compliance. Map every user-facing choice point—consent flows, subscription prompts, content recommendations—against the DSA Article 25 prohibition on distortion or impairment of autonomous decision-making. Pre-ticked boxes, asymmetric button styling, and forced continuity all carry enforcement risk.

  • Implement data protection by default at the architecture level. Under GDPR Article 25(2), disable non-essential data-processing functionalities in default configurations. Only activate additional data collection when the user takes affirmative action, and ensure the default state processes the minimum personal data necessary for the stated purpose.

  • Involve the DPO at design inception, not at launch. GDPR Article 25 requires early and proper involvement of the data protection officer in all interface design decisions with data protection implications. This means embedding DPO review into sprint planning and design review gates.

  • For very large online platforms, conduct systemic risk assessments of addictive design features. Under DSA Recital 83, features that may stimulate behavioural addiction must be identified, assessed, and mitigated. Document the rationale for retaining or modifying features such as infinite scroll, push notifications, and gamified reward structures.

  • Align consent interfaces across both regimes. Cookie banners and consent mechanisms must satisfy GDPR lawfulness requirements while simultaneously avoiding DSA Article 25 manipulation prohibitions. A compliant banner requires equally prominent "accept" and "reject" options, no pre-selection, and no repeated prompting after a user decision.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 12
Art. 3(m) ‘online interface’ means any software, including a website or a part thereof, and applications, including mobile applications; DSA Art. 3(p) ‘active recipient of an online platform’ means a recipient of the service that has engaged with an online platform by either requesting the online pla… DSA Art. 3(q) ‘active recipient of an online search engine’ means a recipient of the service that has submitted a query to an online search engine and been exposed … DSA Art. 3(r) ‘advertisement’ means information designed to promote the message of a legal or natural person, irrespective of whether to achieve commercial or non-c… DSA rec 67 Recital 67 — prohibition of dark patterns online interfaces DSA Oct 2022 rec 74 Recital 74 — online platform interface design and trader compliance DSA Oct 2022 art 25 Online interface design and organisation DSA Oct 2022 rec 87 Recital 87 — VLOPs VLOSEs mitigating measures for illegal content DSA Oct 2022 rec 83 Recital 83 — very large online platforms health risks DSA Oct 2022 rec 107 Recital 107 — online advertising codes of conduct DSA Oct 2022 rec 68 Recital 68 — online advertising transparency requirements DSA Oct 2022 rec 70 Recital 70 — online platform recommender system transparency DSA Oct 2022 rec 77 Recital 77 — online platform active recipients calculation DSA Oct 2022 rec 94 Recital 94 — very large platform recommender system adjustments DSA Oct 2022 rec 95 Recital 95 — very large online platforms advertisement repositories DSA Oct 2022 rec 89 Recital 89 — protection of minors on large platforms DSA Oct 2022
News 2
noyb - European Center for Digital Rights EU Member States (and Google) suddenly want to keep cookie banners! noyb - European Center for Digital Rights Jun 2026 European Digital Rights EDRi welcomes EU preliminary findings on TikTok’s addictive platform design European Digital Rights Feb 2026