# Online Interface Design and Organization — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/online-interface-design-organization-dsa
> Sources are cited per item. Verify against the official texts before relying on them.

This topic is needed to specifically address DSA requirements regarding how online service providers must design and organize their interfaces to ensure transparency, accessibility, and compliance with content moderation and user information obligations. It bridges interface design principles with regulatory compliance requirements.

## Overview

## Legal Framework

Online interface design is governed by two complementary regulatory regimes. Under the Digital Services Act, Article 25 DSA imposes specific obligations on providers of online platforms regarding the design and organisation of their online interfaces. Providers must not design, organise, or operate their online interfaces in a way that deceives or manipulates recipients, or otherwise distorts or impairs their ability to make free, informed decisions. Recital 67 DSA elaborates that so-called "dark patterns"—practices that materially distort autonomous choice, whether intentionally or in effect—are prohibited. Recital 83 DSA extends the risk framework to very large online platforms, identifying interface design that may stimulate behavioural addictions as a systemic risk requiring mitigation.

In parallel, Article 25 GDPR establishes the principles of data protection by design and by default. The controller must implement appropriate technical and organisational measures—both at the design stage and during processing—so that only personal data necessary for the specific purpose are processed. Technical measures may include disabling default software functionalities; organisational measures may involve strict access-right allocation. The data protection officer must be involved early and properly in all matters relating to data protection, facilitating compliance from the outset rather than as a corrective afterthought.

## Key Developments

Enforcement activity is converging on two fronts. First, the European Commission's preliminary findings against TikTok (February 2025) target addictive platform design under the DSA's very large online platform framework, signalling that interface features—such as infinite scroll, personalised recommender triggers, and reward-loop mechanics—will be assessed for their actual or foreseeable negative effects on minors and mental well-being. This represents the first major application of Recital 83's behavioural addiction risk category.

Second, the ongoing debate over cookie consent banners illustrates the intersection of GDPR Article 25 defaults and DSA interface design rules. Member States and major platforms have resisted removing cookie banners, despite criticism that many implementations constitute dark patterns under DSA Article 25—pre-ticked boxes, obstructive "reject" button placement, and nagging repetition all potentially impair autonomous decision-making. The tension between legitimate consent collection and manipulative interface design is now an active enforcement frontier.

## Practical Guidance

- **Audit interface elements for dark pattern compliance.** Map every user-facing choice point—consent flows, subscription prompts, content recommendations—against the DSA Article 25 prohibition on distortion or impairment of autonomous decision-making. Pre-ticked boxes, asymmetric button styling, and forced continuity all carry enforcement risk.

- **Implement data protection by default at the architecture level.** Under GDPR Article 25(2), disable non-essential data-processing functionalities in default configurations. Only activate additional data collection when the user takes affirmative action, and ensure the default state processes the minimum personal data necessary for the stated purpose.

- **Involve the DPO at design inception, not at launch.** GDPR Article 25 requires early and proper involvement of the data protection officer in all interface design decisions with data protection implications. This means embedding DPO review into sprint planning and design review gates.

- **For very large online platforms, conduct systemic risk assessments of addictive design features.** Under DSA Recital 83, features that may stimulate behavioural addiction must be identified, assessed, and mitigated. Document the rationale for retaining or modifying features such as infinite scroll, push notifications, and gamified reward structures.

- **Align consent interfaces across both regimes.** Cookie banners and consent mechanisms must satisfy GDPR lawfulness requirements while simultaneously avoiding DSA Article 25 manipulation prohibitions. A compliant banner requires equally prominent "accept" and "reject" options, no pre-selection, and no repeated prompting after a user decision.

## Legislation (full text of key provisions)

### Online interface design and organisation

*Source: DSA, dsa-art-25-en, 2022-10-19 — https://overview.legal/posts/94426*

### Recital 67 — prohibition of dark patterns online interfaces

*Source: DSA, dsa-rec-67-en, 2022-10-19 — https://overview.legal/posts/95531*

Dark patterns on online interfaces of online platforms are practices that materially distort or impair, either on purpose or in effect, the ability of recipients of the service to make autonomous and informed choices or decisions. Those practices can be used to persuade the recipients of the service to engage in unwanted behaviours or into undesired decisions which have negative consequences for them. Providers of online platforms should therefore be prohibited from deceiving or nudging recipients of the service and from distorting or impairing the autonomy, decision-making, or choice of the recipients of the service via the structure, design or functionalities of an online interface or a part thereof. This should include, but not be limited to, exploitative design choices to direct the recipient to actions that benefit the provider of online platforms, but which may not be in the recipients’ interests, presenting choices in a non-neutral manner, such as giving more prominence to certain choices through visual, auditory, or other components, when asking the recipient of the service for a decision. It should also include repeatedly requesting a recipient of the service to make a choice where such a choice has already been made, making the procedure of cancelling a service significantly more cumbersome than signing up to it, or making certain choices more difficult or time-consuming than others, making it unreasonably difficult to discontinue purchases or to sign out from a given online platform allowing consumers to conclude distance contracts with traders, and deceiving the recipients of the service by nudging them into decisions on transactions, or by default settings that are very difficult to change, and so unreasonably bias the decision making of the recipient of the service, in a way that distorts and impairs their autonomy, decision-making and choice. However, rules preventing dark patterns should not be understood as preventing providers to interact directly with recipients of the service and to offer new or additional services to them. Legitimate practices, for example in advertising, that are in compliance with Union law should not in themselves be regarded as constituting dark patterns. Those rules on dark patterns should be interpreted as covering prohibited practices falling within the scope of this Regulation to the extent that those practices are not already covered under Directive 2005/29/EC or Regulation (EU) 2016/679.

### Recital 74 — online platform interface design and trader compliance

*Source: DSA, dsa-rec-74-en, 2022-10-19 — https://overview.legal/posts/95545*

Providers of online platforms allowing consumers to conclude distance contracts with traders should design and organise their online interface in a way that enables traders to comply with their obligations under relevant Union law, in particular the requirements set out in Articles 6 and 8 of Directive 2011/83/EU, Article 7 of Directive 2005/29/EC, Articles 5 and 6 of Directive 2000/31/EC and Article 3 of Directive 98/6/EC of the European Parliament and of the Council (31). For that purpose, the providers of online platforms concerned should make best efforts to assess whether the traders using their services have uploaded complete information on their online interfaces, in line with relevant applicable Union law. The providers of online platforms should ensure that products or services are not offered as long as such information is not complete. This should not amount to an obligation for the providers of online platforms concerned to generally monitor the products or services offered by traders through their services nor a general fact-finding obligation, in particular to assess the accuracy of the information provided by traders. The online interfaces should be user-friendly and easily accessible for traders and consumers. Additionally and after allowing the offering of the product or service by the trader, the providers of online platforms concerned should make reasonable efforts to randomly check whether the products or services offered have been identified as being illegal in any official, freely accessible and machine-readable online databases or online interfaces available in a Member State or in the Union. The Commission should also encourage traceability of products through technology solutions such as digitally signed Quick Response codes (or ‘QR codes’) or non-fungible tokens. The Commission should promote the development of standards and, in the absence of them, of market led solutions which can be acceptable to the parties concerned.

### Recital 87 — VLOPs VLOSEs mitigating measures for illegal content

*Source: DSA, dsa-rec-87-en, 2022-10-19 — https://overview.legal/posts/95571*

Providers of very large online platforms and of very large online search engines should consider under such mitigating measures, for example, adapting any necessary design, feature or functioning of their service, such as the online interface design. They should adapt and apply their terms and conditions, as necessary, and in accordance with the rules of this Regulation on terms and conditions. Other appropriate measures could include adapting their content moderation systems and internal processes or adapting their decision-making processes and resources, including the content moderation personnel, their training and local expertise. This concerns in particular the speed and quality of processing of notices. In this regard, for example, the Code of conduct on countering illegal hate speech online of 2016 sets a benchmark to process valid notifications for removal of illegal hate speech in less than 24 hours. Providers of very large online platforms, in particular those primarily used for the dissemination to the public of pornographic content, should diligently meet all their obligations under this Regulation in respect of illegal content constituting cyber violence, including illegal pornographic content, especially with regard to ensuring that victims can effectively exercise their rights in relation to content representing non-consensual sharing of intimate or manipulated material through the rapid processing of notices and removal of such content without undue delay. Other types of illegal content may require longer or shorter timelines for processing of notices, which will depend on the facts, circumstances and types of illegal content at hand. Those providers may also initiate or increase cooperation with trusted flaggers and organise training sessions and exchanges with trusted flagger organisations.

### Recital 83 — very large online platforms health risks

*Source: DSA, dsa-rec-83-en, 2022-10-19 — https://overview.legal/posts/95563*

A fourth category of risks stems from similar concerns relating to the design, functioning or use, including through manipulation, of very large online platforms and of very large online search engines with an actual or foreseeable negative effect on the protection of public health, minors and serious negative consequences to a person's physical and mental well-being, or on gender-based violence. Such risks may also stem from coordinated disinformation campaigns related to public health, or from online interface design that may stimulate behavioural addictions of recipients of the service.

### Recital 107 — online advertising codes of conduct

*Source: DSA, dsa-rec-107-en, 2022-10-19 — https://overview.legal/posts/95611*

The provision of online advertising generally involves several actors, including intermediary services that connect publishers of advertisements with advertisers. Codes of conduct should support and complement the transparency obligations relating to advertising for providers of online platforms, of very large online platforms and of very large online search engines set out in this Regulation in order to provide for flexible and effective mechanisms to facilitate and enhance the compliance with those obligations, notably as concerns the modalities of the transmission of the relevant information. This should include facilitating the transmission of the information on the advertiser who pays for the advertisement when they differ from the natural or legal person on whose behalf the advertisement is presented on the online interface of an online platform. The codes of conduct should also include measures to ensure that meaningful information about the monetisation of data is appropriately shared throughout the value chain. The involvement of a wide range of stakeholders should ensure that those codes of conduct are widely supported, technically sound, effective and offer the highest levels of user-friendliness to ensure that the transparency obligations achieve their objectives. In order to ensure the effectiveness of codes of conduct, the Commission should include evaluation mechanisms in drawing up the codes of conduct. Where appropriate, the Commission may invite the Fundamental Rights Agency or the European Data Protection Supervisor to express their opinions on the respective code of conduct.

### Recital 68 — online advertising transparency requirements

*Source: DSA, dsa-rec-68-en, 2022-10-19 — https://overview.legal/posts/95533*

Online advertising plays an important role in the online environment, including in relation to the provision of online platforms, where the provision of the service is sometimes in whole or in part remunerated directly or indirectly, through advertising revenues. Online advertising can contribute to significant risks, ranging from advertisements that are themselves illegal content, to contributing to financial incentives for the publication or amplification of illegal or otherwise harmful content and activities online, or the discriminatory presentation of advertisements with an impact on the equal treatment and opportunities of citizens. In addition to the requirements resulting from Article 6 of Directive 2000/31/EC, providers of online platforms should therefore be required to ensure that the recipients of the service have certain individualised information necessary for them to understand when and on whose behalf the advertisement is presented. They should ensure that the information is salient, including through standardised visual or audio marks, clearly identifiable and unambiguous for the average recipient of the service, and should be adapted to the nature of the individual service’s online interface. In addition, recipients of the service should have information directly accessible from the online interface where the advertisement is presented, on the main parameters used for determining that a specific advertisement is presented to them, providing meaningful explanations of the logic used to that end, including when this is based on profiling. Such explanations should include information on the method used for presenting the advertisement, for example whether it is contextual or other type of advertising, and, where applicable, the main profiling criteria used; it should also inform the recipient about any means available for them to change such criteria. The requirements of this Regulation on the provision of information relating to advertising is without prejudice to the application of the relevant provisions of Regulation (EU) 2016/679, in particular those regarding the right to object, automated individual decision-making, including profiling, and specifically the need to obtain consent of the data subject prior to the processing of personal data for targeted advertising. Similarly, it is without prejudice to the provisions laid down in Directive 2002/58/EC in particular those regarding the storage of information in terminal equipment and the access to information stored therein. Finally, this Regulation complements the application of the Directive 2010/13/EU which imposes measures to enable users to declare audiovisual commercial communications in user-generated videos. It also complements the obligations for traders regarding the disclosure of commercial communications deriving from Directive 2005/29/EC.

### Recital 70 — online platform recommender system transparency

*Source: DSA, dsa-rec-70-en, 2022-10-19 — https://overview.legal/posts/95537*

A core part of the online platform’s business is the manner in which information is prioritised and presented on its online interface to facilitate and optimise access to information for the recipients of the service. This is done, for example, by algorithmically suggesting, ranking and prioritising information, distinguishing through text or other visual representations, or otherwise curating information provided by recipients. Such recommender systems can have a significant impact on the ability of recipients to retrieve and interact with information online, including to facilitate the search of relevant information for recipients of the service and contribute to an improved user experience. They also play an important role in the amplification of certain messages, the viral dissemination of information and the stimulation of online behaviour. Consequently, online platforms should consistently ensure that recipients of their service are appropriately informed about how recommender systems impact the way information is displayed, and can influence how information is presented to them. They should clearly present the parameters for such recommender systems in an easily comprehensible manner to ensure that the recipients of the service understand how information is prioritised for them. Those parameters should include at least the most important criteria in determining the information suggested to the recipient of the service and the reasons for their respective importance, including where information is prioritised based on profiling and their online behaviour.

### Recital 77 — online platform active recipients calculation

*Source: DSA, dsa-rec-77-en, 2022-10-19 — https://overview.legal/posts/95551*

In order to determine the reach of a given online platform or online search engine, it is necessary to establish the average number of active recipients of each service individually. Accordingly, the number of average monthly active recipients of an online platform should reflect all the recipients actually engaging with the service at least once in a given period of time, by being exposed to information disseminated on the online interface of the online platform, such as viewing it or listening to it, or by providing information, such as traders on an online platforms allowing consumers to conclude distance contracts with traders. For the purposes of this Regulation, engagement is not limited to interacting with information by clicking on, commenting, linking, sharing, purchasing or carrying out transactions on an online platform. Consequently, the concept of active recipient of the service does not necessarily coincide with that of a registered user of a service. As regards online search engines, the concept of active recipients of the service should cover those who view information on their online interface, but not, for example, the owners of the websites indexed by an online search engine, as they do not actively engage with the service. The number of active recipients of a service should include all unique recipients of the service that engage with the specific service. To this effect, a recipient of the service that uses different online interfaces, such as websites or applications, including where the services are accessed through different uniform resource locators (URLs) or domain names, should, where possible, be counted only once. However, the concept of active recipient of the service should not include incidental use of the service by recipients of other providers of intermediary services that indirectly make available information hosted by the provider of online platforms through linking or indexing by a provider of online search engine. Further, this Regulation does not require providers of online platforms or of online search engines to perform specific tracking of individuals online. Where such providers are able to discount automated users such as bots or scrapers without further processing of personal data and tracking, they may do so. The determination of the number of active recipients of the service can be impacted by market and technical developments and therefore the Commission should be empowered to supplement the provisions of this Regulation by adopting delegated acts laying down the methodology to determine the active recipients of an online platform or of an online search engine, where necessary, reflecting the nature of the service and the way recipients of the service interact with it.

### Recital 94 — very large platform recommender system adjustments

*Source: DSA, dsa-rec-94-en, 2022-10-19 — https://overview.legal/posts/95585*

The obligations on assessment and mitigation of risks should trigger, on a case-by-case basis, the need for providers of very large online platforms and of very large online search engines to assess and, where necessary, adjust the design of their recommender systems, for example by taking measures to prevent or minimise biases that lead to the discrimination of persons in vulnerable situations, in particular where such adjustment is in accordance with data protection law and when the information is personalised on the basis of special categories of personal data referred to in Article 9 of the Regulation (EU) 2016/679. In addition, and complementing the transparency obligations applicable to online platforms as regards their recommender systems, providers of very large online platforms and of very large online search engines should consistently ensure that recipients of their service enjoy alternative options which are not based on profiling, within the meaning of Regulation (EU) 2016/679, for the main parameters of their recommender systems. Such choices should be directly accessible from the online interface where the recommendations are presented.

## Recent developments

### EU Member States (and Google) suddenly want to keep cookie banners!

*Source: noyb - European Center for Digital Rights, 2026-06-23 — https://overview.legal/posts/53123 — original: https://noyb.eu/en/eu-member-states-and-google-suddenly-want-keep-cookie-banners*

GDPR Policy For years, users and many companies have been complaining about cookie banners. Even though this understandable frustration is mostly caused by misleading dark patterns used by the industry, these banners have become the symbol of what is perceived as excessive EU regulation. As part of the ‘Digital Omnibus’, the European Commission now finally wanted to get rid of cookie banners and replace them with an automated signal. However, Google and some of the very EU Member States that are

### EDRi welcomes EU preliminary findings on TikTok’s addictive platform design

*Source: European Digital Rights, 2026-02-09 — https://overview.legal/posts/52499 — original: https://edri.org/our-work/edri-welcomes-eu-preliminary-findings-on-tiktoks-addictive-platform-design/*

The European Commission preliminarily found that TikTok was in breach of the Digital Services Act (DSA) due to the addictive design of its platform. EDRi welcomes this decision and urges TikTok to swiftly mitigate the risks to which its users are exposed.

## Related topics

- **VLOP/VLSE Framework** — https://overview.legal/topics/vlop-vlse-regulatory-framework-overview
  The content title specifically focuses on 'Very large online platforms and very large online search engines' as a distinct regulatory category under the DSA. A 
- **Recipient** — https://overview.legal/topics/recipient
  A person or body to which personal data are disclosed (Art 4(9) GDPR).
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Marketing** — https://overview.legal/topics/marketing
  Use of personal data for marketing and advertising purposes
- **Transparency** — https://overview.legal/topics/transparantie
  Openness about data processing activities
- **Advertising Practices and Requirements under DSA** — https://overview.legal/topics/advertising-practices-dsa
  This new topic is needed to specifically address advertising practices on online platforms under DSA, including transparency requirements, content moderation of

---
Generated by overview.legal · https://overview.legal/topics/online-interface-design-organization-dsa · 2026-08-22
