Transparency Reporting Obligations Overview
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.While individual aspects of transparency reporting are covered by existing topics, there is no comprehensive overview topic that addresses transparency reporting obligations as a unified framework under DSA Article 24, including the general principles, scope, and procedural requirements.
Overview
18 sources · Jul 23, 2026Legal Framework
Transparency reporting obligations under the Digital Services Act are structured across three articles that create a layered framework based on service type. Article 15 DSA establishes the baseline: all providers of intermediary services must publish reports at least once a year containing information on content moderation activities, including orders issued by Member State authorities. Article 24 DSA extends and deepens these obligations specifically for providers of online platforms, adding requirements to report on automated content moderation tools, the number of disputes submitted to certified out-of-court dispute settlement bodies, and the use of internal complaint-handling systems. Article 42 DSA functions as the overarching transparency provision, consolidating reporting duties and ensuring that reports are machine-readable, publicly accessible, and submitted to the Commission's database.
The rationale is twofold: first, to enable public scrutiny of how intermediary services shape information ecosystems; second, to equip regulators with structured data for supervisory convergence. The obligations scale with risk — hosting providers face lighter duties than very large online platforms, which must report semi-annually under Article 42.
Key Developments
Enforcement signals from data protection authorities confirm that transparency failures are treated as substantive, not procedural, violations. The Croatian DPA's €4.5 million fine against a telecommunications operator demonstrates that inadequate transparency reporting — particularly where data processing intersects with content moderation — carries significant financial exposure. The Irish DPC's €5.5 million penalty against WhatsApp Ireland reinforced that transparency obligations require granular disclosure of processing purposes and legal bases, not generalized statements.
The EDPB's Guidelines 04/2022 on administrative fine calculation establish that transparency violations are assessed against turnover-based thresholds, meaning larger platforms face proportionally higher penalties. The EDPB's Guidelines 1/2019 on codes of conduct further clarify that approved certification mechanisms can serve as evidence of compliance with transparency duties — a practical safe harbor for organizations that adopt approved standards.
Recent regulatory focus on automated moderation accountability signals that transparency reports must now meaningfully disclose the role, scope, and limitations of algorithmic decision-making in content moderation, not merely aggregate takedown numbers.
Practical Guidance
Map your service classification first. Determine whether you qualify as a hosting provider, online platform, or very large online platform under the DSA definitions, as this directly determines whether Article 15, Article 24, or both apply, and sets your reporting cadence (annual versus semi-annual).
Implement structured data collection for every content moderation action. Article 24(2) requires reporting on automated versus human moderation, dispute outcomes, and notice-based removals. Build internal logging systems that tag each action by type, legal basis, and outcome before the reporting deadline arrives.
Publish reports in machine-readable format via the Commission database. Article 42 mandates submission to the EU transparency database. Reports must be publicly accessible and structured to enable automated comparison across providers.
Align DSA transparency reporting with GDPR Article 13–14 obligations. Where content moderation involves personal data processing — particularly automated flagging systems — transparency reports should be consistent with privacy notices to avoid contradictory disclosures that regulators have penalized in the WhatsApp and Croatian telecom enforcement actions.
Document the methodology behind each reported metric. Regulators expect reproducible data. Maintain internal audit trails showing how each figure in the transparency report was derived, including any exclusions or estimation techniques applied.