Skip to content
Topic Developing

VLOP/VLSE Framework

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content title specifically focuses on 'Very large online platforms and very large online search engines' as a distinct regulatory category under the DSA. A dedicated topic covering the comprehensive regulatory framework, definitions, and comparative analysis of these two service categories would provide better organization and clarity than distributing this information across multiple existing topics.

49 linked items 49 Laws

Overview

4 sources · Jul 23, 2026

Legal Framework

The DSA establishes a tiered regulatory architecture, with Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLSEs) subject to the most stringent obligations. Article 33 DSA sets the designation mechanism: the Commission designates a platform or search engine as "very large" when it exceeds 45 million average monthly active recipients in the Union, calculated as an average over the preceding six months. Once designated under Article 33(4), the provider must comply with enhanced obligations including systemic risk assessments (Article 34), mitigation measures (Article 35), independent audits (Article 37), recommender system transparency (Article 38), data access for researchers (Article 40), and crisis response cooperation (Article 36).

Article 92 DSA governs the temporal application of these obligations. Designated providers must comply from four months after the notification under Article 33(6), or by 17 February 2024—whichever is earlier. This staggered entry into force ensures that newly designated services have a defined adaptation window while maintaining the overall regulatory timeline.

Article 65 DSA addresses enforcement specifically for VLOPs and VLSEs. It grants the Commission exclusive competence to supervise compliance with the obligations applicable to these providers, including the power to conduct inspections, request information, and impose fines up to 6% of global annual turnover. This centralizes enforcement at the EU level rather than distributing it across national Digital Services Coordinators.

Key Developments

The Commission designated the first wave of VLOPs and VLSEs in 2023, capturing major search engines, social media platforms, and marketplace services. Subsequent designations have expanded the cohort, with the 45-million-user threshold proving the operative trigger. The Commission's preliminary proceedings against certain designated platforms under Article 66 DSA have begun shaping expectations around risk assessment depth, mitigation effectiveness, and transparency report granularity. Enforcement signals indicate particular scrutiny of recommender system compliance and the adequacy of researcher data access mechanisms.

Practical Guidance

  • Monitor user metrics continuously: Track average monthly active recipients in the EU using the methodology in Article 33(3) DSA. Publish figures at least every six months and prepare for designation once the 45-million threshold is approached or crossed.

  • Prepare a compliance readiness roadmap before designation: Article 92 DSA allows only four months post-notification. Pre-designation preparation for systemic risk assessments, audit infrastructure, and crisis response protocols is essential to meet the deadline.

  • Establish a Commission liaison function: Because Article 65 DSA centralizes enforcement at the Commission level, maintain direct regulatory communication channels and internal processes for responding to information requests and inspections.

  • Implement auditable mitigation frameworks: Article 35 DSA requires mitigation measures proportionate to identified systemic risks. Document decision-making, measure effectiveness, and maintain evidence trails for the independent audit required under Article 37.

  • Build researcher access infrastructure proactively: Article 40 DSA data access obligations require technical and legal readiness. Establish vetting procedures, data schemas, and access controls before designation rather than retrofitting them under enforcement pressure.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 49
Art. 14(5) Providers of very large online platforms and of very large online search engines shall provide recipients of services with a concise, easily-accessibl… DSA Art. 14(6) Very large online platforms and very large online search engines within the meaning of Article 33 shall publish their terms and conditions in the offi… DSA Art. 15(2) Paragraph 1 of this Article shall not apply to providers of intermediary services that qualify as micro or small enterprises as defined in Recommendat… DSA Art. 19(1)(cont)(1) This Section, with the exception of Article 24(3) thereof, shall not apply to providers of online platforms that previously qualified for the status o… DSA art 65 Enforcement of obligations of providers of very large online platforms and of very large online search engines DSA Oct 2022 art 92 Anticipated application to providers of very large online platforms and of very large online search engines DSA Oct 2022 rec 83 Recital 83 — very large online platforms health risks DSA Oct 2022 rec 99 Recital 99 — independent compliance function for very large online platforms DSA Oct 2022 rec 92 Recital 92 — independent compliance audits for very large online platforms DSA Oct 2022 art 33 Very large online platforms and very large online search engines DSA Oct 2022 rec 95 Recital 95 — very large online platforms advertisement repositories DSA Oct 2022 rec 75 Recital 75 — very large online platforms specific obligations DSA Oct 2022 rec 137 Recital 137 — Union supervision of very large online platforms DSA Oct 2022 rec 91 Recital 91 — crisis response mechanism for very large online platforms DSA Oct 2022 rec 85 Recital 85 — risk assessment document retention obligation DSA Oct 2022 rec 86 Recital 86 — systemic risk mitigation by very large platforms DSA Oct 2022 rec 87 Recital 87 — VLOPs VLOSEs mitigating measures for illegal content DSA Oct 2022 rec 88 Recital 88 — very large platform algorithmic risk mitigation DSA Oct 2022 rec 89 Recital 89 — protection of minors on large platforms DSA Oct 2022 rec 90 Recital 90 — evidence-based risk assessment stakeholder consultation DSA Oct 2022 rec 94 Recital 94 — very large platform recommender system adjustments DSA Oct 2022 rec 96 Recital 96 — very large platform compliance data access DSA Oct 2022 rec 97 Recital 97 — researcher data access framework DSA Oct 2022 rec 98 Recital 98 — researcher access to public data DSA Oct 2022 Show 29 more →