VLOP/VLSE Framework
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The content title specifically focuses on 'Very large online platforms and very large online search engines' as a distinct regulatory category under the DSA. A dedicated topic covering the comprehensive regulatory framework, definitions, and comparative analysis of these two service categories would provide better organization and clarity than distributing this information across multiple existing topics.
Overview
4 sources · Jul 23, 2026Legal Framework
The DSA establishes a tiered regulatory architecture, with Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLSEs) subject to the most stringent obligations. Article 33 DSA sets the designation mechanism: the Commission designates a platform or search engine as "very large" when it exceeds 45 million average monthly active recipients in the Union, calculated as an average over the preceding six months. Once designated under Article 33(4), the provider must comply with enhanced obligations including systemic risk assessments (Article 34), mitigation measures (Article 35), independent audits (Article 37), recommender system transparency (Article 38), data access for researchers (Article 40), and crisis response cooperation (Article 36).
Article 92 DSA governs the temporal application of these obligations. Designated providers must comply from four months after the notification under Article 33(6), or by 17 February 2024—whichever is earlier. This staggered entry into force ensures that newly designated services have a defined adaptation window while maintaining the overall regulatory timeline.
Article 65 DSA addresses enforcement specifically for VLOPs and VLSEs. It grants the Commission exclusive competence to supervise compliance with the obligations applicable to these providers, including the power to conduct inspections, request information, and impose fines up to 6% of global annual turnover. This centralizes enforcement at the EU level rather than distributing it across national Digital Services Coordinators.
Key Developments
The Commission designated the first wave of VLOPs and VLSEs in 2023, capturing major search engines, social media platforms, and marketplace services. Subsequent designations have expanded the cohort, with the 45-million-user threshold proving the operative trigger. The Commission's preliminary proceedings against certain designated platforms under Article 66 DSA have begun shaping expectations around risk assessment depth, mitigation effectiveness, and transparency report granularity. Enforcement signals indicate particular scrutiny of recommender system compliance and the adequacy of researcher data access mechanisms.
Practical Guidance
Monitor user metrics continuously: Track average monthly active recipients in the EU using the methodology in Article 33(3) DSA. Publish figures at least every six months and prepare for designation once the 45-million threshold is approached or crossed.
Prepare a compliance readiness roadmap before designation: Article 92 DSA allows only four months post-notification. Pre-designation preparation for systemic risk assessments, audit infrastructure, and crisis response protocols is essential to meet the deadline.
Establish a Commission liaison function: Because Article 65 DSA centralizes enforcement at the Commission level, maintain direct regulatory communication channels and internal processes for responding to information requests and inspections.
Implement auditable mitigation frameworks: Article 35 DSA requires mitigation measures proportionate to identified systemic risks. Document decision-making, measure effectiveness, and maintain evidence trails for the independent audit required under Article 37.
Build researcher access infrastructure proactively: Article 40 DSA data access obligations require technical and legal readiness. Establish vetting procedures, data schemas, and access controls before designation rather than retrofitting them under enforcement pressure.