Regulation & Policy
Digital Services Act
Also known as: DSA, EU Digital Services Act
The Digital Services Act is an EU regulation setting obligations for online intermediaries, from hosting providers and marketplaces to social platforms and search engines. It covers notice and action on illegal content, complaint handling, advertising transparency and periodic reporting, with additional duties for the largest services. It has applied in full across the EU since February 2024.
What it is
The DSA is a directly applicable EU regulation that layers obligations by service type and size, so a small hosting provider carries far less than a global platform. Services designated as very large online platforms or very large online search engines, those reaching at least 45 million average monthly active users in the EU, face systemic risk assessments, independent audits, data access for researchers and direct supervision by the European Commission. It replaced parts of the older e-Commerce Directive framework while keeping the principle that intermediaries are not liable for user content they do not know about.
Why it matters
The rules shape the surfaces marketers depend on: how content is moderated, how ads are labelled and archived, how recommender systems are explained, and what sellers must prove before listing. Public ad repositories and transparency reports give competitive and research visibility that did not previously exist. Marketplace trader verification and faster notice handling also change how brands tackle counterfeits and misleading listings in Europe.
How it works
Practitioners use platform notice mechanisms to report illegal or infringing content and track decision times, keep trader identity data complete so EU listings stay live, and read transparency reports to anticipate moderation or ranking changes. Larger advertisers and agencies mine ad repositories for creative and placement research, while compliance teams map which of their own services fall in scope and prepare terms, complaint routes and reporting accordingly.
When it applies
It applies if you provide intermediary services to users in the EU, regardless of where you are established, and indirectly whenever you sell, advertise or publish through platforms in scope.
Examples
- A marketplace seller supplies verified trader details so its listings remain visible to EU shoppers.
- A brand protection team files notices about counterfeit listings and logs how long each platform takes to decide.
- An agency checks a platform's public ad repository to see how a competitor's EU campaigns were targeted and presented.
How it is measured
- Number of notices submitted and median time to a platform decision.
- Share of your notices upheld, and share of actions against you reversed after complaint or out of court dispute.
- Completeness of trader verification and product compliance data across EU listings.
- Traffic or conversion change following moderation, labelling or recommender changes disclosed in transparency reports.
Insights on Digital Services Act
Related terms in Regulation & Policy
- AI complianceAI compliance is the work of making sure AI systems meet the laws, regulations, standards and internal policies that apply to them. It spans data protection, transparency, risk classification, documentation, human oversight and record keeping across the life of a system. In practice it combines legal interpretation, engineering controls and ongoing evidence gathering.
- AI governanceAI governance is the set of policies, roles, controls and review processes an organisation uses to manage how AI systems are built, bought and used. It covers risk assessment, documentation, human oversight, data handling and accountability. It applies both to AI a company develops and to third-party AI tools used by staff.
- AI privacyAI privacy is the set of practices, rights and obligations that govern how personal data is collected, used, stored and exposed when building or using AI systems. It covers training data, prompts and outputs, retention by AI vendors, and the transparency and control offered to the people whose data is involved. For marketing teams it shapes what customer data can safely be put into AI tools and what must be disclosed.
- AI safetyAI safety is the practice of designing, testing and operating AI systems so they cause less harm, behave predictably and resist misuse. It covers alignment with intended behaviour, evaluation and red teaming, content guardrails, and monitoring once a system is live. For marketers it shapes what models will say, how assistants handle brands, and what compliance teams expect before AI tools go into production.
- AI transparencyAI transparency is the practice of making clear how an AI system works, what sits behind it, and when content or an interaction involves AI. It covers regulatory disclosure duties as well as voluntary explanations such as model cards, labels on synthetic media and citations in AI generated answers. For publishers and marketers it sets expectations about when AI involvement should be declared and how clearly.
- Competition and Markets AuthorityThe Competition and Markets Authority (CMA) is the United Kingdom's competition and consumer protection regulator. It investigates mergers, anti-competitive conduct and market practices, and it holds specific powers over large digital firms under the Digital Markets, Competition and Consumers Act 2024. Its decisions shape how search engines, app stores and AI assistants operate in the UK market.