LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:eu:dsa

EU Digital Services Act (2022)

As of 1 October 2026. Information only, not legal advice – see the disclaimer.

Full title Regulation (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act)
Type EU regulation
Adopted by European Parliament and Council of the European Union
Adopted 19 October 2022
Legal status In force since 16 November 2022; applicable in general since 17 February 2024 (obligations for very large online platforms and search engines apply earlier, four months after designation); binding and directly applicable in all EU Member States
Official text EUR-Lex
Subject area Propaganda, disinformation and elections

Overview

The Digital Services Act (DSA) sets harmonised rules on the obligations of intermediary services in the EU internal market, including liability exemptions, notice-and-action procedures and transparency duties. Articles 34 to 36 impose additional obligations on providers designated as very large online platforms (VLOPs) and very large online search engines (VLOSEs): they must assess and mitigate systemic risks, and the Commission may require specific measures in a crisis. The European Commission is the competent enforcer for these obligations. The provisions on systemic risks to “civic discourse and electoral processes” are referred to in debates on disinformation, foreign information manipulation and interference, and the integrity of elections.

Provisions relevant to the cyber and information sphere

  • Art. 34 – VLOPs and VLOSEs must at least once a year identify and assess systemic risks stemming from their services, including the dissemination of illegal content, negative effects on fundamental rights, and (Art. 34(1)©) “any actual or foreseeable negative effects on civic discourse and electoral processes, and public security”. Art. 34(2) requires them to consider, among other factors, recommender and advertising systems and intentional manipulation of the service, including inauthentic use or automated exploitation.
  • Art. 35 – Providers must put in place reasonable, proportionate and effective mitigation measures tailored to the identified risks (e.g. adapting design, content moderation, recommender or advertising systems, and marking of generated or manipulated content). Under Art. 35(3) the Commission may issue guidelines on specific risks.
  • Art. 36 – Crisis response mechanism: on a recommendation of the European Board for Digital Services, the Commission may by decision require VLOPs/VLOSEs to assess and take measures regarding their contribution to a serious threat. A crisis is deemed to occur where “extraordinary circumstances lead to a serious threat to public security or public health in the Union or in significant parts of it” (Art. 36(2)).
  • Art. 48 – Crisis protocols that the Commission may encourage and facilitate for extraordinary circumstances affecting public security or public health.
  • Arts. 66 et seq., 73, 74 – Commission proceedings, non-compliance decisions and fines of up to 6 % of annual worldwide turnover.

Application to cyber and information operations

The Commission issued “Guidelines for providers of Very Large Online Platforms and Very Large Online Search Engines on the mitigation of systemic risks for electoral processes pursuant to Article 35(3)” (published in the Official Journal on 26 April 2024, C/2024/3014). They recommend, among other measures, election-specific risk mitigation, labelling of political advertising and of AI-generated content, and cooperation with authorities and researchers, including in relation to foreign information manipulation and interference. On 20 February 2025 the Commission published a best-practice elections toolkit for national Digital Services Coordinators.

Formal proceedings with an election or civic-discourse dimension (outcome as of the date above is stated only where an official decision is known):

  • X – proceedings opened on 18 December 2023 (including risk management and information manipulation). On 5 December 2025 the Commission adopted its first DSA non-compliance decision, fining X EUR 120 million for breaches concerning the design of the “blue checkmark”, the advertising repository and researcher data access. On 26 January 2026 the Commission extended its investigation opened in December 2023 into X's compliance with its risk-management obligations concerning recommender systems, and opened new proceedings on the assessment and mitigation of risks linked to the deployment of Grok functionalities in X. On 16 July 2026 the Commission accepted X's action plan concerning the advertising repository and researcher data access; according to the Commission, the European Board for Digital Services considered the plan insufficient in part. X has brought an action against the non-compliance decision before the General Court; on 25 September 2026 the United States Department of Justice applied to intervene in support of X (AP).
  • Meta (Facebook, Instagram) – proceedings opened on 30 April 2024 concerning deceptive advertising and disinformation, the visibility of political content, and the discontinuation of the CrowdTangle tool without an equivalent real-time civic-discourse and election-monitoring tool. The Commission's list of enforcement actions records preliminary findings against Meta of 24 October 2025, 29 April 2026 and 10 July 2026, which concern other matters (including transparency obligations, the protection of minors and platform design); it records no preliminary findings or decision on the election-related strand as of the date above.
  • TikTok – proceedings opened on 17 December 2024 under Arts. 34(1), 34(2) and 35(1), following the Romanian presidential election of 24 November 2024; they concern recommender systems (including coordinated inauthentic manipulation) and political advertising and paid political content. The Commission's list of enforcement actions records later preliminary findings against TikTok (including on the advertising repository, 15 May 2025, followed by accepted commitments on 5 December 2025, and on the protection of minors, 24 July 2026), but no preliminary findings or decision in these election-risk proceedings as of the date above.

Recent developments

  • 2024-04-26: Election guidelines under Art. 35(3) published in the Official Journal (C/2024/3014).
  • 2024-12-17: Formal proceedings against TikTok on election risks (Commission press release IP/24/6487).
  • 2025-02-13: Commission and European Board for Digital Services endorse the integration of the Code of Practice on Disinformation into the DSA framework as a Code of Conduct (Commission press release IP/25/505).
  • 2025-02-20: DSA elections toolkit published.
  • 2025-12-05: First DSA non-compliance decision (X, EUR 120 million).
  • 2026-01-26: Commission extends its investigation into X's recommender systems and opens proceedings concerning Grok.
  • 2026-07-16: Commission accepts X's action plan following the non-compliance decision.
  • 2026-08-31: The Commission designates ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms; the obligations under Arts. 34 and 35, including on risks to electoral processes and public security, apply four months after notification (European Commission).
  • 2026-09-25: The United States Department of Justice applies to intervene in support of X in its action before the General Court against the Commission's non-compliance decision of 5 December 2025; a Commission spokesperson stated that the Commission was “ready to defend our position in court” (AP).

Sources

Change log

  • 2026-09-27: Entry created (draft).
  • 2026-09-30: Entry reviewed and finalised.
  • 2026-10-01: Designations of 31 August 2026 and US application to intervene in the X litigation added.
law/eu/dsa.txt · Last modified: by lfpo