LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:eu:dsa

This is an old revision of the document!


Regulation (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act)

Draft – editorial review pending. As of 27 September 2026.

Type EU regulation
Adopted by European Parliament and Council of the European Union
Adopted 19 October 2022
Legal status In force since 16 November 2022; applicable in general since 17 February 2024 (obligations for very large online platforms and search engines apply earlier, four months after designation); binding and directly applicable in all EU Member States
Official text EUR-Lex
Matrix position pragmatic · State–EU

Overview

The Digital Services Act (DSA) sets harmonised rules on the obligations of intermediary services in the EU internal market, including liability exemptions, notice-and-action procedures and transparency duties. Articles 34 to 36 impose additional obligations on providers designated as very large online platforms (VLOPs) and very large online search engines (VLOSEs): they must assess and mitigate systemic risks, and the Commission may require specific measures in a crisis. The European Commission is the competent enforcer for these obligations. The provisions on systemic risks to “civic discourse and electoral processes” are referred to in debates on disinformation, foreign information manipulation and interference, and the integrity of elections.

Provisions relevant to the cyber and information sphere

  • Art. 34 – VLOPs and VLOSEs must at least once a year identify and assess systemic risks stemming from their services, including the dissemination of illegal content, negative effects on fundamental rights, and (Art. 34(1)©) “any actual or foreseeable negative effects on civic discourse and electoral processes, and public security”. Art. 34(2) requires them to consider, among other factors, recommender and advertising systems and intentional manipulation of the service, including inauthentic use or automated exploitation.
  • Art. 35 – Providers must put in place reasonable, proportionate and effective mitigation measures tailored to the identified risks (e.g. adapting design, content moderation, recommender or advertising systems, and marking of generated or manipulated content). Under Art. 35(3) the Commission may issue guidelines on specific risks.
  • Art. 36 – Crisis response mechanism: on a recommendation of the European Board for Digital Services, the Commission may by decision require VLOPs/VLOSEs to assess and take measures regarding their contribution to a serious threat. A crisis is deemed to occur where “extraordinary circumstances lead to a serious threat to public security or public health in the Union or in significant parts of it” (Art. 36(2)).
  • Art. 48 – Crisis protocols that the Commission may encourage and facilitate for extraordinary circumstances affecting public security or public health.
  • Arts. 66 et seq., 73, 74 – Commission proceedings, non-compliance decisions and fines of up to 6 % of annual worldwide turnover.

Application to cyber and information operations

The Commission issued “Guidelines for providers of Very Large Online Platforms and Very Large Online Search Engines on the mitigation of systemic risks for electoral processes pursuant to Article 35(3)” (published in the Official Journal on 26 April 2024, C/2024/3014). They recommend, among other measures, election-specific risk mitigation, labelling of political advertising and of AI-generated content, and cooperation with authorities and researchers, including in relation to foreign information manipulation and interference. On 20 February 2025 the Commission published a best-practice elections toolkit for national Digital Services Coordinators.

Formal proceedings with an election or civic-discourse dimension (outcome as of the date above is stated only where an official decision is known):

  • X – proceedings opened on 18 December 2023 (including risk management and information manipulation). On 5 December 2025 the Commission adopted its first DSA non-compliance decision, fining X EUR 120 million for breaches concerning the design of the “blue checkmark”, the advertising repository and researcher data access. According to the Commission, other parts of the proceedings remain under investigation [to be verified: current status of the risk-management strand].
  • Meta (Facebook, Instagram) – proceedings opened on 30 April 2024 concerning deceptive advertising and disinformation, the visibility of political content, and the discontinuation of the CrowdTangle tool without an equivalent real-time civic-discourse and election-monitoring tool. No final decision on the election-related strand has been identified [to be verified].
  • TikTok – proceedings opened on 17 December 2024 under Arts. 34(1), 34(2) and 35(1), following the Romanian presidential election of 24 November 2024; they concern recommender systems (including coordinated inauthentic manipulation) and political advertising and paid political content. No final decision has been identified [to be verified].

Recent developments

  • 2024-04-26: Election guidelines under Art. 35(3) published in the Official Journal (C/2024/3014).
  • 2024-12-17: Formal proceedings against TikTok on election risks (Commission press release IP/24/6487).
  • 2025-02-13: Commission and European Board for Digital Services endorse the integration of the Code of Practice on Disinformation into the DSA framework as a Code of Conduct (Commission press release IP/25/505).
  • 2025-02-20: DSA elections toolkit published.
  • 2025-12-05: First DSA non-compliance decision (X, EUR 120 million).

Sources

Change log

  • 2026-09-27: Entry created (draft).
law/eu/dsa.1790533203.txt.gz · Last modified: by lfpo