Introduction
Adopted in 2022 and fully effective as of February 17, 2024, the Digital Services Act (DSA) established a harmonized European framework aimed at increasing the accountability of digital intermediaries, better regulating the dissemination of illegal content, products and services, and strengthening the protection of users online.
In 2026, its implementation will enter a particularly practical phase: following an initial period focused on compliance, European authorities are now stepping up their oversight and expect operators to demonstrate the actual effectiveness of the measures they have put in place.
Evolution of the Digital Services Act
Following the widespread implementation of the DSA in February 2024, European authorities have gradually stepped up their effective compliance with the obligations imposed on digital platforms and intermediaries. The challenge for companies is no longer merely to have formally implemented the measures required by the regulation, but to be able to demonstrate that they are effectively implemented, that they enable the identification and mitigation of the risks addressed by the DSA, and that they produce, in practice, the expected compliance results
This shift is reflected in particular by several proceedings and measures adopted by the European Commission against major digital platforms.
In July 2026, the European Commission fined AliExpress 550 million euros for failures in assessing and mitigating risks associated with the sale of illegal, dangerous, or counterfeit products. It also issued preliminary objections to TikTok regarding the default security settings for minors’ accounts and accepted an action plan from X focusing, in particular, on its advertising registry and researchers’ access to data.
The message to operators is clear: automation, the scale of the service, and technical complexity do not exempt companies from identifying risks or demonstrating the effectiveness of corrective measures. The DSA thus becomes a governance issue shared by the legal, compliance, product, IT, and intellectual property departments.
Which companies fall within the scope of the Digital Services Act?
Classification must be carried out service by service
The DSA provides for several levels of classification depending on the nature and role of the digital service in question. In particular, it distinguishes between simple transport, caching, and hosting services. Among hosting services, some may also be classified as online platforms and, when they enable businesses to enter into distance contracts with consumers, as online marketplaces.
The applicable obligations increase progressively depending on the classification chosen. Additional requirements also apply to very large online platforms and very large search engines, VLOPs and VLOSEs, with at least 45 million average monthly active users in the Union.
A single digital product may offer multiple features that fall under different classifications. A SaaS application, for example, may include a private hosting space, a public forum, and a marketplace offering modules developed by third parties. Each feature must therefore be examined separately to precisely identify the applicable obligations.
Non-EU providers may be directly subject to the DSA
The absence of an EU subsidiary does not exclude the Regulation. The DSA applies where a provider offers services to recipients in the Union and maintains a substantial connection with the EU market.
Relevant indicators may include the language used, euro pricing, payment methods, targeted advertising, the size of the European customer base, delivery arrangements and availability through localised app stores. Mere technical accessibility from the EU is not sufficient.
A covered provider with no EU establishment must appoint a DSA legal representative in a Member State where it offers services. This mandate remains legally distinct from the representative required under Article 27 GDPR, even where both roles are entrusted to the same service provider.
In France, Arcom acts as the Digital Services coordinator for Internet services. It operates alongside the DGCCRF and the CNIL under the French Law of May 21, 2024 on securing and regulating the digital environment.
Which DSA obligations must become operational controls?
Notice, action and redress
Article 16 requires hosting providers to operate accessible and sufficiently precise notice-and-action mechanisms. A properly substantiated notice may give the provider actual knowledge of the alleged illegality.
The provider must then assess the report diligently, document its reasoning and explain any restriction imposed. Online platforms must also provide an internal complaints-handling system and inform users about available out-of-court dispute-settlement procedures.
For intellectual property claims, the reporting form should identify:
- the intellectual property right concerned;
- the rights holder or authorised representative;
- the exact URL of the disputed content or listing;
- the evidence supporting the alleged infringement;
- the reporting party’s good-faith statement.
Fully automated removal may disregard licences, exceptions or territorial limitations. Conversely, failure to act on a properly substantiated notice may undermine the hosting provider’s conditional liability protection.
Transparency, advertising and recommender systems
Terms and conditions must clearly explain content restrictions, automated moderation tools and the role of human review.
Platforms must also:
- identify advertisements and the relevant advertiser;
- disclose the main advertising-targeting parameters;
- explain the principal parameters of recommender systems;
- submit statements of reasons to the EU transparency database.
Harmonised transparency-reporting templates have been mandatory since the second half of 2025. The Arcom professional guidance on the DSA explains the reporting and registration framework applicable in France.
VLOPs and VLOSEs must also perform systemic-risk assessments, implement mitigation measures, undergo independent audits and maintain advertising repositories. Since 29 October 2025, the EU data-access framework has allowed vetted researchers to request access to certain internal platform data relevant to systemic risks.
Safety and privacy for minors by default
Article 28 requires platforms accessible to minors to ensure a high level of privacy, safety and security. The Commission’s July 2025 guidelines clarify expectations concerning age assurance, protective default settings, recommender systems, unwanted contact, addictive design and harmful commercial practices.
A contractual age restriction of thirteen or sixteen is not sufficient where no credible mechanism makes it effective. Regulators may consider the actual audience, the information available to the provider, the content offered and the effectiveness of age-assurance measures.
How should companies build a defensible DSA roadmap?
It is recommended for companies to:
- map every functionality and third-party content flow concerned by the DSA;
- determine whether the service falls within the territorial scope of the DSA and document the number of active users in the European Union
- test notices, response times, statements of reasons and appeals;
- audit traders and controls addressing counterfeit or unsafe products;
- Incorporate requirements related to minors, advertising, and recommendation systems from the very beginning of service design
retain decision logs, metrics and evidence required by regulators.
Conclusion
The update of the EU Digital Services Act in 2026 confirms that compliance is now measured through system quality, decision traceability and the practical effectiveness of safeguards. Platforms, marketplaces, hosting providers and community services should treat the DSA as a continuous programme coordinated with the GDPR, consumer law and intellectual property enforcement.
Dreyfus Law Firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.
Nathalie Dreyfus, with the support of the entire Dreyfus team
Q&A
Does the DSA apply to companies outside the European Union?
Yes. It may apply where they offer services to recipients in the Union and maintain a substantial connection with the EU market. A provider with no EU establishment must generally appoint an EU legal representative.
Do all online businesses have the same DSA obligations?
No. Duties depend on the service category, functionality, size and whether the service facilitates transactions between professional traders and consumers.
Must a platform remove every reported item immediately?
No. A sufficiently precise notice must be assessed promptly, objectively and proportionately. The DSA does not require automatic removal merely because content has been challenged.
What are the maximum DSA penalties?
An infringement may lead to a fine of up to 6% of annual worldwide turnover. Separate fines and periodic penalty payments may apply to inaccurate information or failure to comply with a regulatory decision.
Does the DSA replace the GDPR?
No. The two regulations apply cumulatively. The GDPR governs personal-data processing, while the DSA regulates intermediary services, content moderation, advertising, recommender systems and certain systemic risks.
How does the DSA support anti-counterfeiting enforcement?
It strengthens notice mechanisms, requires the traceability of professional traders on marketplaces and obliges the largest platforms to assess and mitigate risks involving illegal or counterfeit products.
This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

