The Digital Services Act Is an Incident-Response Framework for Platforms
The Digital Services Act is usually described as content law. For the teams running platforms, it is also a system of detection, evidence, decisions, appeals and regulatory reporting.
The Digital Services Act became generally applicable on 17 February 2024. It regulates providers of intermediary services operating in the European Union, with obligations that increase according to the service’s role, size and systemic impact.
The public debate focuses on harmful content and the largest social networks. The engineering challenge is broader. Compliance depends on operational workflows that can receive a notice, classify it, make a decision, explain the outcome, preserve evidence and support review.
Not every service has the same duties
The DSA distinguishes between intermediary services, hosting services, online platforms and very large online platforms or search engines. An infrastructure provider that merely transmits or caches information is not treated the same way as a marketplace or social network.
That makes scoping the first control. Organisations need a service-level inventory showing what each service does, where recipients are located and which DSA category applies. Corporate size and designation as a very large service can change the obligation set.
Applying the strictest possible control everywhere may sound safe, but it can create unnecessary collection and moderation. Applying the lightest category to a platform because the parent company sees itself as “infrastructure” is equally dangerous.
Notice and action is a production workflow
Hosting providers must offer mechanisms through which people can notify them of allegedly illegal content. The mechanism needs enough information for the provider to identify and assess the material. Platforms must make decisions diligently and communicate relevant outcomes.
Content restrictions also require a statement of reasons. For online platforms, these statements feed the Commission’s DSA Transparency Database without personal data.
This is not a mailbox operated by a legal team. It is a queue with security characteristics:
- reports may contain malicious links or files;
- false or coordinated reports may be used to silence lawful users;
- decisions must be consistent across languages and jurisdictions;
- personal data must be separated from public transparency records;
- appeal outcomes must reconnect to the original decision and evidence.
The workflow needs authentication, abuse prevention, access control, tamper-evident logs and clear retention rules.
Automation needs oversight
Platforms use automated tools to rank, detect and moderate content. The DSA does not prohibit automation, but it increases transparency and accountability around its use. Providers need to know which model or rule contributed to a decision, what the confidence was, which human review occurred and how errors are corrected.
The operational question is not whether a model is “AI”. It is whether the organisation can reconstruct why access to content, an account or a service was restricted.
Larger platforms carry systemic duties
Designated very large online platforms and search engines must assess systemic risks and implement proportionate mitigation. Relevant risks include dissemination of illegal content, effects on fundamental rights, public security, elections, gender-based violence, minors and physical or mental wellbeing.
These services also face independent audits, enhanced transparency and crisis-response obligations. Risk assessment therefore needs data from product, security, trust and safety, advertising, recommendation systems and complaints—not an annual narrative created after the fact.
A practical DSA operating model
Providers should be able to demonstrate:
- A current classification of every EU-facing service.
- Accessible notice, complaint and appeal routes.
- Decision records linked to the applicable terms and legal basis.
- Separation of personal information from transparency submissions.
- Governance for automated moderation and recommendation systems.
- Regular measurement of errors, reversals, abuse and response times.
- Escalation routes for urgent illegality, systemic risk and regulator requests.
- Supplier controls where moderation or support is outsourced.
The lesson for technical teams
The DSA turns platform governance into observable system behaviour. A policy can promise fair moderation, but the evidence lives in the queues, interfaces, models, logs and appeal outcomes.
The strongest compliance programme is therefore not built around removing more content. It is built around making lawful, proportionate and reviewable decisions—and being able to prove how those decisions were made.
Official sources
This article provides general information and is not legal advice.
Continue the series: European National Cyber & Digital Law Series index



