
Luxembourg’s DSA Law Gives Platform Oversight Enforcement Teeth
Luxembourg’s national DSA law turned the Competition Authority’s coordinating role into an enforceable procedure, with information requests, inspections and penalties for intermediary-service providers established in the country.
The EU Digital Services Act became generally applicable on 17 February 2024, and Luxembourg’s Competition Authority acted as national Digital Services Coordinator from that date. The national law defining its powers and procedures entered into force on 11 April 2025.
That gap explains why designation and enforcement authority should not be confused. In 2024 the Authority could receive complaints and coordinate, while the national procedural framework for exercising its full powers was still pending. The 2025 law supplied that machinery.
Establishment determines the national regulator
The DSA allocates supervision primarily according to where an intermediary-service provider is established, while the European Commission has special competence for very large online platforms and search engines. Luxembourg hosts a significant number of providers serving users far beyond its borders.
The Competition Authority reported responsibility for roughly 195 providers established in Luxembourg that fall within the DSA framework. Those businesses can include hosting providers, cloud and web-hosting services, online platforms, marketplaces and search services, depending on their functions.
Providers should document which legal entity offers the service, where central administration and decision-making occur, and which DSA category applies. A brand-level answer can obscure several services with different duties.
Notice-and-action needs a governed queue
Hosting services and online platforms need mechanisms through which users can notify potentially illegal content. The mechanism must be accessible and capable of supporting sufficiently precise and substantiated notices.
Compliance is not demonstrated by placing a “report” link on a page. The provider needs triage, jurisdictional analysis, reasoned action, communication and recordkeeping. Notices may contain personal data, illegal material or threats, so access and evidence handling need security controls.
Automation can prioritise or detect duplicates, but decisions should remain connected to the applicable law and service terms. The provider should measure both delay and quality. Removing everything quickly may interfere with expression and redress; leaving a credible notice in a queue may prolong harm.
Transparency must match the decision system
The DSA includes obligations concerning statements of reasons, transparency reporting, advertising and recommender systems, with additional duties for online platforms and larger services. Luxembourg’s Authority can investigate whether the provider’s operation matches what it tells users.
A statement of reasons should be generated from the actual moderation decision, not a generic after-the-fact template. The provider needs consistent categories for content, account and visibility actions. Those categories should feed user notices, internal quality review and regulatory reports.
Recommender transparency also depends on current product configuration. If ranking parameters change frequently, the legal description and user controls need a release trigger rather than an annual policy review.
Enforcement changes evidence readiness
Under the national law, the Competition Authority can request information, conduct inspections and impose sanctions. Fines can reach 6 percent of a provider’s worldwide annual turnover for relevant violations within the DSA framework.
An information request may span legal, operational and technical teams. Providers should maintain an evidence map showing where policies, design decisions, moderation records, trader verification, advertising information and risk controls are held. Retrieval should preserve context and chain of custody without producing unrelated personal data indiscriminately.
The Authority coordinates with other Luxembourg bodies, including the data-protection, audiovisual and product-safety authorities. A marketplace incident may therefore raise DSA, consumer, privacy and dangerous-product questions at once. Internal regulatory triage should mirror that possibility.
The readiness review
An intermediary provider established in Luxembourg should be able to show:
- service-by-service DSA classification and establishment analysis;
- functioning notice-and-action and complaint mechanisms;
- decision records linked to statements of reasons;
- controls for advertising, minors and recommender transparency where applicable;
- a current transparency-reporting data pipeline;
- ownership for requests and inspections; and
- a route for coordinating multi-regulator matters.
The Luxembourg law did not create the DSA’s substantive platform duties. It made their national supervision concrete. For providers, that changes DSA compliance from a policy exercise into inspection-ready operating evidence.
Official sources
- Luxembourg Competition Authority: national DSA law in force
- Luxembourg Competition Authority: role as Digital Services Coordinator
Continue the series
- Also in Luxembourg: Luxembourg’s Whistleblower Law Builds a Network of Reporting Authorities
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.


