EU Regulatory Domain
Regulations (EU) 2022/2065 (DSA) and 2022/1925 (DMA): accountable online intermediaries and contestable digital markets.
Key facts
The DSA has applied to all providers of intermediary services since 17 February 2024, with duties layered by type and size.
Infringements of the DSA can lead to fines of up to 6% of worldwide annual turnover.
Designated gatekeepers face conduct rules and fines of up to 10% of worldwide turnover, or 20% for repeated infringements.
Very large platforms (DSA Article 41) and gatekeepers (DMA Article 28) must establish an independent compliance function.
The Digital Services Act (DSA) and the Digital Markets Act (DMA) form the EU rulebook for the online environment. The DSA makes online intermediaries accountable for how they handle illegal content and systemic risks. The DMA keeps digital markets contestable by imposing conduct rules on the largest platforms, designated as gatekeepers. Both regulations are directly applicable.
The DSA has applied to all providers of intermediary services since 17 February 2024. Its obligations are layered according to the type and size of the service:
all intermediaries: points of contact, a legal representative for non-EU providers, clear terms and conditions and transparency reporting;
hosting services: notice-and-action mechanisms and a statement of reasons for content-moderation decisions;
online platforms: internal complaint handling, out-of-court dispute settlement, trusted flaggers, a ban on dark patterns, advertising transparency and protection of minors, with exemptions for micro and small enterprises;
online marketplaces: traceability of traders;
very large online platforms and search engines: systemic-risk assessments, independent audits, data access for researchers and an independent compliance function (Article 41).
Fines reach 6% of worldwide annual turnover. National Digital Services Coordinators supervise most providers, ANACOM being the coordinator in Portugal, while the Commission supervises the very large platforms and search engines.
The DMA applies to gatekeepers designated by the Commission for core platform services. Gatekeepers must comply with specific obligations and prohibitions, for example on self-preferencing, interoperability, data combination and access for business users. They must also establish an independent compliance function (Article 28). The Commission enforces the DMA exclusively, with fines of up to 10% of worldwide turnover, or 20% for repeated infringements.
Businesses that sell through marketplaces, advertise online or depend on app stores and platforms are directly affected by these rules. Understanding them helps protect their rights as business users and plan their compliance obligations as traders.
Compliance Assessment: classification of the service and a review of DSA obligations;
Implementation Kits: terms and conditions, notice-and-action and transparency-report templates;
Alerts & Repository: monitoring of designations, guidelines and decisions;
Training & Capacity: training for product, legal and trust-and-safety teams.
Related domains: Artificial Intelligence · Data Protection · Cybersecurity (NIS2) · Corporate Governance
Official texts: Regulation (EU) 2022/2065 · Regulation (EU) 2022/1925
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Request a free classification of your service and review of its DSA obligations.