Implementation of the EU Digital Services Act begins

As of 17 February 2024, the Digital Services Act (DSA)[1] rules will apply to all providers of online platforms and other intermediary services which offer their services in the Union. Since the end of August 2023, these rules already apply to the so-called very large online platforms (VLOPs) or very large online search engines (VLOSEs), i.e. platforms with more than 45 million users in the EU (10% of the EU’s population). The European Commission will enforce the DSA together with national authorities, who will supervise the compliance of the platforms established in their territory.

This Regulation fully harmonises the rules applicable to intermediary services in the internal market, intending to ensure a safe, predictable and trusted online environment, as well as to address the dissemination of illegal content online and the societal risks that the dissemination of disinformation or other content may generate. In order to achieve these goals, the DSA establishes 

  • a framework for the conditional exemption from liability of providers of intermediary services, as well as
  • rules on specific due diligence obligations tailored to certain specific categories of providers of intermediary services.

SCOPE OF REGULATION

For the purpose of this Regulation the concept of ‘illegal content’ should broadly reflect the existing rules in the offline environment, and include information relating to illegal content, products, services and activities, i.e, information that under the applicable law is either itself illegal, such as illegal hate speech or terrorist content and unlawful discriminatory content, or that under the applicable rules are illegal because they relate to illegal activities. Illustrative examples include:

  • the sharing of images depicting child sexual abuse, the unlawful non-consensual sharing of private images, online stalking,
  • the sale of non-compliant or counterfeit products, the sale of products or the provision of services in infringement of consumer protection law,
  • the non-authorised use of copyright-protected material,
  • the illegal offer of accommodation services or the illegal sale of live animals.

This Regulation shall apply to intermediary services offered to recipients of the service that have their place of establishment or are located in the Union, irrespective of where the providers of those intermediary services have their place of establishment.

The term information society service is applied in the sense defined by Directive (EU) 2015/1535[2], and includes any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient. Specifically, this Regulation should apply to providers of intermediary services, and in particular intermediary services consisting of services known as ‘mere conduit’, ‘caching’ and ‘hosting’ services, given that the exponential growth of the use made of those services, mainly for legitimate and socially beneficial purposes of all kinds, has also increased their role in the intermediation and spread of unlawful or otherwise harmful information and activities. 

  • ‘Mere conduit’ services consist of the transmission in a communication network of information provided by a recipient of the service, or the provision of access to a communication network. For example, these intermediary services include generic categories, such as
    • internet exchange points, wireless access points,
    • messaging services and web-based email services, where the communication is delivered via an internet access service
    • virtual private networks,
    • wireless local area networks (WLAN)
    • domain name system (DNS) services and resolvers, top-level domain name registries, registrars,
    • certificate authorities that issue digital certificates,
    • voice over IP and
    • other interpersonal communication services.
  • ‘Caching’ services consist of the transmission in a communication network of information provided by a recipient of the service, involving the automatic, intermediate and temporary storage of that information, performed for the sole purpose of making more efficient the information’s onward transmission to other recipients upon their request. Such services are crucial to ensure the smooth and efficient transmission of information delivered on the internet. Generic examples of these intermediary services include
    • the sole provision of content delivery networks,
    • providing localization services or improving the functions of other switching service providers (reverse proxies or content adaptation proxies).        
  • ‘Hosting’ services consist of the storage of information provided by, and at the request of, a recipient of the service. Examples of these services include categories such as
    • cloud computing,
    • web hosting,
    • paid referencing services or
    • services enabling sharing information and content online, including file storage and sharingonline platforms.
    • ‘Online platforms’, such as
      • social networks or
      • online platforms allowing consumers to conclude distance contracts with traders.
    • Online platforms are defined as a hosting services that, at the request of a recipient of the service, store and disseminate (makes information available) information to the public (unless that activity is a minor and purely ancillary feature of another service or a minor functionality of the principal service and, for objective and technical reasons, cannot be used without that other service). For example, the comments section in an online newspaper could constitute such a feature, where it is clear that it is ancillary to the main service represented by the publication of news under the editorial responsibility of the publisher. In contrast, the storage of comments in a social network should be considered an online platform service where it is clear that it is not a minor feature of the service offered, even if it is ancillary to publishing the posts of recipients of the service. For the purposes of this Regulation, cloud computing or web-hosting services should not be considered to be an online platform where dissemination of specific information to the public constitutes a minor and ancillary feature or a minor functionality of such services. Moreover, cloud computing services and web-hosting services, when serving as infrastructure, such as the underlying infrastructural storage and computing services of an internet-based application, website or online platform, should not in themselves be considered as disseminating to the public information stored or processed at the request of a recipient of the application, website or online platform which they host.
    • DSA defines ‘online search engine’ also as an intermediary service that allows users to input queries in order to perform searches of, in principle, all websites, or all websites in a particular language, on the basis of a query on any subject in the form of a keyword, voice request, phrase or other input, and returns results in any format in which information related to the requested content can be found.

LIABILITY OF PROVIDERS OF INTERMEDIARY SERVICES

The rules on liability of providers of intermediary services set out in this Regulation should only establish when the provider of intermediary services concerned cannot be held liable in relation to illegal content provided by the recipients of the service. Those rules should not be understood to provide a positive basis for establishing when a provider can be held liable, which is for the applicable rules of Union or national law to determine. Furthermore, the exemptions from liability established in this Regulation should apply in respect of any type of liability as regards any type of illegal content, irrespective of the precise subject matter or n ature of those laws.

The conditional exemption from liability of providers of intermediary services

The provider of ‘mere conduit’ service shall not be liable for the information transmitted or accessed, on condition that the provider:

    • (a) does not initiate the transmission;
    • (b) does not select the receiver of the transmission; and
    • (c) does not select or modify the information contained in the transmission.

The provider of ‘caching’ service shall not be liable for the automatic, intermediate and temporary storage of the information transsmitted, performed for the sole purpose of making more efficient or more secure the information’s onward transmission to other recipients of the service upon their request, on condition that the provider:

    • a)  does not modify the information;
    • (b) complies with conditions on access to the information;
    • (c) complies with rules regarding the updating of the information, specified in a manner widely recognised and used by industry;
    • (d) does not interfere with the lawful use of technology, widely recognised and used by industry, to obtain data on the use of the information; and
    • (e) acts expeditiously to remove or to disable access to the information it has stored upon obtaining actual knowledge of the fact that the information at the initial source of the transmission has been removed from the network, or access to it has been disabled, or that a judicial or an administrative authority has ordered such removal or disablement.

The provider of ‘hosting’ service shall not be liable for the information stored at the request of a recipient of the service, on condition that the provider:

    • (a) does not have actual knowledge of illegal activity or illegal content and, as regards claims for damages, is not aware of facts or circumstances from which the illegal activity or illegal content is apparent; or
    • (b) upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to the illegal content.

These provisions do not affect the possibility for a judicial or administrative authority, in accordance with a Member State’s legal system, to require the service provider to terminate or prevent an infringement.

When the exemptions from liability do not apply?

  • Although online platforms fall under ‘hosting’ services, exemption from liability shall not apply with respect to the liability under consumer protection law of online platforms that allow consumers to conclude distance contracts with traders, where such an online platform presents the specific item of information or otherwise enables the specific transaction at issue in a way that would lead an average consumer to believe that the information, or the product or service that is the object of the transaction, is provided either by the online platform itself or by a recipient of the service who is acting under its authority or control.                                                    
  • The exemptions from liability established in this Regulation will not apply where, instead of confining itself to providing the services neutrally by a merely technical and automatic processing of the information provided by the recipient of the service, the provider of intermediary services plays an active role of such a kind as to give it knowledge of, or control over, that information.
  • Those exemptions will accordingly not be available in respect of liability relating to information provided not by the recipient of the service but by the provider of the intermediary service itself, including where the information has been developed under the editorial responsibility of that provider.
  • Where a provider of intermediary services deliberately collaborates with a recipient of the services in order to undertake illegal activities, the services should not be deemed to have been provided neutrally and the provider should therefore not be able to benefit from the exemptions from liability provided for in this Regulation. This should be the case, for instance, where the provider offers its service with the main purpose of facilitating illegal activities, for example by making explicit that its purpose is to facilitate illegal activities or that its services are suited for that purpose (the fact alone that a service offers encrypted transmissions or any other system that makes the identification of the user impossible should not in itself qualify as facilitating illegal activities).

Voluntary own-initiative investigations and legal compliance

Providers of intermediary services shall not be deemed ineligible for the prescribed exemptions from liability solely because they, in good faith and in a diligent manner, carry out voluntary own-initiative investigations into, or take other measures aimed at detecting, identifying and removing, or disabling access to, illegal content, or take the necessary measures to comply with the requirements of Union law and national law in compliance with Union law, including the requirements set out in this Regulation (Article 7).

No general monitoring or active fact-finding obligations                                                                                         

Providers of intermediary services don’t have a general obligation to monitor the information that they transmit or store, nor to seek actively facts or circumstances indicating illegal activity. This does not concern monitoring obligations in a specific case and, in particular, does not affect orders by national authorities in accordance with national legislation and Union law.

Orders to act against illegal content or to provide specific information

Depending on the legal system of each Member State and the field of law at issue, national judicial or administrative authorities, including law enforcement authorities, may order providers of intermediary services to act against one or more specific items of illegal content or to provide certain specific information. Upon the receipt of such order, providers of intermediary services are obliged to inform the authority issuing the order, or any other authority specified in the order, of any effect given to the order without undue delay, specifying if and when effect was given to the order.

DUE DILIGENCE OBLIGATIONS FOR A TRANSPARENT AND SAFE ONLINE ENVIRONMENT

In order to ensure a safe and transparent online environment, DSA establishes a  set of harmonised due diligence obligations for providers of intermediary services, which are adapted to the type, size and nature of the intermediary service concerned.

Obligations for all providers of intermediary services

All intermediary service providers are obliged to:

  • to designate a single point of contact to enable them to communicate directly, by electronic means, with Member States’ authorities, the Commission and the Board;
  • to designate a single point of contact to enable recipients of the service to communicate directly and rapidly with them, by electronic means and in a user-friendly manner;
  • to designate, in writing, a legal or natural person to act as their legal representative in one of the Member States where offer his services, if the provider does not have an establishment in the Union;
  • to include information on any restrictions that they impose in relation to the use of their service in respect of information provided by the recipients of the service, in their terms and conditions;
  • to make publicly available, in a machine-readable format and in an easily accessible manner, at least once a year, clear, easily comprehensible reports on any content moderation that they engaged in during the relevant period (transparency reporting obligation).

Additional obligations for providers of hosting services, including online platforms

Providers of hosting services play a particularly important role in tackling illegal content online, given that they store information provided by, and at the request of, a recipient of the service and typically give other recipients access to it, sometimes on a large scale. Therefore, additional obligations are prescribed for all hosting service providers, regardless of their size:

  • to put easily accessible and user-friendly notice and action mechanisms in place to allow any individual or entity to notify them of the presence on their service of specific items of information that the individual or entity considers to be illegal content, pursuant to which that provider can decide whether or not it agrees with that assessment and wishes to remove or disable access to that content;
  • provide a clear and specific statement of reasons to any affected recipients of the service for any of the restrictions imposed on the ground that the information provided by the recipient of the service is illegal content or incompatible with their terms and conditions;
  • to inform the law enforcement or judicial authorities of the Member State promptly, where he becomes aware of any information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person or persons has taken place, is taking place or is likely to take place. 

Additional obligations for providers of online platforms

  • Providers of online platforms shall provide recipients of the service, including individuals or entities that have submitted a notice, for a period of at least six months following the decision referred to in this paragraph, with access to an effective internal complaint-handling system that enables them to lodge complaints, electronically and free of charge, against the decision taken by the provider of the online platform upon the receipt of a notice or against the following decisions taken by the provider of the online platform on the grounds that the information provided by the recipients constitutes illegal content or is incompatible with its terms and conditions: decisions whether or not to remove or disable access to or restrict visibility of the information; decisions whether or not to suspend or terminate the provision of the service, in whole or in part, to the recipients; decisions whether or not to suspend or terminate the recipients’ account; decisions whether or not to suspend, terminate or otherwise restrict the ability to monetise information provided by the recipients.
  • Recipients of the service, including individuals or entities that have submitted notices, addressed by one of these stated decisions, shall be entitled to select any certified out-of-court dispute settlement body in order to resolve disputes relating to those decisions, including complaints that have not been resolved by means of the internal complaint-handling system. 
  • Providers of online platforms shall take the necessary technical and organisational measures to ensure that notices submitted by trusted flaggers, acting within their designated area of expertise, through the mechanisms referred to in DSA, are given priority and are processed and decided upon without undue delay. The status of ‘trusted flagger’ under this Regulation shall be awarded, upon application by any entity, by the Digital Services Coordinator of the Member State in which the applicant is established, to an applicant that has demonstrated that it meets all of the following conditions: (a) it has particular expertise and competence for the purposes of detecting, identifying and notifying illegal content; (b) it is independent from any provider of online platforms; (c) it carries out its activities for the purposes of submitting notices diligently, accurately and objectively                                 

Measures and protection against misuse

  • Providers of online platforms shall suspend, for a reasonable period of time and after having issued a prior warning,
    • the provision of their services to recipients of the service that frequently provide manifestly illegal content.
    • the processing of notices and complaints submitted through the notice and action mechanisms and internal complaints- handling systems respectively, by individuals or entities or by complainants that frequently submit notices or complaints that are manifestly unfounded.
  • Providers of online platforms have additional reporting obligations about the number of disputes submitted to the out-of-court dispute settlement bodies, the outcomes of the dispute settlement, as well as the number of suspensions imposed.
  • Providers of online platforms shall not design, organise or operate their online interfaces in a way that deceives or manipulates the recipients of their service or in a way that otherwise materially distorts or impairs the ability of the recipients of their service to make free and informed decisions.
  • Providers of online platforms that present advertisements on their online interfaces shall ensure that, for each specific advertisement presented to each individual recipient, the recipients of the service are able to identify, in a clear, concise and unambiguous manner and in real time: that the information is an advertisement, the natural or legal person on whose behalf the advertisement is presented; the natural or legal person who paid for the advertisement if that person is different, meaningful information directly and easily accessible from the advertisement about the main parameters used to determine the recipient to whom the advertisement is presented.
  • Providers of online platforms that use recommender systems shall set out in their terms and conditions, in plain and intelligible language, the main parameters used in their recommender systems, as well as any options for the recipients of the service to modify or influence those main parameters.
  • Providers of online platforms accessible to minors shall put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors, on their service.

Additional provisions applicable to providers of online platforms                                                                                              allowing consumers to conclude distance contracts with traders

Providers of online platforms allowing consumers to conclude distance contracts with traders:

  • shall ensure that traders can only use those online platforms to promote messages on or to offer products or services to consumers located in the Union if, before the use of their services for those purposes, they have obtained the relevant information related to the trader;
  • shall ensure that its online interface is designed and organised in a way that enables traders to comply with their obligations regarding pre-contractual information, compliance and product safety information under applicable Union law;
  • shall inform consumers, where become aware that an illegal product or service has been offered by a trader to consumers located in the Union, through their services.

Additional obligations for providers of very large online platforms and of very large online search engines                                    to manage systemic risks

The online platforms and online search engines that have a number of average monthly active recipients of the service in the Union equal to or higher than 45 million are designated as very large online platforms or very large online search engines. Providers of very large online platforms and of very large online search engines:

  • shall diligently identify, analyse and assess any systemic risks in the Union stemming from the design or functioning of their service and its related systems, including algorithmic systems, or from the use made of their services;
  • shall put in place reasonable, proportionate and effective mitigation measures, tailored to the identified specific systemic risks, with particular consideration to the impacts of such measures on fundamental rights;
  • shall be subject, at their own expense and at least once a year, to independent audits to assess compliance with the obligations set out in this Regulation, any commitments undertaken pursuant to the codes of conduct;
  • shall establish a compliance function, which is independent from their operational functions and composed of one or more compliance officers, including the head of the compliance function.

Where a crisis occurs, the Commission, acting upon a recommendation of the Board may adopt a decision, requiring one or more providers of very large online platforms or of very large online search engines to take one or more of the following actions:

  • assess whether, and if so to what extent and how, the functioning and use of their services significantly contribute to a serious threat or are likely to do so;
  • identify and apply specific, effective and proportionate measures, to prevent, eliminate or limit any such contribution to the identified serious threat;
  • report to the Commission by a certain date or at regular intervals specified in the decision, on the assessments, on the precise content, implementation and qualitative and quantitative impact of the specific measures taken and on any other issue related to those assessments or those measures, as specified in the decision.
[1] Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act); 
[2] Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015 laying down a procedure for the provision of information in the field of technical regulations and of rules on Information Society services (codification);