Search
Contact
21.02.2024 | KPMG Law Insights

The Digital Services Act – new rules for online services

The Digital Service Act (DSA) will apply to all providers of intermediary services in Germany from February 17, 2024 and largely replaces the E-Commerce Directive. It is another milestone on the road to greater security in an increasingly networked and digitalized world. The DSA is part of the EU digital strategy and came into force on November 16, 2022.

The background: Digital services are developing rapidly and bring with them numerous challenges: illegal content that is sometimes difficult to combat, trade in illegal goods, unlawful influence on elections, hate speech and much more.

With the Digital Services Act, the EU is pursuing the goal of modernizing the regulation of online services, protecting users and ensuring fair competition.

However, this groundbreaking legislation also raises important questions: How will tiered regulation be implemented? What impact will the DSA have on companies, start-ups and legal practice?

The obligations for companies arising from the DSA depend on the respective classification of the provider

The Digital Services Act divides the central provisions into four successive regulatory levels. The classification is based on the type of activity of the company and its size. Depending on the regulatory level, the DSA provides for different requirements and obligations. Some basic rules apply to all types of providers of intermediary services. These include obligations to set up contact points, adapt general terms and conditions and transparency. Hosting service providers, including online platforms, must already take measures against illegal content and implement effective complaints procedures. Very large platforms are subject to additional obligations.

Obligations for providers of intermediary services (level 1)

A provider of intermediary services (level 1) is any company that offers information society services, such as pure transmission, caching or hosting. In principle, this covers any provider that provides electronic services on the Internet for a fee on the individual request of a recipient; the scope of application of the DSA is therefore very broad. Level 1 providers are subject in particular to new information and transparency obligations.

Obligations for hosting providers (level 2)

Hosting providers (Level 2), for example cloud computing services or web hosting services, must establish procedures for reporting and remedying infringements, including copyright or trademark infringements, in addition to Level 1 obligations in the future.

Obligations for online platforms (level 3)

In addition to the obligations of levels 1 and 2, online platforms (level 3) will in future be subject to bans on “dark patterns” and other manipulative practices to influence user behavior. For example, the design of the termination process must not make it more difficult to terminate a service than the process of signing up for that service. Furthermore, the Commission may in the future issue guidelines in dealing with identified “dark patterns.” Furthermore, additional measures must be taken to protect minors.

Obligations for VLOPs and VLOSEs (level 4)

By far the most intensive regulation in level 4 concerns the “Very Large Online Platform” (VLOP) and “Very Large Online Search Engines” (VLOSE). These are online platforms and online search engines with an average of more than 45 million users per month. The classification as VLOP or VLOSE is made by decision of the EU Commission. Currently, 17 online platforms are among the VLOPs and two search engines are among the VLOSEs. Among other things, these are subject to stricter transparency requirements. For example, personnel resources used for content moderation and the average monthly number of users must be published. In addition, increased requirements apply to risk and crisis management. In particular, providers will be required to conduct risk assessments regarding the dissemination of illegal content or, for example, adverse effects on social debate, electoral processes, or public safety before introducing new features. They are also obliged to undergo an independent audit once a year. Several companies recently filed a complaint against the classification as a VLOP.

Violations of the DSA can result in considerable fines

The national authorities in the EU Member States are responsible for enforcing the Digital Services Act. Greater cooperation and coordination between the Member States is being sought in order to effectively tackle cross-border challenges.

The DSA provides for sanctions and fines to punish violations of the provisions. It provides for fines of up to 6 percent of the worldwide annual turnover of the previous financial year (Art. 52 III DSA, Art. 74 I DSA) and periodic penalty payments of up to 5 percent of the worldwide daily average revenue or annual turnover (Art. 52 IV DSA, Art. 76 I DSA).

“Unlawful content”: Protecting brands in the digital age

The term “illegal content” is defined in Art. 3 (h) DSA as all information that does not comply with Union law or the national law of a Member State. In addition to hate speech and disinformation, this also includes the offer and sale of products that violate applicable law, for example trademark law.

Through the broad definition of illegal content, the DSA also strengthens the protection of brands and counterfeit products. This is because the offer and sale of counterfeits that infringe trademarks and content that advertises counterfeit products constitutes illegal content within the meaning of the DSA. Platforms must take measures to prevent the trade in counterfeit goods from the outset.

In concrete terms, this means that online marketplaces must identify their merchants, in particular request and verify their name, address, telephone number and email address. This data must be made available to users. If the information is incorrect or incomplete, online marketplaces must block traders from their services.

In addition, a new whistleblower system will be introduced under the DSA. Trusted whistleblowers are to take action against counterfeit goods, which should speed up and simplify the reporting and removal of counterfeit goods.

The introduction of the DSA thus represents a further instrument for the protection of intellectual property in the digital space, particularly in the area of trademark protection and counterfeiting.

Challenges and opportunities of the Digital Services Act

The DSA not only represents a regulatory change, but also offers opportunities and challenges that will shape the digital landscape in the coming years.

Overall, the Digital Services Act marks an important step in the effort to make the online world safer and fairer. Companies should therefore rethink their strategies and ensure that they meet the new requirements of the DSA.

The definition of “illegal content” can be challenging due to international differences in laws and the complexity of automated detection. Nevertheless, the DSA offers the opportunity to create a common framework and hold platforms accountable in order to strengthen the protection of trademarks and other intellectual property, among other things.

 

Explore #more

18.09.2026 | KPMG Law Insights

How the Data Act Affects the Drafting of Lease Agreements

The EU Data Act is also of great significance to the real estate industry, as modern commercial properties have become data spaces. Heating and air…

15.09.2026 | KPMG Law Insights

Reporting Deadlines for Cyber Incidents Under the GDPR, BSIG, and CRA—Every Hour Counts

After a cyber incident, companies have only 24 or 72 hours to file their initial report with the authorities. A single incident can trigger multiple…

11.09.2026 | KPMG Law Insights

The Procurement Acceleration Act and Sustainable Procurement: What Is Permitted and What Is Required?

The Public Procurement Acceleration Act took effect on July 1, 2026. The Act implements the reform of public procurement law that has been under discussion…

08.09.2026 | Deal Notifications

KPMG Law advises the shareholders and management of KODIAK on the sale of shares and the strategic partnership with Bencis

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) advised the shareholders and management of KODIAK GmbH (KODIAK) on the sale of shares to Bencis and the establishment…

07.09.2026 | In the media

KPMG Law advises Bosch Rexroth on the sale of its Active Shuttle product business to Neura Robotics

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) has provided legal counsel to Bosch Rexroth AG (Bosch Rexroth) in the sale of its product business related to…

31.08.2026 | In the media

Op-Ed in the Börsen-Zeitung – Interim Assessment of the European Crypto Regulation MiCAR

A year and a half after MiCAR took effect, it is clear that, despite European guidelines, there are still misunderstandings regarding the requirements. KPMG Law…

19.08.2026 | In the media

KPMG Law Interview in HAUFE: Even If AI Makes a Mistake, the Board of Directors Is Still Liable

AI analyzes, makes recommendations, and helps make decisions. But who bears the consequences if it makes a mistake? KPMG Law experts Vincent Manthey and Sabrina

19.08.2026 | In the media

KPMG Law Article in Bloomberg Tax: Germany’s Tax Crime Action Plan Pushes the Boundaries of the Constitution

The new 26-point action plan against tax and financial crime, issued by Germany’s finance and justice ministries, signals a shift toward tougher sanctions, closer interagency…

13.08.2026 | KPMG Law Insights

Federal Ministry of Finance Presents Draft Bill on Mandatory Use of Electronic Cash Registers and Combating Tax Evasion

In July 2026, the Federal Ministry of Finance (BMF) and the Federal Ministry of Justice (BMJV) presented an action plan to combat tax and financial

11.08.2026 | In the media

Guest article in *Versicherungsmonitor* on the topic of cyber claims regulation

Cyberattacks—particularly ransomware campaigns—pose challenges for insurers when it comes to claims settlement. When entire IT infrastructures at insured companies come to a standstill and the…

Contact

Francois Heynike, LL.M. (Stellenbosch)

Partner
Head of Technology Law

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49-69-951195770
fheynike@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll