Search
Contact
21.02.2024 | KPMG Law Insights, KPMG Law Insights

The Digital Services Act – what does it mean for companies?

The Digital Services Act (DSA) is a key component of the EU’s digital strategy and came into force on November 16, 2022. As a regulation, the DSA applies directly without the need for transposition into national law. Providers of intermediary services still have time until February 17, 2024, to implement the requirements. Online platforms within the scope of the DSA had to publish their end-user figures and report them to the EU Commission. On this basis, it is being examined whether the platforms and search engines should be classified as “Very Large Online Platform” (“VLOP”) or “Very Large Online Search Engines” (“VLOSE”). The Commission published the first results on April 25, 2023. Some providers affected by this have now filed a lawsuit against their classification as a VLOP. But what exactly does the Digital Services Act actually regulate?

What is the Digital Services Act about?

The DSA is intended to ensure greater legal certainty and transparency in the digital markets. The regulation also aims to strengthen consumers’ rights and combat illegal content on digital services. Therefore, the regulation also provides for additional liabilities. Ultimately, the Commission wants the Digital Services Act to promote competition and innovation.

The scope of the Digital Services Act

The regulation applies to digital service providers that offer goods, services or content to consumers. This covers all online intermediaries and platforms, such as online marketplaces, social networks, content sharing platforms, app stores and search engines, that offer their services in the EU – regardless of where they are based.

These are the obligations that suppliers face

The obligations of online companies vary depending on their role, size and impact in the online environment. The regulation classifies providers into four tiers of increasing regulatory intensity. A distinction is made between pure intermediary services (Level 1), hosting providers (Level 2), online platforms (Level 3) and VLOPs/VLOSEs (Level 4).

An intermediary service provider (Level 1) is any company that provides information society services, such as caching or hosting. In principle, any provider who mediates services on the Internet in return for payment is covered; the scope of application of the DSA is thus very broad. Level 1 providers are subject in particular to new information and transparency obligations. However, the most important point at this stage is the liability relief for intermediary services. They are liable for illegal content only if they had actual knowledge of the illegality.

Hosting providers (Level 2), for example cloud computing services or web hosting services, must establish procedures for reporting and remedying infringements, including copyright or trademark infringements, in addition to Level 1 obligations in the future.

In addition to the obligations of levels 1 and 2, online platforms (level 3) will in future be subject to bans on “dark patterns” and other manipulative practices to influence user behavior. For example, the design of the termination process must not make it more difficult to terminate a service than the process of signing up for that service. Furthermore, the Commission may in the future issue guidelines in dealing with identified “dark patterns.” Furthermore, additional measures must be taken to protect minors.

By far the most intensive regulation concerns VLOPs and VLOSEs (Level 4). These are online platforms and online search engines with an average of more than 45 million users per month. The classification as VLOP or VLOSE is made by decision of the EU Commission. Currently, 17 online platforms are among the VLOPs and two search engines are considered VLOSEs. Among other things, these are subject to stricter transparency requirements. For example, personnel resources used for content moderation must be provided and the average monthly number of users must be published. In addition, increased requirements apply to risk and crisis management. In particular, providers will be required to conduct risk assessments regarding the dissemination of illegal content or, for example, adverse effects on social debate, electoral processes, or public safety before introducing new features. They are also required to undergo an independent audit once a year.

The implementation effort of all regulations of the DSA is immense and poses enormous financial and organizational challenges for the parties concerned.

Violations are subject to enormous fines

Companies that violate the DSA regulations face high fines and penalty payments: These can amount to up to 5 percent of the daily average revenue. Fines are capped at up to 6 percent of total global annual turnover.

Action against classification as a very large online platform

Companies can bring an action against the classification as a Very Large Online Platform or Very Large Search Engine before the Court of Justice of the European Union (EGC). Several online platforms have already made use of this. One of the largest international online retailers justified its action before the EGC on the grounds that it was not the largest retailer in any EU country. If it were still classified as a VLOP, this would put it at a disadvantage compared to national online retailers. Another online retailer justified its complaint against classification as a VLOP by claiming that the EU Commission had misinterpreted its user figures. The relevant number of users would not exceed the threshold of 45 million.

Whether the EU will succeed in banning illegal content from online services remains to be seen. In any case, the resistance of the online giants makes it clear that the implementation of the DSA will not be easy. The changes required are far-reaching and in part likely to significantly impact existing business practices in the online space. For VLOPs and VLOSEs in particular, the Digital Markets Act (DMA) can additionally play a major role, which also imposes numerous additional obligations on large online platforms.

In view of the high fines that could be imposed from February 17, 2024, companies should check as soon as possible whether they fall within the scope of the DSA. If so, they should ensure that they meet the new compliance regulations.

Explore #more

12.11.2025 | In the media

KPMG Law Statement in In-house Counsel: More stability under the umbrella of corporate governance

There is a lot of talk about “corporate governance” in the face of multiple crises and regulatory tendencies on the part of legislators. But what…

07.11.2025 | Deal Notifications

KPMG Law and KPMG advise Diehl Defence on the acquisition of the Tauber Group

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised Diehl Defence on the acquisition of the Tauber Group. KPMG Law provided legal…

07.11.2025 | KPMG Law Insights

Changes to the H-1B visa and their consequences for US hiring and secondment practices

President Trump’s administration has introduced two significant changes to the highly popular H-1B visa program for skilled workers: The previous random lottery will be replaced…

07.11.2025 | In the media

KPMG Law Statement on HAUFE: Confusion surrounding the EU Deforestation Regulation – and what companies should do now

Possibly, perhaps, under certain circumstances, the EU Deforestation Regulation (EUDR) will not be binding for large and medium-sized enterprises on December 30, 2025 and for…

06.11.2025 | KPMG Law Insights

External personnel: authorities tighten checks with AI support

AI is a blessing for many companies, but it can also quickly become a curse, especially when authorities use the technology to uncover legal violations…

06.11.2025 | KPMG Law Insights

Deforestation regulation – simplification instead of postponement?

In September, the EU Commission wanted to postpone the EUDR deforestation regulation. On October 21, 2025, it published a comprehensive proposal to simplify the EUDR

05.11.2025 | KPMG Law Insights

Employer of Record now not subject to authorization after all – change of heart at BA

On October 1, 2025, the Federal Employment Agency (BA) updated its technical directives and made a U-turn with regard to the so-called employer-of-record model: In…

03.11.2025 | KPMG Law Insights

CO₂ contracts for difference: Participation in the preliminary procedure is a prerequisite for funding

Companies can apply for funding in the preliminary procedure for the climate protection contracts program until 1 December 2025. The funding from the Federal Ministry…

29.10.2025 | KPMG Law Insights

Fund Risk Limitation Act and Location Promotion Act create new scope for infrastructure funds

As the federal government’s special infrastructure fund of 500 billion euros will probably not be enough to finance Germany’s roads, networks and the energy transition,…

29.10.2025 | Deal Notifications

KPMG Law advises management board of Nürnberger Beteiligungs-AG on sale to Vienna Insurance Group

KPMG Law Rechtsanwaltsgesellschaft (KPMG Law) provided legal advice to the Management Board of Nürnberger Beteiligungs-AG throughout the entire public takeover process by Vienna Insurance Group…

Contact

Francois Heynike, LL.M. (Stellenbosch)

Partner
Head of Technology Law

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49-69-951195770
fheynike@kpmg-law.com

Dr. Anna-Kristine Wipper

Partner
Head of Technology Law

Heidestraße 58
10557 Berlin

Tel.: +49 30 530199731
awipper@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll