BRUSSELS, July 20 — The shift is unmistakable. Europe’s Digital Services Act, the sweeping regulatory framework that entered into force back in 2022, is no longer a promise on paper; it’s the operating system for how digital platforms now answer for what they host. The DSA updates the old Electronic Commerce Directive 2000, and the trend underneath is clear: Brussels is turning the screws on algorithmic accountability, and the rest of the world is watching.
The law applies to every digital intermediary service offering services to users based in the European Union—no matter where the company itself is headquartered. That means hosting services, online platforms from social networks to marketplaces to app stores, and search engines all fall under its umbrella.
But not equally. The DSA builds a tiered regulatory ladder: basic obligations for everyone, enhanced duties for online platforms, and the most stringent requirements reserved for Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) that cross 45 million monthly active users in the EU.
A Tiered System of Accountability
The architecture matters. The DSA is organised in five chapters, with the heaviest regulatory weight falling on Chapter 2 (liability exemption of intermediaries), Chapter 3 (obligations on intermediaries), and Chapter 4 (cooperation and enforcement between the European Commission and national authorities). Under the liability rules, companies that host others’ data become liable once they are informed that the data is illegal—a “conditional liability exemption” that European lawmakers deliberately kept distinct from the broad immunities under Section 230 of the U.S. Communications Decency Act.
What’s changing in practice? Platforms must now disclose to regulators how their algorithms work.
They have to create transparency around content removal decisions and around advertiser targeting. The European Commission has set up a dedicated DSA Transparency Database where platforms file explanations for each moderation decision. And to backstop enforcement on the algorithmic side, Brussels created the European Centre for Algorithmic Transparency.
What’s Changing for Researchers and National Laws
One of the most closely watched provisions is Article 40, which requires platforms to grant data access to researchers and non-profit organisations so they can detect, identify, and understand systemic risks inside the EU. The delegated act specifying exactly how that data access works came into force on 29 October 2025—meaning researchers can now formally apply. Implementation is being monitored by the Data Access Collaboratory, a joint project run out of the European New School of Digital Studies at the European University Viadrina and the Weizenbaum Institute in Germany.
The DSA didn’t emerge in a vacuum. Its expressed purpose was to harmonise the patchwork of national laws that had cropped up across member states—most prominently Germany’s NetzDG, Austria’s Kommunikationsplattformen-Gesetz, and France’s Loi Avia.
With the DSA adopted at the European level, those national laws were planned to be overridden and will need to be amended. Watch this space. Enforcement is only now shifting from legislative design to operational reality, and the first battles over data access and algorithmic transparency are just getting started.


























