Document type: Guide Practice area: Technology — Platform Regulation Jurisdiction: European Union, with United States comparison Last reviewed: 5 September 2026


Who this is for

The person at an American technology company who has just worked out that the European platform regulations apply, and now has to do something about it — usually a general counsel, sometimes a head of trust and safety, occasionally a product leader who read something alarming.

Our example is Windrose Collective, a 310-person company in Minneapolis running a marketplace and community for independent craft producers. It has user listings, user reviews, direct messaging, a forum, and an advertising product. About 22% of its users are in the European Union. Its general counsel is Beatriz Okwuosa-Lindgren; its head of trust and safety is Tomasz Beaulieu-Adeyemi.

Nine months, five workstreams. Here they are in order.


Step 1 — Determine your tier, and write it down

Everything downstream depends on this, and it takes an afternoon.

Are you an intermediary service? Mere conduit, caching, or hosting. If you transmit, cache, or store information provided by users, yes.

Are you a hosting service? Do you store information provided by a recipient of the service? A comments field, a review section, a file upload, a profile bio, a support forum. This catches companies that do not think of themselves as platforms at all.

Are you an online platform? Do you, at a user's request, store and disseminate information to the public? Marketplaces, social networks, review sites, forums, app stores.

Are you a marketplace? Do you allow consumers to conclude distance contracts with traders?

Are you small or micro? Small and micro enterprises are exempt from the online platform obligations. This is a genuine and substantial carve-out. Check it, and diarize a recheck, because companies that grow past the threshold and never look again are the ones that get caught.

Are you very large? At least 45 million average monthly active recipients in the Union, and formally designated. Almost certainly not — but know the number.

Then write a scoping memo. Two to four pages: the services offered, the tier conclusion for each, the reasoning, and the obligations that follow. Windrose's ran four pages and ended the internal debate about whether the regulation applied — which, as at every company, had consumed the first six weeks.

One warning about the debate. The first reaction inside every American company is that the rules cannot apply because there is no European entity, no European staff, and no European revenue beyond incidental sales. That reaction is universal and it is wrong: scope follows the offering of the service to recipients in the Union, not establishment. Get past it quickly.


Step 2 — Appoint the legal representative and the points of contact

The legal representative is required for providers with no establishment in the Union. Choose the member state deliberately, because that choice determines which Digital Services Coordinator supervises you. Coordinators differ in resourcing, activity level, and approach. Take advice; do not let the decision be made by whoever answered the procurement email first.

Diligence the representative itself. It must be able to perform the function — receive and act on communications from authorities, cooperate, and be held liable for non-compliance with obligations. A mail-forwarding arrangement is not a legal representative, and the provider remains responsible.

Two points of contact are required and they are different.

  • For authorities: a designated electronic point of contact for direct communication with member state authorities, the Commission, and the Board, with the means of communication and the languages available published.
  • For recipients of the service: a point of contact allowing users to communicate directly and rapidly, by electronic means and in a user-friendly manner, including by allowing users to choose means of communication that do not rely solely on automated tools.

Publish both, in the terms, on the site, and in the help center. Route them to a monitored queue, not to an individual — the most common failure here is an address that goes to someone who left.

Confirm language coverage. You must state the languages in which communication is possible, and they must include a language broadly understood in the Union and the official language of the member state of your coordinator.


Step 3 — Rewrite the terms and conditions

This is a rewrite, not an amendment, and it takes longer than anyone budgets.

What the regulation requires you to state, in clear, plain, intelligible, user-friendly, and unambiguous language: any restrictions imposed on the use of the service in respect of information provided by users, including information on policies, procedures, measures, and tools used for content moderation, including algorithmic decision-making and human review, and the rules of procedure of the internal complaint-handling system.

Why this is hard. Most platform terms describe rights the company reserves — "we may remove any content at our discretion." The regulation requires describing what the company actually does. Nobody has written that down. Extracting it from the trust and safety team's practice, institutional memory, and internal chat is the real work.

Expect the rewrite to surface practices you would rather change than publish. Windrose found four. Beaulieu-Adeyemi's team had been shadow-banning certain accounts without notice, applying a stricter standard to new sellers than to established ones, using an automated tool nobody could describe, and enforcing a rule that existed only in a moderator handbook. Three were changed; one was documented and kept.

Additional requirements to build in: you must act diligently, objectively, and proportionately in applying restrictions, with due regard to the rights and legitimate interests of all parties involved, including fundamental rights. And where you make a significant change to the terms, you must inform users.

If your service is directed at or predominantly used by minors, the terms must explain conditions and restrictions in a way minors can understand.


Step 4 — Build the notice and action mechanism

What it must be: a mechanism allowing any individual or entity to notify you of information they consider illegal, that is easy to access and user-friendly, and that allows submission by electronic means.

What a valid notice must contain, and what your form should therefore capture: a sufficiently substantiated explanation of why the information is alleged to be illegal; a clear indication of the exact electronic location, such as the exact URL; the name and email address of the notifier, except for notices concerning certain offences; and a statement confirming the notifier's good-faith belief that the information is accurate and complete.

Why the form design matters legally. A notice that is sufficiently precise and adequately substantiated to allow a diligent provider to identify the illegality without a detailed legal examination confers actual knowledge, which starts the clock on the conditional liability exemption. A form that collects the right elements produces notices you must act on; a form that collects less produces notices that may not confer knowledge. Design deliberately.

The workflow behind it: acknowledge receipt to the notifier without undue delay; triage; assess; decide; act; generate a statement of reasons; notify the notifier of the decision and of redress possibilities; log everything.

Tell the notifier whether automated means were used in processing and deciding.

And note what you must not build: there is no general monitoring obligation and none may be imposed. You are not required to proactively seek out illegal content, and you should not describe your obligations internally as though you were.


Step 5 — Build statements of reasons

This is the largest engineering item in the program, and the one companies most often underestimate.

When one is required. For any restriction imposed on the ground that information provided by a recipient is illegal or incompatible with your terms: removal, disabling access, demotion or other visibility restriction, suspension or termination of monetization, suspension or termination of the service, and suspension or termination of the account.

What it must contain. All of the following:

  • Whether the decision entails removal, disabling, demotion, or another measure, and where relevant its territorial scope and duration.
  • The facts and circumstances relied on, including whether the decision followed a notice or an own-initiative investigation, and where strictly necessary the identity of the notifier.
  • Where applicable, information on the use of automated means, including whether the content was detected or identified by automated means.
  • Where the ground is illegality: the legal ground relied on and an explanation of why the information is illegal on that ground.
  • Where the ground is the terms: the contractual ground and an explanation of why the information is incompatible with it.
  • Clear and user-friendly information about redress possibilities — internal complaint handling, out-of-court dispute settlement, and judicial redress.

Then submit it. Online platforms must submit statements of reasons to the Commission's public database, without personal data. Your moderation decisions become publicly analyzable at scale. Design the pipeline to submit automatically as part of the enforcement action, not as a batch job someone runs monthly.

The design instruction that saves the project: generate the statement of reasons from the enforcement action itself, at the moment the action is taken, populated from the case record — not from a template a moderator fills in afterwards. A form letter saying "your content violated our community guidelines" satisfies none of the requirements, and it will be sitting in a public database next to compliant statements from your competitors.

One narrow exception to know: the obligation does not apply where the information is deceptive high-volume commercial content.

Step 6 — Build the internal complaint system and connect to dispute settlement

The internal complaint-handling system must be available to recipients, including those who submitted notices, free of charge, for at least six months following a decision, and must permit electronic complaints against: decisions to remove or disable access or restrict visibility; decisions to suspend or terminate the service; decisions to suspend or terminate the account; decisions to suspend, terminate, or otherwise restrict monetization; and decisions not to act on a notice.

How decisions must be made. Timely, non-discriminatory, diligent, and non-arbitrary. Complaints must be handled under the supervision of appropriately qualified staff, and not solely on the basis of automated means. You must reverse the decision where the complaint contains sufficient grounds, and inform the complainant of the decision and of the possibility of out-of-court dispute settlement and other redress.

Out-of-court dispute settlement. Users may select any certified dispute settlement body to resolve disputes about the decisions above. You must engage in good faith with the selected body. The decisions are not binding on the parties, but the cost allocation has teeth: where the body decides in the user's favor, you bear the user's fees and reasonable expenses; where it decides in your favor, the user bears yours only if they acted in bad faith.

Practical design points. Build the complaint entry point into the statement of reasons itself, so the redress information is a link rather than a paragraph. Staff the review with people who did not make the original decision. Track reversal rates by policy and by reviewer, because that data is how you find the policy that is being enforced badly. And budget for out-of-court settlement engagement: a small number of disputes consume a disproportionate amount of time.

Step 7 — Build the marketplace obligations

If consumers conclude distance contracts with traders on your service, three additional workstreams apply.

Trader traceability. Before allowing a trader to use the service, obtain: name, address, telephone number, and email; a copy of an identification document or other electronic identification; payment account details; where the trader is registered in a trade register, the register and registration number or equivalent means of identification; and a self-certification committing to offer only products or services complying with applicable Union law.

Then make best efforts to assess whether the information is reliable and complete, using freely available official online databases or interfaces or by requesting supporting documents. Where you obtain indications that information is inaccurate, incomplete, or not up to date, request correction and suspend the trader until it is provided. Store the information securely for the duration of the relationship and six months afterwards.

Design of the interface. Design and organize the online interface so that traders can comply with their obligations regarding pre-contractual information, compliance, and product safety information under applicable Union law — and make sure traders can provide, at minimum, the trader's details, the product or service identifier, and any required marking or labeling.

Informing consumers about illegal products. Where you become aware that an illegal product or service was offered, inform the consumers who acquired it, where you have their contact details, of the illegality, the identity of the trader, and relevant means of redress. Where you do not have contact details, make the information publicly available on your interface.

The implementation reality. For an existing marketplace, this is a re-verification of the entire seller base, not just a change to new onboarding. Run it in stages by seller tier and volume, with clear communication and a deadline, and expect attrition among the smallest and least engaged sellers. Windrose re-verified 3,400 sellers over five months and lost about 6% of them, almost entirely dormant accounts.

Step 8 — Advertising, recommenders, and interface design

Advertising transparency. For each advertisement presented, recipients must be able to identify, in a clear, concise, and unambiguous manner and in real time: that the information is an advertisement, including through prominent markings; the natural or legal person on whose behalf it is presented; the person who paid for it, if different; and meaningful information about the main parameters used to determine the recipient, and where applicable how to change them.

Advertising prohibitions. No presenting advertisements based on profiling using special categories of personal data. And for online platforms, no presenting advertisements based on profiling where the platform is aware with reasonable certainty that the recipient is a minor. Note the second one carefully: it does not require age verification, and it turns on what you actually know.

Recommender system transparency. Set out in the terms, in plain and intelligible language, the main parameters used in your recommender systems and any options for recipients to modify or influence them, including the criteria most significant in determining what is suggested and the reasons for their relative importance. Where options exist, provide a functionality allowing selection and modification, directly and easily accessible from the section where information is prioritized.

Dark patterns. Do not design, organize, or operate your interface in a way that deceives or manipulates recipients or otherwise materially distorts or impairs their ability to make free and informed decisions. Run an interface review; it reliably finds something. Windrose found a pre-checked consent box and a countdown timer that reset on page reload.

Minors. Put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors on your service, where it is accessible to them.

Step 9 — Build the authority and trusted flagger channels

Two inbound categories arrive outside the ordinary user notice queue, and both carry response obligations.

Trusted flaggers. Notices submitted by an entity awarded trusted flagger status by a Digital Services Coordinator, within its designated area of expertise, must be given priority and processed and decided without undue delay. Build intake routing that identifies these submissions and moves them ahead of the queue, and maintain the list of trusted flaggers. Where a trusted flagger submits a significant number of insufficiently precise or inadequately substantiated notices, you may report it to the coordinator that awarded the status.

Orders from member state authorities. Two types, distinct:

  • Orders to act against illegal content. On receipt, inform the issuing authority of the effect given, specifying whether and when effect was given. Also inform the recipient concerned of the order and the effect given to it.
  • Orders to provide information about specific recipients. Same confirmation obligation.

Check the order's contents. Both types must contain prescribed elements — a statement of reasons, the exact electronic location, information about redress available to the provider and to the recipient, and, for content orders, the territorial scope. An order that lacks them is one you should question rather than comply with silently. And territorial scope is limited to what is strictly necessary, which is the answer to an order purporting to require global removal.

Design the intake for these on day one. A platform that builds an elegant user-facing form and no channel for authority orders will receive its first order at a general address and miss it.

Step 10 — Misuse measures, records, and the annual report

Misuse suspension. After issuing a prior warning, suspend, for a reasonable period, the provision of the service to recipients who frequently provide manifestly illegal content; and suspend processing of notices and complaints from individuals or entities that frequently submit manifestly unfounded notices or complaints. Assess misuse case by case, in a timely, diligent, and objective manner, considering the numbers involved, their proportion of the total, the gravity of the misuse, and the recipient's intention. Set out your policy on this in the terms, with examples.

Records. Keep records of moderation decisions, notices, statements of reasons, complaints and their outcomes, authority orders and responses, and trader verification information. You will be asked, and reconstructing this after the fact is not possible.

The annual transparency report. Content depends on tier, and for online platforms includes: orders received from authorities by type and member state, with median time to acknowledge and to give effect; notices received through the notice and action mechanism, by type of alleged illegal content, action taken and whether on the basis of law or terms, notices from trusted flaggers, and median processing time; own-initiative moderation, including use of automated tools, measures taken, and the numbers affected by type; complaints through the internal system, the basis, decisions, median time, and reversals; use of automated means with qualitative description, purposes, accuracy indicators, and safeguards; and disputes submitted to out-of-court settlement bodies with outcomes and median time.

Publish it in a machine-readable format, in an easily accessible place. Make the first one accurate and unremarkable.

Step 11 — Decide: harmonize or geo-differentiate

An architectural decision that should be made deliberately, because engineering will otherwise make it for you.

Harmonize globally. One system, European rules for everyone. Simpler to build and operate, easier to explain, and it produces a genuinely better product in several respects — reasons for removal, an appeal path, and a documented process.

What you give up. Section 230 gives an American platform broad latitude in moderation decisions that the European framework replaces with a process obligation. And in Moody v. NetChoice, LLC, 603 U.S. 707 (2024) the Supreme Court explained that a platform's curation of third-party speech is itself expressive activity protected by the First Amendment, with the consequence that state laws burdening editorial choices face serious constitutional difficulty. Adopting European process obligations globally means accepting for American users obligations that American legislatures may not be able to impose. That is a legitimate business choice. Make it knowingly.

Geo-differentiate. European rules for European users and content. Preserves flexibility, costs more, and creates a permanent complexity tax: two policies, two workflows, two sets of metrics, and a routing decision on every case that is sometimes wrong.

A middle path many companies take: harmonize the user-facing good practices — reasons, appeals, clear policies — globally, because they are simply better, while keeping regulatory reporting and process formalities scoped to the Union.

Windrose harmonized reasons and appeals, and scoped statements of reasons submission, out-of-court dispute settlement, and trader verification to European users and sellers.

Step 12 — Turn the DMA around: exercise your rights

Almost no reader of this guide will be a designated gatekeeper. Nearly every reader is a business user of one, and the Digital Markets Act creates rights in your favor that most companies have never claimed.

Inventory your gatekeeper relationships. App stores, marketplaces, search, advertising services, operating systems, browsers, cloud services, communications services. Which designated gatekeepers do you depend on, and for what?

Then ask what you are entitled to:

  • Your own data. Effective, high-quality, continuous, and real-time access to data generated by your activity on the platform, including data provided or generated by end users engaging with your products.
  • Steering freedom. The ability to communicate and promote offers to end users acquired through the platform, and to conclude contracts with them, outside the platform — free of anti-steering restrictions.
  • Pricing freedom. The ability to offer the same products or services through other channels at different prices or conditions.
  • No forced bundling of ancillary services. You cannot be required to use the gatekeeper's identification service, browser engine, or payment service as a condition of access.
  • Advertising transparency. Daily information on each advertisement, prices and fees paid, remuneration received, and the metrics on which they are calculated.
  • Fair, reasonable, and non-discriminatory access conditions for app stores, search engines, and social networking services.
  • No misuse of your non-public data by the gatekeeper to compete with you.
  • Complaint routes that do not require you to litigate: the gatekeepers' compliance functions, the Commission, and national authorities.

Assign an owner. This is a commercial file, not a compliance file, and it should sit with whoever runs the platform relationships. The company that has never asked its app store or advertising platform for what the regulation requires them to provide is leaving value on the table.

Step 9A — Budgeting the program honestly

Finance will ask for a number before the scope is settled. Give them a structured one.

One-time build. Engineering is the largest line: notice and action intake, case record, statement-of-reasons generation, transparency database submission, complaint workflow, trader verification, interface and advertising changes. For a mid-sized platform this lands in the mid-six figures. Legal and advisory — scoping, terms rewrite, representative selection, member state advice — is a meaningful but smaller line. Trader re-verification is a project cost with a communications component.

Recurring. Moderation and complaint-review staffing dominates, and it is the line that grows with the service rather than staying flat. Then the legal representative's retainer, out-of-court dispute settlement engagement, the annual transparency report, external advice, and the ongoing engineering maintenance that every pipeline requires.

The line people forget. Out-of-court dispute settlement is unpredictable: a small number of disputes consume disproportionate time, and where the body decides in the user's favor you bear their fees and reasonable expenses. Budget a contingency rather than a point estimate.

Windrose's actual numbers: roughly $600,000 to build, roughly $340,000 a year to run, on $84 million of revenue with 22% of users and 14% of revenue in the Union. Year two came in materially below year one, as these programs do.

How to frame it for the board. Not as a penalty-avoidance exercise — the realistic near-term exposure for a company this size is a supervisory information request, not a percentage-of-turnover fine. Frame it as the cost of continued access to a defined share of the user base, alongside the honest alternative of leaving the market, and let the business make the call on the arithmetic.

Step 10A — How Windrose actually sequenced it

The nine months, month by month, because sequencing is where these programs succeed or fail.

Month 1 — Scoping. Okwuosa-Lindgren wrote the four-page memo. The internal argument about whether the rules applied consumed the first three weeks and ended when the memo circulated. Lesson: write the memo first, not after the debate.

Month 2 — Structure. Legal representative appointed in Ireland after advice on coordinator activity levels. Both points of contact published and routed to monitored queues. Cheap, fast, and it makes the company visibly in-scope-and-engaged rather than absent.

Months 2–5 — Terms rewrite. The long pole, because it required documenting practice that existed only in the trust and safety team's heads. Ran in parallel with everything else. Produced the four practice changes.

Months 3–7 — The build. Notice and action intake first, because it is the smallest and it forces the case-record design that everything else depends on. Then statements of reasons generated from the enforcement action. Then the transparency database pipeline. Then the complaint system. Sequencing matters: teams that build the complaint system before the statement of reasons discover they have nothing to link the complaint to.

Months 4–9 — Trader re-verification. Started early because it takes the longest and depends on seller cooperation rather than engineering. Staged by seller volume, with a communicated deadline. 3,400 sellers, about 6% attrition, almost all dormant.

Month 6 — Advertising and interface. Labeling, parameter disclosure, recommender explanation, dark-patterns review.

Month 8 — Authority and trusted flagger channels. Small build, easy to forget, and the one Beaulieu-Adeyemi nearly missed.

Month 9 — First transparency report and a tabletop. The tabletop exercise — a simulated coordinator information request, answered from documents in 48 hours — surfaced two gaps that were fixed before anyone real asked.

Three sequencing lessons worth stealing. Start the terms rewrite and the trader re-verification on day one, because both depend on people rather than code and both take longer than the engineering. Build the notice-and-action case record before anything downstream of it. And run the tabletop before you think you are ready, because the gaps it finds are cheap in month nine and expensive in month fourteen.

Step 11A — Coordinating with the rest of the European stack

Companies run DSA compliance as a standalone project and then rebuild the same consent flow three more times. Fold these in from the start.

Data protection. The advertising prohibitions turn on special categories of personal data and on knowledge that a recipient is a minor — both concepts that live in the data protection framework and require its analysis. Recommender transparency and the automated-means disclosures in a statement of reasons sit alongside the right to information about automated decision-making. Trader verification creates a new processing activity with its own lawful basis, retention period, and record. One legal analysis, not two.

Consumer law. The marketplace interface obligation is an obligation to enable traders to comply with consumer law requirements — pre-contractual information, the right of withdrawal, price indication, and product compliance information. A team that reads only the platform regulation will build an interface that enables compliance with rules it has not read. Get consumer counsel into the interface design.

Product safety. If physical goods are sold, further obligations attach to online marketplaces, including cooperation with market surveillance authorities and handling of dangerous product notifications. Build the notification and consumer-contact capability once, and use it for both the illegal-product obligation and the safety regime.

Copyright. Services whose main purpose is storing and giving access to large amounts of user-uploaded copyright works are subject to a separate European copyright regime with authorization, best-efforts, and complaint requirements that the DSA's notice and action mechanism does not satisfy. Determine whether you are in that category; if you are, it is a distinct workstream.

Accessibility. European accessibility requirements apply to a range of consumer-facing digital services and e-commerce. If you are rebuilding interfaces for platform-regulation reasons, do the accessibility conformance work in the same pass. Rebuilding twice costs roughly twice as much.

Artificial intelligence. Where automated systems drive moderation, ranking, or ad delivery, the European AI framework layers transparency and, for certain uses, risk-management obligations on top. The DSA already requires disclosing whether automated means were used in a moderation decision; design the two disclosure regimes together rather than bolting the second onto the first.

The instruction: one European product-compliance roadmap, one owner, one backlog. Five separate projects will each discover the same consent screen and each rebuild it.

Step 12A — Staffing, governance, and the operating rhythm

A compliance program that exists only as a build is a program that decays in eighteen months. Give it an operating shape.

Name an owner with real authority. One person accountable for the whole program, with a direct line to whoever can change the product. At Windrose this is the head of trust and safety, with the general counsel as the escalation point. A program owned by "legal and product jointly" is owned by nobody.

Staff the moderation function to the service levels you published. The regulation requires acting diligently and without undue delay, requires human supervision of complaint decisions, and requires priority handling of trusted flagger notices. Those are staffing commitments. A team sized for the pre-compliance workload will miss all three.

Give complaint reviewers independence. The person reviewing a complaint should not be the person who made the original decision. This is both a quality control and the thing that makes "under the supervision of appropriately qualified staff" true rather than aspirational.

Instrument everything. Notices received and processed, by type and source. Median and 90th-percentile handling times. Statements of reasons generated and submitted. Complaints received, reversal rate by policy and by reviewer, and median handling time. Trusted flagger volume and precision. Authority orders and response times. Out-of-court disputes and outcomes. Trader verification status. You need these for the annual transparency report anyway; you need them more for management.

Watch the reversal rate. It is the single most informative metric in the program. A policy with a 40% complaint reversal rate is a badly written policy, not a badly behaved user base. A reviewer with a reversal rate far off the team median needs training or a different job.

Run a quarterly review covering metrics, policy changes, product changes that affect scope, regulatory developments, and any authority contact.

Run an annual scope recheck. Have we crossed the small enterprise threshold? Have we added a feature that changes our tier — a messaging product, a public feed, a marketplace? Product teams add features that move a company across a regulatory line without anyone noticing, and the annual recheck is how you notice.

Keep the record. Moderation decisions, notices, statements of reasons, complaints and outcomes, authority orders and responses, trader verification files. The program's defensibility is entirely a function of whether the record exists.

Step 12B — Handling an authority contact

Sooner or later a Digital Services Coordinator writes to you. What happens next is largely determined by preparation.

Acknowledge immediately, through the designated point of contact, in the languages you published.

Read what is actually being asked. An information request is not an enforcement action. A request for your terms, your notice mechanism, and your transparency report is a routine supervisory step, and companies that respond to it as though it were a prosecution create an impression they then have to undo.

Answer with documents, not assurances. The scoping memo. The terms. Screenshots of the notice mechanism and the complaint flow. A sample statement of reasons. The transparency report. Metrics. A coordinator that receives a complete, organized package forms a very different view from one that receives three paragraphs of description.

Be candid about gaps. If a workstream is in progress, say so, with a date. Coordinators, like most regulators, respond much better to a company that identifies its own gap and shows a plan than to one that is later found to have concealed it.

Engage local counsel in the coordinator's member state. Practice, expectations, and procedure vary, and this is not a place to improvise from Minneapolis.

Then fix what the contact revealed. The most common outcome of a first supervisory contact is not a penalty; it is a list of things the company now knows it should have built. Treat it as the audit you did not have to pay for.

Step 13 — Or decide not to serve the market

The option nobody puts in a compliance plan, and it belongs there.

Run the numbers honestly. European revenue and users, actual and forecast. Implementation cost. Ongoing operating cost, dominated by moderation staffing and the statement-of-reasons pipeline. Windrose's numbers were roughly $600,000 to build and $340,000 a year to run, against 22% of users and 14% of revenue — an easy decision to comply.

A company with 2% European revenue and a thin margin should run the same arithmetic and may reach the opposite answer. A number of smaller American services have geo-blocked the Union rather than build the program, and that is a rational business decision, not a failure.

If you geo-block, do it properly. Actual technical measures, not a banner. Terms that prohibit use from the Union. No European-language marketing, no European currency pricing, no European payment methods, no European domain. The scope test looks at whether the service is offered to recipients in the Union, and a company that geo-blocks while advertising in French and pricing in euros has not left the market; it has created a record of having tried to.

And revisit annually. Markets change, and so do costs — the second year of a compliance program is much cheaper than the first.

Related documents


This guide is general information, not legal advice, and does not create an attorney-client relationship.