Document type: Article Practice area: Technology — Platform Regulation Jurisdiction: European Union, with United States comparison Last reviewed: 5 September 2026
Why an American company is reading this
Because the thresholds are low, the territorial reach is broad, and the penalties are calculated on worldwide turnover.
The Digital Services Act applies to intermediary services offered to recipients located in the European Union, regardless of where the provider is established. There is no employee threshold, no revenue threshold, and no requirement that the company have a European entity. A Denver company with a forum, a marketplace, a review section, or a comments feature, used by people in Portugal, is in scope. The obligations scale with what kind of intermediary you are and how large you are, and the smallest tier of obligations is genuinely modest — but "we have no European operations" is not an answer, and neither is "we are not a social network."
The Digital Markets Act is the opposite in structure. It does not regulate platforms generally; it imposes a specific list of obligations and prohibitions on a small number of designated gatekeepers operating core platform services above quantitative thresholds. Most companies will never be designated. Almost every technology company will nonetheless deal with a gatekeeper as a business user, and the DMA gives business users rights that are worth knowing about — because a right nobody exercises is worth nothing.
This article is written for United States counsel who need to understand what these regimes require, what they do not require, and where they collide with American law.
Larkspur Interactive
Larkspur Interactive is a 240-person company in Boulder that runs a hobbyist marketplace and community for tabletop gaming — user listings, user reviews, a forum, and a storefront where independent designers sell files and physical goods. Roughly 19% of its users are in the European Union.
Its general counsel, Odalys Ferreira-Kwan, received an email from a German user in 2025 asking why a listing had been removed and demanding a "statement of reasons." She had never heard the phrase. Six weeks later a Polish rights holder sent a notice invoking the company's "notice and action mechanism," which Larkspur did not have.
The company was in scope from the day the regulation applied. Nobody had told it.
The DSA's structure: obligations stack by tier
The single most useful thing to understand about the DSA is that it is cumulative and tiered. Each category of provider carries the obligations of the categories above it plus its own. Getting your tier right determines everything else.
Tier 1 — All intermediary services. Mere conduit, caching, and hosting services all sit here. Obligations include: designating a single point of contact for authorities and a separate one for recipients of the service; where the provider is not established in the Union, appointing a legal representative in a member state; setting out in the terms and conditions, in clear and plain language, any restrictions imposed on the use of the service, including content moderation policies, procedures, tools, and the rules of any internal complaint system; acting diligently, objectively, and proportionately when applying those restrictions with due regard to fundamental rights; and publishing an annual transparency report on content moderation activity.
Tier 2 — Hosting services. Any service that stores information provided by a recipient. This includes cloud storage, web hosting, and — importantly for companies that do not think of themselves as platforms — any service with a comments field, review section, or file upload. Additional obligations: a notice and action mechanism that is easy to access and user-friendly and permits the submission of sufficiently precise and adequately substantiated notices by electronic means; and a statement of reasons given to any affected recipient for any restriction imposed on the ground that the information is illegal or incompatible with the terms and conditions.
Tier 3 — Online platforms. Hosting services that, at the request of a recipient, store and disseminate information to the public. Marketplaces, social networks, app stores, review sites, forums, collaborative economy platforms. This is where the substantial obligations begin: an internal complaint-handling system free of charge for at least six months after a decision; out-of-court dispute settlement with certified bodies whose decisions the platform must engage with; trusted flagger priority processing; measures against misuse — suspension of recipients who frequently provide manifestly illegal content and of complainants who frequently submit manifestly unfounded notices, after warning; advertising transparency, including real-time identification that an item is an advertisement, on whose behalf it is presented, who paid, and the main parameters used to determine the recipient; a prohibition on dark patterns; a ban on advertising based on profiling using special categories of personal data; a ban on advertising based on profiling where the provider is aware with reasonable certainty that the recipient is a minor; and recommender system transparency, explaining in the terms and conditions the main parameters and any options to modify them.
Small and micro enterprises are exempt from the Tier 3 online platform obligations — a genuine and significant carve-out. Larkspur, at 240 people, is not small for this purpose.
Tier 3a — Online platforms allowing consumers to conclude distance contracts with traders. Marketplaces. Additional obligations: trader traceability, requiring the platform to obtain and make reasonable efforts to assess the reliability of specified information about each trader before permitting use of the service; design of the interface so traders can comply with pre-contractual information, compliance, and product safety obligations; and where the platform becomes aware that an illegal product or service was offered, informing consumers who acquired it.
Tier 4 — Very large online platforms and very large online search engines. Services with at least 45 million average monthly active recipients in the Union, formally designated by the Commission. The obligations here are of a different character: annual systemic risk assessment covering dissemination of illegal content, effects on fundamental rights, effects on civic discourse and electoral processes, and effects relating to gender-based violence and public health and minors; risk mitigation measures; independent audit at the provider's expense; a non-profiling option for recommender systems; an advertisement repository; data access for vetted researchers; a compliance function with an independent compliance officer reporting to management; crisis response mechanisms; and a supervisory fee.
Where Larkspur landed. It is a hosting service, an online platform, and an online platform allowing consumers to conclude distance contracts with traders. It is not small or micro. It is nowhere near a very large online platform. That means Tiers 1, 2, 3, and 3a apply in full, and Tier 4 does not — a scoping conclusion that took an afternoon and should have been reached two years earlier.
The obligations that actually take work
Reading the list above, three obligations consume most of the implementation effort.
The statement of reasons. For every restriction — removal, disabling access, demotion, demonetization, account suspension or termination, restriction of the ability to monetize — imposed on the ground that content is illegal or incompatible with the terms, the provider must give the affected recipient a clear and specific statement of reasons. The required content is prescribed: the type of restriction and, where relevant, its territorial scope and duration; the facts and circumstances relied on, including whether the decision followed a notice or an own-initiative investigation and, where strictly necessary, the identity of the notifier; whether automated means were used, including whether the content was detected or identified by automated means; where the decision concerns allegedly illegal content, the legal ground relied on and an explanation of why the content is illegal on that ground; where the decision is based on the terms, the contractual ground and an explanation of why the content is incompatible with it; and clear information on redress possibilities.
Statements of reasons for online platforms must also be submitted to the Commission's public transparency database. This is the obligation that most reliably surprises companies: your moderation decisions become publicly analyzable data, at scale, in a way that invites both regulatory attention and journalism.
The notice and action mechanism plus internal complaints. Two distinct systems, frequently conflated. The notice mechanism is inbound from anyone reporting allegedly illegal content, and a sufficiently precise and adequately substantiated notice that allows a diligent provider to identify illegality without a detailed legal examination gives rise to actual knowledge for liability purposes. The complaint system is for recipients contesting decisions — removal, suspension, or a refusal to act on their notice — and must be free, available for at least six months, and produce decisions that are not solely automated, taken under the supervision of appropriately qualified staff.
Trader traceability. For marketplaces, the requirement to collect and make reasonable efforts to verify identification, contact, payment account, and where applicable trade register and self-certification information from every trader, before allowing them to trade. For a platform with thousands of small independent sellers, this is an onboarding redesign, not a policy update.
Enforcement, and the number that gets attention
Enforcement is split. Very large online platforms and search engines are supervised by the European Commission directly. Everyone else is supervised by the Digital Services Coordinator of the member state of establishment — or, for a provider with no Union establishment, the member state where its legal representative resides or is established.
That last point deserves emphasis for United States companies. Appointing a legal representative determines which member state's regulator supervises you. It is a genuine choice with real consequences, and it is frequently made by whoever handles corporate administration, on the basis of which vendor responded fastest.
Penalties are set by member states within a ceiling: up to 6% of annual worldwide turnover for infringements, and up to 1% for supplying incorrect, incomplete, or misleading information or failing to submit to an inspection. Periodic penalty payments can reach 5% of average daily worldwide turnover.
The Commission has been active with the very large platforms, and national coordinators have begun to move on the tier below. The practical exposure for a mid-sized American company is currently less about a headline fine than about a coordinator's information request that the company cannot answer, followed by an order it cannot comply with quickly.
The Digital Markets Act: a different animal
The DMA is often discussed alongside the DSA and is structurally unrelated to it.
It applies to designated gatekeepers. The Commission designates an undertaking as a gatekeeper where it provides a core platform service — the enumerated list includes online intermediation services, search engines, online social networking, video-sharing platforms, number-independent interpersonal communications services, operating systems, web browsers, virtual assistants, cloud computing services, and online advertising services — and meets three cumulative criteria: significant impact on the internal market, operation of a core platform service that is an important gateway for business users to reach end users, and an entrenched and durable position. Quantitative thresholds create presumptions, based on Union turnover or market capitalization, monthly active end users and yearly active business users, and persistence of those figures over three financial years.
Designated gatekeepers are then subject to a list of obligations and prohibitions that apply directly, without a case-by-case competition analysis. Among them: no self-preferencing in ranking; no use of non-public data of business users to compete with them; interoperability for operating systems and for number-independent interpersonal communications services; permitting the installation and effective use of third-party apps and app stores; allowing business users to offer the same products on other channels at different prices and to conclude contracts with end users outside the gatekeeper's platform; no requiring business users or end users to use the gatekeeper's identification, browser engine, or payment service; data portability; providing advertisers and publishers with performance and pricing information; and no combining personal data across services or signing users into other services without consent.
Penalties reach 10% of worldwide turnover, and 20% for repeated infringement, with the possibility of structural remedies in cases of systematic non-compliance.
Why a non-gatekeeper should care. Because the DMA creates enforceable rights in your favor as a business user of a gatekeeper's core platform service. If you distribute an app, sell on a marketplace, advertise through a gatekeeper's ad service, or rely on a gatekeeper's operating system, the regulation gives you: access to the data your own activity generates; the ability to steer users to your own channels; freedom from anti-steering restrictions; access to advertising performance data; and interoperability access in defined circumstances.
These rights are exercised through the gatekeepers' own compliance mechanisms and through complaints to the Commission and to national authorities. Very few mid-sized companies have looked at their gatekeeper relationships through this lens. That is a commercial opportunity sitting in a compliance file, and it is the part of this article most likely to make a company money rather than cost it.
Where European and American law collide
For United States counsel, the interesting part is not the compliance list. It is the places where doing what Europe requires is in tension with how American law has organized the same problems.
Section 230 and the DSA's liability structure. 47 U.S.C. § 230 provides that no provider or user of an interactive computer service shall be treated as the publisher or speaker of information provided by another information content provider, and separately immunizes good-faith restriction of objectionable material. Its practical effect is that an American platform's moderation decisions are, in the ordinary case, unreviewable — the platform may remove or decline to remove, and neither choice creates liability.
The DSA takes a different approach. Its liability exemption for hosting services is conditional: the provider is not liable for stored information provided it does not have actual knowledge of illegal activity or content and, upon obtaining such knowledge, acts expeditiously to remove or disable access. That is much closer to the American copyright regime in 17 U.S.C. § 512 than to § 230 — a notice-driven conditional safe harbor rather than a categorical immunity.
The consequence for a company operating in both: a single global moderation policy will not work. A notice that has no legal effect in the United States confers actual knowledge in the European Union, and the response obligations differ. Companies solve this either by geo-differentiating enforcement — applying the stricter European process to European users and content — or by adopting the European standard globally, which is simpler operationally and gives away flexibility the American statute preserves.
The DSA also imposes obligations that § 230 makes unnecessary at home: reasons for removal, appeal rights, and independent dispute resolution. A United States platform has never had to justify a takedown to the person whose content it removed. Under the DSA it must, in prescribed detail, in a public database.
No general monitoring — a genuine convergence. The DSA expressly prohibits imposing a general obligation to monitor information transmitted or stored, or actively to seek facts indicating illegal activity. That aligns with the structure of § 512's safe harbors and with the general American reluctance to require proactive policing. It is worth telling clients, because they assume the opposite.
Constitutional limits have no European analogue. In Moody v. NetChoice, LLC, 603 U.S. 707 (2024), the Supreme Court addressed Florida and Texas statutes regulating how large platforms moderate content. The Court vacated and remanded because the lower courts had not properly conducted the facial-challenge analysis, but a majority set out the governing principle clearly: a platform's compilation and curation of third-party speech into its own expressive product is itself protected expression, and a state law that forces a platform to carry speech it would exclude, or that burdens its editorial choices, faces serious First Amendment problems.
That reasoning has no counterpart in European law, which treats platform obligations as ordinary market regulation. The practical implication for a company is uncomfortable: the same obligation can be constitutionally suspect in the United States and mandatory in the European Union. A company that harmonizes globally to the European standard may be adopting practices that American legislatures could not impose on it — which is fine as a business choice and should be made knowingly rather than by default.
Antitrust divergence. The DMA and American antitrust law aim at overlapping conduct and work in fundamentally different ways. Section 2 of the Sherman Act requires proof of monopoly power in a defined relevant market and exclusionary conduct, case by case, with effects analysis. The DMA dispenses with all of that: designation is quantitative, the obligations are ex ante, and there is no requirement to show market power in an economic sense or anticompetitive effect in a given instance. Self-preferencing that would require a fully litigated monopolization case in the United States is simply prohibited for a designated gatekeeper.
For counsel advising a company that is not a gatekeeper, the two regimes are complements rather than substitutes: Sherman Act § 1 and § 2, Clayton Act § 7, and FTC Act § 5 remain the American toolkit for conduct by a dominant platform, and the DMA remains a European channel for the same grievance with a much lower evidentiary burden. A company harmed by a gatekeeper should evaluate both.
What compliance actually looks like
Larkspur's implementation took nine months and involved five workstreams. The shape generalizes.
Workstream one — scoping and structure. Determine the tier. Appoint the single points of contact for authorities and for recipients, publish them, and make sure someone actually monitors them. Appoint the legal representative and choose the member state deliberately, because that choice selects your supervising Digital Services Coordinator. Document the analysis; you will be asked.
Workstream two — terms and policies. Rewrite the terms and conditions to state, in clear and plain language, the restrictions imposed on use of the service, the policies and procedures and tools used for content moderation including algorithmic decision-making and human review, and the rules of the internal complaint system. This is a rewrite, not an amendment: most platform terms describe rights the company reserves rather than the process it follows, and the DSA requires the latter.
Workstream three — the notice and action system. Build an intake that is easy to access and user-friendly, that permits electronic submission, and that captures what a valid notice requires: a sufficiently substantiated explanation of why the content is illegal, the exact electronic location, the notifier's name and email except for certain offences, and a statement of good faith. Build the workflow: triage, assessment, decision, action, statement of reasons, and confirmation to the notifier.
Workstream four — statements of reasons and the complaint system. This is the largest build. Every enforcement action must generate a compliant statement of reasons containing the prescribed elements, delivered to the affected recipient, and — for online platforms — submitted to the Commission's transparency database. Then an internal complaint system, free, open for six months, producing non-automated decisions under qualified supervision. Then the interface to out-of-court dispute settlement bodies.
Workstream five — marketplace and advertising obligations. Trader onboarding and verification. Interface changes so traders can present required information. Advertising labeling and parameter disclosure. Recommender system explanations. Removal of any interface pattern that could be characterized as a dark pattern — a review that reliably finds something.
Then the recurring load: annual transparency reports, statement-of-reasons submissions in the ordinary course, records of moderation decisions, trusted flagger handling, misuse suspensions with warnings and records, and responses to authority requests.
Cost. For a mid-sized platform, initial implementation in the mid-six figures including engineering, and an ongoing operating cost dominated by moderation staffing and the statement-of-reasons pipeline. Larkspur's number was $610,000 to build and roughly $340,000 a year to run, on $71 million of revenue with 19% European exposure. That is a real number, and the honest advice to a company with 2% European exposure and a marginal business case is that geo-blocking the Union is a legitimate option to evaluate — one a number of smaller American services have taken.
The very large platform tier, briefly, and why it matters even if you are not there
Most readers of this article will never be designated a very large online platform. The tier is worth understanding anyway, for two reasons: designation thresholds are crossed by growth, and the obligations imposed on the largest services are shaping expectations for everyone below them.
The systemic risk assessment is the centerpiece and is unlike anything in American regulation. A designated provider must assess, at least annually and before deploying functionalities likely to have a critical impact, the systemic risks stemming from the design, functioning, and use of its service. Four categories are specified: dissemination of illegal content; actual or foreseeable negative effects on the exercise of fundamental rights, including private and family life, freedom of expression and information, non-discrimination, and the rights of the child; actual or foreseeable negative effects on civic discourse and electoral processes and on public security; and negative effects in relation to gender-based violence, public health, minors, and physical and mental well-being.
The assessment must consider how recommender systems, content moderation systems, terms and conditions and their enforcement, advertising systems, and data practices influence those risks. Mitigation measures must then be reasonable, proportionate, and effective, and may include adapting design, adjusting moderation processes and resourcing, testing and adapting algorithmic systems, and modifying advertising practices.
Independent audit, annually, at the provider's expense, by organizations meeting independence and expertise requirements, producing an opinion and, where the opinion is not positive, operational recommendations that the provider must implement or explain.
Data access for vetted researchers, on reasoned request through the Digital Services Coordinator of establishment, for research contributing to the detection, identification, and understanding of systemic risks. This is genuinely novel and it is the obligation most likely, over time, to change what is publicly known about how large platforms operate.
An independent compliance function with a compliance officer who has sufficient authority, resources, and access to management, and who cannot be dismissed without the management body's approval — a governance structure borrowed from financial services and imported into technology.
A supervisory fee, an advertisement repository, a non-profiling recommender option, and crisis response mechanisms round out the tier.
Why this matters to a Tier 3 platform. Regulators, researchers, journalists, and enterprise customers are being trained by the very large platform tier on what "responsible platform operation" looks like. Risk assessment, algorithmic accountability, and researcher access are becoming the vocabulary of the whole conversation. A growing platform that has never conducted anything resembling a systemic risk assessment will find that expectation arriving from a customer's procurement questionnaire long before it arrives from a regulator — and the company that has done a lightweight version voluntarily answers it in a paragraph.
The wider European stack, because the DSA does not travel alone
A company standing up DSA compliance discovers that several adjacent regimes attach to the same product decisions, and treating them as separate projects wastes money.
The GDPR overlaps at the seams. The DSA's advertising rules prohibit profiling-based advertising using special categories of personal data and prohibit profiling-based advertising to recipients the provider knows with reasonable certainty are minors — obligations that are meaningless without the data protection framework's definitions and lawful-basis analysis. Recommender system transparency and the automated-decision disclosures in a statement of reasons sit next to the data protection right to information about automated decision-making. Build them together.
Consumer protection law does most of the marketplace work. The DSA requires marketplace interfaces to let traders comply with pre-contractual information and product safety obligations — obligations that come from consumer law, not from the DSA. A marketplace compliance project that reads only the DSA will build an interface that satisfies a requirement to enable compliance with rules nobody on the team has read.
Product safety rules reach the platform. Where a marketplace becomes aware that an illegal product was offered, it must inform consumers who acquired it. Broader European product safety law imposes further obligations on online marketplaces, including registration with a reporting portal and cooperation with market surveillance authorities. If you sell physical goods, this is a workstream.
Accessibility requirements bite on interfaces. European accessibility legislation applies to a range of consumer-facing digital services and e-commerce, with its own conformance expectations and its own enforcement. Companies rebuilding an interface for DSA reasons should do the accessibility work in the same pass rather than rebuilding twice.
Copyright content rules apply to a subset. Providers whose main purpose is storing and giving access to large amounts of copyright-protected works uploaded by users are subject to a distinct European copyright regime with its own authorization, best-efforts, and complaint requirements — a different framework from the DSA's notice and action mechanism, applying to a narrower set of services, and not satisfied by DSA compliance.
And the artificial intelligence framework is arriving on top. Where a platform uses automated systems for moderation, recommendation, or advertising delivery, the European AI rules add transparency and, for some uses, risk-management obligations. The DSA already requires disclosure of whether automated means were used in a moderation decision; the two disclosure regimes should be designed together.
The practical instruction: run one European product-compliance program with one owner and one roadmap, not five projects that each rebuild the same consent flow.
The mistakes companies make
"We're not a platform." The hosting tier catches any service that stores information provided by a user. A comments section, a review feature, a support forum, a file upload, a profile bio. Companies that would never describe themselves as platforms are hosting services with notice and action obligations.
Confusing notice and action with the complaint system. They are different systems, serving different people, with different requirements. Building one and calling it both fails an inspection quickly.
Treating the statement of reasons as a template. It requires facts specific to the decision — the legal or contractual ground, an explanation of why this content violates it, whether automated means were used, the territorial scope and duration. A form letter saying "your content violated our community guidelines" satisfies none of it, and it will be visible in a public database alongside everyone else's.
Appointing the legal representative carelessly. The choice determines your regulator. Some coordinators are more resourced and more active than others. Make the choice on advice.
Ignoring the small enterprise exemption — in both directions. Small and micro enterprises are exempt from the online platform obligations, which is a genuine relief for companies that qualify. Companies that have grown past the threshold and never rechecked are the ones that get caught.
Assuming DMA irrelevance. The obligations apply to a handful of companies. The rights run to every business user of those companies. A company that has never asked its app store, marketplace, or advertising platform for the data and freedoms the DMA requires them to provide is leaving value unclaimed.
Harmonizing globally without deciding to. Engineering teams build one system. If that system implements European rules for everyone, the company has adopted European moderation obligations for American users — with the Moody implications and the § 230 flexibility that get given up along the way. Make it a decision.
Trusted flaggers, orders from authorities, and the two inbound channels people forget
Two categories of inbound arrive outside the ordinary notice queue, and both carry timelines.
Trusted flaggers. Entities awarded that status by a Digital Services Coordinator on the basis of expertise in detecting illegal content, independence from any platform, and diligent and objective activity. Notices submitted by a trusted flagger within its area of expertise must be given priority and processed without undue delay. A platform therefore needs to identify trusted flagger submissions on intake and route them ahead of the general queue — which requires knowing who the trusted flaggers are, maintaining that list, and building the routing. Platforms also have a safeguard: where a trusted flagger submits a significant number of insufficiently precise, inaccurate, or inadequately substantiated notices, the platform may report it to the coordinator that awarded the status.
Orders from member state authorities. Two distinct types, and platforms conflate them. An order to act against illegal content requires the provider to inform the issuing authority of the effect given to the order, specifying whether and when effect was given. An order to provide information about one or more specific recipients requires the same confirmation. Both must contain prescribed elements — a statement of reasons, the exact electronic location, information about redress, and the territorial scope — and a provider receiving an order that lacks them should say so rather than comply silently.
Both channels have to be in the intake design from the start. A platform that builds a beautiful user-facing notice form and no path for an authority order will receive its first order by email to a general address, miss it for eleven days, and then explain that to a regulator.
And note the affected-user side. An order to act against illegal content requires the provider to inform the recipient concerned of the order and the effect given to it. Cross-border orders raise their own questions about territorial scope, which the regulation addresses by limiting the effect of an order to what is strictly necessary — a limitation worth invoking when an order purports to require global removal.
How Larkspur got there
The email from the German user arrived in March. By the following January the company was compliant, and the sequence is worth recording because it is the one most mid-sized companies will follow.
Months one and two — scoping and denial. The first internal reaction was that the regulation could not apply, because Larkspur has no European entity, no European employees, and no European revenue except through its storefront. That reaction is universal and wrong. Ferreira-Kwan's scoping memo ran four pages and reached the tier conclusion — hosting service, online platform, marketplace, not small, not very large — and the argument stopped.
Month three — the legal representative. Larkspur appointed a representative in Ireland, chosen deliberately after advice about which coordinators were most active and best resourced, and after confirming the representative could actually perform the function rather than serve as a mail drop. The points of contact were published on the site, in the terms, and in the help center, and routed to a monitored queue rather than an individual.
Months three to six — the terms rewrite. This took longer than expected because it required the company to describe what it actually does, and nobody had written that down. The moderation team had practices, a Slack channel, and institutional memory. Turning that into a published description of policies, procedures, tools, and algorithmic decision-making surfaced four practices the company decided to change rather than publish — which was, Ferreira-Kwan noted afterwards, the most valuable outcome of the entire project.
Months four to nine — the build. Notice and action intake. Statement-of-reasons generation wired into every enforcement action. The internal complaint system with a six-month window and human review. The transparency database submission pipeline. Trader onboarding and verification for 2,900 existing sellers, run as a staged re-verification rather than a cutover. Advertising labeling. A dark-patterns review that found two — a pre-checked box and a countdown timer that reset.
Month ten — the first transparency report. Short, accurate, and boring, which is what a first one should be.
What it cost: $610,000 to build, roughly $340,000 a year to run, and four months of the general counsel's attention.
What it bought, beyond compliance: a documented moderation process where there had been folklore, an appeals system that reduced angry-customer escalations by about a third, and a seller verification file that turned out to be exactly what the company's payment processor had been asking for.
Ferreira-Kwan's own summary: "We spent six hundred thousand dollars to write down what we were already doing, discovered we were doing four things we shouldn't, and ended up with a better product. I would not have volunteered for it. I would not undo it either."
What to tell the board
One: we are in scope, and scope does not depend on having European operations. It depends on offering the service to people in the Union.
Two: the tier determines the cost. Hosting service obligations are modest. Online platform obligations are substantial. Marketplace obligations add an onboarding rebuild. Very large online platform obligations are a different business entirely, and we are not there.
Three: the exposure ceiling is 6% of worldwide turnover under the DSA and 10% under the DMA. Nobody at our size is looking at those numbers today. What we are realistically looking at is an information request from a Digital Services Coordinator we cannot answer.
Four: the statement-of-reasons obligation makes our moderation decisions public. That is a communications and reputational fact, not only a legal one.
Five: the DMA gives us rights against the platforms we depend on. Somebody should own that file, and it is not a compliance job.
Six: if the European business is marginal, geo-blocking is a real option. It is not the recommendation here — 19% of users is not marginal — but a company with 2% European revenue and a thin margin should run the analysis before spending six figures.
Related documents
- Complying With the DSA and DMA: A Practical Guide
- DSA and DMA Readiness Checklist: A Practical Checklist
- EU Platform Regulation Toolkit: Notice Mechanisms, Reports, and Gatekeeper Obligations
- Section 230 and Platform Liability: What the Statute Actually Says and Where It Stops
- Running a Platform That Hosts User Content: A Practical Guide
- Platform Liability Toolkit: Terms of Service, Notice Procedures, and Litigation Defenses
This article is general information, not legal advice, and does not create an attorney-client relationship.
