The Digital Services Act is the EU law that governs the responsibility of online intermediaries for the content they host or transmit. It is known by its acronym, DSA, and is Regulation (EU) 2022/2065. It has applied in full since 17 February 2024. Coverage always talks about Meta, TikTok or Amazon, which is why many Spanish companies believe it does not affect them. It does. The DSA reaches any provider of intermediary services, from web hosting to an online shop with a comments section. Obligations build up in tiers, and the first tier is lower than people assume.
If you need digital law advice for your business, request a free initial assessment.
The DSA applies to intermediary services offered to recipients established in the European Union, wherever the provider is based. The test is the type of service, not the size of the company or its turnover. A self-employed person running a forum falls within its scope just like a multinational.
What changes with size and function is the number of obligations. The regulation organises them into four cumulative tiers, so each category meets its own obligations plus all those of the tiers before it.
| Category | Who is in it | Burden |
|---|---|---|
| Intermediary services | Internet access, domain name registrars, content delivery networks | Basic obligations |
| Hosting services | Hosting, cloud, anyone storing information provided by others | Basic obligations plus notice and action |
| Online platforms | Marketplaces, social networks, app stores, open forums | All of the above plus complaint handling and advertising transparency |
| Very large online platforms and search engines | More than 45 million monthly users in the Union | All of the above plus systemic risks and audits |
Most Spanish companies sit in the second or third tier without knowing it.
Four duties apply to every provider, whatever its size. They are the most overlooked because they require diligence rather than technology, and for that very reason they are the first thing an authority checks.
Every provider must designate a single point of contact and publish it in an accessible way, so that both authorities and users can reach it. A generic form buried in the footer will not do.
If the company is outside the European Union but offers services within it, it must also appoint a legal representative in a Member State. That representative can be held liable for breaches of the regulation, which makes the appointment a decision with consequences that should not be taken lightly.
The terms of service must explain clearly any restriction imposed on users’ information, including content moderation policies and any algorithmic decision-making tools used. Vague wording is no longer enough.
On top of that comes a public annual report on moderation activity, with the number of orders received from authorities and of complaints handled. Micro and small enterprises are exempt from this report, which is the first significant exemption in the regulation.
Hosting services take on the notice and action mechanism. Anyone must be able to report allegedly illegal content through a simple electronic channel, and the provider has to process that notice and decide in a diligent, non-arbitrary way.
When content is removed or restricted, the person affected must receive a statement of reasons explaining the decision and the available means of redress. And if a provider becomes aware of a suspected criminal offence threatening someone’s life or safety, it must inform the authorities.
An online platform is a hosting service that also disseminates the information it stores to the public. Marketplaces, social networks and open forums fall into this category. The obligations increase considerably.
This is where the most important exemption comes in. Micro and small enterprises are released from these online platform obligations, although they remain subject to those for intermediaries and hosting services. The exemption falls away if the company grows. If you run a marketplace, the detail on trader traceability is in our guide to e-commerce regulations in Spain.
Article 28 adds a specific duty for services accessible to minors: to put in place proportionate measures ensuring a high level of privacy, safety and security. What this requires today, and what may come with the European proposal and a future Spanish organic law, is covered in protecting minors in digital environments.
Spain designated the National Markets and Competition Commission (CNMC) (in Spanish) as its Digital Services Coordinator in January 2024, but the CNMC currently has no power to impose penalties under the DSA. The rule that gave it those powers was repealed, and the attempt to restore them failed in the Spanish Parliament.
| Date | Milestone |
|---|---|
| 24 January 2024 | The Ministry for Digital Transformation designates the CNMC as Digital Services Coordinator |
| 17 February 2024 | The DSA applies in full |
| 16 December 2024 | The European Commission issues a reasoned opinion against Spain for non-compliance |
| 23 December 2024 | Royal Decree-Law 9/2024 gives the CNMC the penalty regime |
| 22 January 2025 | The Spanish Congress overturns that royal decree-law |
| 14 April 2026 | The Spanish Congress rejects the bill that would have restored those powers, by 174 votes to 163 |
It is worth being clear about what this means. The regulation is directly applicable and your obligations have existed since February 2024. What is missing is the national enforcement arm, not the obligation. The European Commission keeps exclusive competence over very large platforms and has already opened proceedings against Spain.
It is the third case in a row of the same pattern. It is happening with the NIS2 Directive, which has not been transposed, and with the Cyber Resilience Act, whose royal decree designating the authorities is still being processed. A company that mistakes the absence of a supervisor for the absence of an obligation is building up documented breaches that someone will review once the supervisor exists.
On 31 August 2026 the European Commission designated ChatGPT as a very large online search engine, and Reddit and Roblox as very large online platforms. All three reported more than 45 million average monthly users in the European Union. They have four months to comply, that is, until January 2027.
From then on they must assess and mitigate the systemic risks of their services relating to the spread of illegal content, minors, physical and mental well-being, fundamental rights, electoral processes and public security. An independent annual audit and opening their algorithmic systems to researchers are part of the package.
For your company the designation changes nothing directly. It does show where the Commission is looking, and that the 45 million threshold is also being applied to services that are not classic social networks.
If you store and publicly disseminate information uploaded by others, you are a hosting service and probably an online platform. The point of contact, clear terms and conditions and the notice and action mechanism apply to you. If you are a micro or small enterprise, you are exempt from the specific online platform obligations.
The EU definition applies. A microenterprise has fewer than 10 employees and a turnover or balance sheet total not exceeding 2 million euros. A small enterprise has fewer than 50 employees and does not exceed 10 million. Crossing the threshold ends the exemption.
No, because it has not been given the penalty regime. That does not make non-compliance harmless. The obligations are enforceable, can be relied on in civil or commercial litigation, and the situation changes as soon as the pending legislation is passed.
The regulation sets a maximum of 6% of the provider’s annual worldwide turnover. Supplying incorrect or misleading information is capped at 1%. There are also periodic penalty payments of up to 5% of average daily turnover.
If your company hosts third-party content, runs a marketplace or manages a user community, it is worth checking which DSA tier you are in and what is missing. Innovatech is a technology law firm and can carry out that assessment for you. Tell us about your case and we will review it.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
