▸ Terms and conditions – clear guidelines and procedures for moderating content need to be established, alongside easily accessible information concerning the right to terminate the use of the service. Moreover, users must also be notified of any significant changes to the terms and conditions;
▸Transparency reporting – publishing annual transparency reports on content moderation activities, including measures taken to apply and enforce the terms and conditions;
▸Takedown and disclosure orders – providers who receive orders to address illegal content must notify the appropriate national authorities of their actions taken in response to those orders, including whether and when they implemented the given instructions. This also applies to orders to provide information;
▸ Point of contact – appointing a single electronic point of contact for official communications with EU regulators and users. Such information needs to be easily accessible, as well as kept up to date;
▸EU legal representative for non-EU-based providers – such providers, as long as they offer their services to EU users, are required to designate a legal representative in the EU (similar to the EU representative concept under the GDPR). What is noteworthy here is the fact that this representative may also be held directly liable in case of failure to comply with the obligations under the DSA.
Specific Obligations On top of the above, there are several additional requirements for some categories of online intermediary service providers. ► Providers of hosting services have the following obligations:▸ Notice and action mechanisms – implementing effective mechanisms for content that users may consider to be illegal. These mechanisms should have a user-friendly design, be easily accessible and have the capability of submitting notices electronically;
▸ Takedown notifications and reasoning – users must be given a statement of reasons whenever hosting services delete or block access to content for moderation reasons or when they restrict payments, suspend or terminate the service/account;
▸ Reporting criminal offence suspicions – in case there is a reasonable suspicion about any serious criminal offences (g., threat to life or safety of persons), then hosting services providers are required to notify the national law enforcement or judicial authorities about it.
► There are some significant changes in regards to online platforms:▸Complaint-handling system – allowing recipients to exercise the right to lodge complaints, electronically and free of charge, against a decision made by the provider of the online platform. These internal complaint-handling systems must be easy to access, user-friendly and enable the submission of sufficiently precise and adequately substantiated complaints;
▸Dispute settlement – establishing mechanisms for out-of-court dispute settlement for any further disagreements concerning the decisions to delete or block access to the user’s content;
▸Trusted flaggers – the DSA introduces the concept of “trusted flaggers”, which are entities appointed by the competent local authorities that have particular expertise in detecting, identifying and notifying illegal content. Online platforms are required to give top priority to reports brought by these trusted flaggers;
▸Misuse – online platforms are to suspend, for a reasonable period of time and after having issued a prior warning, (i) the provision of their services to the users that frequently provide manifestly illegal content and (ii) the processing of notices and complaints submitted through the notice and action mechanisms and internal complaints-handling systems by users that frequently submit notices or complaints that are manifestly unfounded. Online platforms shall also establish in their terms and conditions their policy regarding such misuse;
▸Prohibition of dark patterns – “dark patterns” are practices that materially distort or impair, either on purpose or in effect, the ability of users to make autonomous and informed choices or decisions;
▸Additional transparency reporting obligations – besides the general transparency obligations that are incumbent on all online intermediary services providers, online platforms have several other obligations, such as reporting information on dispute settlements and the suspensions due to misuse of the service;
▸Advertising – users should be able to easily identify advertisements, as well as be provided with information regarding the advertising that is being displayed, including the entity that showcases or pays for that ad and the reasons why a certain ad was shown to them. Additionally, online platforms cannot display advertisements based on profiling, as defined under Article 4 point (4) of the GDPR, using special categories of personal data (g., political opinion, data concerning health or sexual orientation, racial or ethnic origin, etc.);
▸ Recommender system transparency – online platforms that use recommender systems are required to establish in their terms and conditions, in plain and intelligible language, the main parameters used in these recommender systems, as well as any options for the users to modify or influence those main parameters;
▸Protection of minors – the DSA established a general obligation to ensure a high level of privacy, safety and security for minors that use such services. Most importantly, online platforms are forbidden from targeting minors with advertisements based on profiling using personal data;
▸Tracking traders – when online platforms allow other traders to conclude contracts with consumers on their platform, they need to first certify the traders’ identity by obtaining basic information from them and then verifying it;
▸ Compliance by design – in addition to the above, online platforms must ensure that their online interfaces are designed and organised in a way that enables traders to comply with their own obligations pertaining to pre-contractual information, compliance and product safety information;
▸Right to information – in case online platforms become aware that an illegal product or service has been offered by a trader on their platform, they are required to inform the respective consumers about it.
► Finally, VLOPs and VLOSEs are subject to the most stringent obligations brought by the DSA, amongst others:▸ Systemic risks – VLOPs and VLOSEs are required to diligently identify, analyse and assess any systemic risks stemming from the design or functioning of their service and its related systems, including algorithmic systems, or from the use of their services. The DSA refers to the following potential systemic risks: dissemination of illegal content, risks related to fundamental rights, civil discourse, electoral processes, public security, as well as any negative effects in relation to gender-based violence, the protection of public health and minors and serious negative consequences to the person’s physical and mental well-being;
▸ Crisis response – the EC can order VLOPs and VLOSEs to apply specific, effective and proportionate measures in case of a crisis, such as where extraordinary circumstances lead to a serious threat to public security or public health;
▸More transparency requirements – the strictest transparency obligations are naturally conferred to VLOPs and VLOSEs, including those concerning annual independent audits, public advertising repositories, and transparency reporting every six months;
▸Recommender systems – in case VLOPs and VLOSEs use recommender systems, they must provide at least one option for each of their recommender systems which is not based on profiling;
▸Data access – VLOPs and VLOSEs shall allow regulators (DSCs or the Commission) to access their data in order to assess compliance with the DSA’s provisions. Moreover, they are required to also allow vetted researchers to access such data for the sole purpose of conducting research that contributes to the detection, identification and understanding of systemic risks;
▸Compliance function – VLOPs and VLOSEs are required to establish a compliance function, which is independent of their operational functions and composed of one or more compliance officers, including the head of the compliance function, who report directly to management;
▸Supervisory fee – VLOPs and VLOSEs will pay an annual supervisory fee, depending on the estimated costs of supervision incurred by the Commission. The overall amount of the annual supervisory fee does not, in any case, exceed 0,05% of the provider’s worldwide annual net income in the preceding financial year.