DSA tracker #10
Developments in enforcing the Digital Services Act
There are more and more developments regarding the implementation and enforcement of the DSA and more resources are available regarding the application of thes Regulation. In this newsletter, I summarize the most important events and news related to the application of the DSA.
Regulatory & enforcement actions
The Commission fined AliExpress €550 million for breaching the DSA.
What does this mean? “The European Commission fined AliExpress €550 million for breaching its obligations under the Digital Services Act (DSA) to diligently assess and mitigate risks relating to the sale of illegal, unsafe or counterfeit products on its e-commerce platform.”
What is the background to this? “AliExpress fell short of its obligation under the DSA to diligently assess the risk of dissemination of illegal, unsafe, or counterfeit products through its services in multiple ways:
AliExpress did not properly evaluate whether it had sufficient staff to review potentially illegal products. […]
AliExpress inadequately assessed how its recommender and advertising systems exacerbate the spread of illegal products. […]
AliExpress lacked quantitative metrics in its assessment. […]
AliExpress failed to take effective measures to reduce the risk of dissemination of illegal products. The Commission identified, in particular, the following shortcomings:
AliExpress’ system to detect illegal products did not work properly. […]
AliExpress did not properly enforce its penalty policy for traders selling illegal products. […]
AliExpress’ product compliance checks could be easily circumvented through mis-categorisation of products. […]
AliExpress failed to adequately prevent the spread of counterfeit products. […]”
What are the next steps? “[…] AliExpress now has until 20 October 2026 to submit an action plan to the Commission. The plan must set out measures to remedy the breach of its obligations to assess and mitigate systemic risks. The European Board for Digital Services will have one month from the receipt of the plan to issue its opinion. The Commission will then have a further month to adopt its final decision and set a reasonable period for implementation. Failure to comply with the non-compliance decision may lead to periodic penalty payments. The Commission continues to engage with AliExpress to ensure compliance with the decision and with the DSA more generally.”
The Commission preliminary found TikTok in breach of DSA for failing to ensure safe accounts for minors.
What does this mean? “The Commission preliminarily considers that TikTok – in line with the Guidelines on the protection of minors – should adjust the default settings of minors’ ‘public’ accounts, so that their content is, by default, visible only to TikTok users whom the minor has accepted. While older minors may have the option to share their content with a broader audience on TikTok, the content should under no circumstances be accessible to a global audience outside the platform. Moreover, TikTok should refrain from recommending minors’ content to other TikTok users through the For You Feed.”
What is the background to this? “On TikTok, minors can choose to set their account as ‘public’. This means that any user, including those without a TikTok account, may be able to view minors’ content. This setting also allows content published by ‘older’ minors (16-17 years old) to be recommended to any other TikTok user through the For You Feed. This exposure could result in unwanted contact from potential perpetrators and a risk that content can be used for cyberbullying. This feature potentially gives strangers a window into a child’s life. In addition, since what minors publish may stay online forever and follow them into adulthood, the feature comes with risks of potentially life-long consequences. Even when minors choose private accounts, their accounts can be easily found through the ‘following’ and ‘followers’ lists of other users, and their profile photos remain accessible to anyone, including users without a TikTok account. TikTok’s settings continue to expose them to risks – including unwanted contact, cyberbullying, or predatory behaviour.”
What are the next steps? “TikTok now has the possibility to examine the documents in the Commission’s investigation files and reply in writing to the Commission’s preliminary findings. In parallel, the European Board for Digital Services will be consulted. If the Commission’s views are ultimately confirmed, the Commission may issue a non-compliance decision, which can trigger a fine determined by the nature, gravity, recurrence, and duration of the infringement. The amount of the fine must be proportionate and shall in no case exceed 6% of a provider’s global annual turnover.”
The European Board for Digital Services published its second report in cooperation with the Commission pursuant to Article 35(2) DSA on the
most prominent and recurrent systemic risk as well as mitigation measures.
What does this mean? “The report identifies systemic risks - such as the spread of illegal content or threats to fundamental rights - occurring on very large online platforms. It also gives an overview of the mitigation measures taken by platforms to counter identified risks.”
What is the background to this? “Article 35(2) DSA sets out the requirement for the Board, in cooperation with the Commission, to publish comprehensive reports once a year. Article 35(2) DSA requires the identification and assessment of the most prominent and recurrent systemic risks in the Union and in the Member States, as well as best practices for their mitigation. This report is the second year’s edition of the Article 35(2) report. The first edition was adopted by the Board and published on 18 November 2025.”
What are the next steps? “The aim of this Article 35(2) report is to provide an overview of the most prominent and recurrent systemic risks that have been identified by the designated providers as stemming from their services, as well as by third-party stakeholders, such as academics, independent researchers, civil society organisations (“CSOs”), trusted flaggers and Out-of-Court Dispute Settlement Bodies (“ODSBs”), and an overview of certain risk mitigation practices. With regard to risk mitigation, this second edition, like the first one, focuses on reported practices without singling out any as “best” or “good” practice. Over time, and in light of accumulating experience with DSA implementation and enforcement in practice, future editions of this report will also aim to identify evolving best practices for the mitigation of systemic risks.”
The European Commission has accepted X’s action plan to comply with transparency obligations and researchers’ access to data, under the DSA.
What does this mean? “To provide a functional advertisement repository, in line with the standards required by the Digital Services Act, X committed to implement the following corrective measures:
Enhance the repository’s search functionality by introducing additional search filters, such as those based on ad content and targeting criteria.
Display search results directly on the interface of the ad repository rather than on separate Excels.
Improve the repository’s response speed reducing the response time from 200 seconds to the minimum time technically achievable.
Provide additional information about advertisements, including the full content of the advertisement and the URLs to which advertisements redirect users.
Enable access to the repository via an API.
Regarding the breaches concerning the obligation to grant researchers access to public data, X will take the following corrective measures:
Revise and improve its screening process for applications by researchers to access its public data via its API, ensuring eligible researchers are not excluded in error.
Provide eligible researchers with access to data free-of-charge.
Ensure timely access for eligible researchers, including to the appropriate volumes of data. X commits to reduce significantly the processing time for researcher applications, including by avoiding unnecessary exchanges with applicants.
Update its terms and conditions to explicitly state that eligible researchers are not contractually prohibited from scraping publicly available data.”
The European Commission preliminarily found Meta in breach of the DSA for the addictive design of Instagram and Facebook. The investigation focuses on features such as infinite scroll, autoplay, push notifications, and the platforms' highly personalised recommender systems.
What does this mean? “Risk assessment: The Commission’s investigation indicates that Meta did not adequately assess the risks of its addictive design on the physical and mental wellbeing of users, including minors and vulnerable adults. For example, Meta did not consider certain design features of Instagram and Facebook, such as highly personalised recommendations, autoplay and infinite scroll, which constantly show users new content. These features fuel the user’s urge to keep scrolling and shift the brain into ‘autopilot mode’, contributing to unhealthy habits and compulsive use. Moreover, Meta disregarded available information about the time minors spend on Instagram or Facebook at night and how the optimisation of its different formats - such as reels and stories - could lead to excessive or compulsive use of the services.”
“Risk mitigation measures: Evidence also shows that Meta’s current mitigation measures failed to effectively tackle the risks stemming from its addictive design. For example, Instagram’s and Facebook’s time management tools, including those activated by default for teens, can be easily dismissed and do not lead to a meaningful reduction and control of the usage of the service. Moreover, the Commission considers that Meta’s parental controls are only effective if parents and guardians possess adequate technical expertise, as well as devote effort and time to understand them effectively. This undermines the efficiency of such measures in addressing the inherent risks posed by Instagram and Facebook’s addictive design.
Meta’s awareness-raising measures, such as tips and links to mental health resources available via a separate ‘safety centre’ page, do not seem to sufficiently mitigate the risk of addictive design on Facebook and Instagram. At this stage of the investigation, the Commission considers that Meta needs to implement design changes to both Instagram and Facebook. For instance, by disabling key addictive features such as ‘autoplay’ and ‘infinite scroll’ by default, implementing effective ‘screen time breaks’, and adapting its recommender system to make it less engagement-oriented.”
What is the background to this? “The Commission’s preliminary findings today are part of its formal proceedings to investigate Meta’s compliance with the Digital Services Act, launched on 16 May 2024. […] This investigation also covers concerns about the age assurance measures Meta has put in place for minors below 13 years old, for which preliminary findings were adopted on 29 April 2026. Separately, the Commission continues its investigation into so-called ‘rabbit hole’ effects caused by the design of Facebook’s and Instagram’s recommender systems, which may exploit minors’ vulnerabilities and inexperience.”
What are the next steps? “Meta now has the possibility to exercise its right to defence. It may examine the documents in the Commission’s investigation files and reply in writing to the Commission’s preliminary findings. In parallel, the European Board for Digital Services will be consulted. If the Commission’s views are ultimately confirmed, the Commission may issue a non-compliance decision, which can trigger a fine proportionate to the nature, gravity, recurrence and duration of the infringement, capped at 6% of the total worldwide annual turnover of the provider.”
Guidelines, opinions, reports & more
The European Commission has published the final report of the Special Panel on Child Safety Online.
What does this mean? Recommendations on age-appropriate use of social
media and other digital services:
Source: Child safety online, p. 17
Recommendations to protect children and adolescents online:
Propose a harmonised EU-wide access restriction to social media and other digital services for children under 13.
Introduce effective age-assurance systems to check age and underpin safety-by design and age-appropriate approaches to protect and empower minors online.
Extend and harmonise rules on key safety features in the design of social media and other digital services.
Shift the burden of proof to social media and other digital services providers to demonstrate that their products and services are safe for minors.
Strengthen enforcement and evaluation capacities.
Swiftly adopt measures to ensure social media and other digital services providers have clear obligations to prevent, detect, report and block child sexual abuse online, including in interpersonal communication.
Member States can introduce additional precautionary access restrictions to social media and other digital services as of 13.
Strengthen the enforcement of rules on researchers’ access to and scrutiny of data.
Recommendations to empower children and adolescents online:
Expand safe opportunities for minors to actively participate in shaping the social media+ environment.
Strengthen complaint mechanisms and consumer rights for children and adolescents.
Mainstream digital education and literacy actions for minors, parents and caregivers, teachers and educators.
Create more opportunities and adequate infrastructure to support offline activities.
Promote the co-creation of Guidelines for Parents.
Ensure sufficient public funding and common standards for civil society organisations and peer counselling.
Make available long-term funding for European large-scale longitudinal research and continue supporting randomised control trials.
What is the background to this? “The panel has brought together young people and experts from across the EU, including in health, neuroscience, psychology, computer science, child rights, and digital literacy. From March to June 2026, the panel met three times to explore both the opportunities and the risks of children spending time online. Discussions looked at how to better support parents and caregivers, while highlighting key lessons and good practices from across the EU and beyond.”
The DSA Observatory published an analysis, “Platform Governance and Technology-Facilitated Gender-Based Violence: Positioning the DSA in the EU’s Legal Framework”
What is it about? “This post examines technology-facilitated gender-based violence (TFGBV) as a systemic phenomenon shaped by platform design and cross-platform ecosystems, and maps the main EU legal instruments available to address it. It argues that while the Digital Services Act’s systemic risk framework is particularly well suited to tackling the structural drivers of TFGBV, its promise has yet to be realised in practice through implementation and enforcement.”
The bff (Federal Association of Women’s Counselling Centres and Women’s Emergency Hotlines in Germany) published a policy paper on the Digital Services Act and Digital Gender-Based Violence. (The policy paper is in German.)
What is it about? “Platforms decide on a daily basis how visible violence is – and how well those affected are protected. Our new policy paper shows how large online platforms have so far failed to adequately implement their obligations under the Digital Services Act (DSA) when it comes to (digital) gender-based violence. On the basis of the risk analyses according to Art. 34 DSA of platforms such as Instagram, TikTok, Snapchat, Pornhub and XVideos, we analyse key protection gaps in risk analyses, reporting channels and contact points. We show why gender-based violence is systematically trivialized, how manipulative designs prevent those affected from reporting – and why violence in the social environment continues to remain invisible. The paper formulates concrete, feminist recommendations on Art. 12, 16, 34 and 35 DSA: for binding standards, intersectional risk analyses and reporting channels that are actually easily accessible.”
Further DSA resources

