The Digital Services Act (DSA): what your platform owes
If users upload content to your service or sell through it, the DSA already applies to you. Which duties bind a small startup, which don't - and who has enforced them in Bulgaria since November 2025.
If users can upload photos, listings or comments, or sell something through your product, you are already subject to one of the EU's most extensive regulations - not once you grow, but now.
Regulation (EU) 2022/2065 - the Digital Services Act, or DSA - has applied to all intermediary service providers since 17 February 2024. It is a regulation, not a directive: obligations apply directly, with no need for a transposition act. National law only had to name the supervisor and the penalties - Bulgaria did so late, in November 2025.
The good news for startups: the DSA is built in tiers, and its heaviest duties reach only the largest players. The bad news: the baseline rules apply to everyone, including a two-person team, and most founders don't know which tier they are in.
The timeline: where we are
| Date | What happened | Basis |
|---|---|---|
| 16 November 2022 | The regulation enters into force | Art. 93(1) |
| 17 February 2023 | Online platforms first publish their active user counts | Art. 24(2) |
| 17 February 2024 | Full application to all intermediaries | Art. 93(2) |
| 17 February 2025 | The 12-month window to collect data from existing marketplace traders closes | Art. 30(2) |
| 1 July 2025 | Uniform report templates become mandatory | Regulation (EU) 2024/2835 |
| 21 November 2025 | Amendments to the Electronic Communications Act published (State Gazette issue 99) | SG 99/2025 |
| Late November 2025 | The Bulgarian act enters into force; the CRC becomes Digital Services Coordinator | Art. 21(6) ECA |
Which tier you are in
The DSA allocates duties by what you do with users' content. Each higher tier carries the duties of the tiers below it, plus its own.
| Tier | What it does | Examples | Basis |
|---|---|---|---|
| Mere conduit | Transmits data over a network without initiating the transmission, selecting the recipient or modifying content | ISPs, VPNs, public Wi-Fi | Art. 4 |
| Caching | Automatic, intermediate and temporary storage solely to speed up onward transmission | CDNs, caching proxies | Art. 5 |
| Hosting | Stores information at a user's request without disseminating it to the public | B2B SaaS, CRM/ERP, invoicing, cloud storage, private code repositories | Art. 6 |
| Online platform | Hosting that, at a user's request, disseminates the information to a potentially unlimited number of people | Marketplaces, classifieds, forums, social apps, public template catalogues | Art. 3(i) |
| Very large online platform or search engine (VLOP/VLOSE) | An online platform/search engine with 45 million+ average monthly active recipients in the EU, designated by the Commission | Global platforms | Art. 33 |
The line that matters for most startups is between hosting and platform: is uploaded content visible outside the customer's own circle? If public dissemination is only a minor, purely ancillary feature of another main service, the service is not treated as an online platform.
The VLOP/VLOSE tier does not apply to virtually any reader of this article. The threshold is 45 million active recipients in the EU - roughly 10% of the Union's population - and the risk assessments, audits and ad repositories apply only after an express Commission designation. No Bulgarian startup is near that threshold, so we don't cover it further.
A note on terms: an "intermediary service" and "hosting" under the DSA are not the same as "data intermediation" or the cloud-switching rules under the Data Act - a separate regime, covered in our EU Data Act article.
If you are outside the EU - or your customers are
The DSA applies where a service has a "substantial connection" to the EU. A startup targeting only third countries, and technically excluding EU users, does not apply the substantive moderation rules to them. The reverse also holds: a non-EU provider targeting Bulgaria (a Bulgarian interface, euro payments, local advertising) must designate a legal representative in writing in a Member State (Art. 13), who can be held liable for breaches.
The small-enterprise exemption - and where it stops
For DSA purposes a small enterprise has fewer than 50 staff and an annual turnover or balance sheet total under EUR 10 million (Recommendation 2003/361/EC), with three separate reliefs - this is exactly where most mistakes happen, in both directions:
| What | Are micro and small enterprises exempt? | Basis |
|---|---|---|
| Annual transparency reports | Yes, unless a VLOP | Art. 15(2) |
| Additional online platform duties (complaints, out-of-court disputes, trusted flaggers, dark patterns, advertising, recommender systems, minors) | Yes, except Art. 24(3) | Art. 19(1) |
| Marketplace duties (trader traceability, compliance by design, right to information) | No - apply to every marketplace | Art. 29(1); Arts. 30–32 |
| Points of contact, terms and conditions, notices, statements of reasons, reporting criminal offences | No - these apply to everyone | Arts. 11–18 |
Two details that are often missed:
- VLOP status overrides everything - a platform designated as very large owes the full set of duties, whatever the company's headcount.
- The six-monthly count under Art. 24(2) doesn't fall away - even a small platform owes it, and on request must give the CRC or the Commission further data under Art. 24(3).
The duties that apply to every intermediary
Regardless of size or tier:
- A point of contact for authorities (Art. 11) - an electronic channel for the CRC, other national authorities, the Commission and the European Board for Digital Services, stating at least one official language of the Member State of establishment.
- A point of contact for users (Art. 12) - fast communication that does not rely solely on automated tools.
- Terms and conditions (Art. 14) - every content restriction and moderation tool, including algorithmic decision-making, human review and the internal complaint system, in clear, unambiguous, public and machine-readable language. For a service aimed at Bulgaria, a Bulgarian version is required; for one aimed mainly at minors, the terms must be explained so they understand them.
- Compliance with orders (Arts. 9 and 10) - orders from courts and administrative authorities against illegal content or for information.
- An annual transparency report (Art. 15) - unless you are a micro or small enterprise; since 1 July 2025, on the uniform machine-readable templates in Implementing Regulation (EU) 2024/2835.
Mere conduit and caching stop here - neither owes the Art. 16 notice mechanism.
Hosting: notices, decisions and the liability shield
The liability shield (Arts. 6 and 7)
A hosting provider is not liable for third-party content if it has no actual knowledge it's illegal and, once it becomes aware, acts expeditiously to remove or disable it. Article 7 adds the "Good Samaritan" rule: voluntary checks or tools that detect illegal content don't cost you this protection.
In Bulgaria, the old liability regime in Chapter Four of the Electronic Commerce Act (Arts. 13–18) was repealed by the same November 2025 act. The Electronic Commerce Act's rules on pre-contractual information, commercial communications and concluding electronic contracts still apply alongside the DSA.
The notice mechanism (Art. 16)
Every hosting provider, including a SaaS with no public part, needs an easy electronic mechanism for anyone to flag illegal content. The form allows submission of:
| Element | Basis |
|---|---|
| An explanation of why the content is illegal | Art. 16(2)(a) |
| The exact electronic location (URL) | Art. 16(2)(b) |
| The notifier's name and email (not required for notices about child sexual abuse material) | Art. 16(2)(c) |
| A statement of good faith | Art. 16(2)(d) |
A notice containing these elements gives rise to actual knowledge under Art. 6 where it lets a diligent provider identify the illegality without a detailed legal examination - from that moment, the liability-shield clock is running.
The workflow:
- Intake - the form validates the mandatory fields.
- Confirmation - without undue delay, if the notifier left an email, with a ticket number.
- Triage - an urgent queue for child sexual abuse material and terrorist content; a priority queue for trusted flaggers; a standard queue for the rest.
- Review and decision - timely, non-arbitrary and objective. The regulation sets no deadline in hours; 24 to 72 hours for ordinary notices is a working estimate from practice, not a legal requirement.
- Notification - the notifier learns the decision and the redress options, including whether automated means were used.
- Archive - input data, response time and decision, so you can report on your activity.
The statement of reasons (Art. 17)
Every restriction imposed because content is illegal or breaches your terms needs a clear, specific statement of reasons to the affected user (where you have their details) - for removal, disabling, demotion, suspension of payments, suspension of the service or account termination.
The statement contains at least:
- the measure, its territorial scope and duration;
- the facts - including whether the decision followed a notice or your own initiative;
- whether automated means were used;
- the legal ground and why the content is illegal, or the terms clause and why it was breached;
- redress information - internal complaint, out-of-court settlement and the courts, as applicable.
The most common failure here is a generic "you broke our rules" with no specific fact and no specific clause.
Reporting to the authorities (Art. 18)
If you learn of information giving rise to a suspicion of a criminal offence against someone's life or safety, you must promptly inform the law enforcement or judicial authorities of the Member State concerned - in Bulgaria, in practice, the Chief Directorate for Combating Organised Crime (GDBOP), or, if you can't identify it, the authorities where you are established, or Europol.
Online platforms above the small-enterprise threshold
A medium or large enterprise? The duties in Arts. 20-28 come on top of the above.
| Duty | What it means | Basis |
|---|---|---|
| Internal complaint system | Free and electronic; available for at least 6 months from notice of the decision; not by automated means alone | Art. 20 |
| Out-of-court settlement | Information about certified bodies, good-faith engagement, non-binding decisions | Art. 21 |
| Trusted flaggers | Their notices processed with priority and without undue delay | Art. 22 |
| Misuse | Suspension, after a warning, of frequent offenders - manifestly illegal content or manifestly unfounded notices | Art. 23 |
| Extra transparency | Disputes, suspensions, automated moderation in the annual report; statements of reasons in the Commission's database, no personal data | Art. 24 |
| Dark patterns | A ban on interfaces that deceive or manipulate | Art. 25 |
| Advertising | Transparency for every ad; a ban on profiling with special-category data | Art. 26 |
| Recommender systems | Main parameters set out in the terms | Art. 27 |
| Minors | A high level of privacy and safety; no profiling-based ads | Art. 28 |
Complaints and out-of-court disputes
Both the affected user and the notifier can complain; splitting complaints by type - content, accounts, payments, monetisation - helps, since timelines and evidence differ. The CRC certifies out-of-court dispute bodies - and in another Member State.
Dark patterns
Article 25 bans interfaces that deceive, manipulate or otherwise impair users' free choice - giving one option more prominence, repeatedly asking about a choice already made, making cancellation harder than signing up. Dedicated Article 25 guidelines still don't exist.
In practice, a misleading subscription button or cookie banner can be pursued both under Art. 25 of the DSA and under Arts. 68c-68k of the Bulgarian Consumer Protection Act. Cookie rules and the contract withdrawal button are covered in our B2C compliance checklist.
Advertising and recommender systems
For every ad, users must see in real time that it's an ad, on whose behalf, who paid for it (if different), and the main targeting parameters, with a way to change them. Users must also be able to declare their own content as a commercial communication.
Two absolute bans: ads based on profiling using special categories of personal data under Art. 9 GDPR (Art. 26(3)), and profiling-based ads to users known with reasonable certainty to be minors (Art. 28(2)). GDPR consent doesn't lift the first ban.
If you rank content with an algorithm, your terms must explain the main parameters - the most significant criteria, why they carry that weight, and how users can change them; with several ranking options, the choice must be directly available from the relevant part of the interface.
Separately, the AI Act requires transparency for chatbots and generated content (Art. 50) - see our AI Act article.
Minors
Platforms accessible to minors owe a high level of privacy, safety and security (Art. 28 guidelines, C/2025/5519). The regulation expressly does not require processing additional personal data to assess age (Art. 28(3)). The choice of age-assurance technology - a third-party provider, device-level signals, cryptographic proofs disclosing no data - remains a grey area; the EDPB (guidelines 3/2025) advises against mass collection of ID copies and calls for a data protection impact assessment.
Marketplaces: trader traceability
If your platform lets consumers conclude distance contracts with traders, Arts. 30–32 apply - regardless of size. The Art. 19 exemption for micro and small enterprises doesn't reach here: Section 4 of the DSA binds every marketplace, without exception.
| Duty | What it requires | Basis |
|---|---|---|
| Trader data before access | Name, address, phone, email; ID document or electronic identification; payment account details; trade register and number | Art. 30(1) |
| Verification | Best efforts using official databases - Commercial Register validity, VAT number via VIES, IBAN holder name matching the trader - or supporting documents from the trader | Art. 30(2) |
| Existing traders | The deadline to collect their data passed on 17.02.2025; no data means suspension | Art. 30(2) |
| Inaccurate data | Request a correction; if ignored, suspend swiftly | Art. 30(3) |
| Retention | 6 months after the contract with the trader ends, then delete | Art. 30(5) |
| Visibility to buyers | The trader's name, address and registration - at least on the product page | Art. 30(7) |
| Compliance by design | The interface lets traders provide mandatory information; random checks of whether products are flagged as illegal | Art. 31 |
| Right to information | Notify buyers from the past 6 months about an illegal product; if you lack their contact details, a public notice | Art. 32 |
The regulation sets no percentage or frequency for random checks - the methodology remains a grey area. An example from practice: weekly automated scanning of 3-5% of new listings against a list of risk keywords (counterfeits, dangerous ingredients, missing CE marking), plus checks against Safety Gate for dangerous non-food products, with an electronic record of every check.
The Art. 32 notice says three things: that the product or service is illegal, who the trader is, and what redress is available.
The DSA and the GPSR are not the same thing
Marketplace duties under the General Product Safety Regulation (GPSR) - a point of contact, Safety Gate registration and removing dangerous products within 2 working days of an order - are a separate regime for physical goods, covered in our B2C compliance checklist; it applies alongside Arts. 30–32 of the DSA, not instead of them.
Typical cases
SaaS with user-generated content. Closed workspaces are hosting; public galleries, forums and template catalogues are a platform. Separate them architecturally: a report button under public content, spam/malware scanners described in the terms, statement-of-reasons templates ready. Grey area: suspension for non-payment and Art. 17.
Freelance and booking platforms. Marketplaces for services: verify providers under Art. 30 (incl. Tourism Act registration for categorised properties); a statement of reasons for escrow holds; disclose ranking factors. Holding funds also needs to square with the Payment Services and Payment Systems Act.
Mobile app with community features. A "Report" button, statements of reasons for blocking; above the threshold - internal complaints, no profiling-based ads to minors. Whether gamification and notifications count as manipulative design is an open question.
News site with comments. Editorial content isn't an intermediary service; comments are usually ancillary (Recital 13) - but for them the site is a hosting provider, owing a notice mechanism and swift removal.
AI platform. Personal use is hosting; a public sharing community is a platform. Filters are described in the terms (Art. 14). AI Act requirements are separate - see our AI Act article.
Crypto and fintech. MiCA for financial services, DSA for social features - chats, profiles, investment discussion. MiCA's perimeter is covered in our crypto regulation article.
App or plugin store. A marketplace for digital content: verify developers, run random checks, notify users about a compromised plugin.
Who supervises in Bulgaria
The national framework passed the National Assembly on 6 November 2025 and was published in State Gazette issue 99 of 21 November 2025; it entered into force three days later - late against the 17 February 2024 deadline, after the Commission had already opened infringement proceedings against Bulgaria.
| Authority | Remit | Basis |
|---|---|---|
| Communications Regulation Commission (CRC) | Digital Services Coordinator; supervises all intermediaries except video-sharing platforms; dark patterns and recommender systems for all; certifies out-of-court bodies and trusted flaggers; inspections and penalties | Arts. 21(6) and 49g ECA |
| Council for Electronic Media (CEM) | Video-sharing platforms - excluding Arts. 25 and 27 | Art. 49g(3) ECA |
| Commission for Personal Data Protection (CPDP) | Personal-data processing under the DSA - profiling-based advertising and protection of minors | Art. 49g(4) ECA |
| Consumer Protection Commission (CPC) | Not a DSA authority, but pursues unfair commercial practices under the Consumer Protection Act - including misleading interfaces | CPA |
Any user can complain to the CRC; where the case belongs to the CEM or the CPDP, the CRC forwards it. The two proceedings can run in parallel: for a dark pattern in a subscription flow, the CPC can fine up to BGN 50,000 (≈EUR 25,565, roughly - no new euro equivalent) under Art. 68c of the Consumer Protection Act, while the CRC investigates a parallel Art. 25 breach.
What is the real risk? To date, the CRC has publicly announced no penalties against local platforms. The research behind this article assesses that in 2025-2026 the CRC is focused on serious breaches, the trusted-flagger register and cross-border cooperation - broad inspections of small startups without complaints are unlikely. An assessment, not a guarantee: one complaint is enough to start a review.
Penalties
The Bulgarian act sets no fixed euro amounts; it mirrors the regulation's percentage caps:
| Breach | Maximum | DSA basis | ECA basis |
|---|---|---|---|
| Failure to comply with a DSA obligation | 6% of worldwide annual turnover in the preceding financial year | Art. 52(3) | Art. 323f(1) |
| Information not supplied, incorrect or misleading; refusal of an on-site inspection | 1% of annual income or worldwide turnover | Art. 52(3) | Art. 323f(2) |
| Periodic penalty for continuing non-compliance | Up to 5% of average daily worldwide turnover per day | Art. 52(4) | Art. 323f(4) |
The amount depends on the gravity, duration and mitigating or aggravating circumstances. The CRC can also temporarily restrict access, but only through the courts.
The largest penalties so far have come from the Commission against very large platforms - EUR 120 million for X (December 2025), EUR 200 million for Temu (May 2026) and EUR 550 million for AliExpress (July 2026). They don't touch startups directly, but show regulators' focus: deceptive design, advertising transparency and illegal marketplace products.
Checklist by startup type
I run B2B SaaS or hosting
- Do you have a public point of contact for authorities and users?
- Do your terms describe moderation, automated tools and human review?
- Is there a notice mechanism with the four Art. 16 elements?
- Is a statement-of-reasons template ready for Art. 17?
- Does the team know when and how to alert GDBOP under Art. 18?
I run an online platform or a community app
- Everything above, plus a report button under public content.
- Micro or small enterprise? Document it and track when you'll lose that status.
- Do you count active recipients every six months so you can supply them on request?
- Above the threshold: internal complaints with human review, ad transparency, ranking parameters in your terms, no profiling of minors.
I run a marketplace
- Do you collect and verify trader data before activation - whatever your size?
- Do you show the trader's details on the product page?
- Do you have a process for random checks and notifying buyers from the past 6 months?
- Selling physical goods? Then the GPSR applies whatever your size.
I'm based outside the EU but sell into Bulgaria
- Have you designated a legal representative in writing in a Member State and notified the coordinator?
The DSA is rarely breached by one big decision - it's breached by a form missing a mandatory field, an account suspended without explanation, an interface designed to sell rather than inform. All of that is cheap to fix while you're small, and expensive after the first complaint.
This article is general information current as of September 2026, not individual legal advice. The percentage penalty caps have been checked against the text of Regulation (EU) 2022/2065 and the amendments to the Electronic Communications Act (State Gazette issue 99/2025). The Bulgarian act sets no fixed euro amounts, so this article gives none for DSA breaches themselves; at the time of writing there is no publicly announced CRC penalty practice. The Consumer Protection Act figure quoted (BGN 50,000) remains in leva in the statutory text and has been converted at the fixed peg - no new euro equivalent has been set. The exact entry-into-force date of the act and the methodology for marketplace random checks remain unsettled - check the CRC's current position before relying on them.