Back to blog
Startup lawComplianceEU regulation

The Digital Services Act (DSA): what your platform owes

If users upload content to your service or sell through it, the DSA already applies to you. Which duties bind a small startup, which don't - and who has enforced them in Bulgaria since November 2025.

Vladimir Toshev(Co-founder · Legal research)16 min read
Share

If users can upload photos, listings or comments, or sell something through your product, you are already subject to one of the EU's most extensive regulations - not once you grow, but now.

Regulation (EU) 2022/2065 - the Digital Services Act, or DSA - has applied to all intermediary service providers since 17 February 2024. It is a regulation, not a directive: obligations apply directly, with no need for a transposition act. National law only had to name the supervisor and the penalties - Bulgaria did so late, in November 2025.

The good news for startups: the DSA is built in tiers, and its heaviest duties reach only the largest players. The bad news: the baseline rules apply to everyone, including a two-person team, and most founders don't know which tier they are in.

The timeline: where we are

DateWhat happenedBasis
16 November 2022The regulation enters into forceArt. 93(1)
17 February 2023Online platforms first publish their active user countsArt. 24(2)
17 February 2024Full application to all intermediariesArt. 93(2)
17 February 2025The 12-month window to collect data from existing marketplace traders closesArt. 30(2)
1 July 2025Uniform report templates become mandatoryRegulation (EU) 2024/2835
21 November 2025Amendments to the Electronic Communications Act published (State Gazette issue 99)SG 99/2025
Late November 2025The Bulgarian act enters into force; the CRC becomes Digital Services CoordinatorArt. 21(6) ECA

Which tier you are in

The DSA allocates duties by what you do with users' content. Each higher tier carries the duties of the tiers below it, plus its own.

TierWhat it doesExamplesBasis
Mere conduitTransmits data over a network without initiating the transmission, selecting the recipient or modifying contentISPs, VPNs, public Wi-FiArt. 4
CachingAutomatic, intermediate and temporary storage solely to speed up onward transmissionCDNs, caching proxiesArt. 5
HostingStores information at a user's request without disseminating it to the publicB2B SaaS, CRM/ERP, invoicing, cloud storage, private code repositoriesArt. 6
Online platformHosting that, at a user's request, disseminates the information to a potentially unlimited number of peopleMarketplaces, classifieds, forums, social apps, public template cataloguesArt. 3(i)
Very large online platform or search engine (VLOP/VLOSE)An online platform/search engine with 45 million+ average monthly active recipients in the EU, designated by the CommissionGlobal platformsArt. 33

The line that matters for most startups is between hosting and platform: is uploaded content visible outside the customer's own circle? If public dissemination is only a minor, purely ancillary feature of another main service, the service is not treated as an online platform.

The VLOP/VLOSE tier does not apply to virtually any reader of this article. The threshold is 45 million active recipients in the EU - roughly 10% of the Union's population - and the risk assessments, audits and ad repositories apply only after an express Commission designation. No Bulgarian startup is near that threshold, so we don't cover it further.

A note on terms: an "intermediary service" and "hosting" under the DSA are not the same as "data intermediation" or the cloud-switching rules under the Data Act - a separate regime, covered in our EU Data Act article.

If you are outside the EU - or your customers are

The DSA applies where a service has a "substantial connection" to the EU. A startup targeting only third countries, and technically excluding EU users, does not apply the substantive moderation rules to them. The reverse also holds: a non-EU provider targeting Bulgaria (a Bulgarian interface, euro payments, local advertising) must designate a legal representative in writing in a Member State (Art. 13), who can be held liable for breaches.

The small-enterprise exemption - and where it stops

For DSA purposes a small enterprise has fewer than 50 staff and an annual turnover or balance sheet total under EUR 10 million (Recommendation 2003/361/EC), with three separate reliefs - this is exactly where most mistakes happen, in both directions:

WhatAre micro and small enterprises exempt?Basis
Annual transparency reportsYes, unless a VLOPArt. 15(2)
Additional online platform duties (complaints, out-of-court disputes, trusted flaggers, dark patterns, advertising, recommender systems, minors)Yes, except Art. 24(3)Art. 19(1)
Marketplace duties (trader traceability, compliance by design, right to information)No - apply to every marketplaceArt. 29(1); Arts. 30⁠–⁠32
Points of contact, terms and conditions, notices, statements of reasons, reporting criminal offencesNo - these apply to everyoneArts. 11⁠–⁠18

Two details that are often missed:

  • VLOP status overrides everything - a platform designated as very large owes the full set of duties, whatever the company's headcount.
  • The six-monthly count under Art. 24(2) doesn't fall away - even a small platform owes it, and on request must give the CRC or the Commission further data under Art. 24(3).

The duties that apply to every intermediary

Regardless of size or tier:

  • A point of contact for authorities (Art. 11) - an electronic channel for the CRC, other national authorities, the Commission and the European Board for Digital Services, stating at least one official language of the Member State of establishment.
  • A point of contact for users (Art. 12) - fast communication that does not rely solely on automated tools.
  • Terms and conditions (Art. 14) - every content restriction and moderation tool, including algorithmic decision-making, human review and the internal complaint system, in clear, unambiguous, public and machine-readable language. For a service aimed at Bulgaria, a Bulgarian version is required; for one aimed mainly at minors, the terms must be explained so they understand them.
  • Compliance with orders (Arts. 9 and 10) - orders from courts and administrative authorities against illegal content or for information.
  • An annual transparency report (Art. 15) - unless you are a micro or small enterprise; since 1 July 2025, on the uniform machine-readable templates in Implementing Regulation (EU) 2024/2835.

Mere conduit and caching stop here - neither owes the Art. 16 notice mechanism.

Hosting: notices, decisions and the liability shield

The liability shield (Arts. 6 and 7)

A hosting provider is not liable for third-party content if it has no actual knowledge it's illegal and, once it becomes aware, acts expeditiously to remove or disable it. Article 7 adds the "Good Samaritan" rule: voluntary checks or tools that detect illegal content don't cost you this protection.

In Bulgaria, the old liability regime in Chapter Four of the Electronic Commerce Act (Arts. 13–18) was repealed by the same November 2025 act. The Electronic Commerce Act's rules on pre-contractual information, commercial communications and concluding electronic contracts still apply alongside the DSA.

The notice mechanism (Art. 16)

Every hosting provider, including a SaaS with no public part, needs an easy electronic mechanism for anyone to flag illegal content. The form allows submission of:

ElementBasis
An explanation of why the content is illegalArt. 16(2)⁠(a)
The exact electronic location (URL)Art. 16(2)⁠(b)
The notifier's name and email (not required for notices about child sexual abuse material)Art. 16(2)⁠(c)
A statement of good faithArt. 16(2)⁠(d)

A notice containing these elements gives rise to actual knowledge under Art. 6 where it lets a diligent provider identify the illegality without a detailed legal examination - from that moment, the liability-shield clock is running.

The workflow:

  1. Intake - the form validates the mandatory fields.
  2. Confirmation - without undue delay, if the notifier left an email, with a ticket number.
  3. Triage - an urgent queue for child sexual abuse material and terrorist content; a priority queue for trusted flaggers; a standard queue for the rest.
  4. Review and decision - timely, non-arbitrary and objective. The regulation sets no deadline in hours; 24 to 72 hours for ordinary notices is a working estimate from practice, not a legal requirement.
  5. Notification - the notifier learns the decision and the redress options, including whether automated means were used.
  6. Archive - input data, response time and decision, so you can report on your activity.

The statement of reasons (Art. 17)

Every restriction imposed because content is illegal or breaches your terms needs a clear, specific statement of reasons to the affected user (where you have their details) - for removal, disabling, demotion, suspension of payments, suspension of the service or account termination.

The statement contains at least:

  • the measure, its territorial scope and duration;
  • the facts - including whether the decision followed a notice or your own initiative;
  • whether automated means were used;
  • the legal ground and why the content is illegal, or the terms clause and why it was breached;
  • redress information - internal complaint, out-of-court settlement and the courts, as applicable.

The most common failure here is a generic "you broke our rules" with no specific fact and no specific clause.

Reporting to the authorities (Art. 18)

If you learn of information giving rise to a suspicion of a criminal offence against someone's life or safety, you must promptly inform the law enforcement or judicial authorities of the Member State concerned - in Bulgaria, in practice, the Chief Directorate for Combating Organised Crime (GDBOP), or, if you can't identify it, the authorities where you are established, or Europol.

Online platforms above the small-enterprise threshold

A medium or large enterprise? The duties in Arts. 20-28 come on top of the above.

DutyWhat it meansBasis
Internal complaint systemFree and electronic; available for at least 6 months from notice of the decision; not by automated means aloneArt. 20
Out-of-court settlementInformation about certified bodies, good-faith engagement, non-binding decisionsArt. 21
Trusted flaggersTheir notices processed with priority and without undue delayArt. 22
MisuseSuspension, after a warning, of frequent offenders - manifestly illegal content or manifestly unfounded noticesArt. 23
Extra transparencyDisputes, suspensions, automated moderation in the annual report; statements of reasons in the Commission's database, no personal dataArt. 24
Dark patternsA ban on interfaces that deceive or manipulateArt. 25
AdvertisingTransparency for every ad; a ban on profiling with special-category dataArt. 26
Recommender systemsMain parameters set out in the termsArt. 27
MinorsA high level of privacy and safety; no profiling-based adsArt. 28

Complaints and out-of-court disputes

Both the affected user and the notifier can complain; splitting complaints by type - content, accounts, payments, monetisation - helps, since timelines and evidence differ. The CRC certifies out-of-court dispute bodies - and in another Member State.

Dark patterns

Article 25 bans interfaces that deceive, manipulate or otherwise impair users' free choice - giving one option more prominence, repeatedly asking about a choice already made, making cancellation harder than signing up. Dedicated Article 25 guidelines still don't exist.

In practice, a misleading subscription button or cookie banner can be pursued both under Art. 25 of the DSA and under Arts. 68c-68k of the Bulgarian Consumer Protection Act. Cookie rules and the contract withdrawal button are covered in our B2C compliance checklist.

Advertising and recommender systems

For every ad, users must see in real time that it's an ad, on whose behalf, who paid for it (if different), and the main targeting parameters, with a way to change them. Users must also be able to declare their own content as a commercial communication.

Two absolute bans: ads based on profiling using special categories of personal data under Art. 9 GDPR (Art. 26(3)), and profiling-based ads to users known with reasonable certainty to be minors (Art. 28(2)). GDPR consent doesn't lift the first ban.

If you rank content with an algorithm, your terms must explain the main parameters - the most significant criteria, why they carry that weight, and how users can change them; with several ranking options, the choice must be directly available from the relevant part of the interface.

Separately, the AI Act requires transparency for chatbots and generated content (Art. 50) - see our AI Act article.

Minors

Platforms accessible to minors owe a high level of privacy, safety and security (Art. 28 guidelines, C/2025/5519). The regulation expressly does not require processing additional personal data to assess age (Art. 28(3)). The choice of age-assurance technology - a third-party provider, device-level signals, cryptographic proofs disclosing no data - remains a grey area; the EDPB (guidelines 3/2025) advises against mass collection of ID copies and calls for a data protection impact assessment.

Marketplaces: trader traceability

If your platform lets consumers conclude distance contracts with traders, Arts. 30–32 apply - regardless of size. The Art. 19 exemption for micro and small enterprises doesn't reach here: Section 4 of the DSA binds every marketplace, without exception.

DutyWhat it requiresBasis
Trader data before accessName, address, phone, email; ID document or electronic identification; payment account details; trade register and numberArt. 30(1)
VerificationBest efforts using official databases - Commercial Register validity, VAT number via VIES, IBAN holder name matching the trader - or supporting documents from the traderArt. 30(2)
Existing tradersThe deadline to collect their data passed on 17.02.2025; no data means suspensionArt. 30(2)
Inaccurate dataRequest a correction; if ignored, suspend swiftlyArt. 30(3)
Retention6 months after the contract with the trader ends, then deleteArt. 30(5)
Visibility to buyersThe trader's name, address and registration - at least on the product pageArt. 30(7)
Compliance by designThe interface lets traders provide mandatory information; random checks of whether products are flagged as illegalArt. 31
Right to informationNotify buyers from the past 6 months about an illegal product; if you lack their contact details, a public noticeArt. 32

The regulation sets no percentage or frequency for random checks - the methodology remains a grey area. An example from practice: weekly automated scanning of 3-5% of new listings against a list of risk keywords (counterfeits, dangerous ingredients, missing CE marking), plus checks against Safety Gate for dangerous non-food products, with an electronic record of every check.

The Art. 32 notice says three things: that the product or service is illegal, who the trader is, and what redress is available.

The DSA and the GPSR are not the same thing

Marketplace duties under the General Product Safety Regulation (GPSR) - a point of contact, Safety Gate registration and removing dangerous products within 2 working days of an order - are a separate regime for physical goods, covered in our B2C compliance checklist; it applies alongside Arts. 30–32 of the DSA, not instead of them.

Typical cases

SaaS with user-generated content. Closed workspaces are hosting; public galleries, forums and template catalogues are a platform. Separate them architecturally: a report button under public content, spam/malware scanners described in the terms, statement-of-reasons templates ready. Grey area: suspension for non-payment and Art. 17.

Freelance and booking platforms. Marketplaces for services: verify providers under Art. 30 (incl. Tourism Act registration for categorised properties); a statement of reasons for escrow holds; disclose ranking factors. Holding funds also needs to square with the Payment Services and Payment Systems Act.

Mobile app with community features. A "Report" button, statements of reasons for blocking; above the threshold - internal complaints, no profiling-based ads to minors. Whether gamification and notifications count as manipulative design is an open question.

News site with comments. Editorial content isn't an intermediary service; comments are usually ancillary (Recital 13) - but for them the site is a hosting provider, owing a notice mechanism and swift removal.

AI platform. Personal use is hosting; a public sharing community is a platform. Filters are described in the terms (Art. 14). AI Act requirements are separate - see our AI Act article.

Crypto and fintech. MiCA for financial services, DSA for social features - chats, profiles, investment discussion. MiCA's perimeter is covered in our crypto regulation article.

App or plugin store. A marketplace for digital content: verify developers, run random checks, notify users about a compromised plugin.

Who supervises in Bulgaria

The national framework passed the National Assembly on 6 November 2025 and was published in State Gazette issue 99 of 21 November 2025; it entered into force three days later - late against the 17 February 2024 deadline, after the Commission had already opened infringement proceedings against Bulgaria.

AuthorityRemitBasis
Communications Regulation Commission (CRC)Digital Services Coordinator; supervises all intermediaries except video-sharing platforms; dark patterns and recommender systems for all; certifies out-of-court bodies and trusted flaggers; inspections and penaltiesArts. 21(6) and 49g ECA
Council for Electronic Media (CEM)Video-sharing platforms - excluding Arts. 25 and 27Art. 49g(3) ECA
Commission for Personal Data Protection (CPDP)Personal-data processing under the DSA - profiling-based advertising and protection of minorsArt. 49g(4) ECA
Consumer Protection Commission (CPC)Not a DSA authority, but pursues unfair commercial practices under the Consumer Protection Act - including misleading interfacesCPA

Any user can complain to the CRC; where the case belongs to the CEM or the CPDP, the CRC forwards it. The two proceedings can run in parallel: for a dark pattern in a subscription flow, the CPC can fine up to BGN 50,000 (≈EUR 25,565, roughly - no new euro equivalent) under Art. 68c of the Consumer Protection Act, while the CRC investigates a parallel Art. 25 breach.

What is the real risk? To date, the CRC has publicly announced no penalties against local platforms. The research behind this article assesses that in 2025-2026 the CRC is focused on serious breaches, the trusted-flagger register and cross-border cooperation - broad inspections of small startups without complaints are unlikely. An assessment, not a guarantee: one complaint is enough to start a review.

Penalties

The Bulgarian act sets no fixed euro amounts; it mirrors the regulation's percentage caps:

BreachMaximumDSA basisECA basis
Failure to comply with a DSA obligation6% of worldwide annual turnover in the preceding financial yearArt. 52(3)Art. 323f(1)
Information not supplied, incorrect or misleading; refusal of an on-site inspection1% of annual income or worldwide turnoverArt. 52(3)Art. 323f(2)
Periodic penalty for continuing non-complianceUp to 5% of average daily worldwide turnover per dayArt. 52(4)Art. 323f(4)

The amount depends on the gravity, duration and mitigating or aggravating circumstances. The CRC can also temporarily restrict access, but only through the courts.

The largest penalties so far have come from the Commission against very large platforms - EUR 120 million for X (December 2025), EUR 200 million for Temu (May 2026) and EUR 550 million for AliExpress (July 2026). They don't touch startups directly, but show regulators' focus: deceptive design, advertising transparency and illegal marketplace products.

Checklist by startup type

I run B2B SaaS or hosting

  • Do you have a public point of contact for authorities and users?
  • Do your terms describe moderation, automated tools and human review?
  • Is there a notice mechanism with the four Art. 16 elements?
  • Is a statement-of-reasons template ready for Art. 17?
  • Does the team know when and how to alert GDBOP under Art. 18?

I run an online platform or a community app

  • Everything above, plus a report button under public content.
  • Micro or small enterprise? Document it and track when you'll lose that status.
  • Do you count active recipients every six months so you can supply them on request?
  • Above the threshold: internal complaints with human review, ad transparency, ranking parameters in your terms, no profiling of minors.

I run a marketplace

  • Do you collect and verify trader data before activation - whatever your size?
  • Do you show the trader's details on the product page?
  • Do you have a process for random checks and notifying buyers from the past 6 months?
  • Selling physical goods? Then the GPSR applies whatever your size.

I'm based outside the EU but sell into Bulgaria

  • Have you designated a legal representative in writing in a Member State and notified the coordinator?

The DSA is rarely breached by one big decision - it's breached by a form missing a mandatory field, an account suspended without explanation, an interface designed to sell rather than inform. All of that is cheap to fix while you're small, and expensive after the first complaint.


This article is general information current as of September 2026, not individual legal advice. The percentage penalty caps have been checked against the text of Regulation (EU) 2022/2065 and the amendments to the Electronic Communications Act (State Gazette issue 99/2025). The Bulgarian act sets no fixed euro amounts, so this article gives none for DSA breaches themselves; at the time of writing there is no publicly announced CRC penalty practice. The Consumer Protection Act figure quoted (BGN 50,000) remains in leva in the statutory text and has been converted at the fixed peg - no new euro equivalent has been set. The exact entry-into-force date of the act and the methodology for marketplace random checks remain unsettled - check the CRC's current position before relying on them.


Frequently asked questions

Related articles