DSA and GDPR – what do the new EROD guidelines mean for digital service providers?

24 November 2025

The European Data Protection Board has published new guidelines regarding the relationship between the DSA and the GDPR. The document specifies how digital service providers – including online platforms, search engines, and other intermediaries – should integrate the obligations arising from the Digital Services Act with the principles of personal data protection. The EDPB Guidelines 3/2025 indicate, among other things, the legal bases for data processing in the context of actions related to the removal of illegal content, the principles for making automated decisions in accordance with Article 22 of the GDPR, and situations where it is necessary to conduct a Data Protection Impact Assessment (DPIA). We invite you to read the article discussing the key issues arising from the EDPB Guidelines 3/2025 regarding the mutual relations between the DSA and the GDPR.

Who is subject to obligations under the DSA

The DSA imposes obligations primarily on providers of intermediary services, namely:

  • services of "ordinary transmission" involving the transmission over a telecommunications network of information provided by the recipient of the service or ensuring access to a telecommunications network,
  • "caching" services involving the transmission over a telecommunications network of information provided by the recipient of the service, including automatic, intermediate, and temporary storage of that information, carried out solely for the purpose of facilitating the subsequent transmission of information at the request of other recipients,
  • "hosting" services involving the storage of information provided by the recipient of the service and at their request.

An extended scope of obligations applies to online platforms (a specific type of hosting service) and search engines (a type of intermediary service) that have an average of 45 million content recipients per month and have been designated by the European Commission. Such entities are referred to in the DSA as very large online platforms ("VLOP") and very large search engines ("VLOSE").

As of the date of this article, there are 20 entities listed on the European Commission's website that are providers of VLOP and/or VLOSE. These include, among others, Meta Platforms Ireland Limited, Google Ireland Ltd., AliExpress International (Netherlands) BV, and Zalando SE.

This means that in addition to the obligations that apply solely to very large platforms:

  • every obligation provided for intermediary service providers applies to VLOP and VLOSE,
  • every obligation provided for hosting service providers also applies to VLOP.

Does the GDPR take precedence over the DSA

The essence of applying both legal acts is – according to EROD – their coherence and complementarity. Neither of these legal acts constitutes specific provisions in relation to the other. Thus, in model situations, one cannot invoke the Roman maxim lex specialis derogat legi generali in their interpretation.

And indeed: it is likely that a similar approach guided the authors of the DSA text. In Article 2(4) of the DSA, the GDPR is listed as one of the key legal acts that will not conflict with the application of the DSA. However, coherence and complementarity can also be observed in more specific provisions. The GDPR is referenced therein as a point of reference or complement that eliminated the overproduction of content when preparing the DSA (e.g., Article 38 of the DSA refers to the definition of profiling adopted in the GDPR).

The EROD, however, points out that the provisions of the DSA should be taken into account by supervisory authorities when monitoring compliance with data protection regulations. This is particularly significant due to the obligations that the DSA imposes on providers of intermediary services.

The DSA regulates a specific area of social and economic life, and actions taken in this domain are also subject to assessment from the perspective of personal data protection regulations.

DPO Function - it transfers well

How the GDPR relates to verification actions and the removal of illegal content

If the actions of providers of intermediary services involve the processing of personal data of natural persons, they must be based on an appropriate legal basis under Article 6(1) of the GDPR. This is, of course, a choice that is not without significance. It affects the specific rights of the individuals whose data is concerned, as well as various possibilities for protecting the interests of the entity processing the data.

The decision on the choice of legal basis for processing often presents considerable difficulties for data controllers. Therefore, the position of the EROD facilitates the planning of future and the adjustment of current data processing activities.

In the assessment of the EROD, two legal bases are considered:

  • Article 6(1)(c) of the GDPR, which refers to necessity for compliance with a legal obligation,
  • Article 6(1)(f) of the GDPR, which refers to necessity for the purposes of legitimate interests pursued by the data controller or a third party.

The application of the first of the mentioned grounds is undisputed. However, two issues should be noted. First, Article 8 of the DSA prohibits states from imposing general monitoring obligations; therefore, obligations in this regard should be targeted and specific. Second, processing based on a legal obligation does not exempt the data processor from the duty to maintain appropriate proportionality. The data processor is entitled to process only those personal data that are necessary to fulfill the obligation arising from legal provisions. As for the formulation of the obligations themselves, they should primarily be clear, precise, and predictable.

Importantly, Article 6(1)(c) of the GDPR serves as a basis for processing even when it occurs in the context of complying with an order to provide information or to counter illegal content. The order then constitutes the implementation of legal provisions; however, the intermediary service provider must verify whether this order indeed meets the requirements of Articles 9 or 10 of the DSA.

I consider the thesis of the EROD, which requires intermediary service providers to verify orders and conditions the possibility of relying on the basis of Article 6(1)(c) of the GDPR on this verification, to be controversial.

Within the framework of the legitimate interest, providers will process personal data when they, in good faith and with due diligence, conduct voluntary checks or take other measures aimed at detecting, identifying, and removing illegal content or preventing access to it (Article 7 of the DSA).

The EROD indicates three conditions that must be met for processing to be permissible. The first is that the provider has a legitimate interest. However, at this point, the EROD quickly throws a lifeline and indicates that the interest in detecting and combating illegal content in intermediary services to protect the recipients of the service is justified, particularly when such content may be publicly shared via an online platform.

The second condition is the necessity of processing the data for this purpose, and the third is the confirmation that the rights and freedoms of the individuals whose data are being processed do not outweigh the interest in processing that data. In this regard, the observations of the EROD are difficult to consider groundbreaking, as these elements are constant components of any reliable legitimate interest assessment (LIA).

Verification activities and removal of illegal content versus automated decision-making and profiling

The topic of profiling and automated decision-making in the EROD begins with a reference to Recital 56 of the DSA. According to this, the regulation does not provide a basis for profiling service recipients for the potential identification of crimes by hosting service providers. When informing law enforcement authorities, hosting service providers must also comply with other applicable provisions of Union law or national law concerning the protection of the rights and freedoms of individuals. This means that if such profiling were to occur, there would need to be another legal basis as referred to in Article 22 of the GDPR.

The EROD also provides an example of automated decisions involving the removal of illegal content. It emphasizes that in such situations, it is necessary for intermediary service providers to verify whether the decision is based solely on automated data processing (the same applies to situations where human intervention is merely superficial or entirely marginal). Subsequently, the provider should assess whether it has appropriate grounds under Article 22 of the GDPR.

Must an intermediary service provider conduct a DPIA?

Risk Analysis
When was the last time
you conducted a risk analysis?
Risk and DPIA are fundamental elements in building a data protection system.
ORDER A QUOTE
The previously discussed voluntary or mandatory actions related to the verification or removal of illegal content are also subject to assessment regarding the obligation to conduct a DPIA.

The EROD suggests that such an assessment should certainly take into account criteria such as:

  • assessment or scoring,
  • automated decision-making with legal or similar effects,
  • systematic monitoring,
  • data processing on a large scale, especially when it is highly likely to concern very large platforms VLOP and VLOSE, such as Facebook or YouTube, but not limited to them.

Guidelines also indicate that intermediary service providers will typically meet a sufficient number of criteria to conclude that they are obliged to conduct a DPIA in this regard.

Whistleblower Protection

The obligation to create mechanisms for reporting potentially illegal content rests with hosting service providers. However, it is not often that the legislator relieves data controllers of the responsibility to determine how to practically apply the principle of data minimization.

According to the general principle, the reporting mechanisms created by hosting service providers should be designed to collect from reporters first name, last name, and email address. However, this data is not collected in cases where the report concerns crimes listed in Articles 3–7 of Directive 2011/93/EU on combating the sexual exploitation of children and child pornography (“CSAM Directive”).

It is also a fact that, as a rule, the inability to identify the reporter should not result in the hosting service provider refusing to take action. Its role is to enable the reporter to identify themselves, not to condition the processing of the report on such identification. Although, of course, the specifics of certain reports may require the identification of the reporter.

EROD also indicates how, in light of the DSA, the data of reporters (if provided) can be used:

  • to promptly provide the reporter with confirmation of receipt of the notification,
  • to inform the reporter of its decision regarding the “reported” information and information regarding the appeal procedures against this decision,
  • to send the reporter a notification of cases in which hosting providers cannot, for technical or operational reasons, remove specific information,
  • “only where absolutely necessary” – to include the personal data of the reporter in the justification that is to be provided to the service recipients.

It should not be surprising that the burden of determining whether the disclosure of the reporter's data is absolutely necessary has been placed on the hosting service provider. This means that they bear the risk of erroneous determinations and, consequently, data protection violations associated with this. If it is determined after the fact that the disclosure of this data was not necessary, the provider may be accused of acting without legal basis, which would constitute a violation not only of Article 17(2)(b) of the DSA but also of Article 6(1) of the GDPR. The phrase “absolutely necessary” should be treated by the provider as a very rare exception to the ironclad rule.

EROD additionally points out that if the reporter's data is to be shared with the service recipient, the reporter should be notified of this in accordance with the provisions of Article 13 of the GDPR, and the scope of the data shared should be limited to the necessary minimum.

Automated Means and Their Application in the Case of Reports

According to Article 16(6) of the DSA, the consideration of reports or the making of decisions may take place using automated means. This information is communicated to the reporting party post factum – at the stage of notification of the decision made regarding the report.

The "automated means" referred to in Article 16(6) of the DSA may, but do not have to, fall within the scope of Article 22 of the GDPR. If they do, the entity should first verify whether it has the appropriate grounds under Article 22(2) or (4) of the GDPR. If so, regardless of the information from the DSA, information about decisions based solely on automated data processing should be provided – in accordance with the principles set out in Article 13 of the GDPR.

The position of the EDPB on this matter can be summarized as follows:

  • Article 16(6) of the DSA does not constitute an independent basis for automated decision-making as referred to in Article 22 of the GDPR,
  • the information obligation under Article 16(6) of the DSA does not replace but complements the obligation referred to in Article 13 of the GDPR.

It is worth adding in passing that the DSA provides analogous principles concerning service recipients – in the case of preparing justifications using automated means (Article 17(3)(c) of the DSA).

GDPR in IT

Deceptive Interfaces

A deceptive online interface (ang. deceptive design pattern) is a solution that misleads service recipients or manipulates them, or in another significant way distorts or limits the ability of service recipients to make free and informed decisions.

Examples of deceptive interfaces have been discussed, among others, in the EDPB Guidelines 3/2022 on deceptive interfaces in social media platform interfaces. The EDPB rightly points out that a deceptive interface is significant in the context of personal data protection if it affects decisions related to the use of personal data (e.g., providing them to an entity using a deceptive interface). At the same time, the EDPB notes that the boundary here is quite thin.

An example provided by the EDPB in the guidelines: patterns that attempt to persuade all service recipients to purchase a product through manipulation (emotional), e.g., “Only a few products left in stock,” may not be covered by the GDPR. However, if the service recipient is manipulated into providing (additional) personal data, e.g., “Only a few products left in stock. Enter your email address now to make a reservation,” or into providing more personal data than in another case, then the pattern is subject to the GDPR.

The EDPB holds the position that the use of misleading interfaces for purposes related to the processing of personal data (including their collection) constitutes a violation of the principle of fairness in personal data processing (Article 5(1)(a) GDPR). It is difficult to disagree with this conclusion. However, in fact, a misleading interface may cause violations of both other GDPR provisions establishing general principles (especially the principle of transparency) and specific provisions – such as those relating to the voluntariness and awareness of consents for data processing or to the correctness of fulfilling informational obligations.

Prohibition on presenting ads based on profiling using special categories of data

Article 26(3) of the DSA introduces a prohibition on presenting ads based on profiling using special categories of personal data. This prohibition applies to online platforms, and thus also includes VLOPs.

As can be easily noticed, the prohibition does not concern profiling itself, but the effects that such profiling would bring. Purely theoretically, one could imagine that if the relevant conditions specified in Article 22(4) GDPR are met, online platforms could still profile individuals whose data is concerned, based on special categories of data. However, the result of this profiling cannot be the presentation of ads.

Protection of minors

Knowledge base GDPR
Free knowledge about GDPR.
Use it freely!
Webinars, articles, guides, training, snapshots, and assistance. Welcome to the ODO 24 knowledge base.
I'M IN
The DSA imposes specific obligations related to the protection of minors. At the same time, the EROD notes that these must be implemented in compliance with the GDPR. The fundamental principles that emerge in this context are:

  • the prohibition of advertising based on profiling – profiling of minors is prohibited if the platform is certain of the user's age,
  • no obligation to collect additional personal data solely for the purpose of determining age – the platform, when determining the user's age, should rely on the information it possesses about the individual.

The EROD recommends avoiding verification mechanisms that:

  • allow for the unequivocal identification of users,
  • require long-term storage of information about age or age range,
  • violate proportionality in relation to the intended purpose.

Use by VLOP and VLOSE of non-profiling recommendation options

VLOP and VLOSE should provide the option to use a recommendation system that is not based on profiling. This option should be presented equally alongside options that include profiling.

The EROD notes that as long as the user's choice regarding the non-profiling option remains active, the collection of their data for profiling purposes will be unlawful. It also emphasizes that recommendation systems should be organized in such a way that even in the case of multiple changes in settings within a single day, profiling of the user does not occur when they are using the non-profiling option.

From a data protection perspective, it may also be significant that the unequal presentation of individual recommendation systems (profiling and non-profiling) may sometimes constitute a so-called deceptive design pattern. However, even when the presentation is unequal but does not constitute a misleading interface, there may still be a violation of the principle of transparency or the rules for lawful consent to data processing.

Summary

It is easy to notice that the EROD shapes its position in such a way as to minimize any potential doubts that may arise regarding the relationship between the GDPR and the DSA. Many issues raised in the guidelines seem quite obvious – particularly the attempts to establish the grounds for the processing of personal data in connection with the fulfillment of obligations or voluntary initiatives of intermediary service providers.

In my opinion, it is quite significant to clearly distinguish between decisions made using automated means (e.g., Article 16(6) and Article 17(3)(c) of the DSA) and the decisions referred to in Article 22 of the GDPR. Automated means may, but do not have to, involve making decisions as mentioned in Article 22 of the GDPR, which may not be clear with a superficial analysis of the provisions of both legal acts.

On the downside, the EDPB lacks the establishment of the relationship between the exceptions provided in Article 14(5) of the GDPR and the right of access to data (Article 15 of the GDPR) in the context of informing the service recipient about the person who reported illegal content.

A certain breakthrough is the change in regulations regarding the personalization of advertisements based on special categories of data. However, the interpretation of these provisions made by the EDPB does not seem particularly groundbreaking. The conclusions drawn in this regard are, in my view, quite obvious.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.