A regulation with a phased timetable
The Digital Services Act (DSA) lays down European Union rules for online intermediary services. Its scope includes, among other things, hosting services, online platforms and online marketplaces. It does not impose exactly the same obligations on every company: it combines common duties with additional requirements for certain categories, particularly very large online platforms and very large online search engines. This structure is essential to reading its timeline correctly: the date on which the regulation enters into force is not the date on which every obligation starts applying to every service. The timetable must be read alongside the provider’s legal category, because the same date can have different consequences depending on the service and the obligations that apply to it.
Regulation (EU) 2022/2065 was published in the Official Journal of the European Union on 27 October 2022 and entered into force on 16 November of that year. The text set a later date for general application, 17 February 2024, while bringing forward some obligations for services designated as very large. It is therefore useful to distinguish three things: the regulation’s adoption and publication, its entry into force, and the effective start of obligations for each entity. Confusing them can make milestones that the legislator expressly separated appear simultaneous. In practical terms, the fact that the regulation was in force did not mean that all its provisions were already enforceable against all providers.
Timeline: from entry into force to general application
The first verifiable milestone is the regulation’s entry into force on 16 November 2022. From then on, the European legal framework began to apply, but all its provisions did not suddenly become active for every service. The regulation stipulated that certain due diligence obligations would apply earlier to providers identified as very large online platforms or very large online search engines. The European Commission publishes the list of designated services and explains that the relevant threshold is at least 45 million monthly active users in the EU, subject to the prescribed designation process. Reaching the threshold is therefore one element of that process, not a reason to dispense with checking the official designation.
General application of the DSA began on 17 February 2024. That date is a useful reference point for the common regime, but it does not erase the earlier timetable for designated services: their specific obligations started applying four months after notification of the relevant designation decision. There is therefore no single compliance date that applies to every platform without taking its category and designation date into account. To reconstruct the position for a particular service, it is necessary to check the designation decision and the applicable official dates, rather than infer them solely from the general timetable. This distinction separates the general application date from the date that applies to a particular provider.
What services must do: common rules and additional layers
The mechanisms the Commission describes for the DSA include ways for users to report content, goods or services that are allegedly illegal; greater transparency about content moderation and options to challenge certain decisions; and rules on advertising transparency. The Commission also highlights the ban on certain types of personalised advertising, including advertising based on sensitive data or targeted at minors. These descriptions help explain the regulation’s practical purpose, but they do not replace the legal text: the scope of each obligation depends on its conditions and the type of service involved. Not all measures have the same scope, and they do not apply uniformly to every intermediary.
Platforms that allow consumers to conclude distance contracts with traders must comply with specific obligations relating to trader traceability. Very large platforms and search engines, in turn, face additional requirements, including assessing and mitigating systemic risks and undergoing independent audits. It should not be inferred that every hosting provider or intermediary service has to meet all these layers of requirements. Legal classification, exceptions and thresholds matter; online platform and very large platform are not interchangeable terms. The distinction between categories helps explain why some obligations are concentrated on particular services, while others form part of the common framework.
Supervision: European coordination and national authorities
Supervision is also shared. The European Commission has direct powers over platforms and search engines designated as very large, while Member States appoint Digital Services Coordinators and organise the national application of the regulation. The framework provides for cooperation between authorities and mechanisms for handling matters that affect several countries. The DSA therefore does not create a single office that manages every user report or complaint: the competent authority depends on the service, the obligation and the circumstances of the matter. This allocation combines direct supervision of certain services with national responsibilities and cooperation between authorities.
For a user, the first practical step is generally to use the tools that the service itself must provide, such as reporting allegedly illegal content or using internal complaint mechanisms to challenge a moderation decision. The Commission presents these routes as part of the changes introduced by the regulation. This does not mean that every reported item must automatically be removed, or that a complaint will succeed: the obligation is to establish procedures and act in accordance with the law, not to guarantee a favourable outcome in every case. Reporting content and obtaining a favourable decision are different things; the procedure allows the matter to be examined, but does not predetermine the result.
What changes—and what cannot be concluded from the timeline alone
The DSA aims to strengthen transparency, complaint mechanisms and supervision of digital services, as well as to establish duties relating to illegal content, products and services. Its design links certain obligations to the risks and size of a service; it does not, by itself, order platforms to remove any controversial material. The Commission says that the regulation’s application is intended to protect fundamental rights and improve online safety. That legal purpose should be distinguished from an empirical claim about how much safety or each user’s experience has improved: specific evaluation data would be needed to support such a claim. The regulation’s purpose describes what it seeks to achieve; it does not, in itself, prove that those results have already been achieved.
The timeline, then, provides a map of legal effect and responsibilities, not a measurement of outcomes. Official sources allow us to state when the regulation entered into force, when it became generally applicable and what kinds of obligations it contains. By themselves, they are not enough to quantify changes in content removal, exposure to advertising or the speed with which complaints are resolved. For a particular platform, the useful check is more precise: identify its legal category, verify whether it has been designated as a very large service, and review the relevant provision and its date. This order of checks avoids confusing the general timetable with particular obligations and keeps legal dates separate from any assessment of their effects.