On April 23, 2022, the European Commission announced that the European Parliament and EU Member States had reached agreement to implement a Digital Services Act (“DSA”), which will establish accountability standards for online platforms regarding illegal and harmful content.
The Digital Service Act imposes obligations to three types of organization:
· service providers (covering intermediary services, conduit, caching, hosting and network infrastructure services);
· Online platforms (such as app stores, online marketplaces and social media platforms); and
· Very large online platforms (“VLOPs”), defined as online platforms with more than 45 million active monthly users.
The agreement for the Digital Services Act will cover the following:
Online Marketplaces. To ensure removal of illegal products and services from online marketplaces, operators of such marketplaces must establish know-your-customer-type protocols for merchants using their platforms. Operators must also make reasonable efforts, including random checks, to prevent illegal products and services from being listed for sale on their platforms.
Immediate Takedown. Content targeting victims of cyber violence (e.g., “revenge porn”) must be removed “immediately;” other content deemed illegal must be removed “swiftly.”
Dark Patterns. The DSA creates a qualified ban on the use of dark patterns, by prohibiting online platforms from using dark patterns to manipulate users’ choices unless they pertain to practices permitted by the EU GDPR or the Unfair Commercial Practices Directive. The European Commission is expected to issue guidance on the types of practices that constitute dark patterns under the DSA.
Algorithm Accountability. The DSA authorizes the European Commission and EU Member States to access the algorithms of VLOPs upon request and within a reasonable time if necessary to monitor and assess the compliance with the DSA.
Transparency & Profiling. Platforms must clearly describe their recommendation systems in the platform’s terms and conditions. Platforms also must allow users to modify the parameters used in the recommendation systems, and must include at least one option not based on profiling.
Supervisor Fee by the Commission. VLOPs must pay the European Commission a supervisory fee of up to 0.05% of their global annual revenue to enforce the DSA.
Inclusion of search engines. In addition to from VLOPs, very large search engine operators separately fall within the scope of the DSA’s takedown regime. While such search engine operators cannot remove illegal content per se, they are required to delist any links leading users to such illegal content.
The DSA will be sent to the European Parliament and EU Member States for final approval. Once approved, the DSA will become effective 20 days after its publication in the Official Journal. Online platforms will then have 15 months to comply with the legislation, which will is expected to become enforceable in the first quarter of 2024.
If you offer online service and you wish to know more about your responsibilities, please do not hesitate to contact us. We can help you implement measures that will mitigate cyber threats and avoid data breaches.