Digital Services Act (Regulation (EU) 2022/2065)
The EU's intermediary-liability and due-diligence law, published in the Official Journal on 27 October 2022 (OJ L 277, 27.10.2022, p. 1), in force since 16 November 2022 and applying in full since 17 February 2024 (Art. 93, not extracted). It regulates intermediary services — mere conduit, caching and hosting (Art. 3(g)) — offered to recipients in the Union, with duty tiers that escalate from all intermediaries → hosting services → online platforms → very large platforms.
The TODO flagged this instrument "only if we host user-facing content sharing — assess scope before authoring". The assessment (2026-09-06): a portal that stores school- and pupil-created content is a hosting service — "storage of information provided by, and at the request of, a recipient of the service" (Art. 3(g)(iii)) — so the intermediary/hosting tiers are in frame and are extracted here. Whether it is also an online platform turns on "dissemination to the public": an online platform is a hosting service that "stores and disseminates information to the public" (Art. 3(i)), and dissemination to the public means making information available "to a potentially unlimited number of third parties" (Art. 3(k)) — content shared within closed school organisations is not that; a public content-sharing channel would be. The platform-tier provisions extracted (Arts. 19, 28) are the gate and the minors provision that matter if that line is ever crossed.
Applicability to EdTech
- Hosting-tier duties apply to school-content storage: notice-and-action for illegal content (Art. 16), statements of reasons to affected users (Art. 17, not extracted), points of contact (Arts. 11–12), an EU legal representative for non-EU providers (Art. 13), terms-and-conditions transparency including that restrictions must be applied diligently, objectively and proportionately "with due regard to the rights and legitimate interests of all parties involved" (Art. 14), and annual transparency reporting (Art. 15).
- The liability shield for user content is Art. 6: no liability for stored user content absent actual knowledge, with expeditious removal on obtaining it; and no general monitoring may be imposed (Art. 8).
- If a service ever qualifies as an online platform: micro/small enterprises are excluded from most platform duties (Art. 19), but Art. 28 — high level of privacy, safety and security for minors, and no profiling-based advertising using a minor's personal data (Art. 28(2)) — is the provision a child-facing platform must design for. Art. 28(3) adds that compliance must not force collecting extra personal data to age-assess (Art. 28(3)).
Contents
| Document | Covers |
|---|---|
| SCOPE-AND-DEFINITIONS.md | Arts. 1–3 — scope and the gating definitions |
| LIABILITY-EXEMPTIONS.md | Arts. 4–6, 8 — conduit/caching/hosting shields, no general monitoring |
| INTERMEDIARY-DUTIES.md | Arts. 11–16 — contacts, legal rep, T&C, transparency reports, notice-and-action |
| PLATFORM-PROVISIONS.md | Arts. 19, 28 — platform-tier gate and protection of minors |
Scope note: statements of reasons (Art. 17), orders (Arts. 9–10), the full online-platform section (Arts. 20–32), VLOP obligations (Arts. 33–43) and enforcement/Commission machinery can be added with the same tooling if a service crosses the platform line.
Key obligations at a glance
- Run a notice-and-action mechanism: easy electronic notice submission, confirmation, timely diligent non-arbitrary decisions, notification of the decision (Art. 16).
- Publish points of contact for authorities and recipients (Arts. 11–12); non-EU providers designate an EU legal representative (Art. 13).
- State content-moderation policies and tools in the T&C, in clear language — with an extra duty to explain conditions understandably to minors where a service is primarily directed at or predominantly used by them (Art. 14).
- Annual transparency report on moderation activity (Art. 15, with the micro/small exemption in Art. 15(2)).
Enforcement
National Digital Services Coordinators (for most services); Member States must cap fines at 6% of the provider's annual worldwide turnover (Art. 52(3), not extracted; wording checked 2026-09-06). The Commission enforces against very large platforms.
Related
- EU GDPR — Art. 28(2)'s profiling ban imports the GDPR Art. 4(4) definition; both regimes apply cumulatively
- EU AI Act — recommender/moderation systems may engage both
Sources
Meta
Article text in the content documents is reproduced verbatim from the EUR-Lex OJ text (CELEX 32022R2065) and built/re-verified mechanically by tools/eur-lex/build_eu_dsa.py (verify mode; do not hand-edit). The only consolidated edition holds no EN datastream in Cellar and no corrigendum covers English (checked via Cellar RDF, 2026-09-06), so the OJ text is authoritative. Anchors: official ELI ids plus derived paragraph/point anchors from printed labels. The scope assessment in the header is a corpus-inclusion decision recorded per the TODO instruction, not product legal advice; the "applying since 17 February 2024" and 6%-ceiling statements summarise Arts. 93(2) and 52(3), which are not extracted — wording checked against the OJ text on 2026-09-06.