Law / European Union

Digital Services Act (DSA), Articles 40 to 42 (Data access and scrutiny, compliance function and transparency reporting of very large online platforms and search engines)

Regulation (EU) 2022/2065, Arts. 40-42

In force since .

A transparency and process rule binding private bodies.

As of .

What it requires

  • If the Commission designates your online platform or online search engine as a very large online platform or very large online search engine under Article 33(4), the duties below apply to you from four months after it notifies you of the decision (Article 33(6)).
  • Give the Digital Services Coordinator of establishment or the Commission, at their reasoned request and within a reasonable period specified in the request, access to data that are necessary to monitor and assess your compliance with the Regulation. At the request of either, explain the design, logic, functioning and testing of your algorithmic systems, including your recommender systems.
  • On a reasoned request from the Digital Services Coordinator of establishment, give vetted researchers access to data within a reasonable period specified in the request, for the sole purpose of research that contributes to the detection, identification and understanding of systemic risks in the Union under Article 34(1) and to the assessment of the adequacy, efficiency and impacts of your risk mitigation measures under Article 35. If you cannot give access because you do not have the data or because access would lead to significant vulnerabilities in the security of your service or the protection of confidential information, in particular trade secrets, ask the Digital Services Coordinator within 15 days of receiving the request to amend it, with proposals for alternative means of access.
  • Facilitate and provide access to data under Article 40(1) and (4) through the appropriate interfaces specified in the request, including online databases or application programming interfaces.
  • Give access without undue delay to data, including, where technically possible, real-time data, provided that the data is publicly accessible in your online interface, to researchers, including those affiliated to not for profit bodies, organisations and associations, who comply with the conditions in Article 40(8), points (b), (c), (d) and (e), and who use the data solely for research that contributes to the detection, identification and understanding of systemic risks in the Union under Article 34(1).
  • Establish a compliance function that is independent from your operational functions and composed of one or more compliance officers, including a head of the compliance function, with sufficient authority, stature and resources and access to your management body. The head must be an independent senior manager with distinct responsibility for the compliance function, report directly to the management body and not be removed without its prior approval, and the management body must ensure that compliance officers have the professional qualifications, knowledge, experience and ability needed for their tasks.
  • Give your compliance officers the tasks listed in Article 41(3): cooperating with the Digital Services Coordinator of establishment and the Commission; ensuring that all risks referred to in Article 34 are identified and properly reported on and that risk-mitigation measures are taken under Article 35; organising and supervising your activities relating to the independent audit under Article 37; informing and advising management and employees about relevant obligations; monitoring your compliance with the Regulation; and, where applicable, monitoring compliance with commitments made under the codes of conduct and the crisis protocols.
  • Communicate the name and contact details of the head of the compliance function to the Digital Services Coordinator of establishment and to the Commission.
  • Have your management body define, oversee and be accountable for governance arrangements that ensure the independence of the compliance function, including the division of responsibilities, the prevention of conflicts of interest and the sound management of the systemic risks identified under Article 34; approve and review, at least once a year, the strategies and policies for managing, monitoring and mitigating those risks; devote sufficient time to risk management decisions; and ensure that adequate resources are allocated to managing those risks.
  • Publish the reports referred to in Article 15 at the latest by two months from the date from which the obligations apply to you under Article 33(6), second subparagraph, and thereafter at least every six months. Include in them the information on the average monthly recipients of the service for each Member State, in addition to the information in Article 24(2).
  • If you are a very large online platform, specify in those reports, in addition to the information required by Articles 15 and 24(1): the human resources you dedicate to content moderation in respect of the service offered in the Union, broken down by each applicable official language of the Member States, including for compliance with Articles 16, 20 and 22; the qualifications and linguistic expertise of the persons carrying out those activities and the training and support given to them; and the indicators of accuracy and related information referred to in Article 15(1), point (e), broken down by each official language of the Member States. Publish the reports in at least one of the official languages of the Member States.
  • Transmit to the Digital Services Coordinator of establishment and the Commission, without undue delay upon completion, and make publicly available at the latest three months after the receipt of each audit report under Article 37(4): a report setting out the results of the risk assessment under Article 34; the specific mitigation measures put in place under Article 35(1); the audit report; the audit implementation report under Article 37(6); and, where applicable, information about the consultations conducted in support of the risk assessments and the design of the risk mitigation measures.
  • Where publication might result in the disclosure of confidential information of yours or of the recipients of the service, cause significant vulnerabilities for the security of your service, undermine public security or harm recipients, you may remove such information from the publicly available reports. In that case, transmit the complete reports to the Digital Services Coordinator of establishment and the Commission with a statement of the reasons for removing the information.

If you get it wrong

Private right of actionYes

Penalty structure

Article 74(1) lets the Commission fine the provider of a very large online platform or very large online search engine, where it finds that the provider intentionally or negligently infringes the relevant provisions of the Regulation, up to 6 % of its total worldwide annual turnover in the preceding financial year. Article 74(2) caps the fine for supplying incorrect, incomplete or misleading information, failing to reply, failing to rectify information or refusing an inspection at 1 % of the total annual income or worldwide turnover in the preceding financial year.

Rule
Turnover pct only
As of
Turnover percentage cap
6

Who enforces it

Enforcement body

The European Commission, which has exclusive powers to supervise and enforce Section 5 of Chapter III (Article 56(2)).

What it reaches

Obligation class

Governance, Reporting, Disclosure

Applicability criteria

As of
Combinator
All of
Criteria
  • a number of average monthly active recipients of the service in the Union equal to or higher than 45 million
  • designated as very large online platforms or very large online search engines pursuant to paragraph 4

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 92 applies the Regulation to a provider of a very large online platform or very large online search engine designated under Article 33(4) from four months after the notification of the designation, where that date is earlier than . The Commission's first designation decisions under Article 33(4) are dated , so for the providers designated then Articles 40 to 42 apply from .

Article 40(1) requires a provider of a very large online platform or very large online search engine to give the Digital Services Coordinator of establishment or the Commission, at their reasoned request and within a reasonable period specified in that request, access to data that are necessary to monitor and assess compliance with the Regulation.

At the request of either, the provider must explain the design, the logic, the functioning and the testing of its algorithmic systems, including its recommender systems.

Upon a reasoned request from the Digital Services Coordinator of establishment, the provider must within a reasonable period provide access to data to vetted researchers who meet the requirements in Article 40(8), for the sole purpose of research that contributes to the detection, identification and understanding of systemic risks in the Union and to the assessment of the adequacy, efficiency and impacts of the risk mitigation measures.

Within 15 days of receiving such a request the provider may ask the Digital Services Coordinator of establishment to amend it, where it does not have access to the data or giving access would lead to significant vulnerabilities in the security of its service or the protection of confidential information, in particular trade secrets.

The provider must facilitate and provide access to data under Article 40(1) and (4) through appropriate interfaces specified in the request, including online databases or application programming interfaces.

It must also give access without undue delay to data, including where technically possible real-time data, provided that the data is publicly accessible in its online interface, to researchers who comply with the conditions in Article 40(8), points (b), (c), (d) and (e), and use the data solely for research that contributes to the detection, identification and understanding of systemic risks in the Union.

Article 41(1) requires such a provider to establish a compliance function, independent from its operational functions and composed of one or more compliance officers, including the head of the compliance function, with sufficient authority, stature and resources and access to the management body.

The head of the compliance function must be an independent senior manager with distinct responsibility for the function, must report directly to the management body, and must not be removed without the prior approval of the management body.

Compliance officers must cooperate with the Digital Services Coordinator of establishment and the Commission, ensure that all risks referred to in Article 34 are identified and properly reported on and that risk-mitigation measures are taken under Article 35, organise and supervise the activities relating to the independent audit under Article 37, inform and advise management and the workforce about relevant obligations, and monitor compliance with the Regulation and with commitments made under codes of conduct and crisis protocols.

The provider must communicate the name and contact details of the head of the compliance function to the Digital Services Coordinator of establishment and to the Commission. Its management body must define, oversee and be accountable for governance arrangements that ensure the independence of the compliance function, approve and review at least once a year the strategies and policies for managing the risks identified under Article 34, and devote sufficient time to decisions on risk management.

Article 42(1) requires such a provider to publish the reports referred to in Article 15 at the latest by two months from the date of application referred to in Article 33(6), second subparagraph, and thereafter at least every six months.

A provider of a very large online platform must also specify in those reports the human resources it dedicates to content moderation in the Union, broken down by official language, the qualifications and linguistic expertise of those persons and the training and support given to them, and the indicators of accuracy broken down by official language. Such a provider must also include in those reports the information on the average monthly recipients of the service for each Member State.

It must transmit to the Digital Services Coordinator of establishment and the Commission, without undue delay upon completion, and make publicly available at the latest three months after the receipt of each audit report, a report on the results of the risk assessment, the specific mitigation measures put in place, the audit report, the audit implementation report and, where applicable, information about the consultations conducted in support of the risk assessments.

The provider may remove information from the public versions where publication might result in the disclosure of confidential information, cause significant vulnerabilities for the security of its service, undermine public security or harm recipients, but must then transmit the complete reports to the Digital Services Coordinator of establishment and the Commission with a statement of the reasons for removing the information.

When LexLint raises it

When your app profile says your app reuses other publishers' content or operates a social platform.

Back to the example  ·  Lint your app