Back to the blog

Your store sells only its own products.

Learn how to classify your online store under the DSA, check small-business exemptions, and build notice, moderation and reporting processes.

Your store sells only its own products. It has nothing to do with Facebook or TikTok. But it allows customers to post reviews under products — and under the DSA (Digital Services Act, EU Regulation 2022/2065), that already makes it an online platform. This single feature triggers more than a dozen obligations that are probably not mentioned anywhere in your terms and conditions. The DSA has applied in full since 17 February 2024 — as an EU regulation, it applies directly, without the need for Polish legislation. Businesses that waited for national regulations are now more than two years behind, rather than starting with a clean slate. In May 2025, the European Commission referred Poland to the CJEU for failing to designate a Digital Services Coordinator (source: European Commission). The Polish act implementing the DSA (Sejm paper No. 2694) was adopted on 4 September 2026 and designates the President of UKE as the Digital Services Coordinator — but this is not the beginning of the obligations; it is the beginning of enforcement.

In this article, I will take you through seven steps that determine how much of the DSA applies specifically to your service — and what to do about it.

Concepts you need to know before you begin

Before moving on to classification and implementation, establish a common vocabulary. The DSA introduces several concepts that sound technical but have very specific consequences.

Concept What it means Why it applies to you
Provider of an intermediary service An entity providing a mere conduit, caching or hosting service The broadest category — if users can publish anything on your service, you are in the game
Hosting Storing information provided by a recipient of the service at their request (Article 3(g) DSA) A store with just one comment field already meets this definition
Online platform Hosting that publicly disseminates such information (Article 3(i) DSA) Reviews visible to all visitors = public dissemination
Marketplace A platform that allows consumers to conclude distance contracts with traders If you sell third-party products, you have an additional layer of obligations (Articles 30–32 DSA)
Notice and action mechanism A procedure for reporting illegal content and acting on notices (Article 16 DSA) No such mechanism = no exemption from liability for third-party content
Exemption under Article 19 DSA Exemption of micro and small enterprises from platform obligations (Section 3 of Chapter III) It does not exempt you from hosting or general obligations — and expires as the business grows
Dark patterns Interface practices that manipulate user decisions (Article 25 DSA) Forced consent, difficult opt-outs, time pressure — all of these are subject to audit

How to classify your service under the DSA

This is the foundation of the entire implementation. Incorrect classification means either overlooking more than a dozen obligations or implementing procedures that your business is not required to follow.

Decision tree: what type of provider are you?

Review each feature of your service and answer three questions:

  1. Can a user submit any content (a review, comment, photo, question or offer)?
  2. Is that content stored on your service?
  3. Is that content publicly visible to other users?
Answers Classification Layer of DSA obligations
No to question 1 Not an intermediary DSA obligations do not apply
Yes, yes, no Hosting General obligations (Articles 11–15) + hosting obligations (Articles 16–18)
Yes, yes, yes Online platform General + hosting + platform obligations (Articles 20–28)
Yes, yes, yes + consumer–trader contracts Marketplace All of the above + marketplace obligations (Articles 30–32)

A store with product reviews, a Q&A section, a gallery of customer photos or user profiles is an online platform, even if it sells only its own products. Classification depends on the service’s features, not on how you think of your business (Article 3(g) and (i) DSA).

Record the classification result, together with your reasoning and the date. Revisit it whenever you change your service’s functionality — adding a new module may change your category.

Check your enterprise status and the Article 19 exemption

Article 19 DSA removes the layer of platform obligations for micro and small enterprises. The thresholds are set out in Recommendation 2003/361/EC:

Status Headcount Annual turnover or balance sheet total
Microenterprise Fewer than 10 people Up to EUR 2 million
Small enterprise Fewer than 50 people Up to EUR 10 million

The exemption expires once the thresholds have been exceeded for two consecutive accounting periods. After losing this status, you have an additional 12 months to implement the platform obligations (Article 19 DSA). These are two separate, consecutive periods — do not treat them as one.

Add a status review to your calendar whenever the scale of your business changes. If you are growing quickly, the exemption may expire sooner than you expect.

Note: If you are a micro or small enterprise, do not copy platform obligations that you do not have to meet into your terms and conditions. Promising procedures that no one in the company actually handles creates an easier basis for a claim than the absence of a statutory obligation — with risks under consumer law and unfair contract terms rules.

Contact us — we will help you determine your service’s classification and the scope of your DSA obligations.

Obligations accumulate in layers — exactly what you need to implement

The DSA structures obligations like a pyramid: each successive layer is added to the previous one. Below is a definitive list of tasks for each category of provider.

General obligations — for all providers of intermediary services

Regardless of whether you are a hosting provider, platform or marketplace, you must meet these requirements:

  1. Point of contact for authorities (Article 11) — for Member State authorities, the European Commission and the European Board for Digital Services. Specify the language of communication and appoint a named person to manage the inbox.
  2. Point of contact for users (Article 12) — separate from the point of contact for authorities. It must allow electronic communication and be easily accessible.
  3. Legal representative in the EU (Article 13) — if the provider is not established in the Union but offers services on the EU market.
  4. Terms and conditions (Article 14) — expanded to describe content moderation policies and tools, restrictions on the use of the service, the procedure for amending the terms and conditions, the right to terminate use of the service, and the complaints system. If the service is accessible to minors, use language that minors can understand.
  5. Annual content moderation report (Article 15) — published at least once a year. Reports for 2026 onwards must use the templates set out in Implementing Regulation (EU) 2024/2835. Publication deadline for the 2026 report: 28 February 2027.
  6. Compliance with orders from authorities (Articles 9–10) — orders concerning illegal content and information about recipients of the service.

Hosting obligations — when you store third-party content

  1. Notice and action mechanism (Article 16) — a form with mandatory fields: the reason for the notice, the location or URL of the content, the reporting person’s full name or business name and email address, and a statement confirming a good-faith belief that the notice is accurate. Automatic acknowledgment of receipt where contact details have been provided. Notices must be processed in a timely, diligent, non-arbitrary and objective manner. The DSA does not specify a fixed number of days — the requirement to act “without undue delay" is assessed in light of the specific circumstances.
  2. Statement of reasons for moderation decisions (Article 17) — a template with fields covering: the scope of the restriction, the facts and legal grounds relied on, information on the use of automated means, and guidance on available remedies. This applies to content removal, restrictions on visibility, account suspension or termination, and demonetisation.
  3. Notification of law enforcement authorities (Article 18) — where there is suspicion of a criminal offence involving a threat to life or safety.

A valid Article 16 notice gives you, as a hosting provider, actual knowledge of the illegal content (Article 16(3) DSA). From that point onward, inaction means losing the exemption from liability for third-party content under Article 6 DSA. The absence of a reporting mechanism does not protect you — if you acquire knowledge from another source (email, telephone or social media), liability may still arise.

Platform obligations — when content is publicly visible

If your service is an online platform and you do not benefit from the Article 19 exemption:

  1. Internal complaint-handling system (Article 20) — free of charge, electronic, available for 6 months following the decision, and supervised by appropriately qualified staff (rather than exclusively by an algorithm). It covers complaints concerning content removal, restrictions on visibility, account suspension, termination of the service and restrictions on monetisation.
  2. Out-of-court dispute settlement (Article 21) — reference to certified ADR bodies designated by the Coordinator. In your terms and conditions, use a dynamic reference to the European Commission’s list rather than a closed list of entities.
  3. Priority for trusted flaggers (Article 22) — notices submitted by entities certified by the Coordinator must be processed as a priority. The list is published by the European Commission.
  4. Measures against misuse (Article 23) — in both directions: against users who publish manifestly illegal content and against users who flood the service with manifestly unfounded notices. Set thresholds and always issue a warning before suspension.
  5. Enhanced reporting (Article 24) — submission of statements of reasons to the Commission’s database.
  6. Prohibition of dark patterns (Article 25) — forced consent, difficult opt-outs, time pressure, unequal prominence of options and repeated prompts.
  7. Advertising disclosures (Article 26) — clear information that the content is an advertisement, on whose behalf it is presented and why it is being shown to the particular recipient. Advertising based on profiling using special categories of personal data is prohibited (Article 9(1) GDPR).
  8. Transparency of recommender systems (Article 27) — a description of the main parameters used in recommendation systems in the terms and conditions, written in plain and intelligible language. Users must be able to select and change their preferred recommendation option.
  9. Protection of minors (Article 28) — proportionate measures to protect privacy and safety. Advertising based on profiling using minors’ data is prohibited where the provider is aware with reasonable certainty that the recipient is a minor. The provider is not required to process additional personal data solely to determine whether the recipient is a minor. The European Commission’s July 2025 guidelines (source: UKE) recommend, among other things, private accounts by default and limiting the influence of recommender systems.

Marketplace obligations — when you enable consumer–trader contracts

If consumers use your platform to conclude contracts with third-party sellers (and you do not benefit from the Article 29 DSA exemption):

  1. Traceability of traders — know your business customer (Article 30) — before admitting a seller, collect and verify: their name, address, telephone number, email address, a copy of their identity document, payment account details, registration number and self-certification that the products or services offered comply with EU law. If the seller fails to provide the information, suspend the provision of services. Make the seller’s details available to consumers on the product page. Retain them for 6 months after the relationship ends.
  2. Compliance by design in the interface (Article 31) — design the interface so that sellers can provide legally required information (entity details, labelling, product safety information and identifying marks). Make efforts to assess whether the information is complete before allowing the offer to be published, and then randomly check the legality of products in official databases.
  3. Informing consumers about an illegal product (Article 32) — when you become aware of an illegal product or service, inform consumers who purchased it within the previous 6 months about its illegality, the seller’s identity and available remedies. If you do not have consumers’ contact details, make the information publicly available.

What to write and what to build — dividing the work between terms and conditions, product and operations

DSA implementation is 80% a product and operational task, not a drafting exercise. The terms and conditions merely describe processes that must actually exist. If you describe procedures that no one in the company handles, you create risk instead of reducing it.

Layer What it covers Who is responsible
Terms and conditions and documentation Terms and conditions under Article 14, description of moderation policies, information about recommendations (Article 27), illegal content reporting policy Lawyer + product owner
Product (interface and features) Reporting form with mandatory fields, appeal pathway, decision notifications, advertising disclosures, recommendation settings, compliance by design (Article 31) Product owner + UX + dev
Operations Handling notices and complaints, point of contact, event register, team training, annual reporting, seller verification Operations / customer care + compliance

Practical tips

  1. Create a separate illegal content reporting policy — linked from the form. It is easier to update independently of the terms and conditions and is clearer during an inspection.
  2. Prepare an Article 17 statement of reasons template with fields to complete. Do not draft each statement from scratch.
  3. Design a single reporting channel with separate branches — for DSA notices, consumer complaints and copyright infringement reports. Three independent pathways multiply deadlines and registers and increase the burden on your team.
  4. Take an inventory of automated filters — profanity filters, anti-spam tools and automatic blocking of specific phrases. If an algorithm can prevent content from being published, that is automated moderation. Users must be informed about it and have access to human review of the decision. This is the most frequently overlooked obligation in the entire implementation process.
  5. Align Article 27 DSA with the Omnibus Directive — the DSA obligation to describe recommendation parameters overlaps with the Omnibus Directive obligation to provide information about the ranking of offers. Expand your existing document in the relevant areas instead of maintaining two separate documents.

Event register — start collecting data from day one

The annual content moderation report (Article 15, extended by Article 24 for platforms) must follow the template structure set out in Implementing Regulation (EU) 2024/2835. The first full cycle under these templates covers the period from 1 January to 31 December 2026. Publication deadline: 28 February 2027.

If you do not maintain a register from day one, you will have to reconstruct historical data from emails, Slack and spreadsheets. This is costly, time-consuming and carries a risk that the data will be incomplete.

What to record in the register

  1. Orders from authorities (Articles 9–10) — date, content, action taken
  2. Illegal content notices — date, content of the notice, outcome of the assessment, decision taken
  3. Statements of reasons for moderation decisions — scope, grounds, use of automation
  4. Complaints about moderation decisions — date, content, outcome
  5. Out-of-court disputes (Article 21) — date, ADR body, outcome
  6. User warnings and suspensions (Article 23) — date, reason, threshold
  7. Trusted flagger data — number of notices, response time

From the outset, the register structure should correspond to the fields in Annex I to Regulation 2024/2835. This will make generating the report a matter of exporting data rather than spending weeks reconstructing it retrospectively.

The national layer — enforcement, not obligations

The absence of Polish legislation never suspended the substantive obligations. As an EU regulation, the DSA has applied directly since 17 February 2024. National legislation concerns the authority, procedure and penalties — it does not create new obligations but enables their enforcement.

Status as of September 2026

Event Date Status
Full application of the DSA 17.02.2024 In force
Commission referral of Poland to the CJEU (INFR(2024)2041) 07.05.2025 Proceedings pending — no confirmed judgment or discontinuance (source: European Commission)
Temporary designation of the President of UKE as Coordinator 15.05.2025 In force under Council of Ministers Resolution No. 67
Adoption of the act implementing the DSA (paper 2694) 04.09.2026 Adopted; the President’s decision was announced on 25.09.2026
Entry into force of the national act 30 days after publication in the Journal of Laws Requires verification — as of the date this article was prepared, no confirmed item number was available in the Journal of Laws

Penalties

Article 52 DSA requires Member States to provide for effective, proportionate and dissuasive penalties. The maximum fines under the Regulation are up to 6% of annual worldwide turnover (for breaches of obligations) or up to 1% (for supplying incorrect information). The complete national catalogue of penalties, procedural rules and rules applicable to corporate groups have not been fully confirmed on the basis of available sources — they will need to be verified after the act is published in the Journal of Laws.

User’s right to lodge a complaint

Article 53 DSA gives users the right to lodge a complaint with the Coordinator of the Member State where they are located (source: UKE — Digital Services Coordinator). A complaint does not automatically initiate formal administrative proceedings — the Coordinator assesses whether the matter warrants further action.

Interface and advertising audit — what to check before an inspection

Two areas are most frequently overlooked by product teams: dark patterns and the advertising layer.

Dark patterns (Article 25 DSA)

Audit your interface for:

  1. Forced consent — does the user have to accept terms in order to use a feature unrelated to those terms?
  2. Difficult opt-outs — is cancelling the service more difficult than signing up?
  3. Time pressure — does the interface pressure the user into making a decision (countdowns, “offer expires")?
  4. Unequal prominence of options — is the option that benefits the service visually dominant?
  5. Repeated prompts — does the interface repeatedly ask the same question after the user has refused?

Advertising and recommendations

  1. Check advertising disclosures (Article 26) — whether the recipient knows that the content is an advertisement, on whose behalf it is presented and why they are seeing it.
  2. Verify compliance with the prohibition on profiling based on sensitive data (Article 26(3) refers to Article 9(1) GDPR).
  3. Describe recommendation parameters (Article 27) — in plain language, allowing users to change their preferences.
  4. Assess whether the service is “accessible to minors" within the meaning of Article 28 — Recital 71 DSA indicates that a platform is accessible to minors, among other circumstances, where its terms and conditions allow minors to use it or the provider is aware that some recipients are minors. Simply not targeting the service at children does not disapply this obligation.

The DSA and GDPR — handling data in connection with a notice

A single illegal content notice engages both the DSA and GDPR. Article 16 DSA does not establish an autonomous legal basis for processing personal data — you must identify a legal basis under Article 6(1) GDPR (source: Regulation 2022/2065).

Activity Possible GDPR legal basis
Receiving and processing a notice Article 6(1)(c) (legal obligation under Article 16 DSA)
Providing the statement of reasons to the content author Article 6(1)(c) (obligation under Article 17 DSA)
Acknowledging receipt of a notice Article 6(1)(c) (Article 16(4) DSA)
Disclosing the reporting person’s identity to the content author Requires a separate legal basis — Article 17 DSA does not require disclosure of the reporting person’s personal data

The data minimisation principle (Article 5(1)(c) GDPR) and purpose limitation principle (Article 5(1)(b) GDPR) apply to each of these activities. There is no Polish DPA position or court judgment concerning the combined DSA–GDPR classification of content moderation by an online store — so it is worth conducting a separate analysis for your business model.

Recurring tasks — what to put in your calendar

DSA implementation is not a one-off exercise. Add the following to your calendar:

Activity Frequency
Annual moderation report (Articles 15/24) Once a year, published by 28 February for the previous year
Review of service classification Whenever the service’s functionality changes
Review of enterprise status (Article 19) Whenever the scale of the business changes
Update of terms and conditions (Article 14) Whenever moderation policies change
Customer service team training At least once a year
Interface audit for dark patterns Whenever a major UX change is made

How we can help your business implement the DSA

DSA implementation involves a lawyer, product owner, UX team and operations — it cannot be completed with a single document. We help e-commerce businesses, marketplaces and SaaS providers through the entire process: from service classification and designing reporting mechanisms to launching an event register and preparing the first report.

Our support is available at three levels:

  1. Operational minimum — service classification, determination of enterprise status, points of contact, Article 16 reporting mechanism, Article 14 terms and conditions.
  2. Solid foundation — plus a complaint-handling system (Article 20), an Article 17 statement of reasons template, an event register structured for reporting, an automated moderation audit and a specification of form fields for the product team.
  3. Full protection — plus a dark patterns audit, advertising and recommendation layer, protection of minors in line with Commission guidelines, marketplace obligations under Articles 30–32 and management of the reporting cycle.

We work with real scenarios from your service — we do not create documents “just in case"; we design rules where risks actually arise.

Contact us — we will determine the scope of your service’s DSA obligations and divide the tasks between the terms and conditions, product and operational layers.

Implementing the DSA in e-commerce — where to start

The DSA has applied for more than two years. The Polish implementing act activates supervision by the President of UKE — but the substantive obligations exist independently of it. If your service allows users to publish any content, the DSA applies to you.

Three things to do first:

  1. Classify the service — review it feature by feature and record the result with your reasoning.
  2. Launch an event register structured according to the reporting templates — every day without a register means more historical data to reconstruct.
  3. Build a reporting form with the mandatory Article 16 fields and appoint someone to handle notices.

If you need support with classifying your service, designing reporting mechanisms or preparing DSA-compliant terms and conditions — contact us.

Frequently asked questions

Does a product review module really make my store an online platform within the meaning of the DSA?

Yes, if the reviews are publicly visible. Article 3(i) DSA defines an online platform as a hosting service that publicly disseminates information provided by a recipient of the service. A review visible to all visitors meets this condition. Classification depends on the service’s features, not on how you think of it. Q&A sections, galleries of customer photos and user profiles are treated in the same way.

I am a small enterprise — what can I postpone under Article 19 DSA?

Article 19 excludes the obligations in Section 3 of Chapter III DSA — in other words, the platform obligations: an internal complaint-handling system, out-of-court dispute settlement, priority for trusted flaggers, measures against misuse, enhanced reporting, the prohibition of dark patterns, advertising disclosures, transparency of recommendations and protection of minors. You cannot postpone the general obligations (points of contact, terms and conditions and moderation report) or hosting obligations (reporting mechanism and statements of reasons for decisions). The exemption expires after the thresholds have been exceeded for two consecutive accounting periods, followed by an additional 12-month transitional period.

How long do I have to process an illegal content notice?

The DSA does not specify a fixed number of days. Article 16(6) requires notices to be processed “in a timely, diligent, non-arbitrary and objective manner". The requirement to act without undue delay is assessed in light of the specific circumstances. Remember, however, that a valid notice gives you actual knowledge of the content — from that point onward, inaction means losing the exemption from liability for third-party content (Articles 6 and 16(3) DSA).

Is a profanity filter subject to the DSA?

Yes. If an algorithm can prevent user content from being published, this constitutes automated content moderation. You must inform users about it in the terms and conditions (Article 14) and provide a pathway for human review of the decision. This also applies to anti-spam filters and all automatic blocking mechanisms.

Since the Polish act is only now entering into force, do I still have time to implement the requirements?

No. As an EU regulation, the DSA has applied directly since 17 February 2024. The Polish act concerns the supervisory authority, procedure and penalties — it does not create new obligations but enables their enforcement. Non-compliance dates back to February 2024, and the President of UKE has temporarily served as the Digital Services Coordinator since May 2025 under a Council of Ministers resolution.

What do I need to record in the register so that I can submit the report without reconstructing historical data?

From the outset, the register should correspond to the fields in Annex I to Implementing Regulation (EU) 2024/2835. Record: orders from authorities, illegal content notices, moderation decisions and their statements of reasons, complaints about decisions, out-of-court disputes, user warnings and suspensions, and data on notices from trusted flaggers. The first report using this structure covers the period from 1 January to 31 December 2026 and must be published by 28 February 2027.

POLECANE

mogą Cię zaciekawić

Wybrane przykłady projektów, w których wspieraliśmy firmy w sprawach prawnych — od doradztwa regulacyjnego i compliance, przez projekty technologiczne, po transakcje i bieżącą obsługę biznesu.