Poland’s Digital Services Act obligations: a practical guide for online businesses
Your online store sells only its own products. It is nothing like Facebook or TikTok. But customers can post reviews beneath product listings. According to the approved analysis in this article, that feature makes the store an online platform under the Digital Services Act (DSA)—EU Regulation 2022/2065. A single feature can therefore bring obligations that your terms and conditions may not mention.
The DSA has applied in full since February 17, 2024. As an EU regulation, it applies directly; its substantive requirements did not have to wait for a Polish statute. Poland’s later national measures concern supervision, procedure, and penalties. Businesses that deferred implementation while waiting for Polish legislation should not treat its arrival as a fresh start.
This guide works through the decisions a business needs to make: how to classify each service feature, whether an exemption applies, what to build and document, what data to retain, and how the Polish enforcement framework fits in.
First, identify the service you provide
The DSA applies obligations in layers. These terms determine which layers you need to assess:
| Term | Meaning | Practical consequence |
|---|---|---|
| Provider of an intermediary service | A provider of a mere conduit, caching, or hosting service. | This is the broadest category to consider when users can publish material through your service. |
| Hosting | Storing information supplied by a recipient of the service at that recipient’s request (Article 3(g) DSA). | On the source article’s analysis, even a store with one customer-comment field can meet this definition. |
| Online platform | A hosting service that publicly disseminates that information (Article 3(i) DSA). | Publicly visible customer reviews can bring the platform layer into scope. |
| Marketplace | A platform enabling consumers to conclude distance contracts with traders. | Contracts with third-party sellers can bring additional duties under Articles 30–32 DSA. |
| Notice and action mechanism | A process for reporting potentially illegal content and acting on notices (Article 16 DSA). | Notices affect both your operating process and the assessment of liability for third-party content. |
| Article 19 exemption | An exemption for micro and small enterprises from the platform obligations in Section 3 of Chapter III. | It does not remove the general or hosting obligations, and business growth can end it. |
| Dark patterns | Interface practices that manipulate user decisions (Article 25 DSA). | Consent flows, opt-outs, prompts, and presentation of choices need review where this obligation applies. |
Classify the service feature by feature
For every feature—reviews, questions and answers, customer photos, user profiles, or offers—ask:
- Can a user submit content?
- Is that content stored through your service?
- Is it publicly visible to other users?
| Answers | Working classification | Obligations to assess |
|---|---|---|
| No to the first question | Not an intermediary on this feature-based assessment | DSA intermediary obligations do not arise from that feature. |
| Yes, yes, no | Hosting | General obligations (Articles 11–15) and hosting obligations (Articles 16–18). |
| Yes, yes, yes | Online platform | General, hosting, and platform obligations (Articles 20–28). |
| Yes, yes, yes, and the service enables consumer–trader contracts | Marketplace | The preceding layers and marketplace obligations (Articles 30–32), subject to the relevant exemption. |
A store does not avoid the platform classification simply because it sells only its own inventory. The relevant question is what its service does with user-provided information (Article 3(g) and (i) DSA).
Record your conclusion, reasoning, and the date. Revisit the assessment whenever you add or change a feature. A new customer-photo gallery or Q&A module may change the result.
Check whether the micro or small enterprise exemption applies
Article 19 DSA removes the platform-obligation layer for micro and small enterprises. The source uses the thresholds in Recommendation 2003/361/EC:
| Status | Headcount | Annual turnover or balance sheet total |
|---|---|---|
| Microenterprise | Fewer than 10 people | Up to EUR 2 million |
| Small enterprise | Fewer than 50 people | Up to EUR 10 million |
Under the source article’s account, the exemption ends after the thresholds are exceeded in two consecutive accounting periods. A further 12 months is then available to implement the platform obligations (Article 19 DSA). Keep the two-period test distinct from the subsequent transition period, and review your status as the business grows.
Do not promise exempted platform procedures in your terms and conditions if no one will operate them. The source flags a separate consumer-law and unfair-terms risk in describing processes that do not exist.
If classification or enterprise status is uncertain, contact us to assess the scope of your service’s DSA obligations.
Implement the obligations in layers
The lists below follow the approved source’s classification and claims. Apply each additional layer only after assessing your service and any exemption.
General obligations: intermediary services
- Authority contact point (Article 11). Establish a point of contact for Member State authorities, the European Commission, and the European Board for Digital Services. Specify the language of communication and assign a named person to monitor the inbox.
- User contact point (Article 12). Provide an easily accessible electronic contact route for users, distinct from the authority contact point.
- EU legal representative (Article 13). Assess this requirement if the provider is not established in the EU but offers services to the EU market.
- Terms and conditions (Article 14). Describe content-moderation rules and tools, restrictions on use, changes to the terms, ending use of the service, and the complaints process. Where the service is accessible to minors, use language they can understand.
- Annual content-moderation report (Article 15). Publish at least once a year. The source states that reports for 2026 onward use the templates in Implementing Regulation (EU) 2024/2835, with February 28, 2027 identified as the publication deadline for the 2026 report.
- Orders from authorities (Articles 9–10). Put a process in place for orders concerning illegal content and information about recipients of the service.
Hosting obligations: storing user-provided content
- Notice and action (Article 16). Build a reporting route that captures the reason for the notice, the content’s location or URL, the reporting person’s name or business name and email address, and a good-faith statement about the notice’s accuracy. Acknowledge receipt automatically where contact details are provided. Assess notices in a timely, diligent, non-arbitrary, and objective way. The DSA gives no fixed number of days; the speed required depends on the circumstances.
- Statements of reasons (Article 17). Prepare a decision template recording the restriction imposed, factual and legal grounds, use of automated means, and available remedies. The source applies this to removal, reduced visibility, account suspension or termination, and restrictions on monetization.
- Law-enforcement notification (Article 18). Establish an escalation route for suspicion of a criminal offense threatening life or safety.
The source states that a valid Article 16 notice gives a hosting provider actual knowledge of illegal content (Article 16(3) DSA). On its account, remaining inactive from that point means losing the Article 6 DSA exemption from liability for that third-party content. Having no form is not a safeguard: knowledge may arrive by email, phone, or social media.
Platform obligations: publicly disseminating user content
If the service is an online platform and the Article 19 exemption does not apply, assess the following:
- Internal complaint-handling (Article 20). Provide a free electronic system available for six months after a decision, with oversight by appropriately qualified staff rather than an algorithm alone. The source lists decisions about removal, visibility, account suspension, ending the service, and monetization.
- Out-of-court dispute settlement (Article 21). Direct users to certified dispute-settlement bodies. In the terms, refer dynamically to the European Commission’s list rather than hard-coding a closed list that may become outdated.
- Trusted flaggers (Article 22). Prioritize notices from entities certified by a Digital Services Coordinator. The European Commission publishes a list.
- Misuse (Article 23). Address both manifestly illegal posts and repeated manifestly unfounded notices. Set operational thresholds and warn before suspension.
- Enhanced reporting (Article 24). Provide statements of reasons to the Commission’s database.
- Dark patterns (Article 25). Review forced consent, difficult opt-outs, time pressure, unequal prominence of options, and repeated prompts.
- Advertising (Article 26). Make clear that content is an advertisement, on whose behalf it appears, and why the recipient sees it. The source also identifies the ban on profiling-based advertising using special categories of personal data under Article 9(1) GDPR.
- Recommender systems (Article 27). Explain their main parameters in plain-language terms and provide the ability to select and change a preferred recommendation option.
- Minors (Article 28). Adopt proportionate privacy and safety measures. Do not use profiling-based advertising with minors’ data where you know with reasonable certainty that the recipient is a minor; the source notes that you need not process additional personal data solely to establish age. The Commission’s July 2025 guidance, described by Poland’s Office of Electronic Communications (UKE), recommends measures including private accounts by default and limiting the influence of recommender systems.
Marketplace obligations: consumer contracts with third-party traders
If consumers can conclude contracts with external sellers through your platform, assess Articles 30–32 unless the Article 29 exemption applies:
- Trader traceability (Article 30). Before admitting a seller, collect and verify the information identified in the source: name, address, telephone number, email, a copy of an identity document, payment-account details, registration number, and a self-certification that the offering complies with EU law. Suspend the service if required information is not supplied. Make seller details available to consumers on the product page and retain the information for six months after the relationship ends.
- Compliance by design (Article 31). Design listing interfaces so traders can provide legally required business, labeling, product-safety, and identification information. Make efforts to check completeness before publication, then conduct random checks against official product databases.
- Illegal products or services (Article 32). On learning of an illegal product or service, inform consumers who bought it within the previous six months of its illegality, the seller’s identity, and available remedies. If you lack their contact details, publish the information.
Divide the work between legal documents, product, and operations
A DSA project cannot be completed by editing terms and conditions alone. The source characterizes it as predominantly a product and operations task: documents should describe working processes, not substitute for them.
| Workstream | Deliverables | Typical owners |
|---|---|---|
| Terms and documentation | Article 14 terms, moderation rules, Article 27 recommendation information where applicable, and an illegal-content reporting policy. | Legal counsel and product owner |
| Product and interface | Notice form, routes to challenge decisions, decision messages, advertising labels, recommendation settings, and marketplace compliance-by-design features where applicable. | Product owner, UX, and developers |
| Operations | Notice and complaint handling, monitored contact points, event register, training, annual reporting, and trader verification where applicable. | Operations or customer care, with compliance |
Five practical design choices follow from that division:
- Keep the illegal-content reporting policy separate and link to it from the notice form. It can then be updated without rewriting the whole set of terms.
- Use an Article 17 statement-of-reasons template with fields staff complete for each decision.
- Create one intake channel with distinct branches for DSA notices, consumer complaints, and copyright reports. Preserve the different processes behind those branches without forcing users to find three unrelated entry points.
- Inventory automated filters, including profanity and anti-spam tools. If a tool can block publication, the source treats it as automated moderation that should be described to users, with a route to human review.
- Coordinate recommendation disclosures with existing ranking information. The source identifies an overlap between Article 27 DSA and the Omnibus Directive’s ranking disclosures. Update an existing document where appropriate rather than maintaining inconsistent explanations.
Build the event register before the reporting deadline
According to the source, the first full reporting cycle using the templates in Implementing Regulation (EU) 2024/2835 runs from January 1 through December 31, 2026, with publication by February 28, 2027. Article 15 reporting is expanded by Article 24 for platforms.
Start recording events when the process starts. Reconstructing a year from email, messaging channels, and spreadsheets is slower and less reliable. Structure the register around the fields in Annex I to the implementing regulation and record, as relevant:
- Authority orders (Articles 9–10): date, content, and action taken.
- Illegal-content notices: date, substance, assessment, and decision.
- Moderation decisions and reasons: restriction, grounds, and use of automation.
- Complaints about decisions: date, complaint, and outcome.
- Out-of-court disputes (Article 21): date, body, and outcome.
- Warnings and suspensions (Article 23): date, reason, and threshold applied.
- Trusted-flagger notices: volumes and response times.
A register designed for the eventual report makes reporting an export and review exercise rather than a retrospective investigation.
Understand Poland’s enforcement framework
The DSA’s substantive obligations have applied directly since February 17, 2024. The approved source distinguishes those obligations from Polish measures addressing the supervisory authority, procedures, and penalties. For a business outside Poland serving the Polish market, that distinction matters: waiting for a Polish act did not postpone the EU regulation’s requirements.
Position described in the source as of September 2026
| Event | Date | Status stated in the approved source |
|---|---|---|
| Full application of the DSA | February 17, 2024 | Applicable. |
| European Commission referral of Poland to the Court of Justice of the EU, INFR(2024)2041 | May 7, 2025 | Proceedings described as pending, with no confirmed judgment or discontinuance (European Commission announcement; see also the Commission’s Poland page). |
| Temporary designation of the President of UKE as Digital Services Coordinator | May 15, 2025 | Based on Council of Ministers Resolution No. 67. UKE is Poland’s Office of Electronic Communications. |
| Adoption of the Polish DSA implementing act, Sejm paper No. 2694 | September 4, 2026 | Described as adopted; the President’s decision was announced on September 25, 2026. The source says the act designates the President of UKE as Coordinator. |
| Entry into force of the national act | 30 days after publication in the Dziennik Ustaw (Poland’s Journal of Laws) | Requires verification. When the source was prepared, it did not have a confirmed Journal of Laws item number. |
Do not treat the adoption date, a presidential announcement, publication, and entry into force as interchangeable. The source expressly leaves the publication reference and resulting effective date to be checked.
Penalties and user complaints
Article 52 DSA requires Member States to provide effective, proportionate, and dissuasive penalties. The source identifies maximum fines of up to 6% of annual worldwide turnover for breaches of obligations and up to 1% for incorrect information. It does not claim that the complete Polish penalty schedule, procedure, or treatment of corporate groups had been verified: those details require checking after publication of the national act in the Journal of Laws.
Under Article 53 DSA, a user may complain to the Digital Services Coordinator of the Member State where the user is located (UKE’s Coordinator information). A complaint does not automatically open formal administrative proceedings; the Coordinator assesses whether further action is warranted.
Audit the interface, advertising, and automated decisions
Where the platform obligations apply, review actual user journeys—not only policy wording.
Dark patterns
For Article 25, test whether the interface:
- Pressures a user into consent to use an unrelated feature.
- Makes cancellation or opting out harder than signing up.
- Uses countdowns or “offer expires” messages to pressure decisions.
- Gives the service’s preferred choice disproportionate visual prominence.
- Repeatedly asks after a user has refused.
Advertising, recommendations, and minors
Check whether users can tell that a placement is an advertisement, on whose behalf it appears, and why it is shown to them (Article 26). Review profiling against the prohibition concerning the special categories of data in Article 9(1) GDPR.
For Article 27, explain recommendation parameters plainly and check the preference-setting route. For Article 28, assess whether the platform is accessible to minors. As the source notes, Recital 71 includes circumstances in which the terms allow minors to use the platform or the provider knows some recipients are minors. Not marketing a service to children does not, by itself, settle that assessment.
Finally, test what happens when an automated filter rejects a review or comment. The source’s practical advice is to tell users about automated moderation in the terms and provide a route for a person to review a blocked-publication decision.
Handle notice data under both the DSA and GDPR
An illegal-content notice can contain personal data about the reporting person, the content author, and others. The source states that Article 16 DSA does not itself supply a standalone GDPR legal basis for processing personal data; identify a basis under Article 6(1) GDPR.
| Activity | Possible basis or issue identified in the source |
|---|---|
| Receiving and assessing a notice | Article 6(1)(c) GDPR: legal obligation associated with Article 16 DSA. |
| Sending the content author a statement of reasons | Article 6(1)(c) GDPR: obligation associated with Article 17 DSA. |
| Acknowledging receipt of a notice | Article 6(1)(c) GDPR: Article 16(4) DSA. |
| Disclosing the reporting person’s identity to the content author | Requires a separate basis. Article 17 DSA does not require disclosure of the reporting person’s personal data. |
Apply data minimization under Article 5(1)(c) GDPR and purpose limitation under Article 5(1)(b) GDPR throughout. The approved source reports no Polish data-protection-authority position or court judgment resolving the combined DSA–GDPR classification of moderation in an online store. Analyze the data flows for your own business model rather than assuming one generic workflow answers every case.
Put recurring reviews on the calendar
DSA implementation needs maintenance as the service changes.
| Task | Review point stated in the source |
|---|---|
| Annual moderation reporting (Articles 15/24) | Once a year; the source identifies February 28 as the publication date for the preceding year’s report. |
| Service classification | Whenever functionality changes. |
| Enterprise status for Article 19 | Whenever the scale of the business changes. |
| Article 14 terms | Whenever moderation rules change. |
| Customer-service training | At least annually. |
| Dark-pattern audit | Whenever a major UX change is made. |
The fastest useful start is to document your classification, create the reporting register, and launch an Article 16 notice form with a named owner for incoming notices. Those steps establish the facts, data, and operating process on which the rest of the implementation depends.
How we can help
We support e-commerce businesses, marketplaces, and SaaS providers with service classification, notice mechanisms, event registers, and reporting preparation. The work can be scoped to the service rather than producing documents for features it does not have:
- Operational minimum: classification, enterprise-status assessment, contact points, Article 16 notice mechanism, and Article 14 terms.
- Solid foundation: the minimum plus complaint handling where applicable, an Article 17 reasons template, a reporting-ready register, an automated-moderation audit, and form specifications for the product team.
- Full implementation: the foundation plus interface and advertising audits, recommender-system and minors assessments, applicable marketplace duties, and the annual reporting cycle.
Contact us to map the DSA requirements to your service and divide the work between legal documentation, product, and operations.
Frequently asked questions
Can public product reviews make a store an online platform?
On the approved source’s analysis, yes. A publicly visible review is user-provided information stored and disseminated through the service; see Article 3(i) DSA. Assess Q&A sections, customer-photo galleries, and user profiles in the same feature-based way.
What can a small enterprise defer under Article 19?
The source identifies the platform obligations in Section 3 of Chapter III, including complaint handling, out-of-court settlement, trusted-flagger priority, misuse measures, enhanced reporting, dark patterns, advertising, recommender systems, and minors’ protection. The general and hosting layers remain to be addressed. Track the two consecutive accounting periods and the separate 12-month transition described above.
How quickly must an illegal-content notice be decided?
Article 16(6) gives no fixed number of days. The source calls for timely, diligent, non-arbitrary, and objective processing, assessed in context. A valid notice also matters for the actual-knowledge and liability-exemption analysis under Articles 16(3) and 6 DSA.
Does a profanity or anti-spam filter matter?
Yes, if it can prevent user content from being published. The source treats that as automated moderation: describe the tool in the terms and provide a route to human review of the decision.
Does Poland’s later implementing act give businesses extra time?
No. The source’s central distinction is that the DSA has applied directly since February 17, 2024, while the Polish framework addresses enforcement. Check the national act’s publication and effective date separately; the approved source did not confirm its Journal of Laws reference.
What should we retain for the annual report?
Build the register around Annex I to Implementing Regulation (EU) 2024/2835. Capture authority orders, notices, decisions and reasons, complaints, out-of-court cases, warnings and suspensions, and trusted-flagger activity as applicable. The source identifies the first full template-based period as January–December 2026, with publication by February 28, 2027.