Data Protection & AI

DSA meets GDPR

What the (final) guidelines 3/2025 of the EDSA mean for online platforms

On 17.09.2026, the European Data Protection Board (EDSA) has adopted the final version of its Guidelines 3/2025 on the interplay between DSA and GDPR Accepted. For companies that store, moderate, recommend, or monetize user content, the document is a first-draft guidance on how the requirements of DSA and GDPR can be reconciled in individual cases.

EDSA guidelines DSA - GDPR

Table of Contents

Two regulations regulate – side by side

An example: A hosting provider receives a report about illegal content, checks it partially automatically, removes the post, explains the decision to the person concerned and records the process for any possible complaint procedure. From the DSA’s perspective, these are the types of Article 16, 17 and 20 of the DSA. From the GDPR perspective, each of these steps is a processing of personal data that needs a legal basis, a purpose and a deletion period.

Regarding the relationship between the two legal acts, Article 2(4)(g) of the DSA states that the GDPR „remains unaffected“; it is not a lex specialis (Guidelines, Rz 8 et seq.). Furthermore, the DSA refers to the GDPR in key places: the profiling in Article 26(3) and Article 28(2) of the DSA is that of Article 4(4) of the GDPR, the special categories are those of Article 9(1) of the GDPR (Guidelines, Rz 4).

Simultaneity also determines the supervisory level. In Austria, according to the Coordinator for Digital Services Act, Koordinator für digitale Dienste is KommAustria, the dispute resolution body is the RTR-GmbH. For the GDPR, the Data protection authority One and the same matter can affect both spheres at the same time, and as a result, two authorities may be involved who examine the matter according to different standards.

What significance the guidelines have

The EDSA guidelines are issued in accordance with Art. 70(1)(e) GDPR and are not legally binding. That is correct; this is a data protection law provision. The guidelines are not intended to interpret the GDPR; that remains the responsibility of the Commission, the European Digital Services Board, and the European Court of Justice. The EDSA, on the other hand, clarifies how the GDPR is to be applied in the circumstances that the EDSA specifies (Guidelines, § 5).

In practice, this certainly has great potential for impact. The data protection authorities in the EU are examining these lines, and anyone who deviates from them must be able to justify their deviation. Following a consultation round, a firm position has also been established that cannot be dismissed as a working draft. Two topics remain explicitly excluded: political advertising under Regulation (EU) 2024/900 and access to research data under Article 40 of the DSA (Guidelines, Rz 6).

Voluntary measures against illegal content

Art 7 DSA takes away from providers the concern that voluntary search for illegal content costs the liability privileges of Art 4 to 6 DSA (Good Samaritan Clause). However, a data protection legal permission does not exist in this case. Anyone who filters, classifies, or trains models on their own initiative needs a legal basis, and that is regularly the legitimate interest pursuant to Art. 6(1)(f) GDPR (Guidelines, Rz 17).

The EDSA requires a documented assessment to be made in this regard. The interest in identifying illegal content is legitimate, but the necessity must be demonstrated; the assessment also includes the reasonable expectations of users and the question of whether children are affected (Guidelines, Rz 18). It is also important to ensure that data from moderation processes is not used for the personalization of content or advertising. ErwGr 56 The EDSA also clarifies that the EDSA does not permit profiling for the purpose of possible criminal investigation (Guidelines, Rz 22).

However, if there is a specific legal obligation, for example under Article 17 of the Copyright Directive (EU) 2019/790, or to comply with a deletion request under Article 17 of the GDPR, Article 6(1)(c) GDPR serves as the legal basis. The obligation must then be clear, precise and foreseeable, and the processing proportionate (Guidelines, para. 20 ff).

Reporting procedure

The duty to report and take remedial action pursuant to Article 16 DSA applies to every hosting provider, regardless of size (Guidelines, Rz 26; ErwGr 50 DSA). The committee draws a clear line regarding the scope of the data collected (Guidelines, Rz 31 f):

  1. The reporting form must enable the identification of the reporting person, but it must not make it a prerequisite. Anything else applies only if the illegality cannot be judged without identifying the person.
  2. No further data should generally be requested beyond name and email address in accordance with Art. 16(2) DSA.
  3. To prevent misuse of the reporting system, identification data may be processed, based on Art. 6(1)(f) GDPR (cf. ErwGr 53 DSA).
  4. The identity of the reporting person may only be disclosed to the affected person insofar as necessary, for example in cases of intellectual property rights violations. The reporting person must be informed about this in accordance with Article 13 of the GDPR.

In reports regarding offenses under Articles 3 to 7 of Directive 2011/93/EU, the name and e-mail address are not to be collected in the first place (Guidelines, Rz 29).

Blockages and complaints

Article 23 of the DSA allows online platforms to suspend their services from being accessed by individuals who are abusing the system, and also to suspend the processing of reports and complaints that are clearly unfounded. Article 20 of the DSA requires internal complaint management overseen by qualified individuals. This brings a principle to the fore that receives little attention otherwise: the accuracy pursuant to Article 5(1)(d) of the GDPR. Suspendences based on incorrect data hit the affected parties hard, which is why the data base must be accurate and the storage period limited to the purpose (Guidelines, Rz 42 et seq.).

The committee also states that complaint procedures and bans do not affect the rights under the GDPR. Those who have been banned can still request information, deletion, and even data portability (Guidelines, Rz 43).

Manipulative design

Article 25(1) of the DSA prohibits manipulative interfaces (Dark Patterns) on online platforms; Article 2 leg cit assumes what is already covered by the GDPR or the UGP Directive. The demarcation is therefore a question of jurisdiction, and the EDSA lists two criteria (guidelines, Rz 45):

  • Are personal data processed? and
  • Does the affected behavior affect this processing?

The difference can be illustrated by an example. The „Only a few pieces left in stock“ notice is a sales pressure and therefore more of a matter of the Lauterkeit Act. The addition „Enter your e-mail address, date of birth and address now and reserve“ aims at the disclosure of additional data and therefore falls under the GDPR. There, the matter is usually decided because such a design violates the principle of good faith under Art. 5(1)(a) GDPR.

The committee devotes special attention to addictive patterns such as endless scrolling, autoplay, streak mechanisms, or countdowns, which the DSA identifies in ErwGr 81 to 83 as a source of systemic risks (Guidelines, Rz 49 f).

Advertising

Article 26(1) of the DSA requires real-time advertising transparency and is a legal basis for data from advertisers under Art. 6(1)(c) GDPR. It is not explicitly a legal basis for the display itself, i.e., for determining who sees which ads. Those who conduct targeting still need consent or another basis under Art. 6(1) GDPR (Guideline, Recital 60).

The timing is also important. The information provided under Article 26 of the DSA is provided with the advertisement, whereas the information under Article 13 of the GDPR is already provided at the moment of collection. The DSA transparency therefore does not replace the data protection information; it complements it (Guidelines, para. 55 et seq.).

Recommendation systems

Recommendation systems usually process personal data. The EDSA goes one step further and does not rule out that the selection and arrangement of content can constitute a decision within the meaning of Article 22(1) of the GDPR, particularly in the case of housing or job offers (Guidelines, Rz 91 et seq.).

In addition, Article 38 of the DSA requires very large online platforms and search engines to offer an option that is not based on profiling. The committee clarifies what this means. Both options are to be presented equally; any nudging towards profiling is not allowed, and while the profile-free option is active, it must not continue to be profiled for future recommendations in the background. The decision must be respected beyond the meeting until users actively change it (Guidelines, Rz 94). The configuration data itself may only be used to fulfill the DSA obligations (Guidelines, Rz 95).

Protection of minors

Article 28 of the DSA requires platforms accessible to minors to maintain a high level of protection and prohibits advertising based on profiling when the minor status is known with sufficient certainty. The EDSA recognizes Article 28(1) and (2) of the DSA as a legal basis under Article 6(1)(c) of the GDPR, however, only to the extent that the controller demonstrates in the individual case that the processing is necessary and proportionate (Guidelines, point 99).

Art. 28(3) DSA does not impose an obligation to process additional data. Age checks that enable unambiguous online identification, such as uploading an official photo ID, should not be based solely on Art. 28 DSA (Guidelines, Rz 100). Age or age range should not be stored permanently; only whether the usage requirement is met must be recorded (Guidelines, Rz 101). Biometric methods for unambiguous identification should be avoided, especially when children’s data are involved (Guidelines, Rz 99).

Whether an age verification is actually necessary depends on the risk. In low-risk cases, it may be sufficient to provide protective measures for all users without distinguishing between minors and adults (Guidelines, Rz 102).

Systemic risks and DSFA

For very large online platforms and search engines, Articles 34 and 35 require an assessment of systemic risks, explicitly also with regard to the fundamental rights under Articles 7 and 8 of the GDPR. The EDSA draws a practical conclusion from this: If a systemic risk to data protection is identified, a data protection impact assessment under Article 35 of the GDPR will usually also be required (Guidelines, Rz 106 and 114). Conversely, data minimization, pseudonymization, and data protection through technological design under Article 25 of the GDPR can serve as risk mitigation measures under Article 35 of the DSA (Guidelines, Rz 109).

Supervision

Member states do not have to make the data protection authority the zdasDSA authority, and in Austria they have not done so (Guidelines, Rz 121). The committee therefore bases its cooperation on Article 8(3) of the GDPR and the principle of loyal cooperation under Article 4(3) of the EU Charter: If the zdasDSA authority examines whether a conduct is compatible with the GDPR, it must consult the competent data protection authority, and vice versa (Guidelines, Rz 125; CJEU 04.07.2023, C-252/21).

Conclusion

The guidelines bring little surprising news, but they do provide a lot of insurance. The DSA creates new obligations, but no new regulatory requirements. For platform operators, this means one thing above all else. DSA and GDPR cannot be treated separately. Anyone who has built their processes primarily from one perspective should look at them from the other side again. The guidelines provide, for the first time, a useful framework for auditing from a data protection perspective.

Frequently Asked Questions (FAQs)

Does the DSA also apply to us if we don’t operate a large platform?

In many respects, yes. The obligations regarding reporting and resolution procedures, as well as the grounds for moderation decisions, apply to every hosting provider regardless of size. Only the additional obligations for very large platforms and search engines are linked to the threshold of 45 million users; for small and medium-sized businesses, the DSA provides for specific concessions.

Does a DSA requirement replace the legal basis under the GDPR?

Only where the DSA formulates a clear, precise and predictable obligation can it be considered a legal obligation under Art. 6(1)(c) GDPR. The model example for the limit is Art. 26(1) DSA: For the data of the advertisers, it is the legal basis; for the question of who is shown an advertisement, it is explicitly not (Guidelines, Rz 60).

We are integrating open-source components – does this make us liable?

For your own product, yes. Anyone who integrates third-party components and brings the resulting product to market commercially is the manufacturer of the overall product and must include these components in their risk assessment and vulnerability management. The open-source project itself remains unaffected by this.

Can we continue to use advertising to target interests?

Yes, provided there is a suitable legal basis. If processing is based on legitimate interest, there is an absolute right to object in case of direct advertising pursuant to Art. 21(2) GDPR (Guidelines, Recital 73). Any profiling involving special categories of personal data is excluded, including consent, and even if the segment is purchased. What matters is the message conveyed, not how it is named.

Do we need to check the age of our users?

Not on a blanket basis, but based on risk assessment. If the assessment concludes that an age check is required, it should suffice to conclude that someone meets the usage requirement; under the EDSA, no further processing of additional data is permitted in accordance with Art 28 Abs 3 DSA. However, storing age or age range permanently is excessive (Guidelines, Rz 101).

Who is responsible in Austria for the KommAustria or the data protection authority?

Both, depending on the perspective, regarding the same matter. KommAustria, as the coordinator for digital services, monitors compliance with the DSA by providers based in Austria; the data protection authority is the GDPR authority. With very large platforms, oversight of the obligations under Section 5 rests solely with the Commission (Guidelines, Rz 123). The EDSA expects that the authorities will consult before judging one of them based on the other’s regime (Guidelines, Rz 125).

Does your platform come to the right conclusions?

ATB.LAW helps you set up registration and moderation processes, advertising logics, and age verification in a way that they comply with both regulations (DSA and GDPR). Contact Stefan Knotzer and Roman Taudes at any time under office@atb.law or by phone at 01 39 12345 for a non-binding initial consultation.

More articles

Artificial Intelligence (AI) and sensitive data

What Art. 9 GDPR means for chatbots, AI training, and companies
Picture of Roman Taudes
Roman Taudes
EU Commission CRA Guidelines

Cyber Resilience Act: EU Commission guidelines published

Get companies out of standby mode and into the fast lane for the CRA.
Picture of Stefan Knotzer
Stefan Knotzer

When the model sings: Copyright limits of AI training after the Suno ruling

Where AI & Copyright Hit a Sour Note
Picture of Stefan Knotzer
Stefan Knotzer