{"id":9344,"date":"2026-09-28T08:00:00","date_gmt":"2026-09-28T06:00:00","guid":{"rendered":"https:\/\/atb.law\/?post_type=blog-post&#038;p=9344"},"modified":"2026-09-27T15:02:16","modified_gmt":"2026-09-27T13:02:16","slug":"edsa-guidelines-dsa-dsgvo-analysis","status":"publish","type":"blog-post","link":"https:\/\/atb.law\/en\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/","title":{"rendered":"DSA meets GDPR"},"content":{"rendered":"<h2 id=\"page-zwei-verordnungen-regulieren-seite-an-seite\">Two regulations regulate \u2013 side by side<\/h2>\n<p>An example: A hosting provider receives a report about illegal content, checks it partially automatically, removes the post, explains the decision to the person concerned and records the process for any possible complaint procedure. From the DSA\u2019s perspective, these are the types of Article 16, 17 and 20 of the DSA. From the GDPR perspective, each of these steps is a processing of personal data that needs a legal basis, a purpose and a deletion period.<\/p>\n<p>Regarding the relationship between the two legal acts, Article 2(4)(g) of the DSA states that the GDPR \u201eremains unaffected\u201c; it is not a lex specialis (Guidelines, Rz 8 et seq.). Furthermore, the DSA refers to the GDPR in key places: the profiling in Article 26(3) and Article 28(2) of the DSA is that of Article 4(4) of the GDPR, the special categories are those of Article 9(1) of the GDPR (Guidelines, Rz 4).<\/p>\n<p>Simultaneity also determines the supervisory level. In Austria, according to the Coordinator for Digital Services Act, Koordinator f\u00fcr digitale Dienste is KommAustria, the dispute resolution body is the RTR-GmbH. For the GDPR, the <a href=\"http:\/\/www.dsb.gv.at\/\">Data protection authority<\/a> One and the same matter can affect both spheres at the same time, and as a result, two authorities may be involved who examine the matter according to different standards.<\/p>\n<h2 id=\"page-welche-bedeutung-die-leitlinien-haben\">What significance the guidelines have<\/h2>\n<p>The EDSA guidelines are issued in accordance with Art. 70(1)(e) GDPR and are not legally binding. That is correct; this is a data protection law provision. The guidelines are not intended to interpret the GDPR; that remains the responsibility of the Commission, the European Digital Services Board, and the European Court of Justice. The EDSA, on the other hand, clarifies how the GDPR is to be applied in the circumstances that the EDSA specifies (Guidelines, \u00a7 5).<\/p>\n<p>In practice, this certainly has great potential for impact. The data protection authorities in the EU are examining these lines, and anyone who deviates from them must be able to justify their deviation. Following a consultation round, a firm position has also been established that cannot be dismissed as a working draft. Two topics remain explicitly excluded: political advertising under Regulation (EU) 2024\/900 and access to research data under Article 40 of the DSA (Guidelines, Rz 6).<\/p>\n<h2 id=\"page-freiwillige-masnahmen-gegen-rechtswidrige-inhalte\">Voluntary measures against illegal content<\/h2>\n<p>Art 7 DSA takes away from providers the concern that voluntary search for illegal content costs the liability privileges of Art 4 to 6 DSA (<em>Good Samaritan Clause<\/em>). However, a data protection legal permission does not exist in this case. Anyone who filters, classifies, or trains models on their own initiative needs a legal basis, and that is regularly the legitimate interest pursuant to Art. 6(1)(f) GDPR (Guidelines, Rz 17).<\/p>\n<p>The EDSA requires a documented assessment to be made in this regard. The interest in identifying illegal content is legitimate, but the necessity must be demonstrated; the assessment also includes the reasonable expectations of users and the question of whether children are affected (Guidelines, Rz 18). It is also important to ensure that data from moderation processes is not used for the personalization of content or advertising. ErwGr 56 The EDSA also clarifies that the EDSA does not permit profiling for the purpose of possible criminal investigation (Guidelines, Rz 22).<\/p>\n<p>However, if there is a specific legal obligation, for example under Article 17 of the Copyright Directive (EU) 2019\/790, or to comply with a deletion request under Article 17 of the GDPR, Article 6(1)(c) GDPR serves as the legal basis. The obligation must then be clear, precise and foreseeable, and the processing proportionate (Guidelines, para. 20 ff).<\/p>\n<h2 id=\"page-meldeverfahren\">Reporting procedure<\/h2>\n<p>The duty to report and take remedial action pursuant to Article 16 DSA applies to every hosting provider, regardless of size (Guidelines, Rz 26; ErwGr 50 DSA). The committee draws a clear line regarding the scope of the data collected (Guidelines, Rz 31 f):<\/p>\n<ol>\n<li>The reporting form must enable the identification of the reporting person, but it must not make it a prerequisite. Anything else applies only if the illegality cannot be judged without identifying the person.<\/li>\n<li>No further data should generally be requested beyond name and email address in accordance with Art. 16(2) DSA.<\/li>\n<li>To prevent misuse of the reporting system, identification data may be processed, based on Art. 6(1)(f) GDPR (cf. ErwGr 53 DSA).<\/li>\n<li>The identity of the reporting person may only be disclosed to the affected person insofar as necessary, for example in cases of intellectual property rights violations. The reporting person must be informed about this in accordance with Article 13 of the GDPR.<\/li>\n<\/ol>\n<p>In reports regarding offenses under Articles 3 to 7 of Directive 2011\/93\/EU, the name and e-mail address are not to be collected in the first place (Guidelines, Rz 29).<\/p>\n<h2 id=\"page-sperren-und-beschwerden\">Blockages and complaints<\/h2>\n<p>Article 23 of the DSA allows online platforms to suspend their services from being accessed by individuals who are abusing the system, and also to suspend the processing of reports and complaints that are clearly unfounded. Article 20 of the DSA requires internal complaint management overseen by qualified individuals. This brings a principle to the fore that receives little attention otherwise: the accuracy pursuant to Article 5(1)(d) of the GDPR. Suspendences based on incorrect data hit the affected parties hard, which is why the data base must be accurate and the storage period limited to the purpose (Guidelines, Rz 42 et seq.).<\/p>\n<p>The committee also states that complaint procedures and bans do not affect the rights under the GDPR. Those who have been banned can still request information, deletion, and even data portability (Guidelines, Rz 43).<\/p>\n<h2 id=\"page-manipulative-gestaltung\">Manipulative design<\/h2>\n<p>Article 25(1) of the DSA prohibits manipulative interfaces (Dark Patterns) on online platforms; Article 2 <em>leg cit<\/em> assumes what is already covered by the GDPR or the UGP Directive. The demarcation is therefore a question of jurisdiction, and the EDSA lists two criteria (guidelines, Rz 45):<\/p>\n<ul>\n<li>Are personal data processed? and<\/li>\n<li>Does the affected behavior affect this processing?<\/li>\n<\/ul>\n<p>The difference can be illustrated by an example. The \u201eOnly a few pieces left in stock\u201c notice is a sales pressure and therefore more of a matter of the Lauterkeit Act. The addition \u201eEnter your e-mail address, date of birth and address now and reserve\u201c aims at the disclosure of additional data and therefore falls under the GDPR. There, the matter is usually decided because such a design violates the principle of good faith under Art. 5(1)(a) GDPR.<\/p>\n<p>The committee devotes special attention to addictive patterns such as endless scrolling, autoplay, streak mechanisms, or countdowns, which the DSA identifies in ErwGr 81 to 83 as a source of systemic risks (Guidelines, Rz 49 f).<\/p>\n<h2 id=\"page-werbung\">Advertising<\/h2>\n<p>Article 26(1) of the DSA requires real-time advertising transparency and is a legal basis for data from advertisers under Art. 6(1)(c) GDPR. It is not explicitly a legal basis for the display itself, i.e., for determining who sees which ads. Those who conduct targeting still need consent or another basis under Art. 6(1) GDPR (Guideline, Recital 60).<\/p>\n<p>The timing is also important. The information provided under Article 26 of the DSA is provided with the advertisement, whereas the information under Article 13 of the GDPR is already provided at the moment of collection. The DSA transparency therefore does not replace the data protection information; it complements it (Guidelines, para. 55 et seq.).<\/p>\n<h2 id=\"page-empfehlungssysteme\">Recommendation systems<\/h2>\n<p>Recommendation systems usually process personal data. The EDSA goes one step further and does not rule out that the selection and arrangement of content can constitute a decision within the meaning of Article 22(1) of the GDPR, particularly in the case of housing or job offers (Guidelines, Rz 91 et seq.).<\/p>\n<p>In addition, Article 38 of the DSA requires very large online platforms and search engines to offer an option that is not based on profiling. The committee clarifies what this means. Both options are to be presented equally; any nudging towards profiling is not allowed, and while the profile-free option is active, it must not continue to be profiled for future recommendations in the background. The decision must be respected beyond the meeting until users actively change it (Guidelines, Rz 94). The configuration data itself may only be used to fulfill the DSA obligations (Guidelines, Rz 95).<\/p>\n<h2 id=\"page-minderjahrigenschutz\">Protection of minors<\/h2>\n<p>Article 28 of the DSA requires platforms accessible to minors to maintain a high level of protection and prohibits advertising based on profiling when the minor status is known with sufficient certainty. The EDSA recognizes Article 28(1) and (2) of the DSA as a legal basis under Article 6(1)(c) of the GDPR, however, only to the extent that the controller demonstrates in the individual case that the processing is necessary and proportionate (Guidelines, point 99).<\/p>\n<p>Art. 28(3) DSA does not impose an obligation to process additional data. Age checks that enable unambiguous online identification, such as uploading an official photo ID, should not be based solely on Art. 28 DSA (Guidelines, Rz 100). Age or age range should not be stored permanently; only whether the usage requirement is met must be recorded (Guidelines, Rz 101). Biometric methods for unambiguous identification should be avoided, especially when children\u2019s data are involved (Guidelines, Rz 99).<\/p>\n<p>Whether an age verification is actually necessary depends on the risk. In low-risk cases, it may be sufficient to provide protective measures for all users without distinguishing between minors and adults (Guidelines, Rz 102).<\/p>\n<h2 id=\"page-systemische-risiken-und-dsfa\">Systemic risks and DSFA<\/h2>\n<p>For very large online platforms and search engines, Articles 34 and 35 require an assessment of systemic risks, explicitly also with regard to the fundamental rights under Articles 7 and 8 of the GDPR. The EDSA draws a practical conclusion from this: If a systemic risk to data protection is identified, a data protection impact assessment under Article 35 of the GDPR will usually also be required (Guidelines, Rz 106 and 114). Conversely, data minimization, pseudonymization, and data protection through technological design under Article 25 of the GDPR can serve as risk mitigation measures under Article 35 of the DSA (Guidelines, Rz 109).<\/p>\n<h2 id=\"page-aufsicht\">Supervision<\/h2>\n<p>Member states do not have to make the data protection authority the zdasDSA authority, and in Austria they have not done so (Guidelines, Rz 121). The committee therefore bases its cooperation on Article 8(3) of the GDPR and the principle of loyal cooperation under Article 4(3) of the EU Charter: If the zdasDSA authority examines whether a conduct is compatible with the GDPR, it must consult the competent data protection authority, and vice versa (Guidelines, Rz 125; CJEU 04.07.2023, C-252\/21).<\/p>\n<h2 id=\"page-fazit\">Conclusion<\/h2>\n<p>The guidelines bring little surprising news, but they do provide a lot of insurance. The DSA creates new obligations, but no new regulatory requirements. For platform operators, this means one thing above all else. DSA and GDPR cannot be treated separately. Anyone who has built their processes primarily from one perspective should look at them from the other side again. The guidelines provide, for the first time, a useful framework for auditing from a data protection perspective.<\/p>\n<h2 id=\"page-\"><\/h2>\n<h2 id=\"page-haufige-bzw-relevante-fragen-faqs\">Frequently Asked Questions (FAQs)<\/h2>\n<div class=\"schema-faq-section\">\n<h4 id=\"page-gilt-der-dsa-auch-fur-uns-wenn-wir-keine-grose-plattform-betreiben\">Does the DSA also apply to us if we don\u2019t operate a large platform?<\/h4>\n<p>In many respects, yes. The obligations regarding reporting and resolution procedures, as well as the grounds for moderation decisions, apply to every hosting provider regardless of size. Only the additional obligations for very large platforms and search engines are linked to the threshold of 45 million users; for small and medium-sized businesses, the DSA provides for specific concessions.<\/p>\n<\/div>\n<div class=\"schema-faq-section\">\n<h4 id=\"page-ersetzt-eine-dsa-pflicht-die-rechtsgrundlage-nach-der-dsgvo\">Does a DSA requirement replace the legal basis under the GDPR?<\/h4>\n<p>Only where the DSA formulates a clear, precise and predictable obligation can it be considered a legal obligation under Art. 6(1)(c) GDPR. The model example for the limit is Art. 26(1) DSA: For the data of the advertisers, it is the legal basis; for the question of who is shown an advertisement, it is explicitly not (Guidelines, Rz 60).<\/p>\n<h4 id=\"page-wir-integrieren-open-source-komponenten-werden-wir-dadurch-verantwortlich\">We are integrating open-source components \u2013 does this make us liable?<\/h4>\n<\/div>\n<div class=\"schema-faq-section\">\n<p>For your own product, yes. Anyone who integrates third-party components and brings the resulting product to market commercially is the manufacturer of the overall product and must include these components in their risk assessment and vulnerability management. The open-source project itself remains unaffected by this.<\/p>\n<\/div>\n<div class=\"schema-faq-section\">\n<h4 id=\"page-durfen-wir-werbung-weiterhin-nach-interessen-ausspielen\">Can we continue to use advertising to target interests?<\/h4>\n<p>Yes, provided there is a suitable legal basis. If processing is based on legitimate interest, there is an absolute right to object in case of direct advertising pursuant to Art. 21(2) GDPR (Guidelines, Recital 73). Any profiling involving special categories of personal data is excluded, including consent, and even if the segment is purchased. What matters is the message conveyed, not how it is named.<\/p>\n<h4 id=\"page-mussen-wir-das-alter-unserer-nutzerinnen-uberprufen\">Do we need to check the age of our users?<\/h4>\n<\/div>\n<div class=\"schema-faq-section\">\n<p>Not on a blanket basis, but based on risk assessment. If the assessment concludes that an age check is required, it should suffice to conclude that someone meets the usage requirement; under the EDSA, no further processing of additional data is permitted in accordance with Art 28 Abs 3 DSA. However, storing age or age range permanently is excessive (Guidelines, Rz 101).<\/p>\n<div class=\"schema-faq-section\">\n<div class=\"schema-faq-section\">\n<h4 id=\"page-wer-ist-in-osterreich-zustandig-die-kommaustria-oder-die-datenschutzbehorde\">Who is responsible in Austria for the KommAustria or the data protection authority?<\/h4>\n<\/div>\n<div class=\"schema-faq-section\">\n<p>Both, depending on the perspective, regarding the same matter. KommAustria, as the coordinator for digital services, monitors compliance with the DSA by providers based in Austria; the data protection authority is the GDPR authority. With very large platforms, oversight of the obligations under Section 5 rests solely with the Commission (Guidelines, Rz 123). The EDSA expects that the authorities will consult before judging one of them based on the other\u2019s regime (Guidelines, Rz 125).<\/p>\n<\/div>\n<\/div>\n<\/div>\n<h3 id=\"page-kommt-ihre-plattform-zu-recht\">Does your platform come to the right conclusions?<\/h3>\n<p><em>ATB.LAW helps you set up registration and moderation processes, advertising logics, and age verification in a way that they comply with both regulations (DSA and GDPR). Contact <a href=\"https:\/\/atb.law\/en\/stefan-knotzer\/\">Stefan Knotzer<\/a> and <a href=\"https:\/\/atb.law\/en\/roman-taudes\/\">Roman Taudes<\/a> at any time under <a href=\"mailto:office@atb.law\">office@atb.law<\/a> or by phone at <a href=\"tel:+4313912345\">01 39 12345<\/a> for a non-binding initial consultation.<\/em><\/p>","protected":false},"template":"","categories":[29],"class_list":["post-9344","blog-post","type-blog-post","status-publish","has-post-thumbnail","hentry","category-datenschutz-und-ki"],"acf":[],"post-kategorie":"29","_post-kategorie":"field_66d947537140a","post-kurzbeschreibung":"Was die (finalen) Leitlinien 3\/2025 des EDSA f\u00fcr Online-Plattformen bedeuten","_post-kurzbeschreibung":"field_66d949fe1efe2","post-beitragsbild":"9346","_post-beitragsbild":"field_66d94a4a1efe3","post-author_post-author-name":"Stefan Knotzer","_post-author_post-author-name":"field_66d94a801efe5","post-author_post-author-foto":"8759","_post-author_post-author-foto":"field_66d94aa11efe6","post-author":"","_post-author":"field_66d94ee2827ca","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>EDSA-Leitlinien: Zusammenspiel DSA &amp; DSGVO f\u00fcr Plattformen<\/title>\n<meta name=\"description\" content=\"Der EDSA hat die finalen Leitlinien zum Verh\u00e4ltnis von DSA und DSGVO angenommen. Was Plattformbetreiber bei Werbung, Moderation &amp; Jugendschutz beachten m\u00fcssen.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/atb.law\/en\/blog-post\/edsa-guidelines-dsa-dsgvo-analysis\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"EDSA-Leitlinien: Zusammenspiel DSA &amp; DSGVO f\u00fcr Plattformen\" \/>\n<meta property=\"og:description\" content=\"Der EDSA hat die finalen Leitlinien zum Verh\u00e4ltnis von DSA und DSGVO angenommen. Was Plattformbetreiber bei Werbung, Moderation &amp; Jugendschutz beachten m\u00fcssen.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/atb.law\/en\/blog-post\/edsa-guidelines-dsa-dsgvo-analysis\/\" \/>\n<meta property=\"og:site_name\" content=\"ATB.LAW\" \/>\n<meta property=\"og:image\" content=\"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/3bc65683-c5d0-4053-b183-b9c05ecdc08e-1-e1790364523398.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1725\" \/>\n\t<meta property=\"og:image:height\" content=\"1243\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/edsa-leitlinien-dsa-dsgvo-analyse\\\/\",\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/edsa-leitlinien-dsa-dsgvo-analyse\\\/\",\"name\":\"EDSA-Leitlinien: Zusammenspiel DSA & DSGVO f\u00fcr Plattformen\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/edsa-leitlinien-dsa-dsgvo-analyse\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/edsa-leitlinien-dsa-dsgvo-analyse\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/3bc65683-c5d0-4053-b183-b9c05ecdc08e-1-e1790364523398.jpg\",\"datePublished\":\"2026-09-28T06:00:00+00:00\",\"description\":\"Der EDSA hat die finalen Leitlinien zum Verh\u00e4ltnis von DSA und DSGVO angenommen. Was Plattformbetreiber bei Werbung, Moderation & Jugendschutz beachten m\u00fcssen.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/edsa-leitlinien-dsa-dsgvo-analyse\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/atb.law\\\/blog-post\\\/edsa-leitlinien-dsa-dsgvo-analyse\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/edsa-leitlinien-dsa-dsgvo-analyse\\\/#primaryimage\",\"url\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/3bc65683-c5d0-4053-b183-b9c05ecdc08e-1-e1790364523398.jpg\",\"contentUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/3bc65683-c5d0-4053-b183-b9c05ecdc08e-1-e1790364523398.jpg\",\"width\":1725,\"height\":1243,\"caption\":\"EDSA-Leitlinien DSA - DSGVO\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/edsa-leitlinien-dsa-dsgvo-analyse\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/atb.law\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DSA trifft DSGVO\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/atb.law\\\/#website\",\"url\":\"https:\\\/\\\/atb.law\\\/\",\"name\":\"atb Rechtsanw\u00e4lte\",\"description\":\"Rechtsanwaltskanzlei in Wien\",\"publisher\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/atb.law\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/atb.law\\\/#organization\",\"name\":\"atb Rechtsanw\u00e4lte\",\"url\":\"https:\\\/\\\/atb.law\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atb.law\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/ATB_Rechtsanwaelte_site-logo-beige.png\",\"contentUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/ATB_Rechtsanwaelte_site-logo-beige.png\",\"width\":1572,\"height\":1110,\"caption\":\"atb Rechtsanw\u00e4lte\"},\"image\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"EDSA guidelines: Interaction of DSA &amp; GDPR for platforms","description":"The EDSA has adopted the final guidelines on the relationship between DSA and the GDPR. What platform operators need to consider when advertising, moderating, and safeguarding minors.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/atb.law\/en\/blog-post\/edsa-guidelines-dsa-dsgvo-analysis\/","og_locale":"en_US","og_type":"article","og_title":"EDSA-Leitlinien: Zusammenspiel DSA & DSGVO f\u00fcr Plattformen","og_description":"Der EDSA hat die finalen Leitlinien zum Verh\u00e4ltnis von DSA und DSGVO angenommen. Was Plattformbetreiber bei Werbung, Moderation & Jugendschutz beachten m\u00fcssen.","og_url":"https:\/\/atb.law\/en\/blog-post\/edsa-guidelines-dsa-dsgvo-analysis\/","og_site_name":"ATB.LAW","og_image":[{"width":1725,"height":1243,"url":"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/3bc65683-c5d0-4053-b183-b9c05ecdc08e-1-e1790364523398.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/atb.law\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/","url":"https:\/\/atb.law\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/","name":"EDSA guidelines: Interaction of DSA &amp; GDPR for platforms","isPartOf":{"@id":"https:\/\/atb.law\/#website"},"primaryImageOfPage":{"@id":"https:\/\/atb.law\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/#primaryimage"},"image":{"@id":"https:\/\/atb.law\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/#primaryimage"},"thumbnailUrl":"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/3bc65683-c5d0-4053-b183-b9c05ecdc08e-1-e1790364523398.jpg","datePublished":"2026-09-28T06:00:00+00:00","description":"The EDSA has adopted the final guidelines on the relationship between DSA and the GDPR. What platform operators need to consider when advertising, moderating, and safeguarding minors.","breadcrumb":{"@id":"https:\/\/atb.law\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/atb.law\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atb.law\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/#primaryimage","url":"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/3bc65683-c5d0-4053-b183-b9c05ecdc08e-1-e1790364523398.jpg","contentUrl":"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/3bc65683-c5d0-4053-b183-b9c05ecdc08e-1-e1790364523398.jpg","width":1725,"height":1243,"caption":"EDSA-Leitlinien DSA - DSGVO"},{"@type":"BreadcrumbList","@id":"https:\/\/atb.law\/blog-post\/edsa-leitlinien-dsa-dsgvo-analyse\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/atb.law\/"},{"@type":"ListItem","position":2,"name":"DSA trifft DSGVO"}]},{"@type":"WebSite","@id":"https:\/\/atb.law\/#website","url":"https:\/\/atb.law\/","name":"atb Attorneys at Law","description":"Law firm in Vienna","publisher":{"@id":"https:\/\/atb.law\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/atb.law\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/atb.law\/#organization","name":"atb Attorneys at Law","url":"https:\/\/atb.law\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atb.law\/#\/schema\/logo\/image\/","url":"https:\/\/atb.law\/wp-content\/uploads\/2024\/05\/ATB_Rechtsanwaelte_site-logo-beige.png","contentUrl":"https:\/\/atb.law\/wp-content\/uploads\/2024\/05\/ATB_Rechtsanwaelte_site-logo-beige.png","width":1572,"height":1110,"caption":"atb Rechtsanw\u00e4lte"},"image":{"@id":"https:\/\/atb.law\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/blog-post\/9344","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/blog-post"}],"about":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/types\/blog-post"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/media\/9346"}],"wp:attachment":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/media?parent=9344"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/categories?post=9344"}],"curies":[{"name":"Well played","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}