EU Digital Services Act
EU regulation establishing obligations for digital platforms including audit trails for content moderation and algorithmic transparency.
What DSA draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Transparency Reporting
Platforms MUST report on content moderation activities with supporting audit data.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Recommender System Transparency
REQUIRES audit trails for algorithm training data and recommendation decisions.
This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.
Data Access
Very large platforms MUST provide vetted researchers access to data with usage logging.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Audit Requirements
Annual independent audits MUST verify platform compliance including audit log integrity.
A requirement like this is about the record surviving the person who would rather it did not, which means the audit trail has to be protected as carefully as the data. File activity monitoring hashes the datafiles, the transaction logs, the backups, and the audit trail itself with XXH3, then baselines them — so an alteration or a deletion is evident rather than inferred, and it is attributed to the session and OS user behind it. Because the same platform holds the query trail, a destructive statement and the file-level change it produced are two views of one event rather than two investigations.
What DSA covers
This instrument defines no data category of its own. Regulates intermediary SERVICES and the handling of illegal content. Obligations attach to the service and its size, not to a defined category of data.
How DSA is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The European Commission for very large platforms; national Digital Services Coordinators otherwise.
| Published maximum | Charged | As at |
|---|---|---|
| 6% of annual worldwide turnover | for infringements, failure to comply with interim measures, or breach of binding commitments | 2026-08 |
| 5% of average daily worldwide turnover | as a periodic penalty payment, per day of delay in complying with an order | 2026-08 |
The 6% ceiling covers infringements of the obligations, failure to comply with interim measures, and breach of binding commitments. Separately, periodic penalty payments of up to 5% of average daily worldwide turnover accrue for each day of delay in complying with an order.
Very large online platforms and search engines carry additional obligations that smaller services do not, so the applicable duties depend on designation.
Uncapped exposure that sits outside this instrument
These come from company law rather than from DSA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for DSA,
not configured for it afterwards
Platform Content Monitoring
Track content moderation and algorithm training data access
DSA Transparency Report
Annual compliance evidence for independent audits
Platform Data Patterns
Identify content decisions, algorithm inputs, and user data
Algorithm Change Alert
Alert on modifications to recommendation systems
Other AI & Technology frameworks
Walk into the DSA audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.