Full Breakdown
European Commission's Regulatory Actions on Digital Platforms
11/1/2025, 1:17:27 AM
Overview of the Digital Services Act and GDPR Interplay
On September 12, 2025, the European Data Protection Board (EDPB) issued draft guidelines addressing the relationship between the EU General Data Protection Regulation (GDPR) and the Digital Services Act (DSA). The DSA regulates online platforms, including social networks and marketplaces, while the GDPR governs personal data processing. The EDPB's guidelines, open for consultation until October 31, 2025, highlight the complexities companies face in complying with both regulations, as their obligations often overlap and diverge.
Key Compliance Challenges for Companies
The EDPB emphasizes that companies must navigate various compliance requirements when implementing DSA obligations. For instance, while the DSA allows for voluntary investigations of illegal content, companies cannot rely on the GDPR's "necessary to comply with a legal obligation" basis for processing personal data in these cases. Instead, they must utilize the "legitimate interests" basis, necessitating a documented assessment. Additionally, automated tools used to manage illegal content may trigger GDPR obligations regarding automated decision-making, requiring human oversight and transparency.
European Commission's Findings on Meta and TikTok
On October 24, 2025, the European Commission announced preliminary findings indicating that Meta (Facebook and Instagram) and TikTok may have violated the DSA by failing to meet transparency obligations. The Commission's investigations revealed that these platforms implemented restrictive procedures hindering researchers' access to necessary data for compliance assessments. Furthermore, Meta was found lacking in providing user-friendly mechanisms for reporting illegal content and appealing moderation decisions, which are mandated by the DSA.
Implications of Non-Compliance
If Meta and TikTok do not satisfactorily address the Commission's findings, they could face fines of up to 6% of their global annual revenue. Both companies have been given the opportunity to respond to the allegations and propose corrective measures. Meta has asserted that it is compliant with the DSA, while TikTok has expressed concerns about the potential conflict between DSA requirements and GDPR data protection standards.
Broader Regulatory Context and Future Directions
The European Commission is also considering classifying OpenAI's ChatGPT as a "Very Large Online Search Engine" under the DSA, which would impose additional regulatory obligations on the AI tool. This potential classification reflects the EU's ongoing efforts to adapt its regulatory framework to encompass emerging technologies and platforms.
In addition, the Commission is expected to unveil a proposal aimed at addressing "hybrid threats" posed by large online platforms, which would require these companies to enhance their measures against disinformation and foreign interference. This initiative is part of the forthcoming European Democracy Shield, indicating a shift towards integrating digital regulation with national security concerns.
Conclusion
The evolving landscape of digital regulation in the EU underscores the complexities companies face in ensuring compliance with both the DSA and GDPR. As the European Commission continues to scrutinize major platforms like Meta and TikTok, the implications of these regulatory actions will likely shape the future of digital services and data protection across Europe.
