Platform responsibility under the DSA and the OSA: two regulatory models

0

  Introduction    

Comparisons between the Digital Services Act (“DSA“) and the Online Safety Act 2023 (“OSA“) tend to begin with their similarities, and it is easy to see why: a common concern with platform power, an overlapping set of regulated entities, and a shared language of risk.

By May 2026, both frameworks have moved from obligation to enforcement. The DSA – fully applicable since February 2024 – produced its first non-compliance decision in December 2025, while in the United Kingdom, Ofcom has spent the better part of the year turning the OSA from statute into a working enforcement programme, issuing penalties for providers that fell short of their age assurance duties and failed to respond to its requests for information.

It is tempting to treat the two legislative instruments as regional variants of the same regulatory effort. Their similarities, however, are mostly ones of ambition. A closer look reveals different architectures, different premises about what this kind of regulation is meant to achieve, and different triggers for providers’ obligations. All in all, the two regimes agree on the harms but disagree on the approach, and the latter is what compliance depends on.

This article aims to trace this divergence across the areas that matter most in practice – scope and architecture, extraterritoriality, liability regimes, the prevention-versus-reaction balance, and enforcement, with a focus on the areas of child safety and advertising. The objectives overlap; the regulatory techniques do not – and for any provider caught by both the DSA and the OSA, compliance with one will not, in any sustained way, deliver compliance with the other.

1.              Scope and architecture    

The differences begin with the most basic question any such legislation has to answer: which services does it govern? Here the DSA and the OSA give incompatible answers.

The DSA inherits the layered classification of the e-Commerce Directive and builds it into categories best visualised as a set of concentric circles, each contained within a broader one, so that obligations grow heavier as a provider moves towards the centre. The outer circle holds all intermediary services, where mere conduits and providers of caching services carry the lightest obligations. Providers of hosting services form the next circle, and, within hosting providers, the DSA introduces the more heavily regulated online platforms and online marketplaces. For the latter, the exception is size: under the DSA, providers of online platforms and online marketplaces that qualify as micro or small enterprises are exempt from the platform-specific obligations, while remaining subject to the baseline duties that apply to all intermediary services. At the centre sit very large online platforms (“     VLOPs”     ) and very large online search engines (“     VLOSEs”     ), reaching an average of 45 million monthly active users in the European Union and attracting the strictest regulatory regime.

The OSA’s scope is at once narrower and broader than the DSA’s. Narrower, because it covers only providers of user-to-user and search services, leaving mere conduit and caching services outside altogether. Broader, in two respects. First, size: the OSA provides no exception equivalent to the DSA, so every service provider within scope has to comply with its relevant set of obligations. Second, the definition of ‘search’, which under the OSA catches any service that allows users to search more than one website or database – a category  Ofcom reads to include vertical search engines and certain generative-AI tools. The DSA’     s “     online search engine”      category reaches, in principle, only engines that search the web at large, so it may not capture the same services,      though it can still reach them through its other classifications, for instance, as hosting services.

2.              Extraterritoriality effect    

Neither regime defines its reach by where a provider is established: a scope drawn around establishment would be avoidable through relocation, and a poor proxy for where a service’s effects are felt.      Both the DSA and the OSA therefore apply to services with a sufficient connection to their territory, wherever the provider sits – though the question carries different weight in the two regimes: most major platforms maintain an establishment in the Union, so extraterritorial application operates there as a backstop, while for the United Kingdom it is the ordinary state of affairs. What differs is the connection each regime demands.

The DSA applies the criterion of a “substantial connection” to the Union (Article 3(d) and (e)): an establishment in a Member State, a significant number of recipients there, or activities targeted at one or more of them. Where a provider falling in scope has no establishment in the European Union, Article 13 requires it to designate a legal representative, who may be held liable for the provider’s non-compliance,      without relieving the provider of its own liability.

The OSA expresses the same idea differently, requiring “links with the United Kingdom” (section 4(5)). A service has such links if it has a significant number of UK users, if the UK is one of its target markets, or if there are reasonable grounds to believe that it poses a material risk of significant harm to individuals in the UK. This last condition has no equivalent under the DSA. It allows Ofcom to claim jurisdiction over a provider that does not target the UK commercially at all, so long as the risk of harm is serious enough.

The trigger logic diverges accordingly. The DSA’s connection test follows users and markets; the OSA’s follows users, markets and risk – under section 4(6), a material risk of significant harm to individuals in the UK can, by itself, bring a service within scope.

3.              The liability regime    

A defining structural difference between the DSA and the OSA lies in how each addresses liability and in the fact that one does not address it at all. This difference is one of legislative technique more than of substance – indeed, the liability provisions in both the EU and the UK descend from the same source, the e-Commerce Directive. What sets them apart is the choice each made afterwards.

The DSA recasts the traditional safe harbour regime inherited from the e-Commerce Directive. Accordingly, mere conduits, caching providers and hosting providers are not liable, subject to the conditions each article lays down, for the content they transmit or store at their users’ request (Articles 4, 5 and 6). For hosting, the central condition is knowledge: the provider must have no actual knowledge of the illegal content it stores and, as regards claims for damages, no awareness of facts or circumstances from which that illegality would be apparent. Two further provisions complete the scheme. Article 7 explicitly codifies the so-called “Good Samaritan” principle, so that a provider does not lose its exemption from liability merely by carrying out voluntary investigations, on its own initiative, into the presence of illegal content on its services, while Article 8 stresses that no general obligation to actively monitor content may be imposed on such providers. The decisive feature, particularly for litigation, is that these immunities are kept separate from the due diligence obligations that follow. Liability under Articles 4 to 8 does not depend on compliance with Articles 9 to 43. A provider may breach its obligation to establish notice-and-action mechanisms under Article 16 and still be shielded, under Article 6, for the underlying content. Immunity and compliance are distinct questions.

The OSA does not address providers’ liability at all. That question is left to the framework already in place. The Electronic Commerce (EC Directive) Regulations 2002, which transposed the e-Commerce Directive into UK law and survived Brexit as assimilated law, still govern the liability of mere conduits, caching and hosting providers. The contrast is less about substance than about placement: the EU recodified those principles in the DSA and updated them, while the UK left them in older, free-standing rules and built the OSA alongside. The OSA, for its part, regulates something else entirely, treating the issue of liability as already settled and assuming that every in-scope provider is already equipped with a content moderation system capable of dealing with illegal content. What it regulates is the quality of those systems. A provider’s exposure does not turn on any individual piece of content, as it may under the DSA, but on whether its risk assessments, governance, moderation and reporting arrangements are adequate. Liability under the OSA is liability for failures of process, not for content.

The practical implications for litigation are significant. A  DSA dispute over a hosting provider’s liability rests on the concept of  “actual knowledge” : whether the provider was aware of the content, or whether, upon gaining such knowledge, it acted expeditiously to disable or remove such content. An OSA dispute will more often turn on whether the risk assessment was  “suitable and sufficient” within the meaning of section 9, or whether the mitigation measures adopted were proportionate to the risks identified – specific items of content will still feature, but as evidence of what the systems missed rather than as the object of the claim. The first inquiry looks backwards, at a specific piece of content; the second looks forward, at the design of the service. The DSA asks design-level questions too, through the risk management regime discussed in the next section – but it reserves them for designated services and enforces them through the Commission, not through liability actions. A provider caught by both will find that the evidence protecting it under one regime is largely beside the point under the other. This means that counsel defending a provider subject to both the DSA and the OSA necessarily has to assemble two different sets of arguments and evidence out of the same facts.

4.              Prevention versus reaction    

The two regimes differ in what triggers a provider’s obligations. The DSA’s baseline turns on how a provider responds to specific content: under the notice-and-action mechanism, a sufficiently substantiated notice supplies the knowledge relevant to the Article 6 hosting defence (Article 16), after which the duties are procedural – a statement of reasons (Article 17) and an internal complaints route with access to certified out-of-court dispute settlement (Articles 20 and 21).

A further set of obligations applies to VLOPs and VLOSEs, but only once designated and only in defined respects. A designated service must assess annually the systemic risks across four categories – the dissemination of illegal content; effects on fundamental rights; effects on civic discourse and electoral processes; and effects relating to gender-based violence, public health and the protection of minors (Article 34) – and adopt mitigation measures that are reasonable, proportionate and effective, drawn from a non-exhaustive list that includes adapting algorithmic and recommender systems, protecting minors and marking manipulated media (Article 35). These are obligations of assessment and proportionate mitigation, owed only by the limited number of designated services.

The OSA takes a different approach. Its duties fall on in-scope user-to-user and search services with links to the UK and are framed as duties to operate proportionate systems and processes. A provider assesses the risk of illegal content and manages it – preventing users from encountering priority illegal content and acting swiftly against other illegal content once on notice (sections 9 and 10; 26 and 27 for search) – with parallel duties where the service is likely to be accessed by children (sections 11 and 12; 28 and 29). Ofcom’s Codes of Practice operate as a functional safe harbour: under section 50, compliance with a Code is treated as evidence that the underlying duty has been fulfilled.

The distinction lies not so much in the tools employed as in their reach: the DSA confines its systemic obligations to designated services, while the OSA applies its risk-assessment and safety duties across the whole in-scope population, scaling their content to each provider’s size and capacity rather than switching them off below a threshold.

5.              Children’s safety

Both regimes treat the protection of children as a central objective, but they pursue it through markedly different techniques, and the difference is not incidental: each regime protects children the way it does everything else.

The DSA works through a single, horizontal standard. Any online platform accessible to minors must put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security for them (Article 28(1)). Two specific limits support that standard: advertising based on profiling is not permitted where the provider is aware with reasonable certainty that the user is a minor (Article 28(2)), and targeting may not rely on the special categories of personal data listed in Article 9(1) GDPR (Article 26(3)). For designated services, the protection of minors features again as a mitigation consideration under Article 35(1)(j). The standard in Article 28(1) is broadly framed, and the  Commission’s guidelines on the protection of minors – issued under Article 28(4) on 14 July 2025 and not binding – have become the principal reference point against which compliance is assessed.

The OSA approaches the same concern structurally, beginning – as its architecture would predict – not with what minors are shown but with whether they can reach the service at all. A service is treated as likely to be accessed by children unless the provider uses age verification or age estimation such that children are not normally able to access it – the highly effective age assurance standard Ofcom applies – or can show that there is neither a significant number of child users nor a kind of service likely to attract a significant number of them (section 35). Access, rather than advertising or profiling, is the threshold question.

Where children are within reach, the duties are graded by the seriousness of the content. The strongest applies to primary priority content – pornography, and material encouraging suicide, deliberate self-injury or eating disorders – which the provider must prevent children of any age from encountering, through age verification or age estimation that is highly effective (sections 61 and 12(3)(a)). For all other content that is harmful to children, the duty is the lesser one of protecting children, in the age groups deemed to be at risk, from encountering it (section 12(3)(b)). That category covers both priority content – hateful or violent material, bullying and content promoting dangerous stunts (section 62) – and non-designated content drawn from the provider’s own risk assessment; for the latter, section 13(2) confines the duty to the kinds of risk the provider has itself identified.

The contrast is one of emphasis. Under the DSA, what matters is the configuration of the user’s experience – what a minor is shown, profiled for or recommended; under the OSA, it is the architecture of the product and access to it. A service may align with one regime’s approach to minors while engaging the other only to a limited extent.

6.              Advertising    

Advertising marks the sharpest divergence between the two regimes: the DSA sets out a developed advertising scheme, whereas the OSA addresses the subject only at the margin.

Under the DSA, transparency is a general obligation. Every online platform must identify each advertisement, disclose the advertiser and the party funding it, and set out the main targeting parameters (Article 26), reinforced by the profiling prohibitions already noted (Article 26(3) on special-category data and Article 28(2) on known minors). Very large platforms carry more: at least one recommender option not based on profiling (Article 38) and a public, machine-readable repository of the advertising served (Article 39).

By contrast, the OSA contains no equivalent. Notably, its only structural provision is the fraudulent advertising duty in Chapter 5 of Part 3 (sections 38 to 40), confined to Category 1 user-to-user and Category 2A search services and not yet in operation pending categorisation under the register, expected in July 2026. There is no counterpart to the transparency duties, the minor-targeting ban, the recommender opt-out or the repository. The contrast reflects a policy choice: the EU brings advertising within the platform regime, treating ad-funded models as a potential source of systemic risk, while the UK leaves much of the field to other instruments – the Online Advertising Programme, ASA self-regulation, and the consumer protection rules. The same conduct on a single platform may therefore attract detailed obligations under the DSA and comparatively limited direct treatment under the OSA.

7.              Enforcement and sanctions    

On enforcement, the divergence is constitutional before it is regulatory. A single jurisdiction with a pre-existing communications regulator could only mean a single enforcer, Ofcom. The European Union had no such option. The DSA assigns      baseline enforcement      (Articles 4 to 32)      to the Member States through their     Digital Services Coordinators, and reserves      Commission supervision      for      VLOPs and VLOSEs (Articles 33 to 43), whose reach is wide enough to carry Union-wide effects.      Since most large providers are established in Ireland, much of the baseline in practice runs through a single national regulator. The penalties run inversely to jurisdictional reach: fines under the DSA may not exceed 6% of total worldwide annual turnover (Article 74), while the OSA’s statutory maximum is the greater of £18 million or 10% of qualifying worldwide revenue (Schedule 13, paragraph 4).

For children’s rights, the two enforcement architectures have so far produced inverted results. Ofcom’s enforcement has been dominated by age assurance: of the fines issued in the Act’s first year, the largest all concern failures to implement highly effective age checks. Child protection has been the entry point of UK enforcement, not a later chapter. On the DSA side, the Commission’s sanctions to date concern transparency and systemic risk assessment, while its proceedings on the protection of minors remain pending. The regime built around prospective duties has already sanctioned child safety; the regime built around centralised supervision is still investigating it.

Conclusion    

Set against one another, the DSA and the OSA confirm that a shared objective guarantees nothing about the shape of the law. Their distance is architectural rather than ideological – two systems that read the same harms through different glasses, so that the same provider may sit at the outskirts of one regime and at the centre of the other. Architecture, unlike ideology, does not soften with time: it is codified, and it will channel enforcement, litigation and compliance design along diverging paths even where regulators pursue identical goals. For providers caught by both, the practical rule is dual-track compliance – not a translation exercise from one regime to the other, but two purpose-built structures, each answering to its own logic, its own triggers and its own regulator. Whether the two systems will borrow from each other as their case law matures is an open question; that neither can currently be satisfied by compliance with the other is not.

Share this article!

About Author

Giacomo Bertelli

Hogan Lovells Cadwalader

Victoria Grimoldi

Hogan Lovells Cadwalader

Leave A Reply