Digital Services Act (DSA) - Regulation (EU) 2022/2065
Evidence request list. 36 controls, 36 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DSA Chapter II: Liability of Intermediary Service Providers
Upon receipt of an order to provide specific information about one or more individual recipients, providers shall inform the issuing authority of effect given; orders must meet the listed conditions.
- Process for handling information orders and notifying the authority
- No defined process for information orders
A provider of a mere conduit service is not liable for transmitted information where it does not initiate the transmission, does not select the receiver, and does not select or modify the information, without prejudice to orders to terminate or prevent an infringement.
- Documented procedure/system implementing the obligation
- Records evidencing operation (logs, reports, notices)
- No documented procedure
- Procedure exists on paper but no operating evidence
A provider of a caching service is not liable for the automatic, intermediate and temporary storage of information performed for the sole purpose of making onward transmission more efficient, where it meets the listed conditions (no modification, compliance with access/update rules, expeditious removal on obtaining knowledge of removal at source).
- Documented procedure/system implementing the obligation
- Records evidencing operation (logs, reports, notices)
- No documented procedure
- Procedure exists on paper but no operating evidence
A hosting provider is not liable for stored information where it does not have actual knowledge of illegal content and, upon obtaining such knowledge, acts expeditiously to remove or disable access to it; the exemption does not apply where the recipient acts under the authority or control of the provider.
- Documented procedure/system implementing the obligation
- Records evidencing operation (logs, reports, notices)
- No documented procedure
- Procedure exists on paper but no operating evidence
No general obligation may be imposed on providers to monitor the information they transmit or store, or actively to seek facts or circumstances indicating illegal activity.
- Policy confirming no general-monitoring obligation is imposed and how voluntary measures are bounded
- Mischaracterising voluntary measures as a general monitoring duty
Upon receipt of an order to act against specific illegal content issued by national authorities, providers shall inform the issuing authority of effect given to the order; the order must meet the listed conditions (legal basis, territorial scope, redress information, e-translation).
- Process for receiving and actioning authority orders
- Records of effect given and information back to the authority
- No process to receive or respond to authority orders
DSA Chapter III Section 1: Obligations for All Intermediary Services
Providers shall designate a single point of contact enabling direct electronic communication with Member State authorities, the Commission and the European Board for Digital Services, and make the necessary information public.
- Designated and published authority point of contact
- No published authority point of contact
Providers shall designate a single point of contact enabling recipients to communicate directly and rapidly by electronic means and in a user-friendly manner, including by means other than solely automated tools.
- Published recipient point of contact allowing non-automated communication
- Only an automated/chatbot channel with no human route
Providers not established in the Union but offering services there shall designate, in writing, a legal representative in a Member State and notify its details to the Digital Services Coordinator.
- Appointment of an EU legal representative and notification to the DSC
- No EU legal representative despite offering services in the Union
Providers shall set out in their terms and conditions information on any restrictions on the use of their service (including content-moderation policies, procedures, tools and rules of procedure, algorithmic decision-making and human review), in clear, plain, intelligible, user-friendly and unambiguous language, and act diligently, objectively and proportionately when applying them.
- Published terms and conditions describing content-moderation policies and tools
- Evidence of diligent, objective, proportionate enforcement
- T&Cs silent on content moderation/algorithmic decisions
- Arbitrary or non-transparent enforcement
Providers of intermediary services (except micro/small enterprises that are not VLOPs) shall publish, at least annually, clear and comprehensible reports on any content moderation they engaged in during the period.
- Annual content-moderation transparency report meeting the prescribed content
- No annual transparency report
- Report missing prescribed data points
DSA Chapter III Section 2: Additional Obligations for Hosting Services
Hosting providers shall put in place easy-to-access, user-friendly, electronic notice-and-action mechanisms allowing any individual or entity to notify the presence of specific items they consider illegal content, confirm receipt, and notify their decision with redress information; notices giving actual knowledge are relevant for liability.
- A working notice-and-action mechanism with confirmation and decision notices
- Records of notices received and actioned
- No notice mechanism or no acknowledgement/decision notices
Hosting providers shall provide affected recipients a clear and specific statement of reasons for any restriction imposed on the ground that information is illegal content or incompatible with the terms and conditions, covering the listed elements, and (for online platforms) submit it to the Commission transparency database.
- Statement-of-reasons issued for restrictions, with the required elements
- Submission to the DSA transparency database (platforms)
- Restrictions applied with no statement of reasons
Where a hosting provider becomes aware of information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person has taken place, is taking place or is likely, it shall promptly inform the relevant law-enforcement or judicial authorities.
- Procedure to notify law enforcement of life/safety threats
- Records of any such notifications
- No escalation route to law enforcement for life-threatening content
DSA Chapter III Section 3: Additional Obligations for Online Platforms
Online platforms shall provide recipients (and notifiers) access, for at least six months following a moderation decision, to an effective internal complaint-handling system allowing electronic and free-of-charge lodging of complaints, with decisions taken under non-arbitrary supervision of qualified staff (not solely automated).
- An internal complaint-handling system meeting the 6-month/free/non-automated requirements
- No internal appeals system
- Appeals decided solely by automated means
Recipients affected by moderation decisions shall be entitled to select any certified out-of-court dispute settlement body to resolve disputes; platforms shall engage in good faith and bear the body's fees as specified.
- Information provided to users on certified out-of-court dispute bodies
- Records of engagement with such bodies
- No information on out-of-court dispute settlement
Online platforms shall take the necessary technical and organisational measures to ensure that notices submitted by trusted flaggers (awarded that status by the Digital Services Coordinator) through the notice-and-action mechanisms are given priority and processed without undue delay.
- Mechanism prioritising trusted-flagger notices
- Records distinguishing trusted-flagger notices
- No priority handling for trusted-flagger notices
Online platforms shall suspend, for a reasonable period and after prior warning, the provision of services to recipients that frequently provide manifestly illegal content, and the processing of notices/complaints from those that frequently submit manifestly unfounded notices or complaints.
- A documented misuse policy with warning and suspension thresholds
- Records of warnings/suspensions
- No measures against repeat illegal-content posters or abusive notifiers
Online platforms shall include additional information in their transparency reports (disputes, suspensions, average monthly active recipients) and publish their average monthly active recipients in the Union at least every six months.
- Platform transparency report with the additional data points
- Published average monthly active recipients figure
- Active-user figures not published
- Platform-specific report data missing
Providers of online platforms shall not design, organise or operate their online interfaces in a way that deceives or manipulates recipients or otherwise materially distorts or impairs their ability to make free and informed decisions (prohibition of dark patterns).
- Interface-design review confirming no manipulative/dark-pattern practices
- Use of dark patterns (e.g. preselected consent, nagging, obstruction)
Providers of online platforms presenting advertising shall ensure recipients can identify in real time that the content is an advertisement, on whose behalf it is presented, who paid for it, and the main parameters used to target them; and shall not present advertising based on profiling using special categories of personal data.
- Per-advertisement disclosures (advertiser, payer, targeting parameters)
- Controls preventing ad targeting on special-category data
- No real-time ad disclosure
- Targeting ads using special-category personal data
Providers of online platforms that use recommender systems shall set out in their terms and conditions, in plain and intelligible language, the main parameters used in their recommender systems and any options for recipients to modify or influence those parameters.
- Plain-language disclosure of recommender-system main parameters
- User options to modify recommender parameters
- No disclosure of recommender-system parameters
Providers of online platforms accessible to minors shall put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security of minors, and shall not present advertising based on profiling using personal data of a recipient they are aware is a minor.
- Measures protecting minors privacy/safety/security on the service
- Controls preventing profiling-based ads to known minors
- No minor-protection measures
- Profiling-based advertising shown to known minors
DSA Chapter III Section 4: Obligations for Online Marketplaces
Online platforms allowing consumers to conclude distance contracts with traders shall obtain, verify the reliability of, and keep specified information on traders before allowing them to use the platform (know-your-business-customer), and make best efforts to assess whether such information is reliable.
- Collected and verified trader identity/registration/payment information
- Process to assess reliability of trader information
- Allowing traders to operate without KYBC verification
Online platforms allowing distance contracts shall design and organise their interface to enable traders to comply with their obligations regarding pre-contractual information, compliance and product safety information under applicable Union law.
- Interface fields enabling traders to provide pre-contractual/safety information
- Interface that prevents traders meeting their information obligations
Where an online platform becomes aware that an illegal product or service was offered, it shall inform consumers who purchased it of the illegality, the identity of the trader and any means of redress (or, where contact details are unavailable, publish the information).
- Process to inform affected consumers of illegal products/services
- No mechanism to notify consumers of illegal offerings
DSA Chapter III Section 5: Additional Obligations for VLOPs and VLOSEs
Providers of VLOPs and VLOSEs shall diligently identify, analyse and assess at least annually the systemic risks stemming from the design, functioning and use of their services (dissemination of illegal content; effects on fundamental rights; civic discourse and electoral processes; gender-based violence, protection of minors and public health/wellbeing).
- A documented annual systemic-risk assessment covering the four risk categories
- Methodology and supporting analysis
- No systemic-risk assessment
- Assessment omitting required risk categories
VLOPs and VLOSEs shall put in place reasonable, proportionate and effective mitigation measures tailored to the systemic risks identified, with particular consideration to impacts on fundamental rights (e.g. adapting design, terms, content-moderation processes, advertising and recommender systems).
- Documented risk-mitigation measures mapped to identified risks
- Risks identified but no corresponding mitigation
Where the Commission adopts a decision under the crisis-response mechanism, VLOPs and VLOSEs shall assess whether and how the functioning of their services contributes to a serious threat and apply specific, effective and proportionate crisis-response measures.
- Procedure to implement Commission crisis-response decisions
- Records of measures applied during a declared crisis
- No capability to respond to a crisis-response decision
VLOPs and VLOSEs shall be subject, at their own expense and at least annually, to independent audits to assess compliance with the Chapter III obligations and any commitments under codes of conduct and crisis protocols, and shall take due account of audit recommendations.
- Annual independent audit report with an audit opinion
- An audit implementation report addressing recommendations
- No independent audit
- Audit recommendations ignored
VLOPs and VLOSEs that use recommender systems shall provide at least one option for each recommender system that is not based on profiling within the meaning of the GDPR.
- A non-profiling recommender option available to users
- Only profiling-based recommendation with no alternative
VLOPs and VLOSEs presenting advertising shall compile and make publicly available, through a searchable and reliable repository, information on the advertisements presented (content, advertiser, payer, period, targeting parameters and recipients reached) for the period they were presented and one year after.
- A public, searchable advertisement repository with the required fields
- No advertisement repository
- Repository missing required fields
VLOPs and VLOSEs shall provide the Digital Services Coordinator of establishment or the Commission, on reasoned request, access to data necessary to monitor compliance, and provide vetted researchers access to data for the sole purpose of researching systemic risks.
- Process for regulator data-access requests
- Process for vetted-researcher data access
- No mechanism to provide regulator or researcher data access
VLOPs and VLOSEs shall establish a compliance function, independent from operational functions, with sufficient authority, stature and resources, headed by a compliance officer reporting to the management body, to monitor compliance with the Regulation.
- An established, independent compliance function with a compliance officer
- Reporting line to the management body
- No independent compliance function
- Compliance officer without authority/resources
VLOPs and VLOSEs shall publish the transparency reports at least every six months, including the human resources dedicated to content moderation per language, measures taken for training and assistance, and the results of the systemic-risk assessment and audit reports.
- Six-monthly VLOP transparency reports with the additional content
- Published audit and risk-assessment outcomes
- Reports not published six-monthly
- Required VLOP-specific content missing
VLOPs and VLOSEs shall pay an annual supervisory fee to the Commission upon designation, set to cover the estimated costs of the Commission's supervisory tasks and not exceeding the stated cap.
- Payment of the annual supervisory fee
- Records confirming fee calculation/payment
- Non-payment of the supervisory fee
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.