Two Stories of DSA Data (Non)-Access from an NGO perspective

By Oliver Marsh

This piece relates firsthand experience by the NGO AlgorithmWatch with multiple data access requests under the DSA – an early Article 40.4 request to understand AI content, and a “mass data access request” under 40.12. It reflects on the (sometimes surprising) burdens encountered, and their impact: turning attempts to do research into full-time fights about compliance.

Closing the accountability gap for AI Search: Why DSA Risk Assessments Cannot Work Without AI Act Transparency

By R. Buse Çetin (AI Forensics) and Natalia Stanusch (AI Forensics, University of Amsterdam)

The European Commission’s designation of ChatGPT as a Very Large Online Search Engine and the Digital Omnibus’s coordination provisions mark progress in AI Search regulation, but leave critical gaps that can be exploited. Without mandatory coordination and documentation requirements, regulators would be unable to assess whether mitigation strategies are adequate. We propose the following measures using existing authority: mandatory AI Act documentation for DSA assessments, joint review procedures, and expanded moderation definitions including pre-deployment design choices.

Why is enforcement of the DSA systemic risk framework still ignoring environmental risks?

By Rachel Griffin

This post argues that environmental risks stemming from major online platforms—including those linked to digital infrastructure, generative AI, targeted advertising and e-commerce—straightforwardly fall within the scope of platforms’ risk management obligations under Articles 34 and 35 of the DSA. The author questions why neither platforms nor the European Commission have meaningfully addressed these risks, and argues that their continued omission reflects political priorities more than legal constraints.

On the importance of “average monthly active recipients” (AMAR) in the recent case law of the General Court

By Marie-José Garot, IE University

This post analyses how the General Court has clarified the concept of “average monthly active recipients” through three recent cases (Zalando, Meta, and TikTok). The interpretation given by the Court should oblige the European Commission to set a single methodology for calculating the AMAR, whatever the purpose it serves (for transparency obligations, the designation of VLOPs and VLOSEs, or the calculation of the supervisory fee).

Ineffective by design: Bits of Freedom vs Meta at the forefront of enforcing user control for recommender systems under the DSA

By Matteo Fabbri

This post unpacks the legal arguments and implications of Bits of Freedom vs. Meta Ireland, a case which constitutes  an important early example of private enforcement of the DSA and may influence EU-wide interpretations for how VLOPSEs must implement user controls for recommender systems.

Platform Governance and Technology-Facilitated Gender-Based Violence: Positioning the DSA in the EU’s Legal Framework

This post examines technology-facilitated gender-based violence (TFGBV) as a systemic phenomenon shaped by platform design and cross-platform ecosystems, and maps the main EU legal instruments available to address it. It argues that while the Digital Services Act’s systemic risk framework is particularly well suited to tackling the structural drivers of TFGBV, its promise has yet to be realised in practice through implementation and enforcement.

State of Play of DSA Dispute Settlement: Meaningful Redress, Uneven Results

After almost two years of certified out-of-court dispute settlement (ODS) bodies operating under Article 21 of the Digital Services Act (DSA), the first transparency reports provide early evidence of how this new due process layer operates in practice. Drawing on 2025 data from multiple ODS bodies, this article assesses what value the system is already delivering, and where current constraints, including platform participation and information-sharing, limit its effectiveness. We discuss possible ways forward, including stronger incentives, technical infrastructure and feedback loops.

Digital Fairness Act: Why we need an ambitious DFA to protect digital consumers from manipulative and addictive design practices

By John Albert, Marijn Sax, and Natali Helberger

In this policy brief, we advocate for an ambitious Digital Fairness Act that futureproofs EU consumer law and protects consumers from the full range of unfair digital commercial practices across digital services, including deceptive interfaces, manipulative design, and addictive features. This brief builds on proposals developed in the report “Towards Digital Fairness”.

What makes a risk “systemic”? The CJEU’s first interpretation of systemic risks under the Digital Services Act

This post analyses the first major CJEU interpretation of “systemic risks” under the Digital Services Act in Amazon v. European Commission (2025). It argues that the judgment clarifies systemic risks as large-scale societal risks, rejects analogies with financial systemic risk regulation, and provides some guidance on the scope of Article 34 DSA.

If at first you don’t succeed: Reflections on a rejected Art. 40 DSA data access request

By Catalina Goanta & Anda Iamnitchi

Article 40 of the Digital Services Act was hailed as a breakthrough for platform research. But what does the the procedure look like in practice? Drawing on their own rejected data access request, the authors reflect candidly on early lessons for the first wave of Article 40 applications, and what researchers should know before applying for access to platform data. Readers are also invited to contribute to an ongoing researcher survey. A webinar with the authors on 20 March (embedded below) unpacks more lessons learned about DSA data access.