{"id":10346,"date":"2025-10-21T09:38:37","date_gmt":"2025-10-21T08:38:37","guid":{"rendered":"https:\/\/lawwwing.com\/?p=10346"},"modified":"2025-10-21T09:55:31","modified_gmt":"2025-10-21T08:55:31","slug":"dsa-and-gdpr-what-your-digital-platform-needs-to-know-in-2025","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/dsa-and-gdpr-what-your-digital-platform-needs-to-know-in-2025\/","title":{"rendered":"DSA and GDPR: What Your Digital Platform Needs to Know in 2025"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">The European Data Protection Board has released Guidelines 3\/2025 clarifying how the Digital Services Act (DSA) and the General Data Protection Regulation (GDPR) work together. If you manage a digital platform, this directly affects you.<\/h3>\n\n\n\n<p>In September, the <strong>European Data Protection Board (EDPB)<\/strong> published its <strong>Guidelines 3\/2025<\/strong> on the interaction between the <strong>Digital Services Act (DSA)<\/strong> and the <strong>General Data Protection Regulation (GDPR)<\/strong>.<br>The message is clear: the DSA does not replace the GDPR \u2014 both must be applied together.<\/p>\n\n\n\n<p>In practice, this means that whenever the DSA requires you to process personal data, the <strong>GDPR remains your binding legal framework<\/strong>.<\/p>\n\n\n\n<p>For <strong>digital platforms<\/strong> and <strong>marketplaces<\/strong>, this is a new challenge: it\u2019s no longer enough to simply keep your <strong>privacy policy<\/strong> up to date or display a <strong>cookie banner<\/strong>. You\u2019ll need to review moderation systems, ads, and age verification tools through a double lens \u2014 <strong>complying with the DSA without violating the GDPR<\/strong> and ensuring full <strong>data protection on your website<\/strong>.<\/p>\n\n\n\n<div style=\"height:27px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Content moderation: more guarantees and transparency<\/h2>\n\n\n\n<p>The DSA allows platforms to investigate and remove illegal content. But beware: if you process <strong>personal data<\/strong> in that process (for instance, identifying a user who uploads content), you need a valid legal basis under the <strong>GDPR<\/strong> or <strong>national data protection laws<\/strong>.<\/p>\n\n\n\n<p>For voluntary investigations, the most common legal basis will be <strong>legitimate interest<\/strong>, provided you respect proportionality.<br>If the investigation is carried out under a <strong>clear legal obligation<\/strong>, that will be your legal basis.<\/p>\n\n\n\n<p>Additionally, if you use <strong>automated systems<\/strong> to block or flag content, you must disclose the logic, error rates, and criteria used. Remember: the GDPR restricts fully automated decisions with significant effects and requires safeguards such as <strong>human review<\/strong>.<\/p>\n\n\n\n<div style=\"height:27px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Notification and complaint channels<\/h2>\n\n\n\n<p>The DSA also requires platforms to offer mechanisms to report illegal content and submit complaints. This means handling data from reporters, affected users, and third parties \u2014 and therefore triggers GDPR obligations for <strong>data protection and transparency<\/strong>.<\/p>\n\n\n\n<p><strong>Best practices:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Request only the minimum data necessary \u2014 identify the reporter only when essential.<\/li>\n\n\n\n<li>If you share their identity, inform them in advance.<\/li>\n\n\n\n<li>Every removal decision must include a clear justification for the user.<\/li>\n<\/ul>\n\n\n\n<p>When complaint systems rely on automated processes with significant effects, the <strong>GDPR also requires human oversight<\/strong>, just as it does with <strong>cookie management<\/strong> or <strong>Consent Mode v2<\/strong> systems.<\/p>\n\n\n\n<div style=\"height:27px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Goodbye to deceptive patterns<\/h2>\n\n\n\n<p>Infinite scrolls, confusing buttons, or dark patterns that manipulate users into giving consent or data are now <strong>prohibited by the DSA<\/strong>.<br>When these techniques are used to obtain <strong>cookie consent<\/strong> or personal information, they also violate the <strong>GDPR<\/strong>.<\/p>\n\n\n\n<p>If your interface nudges users toward accepting cookies or doesn\u2019t offer clear options like \u201cReject all\u201d or \u201cConfigure cookies,\u201d you\u2019re breaching both frameworks. The EDPB\u2019s recommendation is simple: <strong>redesign your platform<\/strong> and remove any <strong>dark patterns<\/strong> related to privacy or <strong>cookie banners<\/strong>.<\/p>\n\n\n\n<div style=\"height:27px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Advertising and targeting<\/h2>\n\n\n\n<p>The DSA raises the bar for <strong>advertising transparency<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Each ad must clearly state, at the time of display, why the user is seeing it, what targeting criteria are used, and how to modify them.<\/li>\n\n\n\n<li>Using <strong>sensitive data<\/strong> (health, ideology, sexual orientation, etc.) for ad personalization is strictly prohibited.<\/li>\n<\/ul>\n\n\n\n<p>Intensive profiling may count as an <strong>automated decision<\/strong> under the GDPR, activating additional obligations: explaining the logic, reasons, and possible consequences to the user.<\/p>\n\n\n\n<p>If you manage <strong>marketing campaigns<\/strong> or <strong>Consent Mode v2<\/strong>, make sure your <strong>cookie banner<\/strong>, <strong>legal texts<\/strong>, and <strong>privacy policy<\/strong> are properly integrated and GDPR-compliant.<\/p>\n\n\n\n<div style=\"height:27px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Protection of minors<\/h2>\n\n\n\n<p>Platforms accessible to minors must apply proportional measures to protect them. Among these:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>It\u2019s forbidden to show <strong>personalized ads<\/strong> based on minors\u2019 data when their age can be reasonably determined.<\/li>\n\n\n\n<li>Don\u2019t collect more data than necessary: verify age proportionally, without storing sensitive documents unnecessarily.<\/li>\n<\/ul>\n\n\n\n<p>Every <strong>age-verification process<\/strong> must have a valid legal basis, respect <strong>data minimization<\/strong>, and, whenever possible, avoid full user identification.<\/p>\n\n\n\n<div style=\"height:27px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Systemic risks and large platforms<\/h2>\n\n\n\n<p>For very large platforms (VLOPs and VLOSEs), the DSA imposes the duty to <strong>detect and mitigate systemic risks<\/strong>. When that work involves high-risk data processing, the GDPR requires a <strong>data protection impact assessment (DPIA)<\/strong> before deploying large-scale moderation or recommendation systems.<\/p>\n\n\n\n<p>Even if these rules primarily apply to tech giants, they signal where <strong>EU regulation<\/strong> is headed \u2014 and they\u2019re a useful benchmark for any <strong>legal-compliant website<\/strong> or <strong>online business<\/strong> handling personal data.<\/p>\n\n\n\n<div style=\"height:27px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Checklist for your digital platform<\/h2>\n\n\n\n<p>\u2705 Review moderation processes \u2014 define clear legal bases and ensure human review for impactful decisions.<br>\u2705 Adjust complaint systems \u2014 request minimal data, notify users, and justify each decision.<br>\u2705 Redesign interfaces \u2014 remove any dark patterns.<br>\u2705 Improve ad transparency \u2014 show targeting criteria and avoid sensitive data.<br>\u2705 Apply <strong>age-appropriate protection<\/strong> measures without unnecessary data collection.<br>\u2705 If you\u2019re a large platform, conduct <strong>impact assessments<\/strong> where needed.<\/p>\n\n\n\n<p>And don\u2019t forget the basics of <strong>legal website compliance<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use a <strong>cookie banner<\/strong> that properly blocks cookies until consent is given.<\/li>\n\n\n\n<li>Keep your <strong>legal texts<\/strong> (privacy policy, terms and conditions, legal notice) up to date.<\/li>\n\n\n\n<li>Implement a <strong>WordPress cookie plugin<\/strong> or <strong>GDPR plugin<\/strong> compatible with <strong>Consent Mode v2<\/strong> and EU law<\/li>\n<\/ul>\n\n\n\n<div style=\"height:27px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Conclusion<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p>The EDPB\u2019s <strong>Guidelines 3\/2025<\/strong> make it clear: the <strong>GDPR<\/strong> remains the foundation of data protection, while the <strong>DSA<\/strong> adds new transparency and safety obligations in the digital environment.<\/p>\n\n\n\n<p>For platforms, the challenge is not choosing one framework over the other \u2014 but applying both coherently. Ultimately, it\u2019s about ensuring users can browse the internet with confidence, knowing their rights are protected and your website stays <strong>legally compliant<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is your website ready for 2025 compliance?<\/h3>\n\n\n\n<p><strong>Lawwwing<\/strong> helps you keep your <strong>website fully compliant<\/strong>, with an automated <strong>cookie banner<\/strong>, <strong>Consent Mode v2 integration<\/strong>, updated <strong>legal texts<\/strong>, and a <strong>privacy policy<\/strong> adapted to both the DSA and GDPR.<br> <a>Discover how Lawwwing makes compliance simple<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The European Data Protection Board has clarified how the DSA and GDPR work together: they don\u2019t replace each other \u2014 they complement one another. Digital platforms will need to review their moderation systems, advertising, and age verification processes to ensure both data protection and transparency. This article breaks down the key steps to keep your website or e-commerce fully compliant in 2025.<\/p>\n","protected":false},"author":19,"featured_media":10341,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[202,635,636],"tags":[577],"class_list":["post-10346","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-rgpd-en","category-privacy-and-data-protection-eu","category-accessibility-web-compliance","tag-rgpd-2"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/10346","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=10346"}],"version-history":[{"count":2,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/10346\/revisions"}],"predecessor-version":[{"id":10350,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/10346\/revisions\/10350"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/10341"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=10346"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=10346"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=10346"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}