EU Digital Services Act and DMA: what businesses in the Netherlands must know

A tablet displaying the European Union flag beside scales of justice and small building icons

The Digital Services Act (Regulation (EU) 2022/2065) and the Digital Markets Act (Regulation (EU) 2022/1925) are directly applicable EU regulations that have applied in full since 17 February 2024 and 2 May 2023 respectively. The DSA imposes duties on every online intermediary that offers services to users in the EU, scaled to the size and type of the service; the DMA imposes duties only on the large platforms the European Commission has designated as gatekeepers, and it gives the businesses that depend on them enforceable rights. In the Netherlands the Authority for Consumers and Markets (ACM) is the Digital Services Coordinator.

Understanding Europe new digital rulebook

A stylised image of a gavel and a laptop, symbolising digital law and regulation

Both instruments are regulations, not directives, which matters more than it sounds. They apply as they stand in every member state, without national transposition, and their text is the operative law; the Dutch implementing statute only arranges supervision and enforcement. So when you check your obligations, you check the articles of the regulation itself, not a Dutch act.

The DSA is the general rulebook for online intermediation. It replaces the liability regime of the e-Commerce Directive, keeps the exemptions from liability for mere conduit, caching and hosting, and adds a layer of due diligence duties about how you handle illegal content, how transparent you are, and what recourse your users have. It covers everything from an access provider to a webshop with a review function to a global social network, with obligations that scale.

The DMA is competition regulation in the form of ex ante rules. Rather than investigating abuse after the fact, it lists what designated gatekeepers must do and must not do in relation to their core platform services. For a Dutch business that sells through a marketplace, advertises through a search engine or distributes an app, the DMA is a source of rights rather than a compliance burden. That distinction, that leverage in the digital age now has a legal shape, is the single most useful thing to take from these two acts.

DSA and DMA compared

AspectDigital Services ActDigital Markets Act
PurposeA safer and more transparent online environment; rules on illegal content and platform accountabilityContestable and fair digital markets; ex ante rules for dominant platforms
Who it bindsAll intermediary services offered to users in the EU, wherever establishedOnly the core platform services designated as gatekeepers by the European Commission
Main dutiesNotice and action, statement of reasons, complaint handling, transparency reporting, advertising and recommender transparencyNo self-preferencing, data access for business users, interoperability, no forced tying of services
EnforcementACM as Digital Services Coordinator; the Commission for very large platforms; fines up to 6 per cent of worldwide turnoverEuropean Commission exclusively; fines up to 10 per cent of worldwide turnover, 20 per cent on repetition

Which DSA tier does your business fall into

A person at a desk reviewing a checklist on a laptop, symbolising DSA compliance tasks.

The DSA works as a pyramid. Each tier inherits the duties of the tier below it, so the first task is classification, and it is a legal question rather than a marketing one.

Intermediary services are the base: mere conduit, caching and hosting. Internet access providers, domain name registrars and network infrastructure services sit here. Hosting services store information provided by a recipient of the service; cloud and web hosting are the obvious examples, and the Netherlands is one of the largest hosting markets in Europe, which is why this category matters here more than elsewhere. Online platforms are hosting services that also disseminate information to the public at the request of the user: marketplaces, app stores, social networks, review sites and any webshop with a public user-generated section. Very large online platforms and search engines are those the Commission has designated because they reach an average of at least forty-five million monthly active recipients in the EU.

One exemption is regularly overlooked and is worth checking first. Under article 19 of the DSA, the specific obligations for online platforms do not apply to platforms that qualify as micro or small enterprises within the meaning of the EU definition, unless they have been designated as very large. That does not exempt them from the baseline duties for intermediaries and hosting services, but it takes the internal complaint system, the out-of-court dispute settlement route, the trusted flagger priority and the platform transparency reporting off the list. A small Dutch webshop with a comment function is therefore in a very different position from a mid-sized marketplace, and the difference is worth establishing before anyone starts drafting policies.

What the DSA actually requires

The duties are practical and most of them land in documents and processes rather than in technology.

Every intermediary must designate a single point of contact for the authorities and a separate one for users, and must publish both. A provider established outside the EU must appoint a legal representative in a member state where it offers services, and that representative can be held liable for non-compliance. Terms and conditions must set out, in plain and intelligible language, the restrictions imposed on user content, the policies and tools used for content moderation, including any algorithmic decision-making, and the internal complaint procedure. Annual transparency reports on content moderation are required, with the smallest providers exempted.

Hosting services must operate a notice and action mechanism that is easy to access and allows anyone to report content they consider illegal, and must confirm receipt and inform the notifier of the decision. Every removal, demotion, suspension or demonetisation must be accompanied by a statement of reasons to the affected user, and platforms must submit those statements to the Commission transparency database.

Online platforms carry the heaviest of the general duties. They must run an internal complaint-handling system that remains open for at least six months after a decision, allow users to bring the dispute to a certified out-of-court dispute settlement body, give priority to notices from trusted flaggers designated by the Digital Services Coordinator, and suspend, after a warning, users who frequently provide manifestly illegal content or who abuse the notice and complaint systems.

Three prohibitions apply directly to design and advertising. Interfaces may not be designed in a way that deceives or manipulates users, the practices commonly called dark patterns. Advertising must be identifiable as such, with the advertiser and the main parameters of the targeting disclosed, and advertising based on profiling using special categories of personal data is prohibited. Platforms accessible to minors may not present advertising based on profiling where they are aware with reasonable certainty that the user is a minor, and must put appropriate measures in place to protect them. Recommender systems must be explained in the terms and conditions, in plain language, including the main parameters and any options to change them.

Extra duties for online marketplaces

If your platform allows traders to conclude distance contracts with consumers, a further set of obligations applies, and this is the part Dutch marketplaces most often underestimate. Before a trader may use the platform, you must obtain and make best efforts to verify a defined set of identification details: name, address, telephone number and email, a copy of an identity document or another form of electronic identification, payment account details, the trade register entry and registration number, and a self-certification that the trader will offer only compliant products or services. If a trader does not supply them after a reminder, its use of the service must be suspended.

Two further duties follow. The interface must be designed so that traders can comply with their own information and product safety obligations under EU consumer law before they list anything. And where the platform becomes aware that an illegal product or service has been offered, it must inform the consumers who bought it, or publish the information where it cannot identify them. Together these rules turn a marketplace from a passive host into a party with its own compliance file on every seller.

Liability: what the safe harbours still protect

The DSA keeps the intermediary liability exemptions that Dutch practice knew from the e-Commerce Directive and its implementation in the Civil Code. A mere conduit is not liable for the information transmitted, a caching service is not liable subject to the conditions on updating and removal, and a hosting service is not liable for stored information provided it does not have actual knowledge of illegal activity or content and, on obtaining such knowledge, acts expeditiously to remove it or disable access.

Two qualifications matter. There is no general obligation to monitor the information transmitted or stored, nor to actively seek facts indicating illegality; a Dutch court cannot impose one. But voluntary own-initiative investigations do not by themselves cause the exemption to be lost, which removes the perverse incentive that existed under the old regime. And the exemption from liability is not an exemption from the due diligence duties: a hosting provider that ignores a proper notice both loses the shield and breaches the regulation.

The Digital Markets Act and what it gives you

A stylised image of a large, dominant chess piece surrounded by smaller ones, symbolising the DMA focus on gatekeepers.

The DMA applies only to companies the European Commission has designated as gatekeepers in respect of a specific core platform service, a category that covers search engines, app stores, social networks, video-sharing services, messaging services, operating systems, browsers, virtual assistants, cloud services, advertising services and intermediation services. Designation follows from the quantitative criteria in article 3: an annual EU turnover of at least seven and a half billion euros in each of the last three financial years or an average market capitalisation of at least seventy-five billion euros, together with more than forty-five million monthly active end users and more than ten thousand yearly active business users in the EU in the last financial year. A company that meets the thresholds must notify the Commission, and the presumption can be rebutted.

The obligations run for six months after designation and are directly enforceable. The ones that matter most to a Dutch business acting as a business user are these.

  • No self-preferencing. A gatekeeper may not rank its own products or services more favourably than equivalent offerings of third parties, and must apply transparent, fair and non-discriminatory ranking conditions.
  • Access to your own data. Business users are entitled to effective, high-quality, continuous and real-time access to the data they generate through their activity on the platform, including aggregated and non-aggregated data.
  • No anti-steering. A gatekeeper may not prevent business users from offering the same products at different prices or conditions through other channels, and must allow them to communicate offers to, and conclude contracts with, customers acquired on the platform.
  • Alternative distribution. Gatekeepers controlling operating systems must allow the installation and use of third-party applications and app stores, and may not require the use of their own payment or identification services as a condition of access.
  • No forced tying of accounts. Users may not be required to register for another service of the gatekeeper in order to use a core platform service.

These are rights you can invoke. Where a gatekeeper does not comply, the route is a complaint to the European Commission, which enforces the DMA exclusively, and in appropriate cases a claim before a national court, since the obligations are directly applicable. The commercial effect for smaller businesses is concrete: lower distribution costs, usable advertising and sales data, and a ranking that is not structurally tilted against you.

How the DSA is enforced in the Netherlands

A microscope focusing on a map of the Netherlands, signifying local regulatory scrutiny.

The regulation applies directly, but supervision had to be arranged nationally. The Dutch implementing act for the Digital Services Regulation (Uitvoeringswet digitaledienstenverordening) was published in the Bulletin of Acts and Decrees on 3 February 2025 and entered into force the following day. It designates the ACM as the Digital Services Coordinator, gives it investigatory and enforcement powers, and arranges the certification of out-of-court dispute settlement bodies and the designation of trusted flaggers.

The division of labour is worth remembering. The ACM supervises providers established in the Netherlands and handles complaints from users established here. Very large online platforms and search engines are supervised by the European Commission for the systemic risk obligations, with the coordinator of the country of establishment retaining a role for the general duties. Where personal data are processed, the Dutch Data Protection Authority remains the competent supervisor under the GDPR, and the two regimes overlap most visibly in advertising and recommender systems.

The sanctions are serious. Under the DSA the maximum fine is six per cent of the annual worldwide turnover of the provider, with periodic penalty payments of up to five per cent of average daily worldwide turnover for continuing infringements, and the coordinator can also require a compliance plan or, in the last resort, apply to a court for a temporary restriction of access to the service. Under the DMA the ceiling is ten per cent of worldwide turnover and twenty per cent for a repeated infringement, with the possibility of structural remedies.

For an ordinary Dutch business, the practical exposure is not a headline fine but the ACM asking to see three things: the point of contact, the terms and conditions, and the notice and action mechanism. Those are the items to have in order first, and they are also the items a user complaint will be about. The ACM has said publicly that its early supervision concentrates on the accessibility of reporting mechanisms and contact points, on the hosting sector, given the size of the Dutch market, and on the protection of minors online. A provider that can show a documented classification of its own service, a working notice and action route and a terms of service that matches what its systems actually do is a long way ahead of the enforcement curve.

How the DSA fits with the rest of EU digital law

The DSA and DMA are two elements of a much larger body of rules, and treating them as a standalone project is how compliance projects fail. Four neighbours matter most.

The General Data Protection Regulation continues to govern every processing of personal data on your platform, and the DSA expressly leaves it intact. Profiling for advertising, recommender systems and age assurance all raise GDPR questions before they raise DSA questions, and the roles of controller and processor still determine who answers for what. Anyone building GDPR mastery for website compliance and data protection is already doing part of the DSA work; our note on controller and processor roles under the GDPR sets out that allocation.

The European Accessibility Act, implemented in the Netherlands by the Act on the accessibility of products and services, has applied since 28 June 2025 and requires e-commerce services, consumer banking, e-books and a range of digital products to be accessible to people with disabilities. It is enforced separately, with the ACM supervising e-commerce accessibility, and it is a parallel obligation rather than an alternative one: a transparent, DSA-compliant webshop that a visually impaired user cannot operate is still non-compliant.

Cybersecurity has moved as well. The NIS2 Directive has been implemented in the Netherlands by the Cybersecurity Act (Cyberbeveiligingswet), which entered into force on 15 August 2026. Entities within scope must register with the National Cyber Security Centre, take risk management measures, and report significant incidents within twenty-four hours as an early warning and within seventy-two hours in a fuller notification. Many hosting providers and online platforms fall within scope, so the DSA file and the security file end up in the same hands. Our guide to NIS2 and the Dutch Cybersecurity Act sets out what the registration and reporting duties involve in practice, and who has to comply.

Finally, the AI Act is now in force in stages. The prohibitions on unacceptable practices, the rules for general-purpose AI models and the transparency obligations for systems that interact with people or generate synthetic content already apply; the high-risk regime was postponed by the digital omnibus package, to December 2027 for the use cases in Annex III and to August 2028 for products covered by Annex I. Platforms that use AI for content moderation, ranking or age estimation should map those systems now, because the DSA already requires them to be described. The proposed separate directive on AI liability has been withdrawn, so damage caused by AI is assessed under ordinary Dutch liability law and the revised product liability rules.

Our article on the Dutch Cybercrime III Act covers how national criminal law deals with online conduct, which is the other side of the illegal content question.

What counts as illegal content, and who decides

The DSA does not define illegality itself. Illegal content means anything that is not in compliance with EU law or with the law of a member state, whatever the subject matter, so in a Dutch case the question is answered by Dutch law. That covers a wide field: defamation and insult under the Criminal Code and the unlawful publication doctrine developed under article 6:162 of the Civil Code, incitement and threats, counterfeit goods and trade mark infringement, copyright infringement, unsafe or non-compliant products, unlicensed financial or gambling services, and unlawful processing of personal data.

This has an important consequence for platforms. A notice does not oblige you to remove everything that someone finds objectionable. It obliges you to assess whether the content is illegal, and to act expeditiously if it is. Content that is lawful but unwelcome is a matter for your terms and conditions, and the DSA requires you to apply those terms diligently, objectively and proportionately, with due regard to the fundamental rights of users, including freedom of expression. Removing lawful criticism because a company complained loudly is now itself a compliance risk.

Two instruments cut across this. A Dutch judicial or administrative authority can issue an order to act against specific illegal content, and the provider must inform the authority of the effect given to it; the order must state its legal basis, its reasons and its territorial scope. A separate order can require a provider to supply information about a specific recipient of the service, which is the statutory route by which the identity behind an anonymous account is obtained. Outside those orders, a claimant in the Netherlands who wants identifying data or a removal generally goes to the court in summary proceedings, and the established test balances the seriousness of the alleged wrong, the plausibility of the claim, and the absence of a less intrusive route.

If your content or your account is removed

The DSA is not only a burden on platforms; it gives their users a procedure that did not previously exist. Any restriction imposed because content is considered illegal or incompatible with the terms must be accompanied by a clear and specific statement of reasons, which has to say what was restricted and how, on what legal or contractual ground, whether automated means were used, and how the decision can be challenged. For a business whose product listing or advertising account has been suspended, that statement is the starting point of the file.

From there three routes run in parallel. The platform internal complaint-handling system must be free of charge, must remain open for at least six months, and decisions on complaints may not be taken solely by automated means. An out-of-court dispute settlement body certified by the Digital Services Coordinator can then be asked to look at the matter; its decision is not binding on the user, but the platform must engage with the procedure in good faith and bears the costs where the user prevails. And the ordinary route to the Dutch civil court remains open throughout, which in practice means summary proceedings where a suspension is causing continuing commercial damage.

The practical advice for business users is to move quickly and on paper. Preserve the statement of reasons and the correspondence, file the internal complaint within the platform own deadline, quantify the loss from the first day, and do not let an account suspension run for months in the hope of an informal reversal. Where the platform is a designated gatekeeper, the DMA obligations on fair and transparent access conditions may give an additional argument that the general terms alone do not.

Your questions about the DSA and DMA answered

What is the main difference for a small business

The DSA gives you obligations; the DMA gives you rights. Under the DSA you are responsible for how your own service works: your terms and conditions, your notice and action mechanism, your points of contact and, if you are an online platform above the micro and small enterprise threshold, your complaint handling and transparency reporting. Under the DMA you are on the receiving end: the duties fall on designated gatekeepers, and they exist to stop a large platform using its position against you. Read the DSA as your compliance list and the DMA as a set of entitlements to check your platform contracts against.

Do these laws apply if my business is not established in the EU

Yes. Both regulations apply on the basis of where the users are, not where the provider is. The DSA applies to intermediary services offered to recipients who have their place of establishment or are located in the EU, irrespective of where the provider is established, and it requires providers without an EU establishment to appoint a legal representative in a member state where they offer services. That representative can be held liable for non-compliance, so the appointment is not a formality. The DMA likewise applies to core platform services provided to business users established in the EU or to end users located there.

Does the DSA apply to my webshop

It depends on what your webshop does. A shop that only sells its own goods and hosts no user content is not an intermediary service and falls outside the DSA, although consumer law and the Civil Code still apply in full. Add a review function, a comment section or a forum and you are hosting information provided by users and disseminating it to the public, which makes you an online platform. Allow third-party sellers to conclude contracts with consumers and the marketplace rules on trader traceability apply on top. The classification, not the size of the business, is what triggers the duties.

What are the first steps towards compliance

Establish your category and record the reasoning, because the whole analysis follows from it. Publish a point of contact for authorities and one for users, and appoint a legal representative if you have no EU establishment. Rewrite the terms and conditions so that they describe the content moderation policy, the tools used, any automated decision-making and the complaint route in language a user can follow. Build or document the notice and action mechanism and the statement of reasons that goes with every decision. Then review your agreements with the platforms you depend on against the DMA obligations, because rights that are never invoked have no value. Our IT law guides collect the underlying material.

Law & More advises Dutch and international businesses on the DSA and the DMA: classifying the service, drafting terms and conditions and moderation policies that meet the transparency requirements, setting up notice and action and complaint procedures, dealing with ACM investigations, and enforcing the rights that the DMA gives business users against gatekeepers. If you are unsure which tier your service falls into, or an authority has been in touch, contact our IT and technology lawyers.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

An IT services agreement is the contract under which a provider delivers technology services to

Opposition is the remedy against a default judgment: a judgment given against a defendant who

Explore marriage laws Netherlands to gain a comprehensive understanding of legal aspects and implications for

Proprietary software licensing is the model in which the supplier keeps the copyright and the

Protect yourself from cybercrime in the Netherlands! Explore Dutch laws, understand your rights, and learn

A patent gives its holder the exclusive right to exploit an invention commercially for a

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.