Most coverage of the Digital Services Act focuses on the biggest platforms: Meta, TikTok, Amazon, Google. That focus makes sense, since those companies carry by far the heaviest obligations under the law.
It also leaves a lot of smaller businesses genuinely unsure whether the law touches them at all. The honest answer isn't "only big tech," and it isn't "everyone with a website" either. The DSA sits somewhere in between, and where you land depends on one specific question about how your service works.
That question is whether your site or app stores, transmits, or publicly distributes content submitted by other people. This piece walks through what the regulation actually is, how its obligations are tiered, and how to figure out which tier (if any) applies to you.
What is the Digital Services Act?
The Digital Services Act is an EU regulation aimed at making online services more accountable for how they handle illegal content, user complaints, and platform transparency. It entered into force in late 2022, applied to the largest platforms first, and became fully applicable across all in-scope services in February 2024.
It didn't arrive on a blank slate. The DSA builds on the older e-Commerce Directive, keeping that framework's central principle intact: a service generally isn't automatically liable for content its users post, as long as it acts once it becomes aware of something illegal. What the DSA adds on top is a set of due-diligence obligations, meaning process requirements about how you handle reports, explain decisions, and communicate with users and regulators.
The problems it was written to address are mostly procedural rather than technical. Before the DSA, moderation decisions across the EU were inconsistent and largely unexplained, users often had no meaningful way to contest a removal, and regulators had limited visibility into how platforms made these calls at all. Most of what the regulation requires is aimed squarely at those three gaps.
Who the DSA actually applies to
The DSA applies to a broad category it calls "intermediary services." That covers a lot of ground: internet access providers, caching services, hosting providers, cloud infrastructure, online marketplaces, social networks, app stores, and search engines all fall somewhere inside it.
Importantly, scope is determined by who you serve rather than where you're incorporated. A service run entirely from outside the EU is still in scope if it offers services to users located in the EU, which works much the same way GDPR's territorial scope does. Businesses sometimes assume non-EU incorporation is an exemption, and it isn't.
What keeps this from being overwhelming for smaller operators is that the obligations are tiered. Each tier reflects a different level of involvement with user content, and each one inherits the obligations of the tiers above it rather than replacing them.
The four tiers, from lightest to heaviest
| Tier | Who it covers | Representative obligations |
|---|---|---|
| Intermediary services | All services in scope, including access and caching providers | A single point of contact, an EU legal representative if you have no EU establishment, clear terms of service, annual transparency reporting |
| Hosting services | Anything that stores content provided by a user | A notice-and-action mechanism for illegal content, a statement of reasons for removals, reporting suspected serious criminal offences |
| Online platforms | Hosting services that also distribute content publicly | Internal complaint handling, trusted flagger processes, advertising transparency, no dark patterns, protections for minors |
| Very Large Online Platforms and Search Engines | Services with 45 million or more average monthly EU users | Systemic risk assessments, independent audits, researcher data access, crisis response obligations |
The tiering is cumulative, so an online platform also has to meet the hosting and baseline intermediary obligations. The top tier, reserved for services with 45 million or more monthly EU users (roughly ten percent of the EU population), is where audits and systemic risk assessments live, and it's a threshold a small business will realistically never approach.
Where a typical small business website lands
If your site is effectively a brochure, a product catalog, a service description, with nothing from outside your company visible to anyone else, most DSA obligations have nothing to attach to. There's no third-party content to moderate, no removal decisions to explain, and no illegal-content reports to process.
A contact form is the edge case worth understanding, since it does take in content from other people. What keeps it outside the demanding tiers is that nothing submitted through it gets published or distributed to anyone else, which is the thing the platform obligations are actually about.
The moment you add a feature that stores other people's content, that changes. Customer reviews, blog comments, a support forum, user-uploaded images, or marketplace listings all move you into the hosting tier, and possibly the online platform tier if that content is publicly visible to other users rather than just to you.
The practical test is simpler than reading the regulation suggests. Ask whether a stranger can put content onto your site that other people can then see. If yes, you're likely an online platform. If they can submit content but only your team sees it (a contact form or a private support ticket, for example), you're generally closer to the baseline than to the platform tier.
What the hosting tier actually requires
The central requirement is a notice-and-action mechanism: a clear, easy-to-find way for anyone to report content they believe is illegal, and a process for actually reviewing and acting on those reports. It doesn't have to be elaborate. A dedicated form or a clearly published contact route that reaches someone who can act is the substance of it.
Second, when you do remove or restrict content, you generally need to give the affected user a statement of reasons explaining what was removed and on what basis, whether that's a legal requirement or your own terms of service. This is the part most small operators overlook, since informal moderation rarely involves telling anyone why.
Third, if you become aware of information suggesting a serious criminal offence involving a threat to someone's life or safety, you're expected to notify the relevant authorities. In practice this comes up rarely, but it's worth knowing the obligation exists rather than discovering it during an incident.
The micro and small enterprise exemption, and what it doesn't cover
The DSA carves out meaningful relief for smaller operators. Businesses that qualify as micro or small enterprises, broadly under 50 staff and under €10 million in annual turnover, are exempt from the online platform tier obligations, the internal complaint-handling systems, out-of-court dispute settlement, trusted flagger processes, and the rest of that layer.
That exemption is real, and it removes the most administratively demanding parts of the regulation for most small businesses running a forum or a review section. The annual transparency reporting obligation also generally doesn't apply at that size. If you outgrow the threshold, the exemption continues for a further 12 months, so crossing it doesn't create an immediate compliance cliff.
What the exemption doesn't remove is the foundation underneath. The hosting-tier notice-and-action mechanism still applies, as do the baseline requirements around a point of contact, clear terms of service, and an EU legal representative if you have no EU establishment. So the correct summary isn't "small businesses are exempt from the DSA," it's "small businesses are exempt from the heaviest tier while still owing the basics."
What to actually do if the DSA applies to your site
Start with terms of service that actually say something about content. Vague boilerplate isn't enough here; the expectation is that a user can read your terms and understand what content is not allowed and what happens if they post it.
Then build the reporting path. Add a visible way for users or authorities to flag illegal content, make sure reports reach a person who can act on them, and keep a basic record of what you decided and why. That record costs almost nothing to maintain and is the single most useful thing to have if a decision is ever questioned.
Finally, handle the contact requirements. Publish a single point of contact that both users and regulators can reach, and if your business has no establishment inside the EU, designate an EU legal representative. Neither is expensive, but both are easy to forget until someone asks for them.
Where server location fits in
The DSA regulates behavior and accountability, not geography, so hosting on an EU-based VPS neither triggers nor exempts you from anything. A German server running a platform that ignores illegal-content reports is no more compliant than a US one.
That said, businesses already choosing EU-based hosting for data sovereignty reasons tend to find the broader compliance picture easier to explain, since the infrastructure story lines up with the legal one. If you're already documenting where data lives and what your hosting provider's DPA covers, adding DSA-related process documentation to the same file is a small marginal effort rather than a separate project.
Wrapping up
The useful question isn't whether your business is big enough for the DSA to matter. It's whether your site holds content that other people submitted, and whether other users can see it.
If the answer is no, the DSA mostly passes you by. If the answer is yes, the contact-point and hosting obligations apply regardless of your size, while transparency reporting and the genuinely demanding platform requirements stay with larger operators.
Thanks for reading! If you're hosting a website or app while thinking through EU compliance more broadly, QDE provides unmanaged KVM VPS hosting from a Tier III data center in Amsterdam, with GDPR-compliant infrastructure and minimal data collection by default.
Ready to get started, or have questions about your setup? Contact our team to find the right fit for your project.
Frequently asked questions about the Digital Services Act
Does the DSA apply to businesses outside the EU?
Yes. Scope is based on whether you offer services to users located in the EU, not on where your company is established. A business with no EU presence that serves EU users is in scope, and generally needs to designate an EU legal representative.
Is a personal blog subject to the DSA?
A blog with no comments or user submissions has essentially nothing to comply with, since there's no third-party content involved. Once you enable public comments, you're storing and distributing content from other people, which brings the hosting obligations into play even at small scale.
What's the difference between the DSA and GDPR?
GDPR governs how personal data is collected, stored, and processed. The DSA governs how services handle content, complaints, and transparency. A single business can easily be subject to both, and they're assessed separately rather than as one combined compliance question.
Does the DSA replace the old e-Commerce Directive?
It builds on it rather than replacing the core idea. The principle that a service isn't automatically liable for user content, provided it acts on knowledge of illegality, carries forward. What's new is the layer of due-diligence and transparency obligations stacked on top.
What happens if a business doesn't comply?
Penalties are set and enforced at the member state level for most services, and can reach a percentage of turnover for the largest platforms. Practically speaking, enforcement attention so far has concentrated on the biggest platforms, but that's an observation about current priorities rather than a safe assumption for the long term.
Do I need a legal representative in the EU if my business is based elsewhere?
If your service is an intermediary service under the DSA and you have no establishment in the EU, yes. The representative is a designated contact that authorities in the EU can reach, and the requirement applies independently of your company's size.
