Take-Aways (AI)
  • The EU Com­mis­si­on opens the first for­mal DSA inve­sti­ga­ti­on against X (form­er­ly Twit­ter) for alle­ged brea­ches of DSA obligations.
  • VLOPs like X must docu­ment, assess and miti­ga­te risks and ensu­re com­pli­ance depart­ments, audits, trans­pa­ren­cy report­ing and rese­ar­cher data access.
  • Inve­sti­ga­ti­on focu­ses on ille­gal con­tent, dis­in­for­ma­ti­on, trans­pa­ren­cy obli­ga­ti­ons, rese­ar­cher access to data and pos­si­ble mis­lea­ding user interfaces.

The EU Com­mis­si­on has announ­ced that it has ope­ned a for­mal inve­sti­ga­ti­on against X (form­er­ly Twit­ter) under the Digi­tal Ser­vices Act (DSA) has opened.

The DSA applies to inter­me­dia­ry ser­vices offe­red to users estab­lished or loca­ted in the Uni­on, irre­spec­ti­ve of the place of estab­lish­ment of the pro­vi­der of tho­se inter­me­dia­ry services.

He knows a Duty pyra­midThe “Very Lar­ge Online Plat­forms” cate­go­ry inclu­des pro­vi­ders of “very lar­ge online plat­forms”, VLOPs) and of “very lar­ge online search engi­nes” (“Very Lar­ge Online Search Engi­nes”, VLOEs) Addi­tio­nal obli­ga­ti­ons be impo­sed (Art. 33 et seq. DSA; see also here). The­se are online pro­vi­ders with at least 45 mil­li­on acti­ve users in the EU. In April 2023, the Com­mis­si­on desi­gna­ted 19 pro­vi­ders as VLOPs on the basis of Art. 33 (4) DSA. clas­si­fi­edinclu­ding Ama­zon Store, Apple App­Sto­re, Face­book, some Goog­le ser­vices, Insta­gram, Lin­ke­dIn, Snap­chat, Tik­Tok, Wiki­pe­dia, You­Tube and Zalan­do, as well as Twit­ter and X.

Such VLOPs and VLOEs must, for exam­p­le, meet cer­tain Docu­ment riskseva­lua­te and miti­ga­te them. Such risks may ari­se in par­ti­cu­lar from the dis­se­mi­na­ti­on of ille­gal con­tent and may also include risks to fun­da­men­tal rights and cer­tain vul­nerable per­sons that may ari­se, for exam­p­le, from recom­men­da­ti­on systems or other algo­rith­mic systems, from the mode­ra­ti­on of con­tent, the terms and con­di­ti­ons, the dis­play of adver­ti­sing or the pro­ce­s­sing of per­so­nal data (Art. 34 f. DSA). VLOPs and VLOEs must also have a Com­pli­ance depart­ment set up (Art. 41), to audit (Art. 37), Trans­pa­ren­cy reports (Art. 42) and rese­ar­chers Data access (Art. 40).

Added to this are the Gene­ral obli­ga­ti­ons in par­ti­cu­lar from Art. 19 et seq. (e.g. requi­re­ments for com­plaints manage­ment and out-of-court dis­pu­te reso­lu­ti­on, for blocking accounts with obvious­ly unlawful con­tent, trans­pa­ren­cy obli­ga­ti­ons and requi­re­ments for adver­ti­sing, for recom­men­da­ti­on systems and for the GTC).

The inve­sti­ga­ti­on against X is the first inve­sti­ga­ti­on under the DSA. A preli­mi­na­ry inve­sti­ga­ti­on by the Com­mis­si­on has appar­ent­ly reve­a­led indi­ca­ti­ons of vio­la­ti­ons. It con­cerns in particular:

  • the dis­se­mi­na­ti­on of ille­gal con­tent in the EU, in par­ti­cu­lar risk miti­ga­ti­on mea­su­res and the report­ing and respon­se mecha­nism for ille­gal content;
  • Mea­su­res to com­bat disinformation;
  • Trans­pa­ren­cy measures;
  • data access for researchers;
  • Pos­si­ble decep­ti­ons in the user inter­face (e.g. with the blue check marks).