Logo

Your trusted compliance partner

Logo

Your trusted compliance partner

Logo

Your trusted compliance partner

Back To Home

privacy compliance

EDPB Adopts Final Guidance on the DSA–GDPR Relationship: What It Means for Online Platforms

EDPB Adopts Final Guidance on the DSA–GDPR Relationship: What It Means for Online Platforms

EDPB Adopts Final Guidance on the DSA–GDPR Relationship: What It Means for Online Platforms

Research Team (Tsaaro)

Published

WhatsAppFacebookXLinkedIn
The Indian Privacy Adjudication Report

Introduction

Online platforms operating in the European Union must comply with two overlapping regulatory frameworks: the Digital Services Act (DSA) and the General Data Protection Regulation (GDPR). While the DSA regulates platform accountability, online safety and transparency, the GDPR governs how organisations collect, process and protect personal data. Their obligations frequently intersect, particularly in content moderation, targeted advertising and the protection of minors. 

On 21 September 2026, the European Data Protection Board (EDPB) announced the adoption of its final Guidelines 3/2025 on the interplay between the DSA and the GDPR, following public consultation. At the same plenary, it adopted new guidance on the imposition of GDPR administrative fines, introducing a more consistent approach to deciding when financial penalties should accompany other corrective measures.  

For online platforms, the development raises a practical question: how can they meet their obligations under the DSA without compromising the data protection requirements of the GDPR? 

How the DSA and GDPR Work Together 

The Digital Services Act imposes obligations on intermediary services, including hosting providers, online platforms and search engines. These obligations often require activities involving personal data, such as investigating illegal content, identifying users or personalising recommendations. 

The EDPB clarifies that the DSA does not override the GDPR. Under Article 2(4)(g) DSA, both frameworks must be applied consistently. Compliance with a DSA obligation does not automatically establish a lawful basis for processing under the GDPR. Platforms must independently assess the necessity, proportionality and lawfulness of their processing activities.  

Content Moderation Must Respect Data Protection 

Content moderation is one of the principal areas where the two regulations intersect. Article 7 of the DSA allows intermediary services to voluntarily investigate and remove illegal content without automatically losing their exemptions from liability. 

Such investigations may involve analysing posts, monitoring activity or deploying automated detection systems. Where personal data is processed, the EDPB identifies legitimate interests under Article 6(1)(f) GDPR as a potentially appropriate legal basis for voluntary moderation, subject to a necessity assessment and balancing test. 

Article 16 of the DSA separately requires hosting providers to establish notice-and-action mechanisms for reporting illegal content. The EDPB emphasises that these systems should allow individuals to report content without mandatory identification, unless identification is necessary to determine whether the content is illegal. A notifier's identity should generally be disclosed to an affected user only where strictly necessary.  

Dark Patterns and Manipulative Interfaces 

Article 25 of the DSA addresses deceptive design patterns that impair users' ability to make informed decisions. Such practices may also fall within the GDPR when they influence decisions concerning personal data. 

For example, an interface that pressures users into providing unnecessary personal information may raise GDPR compliance concerns. The EDPB explains that data protection authorities are responsible for examining deceptive design practices covered by the GDPR, while competent DSA authorities oversee practices within their jurisdiction. 

Platforms should therefore review their consent interfaces, privacy settings and other design features to determine which regulatory requirements apply.  

Targeted Advertising Faces Additional Restrictions 

Article 26 of the DSA introduces advertising transparency obligations and prohibits online platforms from presenting advertisements based on profiling using special categories of personal data. 

These categories include information revealing religious beliefs, political opinions and health conditions. Importantly, the prohibition can apply even where the underlying processing has a lawful basis under Article 6 GDPR and satisfies an exception under Article 9(2). 

The EDPB also distinguishes between the transparency requirements of the two regulations. Under Article 26 DSA, users must receive real-time information about advertisements, including the principal targeting parameters. Under Articles 13 and 14 of the GDPR, transparency obligations arise in connection with the collection and processing of personal data. 

Consequently, explaining why an advertisement appears does not replace the obligation to establish a lawful basis for the processing that produced it. Platforms must assess both requirements when developing advertising systems.  

Protecting Minors Without Excessive Data Collection 

Article 28 of the DSA requires online platforms accessible to minors to maintain appropriate levels of privacy, safety and security. It also prohibits profiling-based advertising when providers know with reasonable certainty that a recipient is a minor. 

The EDPB recognises that age assurance may sometimes require personal data processing. Articles 28(1) and 28(2) DSA can provide a legal obligation under Article 6(1)(c) GDPR, provided the processing is demonstrably necessary and proportionate. 

Nevertheless, the guidelines discourage unnecessarily intrusive identification methods. Platforms should avoid collecting government-issued identification documents merely to determine users' ages where less intrusive methods are effective. 

They should also avoid permanently storing exact ages or age ranges based solely on Article 28 DSA. Recording whether users satisfy the relevant age requirement may be sufficient.  

Systemic Risks and Regulatory Cooperation 

Articles 34 and 35 of the DSA require very large online platforms and search engines to assess and mitigate systemic risks, including risks affecting fundamental rights. 

The EDPB explains that GDPR obligations concerning data minimisation and data protection by design can contribute to these assessments. Where processing presents high risks to individuals, a data protection impact assessment under Article 35 of the GDPR is likely to be required. 

The guidelines also emphasise cooperation between data protection authorities, Digital Services Coordinators and the European Commission. Such cooperation is intended to promote consistent enforcement while respecting the separate powers of the authorities responsible for each regulation.  

New Guidance on GDPR Administrative Fines 

Alongside the final DSA–GDPR guidelines, the EDPB adopted Guidelines 04/2026 on administrative fines. Unlike the final DSA–GDPR guidance, these guidelines remain subject to public consultation. 

They introduce a five-step methodology for determining whether a GDPR infringement warrants an administrative fine. Supervisory authorities must establish whether the infringement is punishable, identify the responsible controller or processor, and assess whether the violation was intentional or negligent. 

Authorities must then examine aggravating and mitigating circumstances before determining whether a fine would be effective, proportionate and dissuasive. The guidance indicates that minor infringements will generally attract reprimands rather than fines. For non-minor infringements, there is a strong presumption in favour of imposing a fine, subject to the circumstances of the particular case. 

The guidelines also examine how fines interact with other corrective powers, including warnings, processing restrictions and orders. They contain 14 practical examples intended to promote consistent enforcement across European supervisory authorities.  

Stakeholders can submit feedback until 13 November 2026. 

What Should Online Platforms Do Now? 

The final guidelines provide a framework for reviewing existing compliance practices. Online platforms should take the following steps to ensure that their DSA obligations are implemented consistently with the GDPR: 

  1. Review content moderation practices: Identify the lawful basis for processing personal data during content moderation. Assess whether automated detection systems, reporting mechanisms and investigation procedures collect only the information necessary for their intended purposes. 


  2. Reassess targeted advertising: Examine whether advertising systems rely on profiling using special categories of personal data or the personal data of minors. Ensure that users receive clear information about advertisements, including the principal parameters used to determine why particular advertisements are displayed. 


  3. Strengthen recommender-system transparency: Review how personalised recommendations are generated and how users can modify their preferences. Very large online platforms and search engines must provide at least one recommender-system option that does not rely on profiling and ensure that users' choices are effectively respected. 


  4. Implement privacy-conscious age assurance: Assess whether existing age-verification mechanisms are necessary and proportionate. Prioritise less intrusive methods that minimise the collection and retention of children's personal data while maintaining appropriate safety protections. 


  5. Update data protection impact assessments: Identify processing activities that may create high risks for individuals, particularly those involving large-scale profiling, automated decision-making or minors. Review existing assessments to account for overlapping DSA and GDPR obligations. 


  6. Prepare for coordinated regulatory enforcement: Establish clear internal responsibilities for DSA and GDPR compliance, document relevant processing decisions and monitor developments in the EDPB's proposed administrative-fines guidance. This will help organisations demonstrate compliance when responding to inquiries from different supervisory authorities. 

Conclusion 

The EDPB's final guidance clarifies how digital platforms should approach overlapping obligations under the DSA and GDPR. Content moderation, advertising transparency, recommender systems and child protection must all be assessed against the relevant data protection requirements. Together with the proposed administrative-fines guidance, the developments offer greater clarity about regulatory expectations and enforcement. For online platforms, the central compliance question is whether measures adopted under the DSA also satisfy the GDPR's requirements for lawful, necessary and proportionate processing. 

Want to Stay Ahead?     

Reach out to the experts at Tsaaro today. 

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.