What is the difference between the DSA and GDPR?
The DSA regulates online intermediary due diligence; GDPR regulates personal data processing.
DSA vs GDPR: The DSA applies because of the online intermediary service you provide; GDPR applies because of personal data processing. Platform compliance often needs both. Sources: EUR-Lex: Digital Services Act; EUR-Lex: GDPR.
The short version
The DSA asks how online services handle content, notices, transparency and systemic risk. GDPR asks whether personal data processing has a lawful basis, rights handling and protection safeguards.
Side by side
Regulation
DSA
Digital Services Act
- What it is
- The DSA sets due-diligence, transparency and risk-management duties for online intermediaries, with the strongest duties for very large services.
- Scope
- Intermediary services offered to recipients in the EU, including hosting, online platforms, marketplaces, very large online platforms and very large online search engines.
- Who it applies to
- Providers of intermediary services, with obligations scaling by service type, size and designation status.
- Key dates
- Entered into force in 2022.
- Most providers have applied the DSA since 17 February 2024; designated very large services faced earlier duties.
- Core obligations
- Maintain points of contact, terms transparency and illegal-content notice mechanisms where required.
- For platforms, handle complaints, trusted flaggers, advertising transparency and recommender transparency.
- For VLOPs and VLOSEs, assess and mitigate systemic risks, undergo audits and provide data access to vetted researchers.
- Penalties
- Member States and the Commission can impose penalties; the DSA caps fines for infringements at up to 6% of annual worldwide turnover.
Regulation
GDPR
General Data Protection Regulation
- What it is
- The GDPR is the EU's horizontal rulebook for personal data processing and data protection rights.
- Scope
- Personal data processing by controllers and processors, including many non-EU organisations that target or monitor people in the EU.
- Who it applies to
- Controllers, processors and other organisations that determine, perform or support personal data processing covered by the GDPR.
- Key dates
- Adopted in 2016.
- Applicable from 25 May 2018.
- Core obligations
- Have a lawful basis for processing personal data.
- Provide transparency, data-subject rights and security measures.
- Use governance measures such as records, processor contracts, DPIAs and breach notification where required.
- Penalties
- Supervisory authorities can impose administrative fines up to EUR 20 million or 4% of annual worldwide turnover for the highest tier of infringements.
Which applies to you?
If you operate an intermediary service, platform, marketplace or search engine, check DSA. If the service processes personal data, GDPR is also in scope.
Frequently asked
Does the DSA replace GDPR for platforms?
No. The DSA does not replace GDPR. Platforms often need to comply with both.
Which law covers recommender transparency?
The DSA contains platform and very-large-platform transparency duties around recommender systems. GDPR may also matter if personal data is used.
Which law covers user data rights?
GDPR is the core personal-data rights law. The DSA has separate user-facing transparency and complaint-handling duties.
Official sources
Comparisons are grounded explainers, not legal advice. Use the linked EUR-Lex texts and official sources for binding legal wording.
Related terms
Does this comparison affect your company?
Enter your company and Lex builds a cited Exposure Map in about 30 seconds. Free, no login.