How Does the DSA Interact with GDPR? Key Differences and Compliance Overlap Explained

Key Takeaways

  • Both laws apply simultaneously: The DSA does not override the GDPR. Platforms must comply with whichever framework imposes stricter requirements at any given point.
  • Personal data processing triggers GDPR: Virtually every DSA obligation involves personal data processing, making GDPR compliance non-negotiable.
  • Special category data is absolutely prohibited: The prohibition on using special category data to target advertising applies even in situations where the controller has identified an Article 6 GDPR lawful basis and an Article 9 GDPR exception applies to the processing.
  • Transparency timing differs: GDPR requires prior disclosure; DSA permits real-time, ad-level transparency.
  • Recommender systems need non-profiling alternatives: Article 38 of the DSA requires it to provide at least one recommender system option that doesn't rely on profiling as defined in the GDPR.

Understanding the DSA-GDPR Relationship

The General Data Protection Regulation (GDPR) and the Digital Services Act (DSA) are two of the most consequential regulations shaping Europe's digital landscape. Their objectives intersect in meaningful ways, and their requirements can overlap. However, they approach digital regulation from fundamentally different angles.

The DSA aims to create a safe, predictable and trusted online environment by preventing the dissemination of illegal content, reducing societal risks stemming from the spread of disinformation and preserving fundamental rights. These aims are complementary to those of the EU General Data Protection Regulation, which seeks to protect the fundamental rights of data subjects.

On September 11, 2025, the European Data Protection Board (EDPB) adopted guidelines on the interplay between the Digital Services Act (DSA) and the General Data Protection Regulation (GDPR). These guidelines provide much-needed clarity on how platforms should navigate dual compliance. Before diving into specific overlaps, it's helpful to understand whether the DSA applies to your platform.

Scope and Applicability: Where They Differ

The GDPR takes a horizontal approach across all sectors processing personal data, whilst the DSA applies only to intermediary services as defined in Article 3 (g), including hosting services and, within them, online platforms that disseminate user content to the public. Basic DSA duties apply to all intermediary services, enhanced requirements govern online platforms, and the most stringent obligations apply to VLOPs and VLOSEs serving over 45 million monthly active users in the EU.

This layered approach means that GDPR applies universally to personal data processing, while the DSA creates tiered obligations based on platform size and type. Understanding this distinction helps platforms identify which frameworks govern specific processing activities.

Advertising and Profiling: Critical Compliance Overlap

This is where DSA-GDPR interaction becomes most complex. The DSA and GDPR are closely linked, especially where platforms process personal data in areas such as targeted advertising, recommender systems, or content moderation.

The Special Category Data Prohibition

One of the most important areas where the DSA imposes stricter rules than GDPR is the use of special category data for advertising. Article 26(3) DSA forbids providers from processing special categories of data to present advertisements based on profiling, even when the GDPR might otherwise permit profiling (e.g. because the recipient of the service explicitly consented to the processing of its sensitive personal data).

This represents a fundamental difference: while GDPR permits special category data processing under certain conditions (including explicit consent), the DSA creates an absolute prohibition for advertising purposes. Article 26(3) prohibits online platforms from presenting advertisements based on profiling using special categories defined in Article 9(1) of the GDPR. This includes health data, sexual orientation, religious beliefs, political opinions, and similar sensitive information.

Advertising Transparency Timing and Requirements

A subtle but important difference exists in how transparency obligations apply. The DSA requires real-time, ad-level disclosures that are directly accessible from the ad itself – after any potential personal data processing for that particular ad has occurred. The GDPR requires information at or before data collection or before consent is obtained. The DSA, in turn, requires real-time, ad-level disclosures that are directly accessible from the ad itself – after any potential personal data processing for that particular ad has occurred.

Platforms must therefore design transparency layers that satisfy different, complementary obligations at different touchpoints. In practice, this means providing both pre-processing GDPR notices and real-time DSA disclosures. For guidance on implementing these obligations, review our DSA advertising repository compliance guide.

Profiling and Automated Decision-Making

The EDPB notes that ad targeting may qualify as ADM under the GDPR where it significantly affects individuals, for example by influencing user behavior. Factors that could trigger ADM under the GDPR include the intrusiveness of the profiling, cross-site and cross-device tracking, users' expectations, how the ad is delivered, and whether vulnerabilities are being exploited—for instance situations where targeting takes place based on a person's age, economic situation, or emotional state.

When targeting meets this threshold, GDPR's Article 22 automated decision-making rules apply alongside DSA transparency requirements, creating overlapping but distinct obligations.

Recommender Systems: Non-Profiling Alternatives

The DSA's recommender system requirements create direct interaction with GDPR's profiling definitions. VLOPs and VLOSEs must also offer user choice, including at least one option not based on profiling as defined under the GDPR.

The EDPB notes that content presentation through algorithmic curation could constitute Article 22(1) GDPR decisions when producing significant effects on users. Platforms providing multiple recommender options must present choices equally without nudging toward profiling-based systems.

This requirement means platforms must understand GDPR's profiling definition and implement DSA-mandated alternatives accordingly. Additionally, offering non-profiling options under the DSA does not replace GDPR-grade consent for tracking. For detailed implementation guidance, consult our article on recommender system transparency requirements.

Content Moderation and Notice-and-Action Mechanisms

The DSA obliges hosting services to deploy notice-and-action mechanisms so users can flag illegal content. Inevitably, these systems involve processing personal data—from the notifier, the content poster and potentially third parties referenced.

When platforms implement content moderation systems, they must ensure that all personal data processing complies with GDPR principles, including data minimization, lawful basis, and transparency. The EDPB clarifies that online platform providers should be transparent towards data subjects about any processing carried out in the context of a complaint and provide all information required to meet the transparency requirements under the GDPR. Controllers should clearly set out the purposes of processing, applicable retention periods, and any disclosures (for example, to trusted flaggers).

Data Minimization and Lawful Basis

GDPR compliance principles are key – lawful, fair and transparent processing, data minimisation, data protection by design and default, and data retention in particular. These principles apply to all DSA-related personal data processing.

Platforms should ensure all DSA-related processing has a valid legal basis under GDPR, implement transparency, data minimization, and fairness in moderation, recommender systems, and advertising, offer non-profiling options and protect minor users from targeted advertising, and conduct DPIAs where systemic or high-risk data processing is involved.

This means platforms cannot simply rely on DSA obligations as a justification for processing without identifying a proper GDPR lawful basis (such as Article 6(1)(c) for compliance with legal obligations).

Protection of Minors

The DSA bans targeted ads to minors, so controllers must implement proportionate age-assurance and disable targeting for under-18s. Any age-checking must be privacy-preserving and minimised.

This overlaps with GDPR Article 8 provisions on children's consent and Article 4(11) on profiling definitions. Platforms must implement solutions that satisfy both frameworks without creating excessive data collection burdens.

Trader Traceability and Know-Your-Customer (KYC) Lite

The DSA requires online marketplaces to collect and verify information from traders selling to consumers, ensuring they can be identified and located, and to ensure traders only offer products and services that are compliant with EU law. The guidance reiterates that only data that is required by the DSA to verify business users should be collected, and strict retention policies tied to DSA needs should be in place.

This DSA requirement has clear GDPR implications: platforms must identify a lawful basis for collection, apply data minimization principles, and establish appropriate retention schedules.

Enforcement and Regulatory Cooperation

The duty of sincere cooperation (Article 4(3) TEU) applies across enforcement bodies. The European Board for Digital Services (EBDS) and European Data Protection Board (EDPB) are expected to collaborate to ensure consistency in regulatory interpretation.

This means digital services coordinators and data protection authorities may coordinate investigations and enforcement actions, particularly where DSA and GDPR obligations overlap. Understanding enforcement priorities helps platforms prioritize compliance efforts. For insights into current enforcement trends, see our 2026 DSA enforcement case studies.

Practical Compliance Roadmap

Conduct a Dual Compliance Audit

Map all personal data processing activities required by DSA obligations (advertising, content moderation, recommender systems, trader verification) and identify applicable GDPR lawful bases and principles for each. This creates a comprehensive inventory of compliance requirements.

Implement Joined-Up Governance

Rules on transparency, profiling, minors' protection, and automated decision-making overlap and must be applied consistently. To manage these expectations, legal, privacy, compliance, and trust & safety teams should work together to ensure a joined-up approach.

Design Privacy-by-Default Systems

Technical implementation requirements emphasize privacy-preserving approaches to dual compliance. The EDPB recommends zero-knowledge proofs and local processing solutions that minimize additional tracking or profiling risks.

Document Legal Bases and Risk Assessments

For DSA obligations involving personal data processing, clearly document the GDPR lawful basis being relied upon. Consider conducting Data Protection Impact Assessments (DPIAs) for high-risk processing activities, particularly recommender systems and targeted advertising.

Quick Reference: DSA and GDPR Comparison Table

Aspect GDPR DSA Key Interaction
Scope All personal data processing, all sectors Intermediary services, tiered by size GDPR applies to all DSA-related processing
Special Category Data & Advertising Permitted with lawful basis + Art. 9 exception Absolute prohibition for profiling-based ads DSA is stricter; it overrides GDPR permissions
Transparency Timing Before/at time of data collection Real-time, at point of service Both required at different touchpoints
Profiling Definition Any form of automated processing References GDPR's definition DSA non-profiling options use GDPR definition
Lawful Basis Six possible bases (Art. 6) No independent lawful basis; requires GDPR DSA processing must have valid Art. 6 basis
Recommender Systems Transparency + profiling rules apply Non-profiling alternative required (VLOPs) Non-profiling option must use GDPR profiling definition
Automated Decision-Making Article 22 protections when significant effects Transparency on logic + decision-making Both may apply; DSA may extend beyond Art. 22
Data Minimization Core principle; only necessary data Only data necessary for DSA compliance Strictly enforce for all DSA obligations

Frequently Asked Questions

Does the DSA override GDPR?

No. The DSA explicitly states it operates "without prejudice to" the GDPR, meaning both regulations apply simultaneously, and you must comply with whichever provides stronger protection. Where the two conflict, follow the stricter requirement.

Can I use GDPR consent as justification for DSA-related personal data processing?

Not automatically. While consent may serve as a GDPR lawful basis, it must be genuine, informed, and granular under both frameworks. Additionally, the DSA does not affect ('is without prejudice to') the rules of the GDPR and the ePrivacy Directive. Data protection law may thus impose stricter requirements. The DSA's special category data prohibition in advertising applies regardless of consent.

What is the difference between DSA and GDPR transparency requirements for advertising?

The EDPB notes that the DSA's advertising transparency requirements are distinct from, and may require a different approach to, the GDPR's transparency requirements. GDPR transparency must occur before processing; DSA transparency can occur at the point of ad delivery. Both must be satisfied, but at different times.

Are DSA obligations with a legal basis automatically GDPR-compliant?

No. A DSA obligation might justify processing under Article 6(1)(c) GDPR (compliance with legal obligations), but platforms must still apply GDPR principles like data minimization, transparency, and retention limits. DSA necessity doesn't exempt you from GDPR fairness or accountability principles.

Must I conduct a DPIA for DSA compliance activities?

It depends on the nature of processing. High-risk activities like targeted advertising using inferred data, recommender systems, or content moderation involving sensitive personal data should trigger DPIAs. Appropriate implementation of data minimisation and data protection by design and default may contribute to addressing systemic risks.

How should I handle special category data inferred from user engagement?

Special category data stays special: The DSA prohibits targeted advertising based on special category data. If such data is inferred (e.g. from engagement), you need an Article 9 condition - or avoid the processing altogether!

Conclusion

The DSA and GDPR are designed to work in concert, not conflict. Obligations under one regulatory framework may cascade into others, creating overlapping responsibilities and risks. Successfully navigating the regulatory environment requires precision, coordination, and strategic foresight.

The key insight from the EDPB's 2025 guidelines is that rules on transparency, profiling, minors' protection, and automated decision-making overlap and must be applied consistently. Platforms cannot compartmentalize DSA compliance separately from data protection. Instead, successful compliance requires integrated governance where legal, privacy, trust & safety, and product teams align on how DSA obligations translate into GDPR-compliant practices.

Start by auditing your current DSA-related processing activities, identifying GDPR lawful bases, and documenting how you satisfy both frameworks. Consider implementing privacy-by-design approaches that minimize data collection, restrict special categories, and provide genuine user transparency at appropriate touchpoints. For technical guidance on specific DSA provisions, explore our resources on transparency reporting, independent audits, and systemic risk assessment.

Scroll to Top