A marketplace operator based in Rotterdam or Hamburg selling third-party goods to EU consumers has almost certainly run into this question since February 2024: what exactly do the DSA obligations require, and does a mid-sized platform with 200,000 monthly users really need to comply the same way as Amazon or eBay? The Digital Services Act applies a baseline of rules to nearly every online platform and marketplace operating in the EU, then layers additional requirements on top depending on size and role. Understanding which tier applies – and which specific mechanisms need to be built, not just documented – is where most compliance gaps show up.
What the DSA Actually Requires From Platforms and Marketplaces
The Digital Services Act entered into force in November 2022 and became applicable to all covered services on February 17, 2024. It replaces the old e-Commerce Directive framework and creates four tiers of obligation: intermediary services, hosting services, online platforms, and very large online platforms or search engines (VLOPs/VLOSEs) with more than 45 million average monthly EU users.
A marketplace connecting buyers and third-party sellers sits in the “online platform” tier at minimum, which means it inherits everything required of hosting services plus platform-specific rules. These include a notice-and-action mechanism for illegal content, an internal complaint-handling system, access to out-of-court dispute settlement, statement-of-reasons obligations for content moderation decisions, a ban on dark patterns in interface design, and – critically for marketplaces specifically – trader traceability under Article 30.
Trader Traceability Is the Obligation Marketplaces Underestimate
Article 30 requires marketplaces to collect and verify specific information from every business seller before letting them list: name, address, ID or registration number, bank details or payment account, and a self-certification that the trader will only offer legal products. This is often called Know Your Business Customer, and it’s not a one-time onboarding form.
If a marketplace later discovers a trader’s information is incomplete or false, it has to suspend the account until the gap is closed, provided proper notice was given first. A platform that onboarded 3,000 sellers in 2019 under a simple email-verification flow and never revisited those records is very likely non-compliant right now, even if nothing has changed on the storefront itself. Regulators reviewing marketplace compliance in 2025 have specifically flagged stale seller records as a recurring finding.
Notice-and-Action Mechanisms Need to Function, Not Just Exist
A “report this listing” button satisfies the letter of the DSA only if the underlying process meets the statutory requirements: the mechanism must let anyone submit notices electronically, the platform must acknowledge receipt without undue delay, and decisions have to come with a clear statement of reasons when content is removed or a trader is restricted. For platforms above a certain size, those statements of reasons also get submitted to the EU’s DSA Transparency Database.
A practical failure mode: the report button works from desktop but silently fails on the mobile app version, or routes to an inbox nobody monitors after a team reorganization. Cookie consent monitoring beyond visual verification follows the same logic that applies here – a control that looks correct in a screenshot but doesn’t function when actually triggered is a bigger liability than having no control at all, because it creates a false sense of compliance.
Common Mistakes Platforms Make With DSA Compliance
Three patterns show up repeatedly among mid-sized marketplaces and platforms handling DSA rollout.
First, treating the DSA as a one-time legal review completed in early 2024 rather than an ongoing operational requirement. Trader records, recommender system disclosures, and advertising transparency labels all drift out of compliance as the platform adds features or onboards vendors.
Second, assuming an updated Terms of Service document covers the obligation. The DSA requires functioning mechanisms – working complaint systems, actual response times, real record-keeping – not just updated legal text. A GRC lead reviewing a platform’s readiness should ask to see the last 90 days of notice-and-action tickets, not just the policy page.
Third, missing the EU legal representative requirement. Platforms established outside the EU that offer services to EU users need to designate a legal representative within a Member State, and this designation has to be publicly listed, typically alongside consumer rights display and legal requirements already published on the site.
Busting the “DSA Only Applies to Big Tech” Myth
A common misconception is that DSA obligations only bind the handful of platforms designated as VLOPs by the European Commission – currently around 25 services including large marketplaces, social networks, and app stores. That’s wrong. Baseline obligations, including trader traceability, notice-and-action, and internal complaint handling, apply to any online platform serving EU users regardless of size.
There’s a genuine exemption, but it’s narrower than most assume: micro and small enterprises (fewer than 50 employees and under €10 million in annual turnover or balance sheet total) are exempt from some platform-specific obligations like the internal complaint-handling system and certain advertising transparency rules, but not from the core hosting and traceability duties. A ten-person marketplace startup still needs a working notice-and-action process on day one.
Extending Due Diligence to Sellers and Third-Party Integrations
Marketplace due diligence doesn’t stop at the seller onboarding form. Payment processors, fulfillment integrations, and embedded widgets from third parties can all introduce compliance exposure if they collect data or display content outside the platform’s direct control. This overlaps significantly with vendor risk management practices that extend compliance beyond your own site, since a seller’s linked storefront or a payment widget hosted by a subprocessor still reflects on the marketplace’s DSA posture if it facilitates illegal listings.
Frequently Asked Questions
Does the DSA apply to a marketplace based outside the EU?
Yes, if it offers goods or services to users located in the EU, regardless of where the company is incorporated. Non-EU platforms must appoint an EU legal representative and comply with the same baseline obligations as EU-based platforms.
What’s the penalty for non-compliance with DSA obligations?
Fines can reach up to 6% of a platform’s global annual turnover for the most serious infringements, with the European Commission handling enforcement for VLOPs and national Digital Services Coordinators handling enforcement for smaller platforms.
Do refund and return policies fall under DSA scope?
Not directly – those sit more under consumer protection law – but the DSA’s transparency requirements around trader information intersect closely with the disclosures covered in eCommerce compliance for returns, refunds and disclosures, since buyers need accurate seller identity to exercise those rights in the first place.
DSA compliance for a marketplace is less about a single audit and more about maintaining several interlocking systems – trader records, complaint handling, notice-and-action, transparency reporting – that all need to keep working as the platform grows. The practical starting point is pulling the last quarter of seller verification records and checking how many are actually current.
