Marketplaces — the DSA stack, before designation
A marketplace lets third parties sell to consumers on its own surface, which makes it a hosting service and an online platform under the Digital Services Act at the same time. The consequence is that the duties arrive in layers rather than as a single list: the ones every intermediary owes, the hosting layer, the platform layer, and on top of that the specific duties for platforms that allow distance contracts with traders. Most operators are far below the threshold that leads to designation as a very large online platform, and the widespread assumption that the DSA is a law for the big platforms is exactly where the effort gets underestimated — Chapter III applies without any designation. Alongside it the GDPR runs, most sharply where an account is scored, restricted or suspended by automated means. The AI Act, by contrast, needs a hook of its own; ranking and matching do not supply one.
- DSA · Chapter III
- DSA · marketplace duties
- GDPR · active
- AI Act · not activated by ranking alone
- DSA Section 5 · below the threshold
Sector profile for orientation. It describes what a profile of this shape typically reaches in EU digital law — not what applies to your company. That determination is a legal assessment and belongs to a mandate.
The layers below the designation threshold
Designation under Art. 33 DSA is what switches on the systemic-risk chapter — the risk assessment, the mitigation duties, the ad repository, researcher data access and the independent audit. Below that threshold none of it applies, and the rest of Chapter III still does. The table lists the layer that is owed regardless of size, subject to the exemptions the act grants to micro and small enterprises.
Regime footprint
| Regime & norm | Why it bites | What to do first |
|---|---|---|
| DSA · Art. 11 · 12 · 13 | Single points of contact for authorities and for recipients, in a designated language; a legal representative in a Member State where no establishment in the Union exists. | Name the contact points, publish them where they can actually be found, and check whether the establishment question makes Art. 13 relevant at all. |
| DSA · Art. 14 | The terms have to state the moderation rules clearly, and the platform has to apply them diligently, objectively and proportionately, with regard to fundamental rights. | Compare what the terms say about removal and suspension with what the moderation queue actually does; the gap between them is the exposure. |
| DSA · Art. 16 · 17 | Notice and action mechanisms have to be easy to use, and every restriction owes the affected recipient a statement of reasons — including whether automated means were used. | Build the mechanism and the reasons template together, and keep the fields the statement needs in the same record as the decision. |
| DSA · Art. 20 · 21 | An internal complaint-handling system and access to certified out-of-court dispute settlement follow every decision that restricts an account or a listing. | Put the redress path and its deadlines into the product rather than into a policy document nobody in operations reads. |
| DSA · Art. 25 | Interfaces must not deceive or manipulate recipients or otherwise distort their ability to make free and informed decisions. | Review the conversion mechanics — countdowns, pre-ticked options, friction on cancellation — before the next growth experiment ships. |
| DSA · Art. 26 · 27 | Advertising has to be identifiable with its payer and its main parameters; the main parameters of recommender systems have to be set out in the terms in plain language. | Write down how ranking actually works before writing the disclosure, and keep the two in sync when the ranking changes. |
| DSA · Art. 30 · 31 · 32 | Traders may only be admitted once identifying information has been obtained and assessed; the interface has to let traders meet their own duties; buyers have to be informed about illegal products. | Treat trader onboarding as a know-your-business-customer process with a record, and build the notification path for illegal products before it is needed. |
| GDPR · Art. 22 | A score or a rule set that suspends an account without a human in the loop can be an automated individual decision with legal or similarly significant effects. | Establish for each automated restriction whether a person actually decides, and design the intervention path before the first complaint arrives. |
Two boundaries belong next to this table. First, the AI Act is not activated by ranking, matching or scoring as such: it attaches to roles in relation to AI systems, and without that hook an AI Act cockpit would manufacture obligations rather than find them — the role check works the question through. Second, NIS2 names providers of online marketplaces among the digital providers in its annexes, so entity type and size thresholds have to be checked separately; that check is not answered by the DSA analysis.
Three seams that cost coordination
Each act on its own can be worked through. What costs time is the places where two of them describe the same button, the same feature or the same dataset, and neither gives way.
One suspension, two sets of rights
An account closed by an automated trust score is a restriction under the DSA and can at the same time be an automated individual decision under the GDPR. The DSA answers with a statement of reasons, an internal complaint route and out-of-court dispute settlement; the GDPR answers the same person, over the same event, with human intervention, the right to state a point of view and information about the logic involved. One button in the admin panel, two regimes, two clocks — and a product decision that has to satisfy both.
Recommender systems sit on the seam
Art. 27 DSA asks for the main parameters of the ranking to be explained; the GDPR governs the profiling underneath it — legal basis, transparency and the rights of the people being profiled. The two disclosure logics ask different questions: one about how the ranking works, the other about what data made it work. Every change to the ranking therefore touches two rulebooks and two clocks, and a release note that mentions neither is where the divergence starts.
Trader data: obtain it, and then justify keeping it
Art. 30 DSA requires identifying information about traders to be obtained and assessed before sales are allowed, and part of it to be made available to consumers. The GDPR asks the opposite question about the same records: what is necessary, how long it may be kept, and on what basis it may be published where the trader is a natural person. Collecting broadly to be safe under one act creates exposure under the other; the reconciliation belongs in the onboarding design, not in a later clean-up.
The layers separated instead of averaged
- Obligation cockpitThe DSA duties recorded per service and per layer — intermediary, hosting, platform, marketplace — with the source node attached, so a group with several offerings does not end up with one averaged list.
- Marketplace strandTrader traceability, compliance by design of the interface and consumer information as their own thread, because these are the duties that sit with product and operations rather than with legal.
- Collision mapThe seams above as curated walk-throughs, including the three unrelated Article 22s that appear in this fact pattern under different acts.
- Radar watchChange entries tagged to the profile, each with the date its watchlist was last reconciled. It reports a state; it does not claim to be a live feed.
- Deliverables, marked DRAFTObligation register across the layers, a notice-and-action and statement-of-reasons outline, a trader-traceability checklist, a gap report. Everything the suite generates carries a DRAFT mark: no signature, no assessment, no liability. It becomes an assessment only when the law firm Theo Funk takes it into a mandate and signs it off.
Where the software stops
Everything above is orientation drawn from a public corpus and readable back to its sources: structured self-assessment and decision support, not an evaluation of a specific company and not legal advice. Whether a threshold is met and how it is counted, whether an exemption applies, whether a suspension is an automated decision in the sense of the GDPR — those are legal assessments and belong to the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) builds the software and takes on appointed EU-representative functions; the firm does the legal work.
A worked profile of this shape, taken one step further: the model case on a marketplace above the designation threshold — the same layers, plus the chapter that designation switches on. All profiles: model cases. Background reading: playbooks.
Orientation, not legal advice
This sector profile and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.