Social and UGC — moderation as a legal system
A service on which users publish content stores information provided by recipients at their request, which makes it a hosting service and, where the content is disseminated to the public, an online platform under the Digital Services Act. What follows is that moderation stops being an operational matter and becomes a legal system: the terms have to describe the rules, every restriction owes a statement of reasons, and every decision opens a redress path with its own deadlines. Alongside that runs the data-protection layer, because user content routinely carries personal data and, in the nature of the medium, sometimes special categories that nobody in the product asked for. Where minors are among the recipients, a further set of duties attaches — with the awkward consequence that verifying age is itself a processing operation. And where moderation, ranking or generation is automated, the AI Act adds its own transparency duties on top of the ones the DSA already imposes.
- DSA · Chapter III
- GDPR · active
- AI Act · only with automated moderation
- NIS2 · entity- and size-dependent
- Data Act · not activated
Sector profile for orientation. It describes what a profile of this shape typically reaches in EU digital law — not what applies to your company. That determination is a legal assessment and belongs to a mandate.
Moderation, transparency and the people in the content
The duties below apply without any designation as a very large online platform; the systemic-risk chapter sits above them and is switched on by designation, not by ambition. The list is written for the layer that is owed regardless, subject to the exemptions the act grants to micro and small enterprises.
Regime footprint
| Regime & norm | Why it bites | What to do first |
|---|---|---|
| DSA · Art. 14 | The terms have to set out the content-moderation policies, procedures and tools in clear language, and they have to be applied diligently, objectively and proportionately, with regard to fundamental rights. | Write the terms from the moderation playbook that operations actually uses, not the other way round; a rule the queue does not follow is a liability, not a policy. |
| DSA · Art. 16 · 17 | Notices must be easy to submit and to process, and every restriction of content, visibility, monetisation or account owes a statement of reasons — including whether automated means were used. | Keep the fields the statement of reasons needs in the same record as the moderation decision, so the explanation is a by-product rather than a reconstruction. |
| DSA · Art. 20 · 21 · 22 | Internal complaint handling and certified out-of-court dispute settlement follow every restriction; notices from trusted flaggers have to be given priority and processed without undue delay. | Design the priority queue and the redress path together — a fast lane without a review lane is where over-removal accumulates. |
| DSA · Art. 15 · 24 | Transparency reporting on moderation activity, with additional items for online platforms, including disputes, suspensions and the average monthly active recipients. | Define the counting method before the reporting period runs, because a number that cannot be reproduced is worse than a late report. |
| DSA · Art. 26 · 27 · 28 | Advertising must be identifiable with its payer and parameters; the main parameters of recommender systems have to be explained; minors need appropriate protection, and advertising based on profiling of minors is prohibited. | Establish what the service actually knows about the age of its recipients, and let that answer — not an assumption — drive both the ad stack and the recommender disclosure. |
| GDPR · Art. 6 · 9 | User content and the moderation records built from it are personal data, and content about health, beliefs, sexual orientation or political opinions falls into the special categories, whether or not the platform wanted it there. | Fix the legal basis for moderation, for the moderation log and for its retention separately from the basis for publishing the content itself. |
| GDPR · Art. 22 + AI Act · Art. 50 | Fully automated removal or account suspension can be an automated individual decision; where users interact with an AI system or content is generated or manipulated by one, the AI Act adds transparency duties of its own. | Record for each automated step whether a human actually decides, and mark AI interaction and synthetic content where the act requires it rather than where the design prefers it. |
The Data Act is deliberately absent: a social service is not thereby a provider of a connected product or a related service, and opening that strand would generate an impressive but wrong duty list. NIS2, by contrast, names providers of social networking services platforms among the digital providers in its annexes, so entity type and size thresholds have to be checked separately. The AI Act role question — provider or deployer, per system — is worked through in the role check.
Operated without an establishment in the Union: a service with a substantial connection to the Union owes a legal representative under Art. 13 DSA, and the data-protection representative under Art. 27 GDPR is a separate appointment that the first one does not discharge. Depending on the footprint, further appointment duties can stack on top. The overview of appointed representation is at EU representation; the five duties are placed side by side in the EU representative compass.
Three seams that cost coordination
Each act on its own can be worked through. What costs time is the places where two or three of them describe the same moderation decision, the same screen or the same check, and none of them gives way.
Automated moderation, explained three times
A classifier that removes a post triggers three obligations at once: the DSA wants a statement of reasons that discloses the use of automated means, the AI Act wants transparency where users interact with an AI system or where content is generated or manipulated by one, and the GDPR wants the guarantees that surround an automated individual decision. Three catalogues describe the same screen with different vocabularies and different addressees. Working through them one at a time means building the notification flow three times.
Protecting minors by processing more data
Art. 28 DSA asks for appropriate measures for the protection of minors and prohibits advertising based on profiling where the platform is aware that a recipient is a minor. Establishing that awareness usually means an age check, and an age check is a processing operation that the GDPR measures against necessity, data minimisation and, depending on the method, the special-category rules. The safest answer under one act is the riskiest under the other, and the reconciliation is a design decision rather than a policy sentence.
Trusted flaggers against the duty to look
Notices from trusted flaggers have to be handled with priority and without undue delay, while every removal remains a decision that has to be diligent, proportionate and mindful of the fundamental rights of the person who posted. A priority queue that removes on receipt converts the speed requirement into a systematic over-removal, and every one of those removals still owes a statement of reasons and a redress path. The number 22 is also a trap here: Art. 22 DSA is about trusted flaggers, Art. 22 GDPR about automated decisions, Art. 22 AI Act about authorised representatives — three unrelated norms.
Moderation duties as a structure, not as a memo
- Obligation cockpitThe DSA duties recorded per service and per layer — intermediary, hosting, platform — with the source node attached, so a company running several surfaces does not end up with one averaged list.
- Moderation strandNotice and action, statements of reasons, complaint handling, out-of-court settlement and the trusted-flagger queue as one connected thread, because in practice they are one workflow rather than five paragraphs.
- Collision mapThe seams above as curated walk-throughs, including the numbering traps where identical article numbers carry unrelated duties in different acts.
- Radar watchChange entries tagged to the profile, each with the date its watchlist was last reconciled. It reports a state; it does not claim to be a live feed.
- Deliverables, marked DRAFTObligation register, a statement-of-reasons outline, a transparency-report structure, a gap report. Everything the suite generates carries a DRAFT mark: no signature, no assessment, no liability. It becomes an assessment only when the law firm Theo Funk takes it into a mandate and signs it off.
Where the software stops
Everything above is orientation drawn from a public corpus and readable back to its sources: structured self-assessment and decision support, not an evaluation of a specific company and not legal advice. Whether a service is an online platform in the sense of the act, whether an exemption applies, whether an automated removal is an automated decision under the GDPR, how far the duty to protect minors reaches — those are legal assessments and belong to the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) builds the software and takes on appointed EU-representative functions; the firm does the legal work.
The closest worked profile: the model case on a platform with user uploads, advertising and recommender systems — the same moderation stack, seen from a marketplace. All profiles: model cases. Background reading: playbooks.
Orientation, not legal advice
This sector profile and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.