Regingada
Model case · Online marketplace · EU

A marketplace at designation scale — and no AI Act in sight

fictional demo profile

EuroMarktplatz runs advertising, recommender systems, third-party traders and user uploads above the DSA designation threshold. The compliance department does not need a beginners' classification — it needs the depth of Chapter III, Section 5, and nothing it does not owe.

  • DSA · designated-platform duties
  • GDPR · Art. 22
  • AI Act · not activated

Model case study. This scenario is built on a fictional demo persona that ships with the Regingada Compliance Suite — not a real client, not a real company. Any similarity to existing companies is coincidental. It shows how the suite maps a profile of this shape to EU digital law. No legal advice.

1 · The situation

Everything a platform can be, in one service

EuroMarktplatz AG (fictional demo profile) operates an online marketplace from Hamburg. It is established in the Union, so the third-country representative question never arises. What makes the profile hard is not where it sits but how much it does: third-party traders sell through it, users upload content and reviews, advertising is sold against that inventory, recommender systems decide what gets seen, and minors are among the recipients. Each of those features pulls in a different part of the Digital Services Act.

The number of monthly active recipients in the Union sits above the 45 million threshold that leads to designation as a very large online platform, which switches on the heaviest chapter of the regulation. The reader in this persona is a Chief Compliance Officer with a real department behind her; she is not looking for a classification quiz, she is looking for the systemic-risk layer and the marketplace-specific duties. On the data-protection side the sharp edge is a trust score that can suspend a seller account. The demo profile answers: intermediary service in the EU, platform type, above the designation threshold, features advertising, recommenders, marketplace, user uploads and minors; personal data yes, special categories no, automated decisions unsure. The AI Act profile is left empty on purpose.

2 · Regime footprint

The full DSA stack — and a deliberately empty AI Act profile

The suite activates the DSA with its designated-platform layer and the GDPR. It does not activate the AI Act. A marketplace that runs recommender systems is not thereby an AI provider or a deployer of a listed high-risk system, and the twin declines to open a cockpit that would generate an impressive but wrong duty list. That restraint is a feature: an obligation set that includes things you do not owe is not more careful, it is less usable.

Central articles for this profile

Article Duty in short Why for this profile
DSA · Art. 11 · 12Single points of contact for authorities and for recipients of the serviceThe entry door for supervision — and the first thing an authority tests when it wants to reach you.
DSA · Art. 14Terms and conditions: content-moderation rules stated clearly and applied diligentlyEvery moderation and suspension decision is measured against what the terms actually say.
DSA · Art. 16 · 17Notice and action mechanisms, and a statement of reasons for every restrictionUser uploads and trader listings both generate notices; both generate decisions that must be explained.
DSA · Art. 20 · 21Internal complaint-handling and out-of-court dispute settlementA suspended seller has a redress path that runs on the platform's own clock.
DSA · Art. 22Priority treatment of notices from trusted flaggersA queue with legal consequences — and one of three unrelated Article 22s in this fact pattern.
DSA · Art. 25No interface design that deceives or manipulates recipientsMarketplace conversion mechanics live exactly where the dark-pattern prohibition bites.
DSA · Art. 26 · 27Advertising transparency and the main parameters of recommender systemsTwo of the profile's core features become disclosure duties rather than product secrets.
DSA · Art. 28Protection of minors and no advertising based on profiling of minorsThe profile flags minors among the recipients, which switches this duty on rather than leaving it hypothetical.
DSA · Art. 30Traceability of traders — collecting and checking identifying information before allowing salesThe marketplace-defining duty. Not a contract question: a know-your-business-customer duty.
DSA · Art. 31 · 32Compliance by design of the interface, and information to consumers about illegal productsTrader duties have to be enforceable through the interface, and recalls have to reach buyers.
DSA · Art. 33Designation as a very large online platform above the recipient thresholdThe switch that turns on the whole systemic-risk chapter, with its own timeline.
DSA · Art. 34Systemic risk assessment: illegal content; fundamental rights; civic discourse, electoral processes and public security; gender-based violence, public health, minors and physical and mental well-beingFour named risk categories — the core annual exercise for a designated platform.
DSA · Art. 35 · 36Mitigation measures for identified risks, and the crisis response mechanismThe assessment is only half of it; the measures and their evidence are what get audited.
DSA · Art. 39 · 40Public repository of advertisements, and data access for vetted researchersTwo duties that turn internal systems into external interfaces — engineering lead time, not legal drafting.
GDPR · Art. 22Automated individual decision-making, including profilingA trust score that suspends an account is exactly the fact pattern this article was written for.

Articles are shown because a profile of this shape reaches them, not because a lawyer has found that they apply to you. Which of them actually bite in a concrete company is an assessment — and that is a mandate.

3 · Collision points

Where the regimes rub against each other

  • One suspension, two sets of rights

    An account suspended by an automated trust score is a restriction under the DSA and, potentially, an automated individual decision under the GDPR. The DSA gives the seller a statement of reasons, an internal complaint route and out-of-court dispute settlement. The GDPR gives the same person, over the same event, a different set: human intervention, the right to express a point of view, and information about the logic involved. Same button in the admin panel, two regimes, two clocks — and a product decision that has to satisfy both.

  • Three unrelated Article 22s

    Art. 22 DSA is about trusted flaggers. Art. 22 GDPR is about automated decisions. Art. 22 AI Act is about authorised representatives of third-country providers. In this fact pattern the first two are live and the third is not, and a meeting that says "Article 22" without a regime in front of it will produce the wrong action item. The map treats them as separate anchors — same number, different norms, no edge between them.

  • Recommenders sit on the seam

    The DSA requires the main parameters of the recommender system to be explained and, for designated platforms, at least one option that is not based on profiling. The GDPR governs the profiling underneath it — lawful basis, transparency, the rights of the people being profiled. One system, two disclosure logics that ask different questions: the DSA asks how ranking works, the GDPR asks what data made it work.

  • Not every algorithm is an AI Act case

    Ranking, matching and scoring on a marketplace are regulated here by the DSA and the GDPR. The AI Act needs a hook of its own: a role as provider or deployer of a system in one of its regulated categories. Without that hook, opening an AI Act cockpit would manufacture obligations rather than find them. The twin leaves the profile empty and says so, which is a more useful answer than a long list.

4 · What the twin delivers

Depth for a department that already knows the basics

Service portfolio and obligation cockpit

Services are recorded individually and classified by type and features, so a group with several offerings does not end up with one averaged duty list. From that classification the cockpit derives the layered DSA set: the duties every intermediary owes, the hosting layer, the platform layer, the marketplace duties, and the designated-platform chapter on top.

Systemic-risk sub-cockpit

Art. 34 broken into its four named risk categories as a working structure rather than an essay prompt: illegal content; fundamental rights; civic discourse, electoral processes and public security; gender-based violence, public health, minors and physical and mental well-being. Alongside it, the mitigation strand under Art. 35 and the crisis mechanism under Art. 36 — with the source nodes attached, so a draft can be read back to the norm.

Marketplace strand

Trader traceability under Art. 30, compliance by design under Art. 31 and consumer information under Art. 32 as their own thread, because these are the duties that distinguish a marketplace from a content platform — and the ones that most often sit with product and operations rather than with legal.

Cross-regulation view and radar

The DSA-to-GDPR seams as curated walk-throughs, including the suspension pattern and the recommender pattern, with the numbering traps shown as separations rather than links. The radar carries change entries tagged to the profile and reports the state of its watchlist with a date; it does not claim to be a live feed.

Deliverables — and the DRAFT rule

The suite can generate an obligation register across the DSA layers, an outline for the systemic-risk assessment, a trader-traceability checklist, requirements for the advertisement repository and a gap report. Everything it produces is marked DRAFT. A DRAFT carries no signature, no assessment and no liability; it is a structured starting point. It becomes an assessment only when the law firm Theo Funk takes it into a mandate and signs it off. Package details and prices are listed separately under pricing.

5 · Step 2

Where the software stops

Everything above is orientation: a map of what a profile of this shape reaches in EU digital law, drawn from a public corpus and readable back to its sources. It is structured self-assessment and decision support — it is not an evaluation of a specific company, and it is not legal advice.

The assessment is the second step, and it belongs to the law firm Theo Funk under a separate mandate: whether the designation threshold is actually met and how it is counted, how far the systemic-risk assessment has to reach, whether a trust-score suspension is an automated decision in the GDPR sense, how a repository has to be built to hold up. Regingada UG (haftungsbeschränkt) builds the software; the firm does the legal work. The two are strictly separated, and that separation is the reason the tool can be as blunt as it is.

Build your twin Visit the law firm Theo Funk

Other profiles: all five model cases. Packages: pricing.

Disclaimer

Orientation, not legal advice

This model case and the suite provide orientation and information only. They are not legal advice. Individual-case advice is provided exclusively by the law firm Theo Funk under a separate mandate. Regingada UG (haftungsbeschränkt) — the software company and appointed EU representative — and the law firm are strictly separated.