News from Across the Sea #8

News from Across the Sea 8: Welcome to the eighth issue of our bimonthly newsletter on the European Union’s Digital Services Act (DSA). In this issue, we have updates on the data access agenda

News from Across the Sea #8:

Welcome to the eighth edition of our bimonthly newsletter on the European Union’s Digital Services Act (DSA). In this issue, we have updates on the agenda for access to data for research, the online sale of illegal goods, the protection of minors, out-of-court dispute resolution regarding content moderation decisions, and a couple of court rulings addressing the scope of platforms’ obligations under the DSA.

Data Access (i): The Machine in Motion

On October 2, the delegated legislation regarding data access for researchers under Article 40(4) of the DSA. In this post and in this previous article, we analyzed in greater depth its significance, its limitations, and its main challenges, although we have been following the topic for some time. In accordance with this regulation, the European Commission’s Data Access Portal for Researchers is now online. In addition, several services have already launched their data catalogs. The catalogs describe the available datasets for which access may be requested under Article 40(4), along with their structure and metadata. The catalogs must include data on systemic risks in the European Union that data providers have identified in their annual risk assessments in accordance with Article 34 of the DSA, as well as data on any risk mitigation measures referred to in Article 35. The catalogs must be updated periodically and are not required to be exhaustive; therefore, researchers’ data requests may go beyond the data listed in the catalogs. You can find the list of available data catalogs here.

Data Access (ii): Two Providers in Trouble

Notwithstanding the entry into force of delegated legislation regarding the provision of non-public data pursuant to Article 40(4), large platforms and large search engines (VLOPSEs) were already obligated, under Article 40(12) of the DSA, to provide access “without undue delay to the data, including, where technically possible, real-time data, provided that the data is publicly accessible on their online interface.” As we reported earlier, the perception among researchers was that the platforms were not complying with this regulation. Apparently, the European Commission shares this view, and has therefore communicated to Meta and TikTok the preliminary conclusions of its investigations against them, in which it determined that both companies have failed to fulfill their obligation to grant researchers adequate access to public data under Article 40(12). Furthermore, in the case of Meta, it found that both Instagram and Facebook failed to meet their obligations to provide users with (i) simple mechanisms to report illegal content and (ii) mechanisms to appeal content moderation decisions. Both providers will now have at least 14 days to submit their comments and objections, which the Commission must take into account in its final decision.

Temu and Shein in the Crosshairs:

A group of 40 European lawmakers called on the European Commission to investigate the three Chinese e-commerce platforms designated as VLOPs under the DSA—Aliexpress, Temu, and Shein—for selling illegal goods. The request followed investigations by the French authorities against this and other e-commerce platforms for selling child-like sex dolls. France’s Minister of the Economy had already threatened to block access to Shein in that country if the product was not immediately removed from the market. The company claims to have taken steps to ensure that these products are removed immediately from its platform.

Online Protection of Minors: The Commission Steps Up Action

On October 19, the European Commission requested information from four platforms (Snapchat, YouTube, the Apple Store, and Google Play) regarding the measures they are taking to protect minors who use their services. According to the Commission’s press release, Snapchat must explain how it prevents children under 13 from accessing its platform and how it prevents the sale of illegal products such as e-cigarettes and drugs. YouTube is facing questions about its age controls and recommendation system following reports of harmful content reaching minors. For their part, Apple and Google must detail how their app stores block illegal or harmful apps—including those involving gambling and digital nudity—and how they enforce age ratings. These are the first investigative measures taken under the new Guidelines for the Protection of Minors under the DSA, issued pursuant to Article 28 of the DSA, which requires providers to ensure high levels of “privacy, security, and protection” in their services. In addition, the Commission continues to make progress in developing its prototype age-verification app, which is open-source and based on the presentation of identification documents. In the past, organizations such as EFF have warned about the potential challenges to user privacy that could arise if such solutions were implemented. The EU appears to have embraced a techno-solutionist approach by assuming that user age verification is a sort of silver bullet for protecting minors online, and by also assuming that it is possible to develop age verification systems that are both effective and do not compromise user privacy.

Appeals Center Europe Transparency Report:

Article 21 of the DSA, one of the most innovative provisions, grants users the right to appeal any content moderation decision to an out-of-court dispute resolution body. These private bodies may issue decisions (which are not binding on platforms) in cases brought before them by users. To operate, these services must be certified by the Digital Services Coordinator of their country of origin. To date, 9 bodies have been certified. Appeals Centre Europe, one of these bodies, founded and funded by the Oversight Board Trust—the trust established by Meta to oversee the Oversight Board— published its first transparency report, covering the period from November 2024 to August 2025. Among the most notable findings, the report reveals that 55% of the cases decided were initiated by users whose posts were removed or whose accounts were suspended. Furthermore, the Appeals Center overturned the platforms’ decisions in approximately three out of every four cases. However, a large portion (two-thirds) of those decisions were automatically ruled in favor of users because the platforms failed to provide the information necessary to reach a decision. Furthermore, there is no data on what percentage of these bodies’ decisions are being accepted by the platforms or under what criteria. Finally, it is worth clarifying that the DSA does not specify the grounds on which out-of-court dispute resolution bodies must base their decisions, so these bodies face significant coordination challenges ahead.

The DSA and (National) Courts

On October 2, 2025, a first-instance judge in Amsterdam issued a ruling in the lawsuit filed by Bits of Freedom, a Dutch civil society organization, against Meta for violating the DSA in connection with Facebook and Instagram’s recommendation systems. BoF argued that Meta makes it difficult for users to choose a non-profiled feed (e.g., chronological) and that, even when users select it, the platform automatically reverts to the profile-based system when navigating within the app or when closing and reopening it. The court upheld the complaint, finding that Meta does not provide a “direct and easily accessible” way for users to select a non-profiled recommendation system, and that it does not respect the persistence of that choice. It ordered Meta to ensure that the option to choose a non-profiled feed is easily accessible on the main pages and “Reels” sections of Facebook and Instagram, and that users do not have to reselect that option every time they log into the app or website. In another interesting case before national courts, the Berlin Court of Appeals ruled in favor of a user by holding that user notifications via certified mail count as valid notifications for the purpose of establishing that a platform had actual knowledge of the existence of illegal content. It rejected the defendant’s argument that, given the platforms’ obligation under Article 16 of the DSA to establish notification and action mechanisms for illegal content, those mechanisms are the only appropriate means of communicating the existence of such content.

What Are We Reading?

  • This report by the Oversight Board, which proposes ways to reconcile risk mitigation obligations under the DSA with international standards on freedom of expression—a report that cites CELE’s work on the subject and was presented at the CELE Annual Workshop in Buenos Aires.
  • This policy brief by Interface on the gap between the protections EU law provides to minors online and its inadequate implementation.
  • This blog post by Lorenzo Gradoni and Pietro Ortolani on the applicable law for out-of-court dispute resolution bodies under Article 21 of the DSA.
  • This report by Columbia World Projects and the Center for Digital Governance at the Hertie School on the structural limitations of access to data for research, with recommendations for overcoming them.
  • This proposal from the Knight-Georgetown Institute to expand access to public data for research on digital platforms.
  • This article by Daphne Keller on platform data access for researchers (and non-researchers) under the DSA. Thank you so much for reading this far—we’ll be in touch soon! See you next time!