European Data Protection Board sets limits on profiling under the DSA

The European Data Protection Board’s guidelines of 17 September 2026 organise the relationship between the DSA and the GDPR wherever platform obligations require the processing of personal data. Their full text in our Judykatura database shows that compliance with DSA obligations does not relieve a controller of the need to demonstrate a legal basis or to comply with the principles of data minimisation, transparency and proportionality.

This article is available free of charge in full. Subscribe to our newsletter to receive new case notes and a discount code for your first subscription.

Loading

⚖️ Key theses (click to expand)

Teza 1 — Compatible application of DSA and GDPR

The DSA does not constitute lex specialis derogating from the general rules on the processing of personal data under the GDPR or from the rules of the ePrivacy Directive. Both Regulations must be applied compatibly, ensuring coherent application of EU law without lowering the level of protection of privacy and personal data.

Teza 2 — Voluntary moderation requires legal basis

Voluntary detection, identification and removal of illegal content may rely on the controller’s legitimate interests. However, the controller must demonstrate the necessity of the processing, the absence of equally effective and less intrusive means, and the balancing of that interest against the rights and freedoms of the data subjects.

Teza 3 — Automation does not remove responsibility

A decision to remove content may constitute a decision based solely on automated processing within the meaning of Article 22 GDPR where it significantly affects an individual. Token human involvement, or involvement without a genuine influence on the outcome, does not deprive the decision of its automated nature.

Teza 4 — Sensitive advertising remains prohibited

The prohibition on presenting advertisements based on profiling using special categories of data applies even where the processing entity could rely on a legal basis under Article 6(1) GDPR and a derogation under Article 9(2) GDPR. The DSA rules complement the prohibitions arising under the GDPR.

Teza 5 — Non-profiling choice must work

Providers of very large online platforms and very large online search engines should present recommender-system options equally and should not nudge users to select an option based on profiling. While the non-profiling option is active, the provider cannot continue to collect or process personal data to profile the user for future recommendations.

Teza 6 — Age assurance requires minimisation

Obligations to protect minors may constitute a legal basis for processing under Article 6(1)(c) GDPR only where the controller demonstrates necessity and proportionality. Online-platform providers should avoid age-assurance mechanisms enabling unambiguous online identification of users and should not permanently store age or age range on the basis of Article 28 DSA alone.

Teza 7 — Systemic risk supports impact assessment

Where an identified systemic risk concerns the protection of personal data, is not limited to individual users and is likely to result in a high risk to the rights and freedoms of natural persons, a data protection impact assessment is likely to be mandatory.

Teza 8 — Authority cooperation ensures consistency

Authorities enforcing the DSA and data protection authorities should consult and cooperate sincerely where they assess whether an intermediary service provider’s conduct complies with provisions supervised by the other authority. Such cooperation is intended to enhance legal certainty, prevent regulatory inconsistencies and reduce risks relating to ne bis in idem.

The central premise of the document is that the two regulatory frameworks are complementary. The European Data Protection Board stresses that the DSA does not displace the GDPR as lex specialis. The two Regulations must be applied compatibly, and that interpretation cannot result in lowering the protection afforded to privacy and personal data.

Does voluntary content moderation have a GDPR legal basis?

The DSA preserves liability exemptions for intermediary service providers that voluntarily, in good faith and diligently detect or remove illegal content. It does not, however, create an autonomous and general legal basis for the processing of personal data in the course of those activities.

The European Data Protection Board indicates that legitimate interests under Article 6(1)(f) GDPR may be an appropriate legal basis for voluntary detection of illegal content. That basis is not automatic. The provider, acting as controller, must demonstrate cumulatively that the interest pursued is legitimate, that the processing is necessary, and that the interests or rights and freedoms of the data subjects do not override it.

The guidelines also emphasise data minimisation. Processing must concern only data that are adequate, relevant and limited to what is necessary to detect, identify and address illegal content. Data obtained for that purpose should not subsequently be used for incompatible purposes, such as personalising content or advertisements.

When does moderation become an automated decision?

A particular risk arises in systems that automatically flag or remove content. The European Data Protection Board does not exclude that a decision to present particular content, or to remove it, may fall within the concept of a decision under Article 22(1) GDPR, especially where it may have serious consequences for the user.

This is particularly relevant where a content restriction may affect freedom of expression, a user’s reputation or the ability to use a service. Human involvement must be genuine and meaningful. If the person conducting review has neither the authority nor the actual ability to alter the outcome, or in practice merely follows the algorithmic recommendation, the decision may still be considered to be based solely on automated processing.

In such cases, the controller should assess whether an exception to the Article 22 GDPR prohibition applies, provide appropriate safeguards, and give the data subject information on the logic involved, the significance and the envisaged consequences of the processing.

Does advertising transparency legalise profiling?

No. The guidelines clearly distinguish the advertising-transparency obligation under Article 26 DSA from the legal basis for processing personal data used to determine which person should receive a particular advertisement.

The obligation to give a user information on the main parameters of an advertisement may provide a legal basis under Article 6(1)(c) GDPR for processing necessary to fulfil the transparency obligation. It is not, however, a legal basis for profiling used to select the recipient of a particular advertisement. A separate and appropriate legal basis under the GDPR remains necessary for that purpose.

The prohibition concerning advertisements based on profiling using special categories of data goes further still. The European Data Protection Board states that the prohibition under Article 26(3) DSA applies even where the platform or another entity could rely on a legal basis under Article 6(1) GDPR and a derogation under Article 9(2) GDPR. In this area, the DSA establishes an additional limit on the use of data.

What does a non-profiling recommender option mean?

For very large online platforms and very large online search engines, the guidelines require a recommender option not based on profiling to be presented on equal terms with the profiling-based option. It should not be hidden, made less accessible or presented in a manner that nudges users towards more extensive processing.

The practical consequence is crucial. Where a user uses the non-profiling option, the platform cannot continue to collect and process personal data in order to build a profile for future recommendations. This also applies where a user switches between options while using the service. Profiling should not take place during use of the option intended to be free from profiling.

How can minors be protected without excessive identification?

The European Data Protection Board accepts that obligations to protect minors under Article 28 DSA may provide a legal basis for processing under Article 6(1)(c) GDPR. The controller must nevertheless demonstrate that the processing is necessary and proportionate in the specific case.

The guidelines oppose treating age assurance as a justification for broad user identification. Providers should in particular avoid mechanisms resulting in unambiguous online identification, for example by requiring an identity document, solely on the basis of Article 28 DSA. Where an age range is sufficient, an exact date of birth should not be verified. After the process, it should generally be sufficient to record whether the user meets the condition for using the service, rather than permanently retaining their age or age range.

When does a DSA risk assessment require a DPIA?

For providers of very large online platforms and search engines, DSA duties to assess and mitigate systemic risks are closely connected with the GDPR. Where a systemic risk concerns the protection of personal data, extends beyond effects on individual users and is likely to result in a high risk to the rights and freedoms of natural persons, a data protection impact assessment is likely to be mandatory.

The guidelines indicate that implementing data minimisation, data protection by design and data protection by default can simultaneously contribute to mitigating the systemic risks required to be addressed under the DSA. This applies, among other matters, to recommender systems, content moderation systems and advertising systems.

What the guidelines mean for platforms

The document does not determine individual cases, but it sets out an assessment framework relevant to intermediary service providers, data protection authorities and authorities competent under the DSA.

First, an obligation under the DSA does not displace GDPR requirements concerning legal basis, necessity and proportionality. Second, the possibility of automated moderation does not remove the obligations associated with Article 22 GDPR. Third, a user’s choice of a non-profiling recommender system must have a real effect throughout use of the service. Fourth, protecting minors does not justify permanent collection of age-related data where the objective can be achieved by less intrusive means. Fifth, coherent application of the two Regulations requires sincere cooperation between DSA enforcement authorities and data protection authorities.


This material was prepared partly with the use of a general-purpose AI model and, despite due care, may contain errors. The information provided does not constitute legal advice — it reflects solely the Author's view.

The rest of this analysis, all theses and the full text of the ruling are available with an AKTUALNOŚCI PLUS subscription.

Find out how EU supervisory authorities, administrative and civil courts and the CJEU reason their decisions — and keep your organisation aligned with current case law.

Join — see pricing   Have an account? Log in

Wersja polska / Polish version