The 60-second summary
The EDPB has published final Guidelines 3/2025 on how the Digital Services Act and GDPR apply together when intermediary services process personal data. Adopted on 17 September 2026 after public consultation, Version 2.0 covers voluntary illegal-content detection, notice-and-action and complaint systems, deceptive design, advertising, recommender systems, minors, systemic-risk assessments and regulatory cooperation. The DSA does not displace the GDPR or ePrivacy rules. Platforms must identify a lawful basis, minimise data, provide timely transparency, respect non-profiling choices and assess high-risk processing. The guidance also says DSA prohibitions may be stricter than what the GDPR would otherwise permit.
Timeline that matters
11 September 2025
Consultation draft adopted
The EDPB adopted Version 1.0 for public consultation.
17 September 2026
Final Version 2.0 adopted
The EDPB adopted the final guidelines after considering consultation feedback.
21 September 2026
Final adoption announced
The EDPB announced adoption while linguistic publication checks were being completed.
22 September 2026
Final document published
The final publication page and Version 2.0 PDF became available.
23 December 2026
Next review
Check for implementation resources, regulator practice and related guidance.
What changed
Final Version 2.0 replaces the consultation draft and gives providers a consolidated interpretation of the GDPR across core DSA workflows. It confirms that DSA compliance does not itself remove GDPR duties, that voluntary content-detection tools require a separate GDPR analysis, that notice and complaint systems should minimise unnecessary personal data, that deceptive interfaces can breach both frameworks, and that DSA advertising restrictions may prohibit processing even where a GDPR legal basis and Article 9 exception might otherwise exist.
Who should pay attention?
Platform and product teams
Translate the final guidance into notice, complaint, advertising, recommender and minor-safety controls.
Privacy and legal teams
Map each DSA workflow to its GDPR role, purpose, legal basis, necessity and rights implications.
Trust and safety teams
Validate data minimisation, accuracy, human review and appeal safeguards in content-detection processes.
Advertising and AI teams
Review profiling, sensitive-data inferences, targeting logic and recommender-system choices.
Risk and assurance teams
Connect DSA systemic-risk assessments, DPIAs, vendor evidence and regulator-cooperation records.
What the guidance clarifies
- The DSA does not replace the GDPR
- Both frameworks apply coherently. The DSA is without prejudice to the GDPR and relevant ePrivacy rules.
- DSA duties are not a blanket GDPR legal basis
- Providers must assess the legal basis, necessity, proportionality, transparency and other GDPR requirements for each processing activity.
- Voluntary content detection needs its own safeguards
- Automated and human monitoring may create accuracy, fairness and rights risks and must be limited to necessary personal data.
- Advertising restrictions can be stricter
- The DSA prohibition on profiling with special-category data applies even where a provider might otherwise identify a GDPR legal basis and Article 9 derogation.
- Non-profiling choices must be genuine
- Recommender options should be presented equally, must not nudge users toward profiling, and profiling should stop while the non-profiling option is active.
- Age assurance should minimise identification
- Providers should avoid mechanisms that unambiguously identify users and should not permanently retain age or age-range results solely on the basis of Article 28 DSA.
- Systemic-risk work can trigger a DPIA
- For VLOPs and VLOSEs, identified risks and large-scale or sensitive processing may make a GDPR impact assessment necessary.
Platform governance must connect safety duties with privacy controls
Why this matters for global organisations
Services, advertisers, vendors and business customers increasingly depend on platform decisions about moderation, profiling, recommendations and age assurance. Organisations need traceable data flows, genuine user choices, minimised processing, documented legal analysis and evidence that automated controls are accurate and reviewable.
- Treat safety, moderation and privacy as one governed product workflow.
- Stop unnecessary profiling when a non-profiling option is selected.
- Minimise identity data used for age assurance and complaint handling.
- Link systemic-risk assessments, DPIAs, testing and retained evidence.
15 actions to start now
- Map every DSA-related workflow that processes personal data, including moderation, notices, complaints, advertising, recommendations, age assurance and systemic-risk controls.
- Record controller, joint-controller and processor roles for each workflow and supplier.
- Document purpose, legal basis, necessity and proportionality separately for each processing activity.
- Review illegal-content detection models for minimisation, accuracy, bias, error rates and human review.
- Reduce personal data collected through notice-and-action and complaint mechanisms to what is necessary.
- Prevent complaint and misuse controls from becoming disproportionate monitoring systems.
- Test interfaces for nudging, obstruction and other deceptive design patterns.
- Audit advertising systems for profiling based on special-category data or sensitive inferences.
- Ensure advertising transparency information is provided at the correct time and protected against misuse.
- Present profiling and non-profiling recommender options equally and honour the selected option operationally.
- Stop collecting or using data for profiling while a non-profiling recommender option is active unless another justified purpose applies.
- Review age-assurance methods for data minimisation, unlinkability, limited retention and avoidance of unnecessary identification.
- Connect DSA systemic-risk assessments with DPIA screening and data-protection-by-design reviews.
- Add privacy requirements and audit evidence to platform, adtech, moderation and age-assurance vendor contracts.
- Define cooperation and escalation routes for data-protection authorities, Digital Services Coordinators and other competent bodies.
Suggested next steps
- Run a cross-functional review of one live platform journey—from sign-up and age assurance through recommendations, advertising, moderation and complaints—and document every personal-data decision, control, owner and retained evidence.
Evidence worth retaining
- DSA-to-GDPR processing inventory and data-flow maps.
- Controller, processor and joint-controller role assessments.
- Purpose, legal-basis, necessity and proportionality records.
- Moderation-model design, training-data, validation and error-rate evidence.
- Human-review, appeal and complaint-handling records.
- Notice-and-action data fields and retention schedules.
- Interface and dark-pattern test results.
- Advertising taxonomy, targeting rules and sensitive-inference controls.
- Recommender-system configurations and user-choice logs.
- Evidence that profiling stops when the non-profiling option is active.
- Age-assurance design, minimisation, deletion and unlinkability evidence.
- DPIAs and DSA systemic-risk assessments with linked actions.
- Vendor contracts, instructions, subprocessors and assurance reports.
- Security controls for transparency and advertising repositories.
- Regulator correspondence, consultation records and governance approvals.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which DSA workflows process personal data, and for whose purposes?
- Does each activity have a documented GDPR legal basis beyond a generic claim of DSA compliance?
- Are automated moderation decisions sufficiently accurate, explainable and reviewable?
- Do notice and complaint forms collect more data than necessary?
- Could interface design steer users toward profiling or discourage rights exercise?
- Does advertising use sensitive data or inferred special-category characteristics?
- Does the non-profiling recommender option genuinely stop profiling activity?
- Can age assurance work without persistent identification or retention of age evidence?
- Should the systemic-risk assessment trigger or update a DPIA?
- Which vendors can evidence compliance across moderation, adtech, recommendation and age assurance?
- Are authority-cooperation responsibilities clear when two regulatory frameworks apply?
Official sources
- EDPB — Guidelines 3/2025 final publication page
- EDPB — Guidelines 3/2025 Version 2.0 PDF
- EDPB — adoption announcement, 21 September 2026
- EUR-Lex — Digital Services Act
- EUR-Lex — General Data Protection Regulation
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.