The DSA is not only about big tech
The Digital Services Act has applied to all in-scope services since 17 February 2024. Most of the enforcement headlines concern very large online platforms, which is why smaller companies quietly assume the rules are not aimed at them. They are. If your business hosts content that users upload, runs a marketplace, or operates any service where users can share information with others, you have obligations – and they are supervised in Sweden by Post- och telestyrelsen, the national Digital Services Coordinator, together with Konsumentverket and Mediemyndigheten.
Which rules apply to you
All intermediary services
A single point of contact for authorities and for users, a legal representative if you are established outside the EU, and terms and conditions that explain any restrictions you impose on user content – written in clear, plain language.
Hosting services
A notice-and-action mechanism that lets anyone report illegal content easily and electronically, and a statement of reasons whenever you remove content, restrict visibility, suspend an account or demonetise a user.
Online platforms
On top of the above: an internal complaint-handling system, cooperation with out-of-court dispute settlement bodies, priority treatment for trusted flaggers, measures against misuse and manifestly unfounded notices, transparency about advertising and recommender systems, a ban on dark patterns, and a prohibition on advertising based on profiling using special-category data or targeted at minors.
Micro and small enterprises are exempt from most of the platform-specific obligations – but not from the hosting rules, and not from the transparency baseline. The exemption is narrower than most people assume, and it disappears as soon as you grow.
Online marketplaces
Article 30 requires trader traceability: before letting a trader sell, you must obtain their name, address, phone number and email, identification, payment account details and trade register entry where applicable, plus a self-certification that they will only offer compliant products. You must make best efforts to check that the information is reliable using freely accessible official databases. Know-your-business is now a legal duty, not a risk-management preference.
Practical example: a Swedish B2B marketplace
A marketplace connects industrial suppliers with buyers. It assumes the DSA is a consumer regime and that B2B sales fall outside it. That is wrong – the trader traceability obligations apply to online marketplaces allowing consumers to conclude distance contracts, and many B2B platforms serve at least some consumers or sole traders in practice.
The workable approach is to build the onboarding flow around Article 30 from the start: collect the required data, verify it against official registers, keep the records for the required period, and be able to show what you checked and when. Retrofitting verification onto thousands of existing sellers is painful; building it into onboarding is routine.
Common mistakes companies make
Assuming the DSA equals the very large platform rules. Risk assessments and audits apply to VLOPs. Notice-and-action, statements of reasons and traceability apply much more widely.
No statement of reasons. Removing a listing or suspending an account without a documented, communicated reason is one of the easiest breaches to prove.
Terms written for lawyers. The DSA requires plain language and, for services aimed at minors, an explanation they can understand.
Ignoring dark patterns. Interface design is now a compliance surface. Pre-ticked boxes, nagging consent loops and difficult cancellation flows are in scope.
Recommended actions
Classify your service – intermediary, hosting, platform or marketplace – and confirm whether the small-enterprise exemption really applies to you. Publish your point of contact and make it reachable. Build a notice-and-action channel that works and log every notice. Template your statements of reasons. If you are a marketplace, implement Article 30 verification in onboarding. Review your interface for dark patterns and your ad targeting for profiling that is now prohibited. And keep the records – the DSA is enforced on evidence, and fines can reach 6% of global annual turnover.
Frequently asked questions
Do we need a legal representative?
If you offer services in the EU but are not established in the EU, yes – and the representative must be designated and notified.
Does the DSA apply to closed B2B SaaS?
Pure private storage or processing on behalf of a business customer is usually outside the platform rules. The dividing line is whether information is disseminated to the public at the user’s request – assess it, and record the assessment.
Who enforces the DSA against a Swedish company?
Post- och telestyrelsen is Sweden’s Digital Services Coordinator, working alongside Konsumentverket and Mediemyndigheten as competent authorities. The Commission supervises very large platforms and search engines.
Conclusion
The DSA converts content moderation and seller onboarding from operational choices into documented legal processes. For most companies it is not a rewrite of the business – it is a set of mechanisms, notices and records that either exist or do not. The cheapest time to build them is before someone asks to see them.
Lawgent helps digital businesses turn the DSA, the AI Act, the GDPR and the Data Act into governance they can actually prove – policies, processes and terms that hold up under supervision. Book a free first hour and we will scope what applies to your service.