Source: OJ L 277, 27/10/2022, p. 1–102

Current language: EN

Article 35 Mitigation of risks


Summary What does Article 35 of the DSA regulation say?

This article directly follows from Article 34, which requires providers of very large online platforms and very large online search engines to identify and assess systemic risks.

Article 35 is the response mechanism: once those risks are identified, providers must act on them.

The article sets out an obligation to put in place mitigation measures that are reasonable, proportionate and effective, and it provides a broad, non-exhaustive list of the types of actions that may qualify.

These range from adjusting platform design and content moderation processes, to adapting algorithmic systems, advertising practices, and measures specifically protecting minors or addressing manipulated media.

The article also assigns a role to the Board and the Commission, who are to publish annual reports on systemic risks and best practices, and may issue guidelines to assist with implementation.

Important points:

  • Providers of very large online platforms and very large online search engines must put in place mitigation measures tailored to the systemic risks identified under Article 34, with particular consideration for the impact of those measures on fundamental rights.
  • The Board, in cooperation with the Commission, is required to publish comprehensive annual reports identifying prominent systemic risks and best practices for mitigating them, broken down by Member State.
  • The Commission, in cooperation with Digital Services Coordinators, may issue guidelines on applying these mitigation obligations in relation to specific risks, and must organise public consultations when doing so.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Providers of very large online platforms and of very large online search engines shall put in place reasonable, proportionate and effective mitigation measures, tailored to the specific systemic risks identified pursuant to Article 34, with particular consideration to the impacts of such measures on fundamental rights. Such measures may include, where applicable:

      1. adapting the design, features or functioning of their services, including their online interfaces;

      2. adapting their terms and conditions and their enforcement;

      3. adapting content moderation processes, including the speed and quality of processing notices related to specific types of illegal content and, where appropriate, the expeditious removal of, or the disabling of access to, the content notified, in particular in respect of illegal hate speech or cyber violence, as well as adapting any relevant decision-making processes and dedicated resources for content moderation;

      4. testing and adapting their algorithmic systems, including their recommender systems;

      5. adapting their advertising systems and adopting targeted measures aimed at limiting or adjusting the presentation of advertisements in association with the service they provide;

      6. reinforcing the internal processes, resources, testing, documentation, or supervision of any of their activities in particular as regards detection of systemic risk;

      7. initiating or adjusting cooperation with trusted flaggers in accordance with Article 22 and the implementation of the decisions of out-of-court dispute settlement bodies pursuant to Article 21;

      8. initiating or adjusting cooperation with other providers of online platforms or of online search engines through the codes of conduct and the crisis protocols referred to in Articles 45 and 48 respectively;

      9. taking awareness-raising measures and adapting their online interface in order to give recipients of the service more information;

      10. taking targeted measures to protect the rights of the child, including age verification and parental control tools, tools aimed at helping minors signal abuse or obtain support, as appropriate;

      11. ensuring that an item of information, whether it constitutes a generated or manipulated image, audio or video that appreciably resembles existing persons, objects, places or other entities or events and falsely appears to a person to be authentic or truthful is distinguishable through prominent markings when presented on their online interfaces, and, in addition, providing an easy to use functionality which enables recipients of the service to indicate such information.

    1. The Board, in cooperation with the Commission, shall publish comprehensive reports, once a year. The reports shall include the following:

      1. identification and assessment of the most prominent and recurrent systemic risks reported by providers of very large online platforms and of very large online search engines or identified through other information sources, in particular those provided in compliance with Articles 39, 40 and 42;

      2. best practices for providers of very large online platforms and of very large online search engines to mitigate the systemic risks identified.

    2. Those reports shall present systemic risks broken down by the Member States in which they occurred and in the Union as a whole, as applicable.

    1. The Commission, in cooperation with the Digital Services Coordinators, may issue guidelines on the application of paragraph 1 in relation to specific risks, in particular to present best practices and recommend possible measures, having due regard to the possible consequences of the measures on fundamental rights enshrined in the Charter of all parties involved. When preparing those guidelines the Commission shall organise public consultations.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod