FactsheetFinal

EDPB (Factsheet)

GDPR and DSA: how they interact (EDPB factsheet)

This document condenses the full document.

What it covers

This document is a short quick-reference summary illustrating five scenarios where GDPR and Digital Services Act obligations intersect, such as illegal content reporting, protection of minors from targeted ads, age verification, non-profiling recommender options, and sensitive-data-based advertising; the full guidelines carry the detailed legal analysis.

Why it matters

It offers a fast entry point for identifying where DSA obligations trigger GDPR personal data considerations before consulting the fuller interplay guidelines.

Refer to it when

  • quickly checking how a DSA obligation intersects with GDPR
  • orienting a team new to DSA-GDPR overlap issues
  • identifying scenarios needing further study in the full guidelines

Questions this document addresses

  • What personal data minimisation applies to illegal content notices?
  • How should platforms avoid showing targeted ads to minors without excessive data collection?
  • What age verification approaches are consistent with data minimisation?
  • What non-profiling options must VLOPs and VLOSEs offer?

Topics

  • Digital Services Act
  • Children's data
  • Marketing & targeting
  • Transparency

Official EDPB page for this document

Short EDPB factsheet on how hosting providers and online platforms should handle personal data when complying with the Digital Services Act, including anonymous notifications and data minimisation.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.