EDPB (Factsheet)
GDPR and DSA: how they interact (EDPB factsheet)
This document condenses the full document.
What it covers
This document is a short quick-reference summary illustrating five scenarios where GDPR and Digital Services Act obligations intersect, such as illegal content reporting, protection of minors from targeted ads, age verification, non-profiling recommender options, and sensitive-data-based advertising; the full guidelines carry the detailed legal analysis.
Why it matters
It offers a fast entry point for identifying where DSA obligations trigger GDPR personal data considerations before consulting the fuller interplay guidelines.
Refer to it when
- quickly checking how a DSA obligation intersects with GDPR
- orienting a team new to DSA-GDPR overlap issues
- identifying scenarios needing further study in the full guidelines
Questions this document addresses
- What personal data minimisation applies to illegal content notices?
- How should platforms avoid showing targeted ads to minors without excessive data collection?
- What age verification approaches are consistent with data minimisation?
- What non-profiling options must VLOPs and VLOSEs offer?
Topics
- Digital Services Act
- Children's data
- Marketing & targeting
- Transparency
Short EDPB factsheet on how hosting providers and online platforms should handle personal data when complying with the Digital Services Act, including anonymous notifications and data minimisation.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.