GuidelinesPublic consultation versionDigital Services ActAdopted 2025-09-11

EDPB 03/2025

Guidelines 3/2025 on the interplay between the DSA and the GDPR

Version adopted for public consultation on 11 September 2025. The EDPB may adopt a revised version after the consultation; check the official EDPB page before relying on it.

What it covers

These guidelines, adopted as a version for public consultation, clarify how specific provisions of the Digital Services Act relating to illegal content moderation, notice and action mechanisms, deceptive design, advertising transparency, recommender systems, protection of minors, risk assessment and codes of conduct interact with the GDPR. They also address cooperation between Digital Services Coordinators and data protection authorities.

Why it matters

It gives intermediary service providers and regulators a consistent framework for applying DSA obligations that involve personal data processing, reducing the risk of conflicting requirements between the two regimes.

Refer to it when

  • assessing the lawful basis for content moderation activities
  • designing notice-and-action or complaint-handling mechanisms
  • evaluating whether an interface feature is a deceptive design pattern under the DSA or GDPR
  • reviewing advertising transparency and profiling restrictions on online platforms
  • coordinating with a Digital Services Coordinator on a DSA/GDPR overlap issue

Questions this document addresses

  • When can Article 6(1)(c) or (f) GDPR justify measures to detect and remove illegal content?
  • What personal data safeguards apply to notice and action mechanisms under the DSA?
  • When is a deceptive design pattern covered by the GDPR rather than Article 25 DSA?
  • How does Article 26 DSA's advertising transparency and profiling prohibition relate to Articles 9 and 22 GDPR?
  • Can a recommender system's output amount to a decision under Article 22 GDPR?
  • How should data protection authorities and Digital Services Coordinators cooperate?

Topics

  • Digital Services Act
  • Deceptive design patterns
  • Children's data
  • Controller & processor
  • Supervisory authorities

Official EDPB page for this document

Explains how the Digital Services Act and the GDPR operate together, covering notice-and-action mechanisms, recommender systems, advertising, protection of minors, researcher data access and controller roles.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.