Who this is for: general counsels, founders and CEOs of Spanish SaaS platforms, marketplaces and app-store operators, compliance officers, and investors conducting pre-deal diligence.
What this covers: 2026 DSA obligations in Spain, per-platform practical steps, timelines, enforcement risk and mitigation, a compliance checklist and contract-drafting pointers.
Read time: approximately 12 minutes.
The digital services act spain landscape has shifted from paper obligation to active enforcement, and 2026 is the year Spanish platforms feel the pressure. Very Large Online Platforms and Very Large Online Search Engines have been designated across the EU, national supervisory activity is intensifying, and cross-border enforcement coordination is now routine. For SaaS providers, marketplaces and app stores operating in Spain, the practical question is no longer whether the DSA applies but how fast you can close the gaps. This guide takes a position: most Spanish platforms should move now, and this article tells you exactly which compliance track to choose and why.
Regulation (EU) 2022/2065, the Digital Services Act, is directly applicable across all Member States, including Spain (EUR-Lex, Reg. 2022/2065). That means you do not wait for national transposition of core duties, the obligations bite directly. What Spain adds is the enforcement machinery: a national Digital Services Coordinator, plus overlapping authorities such as the AEPD for data-protection dimensions and the CNMC for market conduct. If you run a platform touching Spanish users, the digital services act spain framework is your immediate compliance reality, not a future project.
The DSA governs intermediary services, hosting providers, online platforms, marketplaces and search engines, that connect users with content, goods or services. It scales obligations by role and size: light duties for pure conduits, heavier ones for hosting and online platforms, and the most demanding regime for VLOPs and VLOSEs exceeding 45 million average monthly active recipients in the EU (European Commission, DSA package). If your service hosts third-party content or facilitates third-party transactions reaching Spain, assume you are in scope until a lawyer confirms otherwise.
The DSA layers obligations. Every intermediary carries baseline duties; hosting services and online platforms carry more; marketplaces and app stores carry trader-facing duties; and designated VLOPs carry systemic-risk obligations. Understanding your layer is the first step to sensible DSA compliance Spain planning.
These duties apply broadly and are the fastest to implement:
Marketplaces and app stores that let third parties sell goods, services or software face trader-facing obligations. The centrepiece is “Know Your Business Customer” traceability under DSA Art. 30: before allowing a trader to operate, you must obtain and make best efforts to assess the reliability of identity, contact and registration details, and keep them available for lawful requests. You must also design your interface so traders can meet product-safety and consumer-information duties, and inform buyers when they become aware they have acquired an illegal product or service (DSA Art. 32). For content moderation Spain DSA purposes, marketplaces must act quickly on notices concerning illegal goods and services, not just illegal speech.
Pure B2B SaaS that only provides software tools to a customer, with no hosting of third-party user content and no facilitation of third-party transactions, often falls outside the “hosting” and “online platform” categories (DSA Art. 3 definitions). But the line is thin. The moment your SaaS stores user-generated content that other users can access, or lets your customers’ end users transact with third parties, you may cross into hosting or online-platform territory. SaaS platform DSA obligations therefore turn on an honest mapping of what your product actually does, not on how you market it.
The table below is the decision asset. It maps each obligation across the four platform archetypes so you can locate your service and see, at a glance, what applies. Where a cell references a DSA Article, treat it as the anchor for your own legal review.
| Dimension / Obligation | SaaS Platforms (hosting / B2B SaaS) | Online Marketplaces | App Stores | VLOP / VLOSE |
|---|---|---|---|---|
| Typical scope | In scope if hosting third-party content; many pure B2B SaaS fall outside “hosting” (Art. 3) | In scope as online platform allowing consumer–trader contracts (Art. 3, Art. 30) | In scope when distributing third-party apps and facilitating transactions (Art. 3, Art. 30) | Extra duties once designated by the Commission (>45M average monthly EU recipients) |
| Notice & action | Notice-and-action for illegal content; transparent and timely (Art. 16) | Same, plus illegal goods/services and buyer notification (Art. 16, Art. 32) | Same; reporting flows for malicious apps and swift removals (Art. 16) | Enhanced transparency and mitigation of systemic risks (Art. 34–35) |
| Traceability / KYBC | Generally not required unless facilitating trader transactions (Art. 30) | Must obtain and assess reliability of trader identity and details (Art. 30) | Must identify developers/publishers where they act as traders (Art. 30) | Traceability plus systemic-risk assessment (Art. 30, Art. 34) |
| Transparency reporting | Basic reporting; micro/small-enterprise exemptions may apply (Art. 15, Art. 19) | Periodic reports; clear terms for users and traders (Art. 15, Art. 24) | Same, plus transparency on ranking and in-app advertising (Art. 24, Art. 26) | Extensive public reports, independent audits, data access (Art. 37–42) |
| Risk assessment | Not required unless designated; advisable (Art. 34 if designated) | Systemic-risk duties apply only if designated as VLOP (Art. 34) | Systemic-risk duties apply only if designated as VLOP (Art. 34) | Mandatory annual systemic-risk assessment and mitigation (Art. 34–35) |
| Crisis response | Cooperate with authorities; act on orders (Art. 9–10) | Quicker action for public-safety risks; cooperate with authorities (Art. 9–10) | Extra diligence where apps threaten health or safety | Crisis response mechanism applicable to VLOPs/VLOSEs (Art. 36) |
| Record-keeping | Retain records relevant to notices and decisions (Art. 17) | Retain trader identity data; produce on request (Art. 30) | Developer identity plus relevant records (Art. 30) | Data access, external audits, detailed logging (Art. 40) |
| Independent audits | Not required unless designated VLOP (Art. 37) | Best practice; required only if designated VLOP (Art. 37) | Same as marketplaces (Art. 37) | Mandatory annual independent audit (Art. 37) |
| Penalties & risk in Spain | Subject to Spanish DSC; fines up to 6% of annual worldwide turnover for serious breaches | High, regularly targeted for illegal goods and consumer harm | High, consumer-facing software distribution attracts scrutiny | Maximum enforcement; potential service restrictions and Commission action |
| Initial steps | Map hosting role; update ToS; build notice channel; appoint contact points | Capture trader identity; strengthen takedown workflows and records | Verify developers; vet apps; publish clear listings; set takedown SLA | Full legal/technical audit; appoint compliance lead; prepare risk plans |
Three terms drive most disagreements. “Designation” means the European Commission has formally listed you as a VLOP or VLOSE, you are not a VLOP simply because you are large; designation triggers the extra regime (European Commission, DSA package). “Systemic risk” refers to the platform-wide harms designated VLOPs must assess and mitigate, from disinformation to illegal-goods proliferation. And “in scope” is a factual test about what your service does, decided under the Art. 3 definitions, not by your business label. Read your row top to bottom before choosing a compliance track.
A credible DSA compliance Spain programme is sequenced, not simultaneous. The following timeline is our recommended order of operations for platforms starting from a low base in 2026.
Move fast on the items that carry the highest legal exposure and lowest implementation cost:
With the urgent controls live, turn to the trader-facing and reporting obligations that require engineering and process change. For marketplaces and app stores, traceability is the priority: implement Know Your Business Customer collection and reliability checks at onboarding, capturing identity, contact and registration data, and store it so you can respond to lawful requests (DSA Art. 30). Integrate a structured takedown workflow that logs each notice, decision and timestamp, this is your evidence base if an authority asks how you handled a report.
In parallel, build your internal complaint-handling system so users can contest moderation decisions (DSA Art. 20), and begin drafting your first transparency report even if an exemption may apply, because the discipline of measuring moderation activity exposes gaps early. Run an initial, proportionate risk review: list the illegal-content and consumer-harm scenarios your platform enables, rate their likelihood and severity, and note the controls you have or lack. For SaaS platform DSA obligations, use this window to confirm your scope decision with counsel and, if you are in scope, retrofit the hosting-service duties you may have assumed did not apply.
Convert ad-hoc fixes into governance. Adopt a data-retention policy that specifies how long you keep trader records, notices and moderation logs, aligned with both DSA record-keeping needs and data-protection minimisation principles overseen by the AEPD. Automate moderation transparency by generating statements of reasons and complaint acknowledgements programmatically rather than by hand. Build a compliance calendar that schedules transparency reports, policy reviews and periodic risk reassessment. Assign a named owner, a DSA compliance lead, accountable for the programme, so obligations do not fall between legal, product and operations teams.
If you are approaching the 45-million-recipient threshold, prepare for possible designation before it arrives. Note that platforms meeting that threshold must publish their user numbers and are subject to Commission designation. Build an independent audit capability, document a systemic-risk assessment methodology, and prepare mitigation strategies. Continuous monitoring, of notice volumes, removal times and repeat-infringer patterns, is what distinguishes a defensible programme from a paper one when the digital services act spain enforcement machinery turns its attention to you.
The DSA is an EU regulation, but enforcement in Spain runs through national and EU channels working together. Knowing who can knock on your door, and why, is essential to prioritising your DSA compliance Spain spend.
Each Member State designates a Digital Services Coordinator (DSC) responsible for supervising intermediaries established in its territory and coordinating with the Commission and other DSCs. Spain has designated its national telecommunications and audiovisual regulator to perform the DSC role, working alongside other competent authorities. The DSC leads on most platform supervision, but it does not operate alone. The AEPD supervises data-protection dimensions where DSA obligations touch personal data, trader records, moderation logs, and user rights (AEPD). The CNMC is relevant where platform conduct raises market or competition concerns, and consumer authorities engage where product safety and consumer protection are at stake (CNMC). Expect these bodies to share information rather than work in silos.
Enforcement generally escalates: an information request or notice, an opportunity to respond, an investigation, and, where breaches are confirmed, corrective orders or fines. The DSA authorises penalties of up to 6% of a provider’s annual worldwide turnover for serious infringements, with periodic penalty payments to compel compliance (EUR-Lex, Reg. 2022/2065). For designated VLOPs and VLOSEs, the Commission exercises supervisory and enforcement powers directly. The practical lesson from EU-level DSA enforcement activity is that regulators reward documented, good-faith compliance and scrutinise platforms that cannot show their working. Your logs and reports are your defence.
The DSA does not displace Spanish law. Where a marketplace facilitates the sale of counterfeit goods, Spanish intellectual-property and criminal provisions may apply alongside DSA duties. Where consumers are deceived, Spanish consumer-protection law operates in parallel. The principle that hosting intermediaries can lose their liability exemption once they have actual knowledge of illegal activity or content and fail to act expeditiously, reflected in EU case law and now codified in the DSA (Art. 6), continues to inform how Spanish authorities view hosting responsibility. The DSA’s “notice-and-action” regime is, in effect, the modern operating manual for that principle.
Compliance is not only technical; it is contractual. Your terms with users, sellers and developers are where DSA obligations become enforceable rights and allocated risks.
Rewrite three documents. Your user-facing T&Cs must describe moderation policies, tools, complaint routes and redress options in plain language (DSA Art. 14). Your seller or developer agreement must impose the identity, verification and cooperation obligations that let you satisfy traceability under DSA Art. 30, including the trader’s duty to keep information current and to respond to your product-safety requirements. Your internal moderation policy should map each category of illegal content or goods to a defined response and timeline, so decisions are consistent and auditable.
Allocate risk clearly. A seller indemnity covering illegal-product claims, IP infringement and regulatory fines arising from that seller’s conduct is standard and generally enforceable in Spain, provided it is drafted with precision and does not attempt to exclude liability the platform cannot lawfully shed. Liability caps between businesses are generally enforceable under Spanish contract law, but caps that purport to limit statutory consumer rights or that offend good faith will not hold. A prudent structure combines a reasonable cap, carve-outs for wilful misconduct and IP infringement, and a seller indemnity that survives termination.
Three clauses do the heaviest lifting:
Use this as a rapid self-assessment. Any unchecked item is a gap to prioritise.
The engineering baseline is smaller than most teams fear. Prioritise these four:
The digital services act spain regime is enforceable now, and 2026 is the year Spanish platforms should stop deliberating and commit to a track. The comparison table and playbook above are designed to make that decision fast. Do not spread effort thinly across every possible obligation, identify your platform type, choose the matching track, and execute it in sequence. Documented, good-faith compliance is both your legal defence and your commercial advantage in a market where investors now check DSA readiness during diligence.
Use this decision framework to commit:
Whichever track fits, treat classification as the decision that governs all others and get it right first. For tailored DSA compliance in Spain, seek specialist technology counsel to audit your model, sequence your obligations and draft enforceable platform terms.
This article is general information and not legal advice. Contact qualified counsel for advice tailored to your platform.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.
posted 23 minutes ago
posted 42 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message