[codicts-css-switcher id=”346″]

Global Law Experts Logo
digital services act spain

Our Expert in Spain

What Spain's Online Platforms Must Do Under the DSA (2026): Saas, Marketplaces & App Stores

By Global Law Experts
– posted 1 hour ago

Who this is for: general counsels, founders and CEOs of Spanish SaaS platforms, marketplaces and app-store operators, compliance officers, and investors conducting pre-deal diligence.

What this covers: 2026 DSA obligations in Spain, per-platform practical steps, timelines, enforcement risk and mitigation, a compliance checklist and contract-drafting pointers.

Read time: approximately 12 minutes.

Digital Services Act Spain: Why 2026 Is the Year to Act

The digital services act spain landscape has shifted from paper obligation to active enforcement, and 2026 is the year Spanish platforms feel the pressure. Very Large Online Platforms and Very Large Online Search Engines have been designated across the EU, national supervisory activity is intensifying, and cross-border enforcement coordination is now routine. For SaaS providers, marketplaces and app stores operating in Spain, the practical question is no longer whether the DSA applies but how fast you can close the gaps. This guide takes a position: most Spanish platforms should move now, and this article tells you exactly which compliance track to choose and why.

Regulation (EU) 2022/2065, the Digital Services Act, is directly applicable across all Member States, including Spain (EUR-Lex, Reg. 2022/2065). That means you do not wait for national transposition of core duties, the obligations bite directly. What Spain adds is the enforcement machinery: a national Digital Services Coordinator, plus overlapping authorities such as the AEPD for data-protection dimensions and the CNMC for market conduct. If you run a platform touching Spanish users, the digital services act spain framework is your immediate compliance reality, not a future project.

Quick summary of the DSA’s purpose and who it applies to

The DSA governs intermediary services, hosting providers, online platforms, marketplaces and search engines, that connect users with content, goods or services. It scales obligations by role and size: light duties for pure conduits, heavier ones for hosting and online platforms, and the most demanding regime for VLOPs and VLOSEs exceeding 45 million average monthly active recipients in the EU (European Commission, DSA package). If your service hosts third-party content or facilitates third-party transactions reaching Spain, assume you are in scope until a lawyer confirms otherwise.

What the DSA Requires: High-Level Obligations by Platform Type

The DSA layers obligations. Every intermediary carries baseline duties; hosting services and online platforms carry more; marketplaces and app stores carry trader-facing duties; and designated VLOPs carry systemic-risk obligations. Understanding your layer is the first step to sensible DSA compliance Spain planning.

Core duties for all intermediary services

These duties apply broadly and are the fastest to implement:

  • Notice-and-action mechanisms. You must let users flag illegal content and process those notices in a transparent, diligent and timely way (DSA Art. 16).
  • Content moderation transparency. Decisions to remove or restrict content require a clear statement of reasons to the affected user (DSA Art. 17).
  • Clear terms and conditions. Your T&Cs must explain content moderation policies, tools and complaint routes in plain language (DSA Art. 14).
  • Points of contact. You must designate a single electronic point of contact for authorities (DSA Art. 11) and one for recipients of the service (DSA Art. 12).
  • Transparency reporting. Providers of intermediary services publish periodic reports on moderation activity, with exemptions for micro and small enterprises (DSA Art. 15; additional platform reporting under Art. 24).

Additional duties for online marketplaces Spain DSA compliance

Marketplaces and app stores that let third parties sell goods, services or software face trader-facing obligations. The centrepiece is “Know Your Business Customer” traceability under DSA Art. 30: before allowing a trader to operate, you must obtain and make best efforts to assess the reliability of identity, contact and registration details, and keep them available for lawful requests. You must also design your interface so traders can meet product-safety and consumer-information duties, and inform buyers when they become aware they have acquired an illegal product or service (DSA Art. 32). For content moderation Spain DSA purposes, marketplaces must act quickly on notices concerning illegal goods and services, not just illegal speech.

SaaS platform DSA obligations: where it applies and where it likely does not

Pure B2B SaaS that only provides software tools to a customer, with no hosting of third-party user content and no facilitation of third-party transactions, often falls outside the “hosting” and “online platform” categories (DSA Art. 3 definitions). But the line is thin. The moment your SaaS stores user-generated content that other users can access, or lets your customers’ end users transact with third parties, you may cross into hosting or online-platform territory. SaaS platform DSA obligations therefore turn on an honest mapping of what your product actually does, not on how you market it.

Digital Services Act Spain: Side-by-Side Obligations Comparison

The table below is the decision asset. It maps each obligation across the four platform archetypes so you can locate your service and see, at a glance, what applies. Where a cell references a DSA Article, treat it as the anchor for your own legal review.

DSA obligations compared across SaaS platforms, marketplaces, app stores and VLOPs in Spain (2026)
Dimension / Obligation SaaS Platforms (hosting / B2B SaaS) Online Marketplaces App Stores VLOP / VLOSE
Typical scope In scope if hosting third-party content; many pure B2B SaaS fall outside “hosting” (Art. 3) In scope as online platform allowing consumer–trader contracts (Art. 3, Art. 30) In scope when distributing third-party apps and facilitating transactions (Art. 3, Art. 30) Extra duties once designated by the Commission (>45M average monthly EU recipients)
Notice & action Notice-and-action for illegal content; transparent and timely (Art. 16) Same, plus illegal goods/services and buyer notification (Art. 16, Art. 32) Same; reporting flows for malicious apps and swift removals (Art. 16) Enhanced transparency and mitigation of systemic risks (Art. 34–35)
Traceability / KYBC Generally not required unless facilitating trader transactions (Art. 30) Must obtain and assess reliability of trader identity and details (Art. 30) Must identify developers/publishers where they act as traders (Art. 30) Traceability plus systemic-risk assessment (Art. 30, Art. 34)
Transparency reporting Basic reporting; micro/small-enterprise exemptions may apply (Art. 15, Art. 19) Periodic reports; clear terms for users and traders (Art. 15, Art. 24) Same, plus transparency on ranking and in-app advertising (Art. 24, Art. 26) Extensive public reports, independent audits, data access (Art. 37–42)
Risk assessment Not required unless designated; advisable (Art. 34 if designated) Systemic-risk duties apply only if designated as VLOP (Art. 34) Systemic-risk duties apply only if designated as VLOP (Art. 34) Mandatory annual systemic-risk assessment and mitigation (Art. 34–35)
Crisis response Cooperate with authorities; act on orders (Art. 9–10) Quicker action for public-safety risks; cooperate with authorities (Art. 9–10) Extra diligence where apps threaten health or safety Crisis response mechanism applicable to VLOPs/VLOSEs (Art. 36)
Record-keeping Retain records relevant to notices and decisions (Art. 17) Retain trader identity data; produce on request (Art. 30) Developer identity plus relevant records (Art. 30) Data access, external audits, detailed logging (Art. 40)
Independent audits Not required unless designated VLOP (Art. 37) Best practice; required only if designated VLOP (Art. 37) Same as marketplaces (Art. 37) Mandatory annual independent audit (Art. 37)
Penalties & risk in Spain Subject to Spanish DSC; fines up to 6% of annual worldwide turnover for serious breaches High, regularly targeted for illegal goods and consumer harm High, consumer-facing software distribution attracts scrutiny Maximum enforcement; potential service restrictions and Commission action
Initial steps Map hosting role; update ToS; build notice channel; appoint contact points Capture trader identity; strengthen takedown workflows and records Verify developers; vet apps; publish clear listings; set takedown SLA Full legal/technical audit; appoint compliance lead; prepare risk plans

How to read the table

Three terms drive most disagreements. “Designation” means the European Commission has formally listed you as a VLOP or VLOSE, you are not a VLOP simply because you are large; designation triggers the extra regime (European Commission, DSA package). “Systemic risk” refers to the platform-wide harms designated VLOPs must assess and mitigate, from disinformation to illegal-goods proliferation. And “in scope” is a factual test about what your service does, decided under the Art. 3 definitions, not by your business label. Read your row top to bottom before choosing a compliance track.

Digital Services Act Spain: The Step-by-Step Compliance Playbook

A credible DSA compliance Spain programme is sequenced, not simultaneous. The following timeline is our recommended order of operations for platforms starting from a low base in 2026.

First 30 days, urgent actions

Move fast on the items that carry the highest legal exposure and lowest implementation cost:

  1. Map your service model. Decide, in writing, whether you are a hosting service, an online platform, a marketplace, an app store, or out of scope. This single decision determines everything else.
  2. Appoint points of contact. Designate an electronic point of contact for authorities (DSA Art. 11) and one for recipients of the service (DSA Art. 12), and publish both.
  3. Stand up a notice-and-action inbox. Provide an accessible mechanism for reporting illegal content, goods or services (DSA Art. 16).
  4. Publish compliant terms. Update your T&Cs to describe moderation policies, tools and complaint routes in plain language (DSA Art. 14).
  5. Set a statement-of-reasons template. Prepare the notice you send when you remove or restrict content (DSA Art. 17).

30–90 days, medium-term fixes

With the urgent controls live, turn to the trader-facing and reporting obligations that require engineering and process change. For marketplaces and app stores, traceability is the priority: implement Know Your Business Customer collection and reliability checks at onboarding, capturing identity, contact and registration data, and store it so you can respond to lawful requests (DSA Art. 30). Integrate a structured takedown workflow that logs each notice, decision and timestamp, this is your evidence base if an authority asks how you handled a report.

In parallel, build your internal complaint-handling system so users can contest moderation decisions (DSA Art. 20), and begin drafting your first transparency report even if an exemption may apply, because the discipline of measuring moderation activity exposes gaps early. Run an initial, proportionate risk review: list the illegal-content and consumer-harm scenarios your platform enables, rate their likelihood and severity, and note the controls you have or lack. For SaaS platform DSA obligations, use this window to confirm your scope decision with counsel and, if you are in scope, retrofit the hosting-service duties you may have assumed did not apply.

3–6 months, governance and technical controls

Convert ad-hoc fixes into governance. Adopt a data-retention policy that specifies how long you keep trader records, notices and moderation logs, aligned with both DSA record-keeping needs and data-protection minimisation principles overseen by the AEPD. Automate moderation transparency by generating statements of reasons and complaint acknowledgements programmatically rather than by hand. Build a compliance calendar that schedules transparency reports, policy reviews and periodic risk reassessment. Assign a named owner, a DSA compliance lead, accountable for the programme, so obligations do not fall between legal, product and operations teams.

Ongoing, VLOP readiness and audits

If you are approaching the 45-million-recipient threshold, prepare for possible designation before it arrives. Note that platforms meeting that threshold must publish their user numbers and are subject to Commission designation. Build an independent audit capability, document a systemic-risk assessment methodology, and prepare mitigation strategies. Continuous monitoring, of notice volumes, removal times and repeat-infringer patterns, is what distinguishes a defensible programme from a paper one when the digital services act spain enforcement machinery turns its attention to you.

Spanish Enforcement and How National Law Interacts

The DSA is an EU regulation, but enforcement in Spain runs through national and EU channels working together. Knowing who can knock on your door, and why, is essential to prioritising your DSA compliance Spain spend.

Spain’s Digital Services Coordinator and the enforcement landscape

Each Member State designates a Digital Services Coordinator (DSC) responsible for supervising intermediaries established in its territory and coordinating with the Commission and other DSCs. Spain has designated its national telecommunications and audiovisual regulator to perform the DSC role, working alongside other competent authorities. The DSC leads on most platform supervision, but it does not operate alone. The AEPD supervises data-protection dimensions where DSA obligations touch personal data, trader records, moderation logs, and user rights (AEPD). The CNMC is relevant where platform conduct raises market or competition concerns, and consumer authorities engage where product safety and consumer protection are at stake (CNMC). Expect these bodies to share information rather than work in silos.

Typical enforcement steps and fines

Enforcement generally escalates: an information request or notice, an opportunity to respond, an investigation, and, where breaches are confirmed, corrective orders or fines. The DSA authorises penalties of up to 6% of a provider’s annual worldwide turnover for serious infringements, with periodic penalty payments to compel compliance (EUR-Lex, Reg. 2022/2065). For designated VLOPs and VLOSEs, the Commission exercises supervisory and enforcement powers directly. The practical lesson from EU-level DSA enforcement activity is that regulators reward documented, good-faith compliance and scrutinise platforms that cannot show their working. Your logs and reports are your defence.

Interaction with Spanish criminal and consumer law

The DSA does not displace Spanish law. Where a marketplace facilitates the sale of counterfeit goods, Spanish intellectual-property and criminal provisions may apply alongside DSA duties. Where consumers are deceived, Spanish consumer-protection law operates in parallel. The principle that hosting intermediaries can lose their liability exemption once they have actual knowledge of illegal activity or content and fail to act expeditiously, reflected in EU case law and now codified in the DSA (Art. 6), continues to inform how Spanish authorities view hosting responsibility. The DSA’s “notice-and-action” regime is, in effect, the modern operating manual for that principle.

Contracts, Terms and Marketplace Agreements

Compliance is not only technical; it is contractual. Your terms with users, sellers and developers are where DSA obligations become enforceable rights and allocated risks.

What to change in your ToS and trader agreements

Rewrite three documents. Your user-facing T&Cs must describe moderation policies, tools, complaint routes and redress options in plain language (DSA Art. 14). Your seller or developer agreement must impose the identity, verification and cooperation obligations that let you satisfy traceability under DSA Art. 30, including the trader’s duty to keep information current and to respond to your product-safety requirements. Your internal moderation policy should map each category of illegal content or goods to a defined response and timeline, so decisions are consistent and auditable.

Indemnities, liability caps and enforceability in Spain

Allocate risk clearly. A seller indemnity covering illegal-product claims, IP infringement and regulatory fines arising from that seller’s conduct is standard and generally enforceable in Spain, provided it is drafted with precision and does not attempt to exclude liability the platform cannot lawfully shed. Liability caps between businesses are generally enforceable under Spanish contract law, but caps that purport to limit statutory consumer rights or that offend good faith will not hold. A prudent structure combines a reasonable cap, carve-outs for wilful misconduct and IP infringement, and a seller indemnity that survives termination.

Practical clause pointers

Three clauses do the heaviest lifting:

  • Seller identity and verification. Oblige the trader to provide and maintain accurate identity, contact and registration data, and to permit verification as a condition of continued access (DSA Art. 30).
  • Data-sharing for lawful requests. Reserve your right to disclose trader and transaction data to competent authorities in response to lawful orders, and require the trader to cooperate.
  • Cooperation on takedowns. Grant yourself the right to remove listings or content on notice, suspend repeat infringers, and require the trader to remedy issues within defined timelines.

Templates, Checklist and Quick Technical Controls

A 20-point DSA compliance checklist for Spain

Use this as a rapid self-assessment. Any unchecked item is a gap to prioritise.

  1. Service-model classification documented and dated.
  2. Electronic point of contact for authorities published (Art. 11).
  3. Point of contact for recipients published (Art. 12).
  4. EU legal representative appointed if established outside the EU (Art. 13).
  5. T&Cs updated with moderation and complaint information (Art. 14).
  6. Notice-and-action mechanism live and accessible (Art. 16).
  7. Statement-of-reasons template in use (Art. 17).
  8. Internal complaint-handling system operational (Art. 20).
  9. Out-of-court dispute settlement information provided (Art. 21).
  10. Trusted-flagger handling process defined (Art. 22).
  11. Repeat-infringer suspension policy documented (Art. 23).
  12. Transparency reporting process established (Art. 15, Art. 24).
  13. Trader identity collection and reliability checks live (Art. 30).
  14. Trader data retained and retrievable for lawful requests.
  15. Buyer-notification process for illegal products (Art. 32).
  16. Advertising transparency controls in place (Art. 26).
  17. Recommender-system parameters disclosed where required (Art. 27).
  18. Systemic-risk assessment addressed only if designated as VLOP (Art. 34).
  19. Data-retention policy aligned with AEPD principles.
  20. Named DSA compliance owner and compliance calendar in place.

Minimal technical controls

The engineering baseline is smaller than most teams fear. Prioritise these four:

  • Structured logging. Every notice, moderation decision and takedown should be logged with timestamp, actor and rationale, this is your evidentiary spine.
  • A takedown engine. A workflow that receives notices, routes them, records decisions and issues statements of reasons automatically.
  • Notice metadata. Capture the elements the DSA requires in a notice, the location of the content, the reason it is considered illegal, and the notifier’s details where relevant, so submissions are actionable and auditable (Art. 16).
  • An authority-response capability. A defined, tested process (ideally an internal API or standard export) to produce trader and transaction data on lawful request without scrambling.

Conclusion: Choose Your Digital Services Act Spain Compliance Track

The digital services act spain regime is enforceable now, and 2026 is the year Spanish platforms should stop deliberating and commit to a track. The comparison table and playbook above are designed to make that decision fast. Do not spread effort thinly across every possible obligation, identify your platform type, choose the matching track, and execute it in sequence. Documented, good-faith compliance is both your legal defence and your commercial advantage in a market where investors now check DSA readiness during diligence.

Use this decision framework to commit:

  • Choose lean internal compliance if you are a B2B SaaS provider that does not host significant third-party content or facilitate third-party transactions and has a low EU user base. Implement notice-and-action, update your T&Cs and appoint contact points within 90 days.
  • Choose a proactive marketplace or app-store programme if you handle third-party traders or developers or facilitate consumer transactions in Spain. Prioritise trader verification, traceability, automated takedown workflows and consumer-protection alignment now.
  • Choose VLOP readiness and independent audit if you meet or approach the 45-million-recipient threshold or have systemic impact. Commission a legal and technical audit, prepare risk assessments, and appoint a senior compliance lead immediately.

Whichever track fits, treat classification as the decision that governs all others and get it right first. For tailored DSA compliance in Spain, seek specialist technology counsel to audit your model, sequence your obligations and draft enforceable platform terms.

This article is general information and not legal advice. Contact qualified counsel for advice tailored to your platform.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2022/2065 (Digital Services Act), EUR-Lex
  2. European Commission, Digital Services Act (DSA) package
  3. Agencia Española de Protección de Datos (AEPD)
  4. Comisión Nacional de los Mercados y la Competencia (CNMC)
  5. Court of Justice of the European Union, case-law database (Curia)
  6. European Data Protection Board (EDPB)

FAQs

What is the Digital Services Act and does the digital services act spain regime apply to my SaaS?
The DSA is Regulation (EU) 2022/2065, governing intermediary services. It applies to your Spanish SaaS if you host third-party content or facilitate third-party transactions reaching EU users. Pure B2B tools with no user content often fall outside “hosting” under Art. 3, but the classification is fact-specific, so map your service before concluding.
Yes. Under DSA Art. 30, online platforms allowing consumers to conclude contracts with traders must obtain trader identity, contact and registration details, make best efforts to assess their reliability before allowing them to operate, and make that data available to authorities on lawful request. Build this into onboarding rather than retrofitting it later.
Designated VLOPs must conduct annual systemic-risk assessments, implement mitigation measures, undergo independent audits, provide data access to regulators and vetted researchers, and publish detailed transparency reports (DSA Art. 34–42). These duties apply from designation by the Commission, not merely from crossing the 45-million-recipient threshold.
Serious infringements can attract fines of up to 6% of annual worldwide turnover, with additional periodic penalty payments to force compliance (Reg. 2022/2065). Spanish enforcement, coordinated through the national Digital Services Coordinator and supported by the AEPD and CNMC, favours platforms that can evidence good-faith compliance.
Not literally every app, but app stores acting as online platforms must, where developers act as traders, obtain and assess developer identity information, operate notice-and-action for illegal apps, and take proportionate measures against malicious or deceptive listings (DSA Art. 16, Art. 30). The standard is risk-based diligence and swift response, not a guarantee of perfection.
Spain’s Digital Services Coordinator leads supervision, working with the AEPD on data issues and the CNMC on market conduct. Platforms interact with authorities through their designated electronic point of contact, and authorities issue information requests and orders through the same channels. Keep that contact point monitored and responsive.
There is no single “best” lawyer; the right adviser is one with genuine EU digital-regulation and platform-contract experience relevant to your model. Prioritise counsel who can classify your service, build a compliance timeline, and draft enforceable trader agreements. You can find suitably qualified technology lawyers through the Global Law Experts directory.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

What Spain's Online Platforms Must Do Under the DSA (2026): Saas, Marketplaces & App Stores

Send welcome message

Custom Message