Alessandro Del Ninno
News
EDPB: Guidelines 3/2025 on the interplay between DSA and GDPR definitively adopted.
DATA PROTECTION
20/09/2026

The EDPB adopted the final version of the Guidelines 3/2025 on the interplay between the Digital Services Act and the GDPR, clarifying how the two Regulations must be coordinated where compliance with obligations under the Digital Services Act (DSA) entails the processing of personal data.

The underlying principle is particularly relevant for businesses: the DSA does not replace the GDPR and does not, in itself, constitute a general legal basis for the processing of personal data. Any processing carried out in the context of DSA compliance must therefore be assessed independently under the GDPR, including by identifying the applicable legal basis and verifying necessity, proportionality, data minimisation, transparency, data protection by design, the potential applicability of Article 22 on automated decision-making, and the need to conduct a DPIA.

The Guidelines focus in particular on a number of areas with significant operational implications.

With regard to content moderation, the EDPB distinguishes between voluntary activities and processing that is necessary to comply with specific legal obligations. Voluntary activities aimed at detecting illegal content may, where the relevant conditions are met, be based on legitimate interests; where, by contrast, the processing is required by a specific legal obligation, Article 6(1)(c) GDPR may apply. The EDPB nevertheless makes clear that the DSA cannot justify generalised monitoring or profiling of users. Where automated content moderation results in the removal of content or the suspension of accounts, the potential applicability of Article 22 GDPR must also be assessed, and any human intervention must be genuine and effective rather than merely formal.

In relation to online advertising, the EDPB clarifies that the transparency obligations laid down by the DSA are additional to, and do not replace, those arising under the GDPR. The DSA obligation to inform users about the parameters used for advertising does not provide an autonomous legal basis for targeting. Of particular importance is also the prohibition on using special categories of personal data, including such data inferred through profiling, for advertising based on profiling: the prohibition applies even where the processing might, in principle, be permitted under Article 9 GDPR.

As regards recommender systems, the EDPB stresses that, where the DSA requires the availability of an option that is not based on profiling, that choice must also be effective from a technical perspective. Merely displaying a different feed is not sufficient: where the user selects the non-profiled option, the provider should not continue to collect or use personal data in order to profile that user for future recommendations. In certain circumstances, moreover, an automated recommendation may amount to a decision falling within the scope of Article 22 GDPR, for example in services that recommend job vacancies or real-estate opportunities.

The Guidelines also devote particular attention to dark patterns, clarifying that, where manipulative design affects choices concerning the processing of personal data, the GDPR principle of fairness becomes directly applicable. Interfaces that induce users to provide more data, accept less privacy-protective options or engage in compulsive behaviours may therefore be relevant simultaneously under both the DSA and the GDPR.

Further guidance concerns the protection of minors. The EDPB acknowledges that DSA obligations may justify age-assurance processing, but emphasises the need for proportionate and privacy-preserving solutions. Platforms should avoid the generalised collection of identity documents or the use of other mechanisms resulting in the unique identification of users where this is not strictly necessary and, where possible, should limit themselves to verifying whether or not the relevant age threshold has been met.

For businesses, the operational message is clear: DSA and GDPR compliance can no longer be managed through separate compliance programmes. Content moderation, advertising, recommender systems, complaint handling, the protection of minors and systemic risk assessments must be analysed jointly, by linking each DSA obligation to the data-processing activities required to implement it and verifying their compliance with the GDPR.

Businesses should therefore consider putting in place an integrated DSA-GDPR compliance matrix, capable of mapping, for each process, the purposes of processing, legal basis, categories of data, retention periods, any automated decision-making, security measures and the need for a DPIA. It is precisely this integration between the digital-law obligation and the underlying processing activity that the EDPB now places at the centre of compliance.