Three fines in 8 months, each one bigger than the last. Digital Services Act (DSA) enforcement has moved from feeling theoretical to real, and your brand could be at risk if you make the wrong decisions.

The European Commission has fined three major platforms a combined €870 million: 

  • X (formerly Twitter) was fined €120M in December 2025 for deceptive account-verification design and blocking researcher access to platform data. 
  • Temu followed in May 2026 with a €200M fine for a risk assessment that badly underestimated how often EU shoppers encountered illegal products. 
  • And in July, AliExpress received a €550M fine for weak enforcement against repeat-offending sellers and listings that slipped through compliance checks via misdeclared product categories.

The biggest twist? These fines have been deliberately lenient. The Commission itself said that it went easier because the DSA is still new ("the novelty of the DSA"). Future fines will be even bigger and more detrimental to any brands affected.

Still uncertain about how to stay ahead of the evolving regulatory landscape? The DSA regulations are easy to follow when you have the right systems and strategy in place. We have put together a practical checklist online marketplaces can use to assess their own DSA readiness.

Note: This checklist covers content and policy enforcement; it's not a substitute for legal review of your full DSA obligations. It's useful whether or not you're formally classified as a VLOP (very large online platform). DSA scope isn't the only reason audit-readiness matters.

 

Inside this guide, we cover

  1. Risk assessment
  2. Consistent enforcement
  3. No self-declared categories
  4. System audits
  5. Counterfeit detection
  6. Audit trails

 

Risk assessment grounded in your own platform's evidence

Part of the reason Temu received their fine is that their ‘risk assessment’ was less of a detailed report and more of an essay about e-commerce risks in general. It wasn't based on what was actually happening on their own platform - quite the opposite of what regulators want to see. Temu’s platform-specific data backs that up: in 2025, 28 of the 259 dangerous toys identified for sale online were listed on Temu, up from just 2 the year before. A pattern Temu could have caught with its own data, before it became part of the case for a weak risk assessment.

A successful risk assessment needs to be based on audited, current data from your marketplace's own listings. It's best to outsource this to a DSA compliance platform: tools that continuously check listings against policy produce exactly this kind of live evidence.
 

Consistent enforcement against repeat-offending sellers

In the case of the three DSA fines, a big issue was that sellers who had already broken the rules were allowed to keep selling, and penalties were not applied reliably.

It’s important to apply the same penalty every time the same violation happens; it shouldn't rely on which staff member reviewed it or how busy the team was that week. Inconsistency is itself a liability. A key fix here is to automate your moderation so that every decision is consistently checked against the same policy logic and enforcement doesn't degrade. Automating the policy check removes the variability that comes from human bandwidth. This frees up your human moderators to focus where they add the most value: interpreting borderline or context-dependent cases, handling appeals, and catching nuances that a rules engine may miss.

Listings checked against actual content, regardless of their category 

Bad actors can mis-categorise products to dodge stricter checks. It is possible for sellers to mislabel products into looser categories to avoid being reported, leading to disciplinary action for the platform. What marketplaces need to ensure is that they trust their own category tags, and that they actually double-check what the listing is describing and selling.

Self-declared categories are a huge target if there's no one there double-checking. Listing content should always be evaluated against every policy, regardless of what category it is filed under. This is the core of good marketplace content moderation, and it's what stops mis-declaration from letting something slip through.

Recommendation and ad systems audited for amplification risk 

All three companies that received fines got flagged partly because their own recommendation engines or promotional programs kept pushing bad listings in front of more people - before anyone caught them. This isn't a closed chapter, either: in January 2026, the Commission opened a fresh set of proceedings against X specifically over its recommender systems, separate from and in addition to the €120 million fine it had already paid. Regulators aren't just checking recommendation systems once and moving on. 
This flags that algorithms could be amplifying a listing faster than moderation systems can catch it. What’s best here is to periodically audit what the recommendation system is surfacing, especially newly listed or high-velocity items. Build a feedback loop between your moderation team and whoever owns the recommendation algorithm, so flagged content that violates policies can be deprioritised in real time.


Dedicated counterfeit detection process

It’s good practice to have tooling for counterfeit identification, separate from general listing compliance. Having counterfeit detection as a distinct, dedicated process will protect you from heavy DSA fines. This is reinforced by the DSA's own rules. Under Article 30, marketplaces must verify trader identity and business details before a seller can list at all, and need to re-check that information if they have reason to suspect it's become inaccurate or outdated. This traceability requirement works hand in hand with counterfeit detection: knowing who a seller is doesn't tell you whether what they're selling is genuine, so platforms need a dedicated process for that separately.

Counterfeit detection is specialised enough that the strongest approach is a purpose-built tool integrated into your compliance stack, rather than trying to build a one-size-fits-all model in-house.


Audit trail and transparency reporting

Say a regulator asked you tomorrow: “Show me exactly what happened with this listing” Could you answer instantly? If, instead, it would take days of digging through your archive and systems, you probably need to improve your reporting and compliance strategy. 
This is one of the most concrete DSA requirements: decisions need to be documented and reportable, not just made in the moment. Platforms that automate their DSA transparency report directly from moderation decisions, rather than compiling it by hand retrospectively, are in a much stronger position when reporting deadlines or regulator requests land. Checkstep's integration with Shein is one example of this working at scale, including direct reporting into the EU's Transparency Database.

It’s not too late to get ahead

If you've made it through this checklist, then you should know that even though the DSA fines are getting bigger and the standards are getting stricter, it's not judgement day just yet. With audited risk assessments, consistent automated enforcement, and dedicated tooling for the areas regulators are actually scrutinising, marketplaces can stay ahead.
 

Heading to Marketplace Risk in London?  If you're looking for advice on your Trust & Safety strategy, the Checkstep team will be there. Book a meeting using the link below or try to catch us while we’re there!