EU Privacy Law EU/EEA

DSA Algorithmic Transparency: Recommender Systems, Ad Repositories, and Researcher Access

The Digital Services Act's algorithm transparency duties: Article 27 recommender disclosures, Article 39 ad repositories, Article 40 researcher data access, and audits.

Regulation

Regulation (EU) 2022/2065 (DSA), Articles 27, 34 to 42

Max Penalty

Up to 6% of global annual turnover

Enforcing Authority

European Commission for VLOPs/VLOSEs; national Digital Services Coordinators

Official Source

eur-lex.europa.eu

Executive Summary

  • DSA Article 27 requires every online platform to disclose the main parameters of its recommender systems in its terms, plainly, plus any options users have to modify them.
  • VLOPs must additionally offer at least one recommender option not based on profiling (Article 38).
  • Article 39 requires VLOPs to run public ad repositories: every ad shown, who paid, targeting parameters, and reach, searchable for a year after the last impression.
  • Article 40 gives vetted researchers access to platform data for studying systemic risks, operationalized by a delegated act adopted in 2025.
  • Independent annual audits (Article 37) and Commission proceedings, including against X over its ad repository, give these duties teeth up to 6% of global turnover.

The DSA’s answer to opaque algorithms is not to ban them but to make them observable from three directions: users get plain-language disclosure of how recommendations work, the public gets searchable archives of advertising, and vetted researchers get data access to study what platforms do at scale. For very large platforms, independent audits then verify the story matches reality.

RegulationDSA, Articles 27, 34 to 42
Max penalty6% of global annual turnover
Applies toAll online platforms (Art. 27); VLOPs/VLOSEs for the rest
Official textEUR-Lex CELEX 32022R2065

User-facing transparency

Article 27 binds every online platform, not just giants: the terms of service must state the main parameters of recommender systems and their relative importance, in plain and intelligible language, with any modification options directly accessible where recommendations are shown. Article 38 raises the bar for VLOPs: at least one recommender option must not rely on profiling, which is why the designated platforms now offer chronological or non-personalized feeds. Advertising transparency runs in parallel: Article 26 requires each ad to be labeled with advertiser identity and meaningful targeting information in real time.

Public and research-facing transparency

Article 39 turns VLOP advertising into a public record: a searchable repository of every ad shown, who paid for it, its run dates, main targeting parameters, and aggregate reach, retained for a year after last presentation. The Commission’s first formal DSA proceedings, against X, include alleged shortcomings in exactly this repository.

Article 40 is the most novel provision: Digital Services Coordinators can compel VLOPs to give vetted researchers access to platform data for studying systemic risks. The delegated act adopted in 2025 built the machinery: an application portal, vetting criteria (research affiliation, independence from commercial interests, security capability), and data-sharing conditions. It is the first legal regime anywhere granting outside researchers enforceable access to platform internals.

Audits close the loop

VLOPs undergo yearly independent audits (Article 37) covering all DSA obligations, including the transparency set, with platforms required to address findings or explain why not. Combined with the systemic risk assessments of Articles 34 and 35, the design is a verification chain: disclose, be measured, be audited, correct.

For compliance teams below VLOP scale, the actionable slice is Article 27: write an honest recommender disclosure and surface user options. Note the GDPR layer stays live: profiling-driven recommendations need a lawful basis and, where they produce significant effects, engage Article 22. The broader obligations stack is mapped in our DSA platform compliance guide.

Frequently Asked Questions

What must platforms disclose about their recommender algorithms?

Article 27: the main parameters determining what is suggested to users, and the relative importance of those parameters, in plain and intelligible language in the terms of service, plus any options for users to modify or influence them.

Do users get a non-profiling feed option?

On very large platforms, yes. Article 38 requires VLOPs and VLOSEs to provide at least one recommender option not based on profiling, such as a chronological feed. Smaller platforms only owe the transparency, not the alternative.

What is a DSA ad repository?

A public, searchable archive VLOPs must maintain (Article 39) showing each ad presented, the advertiser and payer, the period it ran, the main targeting parameters, and aggregate reach, kept available for one year after the ad's last presentation.

Who can get researcher data access under Article 40?

Researchers vetted by a Digital Services Coordinator, affiliated with research organizations, studying systemic risks in the EU, independent of commercial interests, and able to protect the data. A 2025 delegated act set out the application and data-sharing mechanics.

Does algorithmic transparency conflict with GDPR?

It layers on top. Recommenders that profile people are personal data processing needing a GDPR basis, and consequential automated decisions engage Article 22. The DSA adds disclosure and user-choice duties; researcher access and ad repositories must themselves comply with data protection.

Regulatory Crosswalk

GDPR Art. 22EU AI ActePrivacy

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.