Skip to Content
OPINION

Notes from the IAPP Europe: DSA and DMA enforcement, return of CSAM detection

The month of July was busy for EU digital regulation activity, including early DMA court rulings, DSA and DMA enforcement and renewed efforts to protect children online.

Published
Subscribe to IAPP Newsletters

Contributors:

Laura Pliauškaitė

European Operations Coordinator

IAPP

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

Before one heatwave ends this summer, another has already been hot on its heels. Likewise, throughout the month of July, one piece of news concerning enforcement of the Digital Services Package was followed by another Digital Services Act or Digital Markets Act-related development. 

On 8 July, the Court of Justice of the European Union delivered one of its first judgments on interpretation of the DMA. Applicable since May 2023, the DMA imposes certain obligations on large digital platforms called gatekeepers in an aim to ensure a contestable and fair digital economy. Organizations that provide core platform services in several EU countries and meet other cumulative conditions, including a specific annual EU revenue and a set number of monthly active end users in the EU, are designated as gatekeepers by the European Commission. 

In this case, Apple contested its gatekeeper designation concerning its App Store and iOS operating system as well as the Commission's classification of its iMessage service as a number-independent interpersonal communications service constituting a core platform service. The CJEU stated that a link between Apple's argument about the illegality of the DMA's interoperability obligations on gatekeepers, and the gatekeeper designation decision itself, was missing, upholding its designation. The court also dismissed the contestation concerning Apple's iMessage services as inadmissible, as such classification did not result in a change in Apple's legal position. 

Although Apple's attempt to overturn the Commission's designation was unsuccessful, it does not mean the designation is uncontestable. Last month, the CJEU agreed with Meta's argument that it should not be designated as a gatekeeper in connection with its Marketplace service. Moreover, Apple can still appeal the decision of the General Court and try to convince the highest EU court to rule in its favor, but such plans are not yet confirmed. 

Apart from this judgment, there were several Digital Services Package-related enforcement developments in July. The Commission shared preliminary findings that Instagram and Facebook's addictive designs and TikTok's unsafe minor accounts breach the DSA, which the companies can still challenge. 

The Commission also issued two fines — one for a DSA breach, finding that AliExpress did not manage risks connected to the sale of harmful products on its platform. The other fine concerning Google's breach of the DMA for self-preferencing on its search engine and anti-steering practices on Google Play. 

There was also a development related to the first noncompliance decision under the DSA — X's fine last year for breach of DSA transparency obligations. In addition to the fine, the social media platform was ordered to come up with an action plan to remediate the breaches. The Commission in mid-July accepted X's proposed measures to comply with transparency requirements and provide access to data for researchers. Instances like this suggest the EU's changing outlook on enforcement with an increased focus on dialogue and corrective measures rather than just retroactive monetary fines.

Another topic that has attracted considerable activity beyond the past month is children's safety online. The recently published report on systemic risks and mitigation measures on very large online platforms and search engines under the DSA focused on online risks to children. In addition to existing efforts at the EU level, European Commission President Ursula von der Leyen suggested more initiatives will drop this fall. France is about to become the first EU country to ban social media for minors.

That is not all for the month of July when it comes to children's protection in the digital world. One more significant development in this area is the return of child sexual abuse material detection. Online service providers will be allowed to scan their platforms for CSAM once again, and, if detected, take efforts to report and remove it. This permission will return as EU institutions reinstated a law that expired in April, which allowed for a derogation from certain provisions of the ePrivacy Directive. The derogation is once again temporary and will expire in April 2028, as EU rulemakers are still negotiating the long-term framework on this issue.

The focus on the fight against CSAM online has been apparent. This is the case not only when it comes to its detection but also generation, as the AI Omnibus, which entered into force 27 July, introduced a ban on AI systems designed to generate nonconsensual sexualized imagery and CSAM. This prohibition takes effect 2 Dec. 

This article originally appeared in the Europe Data Protection Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Laura Pliauškaitė

European Operations Coordinator

IAPP

Tags:

Law and regulationPrivacy

Related Stories