The European Union's Digital Services Act (DSA) has turned advertising transparency and user protections into concrete obligations for covered online platforms. Ads must be identifiable as advertising, users must receive information about who is promoting them and why they are seeing them, and platforms cannot use sensitive personal data for ad targeting. The law also prohibits targeted advertising based on profiling when the user is known to be a minor.
For ad-tech providers, platform operators, and AI-enabled services that deliver or support advertising, the practical challenge is not simply changing an ad label. Compliance depends on whether systems can reliably identify ads, preserve provenance information, apply targeting restrictions, and produce the records needed for regulatory scrutiny. Recent European Commission enforcement activity across major platforms underlines that the DSA is an operating compliance framework, not only a policy statement.
What the DSA requires for online advertising
The DSA's advertising provisions focus on giving users meaningful context about commercial content and limiting the use of particularly sensitive or vulnerable-user data. In its April 2023 communication, the Commission stated that platforms must label ads, disclose who is promoting them, and explain why users see them. The same communication says advertisements cannot be displayed using sensitive user data, including ethnic origin, political opinions, or sexual orientation, and that profiling-based targeted advertising to children is no longer permitted. These requirements are set out in the European Commission's official DSA press release.
The distinction between a general ban on advertising to minors and the DSA rule matters. The verified restriction is a ban on targeted advertising based on profiling toward children. Businesses should avoid reducing this to a broader claim that every ad shown to a minor is prohibited, while still treating age assurance, audience controls, and profiling logic as high-risk compliance areas.
| DSA requirement | What users should be able to understand | Operational compliance focus |
|---|---|---|
| Advertising labels | That content is an advertisement | Consistent ad identification across interfaces and formats |
| Ad transparency information | Who promotes an ad and why it is shown | Accessible advertiser and delivery-rationale data |
| Sensitive-data restriction | Ads cannot be based on sensitive personal data | Controls over audience inputs and targeting workflows |
| Protection of minors | Profiling-based targeted ads cannot be directed at children | Age-related safeguards and restrictions on profiling |
The rules are particularly relevant where advertising delivery involves multiple parties. A platform may operate the user-facing service, while advertisers, agencies, data providers, and technology vendors contribute campaign inputs or delivery tooling. That structure makes it important to establish clear responsibility for the information shown to users and for the data categories allowed into targeting processes.
Reporting rules and enforcement increase the pressure
The DSA's transparency framework has continued to develop. From July 1, 2025, an Implementing Regulation standardized the format and content of required transparency reports. The first harmonised reports are due in early 2026. Standardisation should make reports easier for authorities and stakeholders to compare, while raising the importance of consistent internal data collection.
The supplied European Commission context also identifies enforcement developments in 2026 involving major platforms, including work relating to TikTok, AliExpress, and X. The specific cases differ, but the broader signal is clear: the Commission is actively applying DSA obligations across platforms rather than treating the framework as self-enforcing. Businesses should therefore treat advertising disclosures, minors' protections, and data-use restrictions as controls that need to function in production.
For technology teams, the most useful response is to map the compliance requirements to the actual ad-delivery path. That review should include:
- Ad classification, including how sponsored or paid placements are recognized across product surfaces.
- Disclosure delivery, including where advertiser identity and the explanation for ad delivery are presented to users.
- Targeting inputs, including controls that prevent sensitive personal data from being used for advertising.
- Minor protections, including how systems restrict profiling-based targeting when a user is known to be a child.
- Reporting data, including whether the organisation can assemble information in the harmonised transparency-reporting format.
AI does not remove these obligations. If machine learning systems are used to select, rank, personalise, or manage ads, their role should be evaluated within the same compliance design. A model or automated workflow may influence an advertising outcome, but it does not change the need for an ad to be clearly labeled, for users to receive required information, or for prohibited targeting inputs to be excluded.
For businesses building AI-supported advertising products, the priority is to connect governance to implementation. Product, legal, data, and engineering teams need a shared understanding of which inputs can enter campaign and profiling workflows, what disclosure information must be retained, and how the user experience communicates the required context. The DSA's reporting rules add a further reason to make those decisions traceable rather than relying on manual reconstruction after launch.
For organisations using AI in advertising or platform operations, regulatory requirements can expose gaps between product design, data controls, and governance. Scalevise helps teams translate these obligations into practical architecture, workflow, and oversight decisions through an AI governance and implementation consultation. A focused review can identify where automated targeting, disclosure flows, and reporting data need stronger controls before those gaps become operational risk. Request a consultation to assess your AI-enabled advertising workflows.
Frequently Asked Questions
Does the Digital Services Act require online ads to be labeled?
Yes. The European Commission states that platforms need to label all ads and provide users with information about who is promoting an advertisement and why they are seeing it.
Does the DSA ban advertising to minors?
The DSA prohibits targeted advertising based on profiling when directed toward children. It should not be described as a blanket ban on all advertising that minors may see.
Can platforms use sensitive personal data for ad targeting under the DSA?
No. The Commission says advertisements cannot be displayed based on sensitive user data, such as ethnic origin, political opinions, or sexual orientation.
When do harmonised DSA transparency reports begin?
The Implementing Regulation applied from July 1, 2025, and the first harmonised transparency reports are due in early 2026.
Conclusion
The DSA makes ad transparency, restrictions on sensitive-data targeting, and protections for minors central requirements for covered online platforms in the EU. With harmonised reporting rules in place and enforcement activity continuing, businesses that operate advertising systems should ensure their product controls, data practices, and reporting processes can support compliance in day-to-day operations.
Top comments (0)