sota.io
Join the waitlist
2026-08-10·10 min read·sota.io team

Temu's €200M DSA Fine: What the First Systemic-Risk Enforcement Case Actually Requires From Marketplace, Recommender, and UGC Platforms

Temu's €200M DSA Fine: What the First Systemic-Risk Enforcement Case Actually Requires From Marketplace, Recommender, and UGC Platforms

On 28 May 2026, the European Commission fined Temu €200 million under the Digital Services Act. Not for selling counterfeit chargers, not for a data breach, not for a transparency-reporting gap — for writing a risk assessment the Commission considered too generic to count as compliance. That is a new kind of DSA enforcement, and the Commission's own press release is specific enough about what was wrong with Temu's document that it doubles as a checklist for anyone running a platform with a recommender system, user-generated listings, or algorithmic promotion — whether or not you are anywhere near the size that gets you a Commission investigation.

Temu has until 28 August 2026 to submit a remediation plan. That deadline, and the mechanics of what happens if it slips, are worth understanding even if you never touch the Digital Services Act's systemic-risk chapter directly — because the enforcement logic the Commission just demonstrated is going to be the template for the next VLOP case, and the underlying risk-assessment discipline it demands is good practice for any platform long before it becomes a legal requirement.

What the Commission actually said was wrong

The press release (IP/26/1178) and the corroborating Commission news page list three concrete deficiencies in Temu's 2024 risk assessment — not vague "insufficient effort" language, but specific, checkable failures:

  1. It used sector-wide data instead of platform-specific evidence. Temu's assessment leaned on general e-commerce risk statistics rather than testing and reporting about Temu's own service. The Commission ran its own mystery-shopping exercise through an independent testing organisation and found a very high failure rate on basic safety tests for chargers, and baby toys with chemical or suffocation hazards — numbers Temu's own document never surfaced.
  2. It underestimated exposure. The Commission concluded EU consumers are "very likely" to encounter illegal products on the platform — a materially different risk profile than what Temu's assessment described.
  3. It ignored how the product itself amplifies risk. The assessment did not evaluate how recommender-system design and influencer-led promotion programmes could increase the spread of illegal listings — treating the risk as a static content-moderation problem rather than one shaped by the platform's own ranking and promotion mechanics.

The Commission's characterization, in Executive Vice-President Henna Virkkunen's own words: "Risk assessments are not box-ticking exercises — they are the backbone of the DSA. Temu's risk assessment underestimates concrete risks, lacks specificity, is not grounded in solid evidence, and is not comprehensive."

That is a legible standard. A generic, desk-research risk assessment that does not test your own product and does not analyze your own ranking/promotion systems is now demonstrated — not just theorized — to fail Article 34.

The legal mechanism: Article 34 and Article 35

Temu was fined for failing two specific, cross-referenced obligations that only apply to designated Very Large Online Platforms (VLOPs) — platforms with 45 million or more average monthly active EU recipients under Article 33 of Regulation (EU) 2022/2065.

Article 34 — Risk assessment. VLOPs must diligently identify, analyse, and assess systemic risks stemming from the design or functioning of their service, at least annually and before deploying any feature likely to have a critical impact on identified risks. Article 34(1) names four risk categories:

CategoryWhat it covers
(a) Illegal contentDissemination of illegal content, goods, or services through the platform
(b) Fundamental rightsNegative effects on human dignity, freedom of expression, non-discrimination, the rights of the child, consumer protection
(c) Civic discourseNegative effects on civic discourse, electoral processes, and public security
(d) Individual harmsGender-based violence, public health, protection of minors, effects on physical and mental well-being

Article 34(2) requires the assessment to give "particular consideration" to how these risks are shaped by: the design of recommender systems and other algorithmic systems, content moderation systems, the applicable terms and conditions and their enforcement, advertising-selection systems, and the platform's data practices — plus intentional manipulation, inauthentic use, and regional/linguistic variation. This is precisely the list of things the Commission said Temu's assessment skipped.

Article 35 — Mitigation. Once risks are identified, Article 35(1) requires "reasonable, proportionate and effective" mitigation, tailored to the specific risks found, with fundamental-rights impact considered. The article lists eleven example categories, including:

A risk assessment that never names which of these levers it evaluated is, by the Commission's own precedent, not diligent — regardless of how long the document is.

What happens next, and why the 28 August date matters

Under Article 75, a non-compliance decision requires the platform to submit an action plan setting out the measures needed to remedy the infringement. The Commission's press release lays out the full sequence for Temu specifically:

  1. 28 August 2026 — deadline for Temu to submit its action plan to the Commission.
  2. +1 month — the European Board for Digital Services issues its opinion on the plan.
  3. +1 month — the Commission adopts a final decision and sets a "reasonable period" for implementation.
  4. Non-compliance after that can trigger periodic penalty payments under Article 76 — up to 5% of average daily worldwide turnover per day the infringement continues.

The €200 million fine and the 5% daily-penalty backstop are two different instruments: the fine is the sanction for the past failure, the periodic penalty is the pressure mechanism for future compliance. Combined, they are the Commission's answer to a criticism that has followed the DSA since 2023 — that systemic-risk obligations were symbolic because enforcement was slow and penalties were abstract. Investigation opened 31 October 2024, preliminary findings adopted July 2025, fine issued May 2026: roughly 19 months from opening to decision. That is the enforcement timeline to plan around, not a theoretical maximum.

Who this actually binds — and who should pay attention anyway

Article 34 and Article 35 are Section 5 of DSA Chapter III, and Section 5 applies only to designated VLOPs/VLOSEs (Article 33: 45M+ average monthly EU users, formally designated by the Commission). If your platform is nowhere near that scale, you are not legally required to run an annual systemic-risk assessment. Do not let a vendor compliance checklist tell you otherwise.

But three things are worth being precise about before you conclude the Temu case is irrelevant to you:

First, the baseline DSA obligations apply regardless of size. Article 19 exempts micro and small enterprises from Section 3 (Articles 20–28: internal complaint handling, trusted flaggers, ad transparency, recommender-system transparency, minor protection) — but that exemption does not cover Section 1 (Articles 11–15: points of contact, terms and conditions, transparency reporting) or Section 2 (Articles 16–18: notice-and-action mechanisms, statement of reasons, notification of suspected criminal offences). If you run any hosting service or online platform reachable by EU users, those apply to you today, at any size, with no revenue or user-count threshold.

Second, if you operate a marketplace, recommender feed, or UGC platform and plan to grow, the Article 34(2) factor list is the risk-assessment structure you will eventually need — so it costs nothing to use it as a design checklist now. Concretely: does your ranking or recommendation logic have any documented review for whether it could amplify harmful or illegal listings? Does your promotion/affiliate/influencer program have any assessment of dissemination risk, or does it only get evaluated for conversion performance? Is your only evidence base for "how risky is our platform" industry-wide statistics, or have you tested your own product? Temu's failure was not obscure legal technicality — it was building a governance document around convenient, generic evidence instead of the platform's actual behavior. That failure mode is available to a five-person startup exactly as it was to Temu.

Third, the 45-million threshold is not a permanent shield. Article 33 designation is based on average monthly active EU recipients, reassessed continuously — a platform that crosses the line gets a designation, a compliance countdown, and (per the DSA's general approach) no grandfathering for a risk-assessment methodology that was never built with Article 34(2)'s factor list in mind. Retrofitting evidence-based, product-specific risk assessment under regulatory deadline pressure — after your growth curve already crossed 45M MAU — is a materially worse position than building the habit early.

A practical starting checklist

If you run a platform with any of: a recommender/ranking system, user-generated listings or content, an affiliate/influencer promotion mechanism, or third-party sellers — here is what the Temu case suggests a defensible risk-assessment practice actually contains, independent of whether Article 34 legally applies to you yet:

None of this requires VLOP-scale infrastructure. It requires treating "how risky is our platform" as a question you answer with your own data, on a recurring basis, before growth or a regulator forces the question.

See Also

EU-Native Hosting

Ready to move to EU-sovereign infrastructure?

sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.