A DSA illegal content report form should accept reports without a name or email

Ulf Aslak Lai photo Ulf Aslak Lai Published 29 Sep 2026 AI drafted 8 min read
A DSA illegal content report form should accept reports without a name or email

Your product lets customers publish a page or share a file by public link. A woman emails your support team: a page one of your customers published contains a private photo of her. There is no report form, so support asks for her phone number and a copy of her passport before acting, and the takedown email to your customer names her as the person who reported it.

Under the EU's Digital Services Act (DSA), a product that stores what its users upload is very likely a "hosting service", and it must give anyone an easy way to report illegal content, whatever the company's size. Having no such mechanism is a breach in itself, and national regulators can fine up to 6% of worldwide turnover 1. On 17 September 2026 the European Data Protection Board (EDPB, the body of all EU data protection regulators) adopted final guidelines on how that mechanism must treat the personal data of the people who use it 2.

The phone number, the passport and the name in that email all fail those rules. Most of the DSA's duties fall on large platforms such as social networks and marketplaces, but this one reaches small products too, and I think the EDPB's guidelines are the clearest answer yet to what the report form should look like.

Which products must have a way to report illegal content?

Almost any product that stores what its users give it, including ones based outside the EU that serve EU users. Article 16 of the DSA requires every "hosting service" to let "any individual or entity" report content they consider illegal, electronically, in a way that is easy to find and use. The DSA defines a hosting service as one that stores information a user provides, at that user's request, and lists cloud computing and file storage among its examples 1.

So legally, even a private workspace tool with no public pages is likely in scope. In practice, reports arrive where content can reach people outside the account that created it: a public share link, a published site, a marketplace listing. My advice is to have a report mechanism either way, and to put the link right next to anything public.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.

Get started

What may a DSA report form ask for?

Article 16(2) lists four elements the form must make it easy to submit 1:

  • (a) an explanation of why the content is illegal
  • (b) the exact location, such as the URL
  • (c) the reporter's name and email address
  • (d) a statement that the report is made in good faith

The new guidance is about item (c), the name and email. Applying the GDPR's data minimisation principle (Article 5(1)(c)) 3, the EDPB sets three rules 2:

  • Ask for name and email, but do not make them a condition. Providers "should not make the submission of a notice contingent on their identity being provided", except where the content cannot be judged otherwise. A copyright complaint is the usual example: whether the upload infringes depends on whether the person complaining owns the work.
  • Ask for nothing else. Providers "should generally not ask for notifiers' additional personal data" beyond name and email ("notifier" is the DSA's word for the reporter). A phone number or an ID document is more than the form needs.
  • Leave identity out of child sexual abuse reports. Article 16(2)(c) excludes reports of child sexual abuse offences, including grooming, and the EDPB says the name and email should not be collected there.

If I were building this form today, I would ask for name and email, mark both optional, and only start requiring them from a sender who has already filed a run of unfounded reports. The final guidelines allow that: identifying data may be processed where it is needed to stop someone misusing the form 2. The EDPB added that point after its public consultation, where civil society groups warned that forms demanding identity stop people reporting at all.

What do you owe the person who reported it?

Two messages, sent to the email address if the reporter left one 1:

  1. A confirmation of receipt, without undue delay (Article 16(4)).
  2. Your decision, without undue delay, with the options for challenging it (Article 16(5)). If a model or rule engine processed the report or made the decision, this message has to say so (Article 16(6)).

The EDPB confirms the reporter's name and email may be used for these messages, and to tell them when something cannot be removed for technical reasons 2.

The GDPR adds a notice duty. The reporter gives you their name and email, so Article 13 requires you to tell them, when you collect it, who you are, why you process it and who will receive it 3. The person shown in reported content is owed a notice too, under Article 14, when the report comes from someone else. For most products that means a short notice on the form and a new section in the Privacy Policy. Most Privacy Policies only describe what happens to users' data, and the people on both sides of a report are often not users at all.

You may let a model triage reports and remove content on its own; the EDPB treats the DSA's reporting rules as authorising it 2. What you must do is say so: both the decision to the reporter and the notice to the uploader have to state that automated means were used. I wrote about the GDPR's limits on software-only decisions (Article 22) when the Dutch regulator fined Uber for automated driver deactivations.

When can the uploader learn who reported them?

Only where it is strictly necessary, and in those cases the DSA requires you to tell them. When you remove or restrict someone's content, Article 17 requires you to send that user a "statement of reasons", a notice explaining what you did and why. Point (b) says it includes, "where strictly necessary, the identity of the notifier". Recital 54 gives intellectual property claims as the example, where identity is needed to establish that the content is illegal 1. The same notice must also say if automated means were used (Article 17(3)(c)).

The EDPB adds two duties on top 2:

  • Decide the cases in advance. The GDPR expects you to be able to show your reasoning, so you write down when disclosure is necessary and proportionate, rather than deciding in the moment.
  • Warn the reporter first. If a report might lead to their name being passed on, they must be told under Article 13, and only the strictly necessary data goes to the uploader.

Go back to the woman in the opening scenario. Your support team could fairly ask whether she is the person in the photo, because that can decide whether the page is illegal. There was no reason to hand her name to the customer who published it. A removal-notice template with a {{reporter_name}} field filled by default does that to every reporter. I would ship that field empty and fill it only for the cases written down in advance.

What should you change in your product?

If you run a product where users store content that other people can reach, the DSA's regulators (Digital Services Coordinators) check that a report mechanism exists, with fines of up to 6% of turnover (Article 52(3)) 1. Your data protection authority checks what it collects and who sees it.

  • Put a report link next to public content, not only in the footer. Recital 50 asks for it to be "located close to the information in question".
  • Make name and email optional, remove any other identity field, and drop both for child sexual abuse reports.
  • Add a notice on the form saying what you do with the reporter's details and when, if ever, the uploader might see them.
  • Leave the reporter's identity out of your removal template by default, and write down the cases (such as copyright claims) where it goes in.
  • Send the receipt and the decision, and tell both sides when automation made the call.
  • Add reporters, and people shown in reported content, to your Privacy Policy.

A report form that starts collecting names and email addresses is a change to what personal data your product processes, and it usually ships in a pull request nobody reads for its legal effect. Lawcel, the compliance tool we build, reads pull requests and flags which of your legal documents a change like that affects.

FAQ

If the product stores content for users in the EU, it is likely a hosting service, and Article 16 applies whatever the company's size. The small-company exemption in Article 19 does not cover it.
The EDPB says it should not, unless identity is needed to judge whether the content is illegal or to stop people misusing the form. Ask for both, and let the form submit without them.
The EDPB says providers should generally not ask reporters for more than Article 16(2) lists, which is a name and an email address.
Only where it is strictly necessary, for example some intellectual property claims. In those cases Article 17(3)(b) requires the reporter's identity in the notice to the uploader.
Yes. Articles 16(6) and 17(3)(c) require you to tell both the reporter and the uploader that automated means were used.

References

  1. Regulation (EU) 2022/2065 (Digital Services Act) - accessed 29 Sep 2026
  2. EDPB, Guidelines 3/2025 on the interplay between the DSA and the GDPR, version 2.0, adopted 17 September 2026 - accessed 29 Sep 2026
  3. Regulation (EU) 2016/679 (General Data Protection Regulation) - accessed 29 Sep 2026

About the author

Ulf Aslak Lai

Ulf Aslak Lai

Co-founder, Chief Technology Officer

Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.

  • Platform architecture
  • Data governance
  • ML/AI systems
GDPR

Uber fined 825 million euros for automatically banning drivers

On 21 August 2026 the Dutch data protection authority fined Uber 824,990,000 euros for switching off drivers' accounts by software alone. GDPR Article 22 prohibits solely automated decisions with legal or similarly significant effects on a person, and cutting off income or access someone depends on can reach that bar. Unless one of three exceptions applies, the automation has to stop rather than gain an appeals queue. Where one does, the company owes safeguards and a policy explaining the logic.

GDPR

Two days from launch with no privacy policy. Twelve facts have to be true.

Before you publish a Privacy Policy, GDPR Article 13 requires twelve items. Two are close to boilerplate and one is your company's name. The remaining nine are claims about your own product: who you send data to, where it goes, how long you keep it, and what legal basis each purpose rests on. A generator only repeats what you type in, so make the list first.

GDPR

How long can you keep user data? Write down the period, then make something enforce it.

Set a period for each category of data you hold, publish it, and build something that enforces it. GDPR Article 5(1)(e) lets you keep personal data no longer than is necessary for your purpose, and Article 13(2)(a) makes you publish either that period or the criteria you use to set it. Regulator guidance is explicit that "as long as necessary" does not satisfy it.

GDPR

Every contact you publish for GDPR data requests must be easy to use on its own

Spain's regulator fined Securitas Direct 100,000 euros for a paid 902 phone line on its camera signs, even though its privacy policy listed a free email address. It judged each route for data requests on its own. For a software product, a deletion route behind a login can fail the same test, and a request sent to support@ counts from the day it arrives.