December 22, 2025

The European Commission vs X: What It Means for Corporate Governance

The European Commission has just issued its first major enforcement decision under the Digital Services Act (DSA) with a €120 million fine levied against X (formerly Twitter) for transparency-related breaches.

The European Commission has just issued its first major enforcement decision under the Digital Services Act (DSA) with a €120 million fine levied against X (formerly Twitter) for transparency-related breaches. The charges have provided companies with clarity regarding the EC’s expectations around the governance, risk and evidence required for Very Large Online Platforms (VLOPs) and other online services and intermediaries.

The Commission found X in defiance of the DSA due to three key infractions: their “deceptive” blue-check system in which any user can purchase a verification mark (a long-standing trust symbol previously known to demarcate that a user’s identity had been verified), a lack of transparency regarding their advertising repository and barring vetted researchers from accessing platform data.

This move both offers important insight into what operational compliance looks like in practice for any digital services operating within the EU and sets a precedent for future enforcement against VLOPs as the first non-compliance decision and fine under the DSA.

The key takeaway for all platforms and intermediaries operating in the EU is that transparency, content governance and risk oversight must be considered as core regulatory duties as opposed to best practice. Furthermore, the decision revealed design and UX to be an additional area of rigorous scrutiny in regards to risk and transparency under the DSA.

The Digital Services Act

The DSA was officially introduced in 2022 with the intent to foster a safer, more trustworthy digital environment via strict regulations imposed on online services such as marketplaces, social media networks, app stores and travel platforms.

With the intention of protecting individual consumers’ rights, the DSA delineates a clear set of rules made to empower users whilst still allowing for innovation and growth amongst SMEs and start-ups.

Regulations under the DSA emphasise transparency; appeals and flagging systems; enhanced protection for minors; and obvious choice, consent and personalisation measures for users.

Proportionality forms a key tenet of the DSA, with all online services facing base requirements and larger enterprises (such as VLOPs) bearing significantly enhanced obligations due to their potential impact on fundamental rights, media freedom and pluralism, public security, electoral processes, gender-based violence, public health, health and safety of minors and mental and physical wellbeing of users more broadly.

For VLOPs such as X, enhanced requirements include mandatory, independent annual audits; an established internal compliance function; publicly available repositories of advertisements; open access to data for the Commission, national authorities, and vetted researchers; and more.

While smaller platforms are not explicitly exempt from these requirements, there is a reasonable expectation that they can and will calibrate their governance and documentations to their own risk profile and user base.

The Ruling’s Impact

This case is the first example of the DSA’s requirements in action against a VLOP. It offers a live demonstration of how these concepts will be interpreted and enforced in situ, revealing the evaluation of some of the more potentially oblique ideas such as vetted researcher access, ad repository transparency and dark patterns.

With these expectations finally set, legal teams can begin to more accurately assess the risk of and set proper practices surrounding similarly situated businesses and services.

Importantly, the case proves that compliance frameworks must go beyond writing and be clear in operation; the mere existence of a policy or tool did not classify as proper compliance with regulations, and the absence of practical observance proved a severe enough offense to undermine any existing policies.

Furthermore, the situation reveals how regulators are defining key phrases such as “due diligence” and “systemic risk” as associated with VLOP responsibilities.

Lessons for In-house Legal

The enforcement follows a familiar pattern from GDPR, AML and ESG regulation: inaugural cases that show how written obligations translate into practice. For Jersey’s financial services sector, direct applicability may be limited, but the underlying governance expectations are increasingly consistent across regulatory domains.

The DSA’s definition of “intermediary services” is broad, capturing any service that stores information at users’ request. Client portals, onboarding platforms and data rooms could fall within scope where EU-resident clients or beneficiaries use them. Even where direct applicability is uncertain, the themes emerging from this decision (transparency, operational evidence, design accountability) echo requirements already familiar from data protection regulation and will feature in the AI Act as it comes into force.

The question worth asking: if faced with a regulatory audit tomorrow, could you produce evidence of digital risk assessments, mitigation decisions and board reporting within days rather than months?

Practical actions for in-house teams now include:

Mapping digital touchpoints (client portals, onboarding systems, document repositories) and assessing whether any might qualify as intermediary or hosting services under EU regulation.

Reviewing user-facing design for “dark patterns”: pre-ticked boxes, confusing opt-outs, or flows that steer users away from privacy-protective choices.

Ensuring accountability for digital governance sits with a named individual at appropriate seniority, with clear board reporting lines.

Stress testing your evidence trail: not just whether policies exist, but whether you can demonstrate they operate in practice.

Looking Forwards For Your Business

As companies look to navigate EU regulations, it’s important to remember that these regulatory expectations are starting to converge across domains; key themes such as transparency, accountability and operational evidence can be found throughout content moderation, data protection, AI and sustainability regulations. As such, governance structures must be capable of handling continuous risk assessment and oversight across domains.

And while smaller firms and service providers may not be held to quite the same standards as VLOPs like X, this decision is a useful early warning signal that alignment with these regulations should start well before enforcement reaches them, not after.

For firms looking to get ahead of these developments, FractionGC can assist through ongoing regulatory horizon scanning; aligning board and committee structures with emerging expectations; and building coherent risk and reporting frameworks that keep organisations ahead of, rather than reactive to, the next enforcement wave.

Rory Forest
Founder, FGC

Find the right starting point, designed around what the business actually needs.

Traditional offshore firms are excellent at what they're built for, large institutional transactions, multi-jurisdictional structuring, high-value litigation. That model is poorly suited to founders who need to move fast, and to regulated businesses that need embedded expertise, not episodic advice. FGC was built for the gap between them.