The European Commission refused public access to the risk assessment report submitted by platform X regarding compliance with the Digital Services Regulation. The Ombudsman found maladministration and requested an individual assessment of the document.
The European Ombudsman found maladministration on the part of the European Commission for refusing to individually assess the report submitted by platform X regarding its obligations under the Digital Services Regulation.
In short 1. The European Ombudsman confirmed the finding of maladministration in the case of the Commission's refusal to assess public access to the risk report of platform X.
2. The case concerns the annual risk assessment report submitted by X after the entry into force of the Digital Services Regulation.
3. The Commission refused access citing a general presumption of non-disclosure, commercial interests, and the protection of an ongoing investigation regarding compliance with the DSA.
4. The Ombudsman considered that the report should have been individually assessed to provide the widest possible public access.
5. The Commission did not accept the Ombudsman's recommendation, and the case was closed while maintaining the finding of maladministration.
The European Ombudsman criticized the way the European Commission handled a public access request for the risk assessment report submitted by platform X regarding its obligations under the Digital Services Regulation.
The case originated from a complaint filed in September 2024, after the applicant requested public access to the risk assessment report of a major social media platform. The document concerned the platform's compliance with the provisions of the DSA, within the framework of the obligations applicable to very large online platforms.
The Commission refused access to the document. It argued that a general presumption could apply under which the disclosure of the report could affect the company's commercial interests and an ongoing investigation regarding the platform's compliance with the DSA.
The Commission did not conduct an individual assessment of the report to determine which parts could be disclosed and which information could be protected.
After inspecting the document, the European Ombudsman issued preliminary findings stating that the application of a general presumption of non-disclosure for a risk assessment report prepared under the DSA was not reasonable.
The Ombudsman pointed out that the situations in which EU courts have recognized the possibility of using a general presumption are different from the rules applicable to risk assessment reports.
The Commission maintained its position. It added that the general presumption of non-disclosure was justified by the need to protect an independent audit regarding the platform's compliance with the DSA obligations.
The Ombudsman did not consider this argument sufficient for applying a general presumption of non-disclosure.
The institution noted that, although the timeline for the proactive publication of the risk assessment report by the platform is linked to the completion of the independent audit, this does not mean that public access requests must be denied before that date.
The Ombudsman concluded that the Commission's application of a general presumption of non-disclosure for the risk assessment report constituted maladministration.
She recommended that the Commission conduct an individual assessment of the document, with the aim of providing the widest possible public access.
The Commission did not accept the recommendation. In addition to the previous arguments, the Commission argued that it could not independently assess whether the report contained sensitive commercial information and that the applicant was pursuing a private interest, not a public interest, through the access request.
The Ombudsman expressed regret over the Commission's response.
She emphasized that the assessment of sensitive commercial information is part of the obligations of EU institutions under European legislation regarding public access to documents.
The Ombudsman also rejected the argument regarding the exclusively private nature of the request. She pointed out that the possibility of examining compliance with the DSA by a very large online platform constitutes a public interest.
In the communication regarding the closure of the case, the Ombudsman reminded that the services provided by very large online platforms can lead to serious violations of fundamental rights, including identity theft and sexual violence.
Therefore, examining how platforms comply with the DSA cannot be considered a purely private interest.
The Ombudsman closed the case confirming the finding of maladministration.
The Digital Services Regulation requires providers of very large online platforms to assess certain risks associated with their services. These include risks related to the dissemination of illegal content, negative effects on fundamental rights, and the protection of minors.
Annual reports on these risk assessments are submitted to the European Commission, which monitors and enforces compliance with the DSA obligations by the targeted platforms.
The Commission received the report on the first annual risk assessment conducted by X after the entry into force of the DSA in September 2023.
The case does not establish whether platform X complied with the Digital Services Regulation. It concerns how the Commission handled a public access request for a document in its possession.
EU legislation on access to documents allows institutions to protect sensitive information, including commercial information, but requires the assessment of requested documents. In this case, the Ombudsman considered that the refusal based on a general presumption was not sufficient.
The case fits into the broader debate regarding the transparency of the DSA's application, the role of the Commission as the supervisory authority for very large online platforms, and public access to information regarding digital risks.
Latest News
22:59
22:54
22:43
22:23
22:07
See more news