Compliance Oct 5, 2026 · 6 min read

Filing statements of reasons with the Commission's DSA Transparency Database

Who has to send every restriction to the Commission under article 24(5) of the DSA, who does not, what each filing carries, and how ToxicFilter files them for you and shows you the ones that did not go through.

Eduardo Lázaro
Eduardo Lázaro
Founder of ToxicFilter
Filing statements of reasons with the Commission's DSA Transparency Database

Every time a platform in the EU removes a post, hides it or suspends an account, the Digital Services Act asks for two things. The first is a statement of reasons for the person affected (article 17). The second, for some platforms, is a copy of that decision sent to the European Commission, which publishes it in a public database (article 24(5)). This post is about the second one: who has to do it, what goes in it, and how ToxicFilter does it for you.

What article 24(5) says

The text is short: providers of online platforms shall submit to the Commission, without undue delay, the decisions and the statements of reasons referred to in article 17(1), for inclusion in a publicly accessible, machine-readable database managed by the Commission, and they shall ensure that the information submitted does not contain personal data.

Three things follow from it.

  • It is every decision, not a sample. Each removal, demotion, restriction of visibility or suspension that article 17 covers is a filing.
  • "Without undue delay" means as it happens, not in a quarterly batch.
  • No personal data. What reaches the Commission describes the decision, never the person or the content.

Who has to file, and who does not

This is the part most summaries get wrong, so it is worth being precise.

  • Article 17 binds every hosting service, whatever its size. If you store what users post and you restrict it, you owe the author a statement of reasons. See the overview of the DSA in practice.
  • Article 24(5) is in section 3 of chapter III, the obligations for online platforms: hosting services that disseminate what users post to the public. A private storage service is not one.
  • Article 19 excludes micro and small enterprises from that section (as the EU defines them in Recommendation 2003/361/EC: fewer than 50 people and no more than €10 million of turnover or balance sheet), except for article 24(3). So a small platform does not have to file with the Commission. It keeps that exemption for twelve months after it stops being small, and loses it at once if it is designated a very large online platform.

So the honest summary is: everybody writes statements of reasons; medium and large online platforms also send them to the Commission. If you are small, filing is optional, and some do it anyway because a public record of decisions taken under clear rules is a good answer to the question "why was my post removed".

What a filing carries

The Commission's API takes a statement as a set of structured fields, and ToxicFilter fills them from the verdict and from your settings:

  • What was done: the content was removed, disabled, demoted or its visibility restricted, and separately whether the account was suspended. That comes from the rule that acted ("What happens" on each rule of a policy), from the call when it says so with restriction, or from the project's default.
  • On what ground: incompatible with your terms of service, with the title and text of the rule that applied and a link to it. ToxicFilter never says content is illegal: deciding that is yours, so every filing rests on your own rules.
  • What kind of content and which category: text or image, and the category of harm mapped onto the Commission's list (illegal or harmful speech, cyber violence, scams and fraud, protection of minors, data protection and privacy...). Anything without an equivalent is filed as a breach of the terms of service.
  • Where it applies: the countries the restriction covers, as ISO codes, within the EU and EEA.
  • How it was decided: whether detection was automated (it always is here) and whether the decision was fully automated or a person took it in the review queue.
  • A unique id: the verdict's own mod_ id, so a retry is recognised as the same statement and never counted twice.

No content, no author, no name: only the decision. That is what the regulation asks, and it is also how the rest of ToxicFilter works, since verdicts are stored without the content that produced them.

How ToxicFilter files them

You turn it on per project, in Settings, Transparency, and paste the token the Commission gave your platform for its API. From then on:

  • Every statement of reasons is filed in the background, a few seconds after the verdict, by a queued job. Your API call never waits for the Commission and never fails because the Commission is slow or down.
  • A person's decision is filed too. A held comment rejected in the review queue is a restriction like any other, and it is filed with "decided by a person".
  • Retries are spaced out: one minute, five, half an hour, two hours, six hours. A brief outage at the Commission costs nothing.
  • A refusal is not retried. If the Commission answers that the token is wrong or a field is invalid, retrying would only repeat the error, so the filing is marked as rejected with the Commission's own reason.

Seeing what did not go through

Filing in the background has one risk: a failure nobody sees. So every filing has a status, and Filings in the panel lists them:

  • pending, on its way;
  • filed, with a link to the statement in the Commission's database;
  • rejected, with the reason the Commission gave;
  • failed, when every retry was spent without reaching it.

A rejected or failed filing can be sent again from the same list once the cause is fixed (a new token, say). If you would rather file yourself, the last thirty days are a JSON download from the same screen, and the API serves the same records paged (GET /v1/statements/transparency). Both are in the statements documentation.

What it does not do for you

It does not decide whether you are a platform, whether you are small, or which of your rules a decision rests on. It files what your rules decided, in the shape the Commission asks for, and tells you when a filing did not arrive. Whether you have to file at all is the question at the top of this post, and it is yours to answer.

Put it in front of your real traffic

Allow, review or block, and the reason in words. On the free plan: 2,000 credits a month, no card. A check costs 1 credit, about 8 if the model reads it, about 10 for an image.