Skip to content

Legal Compliance Checklist

Last reviewed: 2026-05-11


DSA (Digital Services Act) — EU Assessment

Section titled “DSA (Digital Services Act) — EU Assessment”

The DSA tiers its obligations by EU active user volume:

TierMonthly EU active usersObligations triggered
BasicAnyGDPR lawful basis, accessible ToS, take-down mechanism
Intermediary / HostingTransmits or stores user content at scaleTrusted Flaggers, annual transparency reports, notice-and-action
VLOP / VLOSE≥ 45 million in EUFull DSA obligations — algorithmic transparency, annual audit

nSelf current status: Sub-threshold. nSelf is a self-hosted infrastructure tool — closer to WordPress (the software) than to a social platform. DSA recital 27 excludes software distribution from the “intermediary service” definition unless the software transmits or stores content on behalf of end users toward third parties.

QuestionAnswer
Does it store user-generated content?No — it displays automated service health metrics
Does it intermediate between users?No — read-only broadcast of infrastructure state
Does nSelf host the status pages?No — each operator self-hosts

Conclusion: The nself-status-page plugin does not independently trigger DSA platform obligations for nSelf. Self-hosted operators with large EU audiences should assess their own DSA position.


ServicenSelf roleLawful basisArt. 9 concern
cloud.nself.orgControllerContract (Art. 6(1)(b)) + Consent for telemetryNone
task.nself.orgControllerContract (Art. 6(1)(b))None
claw.nself.org (hosted)Processor (user-partitioned)Contract + Consent (AI opt-in)Zero-retention API mitigates health-info risk
ping.nself.orgController (telemetry)Consent — opt-in onlyNone
ɳFamily (self-hosted)Vendor; operator is controllern/aMedical, biometric, genetic — Art. 9(2)(a) consent gate implemented

All nSelf-operated services gate signups for users under 13 (US) and under 16 (EU). The parental consent flow:

  1. Age field detected at signup
  2. If age < 13 (US) or age < 16 (EU/EEA): account set to consent_pending
  3. Verification email sent to parent/guardian
  4. Account activated only after verifiable parental consent
  5. Consent record stored in np_parental_consents (self-hosted: operator’s DB)

nSelf does not sell personal data. CCPA rights:

  • Right to know — Privacy Policy §2 enumerates all data collected
  • Right to delete — Account deletion cascade documented; 30-day grace period
  • Right to opt-out of sale — N/A (no sale)
  • Right to non-discrimination — Policy affirms no discrimination for exercising rights

Data typeRetained forBasis
Account dataUntil deletion + 30 daysService continuity
Billing records7 yearsTax law
Art. 9 consent recordsRetained after revokeGDPR Art. 9(4) audit trail
Parental consent recordsRetained after account deleteCOPPA recordkeeping