Field notes for whoever owns trust & safety.
Obligations get overstated by vendors and understated by everyone else, and the numbers get quoted without the context that makes them mean anything. These are written for the person who just became responsible for all of it — plain about what is actually required, and plain about what no tool can do for you.
Showing 3 of 3 posts
- Guide
The DSA, illegal content, and your platform
A practical guide to the Digital Services Act for EU platforms handling user-generated content — what it requires, what it doesn't, and where CSAM detection fits.
6 min read - Explainer
Why “99% accurate” tells you nothing
Accuracy is the wrong number for CSAM detection, and a vendor quoting it is describing their test set rather than your platform. What precision and recall actually cost, and how to benchmark on your own traffic.
7 min read - Guide
GDPR when you scan user uploads
Scanning uploads for illegal content is itself processing personal data. The lawful basis, the Article 28 paperwork every processor needs, the DPIA question, and where the data is allowed to live.
9 min read
Posts here that discuss the law are general information, not legal advice. Obligations depend on your service's classification, member state, and facts — verify the current state of the law with counsel before relying on it.