Your DSA Data Does Not Stay in Europe

Platforms are publishing more regulatory data than ever. Each disclosure is produced for a particular regime and with its own scope and definitions. Once that information becomes public, the original reporting boundary matters less. Regulators, researchers and civil society can read it alongside data and information published elsewhere. That gives outsiders a view of the service that no single reporting regime provides on its own.
In August 2026, SaferNet Brasil analysed more than 25 million Discord Statements of Reasons from the EU Digital Services Act Transparency Database. At the time, Discord was under regulatory scrutiny over child safety in Brazil. The two processes were separate, but they concerned the same service. Public data created for one jurisdiction had become part of the wider evidence available elsewhere.
The DSA database already has an audience well beyond EU supervisors. In 2026, researchers published a TikTok-specific study using 11.6 million Statements of Reasons collected across 2024 and 2025. Because they worked with individual enforcement records, they could examine how the platform moderated a particular area of risk.
Ofcom has also used the dataset. In March 2026, its Economics and Analytics Group commissioned an analysis of 143,726 Discord Statements of Reasons from four daily extracts. The work looked at moderation volumes, harm categories, enforcement methods and automation. It also analysed the timing recorded in the Statements of Reasons. EU enforcement data was already feeding into regulatory analysis outside the EU.
Regulatory reporting is still organised by jurisdiction
The DSA has its own disclosures and definitions. The UK, Australia, India and the US have different requirements. Each regime asks for a different view of the service.
Outside the company, those sources do not have to remain separate. EU DSA material can show risk assessments and decision-level enforcement. Australian disclosures can add information on private messaging and safety interventions. Some India-specific reports add child sexual exploitation figures and timing from detection to final action.
US filings can add exposure metrics, appeals, reinstatements and automation data. These disclosures were created for different regulators, but they can still describe different parts of the same service. An external analyst can place them side by side and look for connections between them.
That is much harder to do if each reporting team only reviews the disclosure it owns. The public record is spread across jurisdictions, but the reader outside the company can assemble it in one place.

The level of detail changes what outsiders can see
The DSA database creates a common reporting framework, but the level of detail still varies by platform. Discord is a useful example. Its Statements of Reasons contain enough detail to separate specific child-safety classifications, policy grounds, enforcement actions and detection sources. Changes over time can also be examined.
Other platforms disclose at a much broader level. A record may show that an enforcement decision concerned child safety, while saying little about the specific harm. The mechanism behind the decision may also remain unclear. That leaves much less room for external analysis.
This becomes important when numbers are compared. A high count for a specific harm can partly reflect detailed disclosure. A lower count on another platform may simply mean that the same activity cannot be isolated from the public data.
The figures can therefore look comparable while showing different levels of visibility. Platforms need to understand how much can be reconstructed from their own disclosures, and how that compares with others. Without that context, public numbers are easy to misread.
Public data can reveal more when sources are connected
Different public sources do not always line up neatly. A risk assessment may describe one set of priorities, while enforcement data shows activity concentrated elsewhere. Two reports may use similar labels but count very different things. A sharp change in one dataset may have no obvious explanation in another.
There may be a good reason for the difference. Definitions can change. Reporting periods can differ. A product change may alter what gets detected or reported.
Those explanations are often available inside the platform. They are not always visible in the public record.
An outside reader sees the numbers first. If two disclosures appear difficult to reconcile, that can become a question before the platform has added any context. An outside reader does not start with internal explanations. They start with the public record and work from there.
That is why reviewing each disclosure separately is no longer enough. The more public reporting expands, the easier it becomes to compare one source with another.
An outside-in view of public data
An outside-in review starts with the material available to everyone else. It looks at the public record as a regulator, researcher, journalist or NGO would find it. The aim is to understand what can be seen before internal context is added.

That can reveal changes in enforcement patterns, gaps in reporting detail or disclosures that look unusual beside other public information. The platform can then examine those points internally and add the context that is missing from the public record.
In many cases, there will be a straightforward explanation. The value lies in knowing where that explanation may be needed before someone else raises the question.
Public regulatory data is becoming easier to collect, compare and analyse. The DSA Transparency Database is part of that shift. So are transparency reports, regulator disclosures and mandatory filings elsewhere.
Platforms produce those records one requirement at a time. Outside the company, they can be read together.
Civility Bureau helps platforms see that wider public record for themselves. We bring disclosures from different regimes into one view, identify where they connect, and show where outside readers may see questions that individual reports do not reveal.
