← Insights

DSA

The Marketplace Enforces First: DSA Trader Traceability and the Marketplace-Dependent Target

What is DSA trader traceability? Article 30 of the Digital Services Act requires online marketplaces to verify a trader's identity and compliance self-certification before letting it sell, and to suspend traders whose information does not hold up. For a target with heavy marketplace revenue, the channel that carries the sales is now also the regulator with the fastest trigger.

What is DSA trader traceability? Article 30 of the EU’s Digital Services Act requires an online marketplace to collect a trader’s identity, address, payment account details, trade register entry, and a self-certification of compliance with EU law before letting it sell to EU consumers, to verify key elements of that information, to display the trader’s identity on the listing itself, and to suspend traders whose information is not provided or does not hold up. It has applied since 17 February 2024, and it quietly rewired who enforces e-commerce compliance first.

Most of the regimes in this series are enforced by authorities: slow, national, complaint-driven. The GPSR piece maps what happens when that machinery eventually reaches a non-compliant target. The DSA changes the sequencing. It deputised the marketplace: the channel that carries the target’s revenue is now also obliged, on pain of its own liability, to check the target’s papers. For a marketplace-dependent target, the fastest regulator is the one it invoices through.

What Article 30 Actually Requires

Before a trader can sell through an in-scope marketplace, the platform must obtain its name, address, phone and email; an identity document; its payment account details; the trade register it is entered in, where applicable; and a self-certification committing the trader to offer only products and services that comply with the applicable rules of Union law. The marketplace must make best efforts to verify the reliability of key elements, display the trader’s identity on the interface where the product is shown, and, where a trader fails to provide or correct required information, suspend it until it does. The full text is in Regulation (EU) 2022/2065, Article 30. Micro and small platforms are exempt; the marketplaces that matter to a growth-stage e-commerce P&L are not.

Alongside this sits GPSR’s own listing regime: since 13 December 2024, product listings must carry the manufacturer’s identity, an EU responsible person for non-EU manufacturers, and applicable warnings, in the listing itself. The two regimes reinforce each other. The DSA makes the marketplace verify who is selling; GPSR makes the listing show whose product it is and who answers for it in the EU. A gap in either becomes the marketplace’s problem, and marketplaces resolve their problems by suspension.

The significant shift is procedural, not substantive. A market-surveillance authority builds a case: correspondence, deadlines, proportionality, appeal. A marketplace runs a compliance sweep: a data check flags an account, a listing comes down, revenue stops the same day, and the burden of proof inverts onto the seller to get reinstated. There is no hearing. The platform is protecting its own DSA and GPSR position, and the cheapest way to do that is to err toward suspension.

For diligence, that changes what a compliance gap is. Under authority-led enforcement, the gaps mapped elsewhere in this series price as probability-weighted future costs. Under marketplace-led enforcement, the same gap in a marketplace-heavy target prices as a revenue-continuity risk with an unknown trigger date: the next verification sweep, the next category policy update, the next competitor report through the platform’s notice mechanisms. How aggressively each marketplace polices each category varies, and the variation is observable per platform rather than something to assume.

Where This Shows Up in the Waterfall

Marketplace economics already live in GP2: platform fees are a visible, priced line. What the P&L does not show is the interaction between revenue concentration and compliance fragility. A target with 60% of revenue through marketplaces and clean papers has a channel-fee question. A target with 60% of revenue through marketplaces and an unresolved responsible-person gap has a single point of failure dressed as diversification: “we sell on four marketplaces” reads as spread on a revenue slide and is, from the compliance side, four independent enforcement surfaces, each running its own sweeps on its own schedule.

The costs of staying reinstated are also real and rarely isolated: verification churn, relisting labour, the sales-velocity reset a suspended listing suffers when it returns (rank, reviews, and buy-box position do not resume where they left off). None of this appears as a line item; it appears as GP2 friction and unexplained marketplace revenue volatility.

Why This Slips Through Due Diligence

Marketplace account standing is treated as operational trivia rather than a diligence object. It is not in the data room beyond seller-controlled dashboard screenshots; legal review covers the reseller and platform agreements, not the account’s verification status or suspension history; and QoE sees marketplace revenue as a channel split, not as revenue whose continuity depends on papers the target may not hold. A target that has already survived one quiet suspension-and-reinstatement cycle has experienced the risk directly, and nothing in a standard process would surface that it happened.

What Outside-In Analysis Can Detect Before the Data Room

  • Whether the trader identity displayed on the target’s marketplace listings matches its corporate registry data, consistently across platforms
  • Article 19 listing completeness on each marketplace: manufacturer identity, EU responsible person, and warnings present in the listing itself, sampled across the catalogue
  • Revenue-dependency proxies: the share of catalogue live on each marketplace versus the target’s own store, and how much of the review volume accrues there
  • Suspension scars: gaps in listing history, review-date discontinuities, relisted ASINs or equivalents with reset review counts, and seller-feedback pages that go quiet for defined periods
  • Whether the same products appear under multiple seller identities, a pattern that verification regimes are specifically built to catch

None of this proves an account is at risk; these are indications of how exposed the channel is and how the target has managed it so far. The formal DD request list they generate is specific: account health records, suspension and appeal history, and verification correspondence for every marketplace the revenue depends on.

The Pre-LOI Question Every PE Fund Should Ask

Marketplace revenue share alone is a channel-mix fact, not a risk read. The question is: how much of the target’s revenue flows through channels that are obliged to suspend it, and would its listings and trader records survive the verification those channels are now required to run?

A target whose papers hold up everywhere it sells has a fee structure to negotiate. A target whose marketplace revenue rests on listings that would not survive a sweep is carrying a continuity risk sized to its best channel, priced by nobody, and triggerable by a policy update neither buyer nor seller controls.


This analysis is part of Tronvik’s GP2 Fulfilment & Service Margin pillar. Nothing in this article constitutes legal advice. To initiate an outside-in marketplace-dependency screen on a specific acquisition target, contact info@tronvik.com.