On May 28, 2026, the European Commission issued its largest fine ever under the Digital Services Act – DSA, €200 million against Temu, the Chinese giant e-commerce, owned by PDD Holdings.
Formal proceedings against Temu were opened in October 2024, after the platform was designated a Very Large Online Platform (VLOP) under the DSA, classification that triggers a more demanding set of rules, including rigorous, evidence-based risk assessments.
The Commission concluded that Temu’s 2024 risk assessment failed to meet the standards the law requires. Regulators found baby toys with chemical substances above legal safety limits and choking hazards, chargers that failed basic safety tests, and jewelry raising further concerns. But the fine was not primarily about the products themselves, but rather about the process. The Commission determined that Temu’s assessment leaned on generic, sector-wide data instead of specific evidence about its own platform and sellers, and that it “seriously underestimated” the likelihood of European consumers encountering illegal items.
The penalty surpassed the previous DSA record of €120 million imposed on X in December 2025. Temu has until August 28, 2026 to submit a corrective action plan, and the investigation remains open on other fronts, including addictive design features and recommender-system transparency. What makes this case significant is that it is the first major DSA enforcement action focused specifically on product safety in e-commerce, indicating that the regulation applies not just to disinformation, but to the physical world of goods that cross borders and reach consumers’ homes.
Brazil has been having its own version of this conversation. Two recent developments reshaped the picture.
The first came in June 2025, when the STF declared Article 19 of the Marco Civil da Internet (Brazilian Internet Bill of Rights) partially unconstitutional. Since 2014, that article had shielded platforms from civil liability unless they ignored a specific court order to take content down. The Court found the rule had aged badly — sensible when platforms were smaller, but no longer adequate once algorithms began amplifying harm at scale. Platforms can now be held liable after an extrajudicial notice alone, with no prior court order. And for marketplaces in particular, the STF confirmed they fall under the Consumer Defense Code (CDC), not just the Marco Civil.
The second development is the STJ’s framework for deciding when that CDC liability actually attaches. In REsp 1.836.349/SP, decided unanimously in June 2022, the Court established a distinction that remains central to Brazilian e-commerce litigation today. The case involved a fraud on the OLX platform: buyers were deceived into depositing money into a private account by sellers impersonating General Motors dealers.

The Court held OLX not liable, because in that specific transaction, OLX acted as a mere classifieds site, taking no commission, managing no payment, and playing no role in the negotiation. The transaction was concluded entirely outside the platform, directly between buyer and fraudulent seller. Holding OLX responsible, the Court reasoned, would be no different from holding a newspaper liable for fraud committed through its classified ads.
The ruling’s lasting contribution, however, is its framework: the same platform can act as a classifieds site in some transactions and as a true intermediary in others, and the applicable liability regime depends on the role played in each case. A platform that manages payments, charges commissions, or actively organizes the transaction is part of the supply chain under the CDC and faces objective liability. One that merely hosts a listing does not, unless it fails to provide means to identify the seller, or ignores a notification to remove illegal content.
The parallel with the DSA is imperfect but worth drawing. Both systems are moving away from blanket immunity toward accountability tied to conduct. The methods differ: the DSA sets uniform duties for large platforms regardless of how individual sales work; Brazilian law looks at each transaction and asks what the platform actually did.
For a foreign company protecting intellectual property or bringing products to Brazil, this means the analysis cannot stop at identifying the platform. It must examine how the platform operates in practice. A listing on a classified-style interface points to a different defendant than a sale processed entirely within a marketplace’s payment and logistics system. When a foreign brand finds its products counterfeited or its IP infringed on a Brazilian platform, the first question is therefore not simply whether the platform knew — it is whether the platform was actively involved in bringing that transaction to completion. If it was, CDC objective liability follows; or, if it was not, the path to accountability runs through notification: documenting that the platform received notice and failed to act, which under the post-STF framework is sufficient to trigger liability even without a court order.
That is why documentation matters. Every notice sent to a platform needs to be formal, traceable, and precise. And the regulatory backdrop keeps moving: the Brazilian National Data Protection Authority – ANPD, elevated to a full regulatory agency under Decree 12.622/2025 — is growing more active in shaping what platforms must do, while Congress is still under pressure from the STF to update the rules.
The Temu fine is ultimately a reminder that risk assessment is not a box-ticking exercise. The Commission’s core criticism was that Temu described the risks of e-commerce in the abstract rather than analyzing its own platform, its own sellers, its own algorithms. That gap between formal compliance and substantive engagement is what regulators are trained to find.
For companies operating across jurisdictions, the practical message is consistent on both sides of the Atlantic: regulators are looking past formal compliance and asking whether the underlying systems are actually doing the work. Brazil and the EU are at different stages of that process, and their legal tools differ considerably — but the direction of travel is the same.
—
Advogado(a) autor(a) do comentário: Natalia Eleutério Garcia Gazote, Lígia Ferreira Marcondes Rocha e Cesar Peduti Filho, Peduti Advogados
Temu é multada em US$ 232 milhões pela UE por venda de brinquedos e carregadores inseguros
União Europeia aperta o cerco à Temu e eleva pressão sobre gigante chinesa
https://economicnewsbrasil.com.br/2026/05/28/temu-multa-uniao-europeia-custo-regulatorio/
UE multa Temu em 200 milhões de euros por permitir venda de produtos ilegais
A responsabilidade civil dos marketplaces de acordo com o STF
STJ — REsp 1.836.349/SP, rel. Min. Marco Aurélio Bellizze, Terceira Turma, julgado em 21/06/2022, DJe 24/06/2022
Decisão do STF sobre Marco Civil deixa vulneráveis as pequenas lojas virtuais
—
Se quiser saber mais sobre este tema, contate o autor ou o Dr. Cesar Peduti Filho.
If you want to learn more about this topic, contact the author or the managing partner, Dr. Cesar Peduti Filho.
