
€200M fine. Not for selling illegal products — for failing to assess whether they were being sold.
The EU just issued its largest-ever Digital Services Act penalty against Temu.
The Commission’s finding: Temu’s 2024 risk assessment described risks facing “the e-commerce sector as a whole” — not risks specific to Temu’s own platform.
That distinction is the whole case.
What this means for your compliance team:
→ A generic risk assessment template is not compliance. It is evidence that your programme has never been stress-tested against your actual operations.
→ Regulators are now running mystery shopping exercises to validate risk assessment claims. Evidence-based, not self-declared.
→ The DSA, GDPR, and AI Act all share this logic: the assessment must reflect what actually happens in your system.
Temu has until 28 August 2026 to submit a remediation plan. Failure triggers periodic penalty payments on top of the €200M already imposed.
At S8fe.ai, we help organisations build data compliance risk assessments grounded in real data flows — jurisdiction by jurisdiction, product by product. Not sector templates. Your actual compliance surface.
Sources:
• https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1178
• https://www.techpolicy.press/eu-tests-limits-of-platform-risk-assessments-with-200-million-temu-fine/
• https://www.euronews.com/next/2026/05/28/eu-fines-chinese-e-commerce-giant-temu-200-million-for-dangerous-baby-toys-and-faulty-char
