There is no size threshold in the TAKE IT DOWN Act. The FTC’s guidance says the definition of “covered platform” reaches a broad range of websites, apps and online services — naming social media, messaging, image and video sharing, and gaming — and that a business primarily providing a forum for user-generated content may fall under TIDA and should comply. Headcount does not appear in the test. A two-person service with an upload button is in the same position as a company with a trust-and-safety org. The statutory definition behind that — the two prongs, the three exclusions and the absence of any threshold — is quoted in full in are you a covered platform.
What follows is the FTC’s own list, in its order, translated into the thing you have to ship. If you want the enforcement timeline and the penalty arithmetic instead, that is in the companion piece on FTC enforcement of the TAKE IT DOWN Act.
1. A notice-and-removal process that exists in plain language
The first obligation is not the removal — it is the notice. A platform must publish plain-language information about its notice-and-removal process for nonconsensual intimate images, including how someone submits a request, and that notice must be clear and conspicuous.
This is the obligation with no incident attached, and therefore the one a platform can be in breach of on a quiet day with zero reports. The FTC’s complaint portal accepts complaints about platforms that never built a way to file at all — a category that requires no victim of yours to have come forward.
2. Notice where the content is, not only in your policy page
The guidance is specific about placement in a way most write-ups skip: depending on your platform, it says, you may need a clear and conspicuous TIDA notice on your home page and wherever intimate content might appear. It gives the example of letting users submit a removal request directly from the photo or video.
A link buried in a terms-of-service footer satisfies the letter of “published” and very little of “conspicuous.” The practical read: the route to reporting should be reachable from where the harm is visible.
3. A route for people who do not have an account
This is the requirement small platforms miss most often, because in-product reporting flows are almost always built behind a login. The FTC states it flatly: TIDA’s protections are not limited to individuals who hold an account on your platform, and asks platforms to consider how to give non-account-holders an easy way to submit a request.
That follows from who is actually harmed. The person in a nonconsensually shared image usually is not the person who posted it, and frequently has no reason to have signed up for the service hosting it. A reporting flow that requires registration asks a victim to create an account on the platform harming them before it will listen.
4. Coverage that includes digital forgeries
TIDA covers nonconsensual intimate real photos and videos as well as “digital forgeries” — images digitally created or altered using software, an app, or artificial intelligence. A report is not disposed of by establishing that the image is synthetic. That finding is not a defence; it is inside scope.
Whatever triage step your process has for “is this real,” it cannot be a step that closes reports.
5. Removal within 48 hours — and the duplicates too
On a valid request, the content comes down within 48 hours. Inside that same window, the platform must make reasonable efforts to find and remove known identical copies — and the guidance closes the obvious escape route in one sentence: people who file a request do not need to report duplicate images. Finding them is the platform’s obligation, not the reporter’s.
Two operational consequences. The clock starts when the request arrives, not when someone opens it — so a shared inbox with no weekend coverage spends most of a window before anyone reads the report. And “reasonable efforts” has to be something you can describe afterwards, which means the search has to leave a trace, not just the removal.
6. An identifying number on every request
The guidance asks platforms to provide an identifying number for each takedown request, so that the person who filed it, the platform, and law enforcement can all be sure they are discussing the same image and the same request. It also says to design the process so people are told you removed the content — or, if you did not, why.
Both halves matter. The identifier is what makes a report referenceable months later; the outcome notice is what stops a declined report from looking identical to an ignored one.
7. Hashing, so removed content does not come back
Beyond the removal itself, the FTC suggests using technology such as hashing to prevent content you have already removed from reappearing, and sharing those hashes — with NCMEC’s Take It Down service where the imagery involves minors, and with StopNCII where it involves people 18 and older — so other platforms can block the same content.
This one is framed as advice rather than a requirement, but it is the difference between removing an image and stopping its circulation, and it is the sort of measure that characterises a process as diligent rather than minimal.
8. Treat the guidance as a floor, not the statute
The FTC ends its own page with a caveat worth repeating: the guidance does not encompass all requirements that covered platforms must follow under TIDA, and platforms should review the language of the Act to understand their full obligations. Eight bullet points from the enforcing agency are the starting point for compliance, not the completion of it.
What this adds up to
Read together, the list is less a legal problem than a plumbing one. Six of the eight items describe an intake: a published route in, open to strangers, reachable from where the content is, that stamps arrival time, issues an identifier, records what was done, and reports an outcome. The legal analysis is mostly settled by the FTC in a page of bullets. What is left is that almost no small platform has anywhere for a report to land.
That is the actual failure mode, and it is a scheduling one: the intake has to exist before the first report does, and the first report is usually what makes anyone think about it.
Where TrustDesk fits
TrustDesk is that intake and the record behind it — a hosted report form that anyone can use without an account, arrival timestamps that start the 48-hour clock on receipt, a per-report reference, an append-only log of every operator action, and sweeps that surface reports approaching the window. The Compliance Kit is $249 one-time and the Hosted Desk is $49/month, and the policy generator is free.
If you are still working out whether the Act reaches your service, the overview on the home page starts with scope. If you want the enforcement record and the penalty exposure, read the enforcement guide. If the list above is settled and the question is now who builds it, counsel, in-house and hosted are compared here. If you want to ask a person about your specific setup, contact reaches one.
Every obligation on this page was read off the FTC’s business-guidance page, “Complying With the Take It Down Act,” and re-checked against it on 31 July 2026. Nothing here is legal advice.