TAKE IT DOWN Act compliance for platforms: counsel, build, or hosted desk

Search the Act and you get client alerts. They are accurate, they are current, and they end at the same sentence: stand up a live takedown workflow on a 48-hour clock. That sentence is a specification, not a deliverable. Here is who can actually deliver it.

Removal window48 hours from a valid requestFTC guidance
Who can fileAnyone — protections are not limited to account holdersFTC guidance
Per requestAn identifying number, and the outcome either wayFTC guidance
Penalty exposure$53,088 per violationFTC guidance
What counsel advisesBuild for a 48-hour compliance clock, not an ordinary moderation queueWilmerHale, 15 June 2026

By the time an operator searches for a “TAKE IT DOWN Act compliance service,” the legal question is usually already answered. They have read a law-firm alert, or the FTC’s own business-guidance page, and they know the shape of the obligation: a published notice-and-removal process, open to anyone, and removal of the reported content and known identical copies within 48 hours of a valid request. What they do not have is anywhere for a report to land.

That is a procurement question with exactly three answers, and they are not mutually exclusive. This page is about what each one actually hands you.

Where the legal read-out stops

The client alerts are worth reading. WilmerHale’s, published 15 June 2026, is a fair example of the genre and is unusually direct about the operational consequence. It tells platforms to “assume the FTC will expect a live, user-friendly takedown workflow now—not later,” to “build for a 48-hour compliance clock, not an ordinary moderation queue,” and to “treat duplicate detection as a core compliance capability.” Read it.

The alerts are not scarce, either. Finnegan’s — “The TAKE IT DOWN Act Is Now in Full Effect: What Platforms Need to Know” — is the other article an operator tends to land on for this search. Both are worth the twenty minutes before you spend anything.

Every one of those is correct. Every one of those is also a requirement handed to whoever is going to build the thing. A client alert is legal analysis; it contains no form, no clock, no log format, and no service level beyond the one the statute already sets. That is not a criticism — it is what a client alert is for. The gap it leaves is simply the gap this page exists to describe.

Route 1 — outside counsel

What counsel is genuinely good at: telling you whether the Act reaches your service at all. The FTC’s definition of “covered platform” reaches websites, apps and online services that primarily provide a forum for user-generated content, and the guidance itself closes by warning that it does not encompass all requirements that covered platforms must follow under TIDA. Scope questions, edge cases, the interaction with your existing moderation policy, and a written opinion you can point at later are all things a lawyer produces and a vendor cannot.

What counsel does not produce: the intake. No client alert ships a public report form, a timestamp that starts a clock on receipt, a per-report reference number, or an append-only record of what your team did and when. Counsel writes the specification and reviews the result. Someone else has to build the middle.

If your only open question is whether the Act applies to you, this route is the whole answer and you can stop here.

Route 2 — build it yourself

Entirely reasonable, and for a platform with an existing trust-and-safety surface, often the right call. It is worth being precise about the scope, because the visible part is the small part. Read off the FTC’s guidance, the build is:

  • A plain-language notice of the process, clear and conspicuous — which the guidance says may mean on your home page and wherever intimate content might appear.
  • A submission route open to people without an account, because TIDA’s protections are not limited to account holders.
  • An arrival timestamp that starts the 48-hour window on receipt rather than on triage.
  • An identifying number issued per request, so the reporter, the platform and law enforcement are demonstrably discussing the same image.
  • An outcome notice either way — the guidance says to let people know you removed the content, or if not, why.
  • A duplicate sweep, because reasonable efforts to find and remove known identical copies are your obligation and land inside the same 48 hours. The reporter does not have to list them.
  • A record of all of the above that still exists, and is still trustworthy, on the day somebody asks.

The form is a weekend. The clock is a week. The part that quietly costs the most is the last bullet: a log that cannot be edited after the fact is a different engineering problem from a table your own admin tooling can update, and it is the one that carries the evidentiary weight. Under-build it and you have compliance you cannot demonstrate, which in front of the FTC is close to the same position as no compliance at all — against a penalty ceiling of $53,088 per violation.

The full obligation-by-obligation version of this list is in the compliance checklist guide.

Route 3 — a hosted desk

The case for buying is narrow and specific: the intake has to exist before the first report does, and the first report is usually what makes anyone think about it. A hosted desk is a way of collapsing the schedule.

TrustDesk is that: a hosted report form anyone can file through without an account, arrival timestamps that start the 48-hour clock on receipt, a reference number per report, an append-only log of every operator action, and sweeps that surface reports approaching the window. The Compliance Kit is $249 one-time, the Hosted Desk is $49/month, and the policy generator is free — the notice obligation is the one you can discharge today at no cost, whichever route you take for the rest.

What it is not: legal advice, and not a scope determination. TrustDesk cannot tell you whether the Act covers your platform. That is Route 1’s job, and the routes compose better than they compete.

How to actually choose

Two questions settle it. First: do you know whether the Act covers you? If not, that is counsel, and nothing else on this page is urgent until it is answered. Second: does your platform already have an intake with an SLA clock and a tamper-evident record? If it does, you are extending something rather than building it, and Route 2 is cheaper than it looks. If it does not, the honest comparison is not vendor-versus-engineers but this month versus next quarter, against an obligation that has been enforceable since 19 May 2026.

The one combination that does not work is the common one: a client alert in a folder, a policy page written from it, and no route for a report to arrive on. That is a documented understanding of an obligation with no discharge of it.

Where to go next

For the enforcement record and the penalty arithmetic behind the number above, read the enforcement guide. For the obligations one by one, read the compliance checklist. If scope is still the open question, the home page starts there, and contact reaches a person who will tell you plainly if the answer is that you do not need any of this.

Every statutory line on this page was read off the FTC’s business-guidance page, “Complying With the Take It Down Act,” on 31 July 2026. The quoted advice is from WilmerHale’s client alert “The TAKE IT DOWN Act Goes Live,” 15 June 2026. Nothing here is legal advice.