What governance duties apply to a platform where users can post and transact?
A platform that lets users publish and transact needs account, content, merchant, product, transaction, complaint, and data governance proportionate to its functions, risk, and scale. It need not promise manual review before every post and cannot guarantee that no user breaks a rule. It must establish rules, identify and handle risk, retain necessary evidence, and respond to reports and authorities. “We only provide technology” does not remove the operator's duties.
Responsibility follows actual control. Rule-setting, ranking, commission, payment control, merchant review, refunds, and the ability to remove a reported listing all affect the boundary. A platform selling its own goods should distinguish those offers from third-party merchants so consumers can identify the responsible seller.
When translating compliance duties into evidence and controls, also compare What content-governance duties apply to a community posting platform?; the linked guidance adds context that should be considered in the same decision.
| Area | Minimum governance question | System capability | Decision retained by operator |
|---|---|---|---|
| Account and entity | Who speaks or trades, and are credentials appropriate? | Registration checks, roles, account action, records | Admission and high-risk entity review |
| Posts, comments, messages | What is prohibited or distribution-limited? | Rules, risk routing, reports, removal, appeal | Escalation of high-impact cases |
| Goods and services | Is it illegal, infringing, deceptive, or licensed? | Category credentials, validation, sampling, recall | Prohibited catalogue and exceptions |
| Order and payment | How are money, fulfilment, refund, and fraud handled? | Order evidence, reconciliation, holds, cases | Compensation, dispute, and release rules |
| Recommendation and ads | Is harmful or misleading material amplified? | Labels, policy version, intervention, choice | Ranking objective and advertising review |
| Data and logs | What is collected, visible, and retained? | Access, masking, export, deletion, audit | Purpose, supplier, and incident notice |
Governance need not mean prior review of everything. Low-risk posts may publish with reports, sampling, and automated discovery. Medical or financial claims, minors, stranger transactions, or high-value goods may need stronger entity or content review. Prohibited goods and content do not publish. Models and keywords triage; people review high-impact suspension, refund, or referral decisions, with an appeal route.
Publish account rules and apply graduated actions such as correction, reduced distribution, transaction suspension, removal, freeze, closure, and re-registration restriction. Retain the original item, rule version, reason, operator, time, and appeal outcome. This supports correction and evidence, but retention must still follow the applicable law and necessity rather than keeping every user record forever.
China's Provisions on the Governance of the Online Information Content Ecosystem require platform governance mechanisms. The E-Commerce Law addresses platform-operator registration, rules, and responsibilities when it knows or should know of specified harm. These rules reject blanket technical-provider immunity without imposing identical liability for every user act.
Before launch, rehearse fake merchants, prohibited goods, infringement, online abuse, minor reports, fraud, repeated refunds, authority requests, and wrongful suspension. Measure intake, automated routing, human review, errors, backlog, repeat abuse, and overturned appeals. Use statutory deadlines where applicable; otherwise set risk-based targets from staffing and service commitments rather than inventing a universal 72-hour promise.
Wavesteam can deliver account, merchant, content, reporting, review, transaction-exception, evidence, and permission systems and translate confirmed rules into operating actions. The client remains the platform operator, defines scope and decisions, and staffs continuing governance. If no team can receive the cases, start by invitation, restrict categories, or defer transactions rather than claiming an API provides governance. Wavesteam's enterprise solution describes the relevant system scope.