Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚑ TL;DR
The EU Digital Markets Act regulates “gatekeepers” β€” platforms with €7.5 billion+ EEA turnover (or €75 billion market value), 45 million+ monthly EU users and 10,000+ yearly business users β€” through per-se obligations: no self-preferencing, no combining data across services without consent, free steering, interoperability, data access and sideloading. No dominance finding, no effects analysis, no years of litigation: designation triggers the duties, and non-compliance costs up to 10% of worldwide turnover (20% for repeat offenders).

The Digital Markets Act is competition policy’s biggest structural experiment since merger control was invented: it converts two decades of platform case law into a standing rulebook enforced ex ante. Whether you run a designated gatekeeper, build on one, or compete against one, the DMA now shapes product design, data flows and commercial terms across the EU digital economy. This guide explains who is caught, what the obligations actually require, and how enforcement works β€” opening the digital-markets pillar of our Global Competition & Antitrust hub.

Key Takeaways

Who are the designated gatekeepers?
Alphabet, Amazon, Apple, ByteDance, Meta and Microsoft were designated in September 2023 across core platform services from search and app stores to social networks, browsers and operating systems; Booking.com followed in 2024, and the service list has been refined case by case (iPadOS added; some services contested successfully).

What changes for business users?
Rights, mostly: steering freedom (tell customers about better offers), access to the data their activity generates, FRAND access to app stores and search rankings without self-preferencing, and portability β€” each a litigation-era demand converted into a statutory entitlement.

What is the enforcement stick?
Commission-led investigations, specification decisions dictating technical compliance, fines to 10% of worldwide turnover (20% repeat), periodic penalties, and β€” for systematic non-compliance β€” structural remedies up to divestiture under Article 18.

Why did the EU abandon case-by-case enforcement for gatekeepers?

Because the case law worked doctrinally and failed practically. Google Shopping took seven years from complaint to decision and another seven in appeals; by the time remedies arrived, the comparison-shopping rivals were dead. Android, AdSense, Amazon Marketplace, Apple Music β€” the same pattern: theories vindicated, markets unrestored. The DMA’s premise is that digital tipping outruns adjudication, so contestability must be protected by standing rules rather than post-mortem findings.

The design borrows from both competition law and regulation: obligations distilled from litigated abuses (self-preferencing from Shopping, anti-steering from Apple, data-combination limits from the German Facebook case, sideloading from Android) β€” but applied without proof of dominance, effects or consumer harm in the individual case. Critics call this over-inclusive; the legislator answered that the six designated groups had each been through a decade of individual proof already. The Google docket is, in that sense, the DMA’s legislative history.

Who qualifies as a gatekeeper β€” and how does designation work?

Three cumulative criteria, each with quantitative presumptions: significant impact on the internal market (€7.5 billion EEA turnover in each of the last three years, or €75 billion average market capitalisation); operating a core platform service (search, intermediation/marketplaces, app stores, social networks, video sharing, messaging, ads, browsers, operating systems, cloud, virtual assistants) that is an important gateway β€” presumed at 45 million monthly EU end users and 10,000 yearly EU business users; and an entrenched, durable position (thresholds met across three years).

Companies meeting the numbers must self-report; the Commission designates within 45 working days; rebuttal arguments are narrowly entertained (a few succeeded β€” Gmail and Outlook escaped as non-gateway services despite the numbers, and X’s ads business was examined and not designated). The Commission can also designate below thresholds after a market investigation, and “emerging gatekeepers” can receive partial obligations. Designation is service-specific: Apple is regulated for iOS, the App Store and Safari β€” not for everything Apple does β€” and each service’s compliance is assessed separately, which is why the gatekeeper list is best read as a matrix, not a roster of names.

What do the core obligations actually require?

Article 5’s self-executing rules: no combining personal data across services (or with third-party data) without genuine consent; no wide or narrow parity clauses preventing business users offering better terms elsewhere; free steering β€” business users may promote and conclude offers outside the platform; no forcing use of the gatekeeper’s identity, payment or browser services; no bundling core services as access conditions; and no anti-complaint retaliation.

Article 6’s specifiable duties carry the engineering weight: no self-preferencing in rankings; sideloading and third-party app stores on operating systems; uninstallable defaults and choice screens; interoperability with OS/hardware features on FRAND terms; real-time data portability for end users and continuous data access for business users; advertising transparency (pricing, metrics, verification data); and search-query data sharing with rival engines. Article 7 adds horizontal messaging interoperability on request. Together they constitute the most detailed conduct code ever applied to private firms outside utilities β€” and the reason gatekeeper compliance is now a product-engineering discipline, not a legal memo.

βš–οΈ Case Study β€” The first designation round and its contests (European Commission, 2023–2024)

September 2023’s designations covered 22 core platform services across six groups. The immediate appeals mapped the boundaries: Apple contested iMessage’s designation and won at the market-investigation stage (insufficient business-user gateway role); Microsoft’s Bing, Edge and Advertising escaped as non-important gateways despite Microsoft’s group-level numbers; ByteDance lost its challenge to TikTok’s designation before the General Court. The lesson for the next tier of platforms β€” including fast-growing marketplaces and AI-era services β€” is that the quantitative thresholds start the argument rather than end it, but rebuttals succeed only with hard evidence that the numbers overstate gateway power.

How does DMA enforcement differ from an Article 102 case?

Speed and specification. There is no market definition fight, no dominance battle, no effects trial: the Commission opens a non-compliance investigation, must generally conclude within 12 months, and can adopt specification decisions that dictate the technical implementation of an obligation β€” as it did in March 2025, ordering Apple’s interoperability mechanics for connected devices in engineering detail. The burden architecture inverts the litigation era: gatekeepers must demonstrate compliance, publish compliance reports, and maintain independent compliance functions.

Sanctions escalate by design: fines to 10% of worldwide turnover, 20% for repeated infringement, periodic penalties to 5% of daily turnover β€” and Article 18’s systematic non-compliance procedure, where three infringements in eight years unlock behavioural or structural remedies including divestiture, plus effective merger bans on the gatekeeper’s ecosystem. The first fines (Apple €500 million, Meta €200 million, April 2025) tested the machine; the enforcement arc β€” including the compliance-design fights over Apple’s Core Technology Fee and Meta’s pay-or-consent model β€” is tracked in our DMA enforcement guide.

THE DMA MACHINE1. DESIGNATION€7.5bn EEA turnover / €75bn cap45M users + 10k business usersper core platform service2. OBLIGATIONSno self-preferencing • free steeringconsent for data combining • sideloadinginteroperability • data access • portability3. ENFORCEMENT12-month investigationsspecification decisionsfines 10% → 20% • Art. 18 structuralWHAT IT REPLACES7-14 year Article 102 cases (Shopping, Android, Apple Music) → standing duties, inverted burden,compliance reports and engineering-level specification — contestability protected before tipping, not after
Designation β†’ obligations β†’ enforcement: the DMA compresses a decade of litigation into a regulatory cycle.

What does the DMA mean for businesses that are not gatekeepers?

Opportunity, mostly β€” if claimed. App developers gained steering and external-payment rights, alternative distribution channels and interoperability hooks; merchants gained parity freedom and data-access rights against marketplaces; advertisers gained transparency entitlements; rival search engines gained query-data access; and complainants gained a regulator with deadlines. The DMA’s beneficiaries, however, must operationalise their rights: data-access requests, interoperability petitions and compliance-report challenges do not file themselves.

There is also second-order exposure. Gatekeepers’ compliance redesigns reshape dependent businesses’ economics (new fee structures like the Core Technology Fee, changed rankings, consent flows depressing ad targeting), and the DMA’s spread β€” Japan’s Smartphone Act, the UK’s DMCC regime, TΓΌrkiye’s pending DMA-style amendments, Brazil’s and India’s drafts β€” means multi-market platforms face a compliance matrix, not a single rulebook. Businesses building on platforms should assign ownership of “gatekeeper relations”: monitoring compliance reports, quantifying the value of new rights, and escalating breaches β€” the practical playbook our DMCC guide extends to the UK.

πŸ’‘ Pro Tip: If you build on a gatekeeper platform, read its DMA compliance report (they are public) against your own contract and data flows once a year. The gaps between promised and delivered compliance are negotiating leverage at minimum and complaint material at best β€” and the Commission has explicitly invited third-party evidence on exactly those gaps.

What are the open questions the next few years will decide?

Four live ones. Whether compliance-by-design or malicious compliance wins: the fee-and-friction architectures (Core Technology Fee, scare screens, pay-or-consent) test whether gatekeepers can price away the statute’s intent β€” the first fines say no, the appeals will say how firmly. Whether interoperability at engineering depth is administrable: the Apple specification decisions make the Commission a standards body, a role it has never held at this granularity.

Whether the DMA exports β€” the emerging national variants diverge in scope and could fragment platform regulation precisely as it globalises; and whether AI redraws the perimeter: virtual assistants are listed, foundation models are not, and the Commission has signalled review as AI interfaces become the new gateways, the frontier mapped in our AI and competition analysis. For gatekeepers and their counterparties alike, the strategic posture is the same: treat the DMA as a permanent operating condition under active construction, and invest in shaping its specification rather than merely absorbing it.

How should a gatekeeper-dependent business build its DMA playbook?

As a rights-exploitation program with an owner. Step one: map your dependencies against the obligation catalogue β€” which Article 5/6 rights touch your economics (steering, data access, ranking neutrality, portability, ad transparency), and what each is worth in revenue or cost terms. Step two: exercise systematically β€” file the data-access requests, implement steering flows, test alternative distribution β€” and document the gatekeeper’s responses, because the deltas between entitlement and delivery are your leverage.

Step three: engage the enforcement layer deliberately β€” compliance-report comments, evidence submissions to open proceedings, and coalition-building with similarly situated businesses (associations of developers, merchants and publishers have shaped every major DMA decision so far). The asymmetry to exploit: the Commission needs third-party evidence to prioritise, and structured, quantified submissions from real businesses move dockets that abstract complaints never reach. Firms that ran this playbook in the first cycle β€” notably in the steering and app-store fights β€” obtained rule changes worth percentage points of margin.

What has the DMA changed on the ground so far?

Measurably, if unevenly: browser choice screens moved default shares by visible points in several member states; alternative iOS distribution exists in the EU where it existed nowhere; steering flows delivered direct-purchase options in major apps; parity-clause removal freed hotel and travel pricing; and business users hold data feeds that simply did not exist in 2023. Against that, self-preferencing and ranking outcomes have shifted less than complainants hoped, and fee redesigns clawed back part of the openness β€” the gap the enforcement cycle is now working.

The honest interim verdict: the DMA has proven it can change product architecture at the deepest incumbents faster than any litigation ever did, while leaving open whether changed architecture becomes changed market shares. That second question β€” contestability in outcomes, not just in design β€” is the one the regime will be judged on, and the reason its five-year reviews and perimeter updates matter as much as its fines.

Frequently Asked Questions

Does the DMA apply outside the EU?

Formally no β€” obligations attach to core platform services provided to EU users. Practically, some compliance changes ship globally for engineering economy, while others are EU-ringfenced (Apple’s alternative app stores). The Brussels-effect question is being answered feature by feature.

Can a gatekeeper justify non-compliance on security or privacy grounds?

Only narrowly: integrity and security exceptions exist for specific obligations (sideloading safeguards), but must be strictly necessary and proportionate β€” blanket security narratives have not persuaded the Commission, and GDPR is not accepted as a shield against data-access duties properly implemented.

How do DMA and Article 102 interact?

They run in parallel: DMA compliance does not immunise abuse liability, and conduct outside DMA obligations remains challengeable under 102 (and national equivalents). Germany’s Β§19a regime adds a third layer for designated firms β€” platform counsel must clear all three.

Will TΓΌrkiye adopt a DMA equivalent?

A DMA-modelled amendment to the competition law has been in the legislative pipeline, and the Rekabet Kurumu already applies DMA-style theories through Article 6 cases and sector inquiries. Platforms with significant Turkish users should build compliance architecture assuming convergence.

Last Updated: August 2026 · Reviewed by the Kurums Law editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading