Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚡ TL;DR
Two years into enforcement, the DMA has produced its first fines (Apple €500 million for steering restrictions, Meta €200 million over pay-or-consent), engineering-level specification decisions on Apple interoperability, retargeted investigations across Alphabet, Apple and Meta, and a compliance economy of fees, screens and appeals. The lesson so far: the Commission moves faster than Article 102 ever did, gatekeepers test the perimeter with priced-in compliance designs, and the appeals now running will fix the regime’s real strength.

DMA enforcement stopped being theoretical in 2024–2025: investigations, preliminary findings, fines and specification orders have mapped where the new regime bites and where gatekeepers still hold ground. This tracker organises what has actually happened, what each decision means for the obligation it enforces, and what to watch next — the operational companion to our DMA explainer in the digital-markets pillar of the Competition & Antitrust hub.

Key Takeaways

What were the first DMA fines?
April 2025: Apple fined €500 million for anti-steering restrictions in the App Store (developers prevented from freely communicating and concluding external offers), Meta €200 million because its binary pay-or-consent model failed the Article 5(2) requirement of a genuine consent alternative. Both appealed.

What is a specification decision?
A Commission order dictating how a gatekeeper must technically implement an obligation. The March 2025 Apple decisions specified interoperability mechanics for connected devices and the developer-request process — the regime’s deepest intrusion into product engineering yet.

What should businesses monitor?
The appeals (fine levels and consent-model doctrine), the Article 6 ranking and self-preferencing investigations, messaging interoperability implementation, and whether repeat findings trigger the 20% tier or Article 18 structural talk.

What did the Apple steering decision establish?

That the DMA’s steering right is broad and commercial, not formal. Apple had “complied” with link-outs wrapped in fees and warnings; the Commission held that Article 5(4) entitles developers to steer customers to external offers free of charge and without gatekeeper-imposed friction that empties the right — condemning both the restrictions and the fee architecture attached to external purchases. The €500 million fine came with a cease-and-desist requiring genuine steering freedom.

The decision’s doctrinal payload: compliance designs that technically permit but economically neutralise an obligation are non-compliance. That principle travels across the obligation catalogue — to sideloading friction, choice-screen design, data-access usability — and it is the Commission’s answer to the malicious-compliance strategy tested since the US Epic injunction saga. Apple’s appeal contests both the interpretation and the fine’s proportionality; the judgment will calibrate every gatekeeper’s cost-benefit on perimeter-testing.

Why was Meta’s pay-or-consent model fined?

Article 5(2) requires genuine consent before combining personal data across services — and, where consent is refused, a less-personalised but equivalent alternative. Meta’s November 2023 model offered EU users a binary: consent to data combination for free access, or pay a monthly subscription. The Commission found this failed the “specific choice” requirement: the alternative must not force users to buy their way out of data combination; a free, less-personalised option (which Meta later introduced with reduced-data ads) was the missing piece.

The €200 million fine covered the binary-model period, and the case became the collision point of competition, data protection and platform economics: the EDPB had reached parallel conclusions under GDPR, and the CJEU’s Bundeskartellamt judgment had already knitted the regimes together. For the ad-funded economy the message is structural: consent architecture is now competition-law infrastructure, and the monetisation gap between consented and unconsented users is a regulated parameter — with Meta’s appeal, and the parallel German and national proceedings, deciding how tightly.

⚖️ Case Study — The Apple interoperability specification decisions (European Commission, 2025)

Acting under Article 8, the Commission specified in engineering detail how Apple must open iOS features to connected devices — notifications, background execution, proximity pairing, AirDrop-class transfers — and how the developer interoperability-request process must run (timelines, transparency, appeal routes). It was the first use of specification powers to write a gatekeeper’s technical roadmap, transforming an abstract duty into product requirements with deadlines. Apple’s appeal argues privacy, security and innovation burdens; the outcome will define whether the Commission can regulate at the API layer — the question on which the DMA’s interoperability promise stands or falls.

Where do the other investigations stand?

Alphabet has faced two fronts: search self-preferencing (whether Google’s own verticals — flights, hotels, shopping — receive treatment rivals cannot obtain under Article 6(5)) and Play Store steering restrictions, with preliminary findings on the latter; ranking-neutrality specification is the likely endgame. Amazon’s marketplace data use and Buy Box mechanics, partially pre-committed under Article 102 cases, are monitored under parallel DMA duties. Microsoft adjusted Windows and LinkedIn flows without formal proceedings, and Booking entered the regime in 2024 with parity-clause obligations biting first.

Messaging interoperability (Article 7) advanced quietly: WhatsApp built the third-party chat architecture, with rollout gated on requesting partners and encryption preservation — a live experiment in whether mandated interoperability can coexist with security engineering. And the perimeter cases continue: iPadOS was added by market investigation, X’s ads service was investigated for designation and spared, and the Commission has signalled attention to AI-era services as usage shifts. The docket’s shape confirms the regime’s logic: continuous supervision with escalating specificity, not episodic litigation.

DMA ENFORCEMENT SCOREBOARDApple — steering (Art. 5(4))Fees + friction on external offers condemned€500M • ON APPEALMeta — pay-or-consent (Art. 5(2))Binary model = no genuine consent alternative€200M • ON APPEALApple — interoperability (Art. 6(7))Engineering-level specification of iOS openingsSPECIFIED 2025Alphabet — self-preferencing + Play steeringRanking neutrality for verticals; store steering findingsINVESTIGATIONSNext tier: repeat findings → 20% fines • systematic non-compliance → Art. 18 structural remedies
The first enforcement cycle: two fines, one specification regime, a standing docket — and the escalation ladder waiting behind it.

What compliance patterns are emerging on the gatekeeper side?

Three archetypes. Perimeter-testing: architectures that monetise or friction the mandated openness (Core Technology Fee, link-out fees, layered consent screens) — now visibly repriced by the first fines and by parallel national contempt findings. Quiet convergence: Microsoft’s unbundlings and Amazon’s pre-emptive adjustments, betting that early alignment buys regulatory goodwill and shapes workable specifications. Engineering negotiation: treating specification proceedings as standard-setting to be participated in, with security and privacy arguments deployed as design constraints rather than refusals.

The market-side response is equally instructive: developers and merchants have been slower to exercise their new rights than the legislation assumed — steering adoption, alternative-store uptake and data-access requests all lag — partly from switching costs, partly from fear of gatekeeper relationship damage. The Commission has responded by soliciting third-party evidence and prioritising obligations where beneficiary uptake proves the counterfactual. For dependent businesses the implication is direct: enforcement momentum partly depends on documented demand, and the firms filing structured evidence are steering where the regime bites next.

💡 Pro Tip: Track three public artifacts per gatekeeper annually: the compliance report, the Commission’s open proceedings list, and the specification decisions. Together they are a free, current map of which platform behaviours are safe to build on, which are about to change, and where your own evidence could tip an investigation — intelligence most competitors of gatekeeper-dependent businesses never read.

What should we expect in the next enforcement phase?

Escalation mechanics first: repeat non-compliance on the same obligation unlocks the 20% tier, and the systematic-non-compliance procedure (three findings in eight years) puts structural remedies and acquisition bans on the table — the endgame the breakups debate anticipates. Watch also the judgments: the General Court’s rulings on the first fines, the consent-model doctrine and the specification appeals will either consolidate the Commission’s muscular reading or force a narrower regime.

Perimeter evolution second: AI assistants and agentic interfaces are becoming the new gateways, and the Commission has both the market-investigation tool and political pressure to extend designations; cloud and virtual-assistant services already sit in the CPS catalogue awaiting numbers. And internationally, the enforcement experience is being encoded into the copies — Japan’s implementation, the UK’s conduct requirements, Türkiye’s pending amendments — so the DMA’s case-by-case answers are becoming the global default settings for platform regulation. Businesses planning multi-year platform strategies should assume today’s investigation topics are tomorrow’s cross-jurisdictional rules.

What do the appeals actually contest — and why do they matter?

Three layers. Interpretation: whether steering includes fee-free external transactions, whether pay-or-consent can ever satisfy Article 5(2), how far interoperability specification can reach into product design — each appeal asks the General Court to fix an obligation’s outer edge. Process: gatekeepers argue the specification and non-compliance procedures compressed defence rights; the judgments will calibrate how much dialogue the Commission owes before deciding. Proportionality: fine levels for first-cycle infringements, and whether compliance attempts in good faith mitigate.

The stakes exceed the parties: DMA obligations copied into other jurisdictions’ laws will be read through these judgments, and national courts hearing private DMA-based claims (the directive-free regulation is directly actionable) will follow them. A broadly pro-Commission outcome entrenches the muscular reading worldwide; significant reversals would shift gravity back toward negotiated specification. Either way, the first-cycle judgments are the DMA’s real constitutional moment — worth tracking more closely than any single fine.

How does private enforcement multiply DMA exposure?

The DMA is directly effective: businesses harmed by non-compliance can sue in national courts for damages and injunctions without waiting for the Commission, and the first wave of DMA-based claims — developer suits over steering restrictions, merchant claims on data access — is being filed alongside classic abuse actions. Commission decisions will function as liability anchors exactly as Article 102 findings do, and collective-action vehicles in the Netherlands, Germany and the UK (via parallel theories) are positioning for gatekeeper claims.

For gatekeepers, this changes the fine calculus: the €500 million headline is the visible fraction of exposure that includes retrospective damages across thousands of business users. For dependent businesses, it creates a self-help route worth pricing — a documented non-compliance loss plus a Commission finding is a claim, and the litigation-funding market has noticed. The follow-on economics that transformed cartel enforcement are arriving in platform regulation on schedule.

What lessons should non-gatekeeper platforms draw from the first cycle?

Two, and they cut in different directions. First, the perimeter grows: services near the user-count and turnover thresholds — fast-scaling marketplaces, super-apps, AI assistants — should model designation scenarios now, because obligations arrive with a six-month compliance runway and the architecture changes (consent flows, data separation, ranking neutrality) take years to retrofit gracefully. Building ‘DMA-ready’ optionality into data and ranking systems while still unregulated is dramatically cheaper than compliance under deadline.

Second, the enforcement record is a free playbook of what regulators consider evasion: fee structures neutralising rights, friction screens, consent architectures without real alternatives — each condemned pattern is a design anti-checklist for any platform anywhere, because national authorities (Türkiye’s Board included) read the same decisions and import the same theories into general abuse law. The DMA’s doctrines are propagating beyond its perimeter faster than its obligations are.

Frequently Asked Questions

Are the DMA fines small compared to Article 102 fines?

The first fines were calibrated to short infringement periods, not weakness: the ceiling is 10% of worldwide turnover (20% repeat) per infringement, and periodic penalties accrue daily. The signal-to-size ratio was deliberate — establish doctrine fast, escalate against recidivism.

Can gatekeepers charge any fee for mandated access?

Unresolved at the edges: FRAND terms are permitted for some obligations (app-store access), but fees that economically negate a right — the steering decision’s core — are non-compliance. The appeals will draw the fee-design line more precisely.

Has anyone escaped designation by shrinking EU operations?

No credible case yet — the thresholds capture established scale, and degrading EU service to duck regulation would be commercially self-defeating for the designated groups. Threshold-adjacent companies, however, do structure EU growth with designation risk in the model.

Do national authorities enforce the DMA too?

The Commission enforces exclusively, but national authorities assist, run parallel national tools (Germany’s §19a, Türkiye’s Article 6 practice) and feed evidence. For companies, the practical consequence is multi-door exposure for the same conduct pattern.

Last Updated: August 2026 · Reviewed by the Kurums Law editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading