Regulation (EU) 2022/1925 imposed the EU's first comprehensive ex ante obligations on "gatekeepers": the handful of large platforms that control the digital gateways through which businesses reach consumers. Contestability and fairness, not just the absence of dominance, are the new standard.
the EU's ex ante framework for contestable and fair digital markets
Digital markets are shaped by properties that make them structurally different from most other industries. Extreme economies of scale mean that adding an extra user costs almost nothing for the largest platforms. Very strong network effects mean that a service becomes more valuable as more people use it, creating a self-reinforcing advantage. Multi-sided architecture, where a platform connects two or more distinct groups such as consumers and sellers, amplifies both effects. Data-driven advantages accrue because a platform that already has a billion users generates data that a challenger cannot replicate. Lock-in effects and the absence of multi-homing on the consumer side make switching difficult and costly.
Taken together, these features can entrench a small number of very large undertakings in gateway positions. Classic competition law requires proof of dominance and harm on a case-by-case basis; it is reactive and takes years. The DMA takes a different approach: it identifies the characteristics of a "gatekeeper" in advance and imposes a list of obligations that must be followed irrespective of whether any particular practice has caused measurable harm. This is what the regulation means by "ex ante."
The legal basis is Article 114 TFEU (internal-market approximation). Before the DMA, a patchwork of national digital market laws had begun to emerge across Member States, creating fragmentation. A single EU-level instrument applicable to all gatekeepers regardless of where they are established restores a level playing field for all businesses operating in the EU.
The DMA explicitly preserves the application of Articles 101 and 102 TFEU and national competition rules (Article 1(6)). Both regimes can run in parallel. A practice might simultaneously breach a DMA obligation and constitute an abuse of dominant position under Article 102, and the Commission can pursue both. The key difference is that DMA enforcement does not require the Commission to define a market, establish dominance, or prove harm; it only requires a showing of non-compliance with the listed obligations.
The DMA also does not preclude Member States from applying national laws pursuing objectives other than contestability and fairness as defined in the regulation. What it does prevent is Member States imposing further obligations on gatekeepers specifically because of their gatekeeper status under the DMA (Article 1(5)).
The DMA applies to core platform services provided or offered by gatekeepers to business users established in the EU or end users established or located in the EU, regardless of where the gatekeeper itself is established (Article 1(2)). An American company operating an app store used by developers and consumers in the EU is fully in scope. National courts and regulators must not take decisions that contradict a Commission decision adopted under the DMA (Article 1(7)).
the ten categories of digital service that fall within the DMA's scope
The definition of CPS is technology-neutral and encompasses services delivered through any means or device, including connected TVs and embedded digital services in vehicles (recital 14). Collaborative projects operating for non-commercial purposes are excluded from the CPS definition entirely (recital 2).
the three-criterion test, the quantitative presumption and the market investigation route
An undertaking is designated as a gatekeeper if it satisfies all three of the following qualitative criteria simultaneously:
An undertaking is presumed to satisfy the three qualitative criteria if it crosses all of the following thresholds in the relevant period:
| Criterion | Threshold | Period |
|---|---|---|
| Annual EEA turnover | EUR 7.5 billion | Each of the last 3 financial years |
| Market capitalisation (alternative) | EUR 75 billion | Average in the last financial year |
| Monthly active end users in the EU | 45 million | Each of the last 3 financial years |
| Yearly active business users in the EU | 10,000 | Each of the last 3 financial years |
| CPS presence in Member States | At least 3 | Current |
The presumption is rebuttable. An undertaking that meets all quantitative thresholds may submit substantiated arguments demonstrating that, in the specific circumstances of its service, it does not actually satisfy the qualitative criteria. The Commission must reject insufficiently substantiated arguments within 45 working days; if the arguments are sufficiently substantiated, a full market investigation follows.
Undertakings that do not meet the quantitative thresholds can still be designated through a market investigation under Article 3(8). The Commission assesses qualitative factors including network effects, data advantages, lock-in effects, switching costs, conglomerate structure and vertical integration. It may also designate emerging gatekeepers: undertakings that do not yet enjoy an entrenched position but for which it is foreseeably imminent. For emerging gatekeepers, the Commission may impose only a subset of the obligations sufficient to prevent the entrenchment from occurring.
Any undertaking that meets all the quantitative thresholds must notify the Commission within 2 months of doing so (Article 3(3)). The Commission then designates the undertaking within 45 working days of receiving complete information. Failure to self-notify exposes the undertaking to a fine of up to 1% of total worldwide annual turnover.
The Commission reviews gatekeeper status at least every 3 years (Article 4(2)). It also examines annually whether new undertakings meet the designation criteria. Where the facts on which designation was based have changed, the Commission may amend or repeal the designation decision. Those reviews do not suspend the gatekeeper's obligations in the meantime. The Commission publishes and continuously updates a public list of gatekeepers and their designated core platform services (Article 4(3)).
prohibitions that apply directly as drafted, without requiring further Commission specification
A gatekeeper must not process end users' personal data from third-party services for online advertising; must not combine personal data from one core platform service with data from another CPS, another gatekeeper service or third-party services; and must not cross-use personal data from a CPS in separately provided services, unless the end user has given freely given, specific, informed and unambiguous consent meeting the GDPR standard (Article 4(11) and Article 7 of Regulation (EU) 2016/679).
Where consent was refused or withdrawn, the gatekeeper may not request consent again for the same purpose more than once within a year. This rule directly addresses the "data combination" business model that allowed gatekeeper platforms to aggregate profiles across dozens of different services without meaningful user control.
A gatekeeper may not prevent business users of its online intermediation services from offering the same products or services at different prices or conditions through third-party online intermediation services or through the business user's own direct online sales channel. This directly ended platform parity clauses: the requirement by hotel booking platforms that hotels not offer cheaper rates on their own websites, and similar requirements by app stores and marketplaces.
Gatekeepers must allow business users, free of charge, to communicate offers (including under different conditions) to end users they have already acquired through the gatekeeper's CPS, and to conclude contracts with those users regardless of whether this happens through the gatekeeper's platform. Business users must be able to steer acquired customers to their own channels.
Gatekeepers must allow end users to access and use, through the gatekeeper's CPS, content, subscriptions, features or other items purchased from a business user outside the gatekeeper's platform. An app store operator may not block a user from accessing a book, music subscription or game that was bought directly from the developer's website, simply because the purchase happened outside the app store.
Gatekeepers may not require end users to use the gatekeeper's identification service, web browser engine or payment service, and may not require business users to use, offer or interoperate with those services, as a condition for accessing or providing services through the gatekeeper's CPS. This means developers must be free to use third-party payment processors instead of the gatekeeper's own in-app payment system.
Registering with one core platform service may not be made a condition for accessing another. A gatekeeper that operates both a cloud service and a productivity suite may not require a user to create an account for the second in order to access the first.
Gatekeepers providing online advertising services must provide advertisers and publishers, free of charge and upon request, with daily information on: the price and fees paid or received for each advertisement, including any deductions and surcharges; the remuneration received by the publisher (subject to the publisher's consent); and the metrics used to calculate each figure. Where a party withholds consent, the gatekeeper must provide the daily average remuneration instead. This addresses the opacity of programmatic advertising and allows advertisers and publishers to evaluate whether the fees they pay or receive represent fair value.
structural obligations that the Commission may specify further following a regulatory dialogue
Article 6 obligations apply directly and must be complied with immediately. However, because their implementation may vary depending on the technical architecture of different services, the Commission may, on its own initiative or at the gatekeeper's request, open a procedure to specify in a Commission implementing act exactly how a particular gatekeeper must comply with a particular Article 6 obligation (Article 8). This specification process does not suspend the obligation; the gatekeeper must comply in the meantime using its own best efforts. The Commission adopts the specifying implementing act within 6 months of opening proceedings.
A gatekeeper must not use, in competition with its own business users, data that is not publicly available and that was generated or provided by those business users in the context of their use of the gatekeeper's CPS. The non-public data includes aggregated and non-aggregated click, search, view and voice data, as well as customers' data generated through business users' activities on the platform. This prohibition addresses the Amazon Marketplace-type situation where a platform operator uses sales data from third-party sellers to develop competing products for its own retail arm.
Gatekeepers must allow and technically enable end users to easily uninstall any software applications on the gatekeeper's operating system, except applications that are essential to the functioning of the operating system or the device and that technically cannot be offered by a third party on a standalone basis. Gatekeepers must also allow end users to easily change default settings for search engines, virtual assistants and web browsers by presenting a choice screen at the end users' first use of those services.
Gatekeepers must allow and technically enable the installation and effective use of third-party software applications or app stores on their operating system, and must permit those applications to be accessed through means other than the gatekeeper's own CPS. A gatekeeper may implement proportionate technical measures to protect the hardware and OS integrity, but only if duly justified; it may not implement such measures as default settings or as pre-installation barriers.
A gatekeeper must not treat its own products, services or content more favourably than comparable third-party products, services or content in ranking, indexing or crawling. Ranking covers all forms of relative prominence: position in search results, display prominence in a feed, rating, linking and voice results. Conditions applied to ranking must be transparent, fair and non-discriminatory. The prohibition applies to the ranking process itself, including how the gatekeeper's crawlers index content before a user makes any query.
Gatekeepers must not technically or otherwise restrict end users' ability to switch between and subscribe to different software applications and services accessed through the gatekeeper's CPS, including in the choice of internet access service. Artificial technical barriers that make switching to a rival service difficult are prohibited.
Gatekeepers must provide hardware and service providers with free, effective interoperability with the same operating-system, hardware and software features that are used in the provision of the gatekeeper's own complementary and supporting services. This covers near-field communication chips, secure elements, processors, authentication mechanisms and the software used to operate them. Third-party smartwatch, headphone and smart-home device makers must receive the same OS-level access as the gatekeeper's own devices.
Gatekeepers must provide advertisers and publishers, free of charge and upon request, with access to the gatekeeper's performance measurement tools and to the data necessary to carry out independent verification of the advertising inventory, including aggregated and non-aggregated data. This allows advertisers to run their own verification tools and assess whether the reach and performance data presented by the platform is accurate.
Gatekeepers must provide end users and their authorised third parties with free, continuous and real-time portability of data provided by or generated through the end user's use of the CPS (Article 6(9)). This complements but goes beyond the GDPR right to data portability by requiring real-time and continuous access.
Gatekeepers must also provide business users and their authorised processors with free, effective, high-quality, continuous and real-time access to aggregated and non-aggregated data, including personal data, generated in the context of those business users' use of the CPS (Article 6(10)). Personal-data access requires end-user opt-in. This allows a business user to retrieve all the data its customers have generated through its products on the gatekeeper's platform.
Gatekeepers operating designated search engines must provide any third-party search engine provider with access, on fair, reasonable and non-discriminatory terms, to ranking, query, click and view data generated by end users on the gatekeeper's search engine. This data must be provided in anonymised form for personal data. The provision directly addresses the information asymmetry between the dominant search engine and its rivals: without access to query-and-click feedback data at scale, a challenger search engine cannot train its ranking model to the same level of quality.
For app stores, online search engines and online social networks, gatekeepers must apply fair, reasonable and non-discriminatory general conditions of access for business users, publish those conditions publicly and provide an alternative dispute resolution mechanism. The Commission assesses whether published conditions comply with the FRAND standard (Article 6(12)).
General conditions for terminating a core platform service must not be disproportionate, and termination must be no harder for users than signing up or subscribing in the first place (Article 6(13)).
the phased obligation to open messaging services to third-party providers
Messaging applications exhibit extreme network effects: the value of a service depends almost entirely on how many of your contacts use it. A new entrant that cannot connect to the users of the dominant messaging platform is structurally disadvantaged from the outset. Article 7 breaks this barrier by requiring gatekeeper messaging services to open interoperability to any third-party messaging provider that offers or intends to offer services to users in the EU and requests interoperability.
| Timeline | Functionality required |
|---|---|
| From designation (within 6 months) | One-to-one text messaging; sharing of images, voice messages, videos and other files between two individual end users |
| Within 2 years from designation | Group text messaging; file sharing between a group and an individual end user |
| Within 4 years from designation | One-to-one voice calls; one-to-one video calls; group voice calls; group video calls |
The gatekeeper must comply with a reasonable interoperability request within 3 months of receiving it (Article 7(5)). It must publish a reference offer setting out technical details and general terms within 6 months of designation (Article 7(4)).
The level of security, including end-to-end encryption where applicable, must be preserved across interoperable services (Article 7(3)). The gatekeeper may take strictly necessary and proportionate measures to ensure that third-party providers do not endanger the integrity, security or privacy of its services (Article 7(9)). End users remain free to choose whether to use the interoperable functionality.
In June 2026, the Commission imposed the first-ever DMA interim measures (Article 24), ordering Meta to restore free access to WhatsApp for rival general-purpose AI assistants within 5 working days. Meta had been excluding third-party AI assistants and proposed a "pay-to-play" access fee. The Commission rejected the fee model as not economically sustainable for competitors and set the measures to remain in force until June 2029 or until the investigation closes. This was the first formal use of the Article 24 interim-measures power.
the Commission as sole enforcer, a tiered penalty regime and structural remedies for systematic non-compliance
The Commission is the sole authority empowered to enforce the DMA (Article 1(7)). National competition authorities may investigate suspected non-compliance and refer findings to the Commission, but they cannot adopt DMA decisions. National courts must not take decisions that run counter to a Commission DMA decision. This centralised model ensures uniform application and avoids divergent enforcement across Member States. The Commission may ask national authorities to assist with investigations.
| Type of violation | Maximum fine |
|---|---|
| Non-compliance with Articles 5, 6 or 7 (first offence) | 10% of total worldwide annual turnover |
| Repeat infringement (same or similar obligation, same CPS, within 8 years) | 20% of total worldwide annual turnover |
| Procedural violations (failure to notify, incorrect information, obstruction, failure to set up compliance function) | 1% of total worldwide annual turnover |
To compel compliance, the Commission may impose periodic penalty payments of up to 5% of average daily worldwide turnover per day. Where the Commission has issued at least three non-compliance decisions in 8 years and the gatekeeper has maintained or strengthened its position, the Commission may impose any behavioural or structural remedy proportionate and necessary for effective compliance: this can include structural separation, prohibition on further acquisitions or divestiture of specific assets.
Every designated gatekeeper must establish an independent compliance function with a compliance officer reporting directly to the management body; the officer cannot be removed without prior board approval. Gatekeepers may not structure, divide or fragment their CPS to circumvent designation thresholds, and may not use dark patterns or interface design to undermine obligations. Presenting end-user choices in a non-neutral manner constitutes a breach of the anti-circumvention rule.
the practical impact of DMA obligations on those who depend on gatekeeper platforms
from the Commission proposal to the first enforcement actions
key terms in the DMA framework
common questions about how the DMA works in practice
No. The DMA applies only to designated gatekeepers in respect of their designated core platform services. A digital platform that does not meet the gatekeeper thresholds, or that has not been designated, bears no DMA obligations. As of mid-2026, only six undertakings have been designated. Smaller platforms are entirely outside scope.
Yes. The DMA applies to CPS provided or offered to business users or end users established or located in the EU, regardless of the gatekeeper's place of establishment (Article 1(2)). All six currently designated gatekeepers are non-EU companies headquartered in the United States. The regulation is a classic example of the "Brussels Effect": EU rules applied extraterritorially based on market effects.
The DMA and the GDPR both regulate how gatekeepers handle personal data, but they pursue different objectives and use different mechanisms. The GDPR establishes rights for individuals and sets lawful bases for processing personal data. The DMA's Article 5(2) data-combination prohibition cross-references GDPR consent (Article 4(11) and Article 7 of the GDPR). A gatekeeper that combines data without the required consent violates both the DMA and the GDPR, and can be fined under each. The two enforcement regimes run in parallel.
No. Article 1(6) explicitly states that the DMA is without prejudice to Articles 101 and 102 TFEU and corresponding national competition rules. The DMA is an additional instrument, not a replacement. The Commission can simultaneously pursue DMA enforcement and a competition investigation against the same gatekeeper for the same or different conduct. The DMA's ex ante nature means it is faster and does not require the Commission to establish dominance or market definition, but competition law remains available for practices not covered by the DMA.
For Article 6 obligations, a gatekeeper may ask the Commission to engage in a process in which the Commission specifies exactly how the gatekeeper should comply (Article 8(2)-(3)). This allows gatekeeper-specific implementation plans for obligations whose technical application may vary by service architecture. The dialogue does not suspend the obligation: the gatekeeper must comply in the meantime. The Commission adopts the specifying act within 6 months of opening proceedings. If the specified measures prove ineffective, the Commission may reopen the proceedings.
The Commission's first DMA review (April 2026) concluded that AI services should not be added to the CPS list at this stage. The Commission reasoned that the DMA cannot tackle every competition issue in the AI value chain and that case-by-case competition enforcement is preferred for AI. The existing CPS categories (virtual assistants, online intermediation services, online advertising) already cover some AI-adjacent services operated by designated gatekeepers. The Digital Fitness Check announced in the same review will assess the broader digital regulatory landscape including AI.
primary sources for the regulation and ongoing enforcement
The consolidated text of Regulation (EU) 2022/1925 on EUR-Lex, including any subsequent amendments. Contains the full operative text, 109 recitals and the Annex on methodology for counting active users.
The Commission's official DMA portal lists designated gatekeepers, their designated core platform services, ongoing proceedings, compliance templates, and annual reports. The definitive reference for enforcement status.
The Commission's first Article 53 review of the DMA, published 28 April 2026. Confirms the DMA remains fit for purpose, concludes that AI services are not to be added as CPS, and announces cloud-computing designation decisions expected November 2026.
The European Parliament's legislative observatory tracks the DMA's adoption history, trilogue documents, rapporteur work and committee opinions from proposal to final text.
use Brubru's AI-powered tools to navigate the DMA and EU digital law