The Digital Markets Act is the European Union regulation that imposes binding obligations on large online platforms designated as gatekeepers to keep digital markets fair and contestable. Enacted as Regulation (EU) 2022/1925, the regulation entered into force on 1 November 2022 and became applicable on 2 May 2023, according to the European Commission's official DMA overview. For the Big Tech companies that operate at scale across Europe, the designation as a gatekeeper carries legally binding consequences that shape product design, data practices, and third-party access rules.
What the Digital Markets Act Is and Why It Exists
The Digital Markets Act is the European Union's primary tool for imposing ex ante obligations on the largest online platforms before competitive harm occurs, rather than correcting it after the fact. Traditional competition enforcement operates retrospectively: regulators investigate conduct, build a case, and seek remedies after market distortions are already established. The DMA changes that logic by setting rules in advance for the largest Big Tech platforms, requiring compliance from designated platforms regardless of whether specific anticompetitive harm has been proved.
The market-failure rationale is platform contestability. When a single platform controls a critical digital gateway, rival services cannot realistically compete on equal terms, and business users have no meaningful alternative. By writing each ex ante obligation into law in advance, the regulation addresses that structural problem directly, describing its purpose as making digital markets "fairer and more contestable."
- Digital Markets Act (DMA)
- An EU regulation that defines objective criteria for identifying gatekeepers, lists binding obligations and prohibitions, and grants the European Commission enforcement powers over designated platforms. It applies to core platform services, not to all digital business activity.
- Gatekeeper
- A large digital platform that meets the DMA's size, reach, and entrenchment thresholds and has been formally designated by the Commission. Designation triggers the full set of DMA obligations and prohibitions.
- Core platform service (CPS)
- A defined category of digital service that the DMA regulates, such as online search, app stores, or messaging. Only services within these categories are subject to the regulation's rules; other parts of a company's business are not covered.
The DMA complements, but does not replace, existing EU competition rules, which continue to apply in full. Where the regulation establishes fixed obligations for designated platforms, competition law remains available for conduct outside the DMA's perimeter, including harm to markets not covered by the core platform service categories. The two frameworks operate in parallel, as the Commission confirms on the DMA overview page.
How the Commission Identifies a Gatekeeper
The Commission applies a defined set of objective criteria to determine whether a platform qualifies as a gatekeeper, covering the size of the company, the reach of the service, and how deeply the platform is embedded in the market. The process follows a formal procedure: platforms that meet the quantitative thresholds must self-notify the Commission, which then has 45 working days to adopt a designation decision, as specified in the DMA's official documentation. Once designated, the company has up to six months to achieve compliance with all obligations and prohibitions.
Being a large technology company does not automatically trigger designation. A platform must provide at least one core platform service (CPS) and satisfy the thresholds. The criteria fall into three categories:
- Size
- The company must have significant financial weight, reflecting its capacity to sustain a large-scale platform operation across the EU.
- Intermediation reach
- The platform must serve a substantial number of active business users and end users in the EU, giving it the market position necessary to act as a gateway between those two groups.
- Entrenchment
- The platform's position must be durable or foreseeable. A service that has held its position across multiple years, or is expected to do so, meets this criterion.
In September 2023, per the Commission's gatekeeper compliance announcement, the European Commission formally designated six companies as gatekeepers under the DMA: Apple, Alphabet, Meta, Amazon, Microsoft, and ByteDance. Those six companies, and the specific core platform services they provide, became subject to the full compliance timeline from that designation date.
The 10 Core Platform Services Covered by the DMA
The DMA draws a precise perimeter by listing 10 core platform service categories, which determine which parts of a designated company's business fall under its rules. A company may operate dozens of products globally, but only the services that fall within these categories are subject to the regulation's obligations. The Commission's gatekeeper announcement confirms the regulation "establishes new rules for 10 defined core platform services."
- Online search engines
- Online marketplaces
- App stores
- Online advertising services
- Social networking services
- Video-sharing platform services
- Operating systems
- Cloud computing services
- Online intermediation services
- Web browsers
Each service category carries its own set of applicable obligations. A company operating an app store faces different specific requirements than one operating a messaging service, though the underlying framework of platform contestability and data access applies across all categories. The algorithmic accountability in AI systems discussion is directly relevant here: ranking rules for search engines and app stores under the DMA intersect with how algorithmic decisions are scrutinized for fairness.
Gatekeeper Obligations: What Platforms Must Now Do
Once designated, a gatekeeper faces a set of affirmative obligations that require opening up its ecosystem to business users, rival services, and end users. These are binding legal requirements backed by enforcement powers, not voluntary guidelines. The DMA overview lists the core affirmative duties that designated platforms must fulfill.
- Data access for business users. A designated platform must allow its business users to access the data they generate through their use of the platform. Sellers on an online marketplace, for example, must be able to retrieve the performance and transaction data their own activity produced.
- Off-platform contracting rights. Business users must be able to promote their offers and conclude contracts with customers outside the platform, without restriction or penalty from the gatekeeper.
- Data portability for end users. End users must be able to take their data with them when they leave a service. The data portability requirement gives individuals and businesses a practical alternative to staying locked into a single ecosystem.
- Interoperability with third-party services. Designated platforms providing messaging services must allow interoperability with third-party messaging providers, so that users on different platforms can communicate across service boundaries. This interoperability obligation is among the most structurally significant in the regulation.
- Transparency in online advertising. Platforms providing online advertising tools must give advertisers and publishers access to the performance data and tools they need to conduct independent verification of ad delivery and pricing.
The GDPR established a data portability principle for personal data in the privacy context; the DMA extends a similar logic to the competitive context. For background on how EU data rules have affected US-based technology companies, the GDPR impact on US tech companies provides a useful reference point.
What Gatekeepers Are Prohibited From Doing
The DMA's prohibitions target the practices most commonly associated with platform lock-in and self-preferencing behavior. Where the affirmative obligations require designated platforms to open access, the prohibitions prevent them from using their market position to tilt the competitive field. The DMA overview enumerates the key prohibitions.
- No self-preferencing in ranking. A designated platform may not treat its own products or services more favorably than equivalent third-party offerings in search results, app store listings, or other ranked surfaces. The self-preferencing ban directly addresses the market distortion that occurs when a platform uses its position to advantage its own verticals.
- No blocking of pre-installed app removal. Users must be able to uninstall any pre-installed software or application on the platform's device or operating system if they choose to do so.
- No preventing off-platform linking. Designated platforms may not block or restrict consumers from navigating to, or transacting with, businesses outside the platform's own environment.
- No cross-context tracking for targeted advertising without consent. A platform may not track end users across services outside its core platform service for the purpose of targeted advertising unless the user has granted effective consent. This prohibition draws a line between contextual advertising within a platform and behavioral tracking that spans unrelated services.
The prohibition on cross-context tracking for targeted advertising without consent gives the DMA an intersection with privacy regulation, though the law's primary purpose is market contestability rather than data protection. The two objectives reinforce each other in practice: when users control their data and can switch services without penalty, platform contestability improves alongside privacy. For a broader look at how EU regulatory frameworks compare to US approaches, the EU AI Act and US AI executive orders compared covers the regulatory philosophy across multiple EU instruments.
Enforcement: Timelines, Investigations, and How the Rules Stay Current
The Commission enforces the DMA through a combination of compliance monitoring, formal investigations, and the power to open new market investigations as digital markets evolve. Non-compliance exposes designated platforms to penalties up to a share of global annual turnover, with more severe remedies available for repeated or systematic violations. The legislative basis for these enforcement powers is set out in Regulation (EU) 2022/1925.
The table below contrasts the DMA's ex ante enforcement approach with the ex post model used in standard EU competition law.
| Dimension | DMA (ex ante) | EU Competition Law (ex post) |
|---|---|---|
| Scope | Applies only to designated gatekeepers and their core platform services | Applies across all sectors and all market participants |
| Trigger event | Gatekeeper designation by the Commission; obligations apply automatically | Formal complaint or Commission investigation into specific conduct |
| Enforcement timeline | Compliance required within six months of designation; ongoing monitoring thereafter | Investigation and remedy process can span years before a final decision |
| Remedy type | Specific behavioral obligations and prohibitions defined in the regulation; financial penalties for breach | Case-by-case behavioral or structural remedies ordered after a finding of infringement |
To keep the rules aligned with the pace of digital markets, the Commission also has the authority to conduct market investigations. These allow the regulator to examine whether new practices warrant updated rules, whether new services should be classified as core platform services, and whether additional companies should be considered for gatekeeper designation. Market investigation powers give the DMA a built-in mechanism for staying current without requiring full legislative revision each time the market shifts.
References
- European Commission: About the Digital Markets Act
- European Commission: Designated Gatekeepers Must Now Comply With All Obligations Under the Digital Markets Act
- European Commission: DMA Legislation (Regulation EU 2022/1925)
- European Commission: Digital Services Act Overview
Further reading
Frequently Asked Questions
What does the Digital Markets Act regulate?
The Digital Markets Act regulates large online platforms that the European Commission designates as gatekeepers. It imposes specific obligations and prohibitions on their core platform services such as search engines, app stores, messaging, online advertising, and online marketplaces. It does not apply to all digital companies, only those that meet objective size and entrenchment thresholds. The law entered into force on 1 November 2022 and became applicable on 2 May 2023.
Which companies qualify as gatekeepers under the DMA?
The European Commission designates gatekeepers based on objective criteria tied to size, user reach, and market entrenchment. As of September 2023, per the Commission's gatekeeper compliance announcement, six companies hold that designation: Apple, Alphabet, Meta, Amazon, Microsoft, and ByteDance. A company is not automatically a gatekeeper simply because it is large; the Commission must issue a formal designation decision, after which the company has up to six months to achieve compliance.
What happens if a gatekeeper violates the DMA?
The European Commission can impose fines for non-compliance, with penalties based on the company's global annual turnover. Repeated or systematic violations can result in more severe remedies. The Commission also has the authority to open market investigations to assess whether new rules are needed as digital markets evolve.
Does the Digital Markets Act replace EU competition law?
No. The DMA operates alongside existing EU competition rules, which continue to apply in full. Where the DMA establishes ex ante obligations for gatekeepers, competition law provides ex post enforcement for anticompetitive conduct across the broader market. The two frameworks complement each other rather than one superseding the other.









