Skip to main content
Category: Privacy Regulations

Digital Markets Act

Also known as: DMA, EU Digital Markets Act
Simply put

The Digital Markets Act is an EU law designed to make digital markets fairer and more open to competition. It focuses on the behavior of large, dominant technology companies, aiming to ensure they act fairly and transparently online. It is primarily a competition and market-fairness regulation rather than a general data protection law.

Formal definition

The Digital Markets Act (DMA) is a European Union regulation intended to make markets in the digital sector fairer and more contestable, addressing the conduct of dominant technology platforms to promote fairness, transparency, and competition. Its objectives include constraining the practices of large digital undertakings and supporting contestability and innovation in the digital economy. Note that the DMA is a competition and market-structure instrument and is distinct from the EU GDPR; while its provisions may intersect with privacy and consent-related practices, the evidence provided here does not detail specific designation criteria, obligations, enforcement mechanics, penalties, or effective dates, and those elements are out of scope for this definition.

Why it matters

The Digital Markets Act matters because it targets the market power of dominant digital platforms and seeks to make digital markets in the EU fairer and more contestable. For compliance and governance professionals, its significance lies in the fact that it operates alongside, but distinct from, the EU's data protection regime. Where the EU GDPR governs how personal data is processed and protected, the DMA is primarily a competition and market-structure instrument aimed at the conduct of large technology undertakings. Treating the two as interchangeable is a common error; a control that satisfies DMA fairness or transparency expectations does not by itself establish a lawful basis or otherwise ensure GDPR compliance, and vice versa.

The practical importance for privacy and governance teams comes from the areas where the DMA's fairness and transparency objectives intersect with data-related practices, including consent management and how platform conduct is presented to users. Because these areas touch both competition and privacy considerations, organizations may need to coordinate across legal, compliance, and privacy functions rather than treating the DMA as owned solely by competition counsel. Accountability under governance frameworks generally requires demonstrable evidence of how obligations are met, not merely stated intent, and that principle applies when mapping DMA-related activities against existing data protection controls.

The evidence available here does not detail the DMA's specific designation criteria, obligations, enforcement mechanics, penalties, or effective dates, so those elements are out of scope for this entry. Readers should consult the regulation's authoritative text and current guidance for those specifics rather than inferring them from a general description of the law's purpose.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads should understand where the DMA's fairness and transparency objectives intersect with data-related practices such as consent management, while keeping the DMA clearly separated from the EU GDPR. The two regimes have different purposes, and satisfying one does not establish compliance with the other.
Compliance and legal teams
Compliance officers and legal counsel supporting large digital platforms need to identify whether DMA obligations may apply and coordinate that assessment with competition, privacy, and governance functions. Because the specific designation criteria, obligations, and enforcement mechanics are not detailed in the evidence here, these teams should work from the authoritative regulatory text.
Information governance leads
Governance leads are relevant because DMA-related activities generally require demonstrable evidence of how obligations are met, not merely stated intent. Mapping any DMA-driven practices against existing policies, ownership, and stewardship structures helps maintain accountability without conflating governance responsibilities with security or data protection controls.
Platform product and engineering teams
Teams building and operating large digital platforms may be affected where fairness, transparency, and consent-related design choices fall within the DMA's scope. They should coordinate with legal and privacy stakeholders rather than assume that technical measures aligned to one regime automatically satisfy the other.

Inside DMA

Gatekeeper designation
The Digital Markets Act (DMA), an EU regulation focused on competition and contestability in digital markets, applies obligations to large platform operators designated as gatekeepers. The DMA is a market-conduct instrument rather than a data protection law, though it intersects with data-related conduct.
Core platform services
The DMA addresses conduct in relation to defined categories of platform services provided by gatekeepers. The scope of what qualifies is set by the regulation itself; this entry does not enumerate the specific service categories or the quantitative thresholds used for designation.
Data-related obligations and interaction with the EU GDPR
Certain DMA provisions touch on the use, combining, and portability of data by gatekeepers. Where these provisions concern personal data, they operate alongside the EU GDPR rather than replacing it; the GDPR continues to govern lawful basis, controller and processor obligations, and data subject rights. The DMA does not itself establish those data protection concepts.
Enforcement authority
The DMA is enforced primarily at EU level rather than solely by national data protection authorities. This entry does not describe specific procedures, remedies, or penalty figures, as those are out of scope and not asserted here without a substantiated reference.

Common questions

Answers to the questions practitioners most commonly ask about DMA.

Is the Digital Markets Act a data protection law like the GDPR?
No. The Digital Markets Act is an EU competition and market-fairness instrument aimed at regulating large digital platforms designated as gatekeepers, not a data protection regime. While it contains provisions that touch on personal data, its primary objective is contestability and fairness in digital markets rather than protecting the rights of data subjects. The GDPR remains the principal EU framework governing the processing of personal data, and it applies independently. Obligations under one instrument do not satisfy obligations under the other, and organizations should assess compliance with each separately. This entry does not cover the substantive data protection rules of the GDPR.
Does the Digital Markets Act apply to every online business operating in the EU?
Generally, no. The Digital Markets Act's core obligations are directed at entities designated as gatekeepers, a status tied to specific criteria and a formal designation process rather than applying to all online businesses by default. Many organizations that process personal data or operate online fall outside its gatekeeper scope while still being subject to other EU frameworks such as the GDPR. Determining whether the DMA applies to a given entity depends on that entity's designation status. This entry does not address the detailed designation thresholds or the procedural mechanics of designation.
How does the Digital Markets Act interact with an organization's existing GDPR compliance program?
The two instruments operate in parallel and address different aims, so a GDPR program does not by itself demonstrate DMA compliance. Where DMA provisions concern personal data, an organization typically needs to reconcile them with its GDPR lawful basis, transparency, and accountability obligations rather than treating either framework as subordinate. In practice this generally means coordinating competition, legal, and data protection functions so that measures taken for one framework do not create gaps in the other. This entry does not specify how particular DMA provisions map onto specific GDPR articles.
Which internal roles should be involved in assessing Digital Markets Act obligations?
Because the Digital Markets Act spans competition, product, legal, and data protection concerns, assessment typically involves legal and competition counsel alongside privacy and governance functions rather than resting with a single role. A data protection officer may be consulted where provisions involve personal data, but the DMA's broader market-fairness obligations generally fall outside a DPO's core remit. Clear allocation of accountability, with demonstrable evidence of who owns which obligation, is advisable under governance principles. This entry does not prescribe a specific organizational structure.
What kind of evidence should an organization maintain to demonstrate handling of Digital Markets Act obligations?
Consistent with accountability expectations under governance frameworks, demonstrable evidence rather than stated intent is generally what withstands scrutiny. This typically includes documented assessments of applicability, records of decisions taken, and evidence of measures implemented in response to relevant obligations. Where obligations touch personal data, such documentation would generally need to align with existing data protection records without duplicating or replacing them. This entry does not define specific record-keeping formats or retention periods required under the DMA.
Should Digital Markets Act considerations be integrated into existing data governance processes?
Where DMA provisions concern data handling, integrating them into existing governance processes covering ownership, stewardship, lineage, and policy can help avoid fragmented compliance, provided the distinction between competition-driven obligations and data protection obligations is preserved. Governance and information security functions may overlap in supporting these efforts, but they address different concerns and should not be collapsed into one. Any integration should be documented so accountability is demonstrable. This entry does not address cross-border transfer mechanics, retention rules, or enforcement outcomes under the DMA.

Common misconceptions

The DMA is a data protection law that overrides or replaces the EU GDPR.
The DMA is a competition and market-contestability regulation. Where its provisions involve personal data, it operates alongside the EU GDPR; the GDPR remains the governing instrument for lawful basis, controller and processor obligations, and data subject rights. The two address different objectives and should not be treated as interchangeable.
Every large online business is subject to the DMA.
The DMA applies to operators formally designated as gatekeepers under criteria set in the regulation, not to all large or online businesses generally. Applicability depends on designation, not size alone.
DMA data-portability or data-use requirements make ported or shared data non-personal.
Requirements affecting how gatekeepers handle data do not change the legal character of that data. If information relates to an identifiable individual it remains personal data subject to the EU GDPR, regardless of the mechanism or obligation under which it is processed or transferred.

Best practices

Determine whether your organization is formally designated as a gatekeeper before assuming DMA obligations apply, since applicability turns on designation rather than size alone.
Treat DMA compliance and EU GDPR compliance as distinct but interacting workstreams, ensuring that data-related DMA measures are assessed against GDPR lawful basis, controller and processor responsibilities, and data subject rights.
Map which DMA data provisions involve personal data and coordinate legal, privacy, and competition functions so that obligations under both regimes are reconciled rather than treated in isolation.
Maintain demonstrable evidence of how data-handling practices satisfy both DMA and GDPR requirements, recognizing that accountability generally requires documented proof rather than stated intent.
Consult the DMA text and qualified counsel for the specific service categories, thresholds, procedures, and penalties, as these are not covered in this entry and should not be inferred from general framing.
Do not rely on data-portability, tokenization, or data-separation measures to conclude that personal data has ceased to be personal data for GDPR purposes.