DMA Article 6EU

DMA Business User Data Access

This page helps scope Article 6 data-access work for a designated gatekeeper core platform service without turning it into a generic privacy, API, or reporting checklist.

It separates business-user access under Article 6(10), end-user portability under Article 6(9), non-public business-user data restrictions under Article 6(2), and the evidence expected in DMA compliance reporting.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

DMA Article 6(10) gives a access to a defined set of data, not every dataset a gatekeeper holds. On request and free of charge, the gatekeeper must give business users and their authorised third parties effective, high-quality, continuous and real-time access to and use of aggregated and non-aggregated data provided for or generated through the relevant core platform service by those business users and by end users engaging with their products or services. Personal data is covered only when it is directly connected to the end user's use of the relevant business user's product or service and the end user opts in to the sharing by giving consent.

Section 1

What Article 6 data-access obligations cover

Start with the core platform service listed in the gatekeeper's designation decision. Article 6(10) covers data provided for or generated through that service, or through services provided together with or in support of it, by the and by end users engaging with that business user's products or services.

Do not collapse into Article 6(9). Article 6(9) is end-user portability for data provided by the end user or generated through the end user's activity, including continuous and real-time access. Article 6(10) is the business-user data-access obligation, including authorised third-party access on the 's request.

Article 6(10) does not create access to unrelated gatekeeper datasets, data generated outside the relevant service context, or every personal-data field the gatekeeper holds. It also does not replace the GDPR or ePrivacy rules: the DMA opt-in condition for personal-data sharing must be handled together with the applicable data-protection and privacy requirements.

  • Confirm the gatekeeper and the exact core platform service listed in the designation context.
  • Identify the requesting and any third party authorised by that business user.
  • Separate business-user access under Article 6(10) from end-user portability under Article 6(9).
  • Limit personal data access and use to data directly connected with the end user's use of the relevant 's product or service through the relevant core platform service, and only where the end user opts in to that sharing by giving consent.
  • Treat Article 6(8) advertising measurement data separately when the request comes from advertisers, publishers, or their authorised third parties.
Section 2

Access scope and request handoff

A useful intake record should describe the 's product or service, the relevant gatekeeper interface, the requested data categories, whether the data is aggregated or non-aggregated, and whether personal data is included. It should also state whether the requester is the business user or an authorised third party.

The Commission's business-resource page lists gatekeeper access routes such as data-access documentation, dashboards, portals, APIs, and request forms. The page helps locate a route; it does not determine whether that route complies with Article 6(10). Test whether the route provides covered data and permits its use with the required effectiveness, quality, continuity, and real-time availability.

  • Capture the request date, requesting entity, authorisation basis, core platform service, and affected business account or property.
  • Classify requested data as provided or generated by the , generated by end users engaging with that business user's offer, advertising-measurement data, or outside Article 6(10). Record whether the relevant activity occurred through the listed core platform service or a service provided with or in support of it.
  • For personal data, record the consent path or the reason only anonymised or non-personal data is being used.
  • Check whether the available portal, export, API, or support channel covers both aggregated and non-aggregated data where required.
  • Keep response-time, data-quality, completeness, error, and denial records because Article 6(10) is not satisfied by a nominal access link alone.
  • Do not invent a universal request-response deadline: Article 6(10) states that access must be effective, high-quality, continuous, and real-time, but it does not set a single number of days for every intake decision.
Section 3

Restrictions that product reviews must catch

Article 6 data rules also restrict gatekeeper use. Article 6(2) prohibits a gatekeeper from using, in competition with business users, non-public data generated or provided by those business users in the relevant service context, including data generated or provided by their customers. The paragraph expressly includes aggregated and non-aggregated data that can be inferred from or collected through commercial activity, such as click, search, view, and voice data.

Product review should therefore test both directions: whether business users can obtain the data Article 6(10) covers, and whether internal gatekeeper uses of non-public business-user data are blocked where Article 6(2) applies. A launch that expands ranking, ads, analytics, marketplace insights, AI training inputs, recommendation features, or internal competitive benchmarking can reopen both questions.

  • Add an Article 6(2) check when non-public business-user or customer interaction data, including inferred data, feeds a gatekeeper product or service that competes with those business users.
  • Add an Article 6(10) check when a new dashboard, API, report, export, or permission model changes business-user access to generated data.
  • Flag any design that makes personal-data consent more difficult for business users than for the gatekeeper's own services.
  • Review data retention, access revocation, account ownership, third-party authorisation, and error handling before release.
  • Do not claim compliance from an API name, a help page, or a data-export button unless the actual data scope and access quality have been tested.
Section 4

Evidence to keep for Article 6(10)

Evidence should prove the substance of access, not just the existence of a policy. Keep the business-user request, authorisation documents for third parties, data-category mapping, consent handling for personal data, delivery method, error logs, denials, partial responses, and follow-up communications.

The DMA compliance-report template points to a broader evidence package: measures implemented, changes to business-user terms, consultations, actions to inform business users, security or privacy measures, testing, indicators, underlying data, and monitoring systems. For Article 6(10), those records should connect the legal scope to the actual access mechanism and to measurable outcomes such as request counts, fulfilled requests, rejected requests, latency, completeness, and data-quality issues.

  • Maintain a data-category matrix showing source, aggregation level, personal-data status, consent dependency, delivery route, and exclusion reason.
  • Retain evidence of business-user and authorised-third-party identity checks without making authorisation a hidden barrier.
  • Save screenshots, API documentation versions, export schemas, response samples, and incident records that show what access actually delivered.
  • Track indicators by core platform service and, where useful, by business-user segment or request type.
  • Keep non-confidential summaries aligned with the underlying compliance evidence when Article 11 reporting is updated.
Section 5

Business-user data-access review checklist

Review this checklist before approving a DMA data-access mechanism, a business-user dashboard, a data export, a third-party authorisation flow, or a product change that touches business-user generated data.

This checklist is Sorena's review aid, not an official Commission form. Its output should be a scoped evidence packet: the applicable Article 6 paragraph, service and data categories, access and use route, personal-data consent treatment, Article 6(2) restriction review, test results, exclusions, and the owner responsible for gaps.

Record the outcome as fulfilled, partially fulfilled with remediation, denied with a stated scope or consent reason, redirected to Article 6(8) or 6(9), or outside Article 6. Reassess when the data schema, consent flow, authorisation model, delivery interface, listed service, business-user product, or gatekeeper use of non-public data changes.

Does DMA Article 6(10) require a gatekeeper to give business users all personal data about end users?

No. Article 6(10) covers access to and use of personal data only where the data is directly connected with the end user's use of the relevant 's product or service through the relevant core platform service, and only when the end user opts in to that sharing by giving consent.

Is an API enough to satisfy DMA business-user data access?

Not by itself. The DMA requires effective, high-quality, continuous and real-time access where Article 6(10) applies. An API, export, dashboard, or request form is evidence only if it delivers the covered data with the required scope and quality.

What records should a gatekeeper keep for DMA Article 6(10) reviews?

Keep the request, authorisation, data-category map, consent treatment, access route, fulfilled and rejected responses, quality and latency tests, security or privacy limits, and the indicators used to show effective compliance.

Does Article 6(10) set one deadline for answering every business-user data request?

No single request-response period appears in Article 6(10). The binding standard is free, effective, high-quality, continuous and real-time access to and use of the covered data. The gatekeeper should still measure intake and delivery time because delay can make access ineffective, but any internal service level should be identified as an operational control rather than quoted as a DMA deadline.

  • Article 6 paragraph identified: 6(10) business-user access, 6(9) end-user portability, 6(8) ad measurement, 6(2) non-public data-use restriction, or out of scope.
  • Relevant gatekeeper, core platform service, , authorised third party, and data categories are named.
  • Aggregated, non-aggregated, personal, non-personal, and anonymised data treatment is recorded.
  • Consent handling for personal data is tested and does not make the 's consent path more burdensome than the gatekeeper's own path.
  • Access is tested for quality, continuity, real-time behaviour where relevant, completeness, authentication, permissioning, and failure handling.
  • Denials and exclusions state the legal or factual reason and are reviewable by legal, product, and compliance owners.
  • Compliance-report evidence can be retrieved without reconstructing the product decision from memory.
Primary sources

References and citations

digital-markets-act.ec.europa.eu
Referenced sections
  • Commission source for designated gatekeeper context and links to compliance reports and related gatekeeper materials.
"designated gatekeepers"
eur-lex.europa.eu
Referenced sections
  • Binding source for Article 6(9), Article 6(10), Article 6(2), Article 11, and the consent-related Article 13(5) guardrail.
"aggregated and non-aggregated data"
Related guides

Explore more topics

DMA Anti-Circumvention Design Review for Gatekeeper Product Changes
Review DMA Article 13 anti-circumvention risks in gatekeeper product, interface, contractual, commercial, and technical changes with obligation mapping and evidence records.
DMA Article 11 Compliance Report Template FAQ
How gatekeepers should use the DMA Article 11 compliance report template to document obligation-by-obligation measures, evidence, updates, and non-confidential summaries.
DMA Article 6(7) and Article 7 interoperability obligations
Official source guide to DMA interoperability duties: Article 6(7) operating-system feature access, Article 7 messaging interoperability, request handling, security conditions, and compliance evidence.
DMA Articles 5, 6 and 7 obligations mapped to CPS evidence
Map EU Digital Markets Act Articles 5, 6 and 7 obligations to affected core platform services, product evidence, legal owners, and Article 11 compliance-report artifacts.
DMA compliance program and monitoring for gatekeepers
Build a DMA compliance program around Article 8 effective compliance, Article 11 reporting evidence, Article 13 anti-circumvention controls, and Article 28 compliance-function governance.
DMA Core Platform Service Scoping
Scope EU Digital Markets Act core platform services by service category, designation evidence, user thresholds, and Form GD service-boundary records.
DMA core platform services FAQ
FAQ on EU Digital Markets Act core platform services: Article 2 service categories, gatekeeper designation evidence, user thresholds, service scoping, and Article 11 reporting.
DMA CPS Obligation Matrix Workflow: Articles 5, 6, 7 and Article 11 Evidence
Build a DMA core platform service obligation matrix that links each designated CPS to Articles 5, 6 and 7 duties, product owners, designation evidence, Article 11 report artifacts and review gates.
DMA designation intake workflow for gatekeeper notifications
Build an official source DMA designation intake record covering core platform service classification, Article 3 thresholds, Form GD evidence, Commission handoff, and Article 11 readiness.
DMA enforcement, penalties, and remedies: Commission powers and evidence
Follow DMA enforcement from investigation and preliminary findings to non-compliance decisions, fines, daily payments, interim measures, commitments, and remedies.
DMA Gatekeeper Compliance Checklist for Articles 5, 6, 7 and 11
A cited EU Digital Markets Act checklist for designated gatekeepers: core platform service scope, Article 5/6/7 controls, Article 11 report evidence, anti-circumvention checks, and review gates.
DMA Gatekeeper Designation Guide: Article 3 thresholds, Form GD, and Article 11 readiness
A cited EU Digital Markets Act guide for assessing Article 3 gatekeeper thresholds, scoping core platform services, preparing Form GD evidence, handling rebuttal annexes, and planning Article 11 compliance reporting.
DMA gatekeeper thresholds: what counts and when to notify
Standalone FAQ on the EU Digital Markets Act gatekeeper thresholds, Article 3 notification timing, Form GD evidence, and active user-count methodology.
DMA interoperability requests: Article 7 and Commission guidance
How DMA Article 7 messaging interoperability requests work, including phased functions, the three-month operational deadline, reference offers, evidence, and safeguards.
DMA penalties and fines: caps, triggers, and enforcement evidence
Compare DMA Article 30 fine ceilings, the narrow 20% repeat test, 1% procedural fines, and Article 31 daily payments, with decision-specific examples.
DMA Product Change Review Workflow for Articles 5, 6, 7, 11 and 13
Review DMA-relevant product releases for Article 5, Article 6, Article 7, anti-circumvention, Article 11 evidence, and product-owner/legal signoff.
DMA Self-Preferencing Compliance Examples for Ranking and Display
Examples and release-review controls for DMA Article 6(5) self-preferencing checks across ranking, indexing, crawling, search results, marketplaces, app stores, feeds, and virtual assistants.
DMA vs Data Act: gatekeeper duties compared with EU data-sharing rules
Compare the EU Digital Markets Act and EU Data Act by scope, actors, data access, interoperability, reporting, evidence, and enforcement without merging distinct obligations.
DMA vs DSA: Digital Markets vs Services Act
Compare the EU Digital Markets Act and Digital Services Act by covered services, regulated actors, core duties, reporting, dates, evidence, and enforcement.
DMA vs EU competition law: gatekeeper obligations, Article 11 evidence, and enforcement
Compare the EU Digital Markets Act with EU competition law: ex ante gatekeeper and core platform service duties, Articles 5 to 7, Article 11 reports, penalties, and evidence records.
DMA vs GDPR: gatekeeper data obligations compared
Compare DMA gatekeeper duties with GDPR rules for personal-data processing, consent, lawful basis, portability, accountability evidence, and enforcement.
EU Digital Markets Act Article 11 Evidence Calendar
Build a DMA Article 11 compliance-report calendar with the correct designation trigger, service annexes, evidence owners, annual updates, and publication gates.
EU Digital Markets Act checklist for gatekeeper compliance
A source-grounded Sorena DMA checklist for designated gatekeepers and core platform services, covering scope, Articles 5, 6 and 7 obligations, Article 11 reporting, evidence, anti-circumvention, and governance.
EU Digital Markets Act compliance: gatekeeper obligations and evidence
DMA compliance guide for designated gatekeepers: core platform service scoping, Articles 5, 6 and 7 controls, Article 11 reports, anti-circumvention checks, interoperability evidence, and enforcement risk.
EU Digital Markets Act deadlines and compliance calendar
Calculate DMA notification, designation, service-compliance, Article 11 reporting, concentration-notice, and profiling-audit deadlines from the correct legal trigger.
EU Digital Markets Act FAQ: gatekeepers, DMA obligations, reports, and enforcement
Concise FAQ on the EU Digital Markets Act for gatekeeper designation, core platform services, Articles 5, 6 and 7 obligations, Article 11 reports, interoperability, business-user data access, compliance evidence, and enforcement.
EU Digital Markets Act requirements for gatekeepers
DMA requirements for designated gatekeepers: core platform service scope, Articles 5, 6 and 7 obligations, Article 11 reporting, anti-circumvention, evidence, remedies, and fines.
EU Digital Markets Act timeline: application, designation, reporting, and review
DMA timeline separating fixed legal dates, threshold and designation clocks, recurring reports, service-specific decisions, final enforcement, and the first Article 53 review.
EU DMA Applicability Test: gatekeeper thresholds, core platform services, and evidence
Test whether the EU Digital Markets Act may apply to a platform service using the DMA gatekeeper criteria, core platform service categories, EU user thresholds, notification steps, and evidence records.
EU DMA Article 11 Compliance Reporting Guide
Official source guide to EU Digital Markets Act Article 11 compliance reports: report purpose, template evidence, non-confidential summaries, annual updates, and submission steps.
EU DMA do's and don'ts for product teams
Product release checks for designated DMA gatekeepers: Article 5, 6 and 7 obligations, anti-circumvention review, data access, interoperability, self-preferencing and Article 11 evidence.
What do DMA Articles 5, 6, and 7 require from gatekeepers?
FAQ explaining how EU Digital Markets Act Articles 5, 6, and 7 group gatekeeper obligations, what product evidence they require, and how Article 11 reporting connects.