Compliance GuideEU DMA

EU Digital Markets Act Compliance

A practical DMA compliance guide for designated gatekeepers and teams reviewing core platform service obligations.

Use it to scope listed core platform services, map Articles 5, 6 and 7 obligations, build Article 11 evidence, test anti-circumvention risk, and prepare interoperable access records.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Digital Markets Act compliance attaches to undertakings designated as gatekeepers and to each listed in the Commission designation decision. Start with that decision, then trace each listed service through the obligations in Articles 5, 6 and 7, the Article 11 compliance report, the anti-circumvention rule in Article 13, and any Commission specification or enforcement process that affects the service.

Section 1

Scope the gatekeeper and the listed core platform service first

A DMA control should be opened only after the team can name the designated undertaking, the listed , and the business-user or end-user journey affected by the control. The legal text defines core platform services to include online intermediation services, online search engines, online social networking services, video-sharing platform services, number-independent interpersonal communications services, operating systems, web browsers, virtual assistants, cloud computing services, and online advertising services provided by an undertaking that provides one of those services.

The designation analysis also matters after designation. Article 3 uses quantitative presumptions for turnover or market value, Union user reach, and durable position, but the Commission can designate under a qualitative assessment as well. The compliance record should therefore separate designation metrics from service-level obligation evidence.

The DMA has applied since 2 May 2023, but the operational compliance date is service-specific: Articles 5, 6, and 7 generally apply six months after the service is listed. A later decision can add or remove a service, and Article 4 reviews do not suspend existing duties unless the Commission changes the designation.

  • Record the exact undertaking and each listed in the designation decision, not just the corporate group or product family.
  • Keep monthly active end-user, yearly active business-user, Member State, turnover, and market-value evidence separate from obligation controls.
  • For product changes, state whether the change affects a listed , a service provided together with or in support of it, or a service outside the designation.
  • Use the Commission gatekeepers page and case materials to confirm which services are listed before reusing a DMA control across products.
  • If the designation relies on the foreseeable-position route in Article 17(4), read the decision itself: the Commission may declare only the listed subset of obligations applicable rather than every paragraph in Articles 5, 6, and 7.
Section 2

Map Articles 5, 6 and 7 to concrete product controls

Articles 5, 6 and 7 are the compliance backbone. Article 5 contains direct obligations such as limits on combining or cross-using personal data without consent, anti-steering restrictions, communication and contracting rights for business users, access for end users to externally acquired content, complaint freedom, tying restrictions for identification, browser engine and payment services, and advertising transparency for advertisers and publishers.

Article 6 adds obligations that may be further specified by the Commission. The operational controls typically touch non-public business-user data, uninstall and default-choice flows, third-party app stores and software installation, ranking fairness, switching, interoperability with operating system or virtual assistant features, ad measurement access, end-user data portability, business-user data access, search-data access, FRAND access conditions, and termination terms.

Article 7 is narrower but technically demanding. It applies where a gatekeeper provides a listed number-independent interpersonal communications service and requires requested interoperability for specified basic functionalities while preserving security, including end-to-end encryption where applicable.

  • Build an obligation matrix by article, paragraph, listed , affected user group, product owner, legal owner, technical owner, and evidence owner.
  • For Article 5 data-use controls, retain consent-choice records, withdrawal handling, consent-reprompt limits, data-combination rules, and service-by-service processing boundaries.
  • For Article 6 controls, retain implementation specs for app installation, default changes, ranking conditions, data-access APIs, portability tools, ad-measurement access, and FRAND access terms.
  • For Article 7 controls, retain the reference offer, request intake records, security and privacy justifications, interface specifications, implementation status, and user-choice handling.
Section 3

Prepare Article 11 reports as service-by-service evidence files

Article 11 requires a gatekeeper to provide the Commission, within six months after designation, with a detailed and transparent report describing the measures implemented to ensure compliance with Articles 5, 6 and 7, plus a . The report and summary must be updated at least annually.

The Commission template makes the evidence burden practical. For each listed and applicable obligation, it asks for a compliance statement, an exhaustive explanation of measures, supporting data and internal documents, pre-designation or post-designation status, implementation timing, product and geographic scope, technical or engineering changes, customer-journey changes, terms and remuneration changes, consultation, alternative measures considered, testing, indicators, monitoring tools, and access procedures for third parties.

A request for specification dialogue does not remove the reporting obligation for the obligations covered by that request. Teams should therefore keep the Article 11 evidence file current even when they are also discussing specifications with the Commission.

  • Create one standalone annex per listed and applicable Article 5, 6 or 7 obligation.
  • Attach raw-data readiness notes for metrics the Commission may request, including definitions and calculation methods.
  • Keep click-by-click user journeys, screenshots, recorded demos, A/B test methods, consent rates, survey outputs, and business-user feedback where the measure changes choice screens, consent forms, warnings, defaults, or access flows.
  • For the , keep the same structure as the compliance report and replace confidential numbers with meaningful ranges, baselines, or aggregated values rather than empty redactions.
Section 4

Run anti-circumvention checks before shipping product changes

Article 13 turns weak implementation into enforcement risk. It prohibits segmenting or splitting core platform services to avoid designation thresholds, requires full and effective compliance with Articles 5, 6 and 7, and bars contractual, commercial, technical, behavioural, or interface-design behaviour that undermines those obligations.

The practical test is whether the implementation preserves the right in substance. A compliant-looking flow can still be risky if it degrades service quality for users who exercise DMA rights, makes choices unduly difficult, uses non-neutral interface design, burdens business users more than the gatekeeper's own services, or relies on security, privacy or integrity restrictions that are broader than necessary.

  • Review each product launch for service fragmentation, renamed service boundaries, changed domains, changed access conditions, or split metrics that could affect designation or obligation scope.
  • For every restriction justified by security, privacy or integrity, document why the measure is strictly necessary and proportionate and why less restrictive options were not chosen.
  • Test user and business-user journeys for neutral presentation, equal quality, friction, warnings, default settings, and degraded functionality after a DMA right is exercised.
  • Escalate changes that affect data access, interoperability, app distribution, defaults, ranking, consent, or business-user communications before release.
Section 5

Treat interoperability and access requests as compliance operations

Article 6(7) requires free and effective interoperability with, and access for interoperability to, the same operating-system, virtual-assistant, hardware, and software features available to the gatekeeper's own services or hardware. Any integrity measure must stay within the paragraph's strictly necessary, proportionate, and duly justified boundary. Article 7 is a separate request-based regime for listed number-independent interpersonal communications services.

The Commission's Developer Portal records completed Article 6(7) specification proceedings for Apple in March 2025 and Alphabet in July 2026. A specification decision sets binding implementation measures but does not itself find non-compliance or impose a fine; a separate non-compliance decision may do so.

  • Maintain a request register with requester identity, requested feature, applicable article, eligibility assessment, confidentiality choice, status, decision reason, appeal or review status, and implementation milestone.
  • Publish and version developer documentation, technical references, APIs, support pages, criteria, and terms used to evaluate requests.
  • Separate teams and access controls so non-public information from interoperability requesters is used only to provide interoperability.
  • For rejected requests, keep the unmet criteria, reasoning, next steps, Commission notification where applicable, and any internal-review or dispute-resolution record.
Section 6

Monitor enforcement exposure and compliance-function evidence

The Commission can adopt non-compliance decisions, require the gatekeeper to cease and desist, and impose fines for intentional or negligent failures to comply with Articles 5, 6 or 7, Commission-specified measures, systematic non-compliance remedies, interim measures, or binding commitments. The DMA also allows periodic penalty payments to compel compliance with specified measures, remedies, information requests, inspections, interim measures, commitments, and non-compliance decisions.

The compliance function should therefore keep management reports, risk assessments, decisions, replies from the management body, monitoring outputs, and remediation status together with the Article 11 evidence. A product team cannot close a DMA control merely by showing that a feature shipped; it must show that the measure is effective for the relevant obligation and that risks of non-compliance were escalated and addressed.

Article 9 suspension and Article 10 exemption are narrow Commission-decision routes, not self-declared defences. Article 9 concerns exceptional circumstances beyond the gatekeeper's control that endanger the economic viability of its Union operation. Article 10 permits exemption only for public health or public security. Unless and until the Commission grants relief, keep the obligation in the compliance register.

Who is responsible for DMA compliance evidence inside a designated gatekeeper?

DMA evidence should have both an operational owner for the listed and an independent compliance-function owner. The Commission Article 11 template asks for the role of the head of the compliance function, reporting lines, monitoring activities, management reports on non-compliance risk, and management-body replies.

What evidence should a DMA Article 11 compliance file contain?

For each listed and each applicable Article 5, 6 or 7 obligation, keep the compliance statement, implementation explanation, supporting data, internal documents, pre-change baseline, implementation date, product and geographic scope, engineering changes, user-journey changes, terms or fee changes, consultation, testing, indicators, monitoring tools, feedback, and non-confidential-summary text.

When does a DMA specification decision create enforcement risk?

A specification decision is not itself a non-compliance decision and does not attach fines merely because it is adopted. It can still create practical enforcement risk because it specifies measures the gatekeeper is expected to implement, while separate non-compliance proceedings can lead to cease-and-desist orders and fines if the Commission later finds an infringement.

Can a gatekeeper suspend a DMA obligation by recording a security, economic, or public-interest concern internally?

No. An internal concern does not suspend an obligation. Article 9 relief requires a Commission suspension decision based on exceptional circumstances beyond the gatekeeper's control that endanger the economic viability of its Union operation. Article 10 exemption requires a Commission decision and is limited to public health or public security. Obligation-specific security, privacy, or integrity measures must separately satisfy the conditions written into the relevant article.

  • Track findings by article, listed , owner, evidence gap, impact on business users or end users, remediation action, and management-body response.
  • Keep a separate log for Commission requests, specification proceedings, non-compliance proceedings, whistleblower or business-user complaints, and commitments.
  • Where a measure relies on estimates or best approximations, label the estimate, define the method, and retain the data source used.
  • Do not rely on annual review alone for high-risk changes; trigger reassessment when a listed service, interface, API, ranking method, consent flow, data-sharing process, access term, or interoperability process changes.
Primary sources

References and citations

digital-markets-act.ec.europa.eu
Referenced sections
  • Identifies designated gatekeepers, their listed core platform services, case references, compliance reports, acquisition notices, and consumer-profiling reports.
"Core platform services"
digital-markets-act.ec.europa.eu
Referenced sections
  • Commission legislation page linking the DMA, procedural implementing regulation, templates, notices, and guidelines relevant to obligation interpretation and submissions.
"implementation of the obligations"
digital-markets-act.ec.europa.eu
Referenced sections
  • Commission business resources page links to gatekeeper resources for interoperability with OS features, data portability, and data access.
"Resources for businesses"
eur-lex.europa.eu
Referenced sections
  • Articles 29, 30 and 31 support enforcement risk analysis, including non-compliance decisions, fines, and periodic penalty payments.
"non-compliance decision"
Related guides

Explore more topics

DMA Anti-Circumvention Design Review for Gatekeeper Product Changes
Review DMA Article 13 anti-circumvention risks in gatekeeper product, interface, contractual, commercial, and technical changes with obligation mapping and evidence records.
DMA Article 11 Compliance Report Template FAQ
How gatekeepers should use the DMA Article 11 compliance report template to document obligation-by-obligation measures, evidence, updates, and non-confidential summaries.
DMA Article 6 Business User Data Access Guide
Official source guide to EU Digital Markets Act Article 6 data access for business users, end users, authorised third parties, consent boundaries, and evidence handoffs.
DMA Article 6(7) and Article 7 interoperability obligations
Official source guide to DMA interoperability duties: Article 6(7) operating-system feature access, Article 7 messaging interoperability, request handling, security conditions, and compliance evidence.
DMA Articles 5, 6 and 7 obligations mapped to CPS evidence
Map EU Digital Markets Act Articles 5, 6 and 7 obligations to affected core platform services, product evidence, legal owners, and Article 11 compliance-report artifacts.
DMA compliance program and monitoring for gatekeepers
Build a DMA compliance program around Article 8 effective compliance, Article 11 reporting evidence, Article 13 anti-circumvention controls, and Article 28 compliance-function governance.
DMA Core Platform Service Scoping
Scope EU Digital Markets Act core platform services by service category, designation evidence, user thresholds, and Form GD service-boundary records.
DMA core platform services FAQ
FAQ on EU Digital Markets Act core platform services: Article 2 service categories, gatekeeper designation evidence, user thresholds, service scoping, and Article 11 reporting.
DMA CPS Obligation Matrix Workflow: Articles 5, 6, 7 and Article 11 Evidence
Build a DMA core platform service obligation matrix that links each designated CPS to Articles 5, 6 and 7 duties, product owners, designation evidence, Article 11 report artifacts and review gates.
DMA designation intake workflow for gatekeeper notifications
Build an official source DMA designation intake record covering core platform service classification, Article 3 thresholds, Form GD evidence, Commission handoff, and Article 11 readiness.
DMA enforcement, penalties, and remedies: Commission powers and evidence
Follow DMA enforcement from investigation and preliminary findings to non-compliance decisions, fines, daily payments, interim measures, commitments, and remedies.
DMA Gatekeeper Compliance Checklist for Articles 5, 6, 7 and 11
A cited EU Digital Markets Act checklist for designated gatekeepers: core platform service scope, Article 5/6/7 controls, Article 11 report evidence, anti-circumvention checks, and review gates.
DMA Gatekeeper Designation Guide: Article 3 thresholds, Form GD, and Article 11 readiness
A cited EU Digital Markets Act guide for assessing Article 3 gatekeeper thresholds, scoping core platform services, preparing Form GD evidence, handling rebuttal annexes, and planning Article 11 compliance reporting.
DMA gatekeeper thresholds: what counts and when to notify
Standalone FAQ on the EU Digital Markets Act gatekeeper thresholds, Article 3 notification timing, Form GD evidence, and active user-count methodology.
DMA interoperability requests: Article 7 and Commission guidance
How DMA Article 7 messaging interoperability requests work, including phased functions, the three-month operational deadline, reference offers, evidence, and safeguards.
DMA penalties and fines: caps, triggers, and enforcement evidence
Compare DMA Article 30 fine ceilings, the narrow 20% repeat test, 1% procedural fines, and Article 31 daily payments, with decision-specific examples.
DMA Product Change Review Workflow for Articles 5, 6, 7, 11 and 13
Review DMA-relevant product releases for Article 5, Article 6, Article 7, anti-circumvention, Article 11 evidence, and product-owner/legal signoff.
DMA Self-Preferencing Compliance Examples for Ranking and Display
Examples and release-review controls for DMA Article 6(5) self-preferencing checks across ranking, indexing, crawling, search results, marketplaces, app stores, feeds, and virtual assistants.
DMA vs Data Act: gatekeeper duties compared with EU data-sharing rules
Compare the EU Digital Markets Act and EU Data Act by scope, actors, data access, interoperability, reporting, evidence, and enforcement without merging distinct obligations.
DMA vs DSA: Digital Markets vs Services Act
Compare the EU Digital Markets Act and Digital Services Act by covered services, regulated actors, core duties, reporting, dates, evidence, and enforcement.
DMA vs EU competition law: gatekeeper obligations, Article 11 evidence, and enforcement
Compare the EU Digital Markets Act with EU competition law: ex ante gatekeeper and core platform service duties, Articles 5 to 7, Article 11 reports, penalties, and evidence records.
DMA vs GDPR: gatekeeper data obligations compared
Compare DMA gatekeeper duties with GDPR rules for personal-data processing, consent, lawful basis, portability, accountability evidence, and enforcement.
EU Digital Markets Act Article 11 Evidence Calendar
Build a DMA Article 11 compliance-report calendar with the correct designation trigger, service annexes, evidence owners, annual updates, and publication gates.
EU Digital Markets Act checklist for gatekeeper compliance
A source-grounded Sorena DMA checklist for designated gatekeepers and core platform services, covering scope, Articles 5, 6 and 7 obligations, Article 11 reporting, evidence, anti-circumvention, and governance.
EU Digital Markets Act deadlines and compliance calendar
Calculate DMA notification, designation, service-compliance, Article 11 reporting, concentration-notice, and profiling-audit deadlines from the correct legal trigger.
EU Digital Markets Act FAQ: gatekeepers, DMA obligations, reports, and enforcement
Concise FAQ on the EU Digital Markets Act for gatekeeper designation, core platform services, Articles 5, 6 and 7 obligations, Article 11 reports, interoperability, business-user data access, compliance evidence, and enforcement.
EU Digital Markets Act requirements for gatekeepers
DMA requirements for designated gatekeepers: core platform service scope, Articles 5, 6 and 7 obligations, Article 11 reporting, anti-circumvention, evidence, remedies, and fines.
EU Digital Markets Act timeline: application, designation, reporting, and review
DMA timeline separating fixed legal dates, threshold and designation clocks, recurring reports, service-specific decisions, final enforcement, and the first Article 53 review.
EU DMA Applicability Test: gatekeeper thresholds, core platform services, and evidence
Test whether the EU Digital Markets Act may apply to a platform service using the DMA gatekeeper criteria, core platform service categories, EU user thresholds, notification steps, and evidence records.
EU DMA Article 11 Compliance Reporting Guide
Official source guide to EU Digital Markets Act Article 11 compliance reports: report purpose, template evidence, non-confidential summaries, annual updates, and submission steps.
EU DMA do's and don'ts for product teams
Product release checks for designated DMA gatekeepers: Article 5, 6 and 7 obligations, anti-circumvention review, data access, interoperability, self-preferencing and Article 11 evidence.
What do DMA Articles 5, 6, and 7 require from gatekeepers?
FAQ explaining how EU Digital Markets Act Articles 5, 6, and 7 group gatekeeper obligations, what product evidence they require, and how Article 11 reporting connects.