WorkflowEU DMA

DMA CPS Obligation Matrix Workflow

Map each designated core platform service to the DMA obligations that must be implemented, evidenced, reported, and kept under review.

Use the matrix to connect designation evidence, Articles 5, 6 and 7 obligation columns, product owners, Article 11 report annexes, and reopening gates.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

Build the matrix one designated at a time. Each row should name the service listed in the Commission designation decision, then map the Articles 5, 6, and 7 obligations, accountable owners, source evidence, material, and review triggers. This is a Sorena workflow, not a Commission-prescribed matrix; the Regulation, designation decision, and any Commission specification or enforcement decision control. A company-level compliance status cannot show which obligation applies to which service.

Section 1

Start with the designated CPS, not the company brand

The DMA matrix should begin with the core platform services listed in the Commission designation materials. Article 3 says the designation decision lists the relevant core platform services, and Article 3(10) ties the Articles 5, 6 and 7 compliance obligation to the listed CPS.

Create one row per listed CPS and record the gatekeeper, case identifier, Article 2 CPS category, product owner, legal owner, engineering owner, evidence owner, and Article 11 annex location. Do not merge separate CPS rows just because the same corporate group owns them.

  • Designation evidence: link the Commission gatekeeper page or case page for the CPS, such as Google Search, Google Play, Android Mobile, Apple App Store, iOS, Safari, iPadOS, Amazon Marketplace, Amazon Advertising, Booking.com, TikTok, Facebook, Instagram, WhatsApp, Messenger, or Meta Ads.
  • Article 2 category: classify the CPS as online intermediation, online search, online social networking, video-sharing, number-independent interpersonal communications, operating system, web browser, virtual assistant, cloud computing, or online advertising.
  • Gatekeeper basis: keep the Article 3 evidence separate from implementation evidence, including whether the row relies on a Commission designation decision, notification threshold material, or a later amendment or repeal.
  • Owner evidence: name the product lead who can explain user journeys, the engineering lead who can explain technical controls, the commercial lead who can explain fees and terms, and the compliance owner who controls .
Section 2

Build the Articles 5, 6 and 7 obligation columns

The matrix should have obligation columns, not a generic compliance status column. Articles 5 and 6 each state that the gatekeeper must comply with the obligations in that Article with respect to each listed CPS, but the Article 11 template also expects a reasoned explanation where a specific obligation cannot by nature apply to the relevant CPS.

For every CPS row, mark each obligation as applicable, not applicable by nature, specification requested, implemented, blocked, or under remediation. Each status needs a cited reason and an evidence pointer.

  • Article 5 columns: consent and personal-data combination limits under Article 5(2), parity and offer restrictions under Article 5(3), business-user communication and contracting under Article 5(4), access to acquired content or subscriptions under Article 5(5), non-restriction of complaints under Article 5(6), tying of identification, browser engine, payment or payment-support services under Article 5(7), forced registration with further CPS under Article 5(8), and advertiser or publisher transparency under Articles 5(9) and 5(10).
  • Article 6 columns: non-public business-user data use under Article 6(2), app uninstall and default-setting changes under Article 6(3), third-party app and app-store installation under Article 6(4), ranking fairness under Article 6(5), switching and multi-homing under Article 6(6), interoperability with operating-system, virtual-assistant, hardware or software features under Article 6(7), advertising measurement access under Article 6(8), end-user data portability under Article 6(9), business-user data access under Article 6(10), search data access under Article 6(11), fair access conditions for app stores, search engines and social networks under Article 6(12), and termination conditions under Article 6(13).
  • Article 7 columns: use only for designated number-independent interpersonal communications services. Track the reference offer, requesting provider, requested functionality, receipt date, three-month operationalisation deadline, security and end-to-end encryption, and any strictly necessary and proportionate integrity, security, or privacy measure.
  • Article 7 timing: distinguish the staged duties in Article 7(2). End-to-end text messaging between two individual users and sharing images, voice messages, videos, and other attached files become due within the Article 3(10) compliance period; group messaging becomes due within two years after designation; and end-to-end voice and video calls between individual users and groups become due within four years after designation. A reasonable request must be made operational within three months after receipt unless the Commission grants an exceptional extension under Article 7(6).
  • Not-applicable evidence: for each non-applicable cell, cite the text-based reason, for example that Article 7 is limited to number-independent interpersonal communications services or that Article 6(11) concerns third-party online search engines requesting search data.
Section 3

Attach product-owner and Article 11 evidence to each cell

A policy that says 'compliant' does not complete an obligation cell. The Article 11 template asks for a compliance statement plus an exhaustive explanation, supporting data, internal documents, implementation timing, product and geographic scope, technical changes, user-experience changes, remuneration and terms changes, consultations, testing, indicators, and relevant data.

Treat each Article 5, 6 or 7 cell as a mini evidence package. The evidence should let a reader reconstruct what changed, why the change addresses the obligation, which CPS it covers, and how effectiveness is monitored.

  • Product evidence: screenshots or recorded demos for choice screens, consent prompts, defaults, interoperability request flows, app-store access paths, data-portability flows, advertising dashboards, and business-user data export interfaces.
  • Engineering evidence: API documentation, feature flags, release notes, access-control rules, logging specifications, ranking or auction parameter summaries, data-flow diagrams, security justifications, and tests for less restrictive alternatives where integrity or privacy restrictions are used.
  • Commercial evidence: fee schedules, revenue-share terms, publisher or advertiser reporting fields, business-user communications, contract updates, termination terms, and records showing whether remuneration flows changed.
  • Effectiveness evidence: user or business-user consultation records, A/B test methodology, consent-rate methodology where consent is relevant, survey methodology, adoption metrics, error rates, response times, dispute outcomes, and the indicators selected to show whether the measure is effective.
  • Article 11 artifact: store the final cell narrative in the CPS-specific annex, keep the underlying raw data ready, and keep a non-confidential summary version that follows the same structure unless information is confidential.
Section 4

Use review gates that catch designation and product changes

Reopen the matrix when the legal designation changes, the product changes, or the evidence no longer demonstrates effective compliance. Article 4 allows the Commission to reconsider, amend, or repeal a designation decision, and the Commission's gatekeeper portal records additions and removals from the designated service list.

Review gates should be concrete enough for product and compliance teams to operate without waiting for an annual reporting cycle.

  • Designation gate: reopen the affected row when the Commission lists, amends, or repeals a gatekeeper or CPS designation, or when a further CPS meets Article 3 notification thresholds.
  • Product gate: reopen the row before launches that change defaults, ranking, app distribution, messaging functionality, data-sharing paths, advertising measurement, fees, terms, consent prompts, or interoperability features.
  • Article 8 gate: reopen any Article 6 or 7 cell when a specification process is requested or opened; do not remove it from merely because specification discussions exist.
  • Article 11 gate: reopen before each annual update, after material implementation changes, after relevant stakeholder feedback, and whenever the non-confidential summary would no longer give a faithful and meaningful picture of the compliance report.
  • Article 7 gate: for messaging CPS rows, track reference-offer publication, provider requests, requested functionalities, three-month operationalization, security and encryption preservation, and strictly necessary privacy or integrity measures.
  • Quality gate: close a row only when the designation source, CPS category, owner map, Article 5/6/7 statuses, evidence pointers, non-applicability reasons, and Article 11 annex location are complete.
Primary sources

References and citations

digital-markets-act.ec.europa.eu
Referenced sections
  • Defines the evidence categories expected in Article 11 reporting, including technical changes, customer journeys, testing, indicators, and non-confidential summaries.
"supporting data and internal documents"
digital-markets-act.ec.europa.eu
Referenced sections
  • Shows that the public CPS list includes designation additions and an undesignation, so matrix rows need designation-change review gates.
"Meta was undesignated"
digital-markets-act.ec.europa.eu
Referenced sections
  • Provides Commission context for Article 6(7) operating-system interoperability request processes, developer transparency, tracking, and reporting expectations.
"structured timeline for handling interoperability requests"
eur-lex.europa.eu
Referenced sections
  • Supports reopening for designation review, Article 8 specification processes, Article 11 updates, and Article 7 interoperability timing.
"update that report and that non-confidential summary"
Related guides

Explore more topics

DMA Anti-Circumvention Design Review for Gatekeeper Product Changes
Review DMA Article 13 anti-circumvention risks in gatekeeper product, interface, contractual, commercial, and technical changes with obligation mapping and evidence records.
DMA Article 11 Compliance Report Template FAQ
How gatekeepers should use the DMA Article 11 compliance report template to document obligation-by-obligation measures, evidence, updates, and non-confidential summaries.
DMA Article 6 Business User Data Access Guide
Official source guide to EU Digital Markets Act Article 6 data access for business users, end users, authorised third parties, consent boundaries, and evidence handoffs.
DMA Article 6(7) and Article 7 interoperability obligations
Official source guide to DMA interoperability duties: Article 6(7) operating-system feature access, Article 7 messaging interoperability, request handling, security conditions, and compliance evidence.
DMA Articles 5, 6 and 7 obligations mapped to CPS evidence
Map EU Digital Markets Act Articles 5, 6 and 7 obligations to affected core platform services, product evidence, legal owners, and Article 11 compliance-report artifacts.
DMA compliance program and monitoring for gatekeepers
Build a DMA compliance program around Article 8 effective compliance, Article 11 reporting evidence, Article 13 anti-circumvention controls, and Article 28 compliance-function governance.
DMA Core Platform Service Scoping
Scope EU Digital Markets Act core platform services by service category, designation evidence, user thresholds, and Form GD service-boundary records.
DMA core platform services FAQ
FAQ on EU Digital Markets Act core platform services: Article 2 service categories, gatekeeper designation evidence, user thresholds, service scoping, and Article 11 reporting.
DMA designation intake workflow for gatekeeper notifications
Build an official source DMA designation intake record covering core platform service classification, Article 3 thresholds, Form GD evidence, Commission handoff, and Article 11 readiness.
DMA enforcement, penalties, and remedies: Commission powers and evidence
Follow DMA enforcement from investigation and preliminary findings to non-compliance decisions, fines, daily payments, interim measures, commitments, and remedies.
DMA Gatekeeper Compliance Checklist for Articles 5, 6, 7 and 11
A cited EU Digital Markets Act checklist for designated gatekeepers: core platform service scope, Article 5/6/7 controls, Article 11 report evidence, anti-circumvention checks, and review gates.
DMA Gatekeeper Designation Guide: Article 3 thresholds, Form GD, and Article 11 readiness
A cited EU Digital Markets Act guide for assessing Article 3 gatekeeper thresholds, scoping core platform services, preparing Form GD evidence, handling rebuttal annexes, and planning Article 11 compliance reporting.
DMA gatekeeper thresholds: what counts and when to notify
Standalone FAQ on the EU Digital Markets Act gatekeeper thresholds, Article 3 notification timing, Form GD evidence, and active user-count methodology.
DMA interoperability requests: Article 7 and Commission guidance
How DMA Article 7 messaging interoperability requests work, including phased functions, the three-month operational deadline, reference offers, evidence, and safeguards.
DMA penalties and fines: caps, triggers, and enforcement evidence
Compare DMA Article 30 fine ceilings, the narrow 20% repeat test, 1% procedural fines, and Article 31 daily payments, with decision-specific examples.
DMA Product Change Review Workflow for Articles 5, 6, 7, 11 and 13
Review DMA-relevant product releases for Article 5, Article 6, Article 7, anti-circumvention, Article 11 evidence, and product-owner/legal signoff.
DMA Self-Preferencing Compliance Examples for Ranking and Display
Examples and release-review controls for DMA Article 6(5) self-preferencing checks across ranking, indexing, crawling, search results, marketplaces, app stores, feeds, and virtual assistants.
DMA vs Data Act: gatekeeper duties compared with EU data-sharing rules
Compare the EU Digital Markets Act and EU Data Act by scope, actors, data access, interoperability, reporting, evidence, and enforcement without merging distinct obligations.
DMA vs DSA: Digital Markets vs Services Act
Compare the EU Digital Markets Act and Digital Services Act by covered services, regulated actors, core duties, reporting, dates, evidence, and enforcement.
DMA vs EU competition law: gatekeeper obligations, Article 11 evidence, and enforcement
Compare the EU Digital Markets Act with EU competition law: ex ante gatekeeper and core platform service duties, Articles 5 to 7, Article 11 reports, penalties, and evidence records.
DMA vs GDPR: gatekeeper data obligations compared
Compare DMA gatekeeper duties with GDPR rules for personal-data processing, consent, lawful basis, portability, accountability evidence, and enforcement.
EU Digital Markets Act Article 11 Evidence Calendar
Build a DMA Article 11 compliance-report calendar with the correct designation trigger, service annexes, evidence owners, annual updates, and publication gates.
EU Digital Markets Act checklist for gatekeeper compliance
A source-grounded Sorena DMA checklist for designated gatekeepers and core platform services, covering scope, Articles 5, 6 and 7 obligations, Article 11 reporting, evidence, anti-circumvention, and governance.
EU Digital Markets Act compliance: gatekeeper obligations and evidence
DMA compliance guide for designated gatekeepers: core platform service scoping, Articles 5, 6 and 7 controls, Article 11 reports, anti-circumvention checks, interoperability evidence, and enforcement risk.
EU Digital Markets Act deadlines and compliance calendar
Calculate DMA notification, designation, service-compliance, Article 11 reporting, concentration-notice, and profiling-audit deadlines from the correct legal trigger.
EU Digital Markets Act FAQ: gatekeepers, DMA obligations, reports, and enforcement
Concise FAQ on the EU Digital Markets Act for gatekeeper designation, core platform services, Articles 5, 6 and 7 obligations, Article 11 reports, interoperability, business-user data access, compliance evidence, and enforcement.
EU Digital Markets Act requirements for gatekeepers
DMA requirements for designated gatekeepers: core platform service scope, Articles 5, 6 and 7 obligations, Article 11 reporting, anti-circumvention, evidence, remedies, and fines.
EU Digital Markets Act timeline: application, designation, reporting, and review
DMA timeline separating fixed legal dates, threshold and designation clocks, recurring reports, service-specific decisions, final enforcement, and the first Article 53 review.
EU DMA Applicability Test: gatekeeper thresholds, core platform services, and evidence
Test whether the EU Digital Markets Act may apply to a platform service using the DMA gatekeeper criteria, core platform service categories, EU user thresholds, notification steps, and evidence records.
EU DMA Article 11 Compliance Reporting Guide
Official source guide to EU Digital Markets Act Article 11 compliance reports: report purpose, template evidence, non-confidential summaries, annual updates, and submission steps.
EU DMA do's and don'ts for product teams
Product release checks for designated DMA gatekeepers: Article 5, 6 and 7 obligations, anti-circumvention review, data access, interoperability, self-preferencing and Article 11 evidence.
What do DMA Articles 5, 6, and 7 require from gatekeepers?
FAQ explaining how EU Digital Markets Act Articles 5, 6, and 7 group gatekeeper obligations, what product evidence they require, and how Article 11 reporting connects.