DMA vs Data Act Gatekeeper obligations and data-sharing rules
This comparison helps separate DMA gatekeeper duties for core platform services from the Data Act's broader access-to-data framework.
The DMA side focuses on gatekeeper designation, Articles 5 to 7 obligations, data access, interoperability, Article 11 reporting, and Commission enforcement.
Use the DMA when the issue concerns a designated gatekeeper, a listed , and an obligation in Articles 5, 6, or 7. Use the Data Act when the issue concerns covered product or related-service data, a statutory data-sharing duty, an exceptional-need public-sector request, an unfair business-to-business data term, or switching between data processing services. The Data Act has applied since 12 September 2025, subject to provision-specific transition rules. A company or data flow can fall under both laws, but each trigger, actor, request, evidence record, and enforcement route must be assessed separately.
Side-by-side comparison
EU Digital Markets Act vs EU Data Act
Compare the regimes by the factual trigger, obligated actor, operational duty, evidence, timing, enforcement path, and overlap rule.
The DMA is a gatekeeper regime for designated core platform services. It imposes conduct, data access, choice, interoperability, reporting, and anti-circumvention duties on designated gatekeepers.
Second framework
EU Data Act
The Data Act sets horizontal rules for access to and use of data. It covers product and related-service data, statutory data sharing, certain unfair business-to-business terms, exceptional-need public-sector requests, switching between data processing services, safeguards for non-personal data, and interoperability.
Starts with a designated gatekeeper and each listed in the Commission designation decision, including categories such as online intermediation, search, social networking, video sharing, number-independent messaging, operating systems, browsers, virtual assistants, cloud computing, and online advertising.
Starts by identifying the applicable Data Act chapter. Chapter II covers data, other than content, about the performance, use, and environment of connected products and related services. Other chapters cover statutory business-to-business data sharing, unilaterally imposed data-contract terms, exceptional-need public-sector access, data-processing-service switching, safeguards for non-personal data, and interoperability.
A large digital platform is not automatically a DMA workstream for every service, and a data-access request is not automatically covered by the Data Act. Record the gatekeeper and core-platform-service trigger separately from the Data Act chapter, data category, role, and request basis.
The obligated actor is the designated gatekeeper for the relevant . Implementation usually involves competition counsel, product owners, platform engineering, data teams, developer relations, advertising, search/ranking, app-store, browser, operating-system, or messaging teams depending on the obligation.
The relevant actor depends on the Data Act chapter: a manufacturer or related-service provider, user, , data recipient, eligible public-sector body or Union institution, customer, provider of data processing services, data-space participant, or smart-contract vendor or deployer. A user is the person that owns a , has temporary contractual rights to use it, or receives a related service.
Chapter II requires connected products and related services to be designed so covered data and necessary metadata are accessible to the user by default, easily, securely, free of charge, in a comprehensive, structured, commonly used, machine-readable format and, where relevant and technically feasible, directly. Where direct access is unavailable, the must make readily available data accessible on request, subject to the Act's conditions, trade-secret safeguards, and personal-data rules.
Translate DMA duties into service-specific product controls and Article 11 evidence; translate Data Act duties into data-access, contract, request-handling, or switching controls.
DMA data work is tied to gatekeeper obligations: business users can need access to data generated through their use of the relevant , end users can need portability, advertisers and publishers can need measurement data, and search competitors can request certain ranking, query, click, and view data on fair, reasonable, and non-discriminatory terms.
For connected products and related services, distinguish product data, related service data, and readily available data. A user may request that a make covered data available to a chosen third party, but a company designated as a DMA gatekeeper is not an eligible third party under this Chapter II route. Chapter II also contains a scoped exclusion for qualifying microenterprises and small enterprises and a limited transition for specified newly medium-sized enterprises. Trade secrets can require agreed protective measures and, in exceptional cases, can justify withholding, suspending, or refusing specific sharing under the statutory procedure and competent-authority notification rules.
A DMA business-user data-access control should cite the relevant Article 6 obligation and CPS; a Data Act data-access control should cite the data category, , user or recipient, and request route.
Article 11 requires a gatekeeper to provide the Commission, within 6 months after designation, a detailed and transparent report on measures implemented to ensure Articles 5 to 7 compliance, publish and provide a non-confidential summary, and update the report and summary at least annually.
The Data Act has no equivalent of the DMA Article 11 gatekeeper report. Evidence depends on the duty: pre-contract disclosures, data catalogues and metadata, access requests and responses, identity and authorization checks, trade-secret measures, compensation terms, exceptional-need request records, switching notices and export assistance, contract terms, and complaint or dispute records.
Use Article 11 evidence for DMA only. The report should be organized by and obligation, with supporting data, internal documents, implementation dates, product scope, geography, technical changes, user-interface changes, business-user terms, consultation evidence, and alternatives considered where applicable.
DMA timing is driven by designation and ongoing compliance. Article 11 sets the 6-month post-designation reporting point and at-least-annual updates; product changes that affect Articles 5 to 7 controls should be reviewed before release because the gatekeeper must ensure and demonstrate effective compliance.
The Data Act entered into force on 11 January 2024 and has generally applied since 12 September 2025. Article 3(1)'s design requirement applies to connected products and related services placed on the market after 12 September 2026. Chapter IV applies to contracts concluded after 12 September 2025 and, from 12 September 2027, to certain older indefinite or long-term contracts. Switching charges are prohibited from 12 January 2027.
Track DMA designation and Article 11 cycles separately from the Data Act's application date, product placement date, contract date and duration, access requests, exceptional-need requests, and switching milestones.
The Commission is the sole DMA enforcer, with cooperation mechanisms for Member State authorities. DMA non-compliance can lead to Commission decisions, remedies, fines up to 10% of total worldwide turnover, up to 20% for certain repeat infringements, and periodic penalty payments up to 5% of average daily worldwide turnover.
Member States designate one or more competent authorities for the Data Act and set effective, proportionate, and dissuasive penalties. Data-protection supervisory authorities remain responsible for monitoring Data Act processing that concerns personal data, and the European Data Protection Supervisor has the corresponding role for Union institutions. Do not borrow DMA fine caps for a Data Act matter.
Escalate DMA risk to the gatekeeper's Commission-facing team and Article 11 evidence owners. Escalate Data Act risk through the owners responsible for the relevant data-access, request, contract, or switching obligation.
Keep DMA labels on facts tied to a designated gatekeeper, CPS, Articles 5 to 7 obligation, Article 11 report, Article 6(7) or Article 7 interoperability request, or Commission DMA proceeding.
Keep Data Act labels on facts tied to a specific chapter: covered product or related-service data, statutory data-holder access, user or eligible third-party access, covered business-to-business terms, exceptional-need public-sector access, or data-processing-service switching.
A shared evidence pack is acceptable only if each item states which law it supports. Avoid one blended 'platform data compliance' control that hides the DMA gatekeeper/CPS test or the Data Act data-role test.
DMA interoperability can arise under Article 6(7) for operating-system, virtual-assistant, hardware, and software features, and under Article 7 for number-independent interpersonal communications services. The Commission's interoperability Q&A shows how specification decisions can make this operational for business users and developers.
Data Act interoperability is a separate data and data-processing-services topic; do not use DMA Article 6(7) or Article 7 language unless the service is a designated DMA .
For DMA, keep records of requests, eligibility decisions, technical interfaces, API documentation, security or integrity justifications, developer communications, and Commission specification materials. For Data Act, keep the switching or data-interoperability record separate.
Starts with a designated gatekeeper and each listed in the Commission designation decision, including categories such as online intermediation, search, social networking, video sharing, number-independent messaging, operating systems, browsers, virtual assistants, cloud computing, and online advertising.
Starts by identifying the applicable Data Act chapter. Chapter II covers data, other than content, about the performance, use, and environment of connected products and related services. Other chapters cover statutory business-to-business data sharing, unilaterally imposed data-contract terms, exceptional-need public-sector access, data-processing-service switching, safeguards for non-personal data, and interoperability.
A large digital platform is not automatically a DMA workstream for every service, and a data-access request is not automatically covered by the Data Act. Record the gatekeeper and core-platform-service trigger separately from the Data Act chapter, data category, role, and request basis.
The obligated actor is the designated gatekeeper for the relevant . Implementation usually involves competition counsel, product owners, platform engineering, data teams, developer relations, advertising, search/ranking, app-store, browser, operating-system, or messaging teams depending on the obligation.
The relevant actor depends on the Data Act chapter: a manufacturer or related-service provider, user, , data recipient, eligible public-sector body or Union institution, customer, provider of data processing services, data-space participant, or smart-contract vendor or deployer. A user is the person that owns a , has temporary contractual rights to use it, or receives a related service.
Chapter II requires connected products and related services to be designed so covered data and necessary metadata are accessible to the user by default, easily, securely, free of charge, in a comprehensive, structured, commonly used, machine-readable format and, where relevant and technically feasible, directly. Where direct access is unavailable, the must make readily available data accessible on request, subject to the Act's conditions, trade-secret safeguards, and personal-data rules.
Translate DMA duties into service-specific product controls and Article 11 evidence; translate Data Act duties into data-access, contract, request-handling, or switching controls.
DMA data work is tied to gatekeeper obligations: business users can need access to data generated through their use of the relevant , end users can need portability, advertisers and publishers can need measurement data, and search competitors can request certain ranking, query, click, and view data on fair, reasonable, and non-discriminatory terms.
For connected products and related services, distinguish product data, related service data, and readily available data. A user may request that a make covered data available to a chosen third party, but a company designated as a DMA gatekeeper is not an eligible third party under this Chapter II route. Chapter II also contains a scoped exclusion for qualifying microenterprises and small enterprises and a limited transition for specified newly medium-sized enterprises. Trade secrets can require agreed protective measures and, in exceptional cases, can justify withholding, suspending, or refusing specific sharing under the statutory procedure and competent-authority notification rules.
A DMA business-user data-access control should cite the relevant Article 6 obligation and CPS; a Data Act data-access control should cite the data category, , user or recipient, and request route.
Article 11 requires a gatekeeper to provide the Commission, within 6 months after designation, a detailed and transparent report on measures implemented to ensure Articles 5 to 7 compliance, publish and provide a non-confidential summary, and update the report and summary at least annually.
The Data Act has no equivalent of the DMA Article 11 gatekeeper report. Evidence depends on the duty: pre-contract disclosures, data catalogues and metadata, access requests and responses, identity and authorization checks, trade-secret measures, compensation terms, exceptional-need request records, switching notices and export assistance, contract terms, and complaint or dispute records.
Use Article 11 evidence for DMA only. The report should be organized by and obligation, with supporting data, internal documents, implementation dates, product scope, geography, technical changes, user-interface changes, business-user terms, consultation evidence, and alternatives considered where applicable.
DMA timing is driven by designation and ongoing compliance. Article 11 sets the 6-month post-designation reporting point and at-least-annual updates; product changes that affect Articles 5 to 7 controls should be reviewed before release because the gatekeeper must ensure and demonstrate effective compliance.
The Data Act entered into force on 11 January 2024 and has generally applied since 12 September 2025. Article 3(1)'s design requirement applies to connected products and related services placed on the market after 12 September 2026. Chapter IV applies to contracts concluded after 12 September 2025 and, from 12 September 2027, to certain older indefinite or long-term contracts. Switching charges are prohibited from 12 January 2027.
Track DMA designation and Article 11 cycles separately from the Data Act's application date, product placement date, contract date and duration, access requests, exceptional-need requests, and switching milestones.
The Commission is the sole DMA enforcer, with cooperation mechanisms for Member State authorities. DMA non-compliance can lead to Commission decisions, remedies, fines up to 10% of total worldwide turnover, up to 20% for certain repeat infringements, and periodic penalty payments up to 5% of average daily worldwide turnover.
Member States designate one or more competent authorities for the Data Act and set effective, proportionate, and dissuasive penalties. Data-protection supervisory authorities remain responsible for monitoring Data Act processing that concerns personal data, and the European Data Protection Supervisor has the corresponding role for Union institutions. Do not borrow DMA fine caps for a Data Act matter.
Escalate DMA risk to the gatekeeper's Commission-facing team and Article 11 evidence owners. Escalate Data Act risk through the owners responsible for the relevant data-access, request, contract, or switching obligation.
Keep DMA labels on facts tied to a designated gatekeeper, CPS, Articles 5 to 7 obligation, Article 11 report, Article 6(7) or Article 7 interoperability request, or Commission DMA proceeding.
Keep Data Act labels on facts tied to a specific chapter: covered product or related-service data, statutory data-holder access, user or eligible third-party access, covered business-to-business terms, exceptional-need public-sector access, or data-processing-service switching.
A shared evidence pack is acceptable only if each item states which law it supports. Avoid one blended 'platform data compliance' control that hides the DMA gatekeeper/CPS test or the Data Act data-role test.
DMA interoperability can arise under Article 6(7) for operating-system, virtual-assistant, hardware, and software features, and under Article 7 for number-independent interpersonal communications services. The Commission's interoperability Q&A shows how specification decisions can make this operational for business users and developers.
Data Act interoperability is a separate data and data-processing-services topic; do not use DMA Article 6(7) or Article 7 language unless the service is a designated DMA .
For DMA, keep records of requests, eligibility decisions, technical interfaces, API documentation, security or integrity justifications, developer communications, and Commission specification materials. For Data Act, keep the switching or data-interoperability record separate.
Use DMA when the issue depends on a designated gatekeeper, a listed , or an Articles 5 to 7 obligation.
Use the Data Act when the issue depends on covered product or related-service data, another statutory data-sharing duty, a covered business-to-business data term, a qualifying exceptional-need public-sector request, or data-processing-service switching.
Use both only when the same product or data flow independently satisfies both triggers; keep the source, article, actor, evidence, and enforcement path separate.
If the issue is a gatekeeper's product release, ranking change, app-store rule, data-access interface, interoperability process, or Article 11 report update, run a DMA review before treating it as a general data-governance change.
Use the DMA column when the work concerns a designated gatekeeper, a designated , or a change to business-user access, end-user choice, ranking, advertising transparency, data portability, business-user data access, app stores, operating systems, browsers, or messaging interoperability.
Use the Data Act column when the work concerns access to product data or related service data from a , making covered data available to a user or the user's chosen third party, statutory data-sharing terms, unfair unilaterally imposed business-to-business data terms, a qualifying exceptional-need public-sector request, or switching between data processing services.
Do not treat a DMA data-access obligation as a general Data Act access request; tie it to the relevant gatekeeper and Article 6 duty.
Do not treat every Data Act data-sharing workflow as a DMA issue; the DMA applies only to designated gatekeepers and the core platform services listed in their designation decisions.
Do not assume every dataset generated around a is covered by Chapter II of the Data Act. That chapter excludes content and focuses on data concerning the product's performance, use, and environment, including data that the manufacturer designed to be retrievable.
Check Data Act Chapter II exclusions before opening a product-data workflow. Its obligations generally do not apply to data generated by connected products manufactured or designed, or related services provided, by a microenterprise or small enterprise that meets Article 7's independence and no-subcontracting conditions. A limited one-year transition also applies to specified newly medium-sized enterprises and their products.
A DMA-designated gatekeeper cannot receive Chapter II connected-product or related-service data as the user's chosen third party. A third party may still use a gatekeeper's data processing service, and gatekeepers may obtain the same data through another lawful route; keep those cases distinct.
When both laws are relevant, keep one evidence file but label each item by source, article, actor, service, and request type.
For DMA work, the practical unit is not a generic platform or account. It is a designated gatekeeper and each listed in the Commission designation decision. The Commission publishes and updates the gatekeeper and core-platform-service list, and the obligation analysis should follow that list.
Organize DMA evidence service by service: Article 5 conduct controls, Article 6 controls that may need technical implementation or further specification, Article 7 number-independent interpersonal communications interoperability where applicable, and Article 11 reporting material that explains the measures in detail.
Keep a CPS register showing the gatekeeper, service, designation case, affected product surfaces, business users, end users, and owner.
Map each Articles 5 to 7 duty to the product, API, ranking, data, advertising, choice-screen, app-store, browser, operating-system, or messaging surface it affects.
For Article 11, retain the compliance statement, implementation explanation, supporting data, internal documents, user-interface evidence, technical change notes, consultation evidence, and non-confidential summary.
Both laws can use the language of data access, portability, interoperability, and business users. The source of the duty changes the implementation. Under the DMA, Article 6 includes duties such as business-user access to data generated in the context of relevant core platform services, end-user portability, search-data access, advertising measurement access, and interoperability with operating-system, hardware, or software features.
The Data Act comparison should stay separate unless the facts concern covered product or related-service data, a statutory data-sharing duty, an exceptional-need request by an eligible public body, a covered contract term, or switching between data processing services. Personal-data and privacy law continues to apply; where it conflicts with the Data Act, the applicable personal-data or privacy rule prevails. A single product team may own both tracks, but the legal trigger and evidence labels should not be merged.
For DMA self-preferencing, test ranking and related indexing or crawling for services and products offered by the gatekeeper itself versus similar third-party offerings.
For DMA interoperability, distinguish Article 6(7) operating-system, virtual-assistant, hardware, and software feature access from Article 7 messaging interoperability.
For Data Act work, identify the chapter and role before designing a control: user, , data recipient, public-sector requester, customer, or provider of data processing services.