DMA vs DSA Digital Markets Act compared with Digital Services Act
The DMA regulates designated gatekeepers and listed core platform services. The DSA regulates intermediary services according to their service category and adds further duties for online platforms, marketplaces, very large online platforms, and very large online search engines.
Use this comparison to separate market-contestability duties from content-governance, transparency, user-redress, trader-traceability, and systemic-risk duties.
Use the DMA when the issue concerns a designated gatekeeper, a core platform service listed in its designation decision, and an obligation in Articles 5, 6, or 7. Use the DSA when the issue concerns an offered to recipients in the EU, then classify it as mere conduit, caching, hosting, online platform, online marketplace, online search engine, or a designated very large service. The DSA has applied generally since 17 February 2024; designated very large online platforms and search engines must comply with their additional duties four months after designation. The same service can fall under both laws, but the legal tests, controls, reports, and enforcement records remain separate.
Side-by-side comparison
DMA vs DSA: where the work diverges
Classify the service under each law, then keep the applicable duties, evidence, deadlines, authority, and outcome in separate records.
The Digital Markets Act targets designated gatekeepers and their listed core platform services to protect contestability and fairness in digital markets.
Second framework
DSA
The Digital Services Act regulates intermediary services offered to recipients in the EU. Obligations accumulate by service category, with additional rules for hosting, online platforms, marketplaces, search engines, and designated very large services.
Has the Commission designated the undertaking as a gatekeeper, and is the issue tied to a listed core platform service used by EU business users or end users?
Does the service transmit, cache, or host information provided by recipients in the EU? If it hosts information, determine whether it disseminates that information to the public as an online platform, performs marketplace functions, or operates as an online search engine. Then check for a designation.
Do not treat a service as DMA-covered merely because it is large, or as subject to every DSA duty merely because it operates online. Apply the designation and service-category tests separately.
Articles 5, 6, and 7 impose DMA duties on gatekeepers. Examples include limits on data combination without consent, business-user freedom to offer different terms elsewhere, user choice and default changes, third-party app and app-store access, fair ranking, interoperability, portability, business-user data access, and messaging interoperability.
DSA duties fall on providers of intermediary services and build by category. Hosting services handle notices and explain restrictions. Online platforms add complaint, dispute, advertising, recommender, interface, and minor-protection duties. Marketplaces add trader traceability and product-compliance design. Designated VLOPs and VLOSEs add systemic-risk, mitigation, audit, data-access, and crisis-response duties.
Map each DMA requirement to the listed core platform service and each DSA requirement to the intermediary-service tier. Reuse a control only after documenting how it satisfies both legal tests.
DMA Article 6 includes interoperability with operating-system, hardware, and software features in specified contexts; end-user data portability; business-user access to data generated through relevant core platform services; advertiser and publisher measurement access; and search-data access on fair, reasonable, and non-discriminatory terms.
DSA duties are triggered by the service category and event: an authority order, illegal-content notice, content restriction, complaint, marketplace trader onboarding, advertisement, recommender-system design, risk assessment, audit, or data-access request. VLOP and VLOSE designation uses an average-monthly-active-recipient threshold of at least 45 million in the EU, followed by a Commission designation decision.
For DMA, preserve request and technical implementation evidence. For DSA, preserve the notice or decision, legal ground, reasons, timing, affected territory and account or content, redress path, reporting entry, and any tier-specific risk or audit evidence.
Article 11 requires gatekeepers to provide the Commission with a detailed compliance report within six months after designation and to update the report and non-confidential summary at least annually. The Commission template asks for detailed explanations, supporting data, internal documents, technical changes, customer-experience changes, consultations, alternatives, testing, and indicators.
DSA evidence includes transparency reports, statements of reasons for content-moderation decisions, average monthly active-recipient publications, advertising and recommender disclosures, complaint and dispute outcomes, trader checks for marketplaces, and, for VLOPs and VLOSEs, risk assessments, mitigation, audits, researcher data access, and advertising repositories.
A shared repository can exist, but label DMA evidence by gatekeeper, core platform service, and obligation, and DSA evidence by provider, service category, decision or risk, article, reporting cycle, and authority.
The Commission enforces the DMA against gatekeepers. For DMA non-compliance, Article 30 allows fines not exceeding 10% of total worldwide turnover in the preceding financial year, and up to 20% for the same or similar Article 5, 6, or 7 infringement concerning the same core platform service within the preceding eight years. Separate 1% fines can apply for specified information, notification, access, inspection, compliance-function, and file-access failures.
Digital Services Coordinators supervise providers established in their Member State, while the Commission has exclusive powers for the enhanced VLOP and VLOSE obligations and shares other enforcement powers for those designated services. Member States must provide for maximum fines of 6% of the provider's annual worldwide turnover in the preceding financial year for DSA non-compliance; maximum fines for supplying incorrect, incomplete, or misleading information, failing to reply or correct information, and failing to submit to inspection are 1% of annual income or worldwide turnover.
Escalate DMA and DSA risk through separate authority and penalty records. The DMA's 10% and repeat-infringement caps are not DSA caps, and the DSA's national penalty framework is not a DMA sanction.
The DMA has applied generally since 2 May 2023. A designated gatekeeper must comply with Articles 5, 6, and 7 within six months after the relevant core platform service is listed. The initial Article 11 report and non-confidential summary are due within six months after the gatekeeper's designation, with updates to both at least annually.
The DSA has applied generally since 17 February 2024. A service designated as a must comply with the DSA obligations applicable to that designation four months after notification of the designation decision. Online platforms and search engines publish average monthly active-recipient information at least every six months.
Calendar the DMA service-listing clock, the DMA Article 11 designation clock, the DSA general duties, the DSA six-month user-number publication cycle, and any four-month post-designation deadline separately.
The Commission enforces the DMA, supported by cooperation with national authorities. Track the affected article and core platform service, prior non-compliance, Commission measures or requests, and whether the Article 11 evidence is complete.
Track the provider's main establishment or legal representative, competent Digital Services Coordinator, any Commission competence for a designated , orders or information requests, complaints, inspections, interim measures, commitments, and penalty basis.
Document the authority, procedural posture, requested evidence, response deadline, and possible measures under the correct law. Enforcement competence does not determine whether the service is in scope.
A service can need both a DMA and a DSA review, but the analysis should be split into separate records so the evidence, owner, and decision path are clear.
The same service may also be a DSA intermediary, hosting service, online platform, marketplace, search engine, or designated very large service. Document that classification and its cumulative duties separately.
Reuse service descriptions, user metrics, interface evidence, and technical diagrams where relevant, but keep the legal tests and conclusions separate.
Start with the DMA question: is there a designated gatekeeper, a listed core platform service, and a specific Article 5, 6, or 7 issue that needs evidence or remediation?
Then classify the service under the DSA and identify the event or feature at issue: hosted content, moderation, notice, complaint, advertisement, recommender system, marketplace trader, minor protection, user-number threshold, systemic risk, audit, or authority request.
Has the Commission designated the undertaking as a gatekeeper, and is the issue tied to a listed core platform service used by EU business users or end users?
Does the service transmit, cache, or host information provided by recipients in the EU? If it hosts information, determine whether it disseminates that information to the public as an online platform, performs marketplace functions, or operates as an online search engine. Then check for a designation.
Do not treat a service as DMA-covered merely because it is large, or as subject to every DSA duty merely because it operates online. Apply the designation and service-category tests separately.
Articles 5, 6, and 7 impose DMA duties on gatekeepers. Examples include limits on data combination without consent, business-user freedom to offer different terms elsewhere, user choice and default changes, third-party app and app-store access, fair ranking, interoperability, portability, business-user data access, and messaging interoperability.
DSA duties fall on providers of intermediary services and build by category. Hosting services handle notices and explain restrictions. Online platforms add complaint, dispute, advertising, recommender, interface, and minor-protection duties. Marketplaces add trader traceability and product-compliance design. Designated VLOPs and VLOSEs add systemic-risk, mitigation, audit, data-access, and crisis-response duties.
Map each DMA requirement to the listed core platform service and each DSA requirement to the intermediary-service tier. Reuse a control only after documenting how it satisfies both legal tests.
DMA Article 6 includes interoperability with operating-system, hardware, and software features in specified contexts; end-user data portability; business-user access to data generated through relevant core platform services; advertiser and publisher measurement access; and search-data access on fair, reasonable, and non-discriminatory terms.
DSA duties are triggered by the service category and event: an authority order, illegal-content notice, content restriction, complaint, marketplace trader onboarding, advertisement, recommender-system design, risk assessment, audit, or data-access request. VLOP and VLOSE designation uses an average-monthly-active-recipient threshold of at least 45 million in the EU, followed by a Commission designation decision.
For DMA, preserve request and technical implementation evidence. For DSA, preserve the notice or decision, legal ground, reasons, timing, affected territory and account or content, redress path, reporting entry, and any tier-specific risk or audit evidence.
Article 11 requires gatekeepers to provide the Commission with a detailed compliance report within six months after designation and to update the report and non-confidential summary at least annually. The Commission template asks for detailed explanations, supporting data, internal documents, technical changes, customer-experience changes, consultations, alternatives, testing, and indicators.
DSA evidence includes transparency reports, statements of reasons for content-moderation decisions, average monthly active-recipient publications, advertising and recommender disclosures, complaint and dispute outcomes, trader checks for marketplaces, and, for VLOPs and VLOSEs, risk assessments, mitigation, audits, researcher data access, and advertising repositories.
A shared repository can exist, but label DMA evidence by gatekeeper, core platform service, and obligation, and DSA evidence by provider, service category, decision or risk, article, reporting cycle, and authority.
The Commission enforces the DMA against gatekeepers. For DMA non-compliance, Article 30 allows fines not exceeding 10% of total worldwide turnover in the preceding financial year, and up to 20% for the same or similar Article 5, 6, or 7 infringement concerning the same core platform service within the preceding eight years. Separate 1% fines can apply for specified information, notification, access, inspection, compliance-function, and file-access failures.
Digital Services Coordinators supervise providers established in their Member State, while the Commission has exclusive powers for the enhanced VLOP and VLOSE obligations and shares other enforcement powers for those designated services. Member States must provide for maximum fines of 6% of the provider's annual worldwide turnover in the preceding financial year for DSA non-compliance; maximum fines for supplying incorrect, incomplete, or misleading information, failing to reply or correct information, and failing to submit to inspection are 1% of annual income or worldwide turnover.
Escalate DMA and DSA risk through separate authority and penalty records. The DMA's 10% and repeat-infringement caps are not DSA caps, and the DSA's national penalty framework is not a DMA sanction.
The DMA has applied generally since 2 May 2023. A designated gatekeeper must comply with Articles 5, 6, and 7 within six months after the relevant core platform service is listed. The initial Article 11 report and non-confidential summary are due within six months after the gatekeeper's designation, with updates to both at least annually.
The DSA has applied generally since 17 February 2024. A service designated as a must comply with the DSA obligations applicable to that designation four months after notification of the designation decision. Online platforms and search engines publish average monthly active-recipient information at least every six months.
Calendar the DMA service-listing clock, the DMA Article 11 designation clock, the DSA general duties, the DSA six-month user-number publication cycle, and any four-month post-designation deadline separately.
The Commission enforces the DMA, supported by cooperation with national authorities. Track the affected article and core platform service, prior non-compliance, Commission measures or requests, and whether the Article 11 evidence is complete.
Track the provider's main establishment or legal representative, competent Digital Services Coordinator, any Commission competence for a designated , orders or information requests, complaints, inspections, interim measures, commitments, and penalty basis.
Document the authority, procedural posture, requested evidence, response deadline, and possible measures under the correct law. Enforcement competence does not determine whether the service is in scope.
A service can need both a DMA and a DSA review, but the analysis should be split into separate records so the evidence, owner, and decision path are clear.
The same service may also be a DSA intermediary, hosting service, online platform, marketplace, search engine, or designated very large service. Document that classification and its cumulative duties separately.
Reuse service descriptions, user metrics, interface evidence, and technical diagrams where relevant, but keep the legal tests and conclusions separate.
Start with the DMA question: is there a designated gatekeeper, a listed core platform service, and a specific Article 5, 6, or 7 issue that needs evidence or remediation?
Then classify the service under the DSA and identify the event or feature at issue: hosted content, moderation, notice, complaint, advertisement, recommender system, marketplace trader, minor protection, user-number threshold, systemic risk, audit, or authority request.
How should teams decide whether DMA or DSA owns the work?
Check DMA designation first: named gatekeeper, listed core platform service, and affected EU business-user or end-user flow.
Map the DMA issue to an Article 5, 6, or 7 duty, Article 11 reporting evidence, or Commission enforcement exposure.
For DSA, classify the intermediary-service tier, check small- or microenterprise exemptions provision by provision, confirm any designation, and map the event to the applicable duty.
Use shared evidence only after labelling which item supports DMA and which item supports DSA.
For DMA work, the first question is whether the undertaking is a designated gatekeeper and which core platform services are listed in the designation decision. The DMA regulation applies to core platform services provided or offered by gatekeepers to EU business users or EU end users, regardless of where the gatekeeper is established.
For DSA work, identify whether the service transmits, caches, or hosts recipient information. An online platform is a hosting service that stores and disseminates information to the public at a recipient's request, unless dissemination is only a minor and purely ancillary feature. Online marketplaces and online search engines have specific duties, while services designated as very large online platforms or very large online search engines have an additional systemic-risk layer.
Keep a DMA scope record for each designated core platform service rather than for the company as a whole.
Record the designation decision, listed service, affected business-user or end-user journey, and the Article 5, 6, or 7 duty being assessed.
Open a separate DSA scoping record when the same service raises content-moderation, illegal-content notice, user-redress, advertising, recommender-system, trader-traceability, marketplace product-safety, or systemic-risk questions.
A useful comparison classifies the service twice. The DMA record names the gatekeeper, listed core platform service, and affected Article 5, 6, or 7 obligation. The DSA record names the intermediary-service category, any online-platform or marketplace status, any very-large-service designation, and the duty triggered by the conduct.
The DSA control set is cumulative. Baseline intermediary-service duties include points of contact, representative duties where applicable, terms, orders, and transparency reporting. Hosting services add notice-and-action and statement-of-reasons duties. Online platforms add complaint handling, out-of-court dispute access, trusted-flagger treatment, interface and advertising rules, recommender transparency, and minor-protection duties, subject to stated exemptions. Marketplaces add trader traceability and compliance-by-design duties. Designated very large services add risk assessment, mitigation, crisis response, independent audit, data access, and enhanced transparency.
Use the Commission gatekeeper page or designation record to identify the gatekeeper and listed service.
Map the change or issue to a specific Article 5, 6, or 7 obligation before assigning engineering or product work.
Separate DMA evidence from DSA evidence so reviewers can see which statute, service category, article, and authority each artifact supports.
Treat Article 11 reporting as DMA-specific. DSA statements of reasons, transparency reports, user-number publications, risk assessments, audits, advertising records, and recommender documentation follow separate DSA provisions.
The DMA Article 11 template expects more than a policy assertion. For each applicable obligation, the gatekeeper is expected to explain the measure, timing, product and geographic scope, technical or engineering changes, user-journey changes, terms changes, consultations, alternatives considered, security or privacy safeguards, testing, indicators, and supporting data.
A product launch, app-store change, data-access API, advertising measurement flow, ranking change, choice screen, consent flow, or interoperability request can require DMA evidence that differs from the DSA evidence for the same service.
Keep pre-change and post-change descriptions for affected user journeys and business-user flows.
Retain API, operating-system, ranking, data-flow, consent, and security documentation where those measures demonstrate an Article 5-7 compliance position.
Keep raw data and indicators retrievable when the Article 11 template expects supporting data or effectiveness evidence.
Write the non-confidential summary separately from the full compliance report so confidential material is not leaked.
Interoperability and data access are DMA-specific pressure points
The DMA includes concrete interoperability and data-access duties. Article 6 includes effective interoperability with operating-system, hardware, or software features in specified contexts, end-user data portability, business-user data access, advertiser and publisher measurement access, and access to search data on fair, reasonable, and non-discriminatory terms.
The Commission's DMA resources for businesses point to request channels, API documentation, portability resources, and data-access materials made available by gatekeepers. Those resources help business users and developers turn a DMA right into an evidence-backed request, while any DSA claim should still be checked against DSA-specific sources.
For interoperability, identify the feature, operating system or service, request route, gatekeeper response, security justification, and implementation evidence.
For data portability, identify the end-user authorization route, covered data, format, timing, and whether access is continuous or real-time where the DMA obligation requires it.
For business-user data access, identify the business user, authorized third party, data generated through the relevant core platform service, and any personal-data consent condition.
For advertising and search data, keep request, response, data-field, frequency, and measurement evidence tied to the relevant Article 5 or 6 provision.
DSA evidence follows the service tier and moderation decision
For DSA work, preserve evidence for the duty that actually applies. A hosting-service notice file should show the notice, assessment, decision, timing, territorial scope, and statement of reasons. An online-platform file may also need complaint outcomes, out-of-court dispute records, trusted-flagger handling, interface testing, advertising disclosures, recommender-system parameters, minor-protection measures, and transparency-report inputs.
For a designated very large online platform or very large online search engine, keep the designation decision, average monthly active-recipient calculations, annual systemic-risk assessments, mitigation measures, crisis-response decisions, independent-audit materials, vetted-researcher data-access records, advertising repository inputs, and evidence showing how recommender options and terms were presented. These records do not replace the DMA Article 11 report even when the same service is covered by both laws.
Classify the service before choosing evidence; duties accumulate from through hosting, online platform or search engine, marketplace, and designated very-large-service status.
Apply the small- and microenterprise exemptions only to the provisions that contain them. They do not remove every DSA duty, and they do not apply once an online platform is designated as very large.
Use the DSA's four-month post-designation clock for additional duties and the DMA's six-month post-designation clock for Articles 5 to 7 compliance and Article 11 reporting; do not merge the calendars.
Official Commission overview of DSA service coverage, tiered obligations, designated very large services, user protections, and the general application date.
Official explanation of service coverage, the 45 million average-monthly-recipient designation threshold, the four-month post-designation compliance period, and general application from 17 February 2024.