This comparison helps separate DMA duties for designated gatekeepers and core platform services from broader GDPR privacy compliance.
Use separate tests for DMA designation and duties, GDPR role and lawful basis, valid consent, data-subject rights, risk controls, records, and supervisory authority.
Use the DMA test when a designated gatekeeper changes a listed core platform service in a way that engages Articles 5, 6, or 7. Use the GDPR test whenever the facts involve processing within its material and territorial scope, then identify the , processor, purpose, lawful basis, data-subject rights, risk controls, and supervisory authority. The same consent screen, advertising flow, login, portability tool, or business-user API can require both reviews. Compliance with one law does not establish compliance with the other.
Side-by-side comparison
DMA vs GDPR: concrete differences for platform data work
Use these rows to decide whether a data, consent, advertising, portability, or access issue is a DMA gatekeeper obligation, a GDPR privacy obligation, or both.
DMA duties in this comparison apply to designated gatekeepers for the core platform services listed in their designation decisions.
Second framework
GDPR
GDPR governs processing of within its material and territorial scope and assigns duties according to roles such as and processor, regardless of DMA gatekeeper status.
DMA vs GDPR: concrete differences for platform data work
Start with Article 3 designation and the specific core platform service listed for the gatekeeper. The same undertaking may have DMA duties for one listed service and different treatment for another service.
Start with personal-data processing, territorial scope, and the organisation's role. Identify the , any joint controller or processor, processing purposes, data and people affected, Article 6 lawful basis, Article 9 condition where special-category data is involved, recipients, retention, transfers, risks, and rights.
Article 5(2) restricts listed practices by gatekeepers: online-advertising processing of third-party-service end-user , combining personal data across services, cross-using personal data across services, and signing users into other gatekeeper services to combine personal data, unless the DMA consent condition is met.
is one possible lawful basis, not a substitute for defining the purpose and role. Where consent is used, it must be freely given, specific, informed, and unambiguous; the must demonstrate it, distinguish the request clearly, allow withdrawal at any time, and make withdrawal as easy as giving consent.
A consent screen for a gatekeeper may need both a GDPR privacy review and a DMA Article 5(2) review of the specific gatekeeper practice and user choice.
Article 6(10) requires the gatekeeper, upon request and free of charge, to provide business users and authorised third parties with effective, high-quality, continuous and real-time access to relevant aggregated and non-aggregated data, including only under the conditions stated in the DMA.
If Article 6(10) data includes , GDPR still requires a lawful basis, transparency, purpose limitation, minimisation, security, and applicable rights. The DMA's opt-in condition for sharing personal data with a business user is an additional condition; it does not settle the full GDPR analysis.
Treat the API, entitlement, consent capture, data-category list, and request log as DMA evidence; link to GDPR records only for personal-data handling.
Article 6(9) requires effective portability, free of charge, for data provided by the end user or generated through the end user's activity in the relevant core platform service, including tools and continuous real-time access.
GDPR Article 20 covers concerning the data subject that the person provided to a when processing is automated and based on consent or contract. It requires a structured, commonly used, machine-readable format and direct transmission to another controller where technically feasible, subject to the rights and freedoms of others.
Do not satisfy Article 6(9) only by pointing to a generic privacy download page; test whether the relevant CPS data, third-party authorisation flow, and continuous access requirement are covered.
Article 11 requires the gatekeeper to provide a detailed and transparent compliance report, a non-confidential summary, and at least annual updates. The Commission template asks for CPS-by-CPS and obligation-by-obligation evidence.
GDPR evidence depends on the processing and risk. It can include Article 30 records, notices, lawful-basis and legitimate-interest assessments, consent logs, -processor terms, rights-request records, retention and deletion controls, security measures, breach records, transfer safeguards, and an Article 35 impact assessment where processing is likely to create high risk.
Maintain a mapped evidence pack: core platform service, DMA article and measure, plus the GDPR purpose, role, lawful basis, data categories, recipients, rights, risk record, and linked artifact. A GDPR record alone is not an Article 11 report.
Articles 5(9), 5(10), and 6(8) create DMA duties for gatekeepers around advertiser and publisher information, performance measuring tools, and data needed for independent verification of advertising inventory.
Where advertising data includes or profiling, identify the , processing purposes, lawful basis, transparency information, recipients, retention, profiling consequences, security, and rights. If the processing is likely to result in high risk, complete an Article 35 impact assessment before processing.
Separate advertising-product evidence into DMA information-access evidence, GDPR processing and risk evidence, and any commercial-confidentiality review.
The Commission is the DMA enforcement authority for gatekeeper obligations, designation, Article 11 reports, specification processes, and non-compliance proceedings.
Independent Member State supervisory authorities enforce the GDPR through investigative, corrective, authorisation, and advisory powers. Depending on the provision and Article 83 factors, administrative fines can reach EUR 20 million or, for an undertaking, 4% of total worldwide annual turnover in the preceding financial year, whichever is higher. Lower-tier maxima apply to specified other infringements.
Route DMA issues to the Commission-facing DMA owner and GDPR issues to privacy governance and the competent supervisory-authority process. Record each penalty basis separately.
Article 13 prohibits conduct that undermines effective compliance with Articles 5, 6, and 7 and specifically addresses making rights or choices unduly difficult or using interface design to subvert user or business-user autonomy.
GDPR review examines whether consent is valid, information is concise and intelligible, withdrawal and data-subject rights are facilitated, and data protection is built into the processing. An interface can fail the GDPR review even if the DMA choice is available, and vice versa.
Review consent prompts, choice screens, default settings, request forms, API access, and warning messages for both DMA effectiveness and GDPR privacy requirements where is involved.
Start with Article 3 designation and the specific core platform service listed for the gatekeeper. The same undertaking may have DMA duties for one listed service and different treatment for another service.
Start with the personal-data processing, territorial scope, and processor roles, purpose, lawful basis, special-category condition where relevant, transparency, rights, security, transfers, and risk. GDPR analysis does not depend on DMA gatekeeper status.
Start with Article 3 designation and the specific core platform service listed for the gatekeeper. The same undertaking may have DMA duties for one listed service and different treatment for another service.
Start with personal-data processing, territorial scope, and the organisation's role. Identify the , any joint controller or processor, processing purposes, data and people affected, Article 6 lawful basis, Article 9 condition where special-category data is involved, recipients, retention, transfers, risks, and rights.
Article 5(2) restricts listed practices by gatekeepers: online-advertising processing of third-party-service end-user , combining personal data across services, cross-using personal data across services, and signing users into other gatekeeper services to combine personal data, unless the DMA consent condition is met.
is one possible lawful basis, not a substitute for defining the purpose and role. Where consent is used, it must be freely given, specific, informed, and unambiguous; the must demonstrate it, distinguish the request clearly, allow withdrawal at any time, and make withdrawal as easy as giving consent.
A consent screen for a gatekeeper may need both a GDPR privacy review and a DMA Article 5(2) review of the specific gatekeeper practice and user choice.
Article 6(10) requires the gatekeeper, upon request and free of charge, to provide business users and authorised third parties with effective, high-quality, continuous and real-time access to relevant aggregated and non-aggregated data, including only under the conditions stated in the DMA.
If Article 6(10) data includes , GDPR still requires a lawful basis, transparency, purpose limitation, minimisation, security, and applicable rights. The DMA's opt-in condition for sharing personal data with a business user is an additional condition; it does not settle the full GDPR analysis.
Treat the API, entitlement, consent capture, data-category list, and request log as DMA evidence; link to GDPR records only for personal-data handling.
Article 6(9) requires effective portability, free of charge, for data provided by the end user or generated through the end user's activity in the relevant core platform service, including tools and continuous real-time access.
GDPR Article 20 covers concerning the data subject that the person provided to a when processing is automated and based on consent or contract. It requires a structured, commonly used, machine-readable format and direct transmission to another controller where technically feasible, subject to the rights and freedoms of others.
Do not satisfy Article 6(9) only by pointing to a generic privacy download page; test whether the relevant CPS data, third-party authorisation flow, and continuous access requirement are covered.
Article 11 requires the gatekeeper to provide a detailed and transparent compliance report, a non-confidential summary, and at least annual updates. The Commission template asks for CPS-by-CPS and obligation-by-obligation evidence.
GDPR evidence depends on the processing and risk. It can include Article 30 records, notices, lawful-basis and legitimate-interest assessments, consent logs, -processor terms, rights-request records, retention and deletion controls, security measures, breach records, transfer safeguards, and an Article 35 impact assessment where processing is likely to create high risk.
Maintain a mapped evidence pack: core platform service, DMA article and measure, plus the GDPR purpose, role, lawful basis, data categories, recipients, rights, risk record, and linked artifact. A GDPR record alone is not an Article 11 report.
Articles 5(9), 5(10), and 6(8) create DMA duties for gatekeepers around advertiser and publisher information, performance measuring tools, and data needed for independent verification of advertising inventory.
Where advertising data includes or profiling, identify the , processing purposes, lawful basis, transparency information, recipients, retention, profiling consequences, security, and rights. If the processing is likely to result in high risk, complete an Article 35 impact assessment before processing.
Separate advertising-product evidence into DMA information-access evidence, GDPR processing and risk evidence, and any commercial-confidentiality review.
The Commission is the DMA enforcement authority for gatekeeper obligations, designation, Article 11 reports, specification processes, and non-compliance proceedings.
Independent Member State supervisory authorities enforce the GDPR through investigative, corrective, authorisation, and advisory powers. Depending on the provision and Article 83 factors, administrative fines can reach EUR 20 million or, for an undertaking, 4% of total worldwide annual turnover in the preceding financial year, whichever is higher. Lower-tier maxima apply to specified other infringements.
Route DMA issues to the Commission-facing DMA owner and GDPR issues to privacy governance and the competent supervisory-authority process. Record each penalty basis separately.
Article 13 prohibits conduct that undermines effective compliance with Articles 5, 6, and 7 and specifically addresses making rights or choices unduly difficult or using interface design to subvert user or business-user autonomy.
GDPR review examines whether consent is valid, information is concise and intelligible, withdrawal and data-subject rights are facilitated, and data protection is built into the processing. An interface can fail the GDPR review even if the DMA choice is available, and vice versa.
Review consent prompts, choice screens, default settings, request forms, API access, and warning messages for both DMA effectiveness and GDPR privacy requirements where is involved.
Start with Article 3 designation and the specific core platform service listed for the gatekeeper. The same undertaking may have DMA duties for one listed service and different treatment for another service.
Start with the personal-data processing, territorial scope, and processor roles, purpose, lawful basis, special-category condition where relevant, transparency, rights, security, transfers, and risk. GDPR analysis does not depend on DMA gatekeeper status.
Name the gatekeeper and listed core platform service before applying a DMA row.
Identify the affected DMA obligation: Article 5 consent and data-combining limits, Article 6 data access or portability, Article 8 compliance demonstration, Article 11 reporting, or Article 13 anti-circumvention.
Run GDPR analysis separately for the personal-data processing: role, purpose, lawful basis, transparency, rights, security, retention, transfers, and high-risk assessment where required.
For shared evidence, label the exact DMA article and the exact GDPR record it supports instead of treating one as proof of the other.
Start with designation and core platform service scope
A DMA analysis is not triggered by every personal-data processing activity. The DMA applies to core platform services provided or offered by gatekeepers to business users established in the Union or end users established or located in the Union.
For a product review, first identify the designated gatekeeper, the exact core platform service listed in the designation decision, and the Article 5, 6, or 7 obligation affected by the change. Then run the GDPR review separately for the personal-data processing affected by the same product change.
Use the Commission gatekeepers page to confirm current designated gatekeepers and core platform services before relying on a DMA obligation.
Do not treat GDPR status as a shortcut for DMA scope; a or processor can have GDPR duties without being a DMA gatekeeper. A controller determines the purposes and means of processing; a processor handles on the controller's behalf.
Do not treat DMA scope as a substitute for GDPR analysis; Article 8 requires DMA compliance measures to comply with applicable law, including GDPR where relevant.
Where DMA and GDPR overlap on consent and personal data
Article 5(2) is the clearest DMA-GDPR touchpoint. For listed core platform services, it restricts specified gatekeeper practices involving unless the end user is presented with a specific choice and gives consent within the meaning of Articles 4(11) and 7 GDPR. must be freely given, specific, informed, and unambiguous, shown by a statement or clear affirmative action; the must be able to demonstrate it, and withdrawal must be as easy as giving consent.
The DMA text covers four practices: processing third-party-service end-user for online advertising services, combining personal data from the relevant core platform service with other gatekeeper or third-party services, cross-using personal data between services, and signing users into other gatekeeper services in order to combine personal data.
Build separate evidence for the DMA question: which Article 5(2) practice is being enabled, blocked, or changed for the listed core platform service.
Build separate privacy evidence for the GDPR question. Identify the processing purpose and Article 6 lawful basis, address special-category data under Article 9 where relevant, provide required information, and preserve the applicable rights and accountability records instead of assuming that DMA consent proves GDPR compliance.
Where consent is refused or withdrawn for Article 5(2), the DMA says the gatekeeper must not repeat the request for the same purpose more than once within one year.
Data access and portability are DMA product obligations, not just privacy rights
Article 6 creates operational duties that often require engineering work: access to performance measuring tools and advertising data, end-user data portability, and business-user access to aggregated and non-aggregated data generated in the context of relevant core platform services.
The GDPR right to portability is narrower in different ways. Article 20 applies to concerning the data subject that the person provided to a , where processing is based on consent or contract and is automated; it requires a structured, commonly used, machine-readable format and direct controller-to-controller transmission where technically feasible. DMA Article 6(9) instead applies to data provided by an end user or generated through that user's activity in the relevant core platform service and expressly includes continuous and real-time access.
Article 6(9) covers effective portability for data provided by the end user or generated through the end user's activity in the relevant core platform service.
Article 6(10) covers business-user access to aggregated and non-aggregated data, including where the DMA conditions are met and end users opt in to such sharing.
Use the Commission resources-for-businesses page to find public examples of gatekeeper resources for interoperability, data portability, and data access.
GDPR accountability records and DMA Article 11 reports can share facts, but they should not be merged into one generic evidence file. Article 11 requires every gatekeeper to provide the Commission with a detailed and transparent report describing measures implemented to ensure compliance with Articles 5, 6, and 7, plus a non-confidential summary.
The Commission's Article 11 template specifies separate annexes for each core platform service and each applicable obligation, compliance statements, supporting data and internal documents, implementation dates, product and geographic scope, technical and engineering changes, user-interface changes, terms changes, consultation, testing, indicators, and privacy or data-access safeguards where applicable.
For DMA work, maintain a CPS-by-CPS obligation matrix that maps each Article 5, 6, or 7 duty to implemented measures and supporting data.
For GDPR work, keep the applicable Article 30 processing record, notices, lawful-basis assessment, consent evidence, contracts and processor instructions, rights-request records, security and breach records, retention decisions, transfer safeguards, and any Article 35 impact assessment. Cross-reference them only where they support a DMA compliance measure.
When a DMA measure changes consent forms, user journeys, privacy policy terms, APIs, ranking parameters, data flows, or data-retention policies, store those artifacts with the Article 11 evidence pack.
Separate DMA gatekeeper evidence from GDPR privacy records
Sorena can help structure DMA Article 5, Article 6, and Article 11 evidence so product, legal, privacy, and engineering teams can see where GDPR records support the DMA work and where they do not.