EU Digital Markets Act Enforcement Penalties and Remedies
The European Commission can investigate DMA compliance, issue preliminary findings, adopt non-compliance decisions, impose fines or daily payments, and use interim measures, commitments, or remedies when their legal conditions are met.
Use this guide to separate each legal stage and prepare service-specific evidence for competition, product, engineering, data-governance, compliance, and reporting teams.
The European Commission is the central enforcer of gatekeeper obligations under the DMA. An investigation or preliminary finding does not establish non-compliance. A final Article 29 does, and the Commission may impose an Article 30 fine if the statutory conditions are met. Article 31 daily payments compel listed actions, while Articles 24, 25, and 18 govern interim measures, commitments, and remedies. Keep those stages separate in public statements and in the evidence file.
1
Section 1
What the Commission can enforce under the DMA
Article 29 requires the Commission to adopt a when it finds that a gatekeeper failed to comply with an obligation in Articles 5, 6, or 7, an Article 8(2) measure, an Article 18(1) remedy, an Article 24 interim measure, or an Article 25 commitment.
Before adopting that decision, the Commission communicates explaining the measures it is considering or considers the gatekeeper should take. The gatekeeper must have an opportunity to comment, and Article 34 gives at least 14 days for observations. Preliminary findings state the Commission's provisional view; they do not prejudge the final outcome.
A final decision orders the gatekeeper to cease and desist within an appropriate deadline and explain how it will comply. The Commission must publish the parties, main content, and any penalty while protecting legitimate confidential information. Article 45 gives the Court of Justice unlimited jurisdiction to review fines and .
Article 29 requires the Commission to endeavour to adopt the within 12 months after opening proceedings; that period is not an automatic expiry of the case. Articles 32 and 33 separately set five-year limitation periods for imposing and enforcing fines or , subject to their interruption and suspension rules.
Keep an enforcement register by core platform service, obligation, Commission measure, owner, and current evidence status.
Treat as a response deadline: preserve the Commission's objections, response period, file-access record, product facts, implementation history, user impact analysis, and proposed corrective measures by obligation.
For each possible breach, separate the underlying DMA obligation from any later Article 8 measure, Article 18 remedy, Article 24 interim measure, or Article 25 commitment.
After a , track the cease-and-desist deadline, any Article 30 fine, the description of measures taken to comply, publication and confidentiality treatment, any Article 45 court challenge, and whether the decision enters an Article 18 or Article 30(2) lookback.
DMA fine caps that should be recorded in the risk file
Article 30 lets the Commission impose, in a , a fine of up to 10 percent of the gatekeeper's total worldwide turnover in the preceding financial year when the listed failure was intentional or negligent. The percentage is a ceiling, not an automatic tariff or a prediction of the amount.
The ceiling can rise to 20 percent only where the gatekeeper committed the same or a similar infringement of an Article 5, 6, or 7 obligation involving the same core platform service as an infringement found in a adopted in the preceding 8 years. A separate ceiling of 1 percent applies to listed intentional or negligent procedural failures by undertakings or associations.
Actual decisions show that the ceiling does not determine the fine. On 23 April 2025, the Commission fined Apple EUR 500 million and Meta EUR 200 million in separate final DMA decisions. On 23 July 2026, it announced two final Google decisions and fines of EUR 460 million and EUR 430 million. Those findings and amounts are decision-specific.
Do not mix DMA fine caps with national competition-law or antitrust penalty tables unless a separate source and page covers that regime.
For each risk entry, capture whether the issue is substantive non-compliance, repeated same-service non-compliance, or a procedural/information failure.
Record the turnover base used for internal exposure analysis as a working assumption, not as a Commission fine calculation.
Keep the factors Article 30 names for fine-setting in the record: gravity, duration, recurrence, and delay caused to the proceedings for procedural fines.
Periodic penalty payments, interim measures, commitments, and remedies
Article 31 allows of up to 5 percent of average daily worldwide turnover in the preceding financial year per day, calculated from the date set by the decision. These daily payments compel an action listed in Article 31. Article 30 fines punish intentional or negligent failures under a separate decision rule. If the compelled obligation is later satisfied, the Commission may set a lower definitive amount.
Article 24 allows interim measures only where there is prima facie infringement of Article 5, 6, or 7 and urgency due to a risk of serious and irreparable damage for business users or end users. Article 25 allows commitments offered during an Article 18 investigation to become binding if the Commission finds that they ensure effective compliance.
Article 18 remedies require more than the prior-decision threshold. At least three Article 29 decisions within the 8 years before the decision opening the market investigation create the deemed systematic-non-compliance threshold. The investigation must also show systematic infringement of Articles 5, 6, or 7 and that the gatekeeper maintained, strengthened, or extended its gatekeeper position. The Commission may then impose proportionate and necessary behavioural or structural remedies.
For periodic penalty payment risk, identify the Commission decision or request that the payment would compel: information, data or algorithm access, inspection, interim measure, commitment, remedy, or Article 29 decision.
For interim-measure risk, document why the user or business-user harm analysis does or does not involve urgency and serious, irreparable damage.
For commitments, keep the offered commitment text, affected core platform services, third-party comments, implementation owner, and monitoring evidence together.
For Article 18 remedies, record the opening decision, the three-decision lookback, affected services and obligations, evidence about the gatekeeper position, , and any behavioural or structural remedy under consideration.
Article 11 compliance-report evidence that supports enforcement readiness
Article 11 reporting creates a recurring evidence record. The regulation requires every gatekeeper to provide a detailed and transparent compliance report within 6 months after designation, publish and provide a non-confidential summary, and update both at least annually. The Commission template states that failure to provide true, correct, and complete information may influence its prioritisation when considering an Article 29 proceeding. That statement alone does not establish non-compliance.
The evidence file should therefore align enforcement risk with the same material used to demonstrate effective compliance: obligation-by-obligation measures, assessment projects, audit or compliance-plan outputs, compliance-function reports, management-body replies, user feedback, and actions taken in response.
Maintain an Article 11 evidence index by obligation, core platform service, measure implemented, test result, owner, and latest update.
Store internal or external audit outputs, compliance plans, assessment methodology, timeline, participants, and independence notes where an assessment project supports a compliance claim.
Keep compliance-function reports to the management body, management replies, and measures taken in response to non-compliance risks.
Track business-user and end-user feedback established in or located in the Union, including confidentiality handling and non-confidential descriptions of actions taken.
Make the non-confidential summary faithful enough for third parties to provide meaningful input while withholding only business secrets or other confidential information.
Enforcement evidence checklist for gatekeeper teams
Use this checklist when a DMA issue could become a Commission question, preliminary finding, , fine analysis, periodic penalty payment, interim measure, commitment, or Article 18 remedy.
The checklist cannot predict the Commission's outcome. It connects the relevant obligation to product facts, measures, evidence, user impact, ownership, and corrective action.
Who enforces the EU Digital Markets Act against gatekeepers?
The European Commission is the central DMA enforcement authority for gatekeeper obligations. Article 29 sets the Commission's process, while other DMA provisions give the Commission investigative, interim-measure, commitment, remedy, fine, and periodic-penalty powers.
What are the DMA fine caps for gatekeeper non-compliance?
Article 30 allows fines up to 10 percent of total worldwide turnover in the preceding financial year for listed intentional or negligent non-compliance, up to 20 percent for the same or similar repeated Articles 5, 6, or 7 infringement involving the same core platform service within the stated 8-year lookback, and up to 1 percent for listed procedural failures.
What evidence matters most before a DMA enforcement issue reaches Article 29?
Keep obligation-specific evidence tied to the affected core platform service: implemented measures, tests or indicators, audit outputs, compliance-function reports, management responses, user feedback, corrective actions, and the Article 11 report section that explains the measure. Each item matters only to the extent that it proves the disputed fact or the measure's effectiveness.
Identify the designated gatekeeper, affected core platform service, DMA obligation or Commission decision, and whether the issue concerns Articles 5 to 7, Article 8, Article 18, Article 24, Article 25, Article 29, Article 30, or Article 31.
Attach Article 11 evidence: compliance-report section, non-confidential summary text, tests, indicators, audits, compliance-function records, user feedback, and management-body materials.
Classify the exposure using DMA categories only: , 10 percent fine cap, repeated-infringement 20 percent fine cap, 1 percent procedural fine cap, 5 percent daily periodic penalty payment, interim measure, binding commitment, or Article 18 remedy.
Document unresolved source gaps separately from legal analysis so the record does not turn unsupported dates, thresholds, or penalty details into published claims.
The Commission template supports the evidence checklist because it identifies report content, monitoring materials, compliance-function records, user feedback, and non-confidential-summary expectations.
The DMA text supports the enforcement checklist categories because it states the Commission powers for non-compliance decisions, fines, periodic penalty payments, interim measures, commitments, and remedies.