---
title: "EU Digital Markets Act FAQ: gatekeepers, DMA obligations, reports, and enforcement"
canonical_url: "https://www.sorena.io/artifacts/eu/digital-markets-act/faq"
source_url: "https://www.sorena.io/artifacts/eu/digital-markets-act/faq"
author: "Sorena AI"
description: "Concise FAQ on the EU Digital Markets Act for gatekeeper designation, core platform services, Articles 5, 6 and 7 obligations, Article 11 reports, interoperability, business-user data access, compliance evidence, and enforcement."
published_at: "2026-05-09"
updated_at: "2026-07-26"
keywords:
  - "EU Digital Markets Act"
  - "DMA FAQ"
  - "gatekeepers"
  - "core platform services"
  - "Article 5"
  - "Article 6"
  - "Article 7"
  - "Article 11 compliance report"
  - "Article 11 reports"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU Digital Markets Act FAQ: gatekeepers, DMA obligations, reports, and enforcement

Concise FAQ on the EU Digital Markets Act for gatekeeper designation, core platform services, Articles 5, 6 and 7 obligations, Article 11 reports, interoperability, business-user data access, compliance evidence, and enforcement.

*Artifact Guide* *EU*

## EU Digital Markets Act Frequently asked questions

Answers to the core DMA questions visitors ask about gatekeepers, core platform services, Articles 5, 6 and 7 obligations, Article 11 reporting, interoperability, business-user data access, compliance evidence, and enforcement.

This page helps orient product, legal, policy, engineering, and compliance work before reading the full legal text or a specific Commission designation decision.

Regulation (EU) 2022/1925, the EU Digital Markets Act, entered into force on 1 November 2022 and has applied in its main part since 2 May 2023. It applies to undertakings designated by the European Commission as gatekeepers, and its main conduct obligations apply only to the core platform services listed in the designation decision. The Regulation and designation decision control; Commission templates and portal materials explain procedure and expected evidence but do not replace the binding text. This FAQ explains the designation test, covered service categories, Articles 5, 6 and 7 duties, Article 11 reporting, interoperability, business-user data access, evidence, and enforcement.

## Definitions

### DMA gatekeeper

**Term:** gatekeeper

A gatekeeper is an undertaking designated by the European Commission under DMA Article 3. The Commission must find significant impact on the internal market, an important-gateway core platform service, and an entrenched and durable position or a foreseeable near-term position. Meeting the quantitative thresholds creates presumptions and a notification duty; designation still requires a Commission decision.

**Why it matters here:** Articles 5, 6, and 7 apply to a gatekeeper only for the core platform services listed in its designation decision. Other products or affiliated companies are not automatically subject to every gatekeeper obligation.

Sources:

- [Regulation (EU) 2022/1925, Articles 2(1) and 3](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io)

### Core platform service

A core platform service is one of the ten categories in DMA Article 2(2): online intermediation, online search, online social networking, video sharing, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, or qualifying online advertising services.

**Why it matters here:** The Commission lists the particular core platform service in the designation decision. That service boundary controls user counting, obligation mapping, and Article 11 reporting.

Sources:

- [Regulation (EU) 2022/1925, Articles 2(2) and 3(9)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io)

### DMA Article 11 compliance report

**Term:** Article 11 compliance report

An Article 11 compliance report is the gatekeeper's detailed and transparent submission describing the measures implemented to comply with DMA Articles 5, 6, and 7. The first report is due within six months after designation and must be updated at least annually.

**Why it matters here:** The Commission template organises evidence by designated core platform service and applicable obligation. It asks for implemented measures, supporting data, internal documents, testing, indicators, and a separate non-confidential summary.

Sources:

- [Regulation (EU) 2022/1925, Article 11](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io)
- [European Commission Article 11 DMA Compliance Report Template Form](https://digital-markets-act.ec.europa.eu/document/download/904debdf-2eb3-469a-8bbc-e62e5e356fb1_en?filename=Article+11+DMA+-+Compliance+Report+Template+Form.pdf&ref=sorena.io)

## Browse sub-FAQ modules

### [DMA Article 11 Compliance Report Template FAQ](/artifacts/eu/digital-markets-act/faq/compliance-report-template.md)

How gatekeepers should use the DMA Article 11 compliance report template to document obligation-by-obligation measures, evidence, updates, and non-confidential summaries.

- 3 items

### [DMA core platform services FAQ](/artifacts/eu/digital-markets-act/faq/core-platform-services.md)

FAQ on EU Digital Markets Act core platform services: Article 2 service categories, gatekeeper designation evidence, user thresholds, service scoping, and Article 11 reporting.

- 4 items

### [DMA gatekeeper thresholds: what counts and when to notify](/artifacts/eu/digital-markets-act/faq/gatekeeper-thresholds.md)

Standalone FAQ on the EU Digital Markets Act gatekeeper thresholds, Article 3 notification timing, Form GD evidence, and active user-count methodology.

- 5 items

### [DMA interoperability requests: Article 7 and Commission guidance](/artifacts/eu/digital-markets-act/faq/interoperability-requests.md)

How DMA Article 7 messaging interoperability requests work, including phased functions, the three-month operational deadline, reference offers, evidence, and safeguards.

- 3 items

### [What do DMA Articles 5, 6, and 7 require from gatekeepers?](/artifacts/eu/digital-markets-act/faq/articles-5-6-and-7-obligations.md)

FAQ explaining how EU Digital Markets Act Articles 5, 6, and 7 group gatekeeper obligations, what product evidence they require, and how Article 11 reporting connects.

- 4 items

Browse all indexed questions: [/artifacts/eu/digital-markets-act/faq/items](/artifacts/eu/digital-markets-act/faq/items.md)

## Who is a DMA gatekeeper?

A DMA gatekeeper is an undertaking designated by the European Commission because it has a significant impact on the internal market, provides a core platform service that is an important gateway for business users to reach end users, and has or is expected to have an entrenched and durable position.

The quantitative presumption uses three main tests: at least EUR 7.5 billion annual Union turnover in each of the last three financial years or at least EUR 75 billion average market capitalisation or equivalent fair market value in the last financial year; the same core platform service in at least three Member States; and, for that service in the last financial year, at least 45 million monthly active end users established or located in the Union and at least 10,000 yearly active business users established in the Union. The user thresholds must have been met in each of the last three financial years for the entrenched-and-durable-position presumption.

- An undertaking that meets the thresholds must notify the Commission without delay and in any event within two months after the thresholds are met.
- The Commission must designate a threshold-meeting undertaking without undue delay and at the latest within 45 working days after receiving complete information.
- Meeting the thresholds creates a presumption, but the undertaking may submit sufficiently substantiated arguments that the relevant service does not meet the gatekeeper requirements.
- The Commission can also designate an undertaking that meets the qualitative Article 3 requirements even if it does not satisfy every quantitative threshold.

Sources for this answer:

- [Regulation (EU) 2022/1925 (Digital Markets Act)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io) - Article 3 defines the gatekeeper test, thresholds, notification timing, designation timing, and designation without all quantitative thresholds.

## Which services count as core platform services?

Article 2(2) lists ten core platform service categories: online intermediation services, online search engines, online social networking services, video-sharing platform services, number-independent interpersonal communications services, operating systems, web browsers, virtual assistants, cloud computing services, and online advertising services provided by an undertaking that also provides another listed core platform service. Software application stores fall within online intermediation services; they are not a separate eleventh category.

The designation decision matters: DMA Articles 5, 6 and 7 apply to the gatekeeper with respect to each core platform service listed for that undertaking. Do not assume every product of a gatekeeper is covered in the same way.

- Build the scope map by undertaking, legal entity, designated core platform service, user metrics, geography, and the Article 3(9) designation decision.
- Treat integrated products carefully because the DMA Annex distinguishes services by category and by user purpose.
- Use the Commission gatekeepers page to check currently listed gatekeepers and their listed core platform services before applying an obligation to a product.

Sources for this answer:

- [Regulation (EU) 2022/1925 (Digital Markets Act)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io) - Article 2 and the Annex identify core platform service categories and user-counting concepts.
- [European Commission - DMA gatekeepers page](https://digital-markets-act.ec.europa.eu/gatekeepers-portal_en?ref=sorena.io) - Current Commission portal listing designated gatekeepers, their designated core platform services, and the related case records.

## What do Articles 5, 6 and 7 require?

Article 5 contains obligations that apply directly to listed core platform services, including restrictions on combining or cross-using personal data without valid consent, anti-steering limits, app-store and payment-choice protections, complaint-access protections, and advertising transparency for advertisers and publishers.

Article 6 contains obligations that can be further specified under Article 8. It covers restrictions on using non-public business-user data to compete with those business users, uninstall and default-choice requirements, third-party app and app-store access, self-preferencing in ranking, switching, interoperability with operating system or virtual assistant features, advertising measurement access, end-user data portability, business-user data access, search-data access, fair access conditions, and termination conditions.

Article 7 addresses interoperability for number-independent interpersonal communications services. Where such a service is listed in the designation decision, the gatekeeper must make specified basic functionalities interoperable with services of another provider offering or intending to offer such services in the Union, upon request and free of charge. One-to-one text and attached-file functions apply following listing, subject to the general six-month compliance period; group functions apply within two years after designation; and listed voice and video call functions apply within four years.

- For each obligation, identify the relevant core platform service first; the same undertaking can have different duties for different listed services.
- For Article 5 data-combination controls, check consent flows and whether refusal or withdrawal is respected without repeated requests for the same purpose more than once within one year.
- For Article 6 ranking, access, switching, portability, and interoperability duties, keep technical implementation records because Article 8 requires the gatekeeper to ensure and demonstrate effective compliance.
- For Article 7 messaging interoperability, preserve security, including end-to-end encryption where applicable, and keep request, reference-offer, timing, and data-minimisation evidence.

Sources for this answer:

- [Regulation (EU) 2022/1925 (Digital Markets Act)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io) - Articles 5, 6, 7 and 8 set the gatekeeper obligations and the duty to ensure and demonstrate effective compliance.

## What does Article 11 require in a DMA compliance report?

Within six months after designation, a gatekeeper must provide the Commission with an Article 11 compliance report describing, in a detailed and transparent manner, the measures implemented to ensure compliance with Articles 5, 6 and 7. It must also publish and provide the Commission with a non-confidential summary, then update the report and summary at least annually.

The Commission's Article 11 template asks gatekeepers to report for each designated core platform service and each applicable obligation. It expects a compliance statement, an exhaustive explanation, supporting data, internal documents, implementation dates, product and geographic scope, technical and engineering changes, terms and condition changes, user or business-user consultation, testing, metrics, and reasons where an obligation cannot by nature apply to a service.

- Organize evidence by core platform service, Article 5/6/7 obligation, measure, implementation date, market scope, and owner.
- Keep non-confidential summaries specific enough for third parties to provide meaningful input to the Commission.
- Track omitted obligations explicitly; the template allows omission only where the undertaking explains why a specific obligation cannot by nature apply to the relevant core platform service.
- The template says the report, annexes, non-confidential summary, and underlying data should be machine-readable.

Sources for this answer:

- [Regulation (EU) 2022/1925 (Digital Markets Act)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io) - Article 11 sets the six-month compliance-report deadline, non-confidential summary requirement, and annual update duty.
- [European Commission - Article 11 DMA compliance report template](https://digital-markets-act.ec.europa.eu/document/download/904debdf-2eb3-469a-8bbc-e62e5e356fb1_en?filename=Article+11+DMA+-+Compliance+Report+Template+Form.pdf&ref=sorena.io) - Commission template specifying minimum information expected in DMA Article 11 compliance reports.

## How do interoperability and business-user data access work?

Interoperability appears in two important places. Article 6(7) requires free and effective interoperability with, and access for interoperability to, the same hardware and software features controlled through listed operating systems or virtual assistants as are available to the gatekeeper's own services or hardware, subject to strictly necessary and proportionate integrity protections that the gatekeeper justifies. Article 7 separately covers interoperability of listed number-independent interpersonal communications services.

Article 6(10) requires a gatekeeper, on request and free of charge, to provide business users and authorised third parties with effective, high-quality, continuous and real-time access to aggregated and non-aggregated data generated in the context of the relevant core platform service or supporting services by those business users and the end users engaging with their products or services. Personal data access is limited to data directly connected with the end user's use of the relevant business user's products or services and requires end-user opt-in consent.

- For interoperability requests, keep the request, feature requested, service or hardware provider, API or interface offered, security assessment, refusal or limitation rationale, and delivery timing.
- For business-user data access, keep request records, authorisations, data categories, personal-data consent status, latency or continuity evidence, access logs, and any refused categories with reasons.
- The Commission's resources for businesses page links to gatekeeper materials for Article 6(7) OS interoperability, Article 6(9) data portability, and Article 6(10) data access.

Sources for this answer:

- [Regulation (EU) 2022/1925 (Digital Markets Act)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io) - Articles 6(7), 6(10) and 7 define interoperability and business-user data-access duties.
- [European Commission - DMA interoperability portal](https://digital-markets-act.ec.europa.eu/developer-portal/interoperability_en?ref=sorena.io) - Current Commission portal for Article 6(7) specification proceedings and gatekeeper-specific interoperability resources.
- [European Commission - DMA resources for businesses](https://digital-markets-act.ec.europa.eu/developer-portal_en?ref=sorena.io) - Commission page collecting gatekeeper resources for OS interoperability, data portability, and data access requests.

## What compliance evidence should a gatekeeper maintain?

DMA evidence should prove effective compliance, not only policy intent. The Article 11 template points to concrete evidence categories: implemented measures, supporting data, internal documents, implementation timing, technical and engineering changes, user-interface flows, APIs, terms and condition changes, consultation records, market analysis, A/B testing, user or business-user surveys, consent rates, metrics, and impact evaluation.

Article 13 also matters for evidence because a gatekeeper may not undermine effective compliance through contractual, commercial, technical, interface-design, or other behaviour. Evidence should therefore show that DMA rights are not made unduly difficult to exercise and that choices are not presented in a non-neutral way.

- Keep a service-by-service obligation matrix for Articles 5, 6 and 7.
- Attach engineering release evidence, API documentation, access logs, ranking-change records, data-access records, consent-flow records, and interoperability request records to the relevant obligation.
- Record rejected alternatives and reasons, especially for interoperability and access choices where the Commission template asks for alternatives considered.
- Keep user and business-user communications consistent with the internal compliance evidence.

Sources for this answer:

- [Regulation (EU) 2022/1925 (Digital Markets Act)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io) - Articles 8 and 13 require effective compliance and prohibit circumvention or undermining DMA rights.
- [European Commission - Article 11 DMA compliance report template](https://digital-markets-act.ec.europa.eu/document/download/904debdf-2eb3-469a-8bbc-e62e5e356fb1_en?filename=Article+11+DMA+-+Compliance+Report+Template+Form.pdf&ref=sorena.io) - Commission template identifying the operational, technical, data, consultation, testing, and metric evidence expected in compliance reports.

## How is the DMA enforced and what penalties can apply?

The European Commission enforces the DMA. It can open proceedings, specify measures for effective compliance, adopt non-compliance decisions, order the gatekeeper to cease and desist, and require explanations of how the gatekeeper plans to comply.

For non-compliance with Articles 5, 6 or 7 and specified measures, remedies, interim measures, or binding commitments, the Commission may impose fines up to 10% of the gatekeeper's total worldwide turnover in the preceding financial year. For the same or similar infringement of an Article 5, 6 or 7 obligation for the same core platform service after a non-compliance decision in the preceding eight years, the fine can be up to 20%. The Commission may also impose periodic penalty payments up to 5% of average daily worldwide turnover in the preceding financial year per day to compel compliance with listed DMA decisions or information duties.

- Do not treat the 10% and 20% figures as automatic penalties; the Commission fixes fine amounts by considering gravity, duration, recurrence, and, for some procedural fines, delay caused to proceedings.
- Separate substantive non-compliance evidence from procedural evidence such as notifications, information responses, inspection cooperation, compliance-function records, and access-to-file conditions.
- Commission enforcement can also rely on interim measures, commitments, market investigations, and specification decisions where the DMA conditions are met.

Sources for this answer:

- [Regulation (EU) 2022/1925 (Digital Markets Act)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io) - Articles 29, 30 and 31 cover non-compliance decisions, fines, and periodic penalty payments.
- [European Commission - DMA legislation page](https://digital-markets-act.ec.europa.eu/about-dma/legislation_en?ref=sorena.io) - Commission page explaining that the DMA contains designation rules and gatekeeper obligations, with procedural rules for implementation and enforcement.

*Recommended next step*

*Placement: before sources*

## Build a DMA obligation map for each designated core platform service

Sorena can help map Article 5, 6, 7 and 11 requirements to product controls, source citations, owners, evidence, and reassessment triggers.

- [Open Research Copilot for the EU Digital Markets Act](/solutions/research-copilot.md): Ask questions tied to cited sources about DMA designation, obligations, interoperability, reporting, evidence, and enforcement.
- [Talk through DMA implementation](/contact.md): Review your DMA scope map, compliance-report evidence, and product-control gaps with Sorena.

## Primary sources

- [Regulation (EU) 2022/1925 (Digital Markets Act)](https://eur-lex.europa.eu/eli/reg/2022/1925/oj?ref=sorena.io) - Binding DMA text for gatekeeper designation, core platform services, Articles 5, 6 and 7 obligations, Article 11 reporting, anti-circumvention, and penalties.
  - Quote: "contestable and fair markets in the digital sector"
- [European Commission - DMA legislation page](https://digital-markets-act.ec.europa.eu/about-dma/legislation_en?ref=sorena.io) - Commission overview of the DMA legislation, procedural implementing regulation, and enforcement context.
  - Quote: "implementation and enforcement of the DMA"
- [European Commission - DMA gatekeepers portal](https://digital-markets-act.ec.europa.eu/gatekeepers-portal_en?ref=sorena.io) - Current Commission portal listing gatekeepers, designated core platform services, and case records.
  - Quote: "currently designated"
- [European Commission - Article 11 DMA compliance report template](https://digital-markets-act.ec.europa.eu/document/download/904debdf-2eb3-469a-8bbc-e62e5e356fb1_en?filename=Article+11+DMA+-+Compliance+Report+Template+Form.pdf&ref=sorena.io) - Commission template for minimum information expected in Article 11 compliance reports and non-confidential summaries.
  - Quote: "Compliance Report Template Form"
- [European Commission - DMA interoperability portal](https://digital-markets-act.ec.europa.eu/developer-portal/interoperability_en?ref=sorena.io) - Current Commission portal for Article 6(7) specification proceedings and gatekeeper-specific interoperability resources.
  - Quote: "Interoperability specification proceedings"
- [European Commission - DMA resources for businesses](https://digital-markets-act.ec.europa.eu/developer-portal_en?ref=sorena.io) - Commission page collecting resources for businesses seeking OS interoperability, data portability, and data access under the DMA.
  - Quote: "Resources for businesses"


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/digital-markets-act/faq.md
