DSA vs DMA content safety duties versus gatekeeper obligations
This comparison helps separate Digital Services Act duties for intermediary services, hosting, online platforms, marketplaces, VLOPs, and VLOSEs from Digital Markets Act duties for designated gatekeepers and their core platform services.
The DSA workstream is usually owned by trust and safety, marketplace operations, legal, policy, ads, recommender, and content-moderation teams. The DMA workstream is usually owned by competition counsel, platform product, engineering, data governance, developer relations, commercial operations, and compliance reporting teams.
The Digital Services Act and Digital Markets Act can apply to the same service, but neither status implies the other. The DSA classifies EU-facing intermediary services and adds duties by service role and size. The DMA applies only to an undertaking designated as a and only for the core platform services listed in its designation decision. Run both tests when a large platform handles content or traders and also controls access, defaults, data, interoperability, or business-user terms.
Side-by-side comparison
DSA vs DMA: operational differences that matter
This table helps decide which law controls a product change, incident, disclosure, access request, regulator question, or evidence gap.
The DSA regulates intermediary-service accountability, especially content moderation, platform transparency, user redress, marketplace traceability, advertising and recommender transparency, and systemic-risk governance for VLOPs and VLOSEs.
Second framework
Digital Markets Act
The DMA regulates designated gatekeepers and listed core platform services to keep digital markets contestable and fair for business users and end users.
market power: conduct by large core platform services that can restrict contestability, user choice, interoperability, data access, switching, business-user reach, or fair access terms.
Mere conduit, caching, hosting, online platforms, online marketplaces, online search engines, VLOPs, and VLOSEs, with obligations increasing by service role and size.
Designated gatekeepers and the core platform services listed in the designation decision, including categories such as online intermediation, search, social networking, video-sharing, number-independent messaging, operating systems, browsers, virtual assistants, cloud, and advertising services.
status uses online platform or search engine average monthly active recipients in the EU equal to or higher than 45 million, followed by Commission designation; the enhanced duties apply four months after notification.
designation uses significant-impact, gateway, and entrenched-position criteria. The quantitative presumption includes EUR 7.5 billion EU turnover in each of the last three financial years or EUR 75 billion average market capitalisation/equivalent fair market value in the last financial year, the same in at least three Member States, and in the last financial year at least 45 million monthly active EU end users and 10,000 yearly active EU business users. The user thresholds must have been met in each of the previous three financial years for the entrenched-position presumption.
Do not infer DMA status from DSA status, or the reverse. Run the tests separately, preserve the counting method, and use the Commission decision to identify the DMA-covered services. A listed generally has six months from designation to comply with .
obligations for each listed , including limits on personal-data combination without valid consent, anti-steering restrictions, access and interoperability duties, default-choice and uninstallability duties, fair access terms, data portability or access duties, anti-circumvention, Article 11 compliance reporting, concentration notices, and consumer-profiling audit descriptions.
Keep a shared evidence register only if each record identifies the regime, article or obligation, owner, source, affected service, date, and next review trigger.
Digital Services Coordinators supervise providers established in their Member State, while the Commission has direct supervisory and enforcement powers for VLOPs and VLOSEs. Commission fines for infringement can reach 6% of total worldwide annual turnover in the preceding financial year.
The Commission is the sole DMA enforcer, supported by cooperation with national authorities. Fines can reach 10% of total worldwide turnover in the preceding financial year, or 20% for the same or similar Article 5 to 7 infringement for the same after a non-compliance decision in the preceding eight years.
Regulator engagement should follow the regime. DSA escalation may involve a Digital Services Coordinator or the Commission for VLOPs/VLOSEs; DMA escalation is Commission-centered and tied to non-compliance.
A combined EU digital-regulation steering group can coordinate dependencies, but the accountable owners should remain tied to the system they can actually change.
The same product change can touch DSA and DMA at once when it affects content moderation, trader verification, ad labels, recommender disclosures, or risk work on one side and data access, interoperability, defaults, steering, or business-user terms on the other.
Reuse is possible only after the team separates the legal question: the DSA asks whether the service is handling intermediary-service duties, while the DMA asks whether a designated is changing conduct for a listed .
Check whether one change creates two obligations. If yes, keep one evidence file, but tag each artifact with the DSA or DMA rule it supports before you send it to legal, product, or regulators.
Start with DSA if the question is about illegal content, moderation, notice handling, transparency reporting, trader traceability, trusted flaggers, complaints, or systemic-risk mitigation for a platform or search service.
Start with DMA if the question is about a designated 's , especially defaults, access, data combination, interoperability, steering, self-preferencing, tying, or business-user terms.
If both regimes apply, assign two findings and two owners. Then decide which parts of the product spec, log set, or report can be shared without collapsing the DSA service-tier analysis into the DMA analysis.
Comparison row 1
Scope boundary
Digital Services Act
Online intermediary accountability: illegal content handling, content-moderation transparency, platform redress, marketplace trader traceability, advertising and recommender transparency, protection of minors, and systemic risks.
market power: conduct by large core platform services that can restrict contestability, user choice, interoperability, data access, switching, business-user reach, or fair access terms.
Frame DSA work as platform governance and safety operations. Frame DMA work as conduct, competition, access, and product-design compliance.
Comparison row 2
Covered actors
Digital Services Act
Mere conduit, caching, hosting, online platforms, online marketplaces, online search engines, VLOPs, and VLOSEs, with obligations increasing by service role and size.
Designated gatekeepers and the core platform services listed in the designation decision, including categories such as online intermediation, search, social networking, video-sharing, number-independent messaging, operating systems, browsers, virtual assistants, cloud, and advertising services.
Classify DSA services by intermediary role; classify DMA services by designation and listed .
Comparison row 3
Trigger
Digital Services Act
status uses online platform or search engine average monthly active recipients in the EU equal to or higher than 45 million, followed by Commission designation; the enhanced duties apply four months after notification.
designation uses significant-impact, gateway, and entrenched-position criteria. The quantitative presumption includes EUR 7.5 billion EU turnover in each of the last three financial years or EUR 75 billion average market capitalisation/equivalent fair market value in the last financial year, the same in at least three Member States, and in the last financial year at least 45 million monthly active EU end users and 10,000 yearly active EU business users. The user thresholds must have been met in each of the previous three financial years for the entrenched-position presumption.
Do not infer DMA status from DSA status, or the reverse. Run the tests separately, preserve the counting method, and use the Commission decision to identify the DMA-covered services. A listed generally has six months from designation to comply with .
Comparison row 4
Core obligations
Digital Services Act
Terms controls, points of contact, transparency reporting, hosting notice-and-action, statements of reasons, platform complaint handling, out-of-court dispute handling, trusted flagger priority, misuse controls, ad transparency, recommender transparency, minors safeguards, trader traceability, and risk management, audits, data access, compliance functions, and ad repositories.
obligations for each listed , including limits on personal-data combination without valid consent, anti-steering restrictions, access and interoperability duties, default-choice and uninstallability duties, fair access terms, data portability or access duties, anti-circumvention, Article 11 compliance reporting, concentration notices, and consumer-profiling audit descriptions.
Keep a shared evidence register only if each record identifies the regime, article or obligation, owner, source, affected service, date, and next review trigger.
Comparison row 6
Enforcement bodies and fine ceilings
Digital Services Act
Digital Services Coordinators supervise providers established in their Member State, while the Commission has direct supervisory and enforcement powers for VLOPs and VLOSEs. Commission fines for infringement can reach 6% of total worldwide annual turnover in the preceding financial year.
The Commission is the sole DMA enforcer, supported by cooperation with national authorities. Fines can reach 10% of total worldwide turnover in the preceding financial year, or 20% for the same or similar Article 5 to 7 infringement for the same after a non-compliance decision in the preceding eight years.
Regulator engagement should follow the regime. DSA escalation may involve a Digital Services Coordinator or the Commission for VLOPs/VLOSEs; DMA escalation is Commission-centered and tied to non-compliance.
Comparison row 7
Enforcement
Digital Services Act
Trust and safety, moderation operations, marketplace operations, advertising product, recommender-system owners, policy, legal, risk, compliance, audit, and researcher-access teams.
A combined EU digital-regulation steering group can coordinate dependencies, but the accountable owners should remain tied to the system they can actually change.
Comparison row 8
Overlap and reuse
Digital Services Act
The same product change can touch DSA and DMA at once when it affects content moderation, trader verification, ad labels, recommender disclosures, or risk work on one side and data access, interoperability, defaults, steering, or business-user terms on the other.
Reuse is possible only after the team separates the legal question: the DSA asks whether the service is handling intermediary-service duties, while the DMA asks whether a designated is changing conduct for a listed .
Check whether one change creates two obligations. If yes, keep one evidence file, but tag each artifact with the DSA or DMA rule it supports before you send it to legal, product, or regulators.
Comparison row 9
Practical decision rule
Digital Services Act
Start with DSA if the question is about illegal content, moderation, notice handling, transparency reporting, trader traceability, trusted flaggers, complaints, or systemic-risk mitigation for a platform or search service.
Start with DMA if the question is about a designated 's , especially defaults, access, data combination, interoperability, steering, self-preferencing, tying, or business-user terms.
If both regimes apply, assign two findings and two owners. Then decide which parts of the product spec, log set, or report can be shared without collapsing the DSA service-tier analysis into the DMA analysis.
Practical decision rule
How to decide which workstream controls a change
If the issue is illegal content, moderation, notice handling, user redress, advertising disclosure, recommender transparency, trader traceability, minors protection, or systemic risk, start with the DSA.
If the issue is a designated 's , user choice, data combination, access, interoperability, business-user terms, anti-steering, self-preferencing, defaults, tying, or compliance reporting under , start with the DMA.
If both apply, write two findings: one DSA service-tier finding and one DMA /core-platform-service finding.
Assign one operational owner per finding, then decide which logs, product specs, reports, or regulator submissions can be reused without changing their legal label.
Use the DSA when the fact pattern is about an intermediary service made available in the EU: mere conduit, caching, hosting, online platform, online marketplace, online search engine, VLOP, or VLOSE. DSA evidence normally starts with service classification and then moves into notice-and-action, statements of reasons, complaint handling, trusted flagger priority, transparency reporting, advertising and recommender disclosures, trader traceability, or systemic-risk files.
Use the DMA when the fact pattern is about a designated and a listed . DMA evidence normally starts with the designation decision, the core platform service map, the obligation matrix, product and data-flow changes, interoperability or access requests, anti-circumvention review, and the Article 11 compliance report.
A marketplace can have DSA duties even if it is not a DMA .
A can have DMA duties for a even where the disputed issue is not a DSA content-moderation issue.
When the same service is both an online platform under the DSA and a under the DMA, keep the source, owner, evidence, and regulator route separate.
Thresholds and designation are not interchangeable
The DSA's very large online platform and very large online search engine layer applies to online platforms and search engines with average monthly active recipients in the Union equal to or higher than 45 million, after Commission designation. Those services then face enhanced systemic-risk, audit, data-access, recommender, advertising, compliance-function, and reporting duties.
The DMA presumption uses a different test: significant internal-market impact, a that is an important gateway for business users to reach end users, and an entrenched and durable position. The quantitative presumption includes EUR 7.5 billion annual Union turnover in each of the last three financial years or EUR 75 billion average market capitalisation or equivalent fair market value in the last financial year, the same core platform service in at least three Member States, and in the last financial year at least 45 million monthly active EU end users and 10,000 yearly active EU business users. The user thresholds must have been met in each of the previous three financial years for the entrenched-and-durable-position presumption.
Thresholds create presumptions, not the final legal status. The Commission can designate an undertaking that meets the qualitative Article 3 criteria without meeting every quantitative threshold, and an undertaking meeting the thresholds may submit sufficiently substantiated arguments that call the presumption into question. The designation decision identifies the covered core platform services; the then has six months to comply with for those listed services.
Do not treat the shared 45 million user figure as the same legal test; the DSA uses average monthly active recipients for designation, while the DMA uses monthly active end users plus yearly active business users for core platform services.
Do not apply DMA because a service is large under the DSA or merely crosses the DMA thresholds; the duties follow a Commission designation and its list of core platform services.
Keep methodology notes for user counts, business-user counts, and service boundaries because both regimes let the Commission examine or request supporting information.
DSA ownership should sit with teams that can change platform governance and user-facing safety systems: trust and safety for notices, moderation, complaints, trusted flaggers, and misuse; marketplace operations for trader traceability; ads and recommender teams for disclosures and user controls; legal and policy for terms, transparency reports, and regulator responses; and risk or compliance teams for assessments, mitigation, audits, and researcher data access.
DMA ownership should sit with teams that can change conduct: competition counsel for interpretation and Commission engagement; product and engineering for defaults, interoperability, tying, access, and ranking changes; data governance and privacy for data-combination, portability, and access obligations; developer relations and commercial teams for business-user terms; and compliance reporting for Article 11 evidence and annual updates.
Use one coordinator only for dependency management; assign separate accountable owners for DSA content-safety controls and DMA contestability controls.
Route launch reviews differently: DSA review asks whether a feature changes platform safety, ads, recommender, marketplace, or VLOP risk duties; DMA review asks whether a 's changes access, interoperability, data, self-preferencing, tying, steering, defaults, or business-user conditions.
Label shared artifacts by obligation. For example, a recommender-system change may support DSA transparency or systemic-risk mitigation, while a ranking or access change may support DMA non-discrimination or business-user fairness.
Build two cited workstreams from the same product inventory
Sorena can help turn this comparison into a scoped DSA control map, DMA gatekeeper obligation matrix, owner assignments, and evidence requests that keep each regime's source and regulator route clear.