Industry Standards – Digital Markets Act (DMA) – ITU Online IT Training
Essential Knowledge for the CompTIA SecurityX certification

Industry Standards – Digital Markets Act (DMA)

Ready to start learning? Individual Plans →Team Plans →

When a platform changes its rules overnight, the first teams to feel it are usually security, compliance, and vendor management. The Digital Markets Act (DMA) is the European Union regulation that turns those platform changes into a governance issue, not just a legal one.

Featured Product

Microsoft SC-900: Security, Compliance & Identity Fundamentals

Learn essential security, compliance, and identity fundamentals to confidently understand key concepts and improve your organization's security posture.

Get this course on Udemy at the lowest price →

Quick Answer

The Digital Markets Act (DMA) is an EU regulation that sets ex ante rules for large digital platforms called gatekeepers so markets stay fairer and more contestable. It affects search, app stores, marketplaces, messaging, and advertising, and it matters to security and compliance teams because it changes data access, interoperability, vendor risk, and operational controls.

Definition

Digital Markets Act (DMA) is a European Union regulation designed to limit unfair practices by dominant digital platforms and keep digital markets fair, open, and contestable. It targets gatekeepers that control access to users, data, distribution, and commercial visibility.

RegulationDigital Markets Act (DMA) as of July 2026
JurisdictionEuropean Union as of July 2026
PurposeFairer and more contestable digital markets as of July 2026
Primary TargetsGatekeepers and core platform services as of July 2026
Core Services CoveredSearch engines, app stores, marketplaces, messaging, advertising, and related platform services as of July 2026
Main ThemesFair access, interoperability, data portability, and transparency as of July 2026
Risk LensOperational continuity, third-party risk, and data governance as of July 2026

What the Digital Markets Act Is and Why It Exists

The Digital Markets Act (DMA) is an EU regulation that creates upfront rules for the largest digital platforms instead of waiting for harm to be proven case by case. The goal is simple: stop a handful of powerful intermediaries from controlling access to customers, data, and distribution in ways that squeeze competitors and reduce choice.

The European Commission designed the DMA to address market failures that traditional competition enforcement often handles too slowly. A platform can change ranking logic, app store terms, messaging access, or marketplace visibility long before an antitrust case finishes. For a business that depends on that platform, the impact can be immediate.

This is why security and compliance teams should care. The DMA is not only about antitrust theory. It affects operational risk, third-party dependence, data access, and business continuity when a major platform becomes the bottleneck between a company and its customers.

The DMA is best understood as a governance rulebook for digital dependencies. If your revenue, identity flow, or customer access runs through a gatekeeper platform, the regulation can change your risk profile even if your company is not the regulated gatekeeper.

For foundational governance concepts that support this topic, ITU Online IT Training’s Microsoft SC-900: Security, Compliance & Identity Fundamentals course is a useful fit because it reinforces how identity, access, and compliance controls work together.

Official references worth tracking include the European Commission Digital Markets Act page, the EUR-Lex legal text repository, and the European Commission Competition policy site.

Understanding Gatekeepers and Core Platform Services

Gatekeepers are very large digital platforms that act as critical intermediaries between businesses and end users. In DMA terms, they are not just popular platforms; they are platforms with structural power over access, distribution, and market reach.

The law focuses on core platform services, which commonly include search engines, app stores, online marketplaces, messaging services, social networking services, video-sharing platforms, operating systems, virtual assistants, and advertising services. The point is not the label. The point is the role the platform plays in controlling market access.

Why gatekeeper designation matters

Once a platform is designated as a gatekeeper, it faces specific obligations that ordinary platform providers usually do not. These obligations can include limits on self-preferencing, stronger transparency requirements, and more openness around interoperability and data use.

Downstream businesses are affected because they often build processes around gatekeeper behavior. If a platform changes ranking rules, app review practices, API policies, or messaging interoperability, the business user may see customer acquisition, service delivery, or support workflows change overnight.

Gatekeeper responsibilities Must follow DMA obligations on fair access, interoperability, transparency, and non-discrimination.
Ordinary platform responsibilities Usually follow general competition, consumer, privacy, and security laws without DMA-specific gatekeeper duties.

That difference matters because it changes who bears the burden of adapting to platform change. Even when your company is not the gatekeeper, your controls, contracts, and technical integrations may still need updates.

For official context, use the European Commission DMA legislation page and the Council of the European Union for policy background.

How Does the Digital Markets Act Work?

The DMA works by imposing proactive obligations on designated gatekeepers before anti-competitive harm becomes entrenched. That is a major shift from classic enforcement models that rely on investigations after the damage is already done.

  1. Designate the gatekeeper. The European Commission identifies platforms that meet size, reach, and intermediary thresholds.
  2. Assign obligations. The platform must comply with rules covering fair treatment, access, data use, and interoperability.
  3. Change business behavior. The platform must adjust ranking, bundling, app store terms, data sharing, and connection rules where required.
  4. Expose operational impact. Business users must adapt to new APIs, new access terms, new data flows, or new compliance controls.
  5. Monitor and enforce. Regulators can investigate non-compliance and issue penalties or corrective measures.

Proactive regulation is the key idea here. Instead of waiting for a company to prove harm after being demoted in search or locked out of interoperability, the DMA sets clear behavioral rules up front. That makes it easier for regulators to act and harder for gatekeepers to rely on opaque platform power.

The technical side matters too. A rule about interoperability is not abstract. It may mean a messaging platform has to support connection with third-party services, or a marketplace has to give sellers fairer access to business data. The compliance outcome becomes an integration and control problem.

For regulatory reading, the European Commission Digital Markets Act page is the primary source. For competition-law context, the European Commission competition policy site is also useful.

What Are the Key Obligations Under the DMA?

The DMA is built around several recurring obligations that change how gatekeepers treat business users and end users. Security and compliance teams should focus on the practical effect of those rules, not just the legal wording.

  • Fair access. Gatekeepers must avoid arbitrary barriers that block business users from reaching customers through the platform.
  • Non-discrimination. Similar services should be treated consistently, rather than giving a platform’s own products a hidden advantage.
  • No self-preferencing. A gatekeeper should not rank or display its own offerings above competitors simply because it controls the platform.
  • Interoperability. In some cases, a platform must allow connection with third-party services so users can communicate or exchange data more freely.
  • Data portability. Users and business customers should be able to move data more easily across services and platforms.
  • Transparency. Platform rules, ranking factors, access conditions, and restrictions should be clearer and more predictable.

The practical result is a narrower path for platform abuse and a broader path for competition. For a business user, this may mean more stable access to customers, fewer surprise policy shifts, and better leverage when negotiating integrations or data terms.

For security teams, the hard part is that openness can introduce complexity. More interoperability often means more endpoints, more permissions, more data exchange, and more places where authentication and authorization can fail.

Warning

Interoperability is not automatically safer. Every new connection expands the attack surface, so teams need strong identity controls, logging, and change management before they treat openness as a business win.

For related standards and governance concepts, see NIST Cybersecurity Framework and NIST guidance on accountability and risk management.

How Does the DMA Affect Data Access and Data Governance?

The DMA can change who can access data, what data can be shared, and under what conditions that sharing happens. That matters because platform data is often mixed: customer data, behavioral data, transaction data, and operational telemetry can sit together in one ecosystem.

Data governance becomes more complicated when a platform must share more information or support easier portability. Organizations have to decide whether shared data is personal data, business data, or operational data, and then apply the right controls to each category.

What security teams should watch

  • Data classification. Know what data is going to or coming from the platform.
  • Access control. Limit who can retrieve, export, or modify shared data.
  • Retention rules. Decide how long transferred or synchronized data should remain available.
  • Auditability. Keep logs that show who accessed what and when.
  • Minimization. Share only the data that is necessary for the business purpose.

This is where Data Minimization becomes relevant. If a workflow requires only order status and customer ID, do not expose full profile records or unnecessary metadata just because the platform can technically exchange them.

Governance teams should also align data handling with regulatory expectations from NIST and, where personal data is involved, the EU’s broader privacy framework through the European Data Protection Board. Openness does not remove privacy obligations.

In practical terms, the DMA can force a business to improve internal records. If you cannot clearly map which systems receive platform data, you will struggle to prove compliance, support incident response, or explain the control design during an audit.

Why Are Interoperability, APIs, and Integration Risk So Important?

Interoperability is the ability of systems to work together across vendor boundaries, and under the DMA it becomes both a policy issue and a technical one. For security teams, interoperability usually means APIs, identity federation, message exchange, and change management.

If a gatekeeper opens a messaging interface, changes app distribution rules, or exposes additional marketplace data, the business may gain flexibility. It may also gain new failure points. Every API integration needs authentication, authorization, rate-limit monitoring, schema validation, and alerting.

Typical integration risks

  • Broken authentication. Tokens expire, scopes change, or identity trust relationships weaken.
  • Overbroad authorization. A connector receives more access than it needs.
  • Version drift. The platform updates an API and the downstream service fails silently.
  • Data inconsistency. Synchronization delays create conflicting records across systems.
  • Hidden dependencies. One platform service relies on another service you did not inventory.

Real-world examples are easy to find. In a marketplace context, a seller depends on platform APIs for inventory updates, order status, and refund handling. In messaging, interoperability can affect how messages are routed, stored, and authenticated across services. In app distribution, policy changes can alter review cycles, payment flows, and release timing.

The technical lesson is straightforward: more open integration requires more disciplined controls. If a company does not test interoperability changes in a staging environment, it may discover the problem only after customers do.

For technical grounding, use the OWASP guidance on API and application security, plus vendor documentation such as Microsoft Learn when Microsoft services are part of the environment.

How Should Third-Party Risk and Vendor Management Change?

The DMA forces a rethink of vendor management because gatekeepers are not just vendors; they are dependency hubs. If one platform controls ranking, access, identity, or app distribution, its policy changes can hit revenue, service delivery, and compliance at the same time.

Third-party risk management should include platform dependency mapping, not just contract review. If a gatekeeper adjusts terms of service, data-sharing rules, or API behavior, downstream businesses may need legal, technical, and process changes immediately.

Pro Tip

Add gatekeeper platforms to your vendor risk register with a higher review cadence than ordinary SaaS suppliers. A monthly policy scan is often more useful than an annual questionnaire when the platform can change core business conditions quickly.

Questions to ask during due diligence

  • What data do we send to the platform, and what data do we receive back?
  • How quickly are policy changes announced and versioned?
  • What is the incident response process if the integration breaks?
  • Are service-level commitments documented, or are they only in public terms of service?
  • Do we have a fallback process if access is reduced or suspended?

This is where legal, procurement, security, and IT operations must work together. Procurement may focus on price, legal on terms, and security on controls. The DMA forces all three views into the same risk discussion.

For broader third-party and supply-chain expectations, review CISA supply chain risk guidance and NIST security frameworks.

What Operational and Security Impacts Should Organizations Expect?

The DMA can affect search visibility, customer acquisition, app distribution, transaction flows, and support operations. Those are not abstract market effects. They are direct operational inputs for sales, support, and security teams.

A platform change can cause revenue friction in several ways. Search ranking may shift. A marketplace may change listing rules. A messaging service may alter access conditions. An app store may revise payment or review requirements. Each of those changes can create a business continuity issue if no fallback path exists.

Security and continuity impacts

  • Service disruption. An integration stops working after an API or policy update.
  • Visibility loss. Customers can no longer find products or services as easily.
  • Data exposure. New exchange paths create additional privacy or security obligations.
  • Operational delay. Release, approval, or payment workflows slow down.
  • Incident complexity. Platform dependencies make root-cause analysis harder.

The best response is to treat gatekeeper changes as part of business continuity planning. If a platform rule change can block sales for 24 hours, that is an operational risk, not just a legal inconvenience.

Security teams should also review whether broader interoperability requires new logging, anomaly detection, or privileged access review. A more open ecosystem can be good for competition, but it must still preserve confidentiality, integrity, and availability.

For workforce and risk context, the U.S. Bureau of Labor Statistics Occupational Outlook Handbook remains a useful source for understanding growth in compliance- and security-adjacent roles, while World Economic Forum reports help frame digital governance trends.

How Should Teams Build Compliance, Monitoring, and Internal Controls?

Organizations need recurring controls, not one-time reviews, to manage DMA exposure. Platform dependencies change too quickly for static compliance checklists.

Internal controls should track policy updates, technical changes, and business impacts together. The goal is to make platform monitoring part of normal governance, not an emergency activity when something breaks.

  1. Inventory platform dependencies. Document which gatekeeper services support revenue, identity, communications, or distribution.
  2. Assign ownership. Name a business owner, technical owner, and risk owner for each dependency.
  3. Monitor updates. Subscribe to policy notices, developer change logs, and legal updates.
  4. Assess impact. Review whether a change affects data flows, contracts, access control, or service levels.
  5. Record decisions. Keep evidence for approvals, exceptions, and control changes.
  6. Test continuity. Validate fallback procedures and recovery steps when access changes.

ISO/IEC 27001 is useful here because it emphasizes repeatable controls, risk treatment, and documented accountability. Teams that already operate under ISO 27001 or similar governance models can fit DMA tracking into existing control libraries.

For many organizations, the most important control is a recurring review meeting. A 30-minute monthly check-in among legal, privacy, security, and IT operations can catch more issues than a large annual review that no one revisits.

NIST Cybersecurity Framework and NIST Risk Management Framework are good references for control discipline, traceability, and evidence collection.

How Does the DMA Fit Into the Broader Regulatory Landscape?

The DMA does not replace privacy, cybersecurity, or competition law. It sits alongside them and often intersects with them in the same workflow.

For example, Data Portability can support user choice, but it also raises questions about lawful transfer, retention, and access control. Interoperability may improve competition, but it may also create privacy risks if data is shared too broadly or without proper safeguards.

Where the DMA overlaps with other rules

  • Privacy law. Personal data transfers must still comply with GDPR obligations.
  • Security law and guidance. New data flows still need authentication, monitoring, and incident response.
  • Competition policy. DMA rules work alongside broader EU competition enforcement.
  • Vendor oversight. Platform dependency now belongs in third-party governance discussions.

This broader context is why the DMA is important for GRC teams. The regulation is not just about one law in one region. It reflects a shift toward stronger accountability in digital ecosystems where a few platforms can shape the operating conditions of many businesses.

For related policy and governance reading, use the GDPR portal, the European Data Protection Board, and CISA for operational security context.

What Should Security and GRC Professionals Do Next?

Security and GRC professionals should treat the DMA as a recurring risk-management topic, not a one-time legal briefing. The most useful response is a simple framework that translates regulation into action.

  1. Identify gatekeeper dependencies. List the platforms that control search, app distribution, messaging, identity, or transactions.
  2. Assess exposure. Ask what happens if ranking changes, API access is reduced, or interoperability expands.
  3. Define controls. Put contracts, logging, change management, and fallback procedures in place.
  4. Monitor change. Track policy notices, technical documentation, and regulator announcements.
  5. Escalate business impact. Translate platform risk into revenue, compliance, and continuity language for leadership.

A practical DMA impact checklist should cover vendors, integrations, user data, identity dependencies, and recovery options. If the business cannot answer those five questions quickly, the organization is probably underprepared.

This topic also maps well to the skills taught in Microsoft SC-900: Security, Compliance & Identity Fundamentals, especially around identity, compliance posture, and governance terminology. That foundation helps non-specialists understand why platform dependence is a control issue rather than just an IT inconvenience.

Business-language explanation example: “If our customer acquisition depends on one gatekeeper platform, a policy change could reduce visibility, break an integration, and create a compliance review before IT even finishes troubleshooting.”

For workforce relevance, the U.S. Department of Labor and BLS remain useful references for understanding how compliance, cybersecurity, and governance roles continue to converge.

What Are the Most Common Misconceptions About the DMA?

The biggest misconception is that the DMA is simply a punishment for big tech. It is not. It is a rule set intended to make digital markets fairer by limiting conduct that makes competition harder than it should be.

Another common mistake is assuming the DMA only affects companies based in the EU. That is wrong. Non-EU organizations can still be affected if they rely on gatekeeper services that operate in the EU or if their products and services depend on those platforms for customer access.

Teams also sometimes assume compliance belongs only to the gatekeeper. It does not. Downstream businesses may need to update contracts, integrations, controls, retention policies, and incident procedures when platform behavior changes.

Interoperability is helpful, but not a silver bullet

It is also a mistake to assume interoperability always improves security. A more connected environment can increase convenience and competition, but it also creates more ways for data to move, more systems to authenticate, and more errors to cascade.

That is why the right mindset is balance. Openness and security are not opposites. They are two requirements that must be engineered together.

For technical risk context, OWASP API Security is a useful reference when you evaluate new integration paths created by platform interoperability requirements.

Digital Markets Act FAQs

What is the Digital Markets Act in simple terms? It is an EU law that limits unfair behavior by large digital platforms so businesses and users have more choice and competition.

Does the DMA only apply to giant tech companies? No. The rules apply to designated gatekeepers, but downstream businesses that rely on those platforms may still have to change operations, contracts, and controls.

Why should cybersecurity teams care about the DMA? Because it affects access control, interoperability, API exposure, data handling, and vendor dependency, all of which can create security and continuity risk.

How does the DMA relate to data governance? It can change how data is shared, moved, and accessed, which means organizations need stronger classification, retention, and audit processes.

Is interoperability always a good thing? No. Interoperability can improve flexibility and competition, but it also increases the attack surface and the need for strong authentication, authorization, and monitoring.

How does the DMA differ from normal competition law? It uses proactive rules for specific gatekeepers instead of relying only on case-by-case enforcement after harm occurs.

DMA obligation Fair access, interoperability, transparency, and reduced self-preferencing.
Operational impact New integration work, revised controls, vendor updates, and continuity planning.

Key Takeaway

  • The Digital Markets Act is a governance issue, not just an antitrust issue. It changes how organizations depend on dominant platforms for access, data, and distribution.
  • Gatekeeper obligations can affect downstream businesses even when those businesses are not directly regulated. Policy changes can disrupt revenue, integrations, and compliance workflows.
  • Interoperability creates opportunity and risk at the same time. More connectivity means more integration effort, more security controls, and more monitoring.
  • Data governance matters as much as legal interpretation. Classification, access control, retention, and auditability become more important when platform data moves more freely.
  • Recurring monitoring is the right control model. DMA-related risk changes often arrive through platform announcements and technical updates, not formal audit notices.
Featured Product

Microsoft SC-900: Security, Compliance & Identity Fundamentals

Learn essential security, compliance, and identity fundamentals to confidently understand key concepts and improve your organization's security posture.

Get this course on Udemy at the lowest price →

Conclusion: The DMA as a Governance and Risk Imperative

The Digital Markets Act (DMA) reshapes how organizations depend on dominant digital platforms. Its practical effect is to force fairer access, more interoperability, stronger transparency, and less platform self-preferencing across key services.

For security and compliance teams, the important lesson is that DMA-related change is ongoing. It touches vendor management, data governance, identity, integration risk, and business continuity. The teams that handle it best are the ones that track platform dependencies, document decisions, and review exposure regularly.

If your business uses gatekeeper platforms for search, app distribution, messaging, marketplaces, or customer access, now is the time to build a real monitoring and control process. Treat the DMA like any other material operational dependency: inventory it, assess it, control it, and revisit it before the next platform rule change hits.

CompTIA®, Microsoft®, ISC2®, ISACA®, and PMI® are trademarks of their respective owners.

[ FAQ ]

Frequently Asked Questions.

What is the main purpose of the Digital Markets Act (DMA)?

The main purpose of the Digital Markets Act (DMA) is to regulate large digital platforms, known as gatekeepers, to ensure fair competition within the digital market. It aims to prevent these dominant platforms from abusing their market power and to promote a more level playing field for smaller and emerging businesses.

By establishing clear rules and obligations, the DMA seeks to foster innovation, protect consumer rights, and ensure that digital markets remain contestable and open. This regulatory framework helps reduce unfair practices such as anti-competitive behavior, unfair data practices, and preferential treatment of certain companies.

Who are considered gatekeepers under the DMA?

Gatekeepers under the DMA are large digital platforms that have a significant impact on the internal market due to their size, user base, and economic importance. These platforms typically offer core platform services such as online search engines, social networking services, app stores, and online intermediation services.

The criteria for being classified as a gatekeeper include a substantial reach within the EU, a significant impact on the internal market, and a strong position that allows them to influence the digital ecosystem. The regulation applies to companies that meet these thresholds, regardless of their country of origin.

What are some key obligations for gatekeepers under the DMA?

Gatekeepers are required to adhere to specific obligations designed to promote fair competition and protect user interests. These include transparency in advertising, fair ranking of search results, and providing users with more control over their data.

Additionally, gatekeepers must allow third-party app stores and prevent self-preferencing practices. They are also prohibited from combining personal data from different services without user consent and must enable business users to access and port their data easily. These obligations aim to curb anti-competitive behavior and foster innovation.

How does the DMA impact smaller businesses and consumers?

The DMA benefits smaller businesses by creating a more competitive environment where they can access digital markets on fairer terms. It limits the dominance of gatekeepers and prevents them from engaging in practices that stifle competition and innovation.

For consumers, the DMA enhances choice, privacy, and transparency. It ensures that digital platforms cannot unfairly manipulate search rankings or restrict access to essential services. Overall, the regulation aims to make digital markets more open and fair, fostering innovation and protecting consumer rights.

What are the consequences for gatekeepers if they violate the DMA?

Violations of the DMA can lead to significant penalties, including hefty fines that can reach up to 10% of a company’s worldwide turnover. Regulatory authorities have the power to investigate, issue compliance orders, and enforce corrective measures.

In addition to financial penalties, non-compliance can damage a company’s reputation and lead to increased scrutiny from regulators. The DMA also provides for remedial actions, such as requiring changes to business practices or service modifications, to ensure compliance and protect market fairness.

Related Articles

Ready to start learning? Individual Plans →Team Plans →
Discover More, Learn More
Industry Standards - Payment Card Industry Data Security Standard (PCI DSS) Learn about industry standards for payment card data security to ensure compliance,… Industry Standards - International Organization for Standardization/International Electrotechnical Commission ISO/IEC 27000 Series Discover how the ISO/IEC 27000 series helps security teams align controls with… AI-Enabled Assistants and Digital Workers: Disclosure of AI Usage Discover how transparent AI usage enhances trust, privacy, and security in enterprise… AI-Enabled Assistants and Digital Workers: Data Loss Prevention (DLP) Discover how AI-enabled assistants and digital workers can enhance your data loss… AI-Enabled Assistants and Digital Workers: Guardrails for Secure and Ethical Use Discover how implementing guardrails for AI-enabled assistants and digital workers enhances security… AI-Enabled Assistants and Digital Workers: Access and Permissions Discover how proper access permissions for AI-enabled assistants and digital workers enhance…
FREE COURSE OFFERS