The Digital Markets Act doesn’t just regulate the six companies Brussels named as gatekeepers – it reaches into every partner, integrator, and third-party service that touches their platforms, and DMA compliance for gatekeepers and their partners has quietly become a shared burden rather than a single-company obligation. Since the DMA’s core obligations took full effect on 7 March 2024, the European Commission has opened multiple non-compliance investigations, including formal proceedings against Apple, Alphabet, and Meta announced in March 2024, and the ripple effects have landed on app developers, advertisers, and B2B service providers who never expected to be part of a competition law enforcement story.
Who Actually Counts as a Gatekeeper Under the DMA
The Commission designated the first group of gatekeepers in September 2023: Alphabet, Amazon, Apple, ByteDance, Meta, and Microsoft. Booking.com was added in May 2024, bringing the list to seven companies covering platforms like Google Search, Android, iOS, the App Store, Amazon Marketplace, WhatsApp, Instagram, TikTok, LinkedIn, and Windows.
Designation isn’t permanent or static. A company crosses the threshold when it has an annual EU turnover of at least €7.5 billion (or a market cap of €75 billion) over the past three years, and its core platform service reaches at least 45 million monthly active EU end users plus 10,000 yearly active business users. Once designated, a gatekeeper gets six months to comply with each “core platform service” obligation listed in Articles 5, 6, and 7.
What trips people up is assuming the DMA only regulates the gatekeeper’s own website or app. It doesn’t. Article 6(4), for example, forces gatekeepers to allow sideloading and third-party app stores on iOS – a change that immediately altered the compliance surface for every developer distributing apps outside Apple’s walled garden.
Why Partners and Third Parties Inherit Compliance Exposure
A gatekeeper’s compliance posture cascades downward. When Apple opened iOS to alternative app marketplaces and browser engines in the EU starting with iOS 17.4 in March 2024, third-party marketplace operators suddenly had their own set of disclosure, security, and consumer-protection duties layered on top of standard GDPR obligations. The same happened with Meta’s “pay or consent” advertising model, which the Commission found non-compliant in April 2025 and fined €200 million – advertisers relying on Meta’s targeting infrastructure had to reassess their own data processing bases almost overnight.
Business users interoperating with gatekeeper APIs face a parallel risk: if a webhook integration or data-sharing pipeline built on top of a designated platform doesn’t handle consent signals or data portability requests correctly, the liability doesn’t stop at the gatekeeper. Anyone auditing webhooks and APIs for their compliance footprint needs to treat DMA-driven interoperability mandates as a new category of risk, not just a GDPR checkbox.
A common misconception is that DMA compliance is purely a “big tech problem” that smaller businesses can ignore. That’s wrong. Business users – the sellers on Amazon Marketplace, the app developers on iOS and Android, the advertisers running campaigns through Google Ads – are explicitly protected parties under the DMA, and several obligations (like the ban on self-preferencing under Article 6(5) or the prohibition on combining personal data across services without consent under Article 5(2)) directly change what data a partner is legally allowed to receive or process.
Practical Steps for Businesses Operating Alongside Gatekeepers
A GRC lead working with a company that distributes through App Store, Google Play, or Amazon Marketplace should start by mapping every data flow that touches a designated core platform service. That means:
1. Identify which gatekeeper platforms your business depends on (search, app distribution, social login, ad networks, marketplaces) and check the Commission’s official designation decisions for the exact obligations attached to each.
2. Review consent mechanisms on your own site or app if you receive data from a gatekeeper’s ad or identity service – Article 5(2) consent requirements for cross-service data combination often require you to have independent, verifiable consent records, not just a pass-through from the gatekeeper.
3. Update your privacy policy and data processing agreements to reflect new data-sharing or portability rights business users can now exercise, similar to how data processing agreements need updating when new obligations attach to a data flow.
4. Monitor gatekeeper compliance reports – Article 11 requires designated companies to publish an annual compliance report, which is a genuinely useful primary source most partners never read.
5. Watch for interoperability changes that alter your own consumer rights disclosures, particularly if you operate in the EU and display device- or platform-specific choice screens.
An experienced compliance analyst treats gatekeeper obligations the way they’d treat a vendor risk assessment: as an ongoing dependency, not a one-time legal read. The same logic that applies to vendor risk management extending beyond your own site applies here – your compliance posture is only as strong as the weakest platform you depend on.
Common Mistakes Businesses Make With DMA Obligations
The most frequent mistake is assuming DMA compliance and GDPR compliance are the same exercise. They overlap on consent and data portability, but the DMA adds competition-law concepts – anti-steering provisions, interoperability mandates, self-preferencing bans – that have no GDPR equivalent and require separate documentation.
A second mistake is reacting only after a Commission decision lands, rather than monitoring designation updates continuously. The Commission reviews and can add or remove gatekeeper designations, and Booking.com’s addition in 2024 caught several travel-industry partners flat-footed because they hadn’t been tracking the review cycle.
A third mistake, seen especially among smaller app developers, is trusting that a platform’s own compliance dashboard reflects the developer’s actual legal exposure. Apple’s Notarization process for sideloaded apps, for instance, checks for malware and basic integrity – it does not verify that the developer’s own privacy disclosures or consumer rights notices meet DMA or GDPR standards. That verification remains the developer’s job.
Frequently Asked Questions
Does the DMA apply to companies outside the EU?
Yes, if the gatekeeper’s designated core platform service is used by business users or end users located in the EU, regardless of where the company is headquartered. Partners and advertisers targeting EU users through a gatekeeper’s platform fall under the same territorial scope.
What penalties can gatekeepers face for non-compliance, and does that affect partners?
Fines can reach up to 10% of a company’s total worldwide annual turnover, rising to 20% for repeated infringements. While partners aren’t fined directly under the DMA, a Commission finding against a gatekeeper (like the €200 million Meta decision in April 2025) often forces immediate changes to shared infrastructure that partners must adapt to on short notice.
How often do gatekeeper obligations change?
The Commission can update specification decisions and open new investigations at any time; there’s no fixed annual cycle. Businesses relying on a designated platform should check the Commission’s DMA compliance page and the gatekeeper’s own annual compliance report at least quarterly.
Treat the DMA as a live dependency rather than a fixed rulebook: gatekeeper obligations shift with each Commission decision, and every business built on top of Apple, Google, Amazon, Meta, Microsoft, ByteDance, or Booking.com inherits a slice of that instability whether it asked for it or not.
