Authors
The EU’s Digital Markets Act and Digital Services Act are reshaping how technology companies operate, compete, and manage online services. In this episode, Reed Smith attorneys Natasha Tardif and Léonie Dhellemmes break down the latest enforcement actions, multimillion-euro fines, and key compliance considerations for businesses navigating Europe’s rapidly evolving digital regulatory framework.
Transcript:
Natasha: Hello everyone and thanks for joining us. Welcome back to Tech Law Talks. I am Natasha Tardif, partner in the European competition and regulatory practice of Reed Smith.
Léonie: And I'm Léonie, associate in Natasha's team. And this is Tech Law Talks; we'll help you navigate EU digital regulation.
Natasha: Yes, so let's open with the biggest number in this entire episode. In July 2026, the European Commission issued its largest DMA fine to date: €890 million against a single gatekeeper, enough to push that company's cumulative EU liabilities past €10 billion.
Léonie: The next day on a social media platform, President Trump accused the EU of illegal and highly unethical conduct and said it would pay a very big price. The US administration opened a Section 301 trade investigation into Europe's treatment of American tech firms. The company said it would likely appeal. It warns that complying with the decision would strip hotel prices, flight costs out of the European search results entirely.
Natasha: Yeah, so this is really a hot topic. A regulatory decision under the DMA became a transatlantic trade flashpoint. That's why we need to understand the law behind it, because it isn't going away.
Léonie: But the DMA exists to guarantee a level playing field for digital companies regardless of their size. It isn't aimed at punishing success. It is aimed at making sure size alone can't be used to block rivals. The DSA, in turn, gives users more control over what they see online. Users should be able to choose a feed that is not based on their personal data. The law also bans targeted ads aimed at children and bans profiling people based on sensitive data like religion or ethnicity.
Natasha: It's not a coincidence. These two were built together, the DMA and the DSA, as the European Commission introduced them as one package to cover, generally, practices in the online world.
Léonie: So let's dive into these two regulations. This series will guide you through Europe's digital laws. They apply based on where your users or data are, not where you're headquartered. Today we'll focus on DMA and the DSA, why they exist, what they require, and how enforcement has developed.
Natasha: So let's start with the DMA. It targets a number of services that the Commission calls core platform services, and those include search engines, app stores, messaging apps, browsers, social networks, and marketplaces. So it doesn't apply to a company as a whole. It doesn't apply to all of the company's activities either, only to those core platform services.
Léonie: Natasha, can you give me a concrete example of that?
Natasha: Yeah, let's take a gatekeeper designated for its operating system and its social network. When the Commission looked at that same company's search engine and browser, they didn't meet the thresholds. So those services stayed outside the DMA entirely. Same company, gatekeeper for two services, free of obligations for two others. Another gatekeeper had the same experience. Its advertising and mapping services didn't qualify, even though it is designated for its app store and operating system. And right now, the Commission is investigating whether certain cloud services should be added to the list, even though they don't currently meet the standard thresholds.
Léonie: What actually are those thresholds? If a company can meet them for one service and not trigger them for another, what happens?
Natasha: Well, it's a product-by-product assessment using three criteria. An undertaking will be designated as a gatekeeper in respect of a core platform service where it has a significant impact on the internal market, where it provides a core platform service, which is an important gateway for business users to reach end users, and where it enjoys an entrenched and durable position. Those criteria, even though they sound a bit abstract, are completed with a number of quantitative thresholds. So first the revenue threshold. €7.5 billion a year in the EU or a market value of €75 billion sustained over the last three years, that will help you meet the first criterion. The second criterion is a genuinely large user base for that specific service. The law sets that at 45 million monthly consumers and 10,000 business users a year across at least three member states. Undertakings have to self-assess whether they meet or not these criteria and they may also decide to notify the Commission within two months to avoid being fined, but they can, at the same time, present in their notification substantiated arguments that show that the criteria are actually not met. If a service meets all criteria, the Commission presumes it is a gateway and the company behind it becomes a gatekeeper for that service specifically.
Léonie: But how big is this list?
Natasha: So the list is comprised of seven companies, but 23 separate core platform services between them. So seven major technology groups have been designated in waves between 2023 and 2024. And it's worth noting that this isn't just a compliance story, it's reshaping how these companies grow as gatekeepers, as they have a separate obligation. They have to notify the Commission before many acquisitions, bringing DMA counsel into the M&A process, before signing. Notifications rose from three in 2023 to 16 in 2024 and 36 in 2025, so 55 in total. The Commission is watching not only existing services but also expansion through acquisitions.
Léonie: And can that gatekeeper status disappear again if the numbers change?
Natasha: Yes, absolutely. The Commission removed its online marketplace from a social media group's designation in April 2025, after active business users fell below 10,000 a year, the first time a core platform service came off that list. The social media group remained a gatekeeper for its other services, including its messaging app.
Léonie: But I want to know, is there a sequel to that one?
Natasha: There is indeed. More than a year later, in June 2026, the EU General Court annulled the Commission's 2023 designation decision for that social media group's online marketplace. It found the Commission had relied on outdated data and had not adequately explained why the service qualified as an online intermediation core platform service.
Léonie: So it's not just that the numbers moved, it's also because the paperwork itself was flawed.
Natasha: Well, in that case both were true. The list can change with usage and can be reassessed by courts.
Léonie: So we've talked about obligations a few times without saying what's actually banned, but Natasha what can't a designated gatekeeper do?
Natasha: Where four main obligations have been enforced up to now. First, no self-preferencing. You can't rank your own products above competitors in your own search results or app store on a discriminatory basis. Second, the one that's already produced fines, you can't stop a business from telling customers through your app that they offer a better deal. Third, genuine interoperability and data portability. A user can take their data with them in real time to a competing service, and the headline example is messaging. A famous messaging service had to open up so as to allow its users to send content to users of rival messaging services. Alongside that, you can't quietly combine a user's data across your own products without their genuinely free specific consent. Fourth, no forcing an unchangeable default browser or search engine on people. They get a real neutral choice the first time they set up the device, not one designed to notch them back to the default.
Léonie: It's very interesting, Natasha, but I have a question because people often confuse the DMA with competition law. What's the actual difference?
Natasha: Well, DMA is not competition law in a traditional sense. Under Article 102 of the EU treaty, the Commission must first prove a company holds a dominant position, and then show it abused that position, meaning that it has to define a relevant market, demonstrate dominance, demonstrate abuse, demonstrate effects on the market. All that process can take easily five to ten years. The DMA skips that entirely. Once a service meets those objective gatekeeper thresholds, the obligations apply automatically. It's ex ante regulation. The rules come before the harm, not after.
Léonie: Thank you, Natasha. But now let's see what happens when rules are broken. Has the Commission actually fined anyone under the DMA?
Natasha: Yes indeed; we were mentioning it earlier. This July, the Commission fined a major gatekeeper €890 million in two decisions, €460 million for ranking its own shopping hotel and travel results above rivals in its search engine, and €430 million for restricting app developers from steering users to cheaper options outside its app marketplace.
Léonie: And the Commission was specific about the remedy, wasn't it? Not just the fine.
Natasha: Indeed, it is not just about a fine, it's about reshaping market behavior. The gatekeeper now has to treat third-party results fairly, let app developers communicate freely with users, and allow them to sell both inside and outside the app marketplace. The Commission did leave room for a fee on the initial connection, but it objected to how large it was and how long the gatekeeper kept charging for off platform sales.
Léonie: And barely a week before that fine, on July 16, the Commission handed the same gatekeeper guidance on AI assistance and search data sharing.
Natasha: Yes, it did, two binding decisions. The first let users set a third party AI assistant as default on its mobile operating system activated by voice, the same way the default voice assistant works now, with privacy and security safeguards.
Léonie: And the second decision puts this behind the gatekeeper's obligation to share search data with rival search engines, a right that rivals said was ineffective in practice?
Natasha: Exactly. AI chatbots with search functionality qualify as recipients. The gatekeeper must share comparable search data under a privacy protective method and fair pricing.
Léonie: Which bring us to another case, April 2025: €500 million against a device manufacturer. The company technically allowed developers to point users toward cheaper options outside its app store. But the Commission found the rights was not genuinely granted in practice. There were too many warning screens, misleading language, and residual fees.
Natasha: Yes, the Commission looked past what the gatekeeper's rules technically permitted and looked at the actual user journey, how many warning screens someone had to click through, how the language was framed, and what fees still applied even after a user left the app entirely.
Léonie: The same month, another gatekeeper was fined €200 million over its pay or consent advertising model. But what did the Commission find?
Natasha: So the gatekeeper gave users two choices: consent to data collection for personalized ads or pay for an ad-free version. The Commission found that the free, non-personalized alternative was never genuinely offered. In practice, users could only choose between paying and consenting, which the Commission treated as no real consent at all. The gatekeeper has since introduced a genuine third option, but daily penalties still apply if it falls short of that obligation.
Léonie: And none of this is actually settled yet, isn't it?
Natasha: That's right. A social media group and a device manufacturer filed annulment actions against their infringement decisions last July. Everything described is enforceable today, but the underlying legal doctrine is still being tested.
Léonie: So that was for the DMA, a market structure, gatekeeper obligations and the first wave of fines. Now let's turn to the other regulation that came out of the same package. So Natasha tell me, how is the DSA built differently?
Natasha: Well, the DSA follows a completely different logic from the DMA. While the DMA asks can a gatekeeper block rivals? The DSA asks can a platform manage the risks its content creates for users. One is about market power used against competitors, and the other is about harm caused to users by the content published. And the tools are different too. The DMA designates gatekeepers service by service, while the DSA catches a much wider range of companies with the heaviest rules reserved for the very largest ones.
Léonie: But Natasha, I don't understand. How does the DSA work in practice?
Natasha: Well if you host content, any content, you get baseline duties, a way for users to flag illegal material, an obligation to act promptly, and a clear point of contact. But the heaviest obligations apply only to the very larger services, what the DSA calls very large online platforms, VLOPs, and very large online search engines, VLOSEs, meaning platforms or search engines with more than 45 million average monthly users in the EU.
Léonie: And as the DMA, that list isn't fixed either. It's actually still growing, and stages can disappear here too.
Natasha: Yeah, so indeed, for instance an adult content platform was originally designated as a very large online platform, then published revised user numbers showing it below the 45 million threshold and the Commission undesignated it.
Léonie: But why do the biggest platforms get a heavier rule book rather than the same rules as everyone else?
Natasha: The DSA considers that large online platforms carry a special responsibility when they have a very large number of users in the EU, because a platform with tens of millions of EU users can shape public debate, expose minors to harm, and let illegal content spread at scale. That reach is why the DSA assigns particular responsibilities to very large online platforms and very large online search engines.
Léonie: That's a good frame. Thank you, Natasha. Let's actually open up on what's required to discuss on what spans for a gatekeeper. What does the DSA require in practice and at each level?
Natasha: Well, three tiers and each one adds obligations on top of the other. If you host any content at all, you're tier one, you need a genuinely accessible way for people to report illegal material, you have to act on those reports diligently and without arbitrary delay, and you need a clear point of contact both for users and for regulators within the EU.
Léonie: What about tier two?
Natasha: Where if you're what the DSA calls an online platform, meaning you don't just host content, you distribute it to the public?
Léonie: What does this reading to the public actually cover?
Natasha: Well, if your service puts content in front of other people, a social feed, a marketplace listing, a public review, you are distributing to the public, and tier two applies. At that level, you must handle user complaints about your moderation decisions, give access to out-of-court dispute resolution, prioritize reports from trusted flaggers, and ban deceptive design patterns. Marketplaces must also verify the identity of their traders. Léonie, why don't you tell us about the top tier, the rules for very large online platforms and online search engines?
Léonie: That's where it gets very demanding for companies. Companies must identify and assess the systemic risks their service creates: illegal content, harm to minors, threats to elections or public health. They must also mitigate those risks with documented measures and submit to an independent audit every year. They must also maintain a public searchable archive of all ads they run, offer users a non-personalized feed option, and give vetted researcher real access to their data. So almost everything we are about to discuss actually traces back to one of these three tiers failing.
Natasha: Precisely, keep that structure in mind because it explains the shape of every case coming up.
Léonie: And now we'll switch to the DSA enforcement. The first DSA fine was a major social media platform, which was fined €120 million on December 2025.
Natasha: Yeah, three findings, none about content moderation. The platform's paid "verified check mark" was considered as being misleading, and its public advertising archive was considered as not genuinely searchable.
Léonie: And qualified independent researchers were denied the data access they were entitled to.
Natasha: That is right, and the platform's remediation plan on advertising transparency and researcher access has since been accepted by the Commission.
Léonie: Two more large e commerce platforms were actually fined this year for inadequate risk management around illegal products. One was €200 million, the other was fined €550 million, the largest content governance fine to date. The Commission found that the larger marketplace hadn't matched its number of moderators to its actual workload, had recommended illegal products to consumers, and relied on a single metric that failed to capture whether banned products kept reappearing in new forms.
Natasha: Yeah, in both cases the Commission found the platform's own risk assessments were generic, not based on real evidence about their actual services.
Léonie: Which is the reminder for e-commerce. The DSA covers large platforms selling into European consumers, not only social networks.
Natasha: Yes, a major social media platform also has an open case from this past July. The Commission's preliminary finding is that the platform didn't ensure adequate privacy and safety for minors' accounts, leaving them exposed to unwanted contact, cyberbullying, and predatory behavior with effects the Commission explicitly said could last into adulthood.
Léonie: In practice, minors' account were public by default, and the platform kept sharing their content with strangers through its main feed.
Natasha: That's right, and the Commission left room for older minors, 16 and 17 years old, to share more broadly on the platform itself, but said that content should never become accessible to a global audience outside it. A final decision will follow consultation with the European Board for Digital Services, with a possible fine of up to six percent of global turnover.
Léonie: Public reaction frames the first fine as a European censorship of an American platform. But none of these cases concern what content stayed up or came down. They concern process, transparency and risk assessments, making this look more like a disclosure and internal controls regime than a speech policing. Let's now close with the key points from today's episode.
Natasha: Yeah, please bear in mind the difference in scope between DMA and the DSA. It might have been confusing at first, but these two pieces of legislation are different. The DMA is about market structure, it tells designated gatekeepers who have self-assessed and self-notified themselves as being those gatekeepers what they cannot do, and particularly that they cannot favor their own platforms to the detriment of competitors. And the DSA, on the other hand, is about content governance and protection of users. It tells all hosting services, and especially the largest ones, how to manage the risks their services create for users, and companies can actually be subject to both pieces of legislation.
Léonie: Second takeaway: designation is not permanent. Companies can come on and off the list under both regulations, and the courts are actively reviewing the Commission's decisions.
Natasha: Yes indeed, nearly every fine issued so far under both legislations came down to a process failure, not a deep substantive judgment call, a risk assessment that was too generic, a consent screen that was misleading, a transparency archive that didn't work. Process failures are fixable.
Léonie: Another key takeaway to keep in mind: none of the major infringement decisions are final yet. Appeals have been filed in almost every case. The law is enforceable today, but the legal doctrine is still being written by the courts.
Natasha: Yeah, and don't assume this only matters if you are a platform. The rules reach any manufacturer of a connected product sold into Europe well beyond the seven designated gatekeepers for the DMA purposes.
Léonie: So that's a wrap for the DMA and the DSA, but these two regulations are only part of a broader legislative package. In our next episodes we will cover three more pieces of European digital regulation that interact directly with today's topics, the AI Act, which regulates artificial intelligence systems by risk level, the Data Act, which extends data sharing rights far beyond the platform world, and the GDPR, the EU financial data protection framework, which underpins the consent and profiling rules we've discussed today.
Natasha: That is right. Thank you so much for listening to today's episode of Tech Law Talks, and we look forward to having you soon on our next episodes.
Outro: Tech Law Talks is a Reed Smith production. Our producers are Shannon Ryan, Amanda Saunders, and Mason Kautz. For more information about Reed Smith's Emerging Technologies Practice, please email [email protected]. You can find our podcast on all streaming platforms, reedsmith.com and our social media accounts at Reed Smith LLP.
Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation. Prior results do not guarantee a similar outcome. Any views, opinions, or comments made by any external guest speaker are not to be attributed to Reed Smith LLP or its individual lawyers.
All rights reserved.
Transcript is auto-generated.