[codicts-css-switcher id=”346″]

Global Law Experts Logo
dma compliance germany

Our Expert in Germany

  • GOLD

Preparing for DMA Designation in Germany (2026): Gatekeeper Obligations & Compliance Steps

By Global Law Experts
– posted 1 hour ago

DMA compliance Germany has become a board-level priority as the European Commission moves from designation and rule-making into an intensified enforcement phase in 2026. The Digital Markets Act (Regulation (EU) 2022/1925) imposes a dense set of ex ante obligations on designated gatekeepers, and companies operating core platform services in Germany now face concrete deadlines, documentary demands and penalty exposure of up to 20% of worldwide turnover for repeated infringements. This guide is written for in-house counsel, compliance leads and heads of product who need a procedural playbook, not high-level commentary.

It sets out the designation tests, a step-by-step preparation process, the documents regulators request, the timelines that apply once a notice lands, and the enforcement risk that defines the 2026 landscape.

What This DMA Compliance Germany Guide Covers (TL;DR)

  • Assessment first. Run the quantitative and qualitative designation tests to understand whether your platform is likely to be captured.
  • Prepare systematically. Follow an eight-step readiness process spanning legal, product, engineering and governance, with defined owners and durations.
  • Know the exposure. Understand compliance windows, required documents and the fine framework before any notice arrives.

1. Overview, The DMA and Germany in 2026

Quick summary of the Digital Markets Act

The Digital Markets Act is Regulation (EU) 2022/1925, a directly applicable EU regulation that creates an ex ante regime for the largest digital platforms. Rather than relying solely on case-by-case antitrust enforcement, the DMA designates certain providers of “core platform services” as gatekeepers and subjects them to a fixed list of obligations and prohibitions. Core platform services as listed in the Regulation include online intermediation services, online search engines, online social networking services, video-sharing platform services, number-independent interpersonal communications services, operating systems, web browsers, virtual assistants, cloud computing services and online advertising services. The regime is designed to keep digital markets contestable and fair, and it operates across the entire single market, including Germany.

2026 enforcement context, EU and Bundeskartellamt signals

The practical significance of the DMA has shifted. The designation framework and the first gatekeeper decisions are in place, and 2026 is characterised by monitoring, audits and non-compliance proceedings rather than foundational rule-making. The European Commission is the sole enforcer of the DMA, but the Bundeskartellamt, Germany’s national competition authority, has long been among the most assertive competition authorities in the digital sphere and operates its own national regime for digital players (notably Section 19a of the German Competition Act, the Gesetz gegen Wettbewerbsbeschränkungen / GWB). For companies in Germany, the effect is that DMA compliance is no longer a theoretical exercise, it is an operational obligation with live supervisory attention.

The likely practical effect, industry observers expect, is faster evidence requests, closer scrutiny of compliance reports and a greater willingness to open formal proceedings where remediation is slow or cosmetic. Firms that treat the DMA as a one-off legal filing rather than an ongoing programme are the most exposed.

2. Eligibility, How to Know if You May Be Designated a Gatekeeper

Designation is not discretionary guesswork; the DMA sets out presumptive quantitative thresholds supported by a qualitative assessment. Understanding both layers is the foundation of any DMA compliance Germany strategy.

Quantitative thresholds

Under Article 3 of the Regulation, a provider of core platform services is presumed to be a gatekeeper where it meets all three of the following:

  • Significant impact on the internal market. Annual turnover in the EEA of at least EUR 7.5 billion in each of the last three financial years, or an average market capitalisation (or equivalent fair market value) of at least EUR 75 billion in the last financial year, and provision of the same core platform service in at least three Member States.
  • An important gateway for business users. A core platform service with at least 45 million monthly active end users established or located in the EU, and at least 10,000 yearly active business users established in the EU, in the last financial year.
  • An entrenched and durable position. The user thresholds above being met in each of the last three financial years.

Qualitative factors

Meeting the thresholds creates a rebuttable presumption, but the Commission can also designate a provider that does not meet the numerical thresholds where a qualitative assessment (following a market investigation) shows it enjoys an entrenched and durable position, or that it is foreseeable one will be enjoyed. Relevant factors include the size and scale of the provider, the number of business and end users, network effects and data advantages, the degree of user lock-in, and whether the provider benefits from a multi-sided business model. A provider meeting the quantitative thresholds may attempt to rebut the presumption with sufficiently substantiated arguments, but the bar is high.

Practical self-test

Before engaging external counsel, internal teams should calculate and document the following metrics for each candidate service:

  • Monthly active end users in the EU, measured consistently with the methodology set out in the Annex to the Regulation.
  • Yearly active business users in the EU, including the counting basis used.
  • EEA turnover for the last three financial years and group market capitalisation.
  • Member State footprint, in how many Member States each service is provided.
  • Service classification, whether each service maps to a defined core platform service category.

Where the thresholds are met and a service maps cleanly to a core platform service, the likelihood of designation is high and preparation should begin immediately rather than waiting for a formal notice.

3. Step-by-Step Preparation, A DMA Compliance Germany HowTo

The following eight-step process converts the abstract obligations of the DMA into an operational programme. Each step identifies the lead function, a realistic duration and the deliverables that evidence compliance. The timings assume parallel workstreams where possible; the technical remediation step is almost always the critical path.

  1. Step 1, Conduct a DMA readiness audit. Legal and compliance (with external counsel where useful) collect top KPIs: user counts, turnover, market capitalisation, and a provisional service map. The deliverable is a designation-risk memorandum setting out whether and how the thresholds are met.
  2. Step 2, Map core services and data flows. Product and engineering, supported by the data protection officer, document each core platform service, the data it collects and processes, and how data moves between services. The deliverable is a data-flow and service architecture diagram.
  3. Step 3, Build an evidence and document preservation plan. Legal and IT records establish retention, logging and legal-hold processes so that relevant evidence survives and is retrievable. The deliverable is a preservation protocol with named custodians.
  4. Step 4, Update contractual terms and developer agreements. Commercial and legal teams review platform policies, developer agreements and partner SLAs to remove clauses that self-preference or discriminate, and to reflect new access rights. The deliverable is a revised contract and terms-of-service pack.
  5. Step 5, Implement technical measures. Engineering delivers the APIs, interoperability interfaces, data portability tooling and any required separation of data processing. This is typically the longest and most resource-intensive step. The deliverable is working, documented technical functionality.
  6. Step 6, Establish internal governance and reporting. Legal and the C-suite create a board-level briefing pack, an escalation path and the recurring compliance report required for Commission oversight. The deliverable is a governance framework and first reporting pack.
  7. Step 7, Prepare for regulator interaction. Legal and public affairs identify contact points for the Commission and the Bundeskartellamt, build response templates, and agree a redaction and privilege protocol. The deliverable is a regulator-engagement playbook.
  8. Step 8, Run tabletop simulations. Compliance, IT and PR rehearse an inspection or information-demand scenario, pressure-testing response times, document retrieval and messaging. The deliverable is a tested incident-response capability and a lessons-learned log.

Step / owner / duration timeline

Step (number & name) Who (lead) Typical duration
1. DMA readiness audit (metrics & service map) Legal + Compliance (external counsel optional) 2–6 weeks
2. Map core services & data flows Product/Engineering + Data Protection Officer 3–8 weeks
3. Evidence preservation & documentation plan Legal + IT (Records) 1–2 weeks to set up; ongoing
4. Contract & ToS updates (partners/developers) Commercial/Legal 4–12 weeks
5. Technical remediation (APIs, interoperability) Engineering/CTO 8–24 weeks (varies by scope)
6. Governance & board reporting Legal + C-Suite 1–2 weeks to prepare first pack; ongoing
7. Regulator interaction prep (templates & contacts) Legal + Public Affairs 2–4 weeks
8. Tabletop & incident response simulation Compliance + IT + PR 1–3 days per simulation

Sequencing the obligations themselves

The substantive obligations the programme must satisfy include ensuring interoperability where required, enabling data portability for end users, granting business users access to the data they generate, refraining from self-preferencing in ranking, allowing business users to promote offers and conclude contracts outside the platform, and refraining from combining personal data across services without consent. Mapping each of these to a named owner and a technical workstream in Step 5 is what separates genuine DMA compliance Germany from a paper exercise.

4. Required Documents, What Regulators Will Request

Whether during designation or a subsequent investigation, the Commission (and, within its national competence, the Bundeskartellamt) will expect prompt, well-organised documentation. Preparing these in advance compresses response timelines and signals a mature compliance posture.

Immediate documents on receipt of a notice

On first contact, regulators typically seek the metrics and service information that underpin designation: user and revenue figures, the list of core platform services and a high-level architecture overview. These should be retrievable within days, not weeks.

Secondary and follow-up documents

As an inquiry deepens, authorities move to technical evidence, API documentation, interoperability plans, data access logs and the contracts governing business-user relationships. These substantiate whether obligations are met in practice rather than on paper.

Best practice: naming, versioning and privilege

Adopt consistent document naming, maintain version control so superseded policies can be distinguished from current ones, and mark legally privileged material clearly. A disciplined redaction protocol protects commercially sensitive credentials while preserving the evidential value of what is disclosed.

Document category Examples Why regulators want it
Corporate metrics & financials User counts (DAUs/MAUs), EEA revenue breakdown, market cap To test quantitative thresholds and economic significance
Service maps & architecture List of core platform services, data flow diagrams, technical architecture To identify covered services and technical obligations
Data management evidence Data retention policies, data access logs, data portability processes To verify data access, portability and non-discriminatory treatment
Contracts & ToS Developer agreements, platform policies, partner SLAs To review discriminatory clauses and self-preferencing
APIs & technical specifications API docs, access credentials (redacted), SDKs, interoperability plans To assess technical feasibility of remedies
Internal compliance docs Board minutes, compliance audit reports, DPIAs To assess governance and prior mitigation
Communications & PR Draft public statements, email templates to partners To evaluate market communications and response plans

5. Timeline & Deadlines, What to Expect After Designation or Notice

Commission designation versus national involvement

The European Commission is the designating and enforcing authority under the DMA. It assesses whether a provider meets the thresholds, may run a market investigation where qualitative designation is in issue, and adopts a designation decision. The Bundeskartellamt does not designate DMA gatekeepers itself, but it coordinates with the Commission through the structures provided in the Regulation, may support investigations, and operates its own parallel national tool under Section 19a GWB for undertakings of paramount significance for competition across markets. For German firms, this means engagement can come from two directions, and a coherent DMA compliance Germany plan must anticipate both.

Typical deadlines

The DMA sets a framework within which, once designated, a gatekeeper must comply. Under Article 3 of the Regulation, a designated gatekeeper must comply with the obligations in Articles 5, 6 and 7 as soon as possible and in any event within six months after a core platform service has been listed in the designation decision. Information requests during investigations carry their own, often short, response windows set by the Commission in each request.

Extensions and phased compliance

Some technical obligations, particularly interoperability measures, may be implemented in dialogue with the Commission where the specifics allow. Companies should not assume extensions; instead, they should plan the engineering workstream (Step 5) to meet the statutory deadline and treat any flexibility as a contingency rather than a baseline.

Event Who issues Typical deadline / window
Notification of threshold metrics by the provider Provider → European Commission Within 2 months of meeting the thresholds
Formal designation as gatekeeper European Commission (decision under Art. 3) Generally within 45 working days of receiving complete information
Coordination with national authorities Commission ↔ Bundeskartellamt Ongoing coordination under the Regulation
Compliance with Art. 5, 6 & 7 obligations Designated gatekeeper Within 6 months of listing of the core platform service
Compliance report submitted to the Commission Designated gatekeeper Within 6 months of designation, then updated at least annually
Implementation monitoring & audits European Commission Ongoing

6. Costs, Fines and Enforcement Risk

The penalty framework under the DMA

The DMA’s enforcement teeth are significant. For infringements of its obligations, the Commission may impose fines of up to 10% of a gatekeeper’s total worldwide annual turnover in the preceding financial year. For repeated infringements within an eight-year period, that ceiling rises to up to 20% of worldwide turnover. The Commission may also impose periodic penalty payments of up to 5% of average daily worldwide turnover to compel compliance, and in cases of systematic non-compliance it may, following a market investigation, impose additional behavioural or structural remedies. These figures are set by the Regulation; the final calculation is always case-specific and reflects the gravity and duration of the breach.

The wider cost picture

Fines are only part of the exposure. Engineering remediation to build interoperability and data-portability functionality can be substantial, legal and advisory costs accumulate across designation and any investigation, and ongoing monitoring programmes carry recurring annual costs. Reputational damage and the operational disruption of restructuring commercial terms are harder to quantify but equally real.

Cost type Typical range / example Notes
Administrative fines under DMA Up to 10% (infringements) / 20% (repeated infringements) of worldwide turnover Set by the DMA Regulation; final calculation is case-specific
Periodic penalty payments Up to 5% of average daily worldwide turnover Imposed to enforce compliance with decisions
Legal & advisory fees Significant; scales with scope & complexity Includes counsel, external auditors, technical experts
Engineering & remediation Can be substantial for larger platforms Depends on required technical changes (APIs, data segregation)
Operational & monitoring costs Recurring annual cost Ongoing compliance program, reporting and audits

Gatekeeper versus non-gatekeeper obligations at a glance

Topic Gatekeeper obligations (after designation) Non-gatekeeper platforms
Data access & portability Mandatory data access & interoperability measures Voluntary / contractual
Non-discrimination Prohibited self-preferencing; ex ante rules Evaluated under general competition law
Monitoring & reporting Regular compliance reporting to the Commission No DMA reporting obligations

7. What Changed in 2026, Intensified Enforcement and German Signals

2026 enforcement priorities

The defining shift in 2026 is the move from establishing the regime to testing compliance in practice. Monitoring of designated gatekeepers has matured, information requests are more detailed, and non-compliance proceedings have moved up the agenda. The Bundeskartellamt, which has historically been an early mover in digital competition enforcement, including through its Section 19a GWB proceedings against large digital undertakings, remains a visible touchpoint for German operations and coordinates with the Commission under the DMA framework.

Practical implications for German firms

For companies pursuing DMA compliance Germany in this environment, the implications are concrete: evidence should be collected and retained continuously rather than assembled reactively; compliance reports must demonstrate real functionality, not aspirations; and response timelines should be compressed on the assumption that regulators will act faster than in the regime’s early years. Early indications suggest that the quality and verifiability of a gatekeeper’s compliance documentation will increasingly determine whether supervisory engagement escalates into formal proceedings.

8. Common Pitfalls and How to Avoid Them

  • Underestimating data and engineering scope. Interoperability and data-portability obligations frequently require more engineering effort than anticipated. Scope the technical workstream early and resource it as the critical path, not an afterthought.
  • Poor document controls. Missing access logs, unversioned policies and unclear privilege markings slow responses and undermine credibility. Establish logging, version control and legal holds before any notice arrives.
  • Treating the DMA as a purely legal issue. Compliance sits across legal, product, engineering, data protection and communications. A siloed, counsel-only approach will miss technical obligations and governance expectations. Build a standing cross-functional programme with a named executive owner.

Conclusion

DMA compliance Germany in 2026 is an operational discipline, not a one-off legal filing. Companies that assess their designation risk early, build a cross-functional readiness programme with clear owners and timelines, prepare their documents in advance and rehearse regulator interaction will be far better placed to meet the Commission’s deadlines and withstand Bundeskartellamt scrutiny. Those that wait for a notice before mobilising face compressed timelines, higher costs and significant penalty exposure. Use the step-by-step process and checklists in this guide to begin preparing now. For tailored advice, consult the Competition, Germany practice page or Find a Competition lawyer in Germany through the GLE directory.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Dr. Sebastian Jungermann at Arnecke Sibeth Dabelstein, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2022/1925 (Digital Markets Act), EUR-Lex (Official Journal)
  2. European Commission, Digital Markets Act (official portal)
  3. European Commission, Competition Policy
  4. Bundeskartellamt, Official website
  5. Bundesministerium für Wirtschaft und Energie (BMWE)
  6. Max Planck Institute for Innovation and Competition
  7. OECD, Competition

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Preparing for DMA Designation in Germany (2026): Gatekeeper Obligations & Compliance Steps

Send welcome message

Custom Message