Our Expert in Germany
No results available
DMA compliance Germany has become a board-level priority as the European Commission moves from designation and rule-making into an intensified enforcement phase in 2026. The Digital Markets Act (Regulation (EU) 2022/1925) imposes a dense set of ex ante obligations on designated gatekeepers, and companies operating core platform services in Germany now face concrete deadlines, documentary demands and penalty exposure of up to 20% of worldwide turnover for repeated infringements. This guide is written for in-house counsel, compliance leads and heads of product who need a procedural playbook, not high-level commentary.
It sets out the designation tests, a step-by-step preparation process, the documents regulators request, the timelines that apply once a notice lands, and the enforcement risk that defines the 2026 landscape.
The Digital Markets Act is Regulation (EU) 2022/1925, a directly applicable EU regulation that creates an ex ante regime for the largest digital platforms. Rather than relying solely on case-by-case antitrust enforcement, the DMA designates certain providers of “core platform services” as gatekeepers and subjects them to a fixed list of obligations and prohibitions. Core platform services as listed in the Regulation include online intermediation services, online search engines, online social networking services, video-sharing platform services, number-independent interpersonal communications services, operating systems, web browsers, virtual assistants, cloud computing services and online advertising services. The regime is designed to keep digital markets contestable and fair, and it operates across the entire single market, including Germany.
The practical significance of the DMA has shifted. The designation framework and the first gatekeeper decisions are in place, and 2026 is characterised by monitoring, audits and non-compliance proceedings rather than foundational rule-making. The European Commission is the sole enforcer of the DMA, but the Bundeskartellamt, Germany’s national competition authority, has long been among the most assertive competition authorities in the digital sphere and operates its own national regime for digital players (notably Section 19a of the German Competition Act, the Gesetz gegen Wettbewerbsbeschränkungen / GWB). For companies in Germany, the effect is that DMA compliance is no longer a theoretical exercise, it is an operational obligation with live supervisory attention.
The likely practical effect, industry observers expect, is faster evidence requests, closer scrutiny of compliance reports and a greater willingness to open formal proceedings where remediation is slow or cosmetic. Firms that treat the DMA as a one-off legal filing rather than an ongoing programme are the most exposed.
Designation is not discretionary guesswork; the DMA sets out presumptive quantitative thresholds supported by a qualitative assessment. Understanding both layers is the foundation of any DMA compliance Germany strategy.
Under Article 3 of the Regulation, a provider of core platform services is presumed to be a gatekeeper where it meets all three of the following:
Meeting the thresholds creates a rebuttable presumption, but the Commission can also designate a provider that does not meet the numerical thresholds where a qualitative assessment (following a market investigation) shows it enjoys an entrenched and durable position, or that it is foreseeable one will be enjoyed. Relevant factors include the size and scale of the provider, the number of business and end users, network effects and data advantages, the degree of user lock-in, and whether the provider benefits from a multi-sided business model. A provider meeting the quantitative thresholds may attempt to rebut the presumption with sufficiently substantiated arguments, but the bar is high.
Before engaging external counsel, internal teams should calculate and document the following metrics for each candidate service:
Where the thresholds are met and a service maps cleanly to a core platform service, the likelihood of designation is high and preparation should begin immediately rather than waiting for a formal notice.
The following eight-step process converts the abstract obligations of the DMA into an operational programme. Each step identifies the lead function, a realistic duration and the deliverables that evidence compliance. The timings assume parallel workstreams where possible; the technical remediation step is almost always the critical path.
| Step (number & name) | Who (lead) | Typical duration |
|---|---|---|
| 1. DMA readiness audit (metrics & service map) | Legal + Compliance (external counsel optional) | 2–6 weeks |
| 2. Map core services & data flows | Product/Engineering + Data Protection Officer | 3–8 weeks |
| 3. Evidence preservation & documentation plan | Legal + IT (Records) | 1–2 weeks to set up; ongoing |
| 4. Contract & ToS updates (partners/developers) | Commercial/Legal | 4–12 weeks |
| 5. Technical remediation (APIs, interoperability) | Engineering/CTO | 8–24 weeks (varies by scope) |
| 6. Governance & board reporting | Legal + C-Suite | 1–2 weeks to prepare first pack; ongoing |
| 7. Regulator interaction prep (templates & contacts) | Legal + Public Affairs | 2–4 weeks |
| 8. Tabletop & incident response simulation | Compliance + IT + PR | 1–3 days per simulation |
The substantive obligations the programme must satisfy include ensuring interoperability where required, enabling data portability for end users, granting business users access to the data they generate, refraining from self-preferencing in ranking, allowing business users to promote offers and conclude contracts outside the platform, and refraining from combining personal data across services without consent. Mapping each of these to a named owner and a technical workstream in Step 5 is what separates genuine DMA compliance Germany from a paper exercise.
Whether during designation or a subsequent investigation, the Commission (and, within its national competence, the Bundeskartellamt) will expect prompt, well-organised documentation. Preparing these in advance compresses response timelines and signals a mature compliance posture.
On first contact, regulators typically seek the metrics and service information that underpin designation: user and revenue figures, the list of core platform services and a high-level architecture overview. These should be retrievable within days, not weeks.
As an inquiry deepens, authorities move to technical evidence, API documentation, interoperability plans, data access logs and the contracts governing business-user relationships. These substantiate whether obligations are met in practice rather than on paper.
Adopt consistent document naming, maintain version control so superseded policies can be distinguished from current ones, and mark legally privileged material clearly. A disciplined redaction protocol protects commercially sensitive credentials while preserving the evidential value of what is disclosed.
| Document category | Examples | Why regulators want it |
|---|---|---|
| Corporate metrics & financials | User counts (DAUs/MAUs), EEA revenue breakdown, market cap | To test quantitative thresholds and economic significance |
| Service maps & architecture | List of core platform services, data flow diagrams, technical architecture | To identify covered services and technical obligations |
| Data management evidence | Data retention policies, data access logs, data portability processes | To verify data access, portability and non-discriminatory treatment |
| Contracts & ToS | Developer agreements, platform policies, partner SLAs | To review discriminatory clauses and self-preferencing |
| APIs & technical specifications | API docs, access credentials (redacted), SDKs, interoperability plans | To assess technical feasibility of remedies |
| Internal compliance docs | Board minutes, compliance audit reports, DPIAs | To assess governance and prior mitigation |
| Communications & PR | Draft public statements, email templates to partners | To evaluate market communications and response plans |
The European Commission is the designating and enforcing authority under the DMA. It assesses whether a provider meets the thresholds, may run a market investigation where qualitative designation is in issue, and adopts a designation decision. The Bundeskartellamt does not designate DMA gatekeepers itself, but it coordinates with the Commission through the structures provided in the Regulation, may support investigations, and operates its own parallel national tool under Section 19a GWB for undertakings of paramount significance for competition across markets. For German firms, this means engagement can come from two directions, and a coherent DMA compliance Germany plan must anticipate both.
The DMA sets a framework within which, once designated, a gatekeeper must comply. Under Article 3 of the Regulation, a designated gatekeeper must comply with the obligations in Articles 5, 6 and 7 as soon as possible and in any event within six months after a core platform service has been listed in the designation decision. Information requests during investigations carry their own, often short, response windows set by the Commission in each request.
Some technical obligations, particularly interoperability measures, may be implemented in dialogue with the Commission where the specifics allow. Companies should not assume extensions; instead, they should plan the engineering workstream (Step 5) to meet the statutory deadline and treat any flexibility as a contingency rather than a baseline.
| Event | Who issues | Typical deadline / window |
|---|---|---|
| Notification of threshold metrics by the provider | Provider → European Commission | Within 2 months of meeting the thresholds |
| Formal designation as gatekeeper | European Commission (decision under Art. 3) | Generally within 45 working days of receiving complete information |
| Coordination with national authorities | Commission ↔ Bundeskartellamt | Ongoing coordination under the Regulation |
| Compliance with Art. 5, 6 & 7 obligations | Designated gatekeeper | Within 6 months of listing of the core platform service |
| Compliance report submitted to the Commission | Designated gatekeeper | Within 6 months of designation, then updated at least annually |
| Implementation monitoring & audits | European Commission | Ongoing |
The DMA’s enforcement teeth are significant. For infringements of its obligations, the Commission may impose fines of up to 10% of a gatekeeper’s total worldwide annual turnover in the preceding financial year. For repeated infringements within an eight-year period, that ceiling rises to up to 20% of worldwide turnover. The Commission may also impose periodic penalty payments of up to 5% of average daily worldwide turnover to compel compliance, and in cases of systematic non-compliance it may, following a market investigation, impose additional behavioural or structural remedies. These figures are set by the Regulation; the final calculation is always case-specific and reflects the gravity and duration of the breach.
Fines are only part of the exposure. Engineering remediation to build interoperability and data-portability functionality can be substantial, legal and advisory costs accumulate across designation and any investigation, and ongoing monitoring programmes carry recurring annual costs. Reputational damage and the operational disruption of restructuring commercial terms are harder to quantify but equally real.
| Cost type | Typical range / example | Notes |
|---|---|---|
| Administrative fines under DMA | Up to 10% (infringements) / 20% (repeated infringements) of worldwide turnover | Set by the DMA Regulation; final calculation is case-specific |
| Periodic penalty payments | Up to 5% of average daily worldwide turnover | Imposed to enforce compliance with decisions |
| Legal & advisory fees | Significant; scales with scope & complexity | Includes counsel, external auditors, technical experts |
| Engineering & remediation | Can be substantial for larger platforms | Depends on required technical changes (APIs, data segregation) |
| Operational & monitoring costs | Recurring annual cost | Ongoing compliance program, reporting and audits |
| Topic | Gatekeeper obligations (after designation) | Non-gatekeeper platforms |
|---|---|---|
| Data access & portability | Mandatory data access & interoperability measures | Voluntary / contractual |
| Non-discrimination | Prohibited self-preferencing; ex ante rules | Evaluated under general competition law |
| Monitoring & reporting | Regular compliance reporting to the Commission | No DMA reporting obligations |
The defining shift in 2026 is the move from establishing the regime to testing compliance in practice. Monitoring of designated gatekeepers has matured, information requests are more detailed, and non-compliance proceedings have moved up the agenda. The Bundeskartellamt, which has historically been an early mover in digital competition enforcement, including through its Section 19a GWB proceedings against large digital undertakings, remains a visible touchpoint for German operations and coordinates with the Commission under the DMA framework.
For companies pursuing DMA compliance Germany in this environment, the implications are concrete: evidence should be collected and retained continuously rather than assembled reactively; compliance reports must demonstrate real functionality, not aspirations; and response timelines should be compressed on the assumption that regulators will act faster than in the regime’s early years. Early indications suggest that the quality and verifiability of a gatekeeper’s compliance documentation will increasingly determine whether supervisory engagement escalates into formal proceedings.
DMA compliance Germany in 2026 is an operational discipline, not a one-off legal filing. Companies that assess their designation risk early, build a cross-functional readiness programme with clear owners and timelines, prepare their documents in advance and rehearse regulator interaction will be far better placed to meet the Commission’s deadlines and withstand Bundeskartellamt scrutiny. Those that wait for a notice before mobilising face compressed timelines, higher costs and significant penalty exposure. Use the step-by-step process and checklists in this guide to begin preparing now. For tailored advice, consult the Competition, Germany practice page or Find a Competition lawyer in Germany through the GLE directory.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Dr. Sebastian Jungermann at Arnecke Sibeth Dabelstein, a member of the Global Law Experts network.
posted 3 minutes ago
posted 24 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message