Europe’s Digital Markets Act turns three. Who is it helping?

A new policy brief by Mara Balestrini, Darío Arjomandi and Laia Serrano takes stock of three years of the DMA. Its verdict: the goals are right, but some limitations remain.

Marta Barquier (Do Better Team)
This article offers an introduction to the ideas explored in Policy Brief: Implementing the Digital Markets Act, by Mara Balestrini, Darío Arjomandi, and Laia Serrano.

Buy a new phone in the EU today and something looks different. Choice screens now let you pick your preferred browser, rather than defaulting to Safari or Chrome. You can even delete pre-installed apps you never asked for. Most people have no idea why any of this changed.

The reason is a piece of European law that has just turned three: the Digital Markets Act. And, after three years of enforcement, the European Commission has published its review assessing the regulation’s performance. Against that backdrop, EsadeGeo researchers Mara Balestrini, Darío Arjomandi, and Laia Serrano have published a policy brief mapping out where the rules create friction and signalling how they could be sharpened.

The DMA’s starting point is well-intentioned. Its ambitions are sound. However, its design and execution leave room for improvement.

What the DMA is built to do

The DMA sets rules for a small group of very large platforms called “gatekeepers”; mostly the companies we lump together as Big Tech. The browser choice screen, the deletable pre-installed apps and the advertising settings on social media platforms all come from the same place: the DMA. The regulation bars gatekeepers from forcing users to use their own services when using their core platform services or from setting those services as the default – for example, users can now open a Google account with a non-Gmail address. It also bans gatekeepers from using your personal data for advertising purposes unless the user has been given a real choice and said yes.

The DMA does not wait for a company to misbehave. It writes the rules in advance, for anyone big enough to count as a gatekeeper

The point of all this is to make Europe’s digital markets more contestable and fairer. Contestability means lower barriers to entry, so more and smaller companies can compete. Fairness means no structural imbalances that hand a few large players an outsized advantage over rivals and over consumers. What makes the DMA different from classic competition law is its timing. Competition law steps in after someone has behaved badly. The DMA works the other way around. It imposes its obligations up front, before any wrongdoing has been proven, as a way to stop monopolies and harmful practices from forming in the first place.

More players does not automatically mean more competition

Here is the assumption the whole regulation seems to lean on: put more companies in a market and you get more competition. The researchers argue it is not that simple, and the reason is a distinction that regulators must pay attention to.

A market can be hard to enter and still play by the rules. The DMA targets the first problem, not the second

Contestability and competition are not the same thing. A market can have very few players and still be clean, with no abuse of dominance and register no anticompetitive behavior. A market can also be crowded and have a dominant player throwing its weight around in an anticompetitive manner.

That is why calling the DMA “complementary” to competition law can be misleading: greater contestability does not necessarily translate into a reduction in anticompetitive practices. More contestability changes how a market behaves, but it does not guarantee fewer anticompetitive practices.

And there is a gap underneath all of this. Three years in, the regulation’s two core goals, contestability and fairness, have not been defined in operational terms. There are no agreed numbers, no quantitative benchmarks, no way to actually measure whether the markets are getting fairer and more contestable. The brief’s fix is straightforward: build real indicators, and the enforcement obligations to back them, so the effects can be judged on evidence rather than intuition.

Interoperability: more power for users, or more friction?

If one DMA obligation has dominated the debate, it is interoperability. The underlying idea is that gatekeepers’ hardware and software should be compatible with products built by other companies, and that gatekeepers’ messaging services should be able to interact to rival messaging apps.

In practice, this means Android has to let third-party AI assistants plug in the same way their own AI assistant (Gemini) does. It means that WhatsApp must allow users to chat with people using other messaging apps. Some of it you have probably noticed already: you can now receive, react to, and reply to iPhone notifications on a smartwatch that isn’t an Apple Watch.

Gatekeepers have pushed back hard, partly over the engineering effort, the regulatory landscape – the DMA coexists with other regimes such as the Digital Service Act (DSA) and the General Data Protection Regulation (GDPR) –, and concerns over intellectual property. The sharper objection is about money and incentives. Interoperability effectively forces gatekeepers to open their systems for free, and the researchers warn this can blunt the appetite to invest in new technology and intellectual property. Why pour money into a design everyone else gets to access at no cost? Applied without due consideration, an obligation meant to open markets can discourage the investment that made those markets worth entering.

There is a user-experience cost too. Where interoperability collides with cybersecurity and data-protection rules, people get routed through even more consent screens than before. The empowerment lands as fatigue. Additionally, some stakeholders now ask for interoperability to be horizontal as well, rather than only vertical, so that every service in the ecosystem is interoperable by design, not just the ones owned by gatekeepers.

Unintended effects

European startups and small businesses were supposed to be the clear winners of the DMA. Yet, the regulation has sometimes affected them in ways that had not been foreseen. The regulation exists to free these companies from depending on the big platforms, but with limited money and capacity, many of them still do. Two examples make the point.

Take alternative app stores. Requiring gatekeepers to allow their use is good news on paper: lower fees, more choice for developers and users. But a lot of these alternative stores do not run thorough security checks or stop the spread of cloned apps, with the security burden landing on app developers who often do not have the resources to handle this.

A further concern relates to timing. Complying with DMA obligations is technically hard, and may, at times, delay the launch of new features by gatekeepers in Europe. For users, this is a minor irritation. For small European companies building on top of these new features, it is a real disadvantage against rivals in markets where the DMA is not applicable and features ship on schedule.

Beyond this, an important question remains, regarding the attribution of responsibility when gatekeepers’ opened-up systems get breached. Security failures can happen inside services run or developed by smaller companies using gatekeepers’ platforms. Add the fact that the DMA, the GDPR, the Cyber Resilience Act and NIS2 do not always fit together cleanly, and you get extra cost and uncertainty concerning security regimes.

Lessons from the last three years

None of these are arguments to tear the regulation up. The researchers are clear that the core goals of fairness and contestability are well founded and the gatekeeper framework holds. Furthermore, some of the up-front obligations have already worked well. The case is for calibration, not demolition.

What the first three years point to:

  • Proportionality. Enforce and interpret the obligations having the differences between digital services and markets in mind. A social network is not an operating system, and treating every market with the same rulebook is the root of much of the friction.
  • Real metrics. Define contestability and fairness in measurable terms, so regulation can be judged on evidence.
  • Incentives alongside obligations. Pair interoperability with financial incentives and stronger rules on innovation and intellectual property. Without that, European startups will lack the scale to contest incumbent market power.

The lesson of the first three years is that the Digital Markets Act needs tuning. Following the Commission’s review, the next phase will decide whether the rulebook gets sharper or simply heavier, and whether Europe’s own companies end up on the winning side of a law that was written for them.

All written content is licensed under a Creative Commons Attribution 4.0 International license.