LOGO

Europe's Digital Services Act & Digital Markets Act Explained

December 30, 2020
Europe's Digital Services Act & Digital Markets Act Explained

Legislators within the European Union have unveiled the most significant overhaul of digital regulations in approximately two decades, drawing a parallel to the introduction of traffic signals on roadways to establish order amidst the complexities arising from increased connectivity. Consider data packets as the vehicles in this analogy.

The proposed Digital Services Act (DSA), designed to establish uniform safety standards for online services, and the Digital Markets Act (DMA), which aims to curb the power of major technology companies to foster greater competition within the digital landscape, are intended to define the future of online commerce for the next twenty years—both within Europe and internationally.

The EU currently leads the United States in the realm of internet regulation. Consequently, while the dominant technology firms of today largely originate in the U.S., the regulations governing their future operations are being formulated in Brussels.

In the latter half of this year, Ursula von der Leyen’s European Commission, which assumed its duties last December, initiated a series of digital proposals—with further announcements anticipated in 2021. The Commission has put forward a Data Governance Act to promote the reuse of industrial (and other) data, and additional data regulations alongside proposals for transparency in political advertising are scheduled for release next year. European-focused guidelines for the application of Artificial Intelligence will also be presented in the coming year.

However, the DSA and DMA are central to understanding how the EU executive branch intends to reshape online business practices, enhancing accountability and fairness—and thereby advancing the region’s interests for years to come.

Similar concepts are gaining traction globally at the national level. The U.K., for instance, is preparing to introduce an “Online Safety Bill” next year in response to public concerns regarding the societal effects of large technology companies. Furthermore, growing interest in tech antitrust has resulted in Google and Facebook facing accusations of anti-competitive practices within their home country.

It remains to be seen whether a U.S. breakup of a major tech company or the effective implementation of EU regulations on internet gatekeepers will occur first. Both possibilities are now viable—allowing entrepreneurs to envision a more diverse, open, and equitable digital environment. One that is not controlled by a limited number of dominant, potentially abusive corporations. However, this outcome is not yet assured.

Through the DSA and DMA, the EU is proposing a framework for e-commerce and digital markets that, upon adoption, will be applicable across its 27 Member States—and to the approximately 445 million residents—exerting substantial regional influence while also aiming to impact global internet giants.

Despite the numerous obstacles to transforming the proposed framework into pan-EU legislation, the Commission’s decision to separate the DSA and DMA appears strategic—making it more difficult for large technology companies to mobilize broader industry support against measures specifically targeting them within the extensive 160+ page legislative proposal currently under consideration.

It is also important to note that the DSA incorporates a tiered system of requirements, with audits, risk assessments, and the most comprehensive algorithmic accountability provisions reserved for the largest organizations.

Achieving technological sovereignty—by expanding Europe’s technological capabilities and businesses—is a key strategic objective for the Commission. And establishing regulatory standards is a crucial component of its strategy—building upon existing data protection regulations, such as the GDPR, which has been in effect since 2018.

The precise implications of these two major policy packages for technology companies, regardless of size, will not be fully understood for months—or even years. The DSA and DMA must navigate the EU’s often challenging co-legislative process, involving representatives from Member States’ governments and directly elected Members of the European Parliament (who frequently approach the process with differing policy priorities and agendas).

The draft presented this month serves as a starting point. Significant changes—or even radical alterations—could occur through the upcoming debates and amendments. Consequently, lobbying efforts are now intensifying. The coming months will be critical in determining the future winners and losers under the new regulations, and startups will need to actively advocate for their interests.

While technology giants have been steadily increasing their investment in lobbying efforts in Brussels for years, the EU is committed to supporting domestic technology—something that most large technology companies are not.

A conflict is almost certain to arise over influencing the world’s most ambitious digital rulebook—particularly in key areas such as the advertising technology business models based on surveillance that currently dominate the internet (to the detriment of individual rights and innovation that prioritizes privacy). Therefore, those who aspire to a better web have much at stake.

Initial reactions to the DSA and DMA reveal the opposing sides, with U.S.-based technology lobbies criticizing the plan to expand internet regulation as “anti-innovation” (and anti-U.S.), while EU rights groups express positive sentiments regarding the draft—although, with a desire to strengthen protections for web users further.

Startups are initially relieved that key elements of the EU’s existing e-commerce framework appear to remain unchanged, while also expressing concern that efforts to regulate technology giants may have unintended consequences—such as on startup acquisitions (and valuations). European founders, whose ability to grow is being directly hindered by the market power of large technology companies, have additional reasons to welcome the direction of policy changes.

In essence, substantial changes are on the horizon, and businesses and entrepreneurs should prepare for evolving requirements—and capitalize on emerging opportunities.

Continue reading for a detailed overview of the key objectives and requirements of the DSA and DMA, as well as further discussion on how this policy plan could shape the future of the startup ecosystem.

Digital Services Act

The DSA seeks to establish a uniform set of regulations for digital services that function as intermediaries, connecting consumers with goods, services, and content. These rules will apply to a diverse range of digital services, encompassing network infrastructure providers (such as Internet Service Providers); hosting services (like cloud storage providers); and online platforms (including social media and marketplaces) – applying to all that offer services within the EU, irrespective of their location.

The current EU e-Commerce Directive was enacted in 2000, and a review of its core principles to assess their continued relevance is warranted. The Commission has essentially determined that these principles remain valid. However, it also aims to enhance consumer protections and increase transparency and accountability for businesses providing online services by introducing new due diligence obligations – responding to a wide array of concerns regarding the impact of content and products that are now being promoted and monetized online (whether it be objectionable content or dangerous or illegal products).

Several EU Member States have been developing their own legislation (in areas like hate speech), which poses a threat to the regulatory consistency of the bloc’s single market, providing lawmakers with additional motivation to create harmonized, pan-EU rules (hence the DSA being a regulation, rather than a directive).

The package will introduce obligations designed to establish rules for how internet businesses address unlawful material (content, services, goods, and so on) – including standardized procedures for reporting and responding to illegal content (an area previously managed by a voluntary EU code of conduct on illegal hate speech); and a “Know Your Customer” principle for online marketplaces (already a standard practice in heavily regulated sectors like fintech) intended to make it more difficult for sellers of illegal products to re-establish themselves within a marketplace under a different identity.

A significant emphasis is also placed on transparency obligations – with the proposal requiring platforms to provide “meaningful” criteria used for ad targeting (Article 24); and to explain the “main parameters” of recommender algorithms (Article 29), as well as requirements to prioritize user controls (including at least one “nonprofiling” option).

The overarching goal here is to enhance accountability by ensuring European users have access to the information necessary to exercise their rights.

However, there is some doubt regarding the practicality of the planned transparency provisions. Dr. Leif-Nissen Lundbæk, co-founder of Germany-based Xayn, a search engine focused on privacy-safe personalized search, expresses this concern.

“It is overdue that the EU addresses the problematic practices of some of the major tech companies (infringing on data privacy, being opaque about their algorithms and how they influence their users). We all have a right to know more about what’s happening behind the scenes of companies that know so much about us,” he states. “The issue I foresee is that for most of these companies, it won’t be feasible to transparently demonstrate how their algorithms function and give users the ability to influence them. So I’m very interested to see what happens next.”

Early concerns have also been raised that the Commission may have missed an opportunity to regulate surveillance-based business models within the DSA – opting for a level of disclosure regarding targeted ads, rather than stronger user controls. (Suggesting that former MEP Nick Clegg, who leads Facebook’s regional lobbying efforts, has been successful in promoting the argument that Facebook’s “personalized” advertising business model is essential to Europe’s economic prosperity.)

“There is a slight lack of ambition in the proposal concerning targeted advertising. And also the types of algorithms that platforms are permitted to use – where there is no genuine option for a more neutral algorithm, preventing users from being encouraged to spend more time on the platform than necessary,” said MEP Karen Melchior, voicing this concern during an online panel organized by industry trade association, Dot Europe (formerly EDiMA).

“I believe this is a unique opportunity for us to regulate the platforms and regulate the internet of today and hopefully the internet of tomorrow, and we shouldn’t let it pass,” she added.

Regarding content, the Commission has chosen to limit the DSA’s regulation to content that is illegal (e.g., hate speech, terrorism propaganda, child sexual exploitation, etc.) – rather than attempting to directly address more ambiguous “legal but harmful” content (e.g., disinformation), as it seeks to avoid exacerbating concerns about impacts on freedom of expression.

However, a strengthened self-regulatory code on disinformation is expected next year, as part of a broader European Democracy Action Plan. And that (voluntary) code is likely to be strongly promoted by the Commission as a mitigation measure platforms can use to fulfill the DSA’s risk-related compliance requirements.

EU lawmakers also intend to regulate online political ads in time for the next pan-EU elections, under a separate instrument (to be proposed next year), and are continuing to urge the Council and European Parliament to adopt a 2018 terrorism content takedown proposal (which will introduce specific requirements in that area).

But the aim of the DSA is to keep the rulebook broad (or “horizontal,” in EU legislative terminology) – complementing issue-specific instruments such as the Audiovisual Media Services Directive and the digital copyright reforms that were passed in 2019. 

The proposal also does not define what constitutes illegality – that is a matter of Member State law. The DSA focuses on streamlining reporting and establishing a system of oversight to generally improve safety and reduce uncertainty by setting standardized mechanisms and processes.

Again, concerning content moderation, there’s a strong emphasis on platform cooperation with so-called “trusted flaggers” aimed at accelerating takedowns. Some of the initial criticism of the Commission’s proposal relates to concerns about who can be designated a trusted flagger, as well as broader worries about the extent to which emphasis is being placed on takedowns, with the concern that platforms will be prompted to remove more content than is necessary.

Kinzen, a Dublin-based startup that offers content moderation tools combining human expertise and machine learning, understandably has concerns in this area.

Co-founder Mark Little told us: “The concern is that this will encourage tech platforms to engage in the worst kind of content moderation: Fully automated content takedowns that are neither fully effective nor consistent with free speech. The EU needs to ensure the act encourages more human oversight of content moderation.”

He added that his preference is for regulation to make Europe “a test bed for a better form of content moderation that is transparent and effective,” i.e., rather than laws that encourage platforms to mindlessly automate takedowns to reduce their risk of being found to host illegal content.

The Commission acknowledges the risk of increasing regulatory pressure that restricts free expression – asserting that the proposed rules are “carefully calibrated and accompanied by robust safeguards” to strike a balance between underremoval and overremoval of content on the grounds of illegality.

Notably, the current proposal leaves it to platforms to assess whether speech is illegal – another point of contention for some (although the alternative scenario, of a dedicated team of judges making decisions on each piece of disputed content, would raise significant questions about cost and speed).

Another concern for those worried about the impact on speech is that the proposal allows for automated takedowns (although there’s no mandate for – nor prohibition of – the use of content filters in the draft). The Commission states it doesn’t want to ban such tools, as that could disproportionately impact smaller businesses that can’t afford to hire thousands of content moderators.

It also points to another key requirement in the proposal – that decisions must be explained to users who must also be given a mechanism to appeal if content is removed – which it intends as a safeguard against poor applications of automation.

The need to protect freedom of expression is a recurring theme in the proposal. The Commission’s hope is that requirements on platforms to explain decisions and provide the means to challenge them will counterbalance any incentive to overremove content.

It is also noteworthy that EU lawmakers have chosen to maintain the ban on a general obligation to monitor content – although any move to remove that provision would have been highly controversial. (The DSA does reference a key ruling by the CJEU last year that opened the door to targeted monitoring of specific illegal speech that was deemed compatible with wider EU law.)

The Commission has also decided to retain other key principles of the e-Commerce Directive – namely: The country of origin principle (which simplifies compliance for cross-border EU business); and the limited liability regime for intermediaries – with some clarifications that the Commission says are to remove existing disincentives for platforms to carry out “voluntary own-initiative investigations” to detect illegal activity.

“The proposal retains many of the fundamental principles around the safe harbors for internet intermediaries that we know from the e-Commerce Directive and that have served well for the last 20 years,” said Sebastian Felix Schwemer, a researcher in algorithmic content regulation and intermediary liability at the University of Copenhagen who wrote one of the DSA background studies for the Commission.

“Importantly, it also continues the horizontal approach of the e-Commerce Directive and focuses on illegal information, leaving the more ambiguous category of ‘harmful’ information untouched.”

“Given that the DSA would replace the current European safe harbors regime in the e-Commerce Directive, the framework will be highly relevant [for startups],” he also told us. “The proposed instrument is a Regulation. This should, compared to the current landscape, make it easier for startups to understand which rules to follow.

“In addition to the proposed new obligations applying to all intermediary services, relating e.g. to terms and conditions, transparency reporting and notice-and-action mechanisms, there are a range of additional obligations for online platforms (in Articles 17 to 24). The latter, however, do not apply to micro and small enterprises.”

Considering how much of the current e-commerce regime is being retained, there appears to be a lot for startups to appreciate, while harmonized requirements for handling illegal content should help cross-border operations gain greater certainty about moderation requirements.

In a first-response statement, startup association, Allied for Startups, gave a general endorsement to the Commission’s decision to maintain the fundamentals of the e-Commerce Directive, writing: “The intermediary liability exemption, the country of origin principle and the prohibition of general monitoring are three key principles of a fully functioning platform economy. The reaffirmation of these principles in the DSA is paramount to the scalability of startups in the European Union.”

VLOPs: With great power, more responsibilities

Requirements in the DSA are also scaled based on digital services’ size and impact – with certain additional requirements for the largest platforms (which are given the acronym VLOPs: aka, very large online platforms).

The highest penalty for noncompliance with the DSA – up to 6% of global annual turnover – is reserved for these larger players.

This indicates that startups will not be exposed to the same level of risk as businesses that have already significantly scaled their usage. Entrepreneurs and early-stage startups should also face lighter compliance demands and greater freedom to experiment with novel products without being obliged to consider (and mitigate) potential risks as VLOPs must, according to the current proposal. They will also be able to avoid the deepest level of oversight (audits) – at least until they scale up.

Who exactly qualifies as a VLOP? The Commission has proposed the size threshold be set at 45 million+ regional users (or 10% of the EU’s population) – which means that a platform like Twitter may not qualify while Snap likely would, for example (based on their current levels of usage). However, expect debate over exactly where that usage line is drawn.

As well as having greater transparency requirements than startups and smaller platforms, VLOPs are required to provide researchers with access to key data to aid public interest oversight into the societal impacts of their services. And, as noted above, all of this compliance is subject to independent auditing.

Another VLOP-specific requirement is they must perform risk assessments before launching new services – with an accompanying obligation to mitigate identified risks – including by involving relevant representatives from their own user-base and external experts, such as from civic society groups.

It’s an interesting approach to try to force major platforms to be proactive about societal risks versus only focusing on scaling. It appears inspired, at least in part, by elements of the GDPR – such as the requirement for data protection impact assessments (as a preemptive check on misuse/abuse of people’s information before privacy is compromised). Though many details remain to be worked out – and how effective oversight proves.

The Commission is attempting to find a way to put meaningful limits on platforms to address wide-ranging concerns about individual and societal impacts without unduly restricting content and users in the process – so it talks about needing to use a scalpel; saying there’s a fine line between mitigating risk and asking platforms to monitor content (with all the speech chilling effects that would result) that it absolutely does not want to cross. But there will surely be considerable debate about how to achieve this balance.

Another key detail for VLOPs: Oversight is not being left solely to Member States. The Commission has recognized the need to strengthen enforcement in the case of digital services that scale across the EU (a current weakness of the GDPR). And a lot of attention is likely to be paid to the exact choice/structure of enforcement in the DSA, again because of how weak GDPR enforcement has been in cross-border cases.

There have been early concerns raised from some quarters about the Commission proposing to manage VLOP oversight itself – i.e., rather than creating a dedicated, independent body to hold and wield what will be major new powers. So, again, this aspect looks set to receive a lot of scrutiny in the coming months.

A common critique of existing EU regulations (such as GDPR) is they create a barrier for tech giants that have the resources to invest in compliance and/or endless legal strategies to avoid requirements.

For the DSA to deliver the best results it therefore needs enforcement to be as strongly felt at the top of the market as elsewhere – and even, potentially, more strongly, given asymmetrical requirements for VLOPs.

Discussing the proposed governance structure of the DSA in a public webinar this week, Irene Roche Laguna, of DG-Connect – which is responsible for Commission policymaking for the digital single market – acknowledged these oversight challenges, saying: “Believe me this has been difficult. And this will be difficult during the negotiations.”

One challenge is that as a horizontal regulation there’s no universal candidate regulator that already exists across all Member States to take on DSA oversight that both spans some fairly distinct issues (content/speech moderation versus e-commerce/marketplace requirements like KYC), and applies to both tiny and giant-sized businesses – so doesn’t obviously suit any single existing national body.

Given varying competencies within Member States’ media/telecoms regulators, Roche Laguna suggested the DSA may require more than one regulator being responsible for enforcing different elements per country – which isn’t perhaps as much streamlining as some digital businesses might be hoping for. (Though it’s still a lot better than dealing simultaneously with regulators in each of the 27 EU Member States).

The other major DSA enforcement challenge is VLOPs themselves. (Or “how to treat platforms equally when they merit to be treated differently?”, as Roche Laguna put it.)

Here the Commission is proposing to separate out enforcement of the subset of obligations that only apply to these larger platforms – and take on this role itself (but still with the help of the Member State of origin, i.e., where the business has legally established itself in the EU).

Roche Laguna argued that VLOPs “merit different treatment and treatment at the European level,” suggesting also that it will be difficult for the Member State of origin to tackle such cases – and “might be unfair that one single Member State tackles that for the whole of Europe.”

That sounds like another Commission admission that the GDPR has been hampered by the bottlenecks that have built up in a few key Member State agencies, such as Ireland’s Data Protection Commission.

“The Commission does not want to become a ‘Federal Bureau of Intelligence’ – this is not our role,” she added. “But it is true that there are some problems that need to be solved at the European level because any solution at national level first might be insufficient and second we will have a clash between different Member States who don’t agree on what is the right way to proceed.”

The DSA proposal also includes a new oversight entity, called the European Board for Digital Services (EBDS) – which is envisaged (initially) in an advisory/support role (i.e., rather than as a body with legal powers), with the relevant Member State agencies represented, and the board helping to coordinate joint investigations and work on standard setting. Here, the Commission is also suggesting itself as the EBDS chair – so it’s clearly pushing for a central role in major digital enforcement (which would be a major change for Europe’s digital rulebook).

The enforcement structure of both the DSA and the DMA will certainly be crucial to whether these frameworks deliver as intended. The GDPR serves as an ongoing reminder of what weak enforcement looks like. Though it’s less clear what alternative enforcement structure might work best and be politically feasible within the EU project – to achieve the sought-for safety, fairness and market efficiency across the digital realm.

“Whether DSA/DMA package reshapes anything, depends on how they are implemented and whether the Member States authorities will be able to bring the necessary technology-wise competencies to the regulators,” Dr. Lukasz Olejnik, an independent researcher and consultant based in Europe, told us. “Currently this is not always the case, so this dimension of enforcement challenge will be key.

“The DSA says in particular, that ‘the Board should be able to rely on the expertise and human resources of the Commission and of the competent national authorities’. It does not even recognize the problem of lacking technical resources. We have seen a similar resources challenge with GDPR. In fact we still see it, two years after entering into force.”

Digital Markets Act

The Digital Markets Act (DMA) represents a significant second pillar of EU policy concerning the digital sector, and is certainly not a secondary consideration.

It aims to identify a specific group of large platforms as “gatekeepers” – a designation that will impose additional obligations (described by the Commission as a set of “do’s and don’ts”) on these most influential “top of the Very Large Online Platforms” (VLOPs), as best as that can be expressed, across numerous areas – including self-preferencing practices, interoperability standards, and data utilization.

Precisely who qualifies as a gatekeeper? The Commission has outlined three primary criteria for determining whether a tech company falls within the DMA’s scope: Business Scale (achieving an annual turnover within the EU of €6.5 billion or more in the preceding three financial years, or possessing an average market capitalization of at least €65 billion in the last financial year); Gatekeeper Status (acting as an intermediary through a platform service with 45 million or more monthly active end users within the EU, or 10,000 or more yearly active business users in the last financial year); and Market Power – indicating either an established dominant position or the potential to achieve one.

Therefore, based on the initial proposal, the commonly recognized major tech companies are likely to be classified and regulated as “gatekeepers” within Europe.

The specific obligations for gatekeepers are detailed in the DMA (Articles 5 and 6). Currently, these consist of a comprehensive list of practices that competitors of companies like Google, Apple, Amazon, and Facebook have voiced concerns about for years.

Among the prohibited actions are unfair self-preferencing (particularly relevant to Google); and preventing users from uninstalling pre-installed applications or restricting access to services outside of the platform’s ecosystem (relevant to Apple).

Gatekeepers are also prohibited from leveraging data collected from third parties to compete with those businesses (relevant to Amazon). Advertising platforms must also grant advertisers and publishers unrestricted access to internal performance measurement tools and data, enabling independent verification of ad metrics hosted by the gatekeeper (relevant to Facebook). Furthermore, there is a prohibition (with certain exceptions) on platforms preventing the operation of third-party app stores within their ecosystems (relevant to Apple).

Regarding interoperability and data portability, the DMA requires the provision of “effective” data portability and the tools to facilitate it – “including through the provision of continuous and real-time access,” which could enable third-party developers to create services on top of dominant platforms without directly competing with them.

Gatekeepers must also provide business users with real-time access to the data they generate on the platform. (For individual users seeking to allow other businesses to utilize their platform (i.e., personal) data, emphasis is placed on obtaining proper consent to avoid conflicts with the GDPR.)

Platform giants will have six months following their designation as a gatekeeper to comply with the various requirements, while platforms that have not yet established a dominant market position, but would otherwise qualify, will need to adhere to a subset of requirements to prevent unfair market gains.

The list of gatekeeper obligations can be expanded in the future (based on market investigations conducted by the Commission) – with the goal of preventing companies from developing new methods of market abuse to circumvent the existing rules.

The proposed penalty framework for violating the “do’s and don’ts” is substantial (at its maximum theoretical level): The DMA allows for fines of up to 10% of global annual turnover, and “periodic” penalty payments of up to 5% of the same.

However, even substantial fines have not yet demonstrably curbed the behavior of large technology companies.

It will also be noteworthy to observe what happens if gatekeepers claim they were unable to develop the necessary capabilities within the allotted timeframe, or if they release poorly functioning application programming interfaces (APIs). (The Commission has indicated this is a potential risk that needs to be addressed through commitments obtained from Google regarding its acquisition of Fitbit this month.)

There are considerable uncertainties regarding the viability of the proposed framework as a means of rebalancing tech market power – even though the DMA clearly acknowledges a failure of existing EU competition law in digital markets.

However, the same regulator recently chose not to prevent Google from further strengthening its market dominance by approving its acquisition of fitness wearable maker Fitbit, which suggests the Commission’s intention with the DMA is not to dismantle tech giants. Simply stated: It does not appear legally capable (or politically inclined) to do so.

Margrethe Vestager, a key architect of the DMA within the Commission and the EVP and competition commissioner, has publicly stated she has no desire to break up large tech companies. Her preferred approach is to regulate access to data, and the DMA provides the framework to test this theory.

However, in a sense, this regulatory framework actually supports mega VLOPs. Because the Commission is signaling that monopoly levels of market dominance are acceptable. It simply wants a set of tools to compel big tech to adhere to European “e-commerce fairness” standards – and to exert pressure regarding additional requirements in areas like openness and interoperability.

If tech giants fully comply with the regulations, the Commission believes it will foster a competitive environment. The crucial question is whether this strategy of long-term regulation – rather than blocking further market consolidation and breaking up tech empires – is the correct approach.

One challenge for the Commission is that the giants have historically disregarded inconvenient EU regulations (such as GDPR’s consent requirements – which carry potential fines of up to 4% of global turnover) in order to continue expanding their user base. Expecting a significant shift by threatening slightly larger fines through centralized enforcement almost requires a leap of faith.

The widespread use of dark patterns across the tech industry also warrants consideration – highlighting how manipulation is a systemic component of the service model employed by these companies.

Unfair practices are integral to their success. And it is unclear how these unethical business strategies can be reformed through a few “do’s and don’ts.” Furthermore, the Commission has not demonstrated a willingness to impede unethical, rights-compromising business models that rely on utilizing personal data to manipulate behavior – suggesting these issues should be addressed through the GDPR (even while acknowledging GDPR enforcement has not achieved its intended results). This is, to put it mildly, a limited response.

The Commission’s rationale behind the DMA is informed by numerous EU antitrust cases against big tech – including three cases involving Google and several others concerning Amazon and Apple. The “gatekeeper” designation is clearly intended to apply to all three of these companies at a minimum, as the listed obligations are aligned with long-standing antitrust complaints related to their business practices.

Examples include Amazon utilizing merchant data to gain an advantage over third-party sellers on its platform; Google employing self-preferencing to rapidly gain market share in new sectors like travel; and mandatory requirements Apple imposes on developers selling products in its App Store, among other open antitrust cases in Europe against big tech. (Although the Commission has refrained from explicitly naming potential contenders when presenting the policy package.)

Therefore, the EU’s inability to reverse digital dominance through competition enforcement – despite issuing billions of dollars in fines – is the core motivation behind the DMA.

However, this also implies that Facebook’s rights-compromising, surveillance-based business model may receive less scrutiny under the current proposal, potentially due to the Commission having devoted less time and resources to investigating how its ad targeting and mass surveillance operations function (it only recently initiated a preliminary Facebook probe).

It is also uncertain whether increased micromanagement of tech giants will ultimately lead to a more equitable distribution of market share for domestic startups, or – indeed – greater choice for internet users and reduced violations of their rights, particularly from surveillance-based business models that underpin a significant portion of big tech.

While the Commission appears to believe it has identified the unfair formula that big tech has been using to stifle competition – and thinks a set of strict operational requirements coupled with the threat of substantial fines will be sufficient to reverse systematic abuse and restore a “fair functioning” market – this is, at best, a significant gamble.

At the same time, the DMA will not supersede competition enforcement within the EU. It is intended to complement specific competition investigations.

Ongoing investigations of big tech will continue and can inform the regulation’s list of obligations. The Commission hopes the DMA’s parallel track will expedite antitrust interventions, addressing complaints that have not been addressed promptly by big tech’s market-abusing tactics.

Once gatekeeper status is conferred on a tech giant, all of the DMA’s pre-set obligations take effect within six months. This is a significant departure from the EU’s previous approach of first investigating a specific practice to prove abuse and then issuing an enforcement decision – allowing tech giants time to develop self-serving remedies or make minor adjustments to their processes to avoid regulatory interference. (Notably: Three Commission decisions against Google have not resulted in any tangible decrease in its regional market share.)

However, the DMA proposal does not appear to restrict further market consolidation by gatekeepers. The Commission has only stated it will monitor acquisition plans, including expanding notification requirements for purchases of smaller companies or startups that would not normally trigger regulatory oversight.

The lack of pre-set limits on acquisitions will likely be welcomed by investors concerned that the regulation could make it more difficult for startups to be acquired by companies like Google, and potentially impact valuations. Therefore, the Commission may be attempting to balance broader tech industry concerns by avoiding strict limits on consolidation. However, this approach also carries the risk of undermining the core objective of rebalancing tipped digital markets – which would be detrimental to European startups seeking to scale their businesses in markets already dominated by tech giants.

Beyond competition issues, the Commission suggests an additional benefit of the DMA will be reduced regulatory fragmentation for online businesses and greater operational clarity for cross-border digital services. “Common rules across the single market will foster innovation, growth and competitiveness, and facilitate the scaling up of smaller platforms, small and medium-sized enterprises and startups who will have a single, clear framework at EU level,” it suggests.

It also highlights reduced compliance costs for companies operating in the internal market. However, reducing compliance costs for tech giants is a somewhat ironic “plus” if the goal is to level the playing field for smaller digital players, who are likely to need to increase their investments to take advantage of DMA-enabled opportunities to better compete with gatekeepers – whether by analyzing new data they receive from gatekeepers or by utilizing new, mandatory APIs. Of course, the underlying idea for legislators is that such investments will yield market share dividends for smaller players in the long run – as they are able to capture a larger portion of big tech’s market.

It will take years before startups are in a position to definitively assess whether the Commission’s gamble has been successful. But in the meantime, businesses that have felt the impact of big tech have reasons to be optimistic.

Johannes Reck, co-founder of vacation experience startup GetYourGuide – one of several in the sector that have urged stronger EU competition enforcement against Google this year – expressed satisfaction with the direction of the policy. (Although he admitted being too preoccupied with an exceptionally challenging year for the travel sector to have thoroughly analyzed the Commission’s proposals.)

“Overall I am super positive about the developments and strongly support the view of Vestager to create a more level playing field,” he told us. “I am personally not worried about ‘overregulation’ at this point. We saw with GDPR that the regulation was less painful than originally anticipated.”

#DSA#DMA#Digital Services Act#Digital Markets Act#Europe#tech regulation