Markets

TechnologyExplainer

Tech platform gatekeeping compliance obligations in 2026

The EU's Digital Markets Act imposes sweeping compliance obligations on Apple, Google, Meta and six other tech giants. Violations carry fines up to 20% of global revenue.

Aerial view of Apple Park's distinctive circular building with solar panel roof
Apple Park in Cupertino, California, with solar panels covering its distinctive circular roof. Daniel L. Lu (user:dllu) · CC BY-SA 4.0 · via Wikimedia Commons

The European Union's Digital Markets Act (DMA), which took effect in March 2024, designates six gatekeepers—Apple, Alphabet, Meta, Amazon, Microsoft, and ByteDance as "gatekeepers," and requires them to meet a detailed set of operational requirements by September 2026 and beyond.

The regulation distinguishes between immediate, non-negotiable obligations and ones that invite regulatory dialogue. Violations carry penalties up to 10 percent of a company's total worldwide turnover, rising to 20 percent for repeat breaches. Enforcement began in April 2025, when Apple and Meta received their first fines—€500 million and €200 million respectively—for failing to meet interoperability and data-combination rules. These penalties signal that compliance is now a material cost driver.

Gatekeepers must also maintain independent compliance functions, with designated compliance officers reporting directly to company boards. The Commission can impose corrective measures beyond fines, including prohibitions on acquiring new services in the digital sector or, as a last resort, requiring divestiture of business units for systematic violations.

The Black List of Prohibited Behaviors

Article 5 of the DMA establishes seven obligations that take effect immediately and admit no regulatory negotiation. These rules ban the data practices that built these platforms at scale.

Gatekeepers cannot combine personal data from different services without explicit user consent. This rule directly targets Facebook's ability to merge data from Instagram and WhatsApp into its advertising engine, or Google's practice of linking YouTube watch history to search behavior. Meta's €200 million fine in April 2025 resulted from offering users only a binary choice: consent to data combination or pay for an ad-free version—a "consent or pay" model that the Commission found violated the rule's requirement for genuine choice.

Gatekeepers must allow business users to offer the same goods or services at different prices and conditions on different channels. This prohibition prevents Amazon from requiring third-party sellers to match prices on the Amazon marketplace or from charging different referral fees based on how products are advertised elsewhere. Google's €460 million fine in July 2026 addressed violations of this rule; the Commission found that Google restricted businesses on Google Play from directing consumers to cheaper purchase channels outside the platform.

Gatekeepers cannot require business users to subscribe to their main service as a condition of accessing ancillary features. Apple triggered a €500 million fine by imposing "anti-steering provisions" that prevented app developers from promoting external payment options—a direct violation of this rule. Other Article 5 rules require gatekeepers to allow complaints to public authorities, forbid mandatory use of their own identification services, and mandate transparency in how ads are priced and revenue is calculated from advertising.

The Grey List and Interoperability

Article 6 obligations allow for negotiation between gatekeepers and regulators, giving companies space to propose compliance measures rather than face prescribed solutions. These rules focus on platforms' control over how customers access and move data. Gatekeepers submit compliance proposals; the European Commission responds within six months with required measures.

Messaging services must support interoperability—specifically, basic end-to-end messaging, voice calls, video calls, and file sharing must work across platforms. A user on WhatsApp should eventually be able to send messages to someone on Apple iMessage or Telegram without converting to a common platform. This requires new technical protocols and APIs that connect competing systems, a substantial infrastructure change for platforms built on proprietary messaging networks.

Data portability, when technically feasible, must occur in real time—called "dynamic portability." Earlier regulations allowed companies to fulfill portability requests with occasional data downloads that lacked real-time accuracy. The DMA requires continuous, current data export. This obligation demands database architecture changes that permit constant data extraction without degrading platform performance.

Gatekeepers must allow alternative app stores and prevent users from being locked into proprietary software ecosystems. Apple's €500 million fine resulted from failing to meet these interoperability obligations. The company has since implemented alternative distribution channels: developers can now operate alternative app marketplaces on Apple devices, distribute directly from their websites, or use Apple's App Store. All apps distributed outside the App Store must pass notarization—Apple's security review process checking for accuracy, functionality, safety, security, and privacy. The May 2026 review milestone gives the Commission authority to assess whether interoperability obligations should expand beyond messaging to email services.

The Commercial Terms of Compliance

Compliance carries direct financial costs. Apple's implementation, effective October 1, 2026, imposes a "Core Technology Commission" (CTC) structure replacing its previous fee model. Apps distributed through alternative app marketplaces or directly from websites face a 5% commission on digital transactions—substantially below Apple's App Store rate of 26% (or 15% for small businesses). However, apps distributed outside the App Store that use alternative payment processors must pay 20% commission (10% for small businesses), versus Apple's 26% on App Store purchases. This creates a complex incentive structure: developers can lower costs by using alternative stores, but Apple still captures revenue.

To operate alternative app marketplaces or distribute directly from websites, developers must meet eligibility requirements effective October 1, 2026: maintain a moderate financial stability score, be publicly traded or owned by a public company, have received venture funding from established firms, undergo a financial audit, be a government entity or nonprofit, provide a $1 million letter of credit, or demonstrate one million first-year installs worldwide. These criteria restrict who can participate in alternative distribution, concentrating power among well-capitalized developers.

Child safety rules add compliance layers. Apps in the "Kids" category and those directed at under-13 users must implement parental gates for alternative payment purchases and prohibit out-of-app payment offers entirely. Users aged 13-17 require parental gates for both in-app and out-of-app purchases. These requirements force platforms and app developers to invest in age-verification infrastructure.

Enforcement and Financial Exposure

The European Commission is the sole enforcer. When the Commission suspects a violation, it can launch an investigation and, if violations are confirmed, impose corrective measures or fines. First violations carry fines up to 10 percent of worldwide turnover. A second violation doubles that to 20 percent. The Commission has already demonstrated enforcement will be aggressive: Apple €500 million (April 2025), Meta €200 million (April 2025).

For systematic violations, the Commission can impose structural remedies beyond fines. These include prohibition on acquiring other companies that provide core platform services or other digital sector services, and as a last resort, requiring divestiture of all or part of a business. This enforcement ladder means that repeated violations could force a company to restructure or shed divisions—a far more severe consequence than fines.

Gatekeepers must submit independently audited compliance reports documenting their measures against DMA obligations. The Commission benchmarks these reports across companies and time periods, using audits to track whether changes are genuine compliance or performance theater. KPMG's 2026 benchmark analysis compares compliance approaches and consumer profiling techniques across gatekeepers, identifying patterns of enforcement-driven updates versus voluntary changes. This surveillance mechanism creates continuous compliance obligations, not one-time fixes.

The U.S. Approach Diverges

The United States lacks a comparable digital gatekeeping statute. Instead, the Federal Trade Commission enforces existing laws through targeted enforcement and consent decrees. This creates a fundamental contrast: the EU imposes uniform operational requirements on designated gatekeepers; the U.S. pursues case-by-case enforcement without prescribing specific business model changes.

In 2026, the FTC has focused on familiar violations: subscription dark patterns, "Made in USA" misrepresentations, children's data privacy, and hidden fees. In April 2026, the FTC and state attorneys general secured settlements with WPP, Publicis, and Dentsu for collusion on digital advertising standards—addressing gatekeeping-adjacent behavior through existing antitrust law rather than new regulation. This enforcement targets specific conduct rather than systemic platform design.

Tech companies face divergent requirements: DMA obligations in Europe, FTC scrutiny in the U.S., and similar but distinct rules in the U.K., creating a patchwork compliance burden across geographies. European compliance costs may flow through to other markets as companies apply unified rules globally, but legal divergence prevents harmonized solutions.

Implementation and Market Impact

Compliance with these obligations requires infrastructure and policy changes. Interoperability demands new APIs and protocols that connect competing systems. Real-time data portability requires database architecture that permits continuous data export. App store alternatives require platforms to allow competing storefronts and payment methods on their devices, fundamentally changing the closed ecosystems these companies built.

Gatekeepers have submitted compliance proposals and negotiated with regulators. Implementation timelines vary: Apple's unified EU terms took effect October 1, 2026, after the Commission rejected earlier proposals. Some obligations, like email interoperability, remain unspecified pending the May 2026 review. Others, like messaging interoperability and app store opening, approach firm deadlines with technical and commercial questions unresolved. Companies face uncertainty about which compliance methods the Commission will accept, raising the cost of implementation mistakes.

The regulation is at the threshold of full enforcement. Designated gatekeepers now face not proposals but mandatory compliance measures, backed by escalating penalties. 2026 will test whether these obligations can reshape how the largest digital platforms operate and whether alternative distribution channels and payment systems will compete effectively against entrenched platforms.