The European Commission is in the process of reviewing the Digital Markets Act (DMA), the flagship ex-ante competition regulation introduced a few years ago to manage digital platform competition. It is a good opportunity to reflect on the DMA and, together with other digital regulations, its impact on Europe’s competitiveness. A consultation was launched last summer and, just a month ago, some summaries of the submissions were released. It is now up to the Commission to ponder the responses and the experiences of the regulation so far – and this is a process that would benefit from more participation by national governments and EU institutions.
Both economic and political reality are forcing themselves onto the Commission’s digital agenda. António Costa has invited EU leaders to an informal retreat on February 12 to discuss Europe’s competitiveness and geoeconomic standing in the world. A Digital Omnibus package has been proposed by the European Commission to take away some of the excesses in digital regulations in the past decade. Following Mario Draghi’s report on The Future of European Competitiveness, there is growing acceptance among EU governments and institutions that an excessive burden of regulation has dented the appetite for digital innovation and investment in Europe. Draghi’s report and scores of other studies of Europe’s digital economic performance have made an alarming point: Europe risks becoming a digital innovation laggard in the world.
Europe should also take stock of similar policies elsewhere. While the DMA is a unique category of regulation – seeking to manage competition on and by digital platforms with other instruments than traditional competition policy – several other governments have also wrestled with the same concerns over platforms. Japan is a case in point. In December last year, Japan’s new Mobile Software Competition Act (MSCA) went live – and, just like the DMA, it establishes an ex-ante competition regulation for platforms benefitting from network effects in markets characterised by oligopolistic competition.
There are differences and similarities in the approaches by the EU and Japan. Both regulations build on a previously expanding body of competition enforcement and rules on fairness and transparency in platform markets. The two regulations basically share the same objectives. They feature regulatory characteristics – and, to be frank, design problems – that are dependent on national context and concern. However, Japan’s version of a digital markets act could benefit from the fact that the EU’s DMA came a few years earlier. The implementation experiences of the DMA, therefore, became a useful source of information for Japan’s Fair Trade Commission (JFTC) and the Cabinet Secretariat as they prepared practical aspects of the proposal and its method of implementation and enforcement.
The EU can now repay the complement – and learn from Japan’s approach to platform competition management. In this Insight, we compare the DMA and the MSCA and point to several policy takeaways for Europe, especially on interoperability, governance, and the innovation-proofing of implementation and enforcement.
Scope and Designation
Let us review some key similarities and differences between the two approaches. A first point is, obviously, the scope of regulation. In the EU, the DMA establishes a broad, cross-sector regime for designated “gatekeepers” and their “core platform services,” with obligations intended to support “fairness” and “contestability.” Japan shares these objectives but parted with the EU on scope.
The European Commission initially designated six gatekeeping firms under the DMA – Alphabet, Amazon, Apple, ByteDance, Meta, and Microsoft. Subsequently, Booking.com and Apple’s iPad OS were added to the list. Meta’s online intermediation service Facebook Marketplace was later removed from the list of designated services after review. While the Japanese government – and the JFTC in its competition enforcement – have signalled competition concerns with many of the companies covered in the DMA, Japan adopted a more targeted design with a more specific scope in its regulation. Rather than regulating gatekeepers across multiple digital sectors, the MSCA concentrates specifically on the smartphone software ecosystem, mobile operating systems, app stores, browsers, and search engines, under the supervision of the JFTC. By focusing on clearly defined software layers of Android and iOS, Japan seeks to address competitive bottlenecks while avoiding the broad, cross-sector intervention characteristic of the DMA.
This targeted design is justified by Japanese authorities on the basis that smartphones function as the “foundation of daily life” and display distinctive structural features, including strong network effects and cross-layer leveraging. However, the motivation also extends into factors that were central to the DMA. According to the MSCA, also known as the Smartphone Act, these characteristics of the smartphone market create particularly high entry barriers and reinforce incumbents’ market power. The problem, according to the Act, is that structural features of the market will naturally pull it in the direction of oligopolistic competition.
Clearly, a more focused regulatory approach is administratively more manageable and operationally precise than the DMA’s broad, cross-sector framework. The broad scope of the DMA has already provoked uncertainties about what rules that can be applied to what type of platform. While the Act’s catch-all type of approach allows for a great amount of discretionary flexibility for the regulator, it also creates ambiguities both for market stakeholders and those administrating the regulation. Unfortunately, it also leads to unintended consequences. There are already examples of DMA implementation and enforcement leading to degraded services, product fragmentation, and postponed product releases. Such consequences were explicitly ruled out when Thierry Breton and his team were promoting the bill before its approval. Now they are real.
Japan was certainly paying attention. With an independent agency (JFTC) tasked with enforcement, the regulation is more protected from undue political influence. Japanese officials also talked with – ahem! – European scholars who had pointed out risks with the DMA. In the smartphone market, for instance, the DMA administrators have yet to find a way to practically balance platform openness and security standards – and issue that was riling EU competition officials before the DMA. Because of the DMA design, competition officials have gradually been taking on a role as regulator of products and product design, or – as in the DMA enforcement case against Meta – a role as price regulator. Officials in Japan wanted to avoid that outcome.
This point has bigger implications. The difference in design between the EU’s and Japan’s regulations will therefore matter for how they accommodate product change and adapt to new technological conditions. While both regimes are constrained by the structural gap between legal processes and technological change, Japan’s narrower focus enables it to become more targeted, precise, and pragmatic in its enforcement. Rather than following the EU’s implementation posture of remote due diligence of implementation measures, the Japanese government is already operationalising the MSCA through detailed enforcement guidelines – a practice that the EU is still resisting, partly because of the DMA’s larger scope.
Key Obligations and Technical Divergences
These structural differences between the DMA and the MSCA are reflected in the substantive obligations imposed under each legislation. Let us get into the weeds of the two regulations and focus on some issues that have been bones of contention in Europe.
- Data use: Article 6(2) of the DMA imposes a strict prohibition on using business users’ data to compete against them, reflecting a structural separation logic. By contrast, Articles 5 and 10 of the MSCA prohibit the improper use of acquired data and require disclosure of acquisition conditions. This allows the JFTC to distinguish between exploitative data practices and legitimate data-driven innovation. As a result, the MSCA reduces the risk of discouraging beneficial data integration while still constraining exclusionary behaviour. The DMA’s stricter rule, although easier to enforce, may inhibit efficient data utilisation in complex platform ecosystems.
- Payment solutions: Both regimes require dominant platforms to permit alternative payment solutions, but there is a substantial difference in approach. The MSCA encourages choice but does not force users to go with one payment option. Hence, it allows “side-by-side” payment options accompanied by transparency requirements that inform users of material differences in security guarantees, and liability regimes when using third-party systems. This design seeks to reconcile competitive openness with informed consumer choice and risk awareness.
The DMA takes a somewhat different stance. Principally, its anti-steering and alternative payment provisions constrain the ability of platforms to differentiate native and external payment systems through security or privacy-related disclosures, insofar as such disclosures may be interpreted as discouraging the use of alternative options. Actual implementation has moderated the principal position a bit and standard platform payment solution has more optionality, including the use of the payment service offered by the platform. Still, the core anti-steering principle is the guide and do not put the same emphasis as in the MSCA on the protection of user information and security in payments.
- Apps distribution. Security issues were also a point of concern during Japan’s design and implementation of the MSCA. Japan’s approach is restrictive but seeks a balance between two desirable objectives that sometimes compete with others: platform openness and user security. It has also been noted in firm-level implementation of the MSCA. For instance, Apple’s response to the implementation of the MSCA illustrates the risk-balancing logic embedded in the Japanese framework. While the company emphasised that the opening of alternative app marketplaces and payment systems increases exposure to malware, fraud, and privacy risks, it simultaneously highlighted the introduction of regulatory-approved safeguards, including app notarisation, marketplace authorisation, and enhanced protections for minors.
The MSCA’s approach is also more responsive to existing mobile operating system governance models, under which openness is accompanied by graduated security warnings and technical controls. For example, alternative app installations on Android devices are permitted, but are subject to explicit risk notifications, additional authorisation steps, and, in some cases, automatic blocking. These mechanisms enable users to exercise meaningful choice while internalising security risks. By permitting similar forms of differentiated disclosure and risk management in relation to alternative app stores – and payment systems – the MSCA enables both Apple and Google to compete on security and consumer protection alongside price and functionality.
By contrast, the DMA’s logic constrains the use of such signalling mechanisms, prioritising formal neutrality over informed user decision-making. It explicitly seeks a regimented openness – sometimes labelled as openness or interoperability by design rather than effect – which does not accommodate differences in business models and technological solutions, especially though mandated side-loading.
- Self-preferencing. A further divergence arises in relation to self-preferencing. While both the EU and Japan treat self-preferencing with suspicion, the DMA adopts a largely categorical approach (Article 6(5)), under which gatekeepers are generally prohibited from favouring their own services, regardless of whether such treatment can be objectively justified. This model prioritises enforceability but limits the scope for considering efficiency, security, or quality-based differentiation.
By contrast, Article 9 of the MSCA prohibits self-preferencing only where preferential treatment results from unfair or discriminatory algorithmic design. The focus is not on the mere existence of preferential ranking, but on whether the ranking criteria systematically disadvantage competitors without legitimate justification. This requires an assessment of data inputs, weighting factors, and ranking parameters. Japan therefore adopts a more effects-based and technically grounded approach, under which self-preferencing is unlawful only when it can be linked to demonstrable distortions of competition. While this increases the evidentiary burden on regulators, it reduces the risk of prohibiting pro-competitive platform design and allows greater flexibility in fast-evolving digital markets.
Interoperability: Balancing Openness with Cybersecurity and Privacy
We should dig a bit deeper into the regulatory balancing act between openness and security: it also relates to fundamental issues concerning interoperability. As discussed above, Japan takes a different approach than the EU and the MSCA places particular emphasis on this balance through its recognition of “objective justification”. Firms may justify otherwise prohibited conduct where it is necessary to protect cybersecurity or system stability. For the products that are covered – smartphones – it means more flexibility for companies to protect user information, including the information the user has stored on the device.
Generally, the more flexible approach is also reflected in MSCA provisions which requires designated providers to allow competing app stores. While these rules reflect the same attitude as in the DMA, the MSCA does not oblige platforms to permit direct downloading of applications from external websites (so called sideloading). Alternative distribution must therefore take place within managed environments that retain security screening and quality control mechanisms. Moreover, the MSCA expressly exempts conduct that is necessary to protect information stored on devices. These provisions demonstrate a regulatory philosophy that treats security and privacy as integral components of competition policy, rather than external constraints. In Europe, the DMA requires gatekeepers to allow both competing app stores and direct web-based app downloads, prioritising structural openness over platform governance. While this reduces dependence on proprietary app stores, it also increases exposure to malware, fraud, and fragmented user experiences.
Vertical interoperability obligations are another example of how Japan has opted for a more pragmatic enforcement. To become a bit technical, article 7(ii) of MSCA corresponds to Article 6(7) of DMA in imposing such obligations on designated providers. Under Article 7(i), providers are prohibited from preventing third parties from accessing operating system functions with equivalent performance for the provision of their services. However, the JFTC Guidelines clarify that this obligation requires functional equivalence rather than technical identity. Designated providers are not required to grant access to the same internal tools or architectures they use themselves. Instead, they must ensure that third parties can achieve comparable functionality.
This approach mirrors and substantiates the principle towards statutory guidance. By focusing on equivalence of outcome rather than symmetry of technical access, the MSCA recognises that forcing disclosure of internal system components may undermine security, system stability, and intellectual property protections. It allows regulators to assess interoperability in light of concrete use cases and technological constraints. Thus, the MSCA allows regulators to distinguish between legitimate technical differentiation and exclusionary design. By contrast, the DMA’s more open-ended interoperability mandate provides less guidance on how functional equivalence should be evaluated, exacerbating legal uncertainty and encouraging defensive compliance – including delayed or denied product development.
Enforcement Styles
The divergence between the DMA and the MSCA is particularly visible in their respective enforcement architectures, which determine how regulatory fairness is operationalised in practice. Under the DMA, enforcement follows a graduated “pyramid” model, beginning with regulatory dialogue and compliance monitoring and escalating to financial penalties and, in exceptional cases, structural remedies. Once a firm is designated as a gatekeeper, compliance is assessed primarily through conformity with predefined statutory obligations. Although this framework incorporates formal procedural safeguards, it has been criticised for its administrative intensity and limited capacity for rapid, context-sensitive adjustment.
Building on the EU’s DMA, the MSCA imposes directly applicable and self-enforcing obligations on designated providers, with Articles 5 to 9 addressing prohibited conduct and Articles 10 to 13 setting out compliance requirements. The Act also offers a flexible enforcement mechanism, under which designated providers may argue that meeting certain obligations would unduly undermine the security, integrity, or proper functioning of their services. In other words, Japan practices a hybrid structure combining ex ante regulatory discipline with ex post contextual review. The difference with the DMA is important – and a lesson that the Japanese government took from Europe’s DMA process: it wanted a less confrontational approach than in Europe and a less rigid enforcement style.
The institutional design is reflected in the MSCA’s enforcement procedure. The regime structures enforcement around a “without rational basis” standard that shifts the evidentiary burden onto designated providers. When potentially restrictive conduct is identified, firms must demonstrate, with technical and economic evidence, that the measure pursues a legitimate objective, such as security or system integrity, and that no less competition-restrictive alternative is available. Illegality is established only where this justificatory burden is not satisfied.
The procedural divergence reflects differing conceptions of regulatory fairness. Whereas the DMA relies primarily on categorical obligations and formal compliance assessment, the MSCA enables authorities to evaluate distributive effects, contractual asymmetries, and differential treatment through case-specific evidentiary analysis. The difference carries over to sanctions regimes. Under the MSCA, fines of up to 20 per cent of relevant turnover, and 30 per cent for repeated infringements, may be imposed. By contrast, breaches of other obligations are primarily addressed through cease-and-desist orders and corrective measures under Article 18. This structure concentrates the strongest sanctions on conduct that directly forecloses market access and monetisation. Restrictions on distribution and payments can eliminate competitive pressure entirely, whereas practices relating to ranking, data use, or interoperability typically generate more incremental competitive effects. By aligning sanction severity with foreclosure risk, the MSCA implements a form of targeted deterrence.
The DMA adopts a less differentiated approach. A wide range of infringements, including self-preferencing, default settings, and data-related conduct, can trigger similarly high administrative fines and structural remedies. As a result, heterogeneous forms of conduct are exposed to comparable sanction risks, increasing incentives for risk-averse compliance strategies.
Two Models of Platform Regulation: EU’s DMA and Japan’s MSCA
After examining the EU’s DMA and Japan’s MSCA across their legal design, enforcement logic, and underlying regulatory objectives, clear structural differences emerge. While both frameworks seek to address market power in digital ecosystems, they do so through distinct institutional and procedural models. To synthesise these qualitative findings further, the Table below provides a comparative summary of the two regimes across key regulatory dimensions.
Table 1: Comparing the EU’s DMA and Japan’s MSCA
Source: ECIPE analysis of Digital Markets Act (DMA) and Mobile Software Competition Act (MSCA).
Although inspired by the DMA, the MSCA does demonstrate to an extent how ex ante regulation can be designed in a more context-sensitive and operationally adaptive manner. Several aspects of this approach offer valuable lessons for the EU.
- Integration of Regulation in Identifiable Sectoral Risks
A distinctive feature of MSCA is its approach towards sector specific competitive risks. Japanese policymakers have linked the legislation to independent developers, particularly in the gaming sector, who have consistently reported structural dependence on Apple’s and Google’s app stores. Preparatory studies in Japan by authorities claimed that commission rates of 15–30 per cent, combined with opaque approval processes and frequent unilateral rule changes, have limited developers’ bargaining power and constrained monetisation strategies. These conditions have been characterised as quasi-essential facility dynamics, in which access to end users is mediated through a small number of unavoidable intermediaries.
Similarly, many Japanese web-service providers rely heavily on dominant search engines for user traffic. Preferential ranking of proprietary services and limited transparency in algorithmic design have raised concerns about foreclosure risks and reduced visibility for independent providers. In addition, the increasing integration of digital services into connected vehicles has generated concerns regarding vertical dependency in the automotive sector. As navigation, entertainment, and payment systems become app-based, Japanese manufacturers risk being compelled to distribute core services through foreign-controlled operating systems and app stores. According to Japan’s regulators, this may result in a transfer of value and strategic control from domestic producers to external platform operators, undermining industrial autonomy.
Against this background, the MSCA’s ecosystem-specific design narrows regulatory oversight to defined technological environments, reducing administrative complexity and facilitating more context-sensitive enforcement. This targeted approach may, in principle, improve regulatory proportionality by aligning obligations more closely with identifiable market risks. At the same time, the concentration of regulatory attention increases the risk of rigid compliance frameworks and may constrain firms’ ability to adapt to evolving market conditions.
By contrast the DMA’s gatekeeper framework is largely detached from sector-specific conditions. Its horizontal structure applies across heterogeneous markets with limited differentiation based on underlying industrial contexts. While this expansive scope reflects the DMA’s ambition to address systemic digital power, it has generated interpretive ambiguity, particularly where uniform remedies are applied across diverse services. This increases the likelihood of standardised interventions that insufficiently reflect sectoral variation.
- Institutionalising Proportionality through Objective Justification
A central difference between the DMA and the MSCA concerns the balance between formalistic and functional compliance. In the DMA, obligations are largely applied uniformly to all designated gatekeepers, with limited scope for contextual adjustment. While exemptions are theoretically available, they remain procedurally burdensome and dependent on Commission discretion. By contrast, the MSCA institutionalises proportionality through the doctrine of objective justification. Designated providers may demonstrate that strict compliance would be excessively detrimental to service integrity, cybersecurity, or system stability. This shifts regulatory assessment from abstract rule-following toward functional evaluation of market conditions. For the EU, this model suggests that regulatory flexibility need not automatically undermine enforcement outcomes. When embedded transparently in statutory design, proportionality may improve regulatory predictability and reduce incentives for purely defensive compliance behaviour.
- Embedding Privacy and Security into Interoperability Governance
The DMA conceptualises interoperability primarily as a technical and standardisation problem, to be resolved through implementing acts and harmonised interfaces. While this may promote uniform access, it has clearly generated privacy and security risks, including demands for access to highly sensitive user data. The MSCA’s approach reframes interoperability as a governance challenge rather than a purely technical mandate. By permitting refusals where requests threaten privacy or cybersecurity, and by requiring proportionality to competition concerns, the MSCA integrates user protection into market-opening mechanisms. This design reduces the likelihood of the feature degradation and delayed deployment observed in Europe. For the EU, it demonstrates the importance of integrating security safeguards within interoperability obligations, rather than treating them as after-the-fact exceptions.
- Refining the Concept of Self-Preferencing through Algorithmic Governance
The DMA’s categorical approach to self-preferencing reflects a precautionary logic but provides limited guidance on how algorithmic discrimination should be assessed in practice. This contributes to legal uncertainty and compliance conservatism. The MSCA links self-preferencing to unfair or discriminatory algorithmic design. Through disclosure and transparency obligations, the JFTC seeks to make ranking systems partially verifiable by affected parties and regulators. This may shift regulatory scrutiny from abstract outcome-based prohibitions toward evidence-based assessment of decision-making processes Compared to blanket restrictions, this approach is more likely to support proportionate enforcement and reduce the risk of over-deterrence. For the EU, it suggests that effective control of digital discrimination may depend less on categorical bans and more on governance frameworks that enable verification, and contestability.
- Rebalancing Enforcement toward Cooperative Governance
The MSCA’s enforcement style demonstrates the advantages of consultative regulation in technologically complex markets. The JFTC’s emphasis on guidance, reporting, and negotiated compliance reflects an understanding that rigid adversarial enforcement may lag innovation cycles. Although the MSCA strengthens formal powers, it retains mechanisms for regulatory dialogue and adaptive adjustment. By contrast, the DMA’s enforcement framework is heavily proceduralised, often resulting in prolonged investigations and delayed remedies. Greater use of structured consultation mechanisms could improve regulatory responsiveness without forgoing accountability.
- Innovation and the Future
In fast-paced technology sectors, the long-term impact of these regulatory regimes depends largely on their interaction with technological change. Early implementation of the DMA has reportedly resulted in delayed services and feature fragmentation, as firms divert resources towards compliance. This raises concerns about regulatory-induced inefficiencies. Similar critique has been raised against Japan’s Smartphone Act. Both regulations risk being misaligned with technological developments, insofar as they remain anchored in existing market structures. However, the two exhibit different modes of obsolescence: the DMA ties regulatory obligations to fixed market classifications and the MSCA enables authorities to reinterpret and redeploy its provisions in light of evolving technological configurations. While the MSCA could still be misaligned with future market developments, it nonetheless retains greater adaptive capacity than the DMA’s more formalised framework.
4 responses to “Reviewing the Digital Markets Act: Inspirations from Japan”