The EU’s digital rulebook is entering a new phase, one marked less by the need to close regulatory gaps than by the risk of friction between overlapping rules. At the centre of this shift stands the Digital Markets Act (DMA), a landmark regulation designed to reshape digital competition and improve user choice and value. But as the original DMA implementation has mostly been completed, new structural issues have become apparent as DMA regulators are pushing deeper and deeper on issues around interoperability.
One issue in particular is a source of big concern: the EU’s growing reliance on ex ante and rather interventionist regulation under the DMA is increasing the risk of conflicts with other key regulations. Unfortunately, this reflects a deeper transformation in how the EU has started to regulate digital markets, an administrative shift that is generating tensions between DMA measures and core policies on data protection, cybersecurity, and intellectual property. As a result, privacy and cybersecurity objectives are already compromised. Moreover, companies are pulling innovation and new features from the EU market to avoid getting trapped in regulatory conflicts they cannot resolve. And the region’s users? They are at risk of being deprived of more positive, safe, and user-friendly services.
Regulatory Conflict: The Case of the GDPR
The DMA has changed since its original conception. Initially conceived to make digital markets fairer and more contestable, the DMA has evolved into a more expansive and detailed regime that is increasingly disassociated with real-market developments. In effect but not by law, the DMA almost operates as a lex specialis within the EU legal order, an administrative regime that in practice can override or sideline other frameworks such as the General Data Protection Regulation (GDPR).
Take the joint publication by the European Commission and the European Data Protection Board (EDPB) on the interplay between the DMA and the GDPR. In the guidelines, the primacy of the DMA emerges as a practical result. While the jointly issued guidelines emphasise that the two frameworks should be applied in a coherent and complementary manner, they introduce a clear operational bias: where multiple GDPR implementation options exist, gatekeepers are expected to choose those that least undermine the objectives of the DMA. In practice, even without a formal legal hierarchy, this embeds a functional prioritisation of DMA compliance.
This may appear as a clear guidance for what companies should prioritise as well: the DMA should take precedence over the GDPR, when there are multiple options in the latter regulation. Unfortunately, the actual regulatory reality is far from clear. For instance, what should happen in cases where, in practice, no meaningful choice options exist? Or when a national Data Protection Authority imposes restrictions that sit uneasily with DMA obligations – effectively requiring a gatekeeper to disregard data-protection constraints in order to comply with data-sharing mandates? These are not theoretical questions: they are the result of actual investigations and enforcement measures taken in Europe.
Frankly, these guidelines on regulatory priority risk becoming overly abstract, not least because decisions are taken by different authorities. In practice, coordination across Commission services and national agencies remains limited, making coherent implementation difficult. Moreover, when DMA actions effectively force a company to assume liability for data protection practices at a third-party developer – again, not a theoretical risk (hey presto, “specification proceedings”) – it is impossible to see how this would not lead to a conflict between regulations and their objectives. Users clearly assume that a platform handle their data in accordance with law and high standards of data safety. However, the regulatory reality often prevents platforms from doing so: they are mandated by the DMA to hand over sensitive data to third parties.
Much as some commentators and officials remain dismissive of concerns raised by gatekeepers, the situation is becoming messy. In the case of GDPR, it is particularly visible when looking more closely at how the GDPR’s core principles – such as purpose limitation, data minimisation, and accountability – interact with DMA obligations. The GDPR requires that personal data are processed only for specific, explicit purposes and that controllers ensure appropriate safeguards before sharing data.
By contrast, the DMA obliges gatekeepers to enable broad data access and portability at the request of users and third parties, including in real-time and on a continuous basis – regardless of service, market structure, and business model. This can significantly expand the scope of data flows beyond what would normally be considered proportionate under GDPR standards. Obviously, it may lead to a proliferation of consent requests and “consent fatigue”, undermining the very idea of meaningful user control over personal data.
Practical implications have already been highlighted elsewhere. Take a user who wants to connect a new budgeting or fitness app to their main platform account. Under the DMA and the DMA–GDPR guidelines, gatekeepers are required to enable third-party access to user data at the user’s request and cannot unduly restrict or discriminate against such third parties. This means the platform must make these apps interoperable and accessible within its ecosystem – regardless of what ecosystem it runs – rather than limiting visibility only to the platform’s pre-vetted or trusted partners. Once the user gives consent, the gatekeeper may be required to transfer personal data, such as transaction history, location data, or messages, to the third-party developer.
In the Commission’s specification proceedings against the two OS platforms, this conflict is on full display. By design, these proceedings are highly granular, focusing on technical specifications and system architecture. The Commission frames them as a means to assist gatekeepers in complying with the DMA. Yet it is difficult to avoid the impression that insufficient weight has been given to security implications and to the limits of what platforms can realistically control – and be held liable for.
The forthcoming specification concerning Android and access to Gemini has not yet been published. However, the Commission has previously downplayed privacy concerns raised by both Google and Apple. In both instances, enforcement appears to move towards a form of structural access in which it remains unclear how data can remain anonymised and secure while being widely shared with third-party developers.
In a same way, the guidelines constrain the gatekeepers’ ability to apply basic safeguards. They limit their capacity to screen third parties, restrict access based on risk, or even clearly warn users about potential security or data protection concerns. In practice, this means that even where an app has weak security practices or a history of data breaches, the platform may still be required to facilitate the transfer. This creates a situation where compliance with the DMA sits awkwardly with the GDPR’s own requirements on data protection, exposing users to risks they may neither anticipate nor understand.
These tensions are further amplified by the way the DMA reshapes consent itself. Rather than reinforcing informed and freely given consent as envisaged under the GDPR, the DMA–GDPR interaction risks turning consent into a procedural gateway for mandated large-scale data transfers. In practice, users may be presented with frequent and complex consent requests linked to interoperability and data portability, often in contexts where they lack the information or expertise to assess risks. This risks hollowing out the substantive protections of the GDPR, replacing them with formal compliance mechanisms that do little to improve actual user control.
Cybersecurity and the DMA
Similarly, the DMA’s requirements to open systems to third parties raise concerns from a cybersecurity and cyber-resilience perspective, particularly where system integrity and risk management depend on controlled access.
These tensions should not be understood only as policy trade-offs, but as conflicts that emerge at the level of system design itself, where regulatory obligations interact directly with security architectures that were originally built on controlled and closed access models.
For instance, interoperability mandates under the DMA can significantly expand the “attack surface” of digital systems. These concerns have been raised time and again in DMA discussions – and not just from the affected companies but from technology and security experts as well. By requiring operating systems and platforms to grant access to core functionalities, data interfaces, and AI integration, the DMA may introduce new technical entry points that were not originally designed with external access in mind. This can increase vulnerabilities to malware, spyware, and other forms of cyber intrusion, including sophisticated attacks that exploit system-level permissions.
Concrete examples of this tension are already emerging in the mobile ecosystem. Requirements to allow third-party app stores, sideloading, or external payment links can bypass established security controls, exposing users to phishing attacks, malicious applications, and fraudulent transactions. Security frameworks such as app review processes or controlled distribution channels, designed to mitigate these risks, may be weakened when platforms are required to allow unvetted third-party access. It matters little what type of ecosystem is in place when all actors are, in effect, subject to a general obligation to grant access.
More broadly, this creates a structural conflict between the DMA and the EU’s wider cybersecurity agenda, including instruments such as the Cyber Resilience Act and the NIS2 Directive and the newly proposed revision of the EU Cybersecurity Act. While these frameworks aim to strengthen system integrity, risk management, and resilience, the DMA may in some cases require platforms to prioritise openness and interoperability over security considerations. So far, the Commission has dismissed concerns raised by gatekeepers that security may be compromised because of mandated implementation and enforcement actions under the DMA. However, firms are increasingly facing situations where complying with DMA obligations entails accepting higher cybersecurity risks or limiting the effectiveness of protective measures.
Crucially, these tensions are compounded by the absence of operational guidance or safe harbours that would allow firms to demonstrate that certain security measures are necessary and proportionate, thereby creating legal uncertainty around how far protective restrictions can be maintained without breaching DMA obligations.
At a more technical level, a programmatic and mandated interoperability also impacts on core security architectures. For example, requests for access to sensitive system functions, such as execution environments or hardware-level interfaces, can create pathways for exploitation by malicious actors, including nation-state actors. Features like Just-In-Time (JIT) compilation, when opened to third parties without adequate safeguards, have historically been associated with major vulnerabilities and exploit chains. This illustrates how regulatory requirements designed to promote competition can inadvertently undermine deeply embedded security models.
Intellectual Property Law and the DMA
The interaction between the DMA and intellectual property (IP) protection also raises a distinct set of challenges, particularly where obligations to ensure interoperability or data access intersect with legally protected assets. In practice, certain DMA requirements may require gatekeepers to provide access to interfaces, technical information, or datasets that are otherwise protected under copyright, trade secrets, or database rights. For example, enabling interoperability with third-party services may necessitate the disclosure of interface specifications or system functionalities that would typically remain proprietary. Similarly, data portability and access obligations may extend to datasets that benefit from legal protection, raising questions about the limits of mandated sharing.
These tensions do not amount to a direct contradiction between the DMA and IP law. Rather, they reflect the fact that both frameworks pursue, in different ways, the broader objective of promoting innovation. IP protection does so by granting exclusive rights that incentivise investment and creativity, while the DMA seeks to ensure that such exclusivity is not used to entrench market power and foreclose competition. As such, conflicts arise not at the level of objectives, but in their operationalisation.
Addressing these tensions requires a structured and transparent balancing exercise. While IP rights are recognised as fundamental within the EU legal order, they are not absolute and may be limited where this is necessary to achieve objectives of general interest, such as ensuring fair and contestable markets. In this context, enforcement of the DMA must ensure that any limitation on IP protection remains proportionate and targeted. This implies assessing whether access obligations are necessary to achieve contestability, whether less restrictive alternatives are available, and whether the exercise of IP rights serves a legitimate protective function or is being used strategically to reinforce market power.
A key challenge, however, lies in the absence of clear and predictable frameworks to guide this balancing exercise. Without such guidance, both regulators and firms face uncertainty in determining when IP-based restrictions are justified and when they may conflict with DMA obligations. This increases the risk of inconsistent enforcement and may ultimately weaken both innovation incentives and the effectiveness of competition policy.
Different Rules, Different Outcomes
The deeper issue lies, however, in the design of regulations. The DMA’s objectives are laudable, and many of its initial implementation actions were well-motivated. However, the shift towards more detailed interventions has exacerbated regulatory conflicts – and the growing use of specification proceedings brings these tensions into sharper relief. These conflicts increasingly reflect a legislative approach in which new rules are introduced every few years, each expanding the scope of intervention and redefining what firms cannot – and, critically, must – do. The result is a granular but fragmented rulebook in which multiple instruments pursue distinct objectives (e.g., competition, privacy, security) without effective mechanisms to manage trade-offs.
To understand why conflicts such as those between the DMA and the GDPR, or between the DMA and the EU’s cybersecurity agenda or IP law, are becoming more frequent, it is necessary to look beyond individual instruments and consider the broader trajectory of EU regulatory design.
Historically, the Single Market was built on proscriptive rules. These frameworks defined what firms were not allowed to do, such as restricting competition or discriminating against market participants, while leaving considerable flexibility in how businesses organised their activities. This approach facilitated cross-border integration by ensuring a common baseline without over-specifying outcomes.
By contrast, many EU digital regulations have moved towards a more prescriptive model. Regulations such as the DMA, and instruments like specification proceedings, do not simply prohibit harmful conduct; they require firms to adopt specific behaviours, technical configurations, and forms of interaction. As the European Commission itself notes, “gatekeepers will have to comply with the do’s (i.e. obligations) and don’ts (i.e. prohibitions) set out in the DMA.” In practice, this approach goes beyond shaping market outcomes to influencing the design, interfaces, and day-to-day operation of digital services.
While this shift has been motivated by concerns such as entrenched market power and data asymmetries, it comes with important trade-offs. Prescriptive rules are inherently more difficult to reconcile across policy domains, particularly when they are layered on top of existing frameworks, also prescriptive in nature, that were designed with different objectives in mind.
The move towards prescriptive regulation significantly increases legal and operational complexity. As rules become more detailed and interventionist, they are more likely to overlap with other regulatory requirements, creating zones of ambiguity and contradiction.
In practice, firms may find themselves required to comply simultaneously with obligations that pull in different directions. A platform may be required to share data to promote competition under the DMA, while being constrained in how that data can be processed or transferred under the GDPR. Likewise, efforts to ensure interoperability may conflict with obligations to maintain robust cybersecurity safeguards. In the worst-case scenario, a company may be forced to directly violate one regulation in order to comply with another.
The risks associated with regulatory complexity are compounded by the EU’s enforcement structure. While regulations are adopted at the European level, their implementation often involves national authorities with varying capacities, priorities, and interpretations.
The experience of the GDPR illustrates this challenge. Despite being a directly applicable regulation intended to harmonise data protection rules across the EU, its enforcement has been marked by significant divergence in interpretation and practice. Differences in how national Data Protection Authorities assess compliance, handle complaints, and impose sanctions have resulted in uneven outcomes across Member States.
As more prescriptive and overlapping regulations on competition law, cybersecurity law and national rules of some Member States are introduced, the scope for such divergence increases. Where multiple regimes intersect, national authorities sometimes prioritise different objectives. The result is a form of de facto fragmentation, where firms face varying compliance expectations depending on the jurisdiction.
This outcome runs counter to the original logic of the Single Market, which sought to reduce regulatory barriers and create a predictable environment for cross-border activity. Instead, the current trajectory risks reintroducing uncertainty through the back door.
This raises broader questions about the sustainability of the EU’s regulatory trajectory. If the accumulation of prescriptive rules continues without sufficient attention to coherence, the result may be a system in which legal obligations remain formally intact but are increasingly difficult to reconcile in practice.
A more sustainable approach requires a recalibration towards principle-based frameworks, clearer mechanisms for resolving conflicts between regimes, and stronger coordination at the European level. At a minimum, it requires recognising that regulatory design choices – particularly the shift from proscriptive to prescriptive rules – have systemic consequences.
As the EU continues to expand its digital rulebook, the key question is no longer whether there is enough regulation, but whether the rules that exist can work together. If they cannot, the risk is that the very instruments intended to strengthen the Single Market may, over time, begin to pull it apart.