Skip to content

Evidence request lists

EU Digital Markets Act

Evidence request list. 26 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DMA - Article 5 Self-Executing Obligations (Ch III)

DMA-Art.5
Article 5 self-executing obligations (Article 5)

Article 5 sets the self-executing obligations applying from the 6-month post-designation date (default 6 March 2024 for the first cohort): (1) no processing of personal data for cross-CPS advertising without specific GDPR-compliant consent; (2) allow business users to offer the same products / services at different prices and conditions through third-party online intermediation services (no MFN clauses); (3) allow business users to communicate and conclude contracts with end users acquired through the CPS, regardless of whether they use the gatekeeper's CPS for the contract; (4) allow end users to access content acquired through their business-user relationship outside the gatekeeper's CPS; (5) no restrictions on business users / end users raising issues of non-compliance with authorities; (6) no requirement to use the gatekeeper's identification, browser, payment services to use the CPS

Artefacts an auditor will ask for
  • For each Article 5(1)-(8) obligation, a documented compliance approach + audit trail
  • Article 8(1) explanatory measures published by the entity
  • Internal annual Article 11 compliance reporting
Where this commonly fails
  • Cross-CPS personal-data combining without GDPR-compliant consent
  • Anti-steering (MFN) clauses with business users
  • Tying of identification/browser/payment services to CPS access
  • Mandatory multi-CPS subscription

DMA - Article 6 Obligations Susceptible of Specification (Ch III)

DMA-Art.6
Article 6 obligations susceptible to specification (Article 6)

Article 6 sets obligations that may be further specified by Commission decision (Article 8 process). Highlights: (1) no use of non-public business-user data to compete against business users on the CPS; (2) allow end users to uninstall pre-installed apps + change defaults; (3) allow installation and effective use of third-party app stores + sideloaded apps (operating systems); (4) no self-preferencing in ranking, indexing, crawling; (5) interoperability access to hardware and software features used or controlled through the OS / virtual assistant (Article 6(7)); (6) free and effective end-user data portability (continuous + real-time where applicable); (7) free + effective business-user data access (incl. data generated through end-user interaction on the CPS); (8) advertiser/publisher performance-data access (impressions, clicks, billing rates); (9) FRAND access to app stores / online s

Artefacts an auditor will ask for
  • For each Article 6(2)-(13) obligation: documented compliance approach + Article 8 specification engagement records
  • Independent audit (Article 15) covering the implementation
Where this commonly fails
  • Use of non-public business-user data to compete (Article 6(2))
  • Default-app pre-installation that cannot be uninstalled (Article 6(3))
  • Operating system that blocks third-party app stores (Article 6(4))
  • Self-preferencing in ranking (Article 6(5))

DMA - Article 7 N-IICS Interoperability and Compliance Obligations (Ch III)

DMA-Art.11_12_13
Reporting, updating obligations and anti-circumvention (Articles 11-13)

Article 11 requires gatekeepers to provide to the Commission, within 6 months of designation and annually thereafter, a detailed report describing the measures implemented to ensure compliance with Articles 5, 6 and 7. Article 12 requires the gatekeeper to update the report when there are material changes. Article 13 prohibits the gatekeeper from circumventing Article 5/6/7 obligations through technical means, contractual terms or other behaviour having an equivalent effect.

Artefacts an auditor will ask for
  • Article 11 annual compliance report
  • Article 12 material-change update procedure
  • Anti-circumvention control review
Where this commonly fails
  • Late or omitted Article 11 annual report
  • Engineering / contractual changes that effectively limit Article 5/6/7 implementation (Article 13 breach)
DMA-Art.14
Notification of concentrations (Article 14)

Article 14 requires gatekeepers to notify the Commission of any intended concentration (acquisition) where the merging entities or the target provide CPS or any other services in the digital sector, or enable the collection of data, regardless of whether the concentration is otherwise notifiable under EU/national merger control. Notification is required prior to its implementation and following the conclusion of the agreement.

Artefacts an auditor will ask for
  • Internal M&A pipeline tracking with Article 14 trigger flags
  • Article 14 notifications filed (including non-EU and non-merger-control transactions)
Where this commonly fails
  • Closing of a concentration without Article 14 notification
  • Late Article 14 notification
DMA-Art.15
Audit obligation (Article 15)

Article 15 requires gatekeepers to submit, within 6 months of designation and annually thereafter, an independently-audited description of any techniques for profiling of consumers that the gatekeeper applies to or across its CPS. The audited description is provided to the Commission and a non-confidential summary is made publicly available.

Artefacts an auditor will ask for
  • Annual Article 15 audited description of consumer profiling techniques
  • Public non-confidential summary
Where this commonly fails
  • No annual Article 15 audited description
  • Audited description not covering all CPS
DMA-Art.7
N-IICS interoperability (Article 7)

Article 7 imposes phased interoperability on Number-Independent Interpersonal Communication Services (N-IICS) designated as CPS: (1) free-of-charge interoperability access on request to any other N-IICS, with messaging functionality (text, image, audio, video); (2) phased: messages + files + voice/video calls; (3) preservation of end-to-end encryption equivalent to the level offered between users of the gatekeeper's own service; (4) basic functionality offered first, with group + voice/video added on the 2-year and 4-year timelines respectively; (5) technical specifications published and updated.

Artefacts an auditor will ask for
  • Article 7 interoperability roadmap demonstrating the phased deliverables (text/images/files 2024; group 2025; voice/video 2027)
  • Article 7(3) end-to-end-encryption equivalence assessment
  • Published technical specifications + reference documentation
Where this commonly fails
  • N-IICS gatekeeper without published Article 7 technical specifications
  • Interoperability that weakens end-to-end encryption
  • Failure to honour Article 7(2) phased deliverables
DMA-Art.8
Compliance with obligations - Article 8 specification process (Article 8)

Article 8 governs how Article 6 + Article 7 obligations may be specified by the Commission. The gatekeeper publishes its compliance approach in a non-confidential summary (Article 8(2)); the Commission may open a dialogue, may specify the measures required, may demand changes. The Article 8 specification process is collaborative but binding on the gatekeeper.

Artefacts an auditor will ask for
  • Public non-confidential Article 8(2) compliance summary maintained for each Article 6 + Article 7 obligation
  • Records of Article 8 specification dialogues and resulting Commission decisions
Where this commonly fails
  • No Article 8(2) public compliance summary
  • Specification dialogue not honoured in the entity's compliance program
DMA-Art.9_10
Suspension and exemption (Articles 9-10)

Article 9 enables the Commission to suspend an Article 5/6/7 obligation in case of an unforeseen event with material consequences. Article 10 enables an exemption for grounds of public health or public security. Both are strictly time-limited and reviewed.

Artefacts an auditor will ask for
  • Documentation of any Article 9 / Article 10 requests filed by the entity

DMA - Cooperation, Penalties, Final Provisions (Ch V-VI)

DMA-Art.29
Non-compliance (Article 29)

Article 29 enables the Commission to adopt a non-compliance decision establishing that the gatekeeper does not comply with one or more Article 5/6/7 obligations and ordering compliance. Where two non-compliance decisions are adopted within 8 years for the same CPS, the conduct is systematic non-compliance triggering enhanced Article 18 market-investigation remedies (including structural remedies).

Artefacts an auditor will ask for
  • Internal procedure to receive and remediate a non-compliance decision
  • Lessons-learned analysis
Where this commonly fails
  • Repeat non-compliance triggering Article 18 systematic-non-compliance investigation
DMA-Art.30_31
Fines and periodic penalty payments (Articles 30-31)

Article 30 enables the Commission to impose administrative fines: up to 10% of worldwide annual turnover for breach of Articles 5/6/7/16/18 or breach of commitments; up to 20% of worldwide annual turnover for repeated infringements within 8 years; up to 1% of worldwide annual turnover for supplying incorrect / incomplete / misleading information. Article 31 enables periodic penalty payments up to 5% of average daily worldwide turnover per day to compel compliance.

Artefacts an auditor will ask for
  • Internal compliance program demonstrating risk management against the Article 30 + Article 31 penalty regime
  • Annual Article 30(7) compliance risk-assessment
Where this commonly fails
  • Compliance program treating Article 30 penalty as the cost of non-compliance
DMA-Art.32_33_34
Limitation periods and right to be heard (Articles 32-34)

Article 32 sets the limitation period for the imposition of penalties (3 years for procedural / 5 years for substantive). Article 33 sets the limitation period for enforcement of imposed penalties (5 years). Article 34 ensures the right to be heard and access to the file before adverse decisions.

Artefacts an auditor will ask for
  • Records of any Article 34 right-to-be-heard interactions
  • Penalty-time-bar tracking
DMA-Art.36
Professional secrecy (Article 36)

Article 36 imposes professional-secrecy obligations on the Commission and on any persons acquiring information in the course of DMA procedures. Information obtained may only be used for the purpose for which it was acquired; carve-outs for cooperation with other authorities.

DMA-Art.37_38_39_40
Cooperation with national authorities, competition authorities and courts; high-level group (Articles 37-40)

Article 37 covers cooperation with national authorities. Article 38 covers cooperation and coordination with national competition authorities enforcing competition rules (Articles 101-102 TFEU + national equivalents). Article 39 covers cooperation with national courts (amicus-curiae submissions). Article 40 establishes a high-level group of European regulators (BEREC, EDPB, EDPS, ERGA, EU CPC Network) advising the Commission on DMA implementation.

Artefacts an auditor will ask for
  • Records of any cooperation interactions involving the entity (DG COMP coordination, national competition authority interaction, court amicus)
DMA-Art.41_42_43_44_45
Market-investigation requests, representative actions, whistleblower protection, publication of decisions, judicial review (Articles 41-45)

Article 41 enables three or more Member States to request the Commission to open a market investigation under Article 17/18/19. Article 42 brings the DMA into the scope of Directive (EU) 2020/1828 on representative actions. Article 43 brings the DMA into the scope of Directive (EU) 2019/1937 on whistleblower protection. Article 44 requires publication of Article 8/9/10/17/18/19/24/25/29 decisions (with confidentiality carve-outs). Article 45 confirms judicial review by the Court of Justice (Article 261 TFEU unlimited jurisdiction over Article 30/31 penalties).

Artefacts an auditor will ask for
  • Internal alignment with Directive (EU) 2019/1937 whistleblower protection for DMA breach reports
  • Tracking of Commission Article 44 published decisions
Where this commonly fails
  • No whistleblower channel for DMA-breach reports
DMA-Art.46_47_48
Implementing acts, guidelines and standardisation (Articles 46-48)

Article 46 enables the Commission to adopt implementing acts on the form, content and procedural details of notifications, applications and reasoned requests. Article 47 enables the Commission to adopt guidelines on the application of the Regulation. Article 48 enables the Commission to mandate European standardisation bodies (CEN/CENELEC/ETSI) to develop technical standards supporting Article 7 interoperability, in particular for N-IICS interoperability.

Artefacts an auditor will ask for
  • Tracking of Article 46 implementing acts (notification forms, procedural rules)
  • Adoption of Article 48-mandated standards for N-IICS interoperability
DMA-Art.49_50
Delegation and committee procedure (Articles 49-50)

Article 49 governs the exercise of the delegation of power (Article 3, Article 12 updating of obligations). Article 50 sets the committee procedure (the Digital Markets Advisory Committee).

DMA-Art.51_52
Amendments to Directives 2019/1937 and 2020/1828 (Articles 51-52)

Article 51 amends Directive (EU) 2019/1937 (whistleblower protection) to add the DMA to its scope. Article 52 amends Directive (EU) 2020/1828 (representative actions) to add the DMA to its Annex I scope.

DMA-Art.53_54
Review and entry into force (Articles 53-54)

Article 53 requires the Commission to evaluate the Regulation by 3 May 2026 and every three years thereafter, in particular the effectiveness of the obligations and the case for adding new CPS categories or new obligations. Article 54 provides that the Regulation entered into force on the twentieth day following its publication in the OJ (1 November 2022) and applied from 2 May 2023, with phased application of certain articles.

Artefacts an auditor will ask for
  • Tracking of the Commission's Article 53 evaluation cycle

DMA - Gatekeeper Designation (Ch II)

DMA-Art.3
Designation of gatekeepers (Article 3)

Article 3 sets the designation criteria. An undertaking is designated as a gatekeeper if it (a) has a significant impact on the internal market (EUR 7.5 billion annual Union turnover OR EUR 75 billion average market cap in each of the last three financial years), (b) provides a CPS that is an important gateway for business users to reach end users (at least 45 million monthly active end users + 10,000 yearly active business users in the Union in the last financial year), and (c) enjoys an entrenched and durable position in its operations (at least three consecutive financial years of meeting both thresholds; or substantiated likelihood of meeting them in the near future). Designation is presumed where thresholds are met; the undertaking can rebut. Article 3(8) sets the 45-business-day timeline for designation following notification by the undertaking.

Artefacts an auditor will ask for
  • Article 3 self-assessment of designation thresholds for each CPS the entity provides
  • Article 3(3) notification + supporting evidence
  • Designation-decision tracking for the entity's CPS
Where this commonly fails
  • Operating a CPS meeting Article 3 thresholds without notification
  • Late or incomplete Article 3(3) notification
DMA-Art.4
Review of gatekeeper status (Article 4)

Article 4 requires the Commission to review designations periodically (at least every three years), and may un-designate where designation criteria are no longer met, or designate additional CPS of the same undertaking. The undertaking has the right to be heard before un-designation or scope changes.

Artefacts an auditor will ask for
  • Records of Article 4 reviews involving the entity (Commission-initiated or undertaking-requested)
  • Updated self-assessment for the 3-year review cycle
Where this commonly fails
  • Failure to update Article 3 thresholds for the Article 4 review

DMA - Market Investigation, Investigative Powers and Enforcement (Ch IV-V)

DMA-Art.16_17_18_19
Market investigation (Articles 16-19)

Article 16 enables the Commission to open a market investigation. Article 17 sets the investigation route for designating gatekeepers when Article 3 thresholds are nearly met but evidence of qualitative gatekeeper position exists. Article 18 sets the investigation route for systematic non-compliance with Articles 5-7. Article 19 sets the investigation route for new services and new practices, with the possibility of extending Article 5-7 obligations to other CPS-like services.

Artefacts an auditor will ask for
  • Internal procedure to receive and respond to Article 16-19 investigation notifications
  • Cooperation with Commission investigations under Articles 17-19
DMA-Art.20_21_22_23
Investigative powers (Articles 20-23)

Article 20 governs the opening of proceedings. Article 21 enables the Commission to require information by simple request or by binding decision. Article 22 enables the Commission to interview persons. Article 23 enables the Commission to conduct unannounced inspections at the premises of undertakings, including the power to enter, examine and copy books and records, seal premises, interview personnel.

Artefacts an auditor will ask for
  • Dawn-raid response plan for the entity's EU premises
  • Document-retention practices supporting cooperation
  • Information-request handling SLA
Where this commonly fails
  • No dawn-raid response plan
  • Document-destruction practices that risk Article 30(1)(d) penalty
DMA-Art.24_25_26_27
Interim measures, commitments, monitoring and third-party information (Articles 24-27)

Article 24 enables interim measures in urgent cases. Article 25 enables the Commission to make commitments offered by the undertaking binding (and to declare proceedings closed). Article 26 governs monitoring of obligations and remedies. Article 27 enables third parties (business users, end users, competitors, consumer associations) to bring concerns to the Commission's attention.

Artefacts an auditor will ask for
  • Records of any Article 25 commitments offered or accepted
  • Internal Article 26 monitoring and reporting
DMA-Art.28
Compliance function (Article 28)

Article 28 requires each gatekeeper to introduce a compliance function independent from the operational functions of the gatekeeper, composed of one or more compliance officers, including the head of the compliance function. The compliance function: organises Article 8 specification dialogues, prepares Article 11 reports, monitors compliance with the DMA, identifies and reports DMA risks. The head of the compliance function reports directly to the management body.

Artefacts an auditor will ask for
  • Org chart showing the compliance function reporting line into the management body
  • Compliance-officer mandate, resources and independence safeguards
  • Quarterly compliance reports to the management body
Where this commonly fails
  • Compliance function embedded within operational functions
  • Compliance officers reporting only to operational management

DMA - Subject Matter, Scope and Definitions (Ch I)

DMA-Art.1
Subject matter and scope (Article 1)

Article 1 sets out the subject matter: harmonised rules ensuring for all businesses, contestable and fair markets in the digital sector across the Union where gatekeepers are present, for the benefit of business users and end users. Article 1(5)-(7) sets the relationship with Union competition law (no derogation; the DMA is without prejudice to Articles 101-102 TFEU) and with national-law gatekeeper provisions.

Artefacts an auditor will ask for
  • Internal scope determination: gatekeeper / business user / end user / non-gatekeeper provider of CPS
  • Documentation of DMA + competition-law interaction (Article 1(5)-(7))
Where this commonly fails
  • Reliance on the DMA as a defence under Articles 101-102 TFEU (DMA does not derogate competition law)
DMA-Art.2
Definitions (Article 2)

Article 2 supplies the definitions used throughout the Regulation. Core definitions: 'core platform service' (the 10 enumerated CPS categories), 'gatekeeper' (an undertaking providing one or more CPS meeting Article 3 criteria), 'business user', 'end user', 'undertaking' (per competition law), 'group' (parent + subsidiaries), 'ranking', 'data', 'personal data' (per GDPR Article 4), 'online intermediation service' (per (EU) 2019/1150), 'online search engine' (per (EU) 2019/1150), 'social networking service', 'video-sharing platform service' (per AVMSD), 'N-IICS' (per the European Electronic Communications Code), 'operating system', 'virtual assistant', 'web browser', 'cloud computing service' (per NIS2), 'online advertising service'.

Artefacts an auditor will ask for
  • Definitions glossary mapping the entity's services to the Article 2 CPS taxonomy
Where this commonly fails
  • Service description that does not commit to a particular Article 2 CPS category
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EU Digital Markets Act framework page.