Skip to content
VibeFormer
38 min

The Five Instruments, Side by Side

Competition law, DMA, DSA, GDPR and AI Act in one place — who they bind, what triggers them, who enforces, what the fines are, and where they overlap, collide and leave gaps. The chapter to revise from.

Listen

1. What each one actually is, in one line

Start here. If you can say these five sentences cleanly you can hold the whole framework in your head, and most confusion comes from mixing up what each instrument is *for*.

InstrumentIn one lineThe question it asks
Competition law — Arts 101 & 102 TFEU, Reg 1/2003, EU Merger RegulationStops firms from agreeing not to compete, and stops dominant firms from abusing their position*Did this firm behave badly?* Backward-looking, conduct-based, proven case by case
DMA — Reg 2022/1925Imposes a fixed list of do's and don'ts on a handful of very large platforms, by designation rather than by proof of harm*Is this firm big enough to be caught?* Forward-looking, status-based, triggered by counting
DSA — Reg 2022/2065Makes online intermediaries handle illegal content properly, be transparent about moderation and advertising, and assess their own systemic risks*Is this platform managing what happens on it responsibly?* Process obligations rather than outcome liability
GDPR — Reg 2016/679Governs any handling of information about an identifiable person, whoever does it*Is this processing of someone's data lawful, fair and transparent?* Rights-based, and it attaches to the individual
AI Act — Reg 2024/1689A product-safety law for AI systems: the riskier the intended use, the heavier the obligations before you may put it on the market*Is this system safe enough to be sold or deployed for this purpose?* Risk-tiered, and the obligations land before use rather than after harm

2. Who they bind, and what sets them off

Who it bindsWhat triggers itDo you have to prove harm?
Competition lawUndertakings — any entity carrying on economic activity, whatever its legal form. Includes a parent group as a single economic unitConduct: an agreement or concerted practice restricting competition (101), or abusive conduct by a dominant firm (102)Usually yes — except for *by object* restrictions like price fixing and bid rigging, where no proof of actual harm is needed. That exception is why cartel enforcement is tractable
DMADesignated gatekeepers providing one of ten listed core platform services. Around seven firmsPure counting: roughly €7.5bn EU turnover in each of three years or €75bn market cap; 45 million monthly active end users and 10,000 yearly active business users in the EU; sustained over three years. Firm may rebutNo. That is the point. Obligations apply on designation and the Commission need not prove any effect
DSAIntermediary services in four stacked tiers: intermediary → hosting → online platform → VLOP/VLOSE at 45 million average monthly recipients in the EUService type plus user numbers. Obligations accumulate upwardNo for the due-diligence duties. They are process obligations — you must have a complaints system, not achieve an outcome
GDPRControllers (who decide why and how) and processors (who act on instructions). Public and private alikeAny processing of personal data relating to an identifiable living person. Extraterritorial under Art 3 where you target or monitor people in the EUNo. A breach of the principles is actionable without demonstrable damage, though damages claims need harm
AI ActProviders, deployers, importers, distributors and product manufacturers. Note: *deployer* catches an agency using a bought-in systemIntended purpose, mapped to a risk tier: prohibited (Art 5), high-risk (Art 6 + Annexes I & III), limited risk (Art 50), minimal. Plus a separate track for general-purpose AI models (Arts 51–56)No. Conformity is assessed before market placement. The obligation is to have done the work, not to avoid a bad outcome

3. Who enforces, and what it costs

EnforcerMaximum penaltyPrivate claims?
Competition lawCommission (DG COMP) and national competition authorities, working as a network under Reg 1/2003. Decentralised — NCAs apply Arts 101 and 102 directly10 percent of worldwide group turnoverYes, and substantially — damages actions under the Damages Directive, including follow-on claims after a decision
DMAThe Commission alone. Centralised by design, because consistency across the internal market was the priority10 percent of total worldwide turnover, rising to 20 percent for a repeat of the same or similar breach within eight years. Plus periodic penalty payments up to 5 percent of average daily turnover, and structural remedies for systematic non-complianceDeveloping. The regulation does not create a damages regime, but national courts are being used
DSASplit. The Commission exclusively supervises VLOPs and VLOSEs on the systemic-risk obligations; national Digital Services Coordinators handle everything else, on a country-of-establishment basis6 percent of annual worldwide turnover, plus periodic penaltiesYes — the DSA provides for compensation routes, and national consumer law sits alongside
GDPRNational supervisory authorities (DPAs), with a lead-authority *one-stop shop* for cross-border cases and the EDPB resolving disagreements€20 million or 4 percent of worldwide annual turnover, whichever is higher for the serious tier. €10m/2% for the lower tierYes — Art 82, including non-material damage. A major and growing route
AI ActNational market surveillance authorities, plus notified bodies for conformity assessment, plus the AI Office within the Commission for general-purpose models, coordinated by the AI Board€35 million or 7 percent for breaching the Art 5 prohibitions. €15 million or 3 percent for most other obligations including high-risk. €7.5 million or 1 percent for giving authorities incorrect information. GPAI providers face up to 3 percent or €15mNot directly. The AI Act creates no standalone damages right, which is one of the main criticisms of it

4. Ex ante against ex post — and why that is the real dividing line

Where each one intervenes on a timeline

**The move from *after* to *before* is the single biggest shift in EU digital regulation**, and it is a response to a measurement problem: proving an infringement takes years, and digital markets reorganise faster than that. Ex ante regulation buys speed by pre-committing the theory of harm into a threshold.

5. Where they overlap, collide and leave holes

PairingHow they interactThe live example
GDPR × Competition lawLong kept apart, now converging. A competition authority may take data-protection compliance into account in an abuse analysisMeta Platforms v Bundeskartellamt (C-252/21) — the Court accepted that a national competition authority could consider GDPR compliance when assessing abuse. Learn this case name; it is the hinge between the two regimes and squarely in Mirza's field
GDPR × DMABoth bear on data combination across services. The DMA imposes flat prohibitions where the GDPR requires a lawful basis and a balancing exerciseMeta's *consent or pay* model was found in breach of the DMA obligation to offer a less-data-intensive option in April 2025 — a data question decided under competition-style regulation rather than under the GDPR
DSA × AI ActThe DSA governs recommender systems and dark patterns as platform duties; the AI Act governs them as product characteristics. Both can applyArt 25 DSA already prohibits interface designs distorting choice. The forthcoming Digital Fairness Act is a third layer on the same conduct — which raises the obvious question of why two existing prohibitions needed a third
AI Act × GDPRThe AI Act governs the system; the GDPR governs the personal data flowing through it. Neither displaces the other, and Art 22 GDPR plus Art 14 AI Act both address human involvement from different anglesThis is your territory. Art 22 asks whether a decision was *solely* automated; Art 14 asks whether a reviewer can *meaningfully* oversee. Both are empirical questions dressed as legal standards, and nobody measures either
Competition law × DMAThe DMA explicitly does not displace Arts 101 and 102 — they run in parallel, and the same conduct can attract bothA gatekeeper can be fined under the DMA for breaching an obligation and under Art 102 for the same underlying behaviour, on different reasoning. Double jeopardy arguments here are live and unresolved

6. One fact pattern, all five instruments

The fastest way to learn the distinctions is to run one scenario through all of them. A designated gatekeeper runs a marketplace with an AI recommender that ranks sellers, trained on user behaviour, and it ranks its own products higher.

InstrumentDoes it bite?On what reasoning
Competition law — Art 102Possibly, and expensivelySelf-preferencing by a dominant firm can be abusive, but the Commission must define the market, establish dominance, and show actual or likely harm. Years of work. The *Google Shopping* line of cases is the template
DMA — Art 6(5)Yes, directly and quicklyGatekeepers must not treat their own services more favourably in ranking. No market definition, no dominance, no proof of harm needed — just the designation and the conduct. This is exactly the provision Google was fined €460 million under on 16 July 2026
DSA — Arts 27 & 25Yes, partiallyArt 27 requires the main parameters of the recommender to be explained in the terms and conditions. If the interface nudges users toward the firm's own goods in a way that distorts choice, Art 25's dark-patterns prohibition engages. Transparency and design duties, not a ranking prohibition
GDPRYes, as to the training dataThe recommender is trained on user behaviour, which is personal data. Needs a lawful basis under Art 6, must satisfy purpose limitation and data minimisation under Art 5, and if it profiles users at scale it needs a DPIA under Art 35. Says nothing about the ranking being unfair to sellers — sellers are not data subjects in that respect
AI ActProbably only lightlyA recommender is not in Annex III, so not high-risk. It is not prohibited. Art 50 transparency duties are about telling a person they are dealing with AI, which is not the issue here. So the AI Act, the instrument actually about AI, has the least to say about the AI system in this scenario — because it regulates by intended purpose and commercial ranking is not a listed purpose

7. Which instrument for which question

A rough triage

The blank line is the point of this whole chapter. Four of the five bind private actors; the GDPR binds public authorities but only as to personal data; the AI Act reaches an agency as a deployer but only inside a regulated tier. The state's own market-surveillance instrument falls between them.

8. The dates, since they get asked

InstrumentKey dates
Competition lawArts 101 and 102 are Treaty provisions, so in substance they date to 1957. Reg 1/2003 decentralised enforcement from 1 May 2004
GDPRAdopted 2016, applicable 25 May 2018
DMAIn force 1 November 2022, applicable 2 May 2023, gatekeeper obligations from 7 March 2024
DSAIn force 16 November 2022, VLOP obligations from late August 2023, full application 17 February 2024
AI ActIn force 1 August 2024. Prohibitions and AI literacy from 2 February 2025. GPAI, governance and penalties from 2 August 2025. Then the Digital Omnibus, in force 27 July 2026, moved Annex III high-risk to 2 December 2027 and Annex I to 2 August 2028
Data Act (adjacent, and live)General application 12 September 2025; access-by-design for new connected products 12 September 2026; cloud switching charges banned from 2027
Digital Fairness Act (pending)Expected around Q4 2026 after slippage. Dark patterns, influencer marketing, addictive design, unfair personalisation. Commission reported to be split on scope

9. If you remember ten things

  1. Three regulate a thing, two regulate behaviour. AI Act = a system (product safety). DMA = a status. DSA = a role. Competition law = conduct. GDPR = an activity.
  2. **Competition law asks *did this firm behave badly*. The DMA asks *is this firm big enough to be caught*.** That is the ex post / ex ante divide in one line.
  3. The DMA needs no proof of harm — designation plus conduct is enough. That is why it is fast, and why the thresholds *are* the theory of harm.
  4. Penalty ceilings: AI Act 7 percent, competition law and DMA 10 percent (DMA 20 for repeats), DSA 6 percent, GDPR 4 percent or €20m. The AI Act is heavier than people assume.
  5. The DMA is enforced by the Commission alone. The GDPR's decentralised one-stop shop is the mistake it was designed to avoid.
  6. The AI Act creates no private damages right. The GDPR's Art 82 does. That pushes AI harms back onto administrative law and rights of defence.
  7. Meta Platforms v Bundeskartellamt (C-252/21) is the case where data protection entered competition analysis. Know the name — it is Mirza's hinge.
  8. They are cumulative, not alternatives. One set of facts, five reasonings, five enforcers. Run a scenario through all five and you have shown the cross-project skill.
  9. On a gatekeeper's self-preferencing recommender, the DMA does the work and the AI Act barely features — because the AI Act regulates by intended purpose, and commercial ranking is not a listed one.
  10. None of the five cleanly reaches a public authority's own analytical tool. 1,500 pages of digital regulation, and the state's instrument of market surveillance falls between them. That is the pitch.