The Five Instruments, Side by Side
Competition law, DMA, DSA, GDPR and AI Act in one place — who they bind, what triggers them, who enforces, what the fines are, and where they overlap, collide and leave gaps. The chapter to revise from.
Listen
1. What each one actually is, in one line
Start here. If you can say these five sentences cleanly you can hold the whole framework in your head, and most confusion comes from mixing up what each instrument is *for*.
| Instrument | In one line | The question it asks |
|---|---|---|
| Competition law — Arts 101 & 102 TFEU, Reg 1/2003, EU Merger Regulation | Stops firms from agreeing not to compete, and stops dominant firms from abusing their position | *Did this firm behave badly?* Backward-looking, conduct-based, proven case by case |
| DMA — Reg 2022/1925 | Imposes a fixed list of do's and don'ts on a handful of very large platforms, by designation rather than by proof of harm | *Is this firm big enough to be caught?* Forward-looking, status-based, triggered by counting |
| DSA — Reg 2022/2065 | Makes online intermediaries handle illegal content properly, be transparent about moderation and advertising, and assess their own systemic risks | *Is this platform managing what happens on it responsibly?* Process obligations rather than outcome liability |
| GDPR — Reg 2016/679 | Governs any handling of information about an identifiable person, whoever does it | *Is this processing of someone's data lawful, fair and transparent?* Rights-based, and it attaches to the individual |
| AI Act — Reg 2024/1689 | A product-safety law for AI systems: the riskier the intended use, the heavier the obligations before you may put it on the market | *Is this system safe enough to be sold or deployed for this purpose?* Risk-tiered, and the obligations land before use rather than after harm |
2. Who they bind, and what sets them off
| Who it binds | What triggers it | Do you have to prove harm? | |
|---|---|---|---|
| Competition law | Undertakings — any entity carrying on economic activity, whatever its legal form. Includes a parent group as a single economic unit | Conduct: an agreement or concerted practice restricting competition (101), or abusive conduct by a dominant firm (102) | Usually yes — except for *by object* restrictions like price fixing and bid rigging, where no proof of actual harm is needed. That exception is why cartel enforcement is tractable |
| DMA | Designated gatekeepers providing one of ten listed core platform services. Around seven firms | Pure counting: roughly €7.5bn EU turnover in each of three years or €75bn market cap; 45 million monthly active end users and 10,000 yearly active business users in the EU; sustained over three years. Firm may rebut | No. That is the point. Obligations apply on designation and the Commission need not prove any effect |
| DSA | Intermediary services in four stacked tiers: intermediary → hosting → online platform → VLOP/VLOSE at 45 million average monthly recipients in the EU | Service type plus user numbers. Obligations accumulate upward | No for the due-diligence duties. They are process obligations — you must have a complaints system, not achieve an outcome |
| GDPR | Controllers (who decide why and how) and processors (who act on instructions). Public and private alike | Any processing of personal data relating to an identifiable living person. Extraterritorial under Art 3 where you target or monitor people in the EU | No. A breach of the principles is actionable without demonstrable damage, though damages claims need harm |
| AI Act | Providers, deployers, importers, distributors and product manufacturers. Note: *deployer* catches an agency using a bought-in system | Intended purpose, mapped to a risk tier: prohibited (Art 5), high-risk (Art 6 + Annexes I & III), limited risk (Art 50), minimal. Plus a separate track for general-purpose AI models (Arts 51–56) | No. Conformity is assessed before market placement. The obligation is to have done the work, not to avoid a bad outcome |
3. Who enforces, and what it costs
| Enforcer | Maximum penalty | Private claims? | |
|---|---|---|---|
| Competition law | Commission (DG COMP) and national competition authorities, working as a network under Reg 1/2003. Decentralised — NCAs apply Arts 101 and 102 directly | 10 percent of worldwide group turnover | Yes, and substantially — damages actions under the Damages Directive, including follow-on claims after a decision |
| DMA | The Commission alone. Centralised by design, because consistency across the internal market was the priority | 10 percent of total worldwide turnover, rising to 20 percent for a repeat of the same or similar breach within eight years. Plus periodic penalty payments up to 5 percent of average daily turnover, and structural remedies for systematic non-compliance | Developing. The regulation does not create a damages regime, but national courts are being used |
| DSA | Split. The Commission exclusively supervises VLOPs and VLOSEs on the systemic-risk obligations; national Digital Services Coordinators handle everything else, on a country-of-establishment basis | 6 percent of annual worldwide turnover, plus periodic penalties | Yes — the DSA provides for compensation routes, and national consumer law sits alongside |
| GDPR | National supervisory authorities (DPAs), with a lead-authority *one-stop shop* for cross-border cases and the EDPB resolving disagreements | €20 million or 4 percent of worldwide annual turnover, whichever is higher for the serious tier. €10m/2% for the lower tier | Yes — Art 82, including non-material damage. A major and growing route |
| AI Act | National market surveillance authorities, plus notified bodies for conformity assessment, plus the AI Office within the Commission for general-purpose models, coordinated by the AI Board | €35 million or 7 percent for breaching the Art 5 prohibitions. €15 million or 3 percent for most other obligations including high-risk. €7.5 million or 1 percent for giving authorities incorrect information. GPAI providers face up to 3 percent or €15m | Not directly. The AI Act creates no standalone damages right, which is one of the main criticisms of it |
4. Ex ante against ex post — and why that is the real dividing line
Where each one intervenes on a timeline
5. Where they overlap, collide and leave holes
| Pairing | How they interact | The live example |
|---|---|---|
| GDPR × Competition law | Long kept apart, now converging. A competition authority may take data-protection compliance into account in an abuse analysis | Meta Platforms v Bundeskartellamt (C-252/21) — the Court accepted that a national competition authority could consider GDPR compliance when assessing abuse. Learn this case name; it is the hinge between the two regimes and squarely in Mirza's field |
| GDPR × DMA | Both bear on data combination across services. The DMA imposes flat prohibitions where the GDPR requires a lawful basis and a balancing exercise | Meta's *consent or pay* model was found in breach of the DMA obligation to offer a less-data-intensive option in April 2025 — a data question decided under competition-style regulation rather than under the GDPR |
| DSA × AI Act | The DSA governs recommender systems and dark patterns as platform duties; the AI Act governs them as product characteristics. Both can apply | Art 25 DSA already prohibits interface designs distorting choice. The forthcoming Digital Fairness Act is a third layer on the same conduct — which raises the obvious question of why two existing prohibitions needed a third |
| AI Act × GDPR | The AI Act governs the system; the GDPR governs the personal data flowing through it. Neither displaces the other, and Art 22 GDPR plus Art 14 AI Act both address human involvement from different angles | This is your territory. Art 22 asks whether a decision was *solely* automated; Art 14 asks whether a reviewer can *meaningfully* oversee. Both are empirical questions dressed as legal standards, and nobody measures either |
| Competition law × DMA | The DMA explicitly does not displace Arts 101 and 102 — they run in parallel, and the same conduct can attract both | A gatekeeper can be fined under the DMA for breaching an obligation and under Art 102 for the same underlying behaviour, on different reasoning. Double jeopardy arguments here are live and unresolved |
6. One fact pattern, all five instruments
The fastest way to learn the distinctions is to run one scenario through all of them. A designated gatekeeper runs a marketplace with an AI recommender that ranks sellers, trained on user behaviour, and it ranks its own products higher.
| Instrument | Does it bite? | On what reasoning |
|---|---|---|
| Competition law — Art 102 | Possibly, and expensively | Self-preferencing by a dominant firm can be abusive, but the Commission must define the market, establish dominance, and show actual or likely harm. Years of work. The *Google Shopping* line of cases is the template |
| DMA — Art 6(5) | Yes, directly and quickly | Gatekeepers must not treat their own services more favourably in ranking. No market definition, no dominance, no proof of harm needed — just the designation and the conduct. This is exactly the provision Google was fined €460 million under on 16 July 2026 |
| DSA — Arts 27 & 25 | Yes, partially | Art 27 requires the main parameters of the recommender to be explained in the terms and conditions. If the interface nudges users toward the firm's own goods in a way that distorts choice, Art 25's dark-patterns prohibition engages. Transparency and design duties, not a ranking prohibition |
| GDPR | Yes, as to the training data | The recommender is trained on user behaviour, which is personal data. Needs a lawful basis under Art 6, must satisfy purpose limitation and data minimisation under Art 5, and if it profiles users at scale it needs a DPIA under Art 35. Says nothing about the ranking being unfair to sellers — sellers are not data subjects in that respect |
| AI Act | Probably only lightly | A recommender is not in Annex III, so not high-risk. It is not prohibited. Art 50 transparency duties are about telling a person they are dealing with AI, which is not the issue here. So the AI Act, the instrument actually about AI, has the least to say about the AI system in this scenario — because it regulates by intended purpose and commercial ranking is not a listed purpose |
7. Which instrument for which question
A rough triage
8. The dates, since they get asked
| Instrument | Key dates |
|---|---|
| Competition law | Arts 101 and 102 are Treaty provisions, so in substance they date to 1957. Reg 1/2003 decentralised enforcement from 1 May 2004 |
| GDPR | Adopted 2016, applicable 25 May 2018 |
| DMA | In force 1 November 2022, applicable 2 May 2023, gatekeeper obligations from 7 March 2024 |
| DSA | In force 16 November 2022, VLOP obligations from late August 2023, full application 17 February 2024 |
| AI Act | In force 1 August 2024. Prohibitions and AI literacy from 2 February 2025. GPAI, governance and penalties from 2 August 2025. Then the Digital Omnibus, in force 27 July 2026, moved Annex III high-risk to 2 December 2027 and Annex I to 2 August 2028 |
| Data Act (adjacent, and live) | General application 12 September 2025; access-by-design for new connected products 12 September 2026; cloud switching charges banned from 2027 |
| Digital Fairness Act (pending) | Expected around Q4 2026 after slippage. Dark patterns, influencer marketing, addictive design, unfair personalisation. Commission reported to be split on scope |
9. If you remember ten things
- Three regulate a thing, two regulate behaviour. AI Act = a system (product safety). DMA = a status. DSA = a role. Competition law = conduct. GDPR = an activity.
- **Competition law asks *did this firm behave badly*. The DMA asks *is this firm big enough to be caught*.** That is the ex post / ex ante divide in one line.
- The DMA needs no proof of harm — designation plus conduct is enough. That is why it is fast, and why the thresholds *are* the theory of harm.
- Penalty ceilings: AI Act 7 percent, competition law and DMA 10 percent (DMA 20 for repeats), DSA 6 percent, GDPR 4 percent or €20m. The AI Act is heavier than people assume.
- The DMA is enforced by the Commission alone. The GDPR's decentralised one-stop shop is the mistake it was designed to avoid.
- The AI Act creates no private damages right. The GDPR's Art 82 does. That pushes AI harms back onto administrative law and rights of defence.
- Meta Platforms v Bundeskartellamt (C-252/21) is the case where data protection entered competition analysis. Know the name — it is Mirza's hinge.
- They are cumulative, not alternatives. One set of facts, five reasonings, five enforcers. Run a scenario through all five and you have shown the cross-project skill.
- On a gatekeeper's self-preferencing recommender, the DMA does the work and the AI Act barely features — because the AI Act regulates by intended purpose, and commercial ranking is not a listed one.
- None of the five cleanly reaches a public authority's own analytical tool. 1,500 pages of digital regulation, and the state's instrument of market surveillance falls between them. That is the pitch.