Skip to content
VibeFormer
48 min

REVISION 4 — The Five Laws

Competition law, the AI Act, the GDPR, the DMA and the DSA — what each one is for, who it bites, what it costs to breach, and how they overlap. Written for someone who has not studied EU law, with one fact pattern run through all five.

Listen

0. The map — five laws, five different jobs

The one distinction to get right: before or after

This single distinction explains the architecture of EU digital regulation. Competition law asks a question and takes years to answer it. The DMA asserts an answer in advance for a named list of firms. Everything else follows from that choice, including the criticism that ex ante rules cannot adapt.
LawWhat it is for, in one lineWho it bitesMaximum penalty
Competition law (Arts 101 & 102 TFEU)Stops firms agreeing not to compete, and stops dominant firms abusing their position**Any *undertaking*** — any economic actor, whatever its legal form10% of worldwide annual turnover
DMA (Digital Markets Act)Standing rules for a named handful of very large platforms, applying without any investigation**Designated *gatekeepers*** only — a published list10%, rising to 20% for repeat breach, plus periodic penalties up to 5% of daily turnover
DSA (Digital Services Act)How online intermediaries must handle illegal content and systemic riskAll online intermediaries, with heavier duties as you get bigger6% of worldwide annual turnover
GDPR (Reg (EU) 2016/679)Protects individuals when their personal data is processedAny controller or processor of personal data4% of worldwide turnover or €20 million, whichever is higher
AI ActProduct-safety-style rules for AI systems, scaled to riskProviders and deployers of AI systems7% for the banned practices, then 3%, then 1%

1. Competition law — the two articles

ConceptPlain meaningWhy it matters for measurement
Undertaking**The actor competition law acts on: a *single economic unit*, not a legal person.** A parent and its subsidiaries are normally one undertakingThis is the one to remember. It is why a parent can be liable for a subsidiary's conduct, why fines are computed on group turnover — and why deciding whether two company names are the same entity is doing legal work
AgreementA meeting of minds. Need not be written or enforceable—
Concerted practiceCoordination short of an agreement — a form of cooperation that replaces independent competitive behaviour without a formal dealThis is the category computational evidence usually speaks to, and it is harder to prove
Object or effectA restriction can be unlawful by its *object* — some are so obviously harmful that no effects analysis is required — or by its *effect*Object infringements need no economic proof of harm. Cartels are the standard example
Dominance (Art 102)Not just a big market share. Market power sufficient to behave independently of competitors and customers, judged on entry barriers, countervailing buyer power and moreA legal conclusion, not a data field — which is why market share is only a proxy
AbuseDominance is lawful. Abusing it is not. Examples: predatory pricing, exclusivity, refusal to supply, tying, self-preferencingAbuse requires dominance first. No dominance, no abuse — however aggressive the conduct
LeniencyThe first cartel member to confess and cooperate can get full immunity from the fineIt is the single largest source of cartel cases — and therefore a major reason detected cartels are a biased sample

2. The DMA — standing rules for a named list

How a firm becomes a gatekeeper

Designation is close to mechanical, and obligations follow automatically. That is the whole point of the DMA: it removes the years of market definition and effects analysis that competition law requires, by asserting in advance which conduct is prohibited for which firms.

3. The DSA — duties that scale with size

The four tiers

The DSA is deliberately asymmetric: a blog with comments carries almost no burden, while a platform reaching a tenth of the EU population must assess and mitigate systemic risks and submit to independent audit. The 45-million threshold is the same number the DMA uses, which is not a coincidence.

4. The GDPR — the one most likely to come up

ConceptPlain meaning
Personal dataAny information relating to an identifiable living person. Much broader than most people assume — an IP address or a device identifier can qualify
Controller / processorThe controller decides *why and how* data is processed; the processor acts on the controller's instructions. Different obligations attach to each
Lawful basis (Art 6)You need one of six before you process at all: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Consent is only one of six and is often the weakest choice
Special categories (Art 9)Health, race or ethnicity, political opinions, religion, trade union membership, sex life, biometrics for identification. Processing is prohibited unless a narrow exception applies
The principles (Art 5)Lawfulness and fairness, purpose limitation (do not reuse data for an incompatible new purpose), data minimisation, accuracy, storage limitation, security, and accountability
Data subject rightsAccess, rectification, erasure, restriction, portability, objection. And Article 22 on automated decisions
Article 22The right not to be subject to a solely automated decision with legal or similarly significant effects, subject to exceptions — with safeguards including a right to human intervention and to contest the decision
Article 25Data protection by design and by default. Build it in; do not bolt it on
Article 35Data protection impact assessment — mandatory before high-risk processing
Article 82A right to compensation for damage. The private enforcement route the AI Act lacks

Article 22, as a decision tree — the provision most relevant to enforcement tools

The hinge is the word solely, and it turns on whether the human reviewer has real capacity to decide otherwise. This is the same substantive question the AI Act asks about human oversight, and it is where most compliance claims are weakest in practice.

5. The AI Act — risk tiers, and the gap that matters to you

The risk pyramid

The Act is structured like product safety law rather than rights law: obligations attach to the system's risk category, not to the harm it causes in a particular case. Most AI falls in the bottom tier with no obligations at all, which is a fact worth knowing because public discussion implies otherwise.

6. One fact pattern through all five — the best way to prove you understand them

LawDoes it bite?Why
Competition lawPossibly — and only after investigationSelf-preferencing by a dominant firm can be an abuse under Article 102. But you must first define the market and establish dominance, which takes years. No dominance, no abuse
DMAYes, immediately, if designated60 million users is over the 45-million threshold. Self-preferencing in ranking is prohibited outright under Article 6(5) — no market definition, no dominance finding, no proof of harm required. This is the difference the DMA was built to make
DSAYes — it is a VLOPOver 45 million users, so systemic risk assessment, independent audit, Article 40 researcher access. And the automatic suspensions require a statement of reasons and an internal complaints route
GDPRYesProfiling identifiable individuals needs a lawful basis, and automatic suspension is a solely automated decision with significant effects — Article 22 territory, requiring human intervention and a right to contest. Plus Article 35: this is high-risk processing, so a DPIA is mandatory
AI ActDepends on classificationThe honest answer, and the interesting one. A fraud-prediction system affecting access to a service may sit near the Annex III categories — but ranking products is not obviously a listed high-risk use at all. So the same system may be high-risk in one function and unregulated in another

7. If you remember ten things

  1. Ex ante against ex post is the master distinction. The DMA, DSA, GDPR and AI Act set rules in advance; competition law investigates afterwards. The DMA exists because ex post was too slow for digital markets.
  2. **The *undertaking* is the actor in competition law — a single economic unit, not a legal person. It is why parents are liable for subsidiaries, why fines use group turnover, and why entity resolution is legal work**.
  3. Penalty ceilings: competition 10%, DMA 10% rising to 20%, DSA 6%, GDPR 4% or €20m, AI Act 7% / 3% / 1%. And the asymmetry: the GDPR has a private damages route in Article 82; the AI Act has no equivalent.
  4. **GDPR = General Data *Protection* Regulation, Regulation (EU) 2016/679, applicable 25 May 2018. Your IoT paper gets this wrong — do not repeat it.**
  5. **Article 22 turns on the word *solely*, and a human who rubber-stamps is not a human decision.** Same substantive question as the AI Act's human oversight duty.
  6. DMA designation is near-mechanical: around €7.5bn EU turnover, 45 million monthly end users, 10,000 business users. Live fact: 16 July 2026, Google fined about €460m for self-preferencing plus about €430m on anti-steering — €890m, the largest DMA fine so far.
  7. DSA is tiered, and the 45-million threshold makes you a VLOP. Article 40 gives vetted researchers data access — the most relevant provision in all five laws to your own position.
  8. AI Act: four risk tiers, and most AI is in the bottom one with no obligations. The gap worth naming: Article 27's rights assessment is tied to the Annex III list, so a tool that flags firms rather than people may escape the high-risk regime entirely.
  9. ***Wood Pulp* (C-89/85, 31 March 1993): parallel conduct proves concertation only where no other explanation is plausible. This is the ceiling on all computational evidence and the best thing you can say about screens.**
  10. ***Meta Platforms v Bundeskartellamt* (C-252/21) is where data protection entered competition analysis** — the case to name if asked how these regimes interact.