REVISION 4 — The Five Laws
Competition law, the AI Act, the GDPR, the DMA and the DSA — what each one is for, who it bites, what it costs to breach, and how they overlap. Written for someone who has not studied EU law, with one fact pattern run through all five.
Listen
0. The map — five laws, five different jobs
The one distinction to get right: before or after
| Law | What it is for, in one line | Who it bites | Maximum penalty |
|---|---|---|---|
| Competition law (Arts 101 & 102 TFEU) | Stops firms agreeing not to compete, and stops dominant firms abusing their position | **Any *undertaking*** — any economic actor, whatever its legal form | 10% of worldwide annual turnover |
| DMA (Digital Markets Act) | Standing rules for a named handful of very large platforms, applying without any investigation | **Designated *gatekeepers*** only — a published list | 10%, rising to 20% for repeat breach, plus periodic penalties up to 5% of daily turnover |
| DSA (Digital Services Act) | How online intermediaries must handle illegal content and systemic risk | All online intermediaries, with heavier duties as you get bigger | 6% of worldwide annual turnover |
| GDPR (Reg (EU) 2016/679) | Protects individuals when their personal data is processed | Any controller or processor of personal data | 4% of worldwide turnover or €20 million, whichever is higher |
| AI Act | Product-safety-style rules for AI systems, scaled to risk | Providers and deployers of AI systems | 7% for the banned practices, then 3%, then 1% |
1. Competition law — the two articles
| Concept | Plain meaning | Why it matters for measurement |
|---|---|---|
| Undertaking | **The actor competition law acts on: a *single economic unit*, not a legal person.** A parent and its subsidiaries are normally one undertaking | This is the one to remember. It is why a parent can be liable for a subsidiary's conduct, why fines are computed on group turnover — and why deciding whether two company names are the same entity is doing legal work |
| Agreement | A meeting of minds. Need not be written or enforceable | — |
| Concerted practice | Coordination short of an agreement — a form of cooperation that replaces independent competitive behaviour without a formal deal | This is the category computational evidence usually speaks to, and it is harder to prove |
| Object or effect | A restriction can be unlawful by its *object* — some are so obviously harmful that no effects analysis is required — or by its *effect* | Object infringements need no economic proof of harm. Cartels are the standard example |
| Dominance (Art 102) | Not just a big market share. Market power sufficient to behave independently of competitors and customers, judged on entry barriers, countervailing buyer power and more | A legal conclusion, not a data field — which is why market share is only a proxy |
| Abuse | Dominance is lawful. Abusing it is not. Examples: predatory pricing, exclusivity, refusal to supply, tying, self-preferencing | Abuse requires dominance first. No dominance, no abuse — however aggressive the conduct |
| Leniency | The first cartel member to confess and cooperate can get full immunity from the fine | It is the single largest source of cartel cases — and therefore a major reason detected cartels are a biased sample |
2. The DMA — standing rules for a named list
How a firm becomes a gatekeeper
3. The DSA — duties that scale with size
The four tiers
4. The GDPR — the one most likely to come up
| Concept | Plain meaning |
|---|---|
| Personal data | Any information relating to an identifiable living person. Much broader than most people assume — an IP address or a device identifier can qualify |
| Controller / processor | The controller decides *why and how* data is processed; the processor acts on the controller's instructions. Different obligations attach to each |
| Lawful basis (Art 6) | You need one of six before you process at all: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Consent is only one of six and is often the weakest choice |
| Special categories (Art 9) | Health, race or ethnicity, political opinions, religion, trade union membership, sex life, biometrics for identification. Processing is prohibited unless a narrow exception applies |
| The principles (Art 5) | Lawfulness and fairness, purpose limitation (do not reuse data for an incompatible new purpose), data minimisation, accuracy, storage limitation, security, and accountability |
| Data subject rights | Access, rectification, erasure, restriction, portability, objection. And Article 22 on automated decisions |
| Article 22 | The right not to be subject to a solely automated decision with legal or similarly significant effects, subject to exceptions — with safeguards including a right to human intervention and to contest the decision |
| Article 25 | Data protection by design and by default. Build it in; do not bolt it on |
| Article 35 | Data protection impact assessment — mandatory before high-risk processing |
| Article 82 | A right to compensation for damage. The private enforcement route the AI Act lacks |
Article 22, as a decision tree — the provision most relevant to enforcement tools
5. The AI Act — risk tiers, and the gap that matters to you
The risk pyramid
6. One fact pattern through all five — the best way to prove you understand them
| Law | Does it bite? | Why |
|---|---|---|
| Competition law | Possibly — and only after investigation | Self-preferencing by a dominant firm can be an abuse under Article 102. But you must first define the market and establish dominance, which takes years. No dominance, no abuse |
| DMA | Yes, immediately, if designated | 60 million users is over the 45-million threshold. Self-preferencing in ranking is prohibited outright under Article 6(5) — no market definition, no dominance finding, no proof of harm required. This is the difference the DMA was built to make |
| DSA | Yes — it is a VLOP | Over 45 million users, so systemic risk assessment, independent audit, Article 40 researcher access. And the automatic suspensions require a statement of reasons and an internal complaints route |
| GDPR | Yes | Profiling identifiable individuals needs a lawful basis, and automatic suspension is a solely automated decision with significant effects — Article 22 territory, requiring human intervention and a right to contest. Plus Article 35: this is high-risk processing, so a DPIA is mandatory |
| AI Act | Depends on classification | The honest answer, and the interesting one. A fraud-prediction system affecting access to a service may sit near the Annex III categories — but ranking products is not obviously a listed high-risk use at all. So the same system may be high-risk in one function and unregulated in another |
7. If you remember ten things
- Ex ante against ex post is the master distinction. The DMA, DSA, GDPR and AI Act set rules in advance; competition law investigates afterwards. The DMA exists because ex post was too slow for digital markets.
- **The *undertaking* is the actor in competition law — a single economic unit, not a legal person. It is why parents are liable for subsidiaries, why fines use group turnover, and why entity resolution is legal work**.
- Penalty ceilings: competition 10%, DMA 10% rising to 20%, DSA 6%, GDPR 4% or €20m, AI Act 7% / 3% / 1%. And the asymmetry: the GDPR has a private damages route in Article 82; the AI Act has no equivalent.
- **GDPR = General Data *Protection* Regulation, Regulation (EU) 2016/679, applicable 25 May 2018. Your IoT paper gets this wrong — do not repeat it.**
- **Article 22 turns on the word *solely*, and a human who rubber-stamps is not a human decision.** Same substantive question as the AI Act's human oversight duty.
- DMA designation is near-mechanical: around €7.5bn EU turnover, 45 million monthly end users, 10,000 business users. Live fact: 16 July 2026, Google fined about €460m for self-preferencing plus about €430m on anti-steering — €890m, the largest DMA fine so far.
- DSA is tiered, and the 45-million threshold makes you a VLOP. Article 40 gives vetted researchers data access — the most relevant provision in all five laws to your own position.
- AI Act: four risk tiers, and most AI is in the bottom one with no obligations. The gap worth naming: Article 27's rights assessment is tied to the Annex III list, so a tool that flags firms rather than people may escape the high-risk regime entirely.
- ***Wood Pulp* (C-89/85, 31 March 1993): parallel conduct proves concertation only where no other explanation is plausible. This is the ceiling on all computational evidence and the best thing you can say about screens.**
- ***Meta Platforms v Bundeskartellamt* (C-252/21) is where data protection entered competition analysis** — the case to name if asked how these regimes interact.