The AI Act is not the only European regulation that affects your digital business. The DMA, DSA and NIS2 regulate how you sell on marketplaces, how you manage your content and how you protect your infrastructure. This is a practical guide to the complete regulatory landscape
If you have followed our articles on the AI Act, you already know that European artificial intelligence regulation uses a risk-based approach. But the AI Act does not operate in isolation. It is part of a broader regulatory ecosystem that regulates different aspects of your digital business: how you compete on marketplaces, how you manage content on your platforms and how you protect your systems against cyberattacks.
Three European regulations that are probably not on your radar but are already in force and generating multimillion-euro penalties: the DMA (Digital Markets Act), the DSA (Digital Services Act) and NIS2 (the Network and Information Security Directive). Together with the GDPR and the AI Act, they make up the complete framework that defines the rules of the digital game in Europe.
In this article, we explain what each one regulates, how it affects you as an SME or ecommerce business, which penalties are being applied and what specific actions you should take.
The European regulatory ecosystem: an overview
The European digital regulatory framework is structured in complementary layers, each regulating a different aspect:
- GDPR: Protection of personal data. The backbone of all digital regulation.
- DMA: Fair competition in digital markets. Regulates large platforms (gatekeepers).
- DSA: Responsibility for digital content. Algorithmic transparency and moderation.
- NIS2: Mandatory cybersecurity. Network resilience and incident notification.
- AI Act: AI risk management. Technical documentation, human oversight and ethics.
These regulations are not independent: they overlap and reinforce one another. An AI system that operates on a marketplace (AI Act + DMA), processes personal data (GDPR), recommends content (DSA) and runs on critical infrastructure (NIS2) may be subject to all five simultaneously.
Key fact: In 2025, the European Commission proposed a Digital Simplification Package to align and reduce overlaps between the GDPR, AI Act, Data Act, NIS2 and ePrivacy. But until it is approved, each regulation operates independently, with its own deadlines and penalties.
DMA: fair competition in digital markets
The Digital Markets Act (DMA) regulates large digital platforms designated as gatekeepers: companies that control key access points to the digital market. There are currently seven designated gatekeepers: Meta, Alphabet (Google), Amazon, Apple, Microsoft, ByteDance (TikTok) and Booking, with 23 core platform services subject to regulation.
How does it affect you as an SME?
If you sell on Amazon, use Google Shopping, advertise on Meta Ads or distribute your app through the App Store, the DMA affects you indirectly but with a real impact:
- Ban on self-preferencing: Gatekeepers may not favour their own products in search results or recommendations. Google may not rank Google Shopping above your shop in organic results. In September 2025, Google was fined €2.95 billion for this practice.
- Mandatory interoperability: Platforms must allow cross-service communication between messaging services and interoperability between hardware and software.
- Data portability: You have the right to access and export your commercial data from the platform in real time, continuously and free of charge.
- Freedom of communication: Developers and sellers can communicate directly with their customers outside the platform. Apple was fined €500 million in April 2025 for preventing developers from informing their users about alternative payment options.
DMA penalties: Up to 10% of annual global turnover. In the event of repeat offences, up to 20%. The penalties already imposed show that they are not theoretical.
Action for your SME: Review your terms with each gatekeeper platform where you operate. Exercise your right to data portability. If you detect self-preferencing practices that harm you, you can file a complaint with the European Commission.
DSA: responsibility for digital content
The Digital Services Act (DSA) regulates the responsibility of digital services for the content they host and recommend. It affects online platforms, marketplaces, social networks and search engines.
How does it affect you as an ecommerce business?
The DSA has direct implications for any business that operates as a platform or uses recommendation algorithms:
- Algorithmic transparency: If your platform uses algorithms to recommend products, rank content or prioritise results, you must explain how they work. Users have the right to a non-personalised alternative (a chronological feed).
- Targeted advertising: Advertising must be clearly labelled. Targeting advertising based on sensitive data (religion, sexual orientation or health) is prohibited, and targeted advertising to minors is completely banned.
- Illegal-content management: Platforms must actively manage illegal or harmful content, implement accessible reporting mechanisms and respond within defined timeframes.
- Data access for researchers: Very large platforms (VLOPs, with more than 45 million users in the EU) must give accredited researchers access to their data so they can detect systemic risks.
DSA penalties: Up to 6% of annual global turnover. In December 2025, X (formerly Twitter) was fined €120 million for deceptive design in its verification system, an incomplete advertising repository and barriers to researcher access.
Action for your ecommerce business: If you use recommendation or personalisation algorithms, document how they work and offer a non-personalised option. If you manage a marketplace, implement content-reporting mechanisms and verify the identity of your sellers.
NIS2: mandatory cybersecurity
The NIS2 Directive strengthens cyber resilience in essential and important sectors of the European economy. Unlike the DMA and DSA (which are directly applicable regulations), NIS2 is a directive that each Member State must transpose into national law.
Transposition status
The transposition deadline was October 2024. As of January 2026, only 20 of the 27 Member States have completed the process:
- Italy: Transposed through Legislative Decree 138/2024 (October 2024). Already operational.
- Spain: Has not completed transposition. The European Commission issued a reasoned opinion in May 2025 for non-compliance.
Who is required to comply?
NIS2 classifies entities as essential (energy, transport, banking, healthcare, water and digital infrastructure) and important (postal services, waste management, food, manufacturing and digital providers). If your company operates in one of these sectors or provides them with critical services, you are affected.
Key obligations
- Phased incident notification: Early warning within 24 hours, full notification within 72 hours and final report within 30 days.
- Risk management: An all-hazards approach with proportionate technical and organisational measures.
- Multi-factor authentication (MFA): Mandatory for critical access.
- Encryption: Data at rest and in transit.
- Intrusion detection: Active monitoring and alerting systems.
- Regular risk assessments: This is not a one-off exercise, but an ongoing process.
- Tested backups: It is not enough to have them; you must demonstrate that they work.
NIS2 penalties: For essential entities, up to €10 million or 2% of global turnover. For important entities, up to €7 million or 1.4%.
Connection with AI: If your AI system operates on critical infrastructure or in a sector covered by NIS2, NIS2 cybersecurity obligations are added to those of the AI Act. The kill switch, rollback and continuous monitoring required by the AI governance model we use at Impulsa3 fit directly with NIS2 requirements.
How they relate to one another: the complete map
Understanding each regulation separately is necessary, but the reality is that they apply simultaneously. A typical ecommerce case:
Imagine that you have an online shop selling on Amazon (the DMA gives you portability and anti-discrimination rights), use an AI chatbot for customer service (AI Act: limited risk and transparency; GDPR: a DPIA if it processes personal data), display personalised recommendations (DSA: algorithmic transparency) and operate on cloud infrastructure in a covered sector (NIS2: cybersecurity).
All five regulations apply to the same business. But the good news is that they share common principles:
- Transparency: Inform users and regulators how your systems work (GDPR, DSA and AI Act).
- Proportionality: Obligations adjusted to the actual risk (AI Act, NIS2 and GDPR).
- Demonstrable accountability: It is not enough to comply; you must be able to demonstrate it with evidence (all of them).
- Citizens’ rights: Consumer protection, privacy and non-discrimination (GDPR, DMA and DSA).
If you already comply well with the GDPR and are working on the AI Act, you have a solid foundation for addressing DMA, DSA and NIS2 without starting from scratch.
Tensions and overlaps: what nobody tells you
Although the regulations share principles, they also create practical tensions that you need to understand:
Interoperability (DMA) versus data protection (GDPR)
The DMA requires platforms to open their messaging services to cross-platform communication. But sharing data between platforms may conflict with the GDPR’s data-minimisation principle. Which prevails? Practice is showing that specific technical agreements (such as end-to-end encryption protocols) are needed to comply with both simultaneously.
Explainability (AI Act) versus minimisation (GDPR)
The AI Act requires detailed technical documentation and traceability of system decisions. The GDPR requires data minimisation. Keeping detailed logs to meet traceability requirements may mean retaining more personal data than is strictly necessary. The solution: pseudonymise logs, limit retention and restrict access.
Algorithmic transparency (DSA) versus trade secrets
The DSA requires an explanation of how recommendation algorithms work. But proprietary algorithms are intellectual-property assets. The balance: explain the general logic and main criteria without revealing the model’s specific parameters.
Practical advice: When you identify a tension between regulations, document your decision and its reasoning. Regulators value the fact that you identified the conflict and made a reasoned decision, even if it is not perfect.
Real penalties in 2025: it is no longer theory
European enforcement has accelerated dramatically. These are the most relevant penalties imposed in 2025:
- Apple: €500M (DMA, April 2025). For preventing app developers from informing their users about alternative payment options outside the App Store.
- Google: €2.95B (DMA, September 2025). For illegally favouring its own digital advertising services in search results.
- Meta: €200M (DMA, April 2025). For its “pay or consent” model, which did not comply with the DMA’s transparency conditions.
- X (Twitter): €120M (DSA, December 2025). For deceptive design in its verification system, an incomplete advertising repository and barriers to researcher access to data.
These penalties affect large platforms, not SMEs directly. But the knock-on effect is real: platforms are changing their terms and conditions, which affects how you operate as a seller or advertiser on them.
Your action plan: what to do from today
- Map your regulations. List every digital system in your company and mark which regulations apply to each one: GDPR, AI Act, DMA, DSA and NIS2. Using one factsheet per system will give you clarity.
- Prioritise by penalty risk. The GDPR and DMA are already generating multimillion-euro penalties. The DSA is too. NIS2 depends on transposition in your country. Start where the risk is immediate.
- Review your platform contracts. If you sell on Amazon, Google or Apple, review your rights under the DMA: portability, non-discrimination and direct communication with customers.
- Audit your recommendation algorithms. If your website or app personalises content, document how it works and offer a non-personalised alternative (DSA).
- Review your cybersecurity. MFA, encryption, intrusion detection and an incident plan with NIS2 deadlines (24h/72h/30d). Even if your country has not yet transposed it, preparing now is cheaper than reacting later.
- Integrate everything into a governance model. Do not manage each regulation in a silo. A governance committee covering data, AI, security and regulatory compliance is more efficient than four independent processes.
Do not manage each regulation in a silo. Integrate them into a single governance model.
If you need help mapping which regulations apply to your business, prioritising actions or integrating compliance into an operational governance model, Impulsa3 can support you with a practical, cross-functional approach.