The AI Act is not the only European regulation impacting your digital business. DMA, DSA and NIS2 regulate how you sell in marketplaces, how you manage your content and how you protect your infrastructure. This is the practical guide to the complete regulatory landscape
If you've followed our articles on the AI Actyou already know that European artificial intelligence regulation uses a risk-based approach. But the AI Act doesn't operate in isolation. It's part of a broader normative ecosystem that regulates different facets of your digital business: how you compete in marketplaces, how you manage content on your platforms and how you protect your systems against cyberattacks.
Three European regulations that are probably not on your radar but are already in force and generating million-euro fines: the DMA (Digital Markets Act) DSA (Digital Services Act) and NIS2 (Directiva de Seguridad de Redes e Información). Juntas con el RGPD y el AI Act, configuran el marco completo que define las reglas del juego digital en Europa.
En este artículo te explicamos qué regula cada una, cómo te afectan como pyme o ecommerce, qué sanciones se están aplicando y qué acciones concretas debes tomar.
The European regulatory ecosystem: overview
The European digital regulatory framework is structured in complementary layers, each regulating a different aspect:
- GDPR: Personal data protection. The backbone of all digital regulation.
- DMA: Fair competition in digital markets. Regulates large platforms (gatekeepers).
- DSA: Responsibility for digital content. Algorithmic transparency and moderation.
- NIS2: Ciberseguridad obligatoria. Resiliencia de redes y notificación de incidentes.
- AI Act: Managing AI risks. Technical documentation, human supervision, ethics.
These regulations are not independent: they overlap and reinforce each other. An AI system that operates in a marketplace (AI Act + DMA), processes personal data (GDPR), recommends content (DSA) and runs on critical infrastructure (NIS2) may be subject to all five simultaneously.
Key fact: The European Commission proposed in 2025 a Digital Simplification Package to align and reduce overlaps between GDPR, AI Act, Data Act, NIS2 and ePrivacy. But while it's being approved, each regulation operates independently with its own timelines and penalties.
DMA: fair competition in digital markets
The Digital Markets Act (DMA) regulates large digital platforms designated as gatekeepers: companies that control key access points to the digital market. There are currently 7 designated gatekeepers: Meta, Alphabet (Google), Amazon, Apple, Microsoft, ByteDance (TikTok) and Booking, with 23 main platform services under regulation.
How does it affect you as an SME?
If you sell on Amazon, use Google Shopping, advertise on Meta Ads or distribute your app on the App Store, the DMA affects you indirectly but with real impact:
- Prohibition of self-preferencing: Gatekeepers cannot favor their own products in search results or recommendations. Google cannot rank Google Shopping above your store in organic results. In September 2025, Google was fined €2.95 billion for this practice.
- Mandatory interoperability: Platforms must allow cross-service communication between messaging services, as well as hardware and software interoperability.
- Data portability: You have the right to access and export your business data from the platform in real time, continuously and free of charge.
- Freedom of communication: Los desarrolladores y vendedores pueden comunicar directamente con sus clientes fuera de la plataforma. Apple fue sancionada con 500 millones de euros en abril de 2025 por impedir que los desarrolladores informaran a sus usuarios sobre opciones de pago alternativas.
DMA sanctions: Up to 10% of global annual turnover. In cases of repeated infringement, up to 20%. The sanctions already imposed show that these are not merely theoretical.
Action for your SME: Review your terms with each gatekeeper platform where you operate. Exercise your right to data portability. If you detect self-preferencing practices that harm your business, you can file a complaint with the European Commission.
DSA: Digital Content Responsibility
The Digital Services Act (DSA) regulates the Responsibility of digital services for the content they host and recommendIt applies to online platforms, marketplaces, social media platforms, and search engines.
How does it affect you as an eCommerce?
The DSA has direct implications for any business that operates as a platform or uses recommendation algorithms:
- Algorithmic transparency: If your platform uses algorithms to recommend products, rank content, or prioritize results, you must explain how they work. Users have the right to a non-personalized alternative, such as a chronological feed.
- Targeted advertising: Advertising must be clearly labelled. Targeted advertising based on sensitive data, such as religion, sexual orientation, or health, is prohibited, and targeted advertising aimed at minors is completely banned.
- Illegal content management: Platforms must actively manage illegal or harmful content, implement accessible reporting mechanisms, and respond within defined timeframes.
- Access to data for researchers: Very large online platforms (VLOPs, with more than 45 million users in the EU) must provide access to their data to accredited researchers in order to detect systemic risks.
DSA Sanctions: Up to 6% of global annual turnover. In December 2025, X (formerly Twitter) was fined €120 million for deceptive design in its verification system, an incomplete advertising repository, and barriers to researcher access.
Action for your ecommerce: If you use recommendation or personalization algorithms, document how they work and offer a non-personalized option. If you manage a marketplace, implement content reporting mechanisms and verify the identity of your sellers.
NIS2: Mandatory Cybersecurity
The NIS2 Directive reinforces the cyber resilience In essential and important sectors of the European economy. Unlike the DMA and the DSA, which are directly applicable regulations, NIS2 is a directive that each Member State must transpose into its national legislation.
Transposition status
The transposition deadline was October 2024. As of January 2026, only 20 of the 27 Member States had completed the process:
- Italy: Transposed by Legislative Decree 138/2024 in October 2024. Already operational.
- Spain It has not completed transposition. The European Commission issued a reasoned opinion in May 2025 for non-compliance.
Who is obligated?
Il NIS2 classifica le entità in essential (energy, transport, banking, healthcare, water, digital infrastructure) importants (postal services, waste management, food, manufacturing, digital providers). If your company operates in any of these sectors or provides critical services to them, you are affected.
Main obligations
- Staggered incident notification: Early warning within 24 hours, full notification within 72 hours, final report within 30 days.
- Risk management: All-hazards approach with proportionate technical and organizational measures.
- Multi-factor authentication (MFA): Mandatory for critical access.
- Encryption: Data at rest and in transit.
- Intrusion detection: Active monitoring and alert systems.
- Periodic risk assessments: It is not a one-off exercise, but a continuous one.
- Tested backups: It is not enough to have them; you must prove that they work.
NIS2 Sanctions: Para entidades esenciales, hasta 10 millones de euros o el 2% de la facturación global. Para entidades importantes, hasta 7 millones o el 1,4%.
Conexión con la IA: Si tu sistema de IA opera sobre infraestructura crítica o en un sector cubierto por NIS2, las obligaciones de ciberseguridad de NIS2 se suman a las del AI Act. El killswitch, el rollback y la monitorización continua que exige el modelo de gobernanza de IA que usamos en Impulsa3 encajan directamente con los requisitos de NIS2.
Cómo se relacionan entre sí: el mapa completo
Entender cada normativa por separado es necesario, pero la realidad es que se aplican simultáneamente. Un caso típico de ecommerce:
Imagina que tienes una tienda online que vende en Amazon (DMA te da derechos de portabilidad y anti-discriminación), usa un chatbot IA para atención al cliente (AI Act: riesgo limitado, transparencia; RGPD: DPIA si procesa datos personales), muestra recomendaciones personalizadas (DSA: transparencia algorítmica) y opera sobre una infraestructura cloud en un sector cubierto (NIS2: ciberseguridad).
Las cinco normativas aplican al mismo negocio. Pero la buena noticia es que comparten principios comunes:
- Transparencia: Informar a usuarios y reguladores de cómo funcionan tus sistemas (RGPD, DSA, AI Act).
- Proporcionalidad: Obligaciones ajustadas al riesgo real (AI Act, NIS2, RGPD).
- Responsabilidad demostrable: No basta con cumplir; debes poder demostrarlo con evidencias (todas).
- Derechos del ciudadano: Protección del consumidor, privacidad, no discriminación (RGPD, DMA, DSA).
Si ya cumples bien con el RGPD y estás trabajando en el AI Act, tienes una base sólida para abordar DMA, DSA y NIS2 sin empezar de cero.
Tensiones y solapamientos: lo que nadie te cuenta
Aunque las normativas comparten principios, también generan tensiones prácticas que debes conocer:
Interoperabilidad (DMA) vs. protección de datos (RGPD)
El DMA exige que las plataformas abran sus servicios de mensajería para comunicación cruzada. Pero compartir datos entre plataformas puede entrar en conflicto con la minimización de datos del RGPD. ¿Qué prevalece? La práctica está demostrando que se necesitan acuerdos técnicos específicos (como protocolos de cifrado end-to-end) para cumplir ambas simultáneamente.
Explicabilidad (AI Act) vs. minimización (RGPD)
El AI Act exige documentación técnica detallada y trazabilidad de las decisiones del sistema. El RGPD exige minimización de datos. Guardar logs detallados para cumplir con la trazabilidad puede implicar retener más datos personales de los estrictamente necesarios. La solución: pseudoanonimización de logs, retención limitada y acceso restringido.
Transparencia algorítmica (DSA) vs. secreto comercial
El DSA exige explicar cómo funcionan los algoritmos de recomendación. Pero los algoritmos propietarios son activos de propiedad intelectual. El equilibrio: explicar la lógica general y los criterios principales sin revelar los parámetros específicos del modelo.
Practical tip: Cuando detectes una tensión entre normativas, documenta tu decisión y la justificación. Las autoridades reguladoras valoran que hayas identificado el conflicto y tomado una decisión razonada, incluso si no es perfecta.
Sanciones reales en 2025: ya no es teoría
El enforcement europeo se ha acelerado drásticamente. Estas son las sanciones más relevantes aplicadas en 2025:
- Apple: 500M€ (DMA, abril 2025). Por impedir que los desarrolladores de apps informaran a sus usuarios sobre opciones de pago alternativas fuera de la App Store.
- Google: 2.950M€ (DMA, septiembre 2025). Por favoritismo ilegal hacia sus propios servicios de publicidad digital en los resultados de búsqueda.
- Meta: 200M€ (DMA, abril 2025). Por su modelo de «pagar o consentir» que no cumplía con las condiciones de transparencia del DMA.
- X (Twitter): 120M€ (DSA, diciembre 2025). Por diseño engañoso en su sistema de verificación, repositorio de publicidad incompleto y barreras al acceso de datos para investigadores.
Estas sanciones afectan a grandes plataformas, no directamente a pymes. Pero el efecto en cascada es real: las plataformas están cambiando sus términos y condiciones, lo que afecta a cómo operas tú como vendedor o anunciante en ellas.
Tu plan de acción: qué hacer desde hoy
- Haz un mapa de tus normativas. Lista todos los sistemas digitales de tu empresa y marca qué normativas aplican a cada uno: RGPD, AI Act, DMA, DSA, NIS2. Usar una ficha por sistema te dará claridad.
- Prioriza por riesgo sancionador. El RGPD y el DMA ya están generando sanciones millonarias. El DSA también. NIS2 depende de la transposición en tu país. Empieza por donde el riesgo es inmediato.
- Revisa tus contratos con plataformas. Si vendes en Amazon, Google o Apple, revisa tus derechos bajo el DMA: portabilidad, anti-discriminación, comunicación directa con clientes.
- Audita tus algoritmos de recomendación. Si tu web o app personaliza contenido, documenta cómo funciona y ofrece una alternativa no personalizada (DSA).
- Revisa tu ciberseguridad. MFA, cifrado, detección de intrusiones, plan de incidentes con plazos NIS2 (24h/72h/30d). Aunque tu país no haya transpuesto aún, prepararte ahora es más barato que reaccionar después.
- Integra todo en un modelo de gobernanza. No gestiones cada normativa como un silo. Un comité de gobernanza que cubra datos, IA, seguridad y cumplimiento normativo es más eficiente que cuatro procesos independientes.
No gestiones cada normativa como un silo. Intégralas en un modelo de gobernanza único.
Si necesitas ayuda para mapear qué normativas aplican a tu negocio, priorizar acciones o integrar el cumplimiento en un modelo de gobernanza operativo, en Impulsa3 te acompañamos con un enfoque práctico y transversal.