EU Digital Services Act or Digital Markets Act Obligations

Most European regulation applies to a category. The Digital Services Act and Digital Markets Act apply to a company by name and by number. Online platforms must publish their average monthly active recipients in the European Union twice a year, and that published figure is what determines whether they cross the threshold into the very large platform tier with its risk assessments, independent audits, ad repositories, researcher data access, and recommender system transparency. Gatekeepers under the DMA are designated by decision, and designation brings interoperability, self-preferencing, data separation, and consent obligations that reach directly into product architecture. Below both tiers sits a large population of intermediaries and marketplaces carrying the baseline obligations anyway: notice and action mechanisms, statements of reasons filed to a public database, internal complaint handling, trader traceability, transparency reporting, and a named point of contact and legal representative. A company publishing a user-number disclosure, standing up a notice mechanism, or hiring a DSA compliance officer has entered a program with fixed reporting dates and an audit at the end of it.


Why DSA and DMA Obligations Are a Buying Signal for Sales Teams

The threshold mechanism is what makes this signal unusually precise. A platform that publishes a user figure approaching the very large platform threshold has effectively announced its own future regulatory tier, in public, on a schedule, with a number it cannot revise casually because the methodology is prescribed and the figure is compared against its own prior disclosures. Vendors selling risk assessment, audit readiness, ad transparency, or content moderation tooling can see a company's tier change coming two reporting cycles ahead of the designation decision, which is a lead time no other compliance regime offers. The baseline obligations are heavier than most companies expect before they scope them. A notice and action mechanism is not a contact form: it has to accept notices with defined elements, produce a decision, deliver a statement of reasons to the affected user, and submit that statement to a public database in a structured format. That last requirement converts a moderation workflow into a data pipeline with schema obligations and volume that scales with enforcement activity. Internal complaint handling adds an appeals tier with its own timelines. Out-of-court dispute settlement adds an external party who can demand records. The company's existing tooling — usually a support desk with some custom fields — cannot produce any of it in the required form. Marketplaces carry an additional identity burden. Trader traceability requires collecting and making best efforts to verify seller identity, contact, payment, and registration details, keeping them current, and designing the interface so a consumer can see who they are actually buying from. For a marketplace that onboarded sellers with an email address and a payout account, this is a re-verification project across the entire existing seller base, not a change to the onboarding form. Advertising obligations reach the revenue stack. Platforms must expose ad transparency information, and the larger tier must maintain a searchable repository of ads with advertiser, targeting, and reach data retained for a year after last display. That requires the ad serving system to emit a durable record, which is a different design than most systems were built with, and it is typically owned by a revenue engineering team with no compliance history. The very large tier adds annual systemic risk assessment, mitigation measures, and an independent audit against those measures, plus researcher data access and recommender system transparency including a non-profiling option. The audit is the forcing function, because an auditor issuing a negative opinion creates a public document and a remediation obligation, and audit readiness work starts six to nine months before the first audit window. DMA designation is narrower but heavier, since the obligations are architectural: interoperability for messaging services, restrictions on combining personal data across services without consent, data access for business users, restrictions on self-preferencing in ranking, and portability with continuous real-time access. Each is a product program with a Commission-facing compliance report attached, and non-compliance proceedings are public, which turns each one into a dated, visible event.

How Does Avina Detect DSA and DMA Compliance Programs?

Avina, an AI-powered GTM platform, starts with the published numbers. Platform-disclosed average monthly active recipient figures are collected on each publication cycle and tracked over time, so accounts approaching, crossing, or receding from the very large platform threshold are identified from their own disclosures rather than from speculation. The Commission's designation lists are monitored for additions and removals, and proceedings, preliminary findings, and specification decisions are captured as separate and sharper triggers. Public compliance surfaces are diffed on a schedule. Terms of service and community guidelines are compared across captures for the vocabulary this regime introduces — notice and action, statement of reasons, internal complaint handling, out-of-court dispute settlement, trusted flaggers — and the appearance of a dedicated EU legal representative or point of contact page is treated as a direct confirmation that the obligation has been accepted rather than debated. Transparency artifacts are tracked as evidence of program maturity. Published transparency reports, risk assessment summaries, audit reports, and ad repositories are checked for existence, cadence, and format, and a company that has published a report but not an ad repository, or a repository without retention, has a visible gap a vendor can name precisely. The statements of reasons database is used as a volume and capability indicator. Whether a platform is submitting at all, how consistently, and in what structural quality distinguishes companies that built a pipeline from those manually filing, and manual filing at scale is an unsustainable state that resolves into a purchase. Marketplace surfaces are inspected for trader traceability work: seller identity disclosure on listings, verification badges and disclosure pages, and changes to seller onboarding documentation. Interoperability and portability documentation, developer portals, and API announcements are monitored on the DMA side, since gatekeeper obligations become visible as published interfaces. Hiring dates the program and names its owner. Postings for DSA or DMA compliance, platform regulatory counsel, trust and safety operations, content policy, transparency reporting, and EU-based compliance roles are collected, with first-of-kind roles weighted heavily and location weighted toward EU establishment, which the regulation effectively requires. Avina also maintains structural context: whether the company hosts third-party content, intermediates transactions, serves advertising, operates a recommender system, and has an EU establishment or must appoint a representative — because each of those determines which obligations attach, and a vendor who knows which tier an account falls into avoids the most common wasted call in this category. Each account is enriched with its disclosed user figures and trend, designation status, published artifacts and their gaps, observed policy and product changes, and compliance hiring, then matched against your ICP filters.

What Happens When a DSA or DMA Signal Fires?

Avina scores on tier and on gap. A designated very large platform or gatekeeper scores highest because the obligations are non-negotiable and audited. A platform whose disclosed user figure is rising toward the threshold scores nearly as high on a forward basis, since the work has to begin before the designation arrives. Among baseline-tier platforms, scoring favors those with the largest gap between obligation and observable capability: a marketplace with no seller identity disclosure, a platform with moderation but no statements of reasons submission, an ad-serving platform with no repository. Timing is set by the reporting calendar and by proceedings. Semi-annual user-number publication, annual transparency reporting, and the audit cycle each create a dated internal deadline, and purchasing clusters in the eight to twelve weeks preceding them. A Commission proceeding or request for information compresses everything, because the response has a deadline measured in weeks and frequently reveals that the company cannot produce the requested data in any form. Routing follows where each obligation lands. Notice, appeals, and statements of reasons route to trust and safety operations and the platform legal team. Ad repository and transparency route to ad platform engineering and revenue operations. Risk assessment, mitigation, and audit readiness route to the compliance or regulatory affairs owner and, in designated companies, to a dedicated compliance function the regulation requires them to maintain. Interoperability and data access route to product and platform engineering leadership. Contacts are enriched with verified emails, phone numbers, and LinkedIn profiles through waterfall enrichment. Avina identifies the head of trust and safety, the platform or regulatory counsel, the DSA compliance officer where one has been appointed, the head of content policy, the ad platform engineering leader, the data protection officer, and the EU-based legal representative, whose appointment is itself public and who is frequently the most reachable entry point into an otherwise closed organization. Reps receive a Slack alert naming the tier, the disclosed user figure and its trend, the published artifacts and the missing ones, and the hiring observed. Salesforce and HubSpot records carry the obligation map so outreach references the specific requirement the account has not yet met. Qualified accounts can be auto-enrolled into Outreach or Salesloft sequences matched to your position: content moderation and notice handling, appeals and dispute workflow, transparency reporting and structured submission, ad repository and ad transparency infrastructure, seller identity verification, risk assessment and audit readiness, recommender explainability, researcher data access, or advisory and audit services. The message that works is specific about tier and gap, because platform compliance teams have been told for three years that this regulation is coming and are entirely unmoved by being told again; what moves them is a vendor who has read their last transparency report and can name what was missing from it.

Start Tracking DSA and DMA Programs With Avina

A published user count, a new notice mechanism, and a first DSA compliance hire mark a platform entering a reporting and audit cycle it cannot miss. Activate this signal in Avina's Signals Library. Every plan includes a 7-day free trial with no credit card required.

Book a Demo