Source: OJ L 265, 12.10.2022, pp. 1–66Consolidated text

Current language: EN

Article 15 Obligation of an audit


Summary What does Article 15 of the DMA regulation say?

This article establishes a transparency obligation for gatekeepers regarding their consumer profiling practices.

Building directly on the designation process in Article 3, it requires gatekeepers to formally disclose and subject to independent audit any profiling techniques they use across their core platform services.

The audited findings are then shared with the European Data Protection Board, creating a clear link between this Regulation and the EU's data protection oversight framework.

Important points:

  • Submit an independently audited description of all consumer profiling techniques used across your core platform services to the Commission within 6 months of designation.
  • The Commission shall transmit the audited description to the European Data Protection Board, connecting this obligation to the broader data protection regulatory landscape.
  • Make a public overview of the audited description available, and update both the description and the overview at least annually — though business secrets may be taken into account when doing so.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Within 6 months after its designation pursuant to Article 3, a gatekeeper shall submit to the Commission an independently audited description of any techniques for profiling of consumers that the gatekeeper applies to or across its core platform services listed in the designation decision pursuant to Article 3(9). The Commission shall transmit that audited description to the European Data Protection Board.

    1. The Commission may adopt an implementing act referred to in Article 46(1), point (g), to develop the methodology and procedure of the audit.

    1. The gatekeeper shall make publicly available an overview of the audited description referred to in paragraph 1. In doing so, the gatekeeper shall be entitled to take account of the need to respect its business secrets. The gatekeeper shall update that description and that overview at least annually.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod