Source: OJ L 265, 12.10.2022, pp. 1–66Consolidated text

Current language: EN

Article 27 Information by third parties


Summary What does Article 27 of the DMA regulation say?

This article establishes a reporting mechanism that allows third parties to flag potentially non-compliant behaviour by gatekeepers to either national competent authorities or the Commission.

It is a relatively brief but practically important provision, as it opens a formal channel for business users, competitors, end users, and their representatives to raise concerns.

Crucially, it connects to the Commission's enforcement role by requiring national competent authorities to escalate relevant information to the Commission where they identify a possible non-compliance issue, reinforcing the Commission's position as the central enforcer under this Regulation.

Important points:

  • Any third party, including business users, competitors, or end users, may report gatekeeper behaviour to national competent authorities or directly to the Commission.
  • National competent authorities and the Commission have full discretion over whether to act on information received and are under no obligation to follow up.
  • National competent authorities are required to transfer information to the Commission where they determine it may indicate a non-compliance issue.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Any third party, including business users, competitors or end-users of the core platform services listed in the designation decision pursuant to Article 3(9), as well as their representatives, may inform the national competent authority of the Member State, enforcing the rules referred to in Article 1(6), or the Commission directly, about any practice or behaviour by gatekeepers that falls within the scope of this Regulation.

    1. The national competent authority of the Member State, enforcing the rules referred to in Article 1(6), and the Commission shall have full discretion as regards the appropriate measures and are under no obligation to follow-up on the information received.

    1. Where the national competent authority of the Member State, enforcing the rules referred to in Article 1(6), determines, based on the information received pursuant to paragraph 1 of this Article, that there may be an issue of non-compliance with this Regulation, it shall transfer that information to the Commission.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod