DMADSAAudit — EU DMA + DSA Compliance Audit
32 platform behaviors checked against EU Digital Markets Act 2022/1925 + Digital Services Act 2022/2065. Per finding: applicable article (DMA Art 5/6/7 or DSA Art 14/15/16/24/25/27/30/34/40), gatekeeper-threshold check, self-preferencing audit, dark-pattern detection. Surfaces 3 self-preferencing patterns + 2 dark-pattern UX choices that face EU consumer-law scrutiny even pre-designation.
What it is
The shape behind every EU platform-regulation review. DMA + DSA are the two regulations every EU-active platform team has to know. Most companies are NOT yet designated as gatekeepers / VLOPs — but the obligations cascade: even non-gatekeepers face EU consumer-law scrutiny on dark patterns + self-preferencing under DSA Art 25.
What’s in it
- 32 findings spanning DMA + DSA:
- DMA gatekeeper-threshold checks (4) — €7.5B revenue, 45M EU MAU, 10k EU business users, 8 core platform services. We are below all 4 — confirm annually.
- DMA Art 5-7 obligations (6) — self-preferencing in ranking, data combination, anti-steering, sideloading, defaults, messaging interop. Most are N/A (we are not a gatekeeper); 1 self-preferencing pattern flagged for review.
- DSA Art 14-30 obligations that apply to all online platforms — plain-language ToS, transparency reporting, notice-and-action, statement of reasons, anti-misuse, recommender-system transparency, advertising transparency, minors protection, KYBC for traders.
- DSA Art 34/35/37/40 — VLOP/VLOSE only (5 marked N/A) — systemic risk assessment, external audit, data access for researchers.
- Self-preferencing patterns (3) — 1p product highlighted on category landing, search-result boost, ranking-algorithm transparency.
- Dark patterns (2) — cancellation friction (cross-references WaitlistEthics EX-006 + CookieConsent P03), opt-in visual emphasis.
- Per-finding article mapping — every finding tagged with the exact DMA / DSA article number.
- Designation tracking — EU MAU 8M (low), business users <10k. Below all gatekeeper thresholds. Tracked annually.
Why this shape
EU DMA Reg 2022/1925 (effective Mar 2024) targets designated gatekeepers (Apple, Google, Meta, Amazon, Microsoft, ByteDance). EU DSA Reg 2022/2065 (effective Feb 2024) cascades through all online intermediaries — Art 25 dark-pattern prohibition + Art 14 plain-language ToS + Art 16 notice-and-action apply to every platform serving EU users. DMADSAAudit prototypes the audit that distinguishes “applies to gatekeepers / VLOPs only” from “applies to us today.”
How it ships
Single HTML file, ~16KB. Zero dependencies. 32 findings × DMA/DSA article mapping in 200 lines of vanilla JavaScript.