The DMA, and what it actually asks of your website

The Digital Markets Act has applied since May 2023, with obligations biting from March 2024. It regulates designated gatekeepers, which means Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft and Booking. If you run a website you are not a gatekeeper and you have no obligations under it. What reaches you is a consequence: Google now requires a certified consent platform for traffic from the EEA, the UK and Switzerland.

  • European Union, since March 2024
  • Binds gatekeepers, not you
  • Google certification required

From €10 a month. No credit card, no per-visitor billing.

What actually applies to a website owner

None of these come from the DMA directly. They come from what gatekeepers now require in order to keep serving you.

  • A Google-certified CMP for EEA, UK and Swiss traffic
  • Consent Mode integrated, not just a banner installed
  • Consent signals sent for advertising and analytics
  • A record of what each visitor allowed
  • The same treatment applied across all your domains

This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.

What Consent Studio does about it

  • Certified with Google

    Consent Studio is a Google Certified CMP Partner, first certified at Silver tier in 2024, and Gold since 2026. That is the requirement Google places on traffic from the EEA, the UK and Switzerland, and it is a checkable fact rather than a claim about the law.

    • Certified CMP partner
    • Gold tier since 2026
    • Consent Mode v2
  • Sends the signals from the first page load

    Consent Mode carries the visitor’s answer to Google’s tags rather than simply blocking them, so measurement degrades gracefully instead of disappearing. Installing a banner without wiring this up is what makes conversions vanish quietly.

    • From first load
    • Advertising and analytics
    • Modelled conversions
  • Applies to every domain you run

    The requirement covers all traffic you send to Google, not your main site. Per-domain pricing rather than per-visitor means covering the fourth and fifth site does not turn into a negotiation.

    • Per domain
    • Partner rate available
    • One configuration

What people get wrong about the DMA

  1. Believing the DMA applies to them

    It regulates a short list of designated gatekeepers and nobody else. A website owner has no DMA obligations, and a vendor telling you that you need their product to be DMA compliant is describing a requirement that does not exist.

  2. Treating a platform rule as a legal one

    Google’s Certified CMP requirement is real and it is a condition of using Google’s advertising products, not a law. The distinction matters when you are deciding what happens if you ignore it: the consequence is commercial rather than regulatory.

  3. Installing a banner without Consent Mode

    Certification is about the integration, not about having a panel on screen. A banner that blocks Google tags without passing consent signals satisfies neither the platform requirement nor your own interest in keeping measurement.

Essential

€10/month

For a single site that has to be compliant, and stay that way.

  • Unlimited pages and displays
  • 200,000 consent actions a month
  • The full stack, not a starter tier
Try Essential for FreeNo credit card required. 7 day free trial.

Running under rules like these, in more than one country


  • Philips, the Dutch electronics group, using Consent Studio for cookie consent
  • Erasmus Universiteit Rotterdam, managing cookie consent with Consent Studio
  • America Today, a fashion retailer using Consent Studio across its webshop
  • Van Vulpen, an infrastructure contractor using Consent Studio for cookie consent
  • EuroParcs, a European holiday park operator running Consent Studio on its booking sites
  • Optica, a Dutch opticians chain using Consent Studio for consent management
  • Jeans Centre, a Dutch fashion retailer using Consent Studio for cookie consent
  • Mondiaen, a Tilburg primary school foundation, running Consent Studio across its school websites
  • Fiterman Pharma, a pharmaceutical company using Consent Studio for cookie consent
  • Eddie Rockets, a hospitality group managing cookie consent with Consent Studio
  • Veneta, a kitchen retailer using Consent Studio for consent management
  • MS Mode, a fashion retailer running Consent Studio across its European webshops
  • Dynamis
  • SB Supply
  • The Chosen

Other rules that may apply to you

Common DMA questions

Does the DMA apply to my website?

No. Its obligations fall on designated gatekeepers, currently Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft and Booking. If you are reading this to find out what you have to do, the answer is that the DMA itself asks nothing of you.

Why do I need a Google-certified CMP then?

Because the DMA constrains what Google may do with data across its services without consent, Google now requires advertisers and publishers serving EEA, UK and Swiss traffic to use a certified consent platform integrated with Consent Mode. It is a platform condition arising from the law, not the law itself.

What happens if I do not use a certified CMP?

Google can limit personalised advertising features for the affected traffic, which shows up as reduced audience reach and degraded measurement rather than as a fine. The consequence is commercial, which is why it is worth separating from the regulatory questions on the other pages here.

Is Consent Studio certified?

Yes, as a Google Certified CMP Partner, first certified at Silver tier in 2024, and Gold since 2026. The certification covers integration with Consent Mode and Google Tag Manager, which is what the requirement is actually about.

Does Consent Studio make us compliant?

No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.

Where is our consent data stored?

In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.

Get Started with the Full Consent Stack

Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.

Read the documentation

Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.

Which privacy policy?

We publish two, and they cover different audiences. Pick the one that describes you.