Computer & Communication Industry Association
PublishedJuly 2, 2026

The DMA Security Paradox: Balancing Openness and User Safety in the Mobile Age

More than two years into enforcement of the Digital Markets Act (DMA), one of its most difficult challenges is becoming increasingly clear: how can digital ecosystems be opened to greater competition without weakening the security, privacy, and seamless experience European users have come to expect? While some DMA obligations may expand consumer choice, they can also have unintended effects that ultimately undermine consumer welfare. 

At the 2026 European Digital Competition Day, an expert panel examined these trade-offs and the growing ‘security paradox’ at the heart of ex-ante regulation. The discussion explored how the DMA’s obligations should be enforced – and potentially updated – to strike the right balance. Doing so will require moving beyond rigid, adversarial enforcement towards a collaborative approach grounded in technical expertise. 

1. The spectrum of openness and its unintended risks

Setting the conceptual stage for the panel, Zach Meyers, Director of Research at the Centre on Regulation in Europe (CERRE), stressed that regulatory interventions must recognise the nuanced realities of digital ecosystems. Pointing to the DMA’s interoperability mandates, he warned against extreme, one-size-fits-all solutions. “I think one of the starting points here is that openness isn’t a binary choice. It is a spectrum,” Meyers explained. 

He observed that platforms inherently have to balance access with safety all the time in order to remain attractive to users. “I don’t think that taking an approach that says either maximum possible choice at the expense of everything else, or maximum security at the expense of everything else, is the right approach.” However, Meyers acknowledged the regulatory concern that vertically integrated platforms might not always strike the perfect balance. “You can’t necessarily assume in those cases that platforms will always get it right and always choose the optimum level of openness on that spectrum.” 

To solve this, Meyers called for a change in how the European Commission approaches enforcement. “To date, I think the DMA implementation model has relied heavily on gatekeepers being expected to put forward their own solutions, with the Commission intervening only where it thinks players are getting it egregiously wrong.” He advocated for a more inclusive process, arguing that the Commission should involve independent experts and cybersecurity agencies to properly scrutinise both the gatekeepers’ security claims and the regulatory demands being placed upon them. 

2. Enforcement timelines and the ‘denial of sleep’

The risks outlined by Meyers are already manifesting as compliance hurdles for gatekeepers. Gary Davis, Senior Director of Regulatory Legal at Apple, described the procedural pressures facing gatekeepers under the DMA. Echoing concerns raised by CCIA Europe about the regulation’s timelines, Davis argued that the current enforcement process places excessive pressure on both gatekeepers and the Commission. 

“I would call the specification procedure to be a ‘denial of sleep’ attack, because it’s conducted both on the gatekeeper side and the European Commission side,” Davis argued. He explained that the statutory six-month window leaves insufficient time to safely engineer highly sensitive technical changes. “Opening up to third parties in a sensible way takes time and thought. That cannot be done within six months.” 

A central point of contention is the Commission’s lack of specialised privacy and cybersecurity expertise during these deliberations. Davis pointed out that DG COMP is inherently designed to view cases through a strict competition lens, lacking the mandate and knowledge of bodies like the European Data Protection Board (EDPB) or ENISA, the EU cybersecurity agency. “That is the tension that we are seeing on an ongoing basis. The outcomes we are being asked to put in place do not have, what I would call, legitimacy attaching to them in relation to having gone through an appropriate privacy and security filter involving people who know what they’re talking about.” 

Davis argued that these procedural and regulatory constraints have delayed the introduction of certain technological features in the EU. “We have not launched many features here in the EU because we have not been able to solve those privacy and security issues in a way that we could find a good outcome with the Commission,” Davis said, citing the delay of features like iPhone Mirroring. 

3. The architectural reality: Is complexity the enemy of security?

The procedural pressures highlighted by Davis were also discussed in the context of the engineering challenges involved. Providing a technical perspective, Heather West, Senior Fellow at the Center for Cybersecurity Policy and Law, expanded on the architectural realities of forced interoperability. She cautioned regulators against applying outdated or misunderstood assumptions to modern mobile architectures. “Desktop operating systems were really early on designed for maximum openness because there was an assumption that everyone was a good actor,” West said as she recalled the early era of computer viruses. 

West warned about the practical dangers of mandating unrestricted third-party access to core system functionalities. “Introducing unanticipated interfaces or interoperability into a system architecture is hard. It is one of those things that I think people underestimate the engineering complexity of. […] Complexity is the enemy of security. We want simple, we want it to work, we want you to not have to think about it.” 

She further argued that poorly implemented openness mandates will inevitably be exploited. “The criminals, the malicious actors online, are very quick to adopt some of these techniques. If they see a hole, they’re going to use it for as long as they can,” West cautioned, insisting that cybersecurity experts must be at the table to ensure interoperability is done safely. 

4. The consumer view and the challenge of compliance

Providing the consumer advocacy perspective, Sébastian Pant of BEUC argued that the regulation is already delivering tangible benefits, emphasising that the DMA’s core objective is to improve user choice. “I don’t think it’s going to be a surprise to any of you when I say that we believe the DMA is beginning to work,” he stated, praising the introduction of new browser choice screens and payment solutions like PayPal on iOS in Germany. 

Pant reported a positive experience testing new messaging interoperability, noting: “I just tested on Monday the new instant messaging interoperability between Beeper and WhatsApp. Honestly, go out there and try it. It works. It’s really good. It’s great.” However, he remained critical of overall industry efforts. “Compliance with the DMA by the gatekeepers on the whole is still pretty poor,” he argued. 

Addressing the security debate, Pant agreed that it is not a binary choice, but added that “you cannot prevent competition in terms of connecting devices on the basis that it’s good for the security of the user.” Regarding the procedural concerns raised by industry about involving independent agencies, Pant agreed: “Indeed, let the Commission consult ENISA. Let them consult the Data Protection Authorities (DPAs).” However, he defended the current regulatory hierarchy, asserting that “it is for the Commission to decide on these things” and that consultation “should not come at the expense of an endless dialogue.” 

5. Real-world market dynamics and structural flaws

While technical interoperability can expand consumer choice, available market data presents a more complex picture of consumer uptake. Chiara Caccinelli of the French regulator ARCEP offered insights into the friction that remains for new competitors. She argued that barriers to uptake also arise from user behaviour, rather than just from gatekeeper conduct. 

Sharing her own experience with trying alternative messaging services, Caccinelli noted the technical hurdles early adopters face. “I had to go through four different steps to activate it… I don’t think that all consumers are so motivated.” She explained that ARCEP collects “data on messaging services and the usage of those services and we know that 66% of users choose [a specific messaging service] because their friends are there,” while “only 9% choose it because of the functionalities.” 

Furthermore, Caccinelli pointed out her view of a structural flaw in the DMA itself that severely could hinder competition. By forcing gatekeepers to offer interoperability for free, and explicitly prohibiting competitors from offering it to highly lucrative business users, the regulation destroys the incentives for some new entrants. “This restriction in the DMA makes it also more difficult for potential competitors to find a business case to say: okay, I will invest engineering costs to make sure that I provide this service, but still I will not get any money from it.”

Conclusion

The panel discussion made clear that openness, competition, privacy, and security cannot be considered in isolation. Yet there remains a notable lack of openness from the EU institutions to properly acknowledge the existing risks to consumer privacy and security, and the complexity of many of the interplays and their consequences on wider sectors. To ensure the DMA genuinely serves Europeans, both enforcers and policymakers must ensure that future guidance is informed by technical, cybersecurity, and data-protection expertise. 

Balancing openness with security will require abandoning the ‘denial of sleep’ adversarial approach in favour of genuine, proportionate dialogue that empowers experts from ENISA and national DPAs to play a central role in the compliance workflow, for instance. Ultimately, the measure of the DMA’s success should be whether European consumers gain more choice, innovation, and control while continuing to receive the same level of security, privacy, and seamless experience they have come to expect.

Maria Teresa Stecher

Senior Policy Manager, CCIA Europe
Article

The Supreme Court Expands Privacy Rights to More Squarely Encompass Your Digital Footprint

When police cannot identify a suspect, they increasingly turn to technology companies rather than witnesses. The Supreme Court confronted one of the most aggressive versions of this practice in Chatri...
  • Privacy
Article

In Pictures: European AI Roundtable on Copyright – Fuelling Creativity in the AI Age 

On 2 June 2026, the Computer & Communications Industry Association (CCIA Europe) hosted the latest edition of its European AI Roundtable in Brussels. The event brought together EU policymakers, le...
Article

Functional App Stores Aren’t a Tax

Two “studies” this week discussed in the Daily Mail purport to show a large imposition on consumers. They describe almost all the costs associated with running an app store -- including keeping us...
  • Digital Economy
Article

Amazon Opened Its Logistics Network, Following the Virtuous Cycle Strategy 

In May 2026, Amazon opened its logistics network to everyone. Amazon Supply Chain Services (ASCS) makes the company's freight, warehousing, fulfillment, and parcel-delivery capabilities available to a...
  • Competition