The EU’s new rules, specifically the Digital Services Act (DSA) and Digital Markets Act (DMA), are a massive headache for marketers. Doing a proper impact analysis isn’t just a good idea anymore. It’s about survival. If you don’t, your campaigns could get shut down, and you’ll be watching competitors who did their homework eat your lunch. Frankly, is your 2026 marketing strategy even close to ready for this?
Key Takeaways
- Make a list of every digital tool and platform you use, figure out if the DSA or DMA applies to it, and write down exactly what you’re obligated to do.
- Start an internal audit right now. Map all your current data practices against the new consent rules, paying close attention to how you’re running targeted ads.
- Write down your exact process for moderating content and handling user complaints so it lines up with the DSA’s transparency rules. No more winging it.
- Appoint a compliance officer (or a team) whose job is to track these regulations and be the point person for your lawyers.
- Build a real, detailed plan for rebuilding your ad tech stack so it can function under the new data privacy and interoperability guidelines.
1. Identify Applicable Regulations and Their Scope
First things first: you have to figure out which of these EU rules actually hit you. For most marketers, that means getting into the weeds of the Digital Services Act (DSA) and the Digital Markets Act (DMA). The DSA is all about online platforms, think content moderation, transparency, and protecting users. The DMA is a different animal. It goes after the massive “gatekeeper” platforms to force fair competition. So, the question for your company is whether you’re running a site that counts as an “online platform” under the DSA, or if your marketing depends so heavily on a “gatekeeper” that you’re caught in the DMA’s net.
Here’s a practical example. If your company runs a big e-commerce site that has user reviews, you’re directly in the DSA’s crosshairs for content moderation, how you handle takedown notices, and how you report on those decisions. You can get the specifics from the European Commission’s official DSA portal, which provides detailed guidance on the scope and your obligations. And if your entire ad strategy is built on data from platforms like Meta (Facebook, Instagram) or Google (Search, YouTube), then the DMA’s rules on interoperability and its bans on combining personal data from different services should have you scrambling right now.
Pro Tip: Don’t rely on summaries. Go get the full text of both the DSA and DMA from the EU Commission’s site. Your legal team is probably poring over this stuff, and your marketing plan better be in sync with what they find. Pay close attention to the definitions for “online platform,” “very large online platform (VLOP),” “gatekeeper,” and “core platform services” because getting those wrong will create huge holes in your compliance.
2. Conduct a Data Inventory and Mapping Exercise
After you’ve sorted out the regulations, you have to sort out your data. It’s time for a full-on data inventory and mapping exercise. You’ve got to track down every single bit of user data your marketing team touches, collects, processes, stores, and shares. I’m talking everything: IP addresses, cookie data, behavioral analytics, right down to demographic profiles.
Get a tool like OneTrust or BigID to do the heavy lifting. These platforms can scan your websites and databases, find the data, and map out where it all goes. Inside OneTrust, for example, you’d go to the “Data Mapping” section and kick off a “Discovery Scan” on your web properties and internal systems, specifically configuring it to find personally identifiable information (PII) and connect it to what you’re doing with it (targeted advertising, analytics, email marketing). The goal is a clear map showing where data comes from, where it lives, who can see it, and why you’re using it. And for every single one of those uses, you must have the legal basis documented. Both the DSA and GDPR are screaming about this.
Common Mistake: People almost always stop at direct customer data, but you can’t. All that data scooped up by third-party cookies, pixels, and the SDKs embedded in your website or mobile apps is also on the hook. These are the things that get overlooked, but they are absolutely covered by EU data rules, and your audit has to include them.
3. Assess Impact on Targeted Advertising and Personalization
The new EU rules, especially the DSA, are coming down hard on targeted advertising and personalization. Specifically, Article 26 of the DSA bans targeting minors with profiled ads and stops you from using sensitive personal data for any targeting. For gatekeepers under the DMA, the rules get even tighter about mixing personal data from different services to build ad profiles.
It’s time for a hard look at your ad tech stack. This means digging into how you use your demand-side platforms (DSPs) like The Trade Desk, as well as your data management platforms (DMPs) and customer data platforms (CDPs). For every tool, you have to know exactly how it’s collecting and using data for targeting. If you’re running campaigns on The Trade Desk, for instance, you need to go into your audience segments and make damn sure they aren’t built on any data that’s now forbidden. You’re probably going to have to shift your strategy, leaning much more on contextual advertising or first-party data you’ve gathered with very specific, clear consent.
This isn’t just my opinion. A recent IAB Europe report basically said that to comply, most advertisers will have to completely rebuild their consent management platforms (CMPs) to handle the kind of detailed consent these new rules demand for specific ad targeting purposes.
4. Revamp Consent Management Platforms and Privacy Notices
In the EU, everything comes back to valid consent. Both the DSA and GDPR are clear: consent has to be freely given, specific, informed, and unambiguous. That means your Consent Management Platform (CMP) has to be solid and dead simple for a user to grant or take back consent for different data uses.
Go look at your current CMP, whether it’s Cookiebot or Sourcepoint. It needs to give users real, granular control over cookie categories (necessary, analytics, marketing) and an easy way to opt-out. The interface has to be clean, with no “dark patterns” trying to trick people into agreeing. For example, if you use Cookiebot, go into your “Dialog” settings and make sure the “Accept All” and “Reject All” buttons are equally easy to see and click. Your privacy notice needs a complete rewrite, too. It has to spell out in plain English what data you collect, why, what you do with it, who you share it with, and how people can exercise their rights (like to access or delete their data). This is a transparency tool that builds user trust.
So many companies get this wrong, just slapping up some boilerplate legal text. But regulators are actually reading these notices now. Having a privacy policy that a normal person can actually understand is a real competitive edge as more people care about what’s happening with their data.
5. Establish Internal Compliance Protocols and Training
Compliance is a process, not a project you can just check off a list. It’s a constant effort. You’ll have to create clear internal compliance protocols and set up regular training for anyone on your team who handles marketing or data. This means writing down your actual policies for how you collect, use, and retain data according to the new EU guidelines.
Pull together a working group with people from legal, marketing, and IT to keep an eye on regulatory changes and make sure everyone is following the new rules. You’ll need a real training program that explains the DSA and DMA and, more importantly, how they change the day-to-day jobs of your marketers. Make the training mandatory and repeat it every year. For example, your social media team needs to be trained on the DSA’s content moderation guidelines so they know what to do about illegal content. Your ad ops team needs to be drilled on the new ad targeting restrictions and consent requirements. Keep records of who was trained and when they acknowledged the policies, because that paperwork is your proof of due diligence if a regulator comes knocking.
6. Develop a Crisis Response and Incident Management Plan
Even if you do everything right, things can still go wrong. A data breach or a compliance slip-up can happen, which is why you absolutely need a crisis response and incident management plan. This is your playbook for what to do in the event of a data breach, a regulatory inquiry, or a major user complaint about privacy.
The plan needs to spell out your communication chain (who calls who, and when you notify the authorities), how you’ll investigate what went wrong, and the steps to fix it. For a data breach, your plan must include the 72-hour deadline for notifying the relevant Data Protection Authority (DPA) under GDPR and how you’ll tell affected users. For a DSA-specific problem, like a major screw-up in your content moderation that causes real harm, the plan should detail how you report it to the Digital Services Coordinator. Running regular fire drills for these situations is the only way to make sure your team can actually execute the plan under pressure and reduce the damage.
There’s no question that the rules for digital marketing in the EU are much tougher for 2026. Getting ahead of this by doing a proper impact analysis and adapting your strategies now will keep you compliant and, just as important, build real trust with your customers. Being the company that handles data responsibly and operates transparently gives you a serious leg up in a market where everyone is worried about their privacy.
What is the primary difference between the DSA and DMA for marketers?
The DSA is about what happens *on* platforms (content, safety, transparency). Think of it as rules for the road. The DMA is about the platforms themselves, specifically the huge “gatekeepers,” to stop them from being anti-competitive. It affects how you can even use their services and data.
How do the new EU guidelines affect the use of third-party cookies?
They reinforce what GDPR started: you need explicit, active consent for third-party cookies for ads or analytics. Your consent pop-up can’t be wishy-washy. It has to give people a clear and easy choice to say no, and consent can’t be assumed just because they keep browsing.
Can I still use personalized advertising under the DSA and DMA?
Yes, but it’s gotten a lot harder. The DSA outright bans targeting minors and using sensitive personal data for ads. The DMA puts heavy restrictions on gatekeepers, forcing them to get separate, explicit consent to combine user data from their different services for advertising.
What is a “gatekeeper” under the DMA, and why does it matter?
A “gatekeeper” is a giant online platform (like Google or Meta) that the EU Commission has officially designated because of its size and power. This matters immensely because these companies face a whole extra set of strict rules under the DMA, which directly changes how you, as a marketer, can use their platforms and data.
What steps should a small to medium-sized business (SMB) take to comply with these new regulations?
First, figure out if any of this even applies to you by looking at the platforms and data you use. For most SMBs, the key steps are to get your consent pop-ups right, rewrite your privacy notice in plain English, make sure you have a legal reason for every piece of data you process, and teach your team the basics of handling data responsibly.