The DMA raises risk because it makes profiling practices more transparent and reviewable, which limits opaque data use and weak consent models. For gatekeepers, that means customer profiling, advertising practices, and platform self-preferencing can trigger scrutiny, audit obligations, and large fines. The practical impact is that revenue models built on hidden data exploitation face stronger regulatory constraints.
Why the DMA Changes the Risk Profile for Data-Driven Platforms
The DMA matters because it raises the cost of opaque behavioural profiling and makes the surrounding operating model easier to challenge. Platforms that depend on hidden data flows, weak consent interpretation, or internal self-preferencing face a different risk profile once regulators can inspect how audience targeting, ranking, and ad monetisation are actually driven. That changes both legal exposure and product design choices.
For large platforms, the practical issue is not only whether profiling is permitted, but whether it can be defended under clearer scrutiny. If targeting logic depends on broad data reuse or cross-service correlation, the organisation must assume that documentation, traceability, and internal approval evidence will matter more than historical practice.
- Opaque segmentation becomes harder to defend when the underlying data logic is reviewable.
- Revenue models that rely on indirect, inferred, or bundled consent face stronger challenge.
- Self-preferencing in ad delivery or ranking can become a compliance and competition issue at the same time.
That is why the DMA shifts risk from “can we monetise this data?” to “can we explain, evidence, and justify the full targeting chain?”
What Breaks First in Profiling-Heavy Advertising Models
The first failure point is usually data governance, not the ad platform itself. If profiling depends on large-scale collection, enrichment, and reuse across products, the platform can end up with weak line-of-sight from source data to ad decision. That creates review, retention, and purpose-limitation problems that are difficult to unwind quickly.
A second failure point is commercial dependency. If a major share of revenue comes from audience precision, even modest restrictions on cross-service profiling, default settings, or consent quality can reduce targeting efficiency. The result is not just a compliance burden, but a material product and revenue redesign problem.
NHI Mgmt Group’s Ultimate Guide to Non-Human Identities is relevant here because the same governance failure pattern appears whenever large-scale systems rely on poorly governed access paths and secrets to move data across services.
In practice, that means organisations need to separate what is technically possible from what is defensible under scrutiny. A model that depends on broad internal reuse may still work operationally, but it becomes fragile once regulators ask for evidence of purpose, necessity, and control.
Risk and Threat Considerations
Large platforms face both compliance risk and abuse risk when profiling is central to monetisation. The more valuable the targeting logic, the more attractive it becomes as an object of scrutiny, challenge, or manipulation, especially where data use is hard to trace and consent boundaries are unclear.
Failure mechanism: The platform cannot reliably prove how profiling inputs were collected, combined, and applied, so regulators and challengers can question the validity of the targeting chain and any downstream ad outcome built on it.
Impact: The organisation can face fines, product constraints, redesign pressure, and loss of margin if core ad workflows depend on practices that are now harder to justify or defend.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | DMA exposure depends on how profiling supports the platform's revenue and operating model. |
| GV.RM-01 — Risk Management Strategy | The DMA raises regulatory and revenue risk for opaque profiling models. | |
| PR.AA-01 — Identity Management, Authentication, and Access Control | Profiling systems depend on controlled access to customer and behavioural data. | |
| Recommendation — Map profiling and ad targeting to business context so governance can challenge high-risk monetisation dependencies. Set risk appetite for behavioural profiling and require redesign when controls cannot support defensible use. Restrict access to profiling inputs and processing paths to reduce misuse and unsupported data reuse. | ||
| CIS Controls v8 | 12.3 — Data Recovery | Profiling-heavy platforms need evidence and recoverability for regulated data flows. |
| 6.3 — Data Protection | Behavioural targeting relies on sensitive data collection, storage, and reuse. | |
| Recommendation — Maintain recoverable records of profiling inputs, approvals, and data-use decisions. Classify and protect profiling data to limit unnecessary collection, exposure, and secondary use. | ||
| NIST SP 800-63 | 3.1.4 — Binding Authenticator to Subscriber Account | Identity assurance underpins traceable user data collection used for targeting. |
| 7.1 — Federation Assurance Level | Ad platforms often depend on federated identity and cross-service trust for data sharing. | |
| 5.2 — Phishing Resistance | Compromised accounts can distort profiling inputs and ad decision data. | |
| Recommendation — Bind user data collection to stronger identity assurance where profiling decisions depend on account trust. Use assured federation settings before allowing profile data to flow across services or business units. Prefer phishing-resistant authentication for privileged access to profiling and advertising systems. | ||
Practitioner Guidance
What to verify: Treat profiling as a governed workflow, not just an ad-tech feature. You should be able to show which data sources feed targeting, which services enrich it, which approvals exist, and which controls prevent reuse beyond the stated purpose.
Decision rule: If a targeting method cannot be explained without relying on implicit consent assumptions or undocumented cross-service data sharing, treat it as a high-risk model and prioritise redesign over incremental patching.
Practitioner takeaway: The organisations most exposed under the DMA are usually the ones that cannot prove their targeting logic is narrower, cleaner, and more reviewable than the revenue model assumes.
Related resources from NHI Mgmt Group
- Why does the Digital Services Act create operational risk for large online platforms?
- Why do CPRA obligations create more risk for businesses that use targeted advertising and consumer profiling?
- Why does ad fraud create such a large financial risk for retailers using digital advertising?
- Why do targeted advertising and third-party sharing create higher compliance risk under the updated COPPA rules?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org