Skip to main content
Data Sharing Mandates Won't Fix CompetitionEU AI Act & GPAI
4 min readFor Legal & Compliance Officers

Data Sharing Mandates Won't Fix Competition

The Conventional Wisdom

When a dominant platform like Google refuses to share data with competitors, regulators often think forcing them to open up will level the playing field. The European Commission's decision requiring Google to share search data with competitors by January 2027 reflects this belief. If you're a compliance officer, you've likely heard that data sharing mandates can restore competitive balance.

This perspective treats data access as the primary barrier to entry. Remove that barrier through regulation, and market dynamics should correct themselves.

Why This Approach Falls Short

Mandated data sharing mixes up two issues: market concentration and data monopoly. You can address one without solving the other, and sometimes the solution creates more governance risks than it solves.

The Commission's order requires Google to provide search metrics to competitors "transparently and for a reasonable fee," with AI chatbots classified as search services for data-sharing purposes. The goal is to give smaller players access to metrics "similar to what Google itself sees." But this assumes data access is the main constraint, ignoring data interpretation, infrastructure, or the network effects that made Google dominant.

For compliance teams, the mandate introduces tension between competition policy, privacy protection, and security controls. The EU asks Google to anonymize data using a "multilayered approach" while remaining open to amending the decision for identifiable data. This isn't a technical specification; it's a placeholder for future negotiation, and your organization must build compliance programs around it.

The Evidence

Google's president of global affairs claims the decision "risks undermining vital privacy and security guardrails for millions of Europeans." Beyond corporate rhetoric, there's a real governance question: how do you operationalize "transparent" data sharing with "appropriate" anonymization when the regulatory standard isn't defined?

Consider what's needed for compliance with this mandate:

  • Identify which search metrics competitors receive.
  • Design anonymization that satisfies both GDPR's data minimization and the DMA's competition goals.
  • Establish fee structures that meet "reasonable" standards without clear regulatory benchmarks.
  • Extend the framework to AI chatbots, which process queries differently than traditional search engines.
  • Document all of this for audits while protecting proprietary methods.

The Android AI integration requirement, due by July 2027, adds complexity. The Commission wants "deeper integration with AI apps" beyond Gemini, but Google argues this bypasses existing safeguards. If you're managing vendor risk for AI on Android devices, you're caught between the DMA's demand for openness and your obligation to validate third-party AI tools before they access sensitive data.

This isn't hypothetical. Once Google shares anonymized search data with a competitor, that competitor becomes a data processor under GDPR. Your vendor due diligence process now includes evaluating whether that competitor's anonymization methods meet the same standard Google applied. But you won't have visibility into Google's multilayered approach because it's likely protected as a trade secret. You're auditing compliance with a standard you can't fully observe.

What to Do Instead

If you're building governance frameworks around platform competition mandates, separate the data-sharing mechanics from the competitive outcome you're trying to achieve.

Start with risk tiering. Not all search data carries the same privacy or security weight. Query volume by topic differs from click-through rates, which differ from session duration metrics. Map which data elements the regulation requires you to share, then apply Data Protection Impact Assessment rigor to each category. Don't treat "search data" as a monolithic set.

For the Android AI integration mandate, establish clear security baselines before opening platform access. If the DMA requires deeper AI app integration, your response isn't to disable vetting. It's to document the specific security controls non-Gemini AI tools must meet, publish those requirements, and enforce them consistently. The regulation mandates access; it doesn't prohibit you from setting security standards for that access.

On anonymization, demand regulatory clarity before you build the system. The Commission's willingness to amend its decision "to ensure identifiable data is appropriately handled" is an invitation to negotiate technical standards. Use it. Submit detailed questions about what "multilayered" anonymization means in practice, what constitutes "similar" metrics, and how conflicts between competition and privacy obligations should be resolved. Get those answers in writing.

Most importantly, treat "reasonable fee" as a compliance control, not a pricing decision. If you're required to share data for a reasonable fee, document the actual cost of anonymization, infrastructure, ongoing monitoring, and audit support. Build a defensible cost model. When regulators or competitors challenge the fee, you're defending a documented compliance cost, not a market rate.

When the Conventional Wisdom Is Right

Data sharing mandates make sense when the data itself is the bottleneck and when sharing it doesn't create new governance risks that outweigh the competitive benefit.

If a dominant platform controls a dataset that's truly essential for market entry, and if that dataset can be shared without compromising privacy or security, mandated access can work. The conventional wisdom holds when three conditions align: the data is non-replicable, the sharing mechanism is technically specified, and the privacy-competition tradeoff is explicit rather than deferred.

The EU's approach might reach that standard by January 2027, once the multilayered anonymization framework is defined and the fee structure is settled. Until then, compliance teams are building programs around incomplete requirements. This isn't a criticism of competition policy. It's a warning that regulatory timelines and operational readiness don't always sync, and your governance framework needs to account for that gap.

The Commission's goal of reducing Google's search dominance is defensible. The method of getting there creates compliance complexity that won't be resolved by the implementation deadline. If you're responsible for operationalizing these mandates, plan for iterative clarification, not day-one certainty.

You Might Also Like