EU weighs forcing Google to share search data with rivals despite privacy concerns
There’s a fight brewing in Brussels over who gets access to the trillions of search queries Europeans make on Google each year.
As reported by POLITICO, by late July, the European Commission will tell Google precisely which slices of its search data it has to share with competitors, as part of a regulatory procedure that will dictate how the internet giant should comply with the EU Digital Markets Act.
At stake is one of the most sensitive questions in Europe’s digital rulebook: whether regulators can open up Google’s vast data advantage to competitors without compromising the privacy of millions of Europeans.
The DMA, which came into force in 2024, was designed to rein in the market power of large tech platforms by imposing specific obligations on “gatekeepers” — firms that control critical bottlenecks in digital markets. For Google, one of those bottlenecks is search data itself.
Questions over what data should be shared — and with whom — have sparked a three-way fight between Google, search startups, and activists and academics who disagree over whether the dual policy goals of opening up the search market while protecting Europeans’ privacy and online security are compatible.
“No organization in the history of mankind has amassed more deeply private information on such a large scale,” said Wolfgang Oels, the chief operating officer of the upstart German search provider Ecosia — one of the firms seeking access to Google’s data empire.
Data driven
If Ecosia — or firms ranging from French startup Qwant to rival AI services like OpenAI and Perplexity — are to stand a chance of competing in either search or the burgeoning market for chatbots, argues Oels, they’re going to need some of Google’s data.
The reason has less to do with algorithms than with sheer scale, said Jens Prüfer, a professor in economics at the University of East Anglia and director of the Tilburg Law and Economics Center who wrote a 2012 paper that was among the first to model how data-driven markets tip toward a single winner.
Whoever has the most users learns the most about what people want, and can improve its product faster than anyone else. It’s a “very mechanical relationship,” he said, that has kept Google’s global market share in search at around 90 percent for the past 17 years. “They have it because they have the data,” Prüfer said, “not because they have the best algorithm.”
According to the Commission, access to search data has long been a major barrier to entry for competitors. “Google Search has collected a vast amount of user data, which third-party search engines haven’t been able to access,” Thomas Regnier, spokesperson for the Commission, said in a statement. “The Digital Markets Act has as an objective to alleviate this entry barrier.”
Out of control
At the heart of the fight is a particular kind of search data: highly specific, unique queries that can only be collected by a firm that processes billions of requests per day — but which can contain very personal information.
“Once it’s out, it’s out,” said Sergei Vassilvitskii, a New York-based computer scientist at Google, in an interview. “It doesn’t matter what the intentions are — if it’s out to a good party, a bad party. Once it’s out of control, it’s out of control.”

In April, Vassilvitskii’s team told the Commission that it had re-identified users from data that had been anonymized under the method proposed by the EU executive — in a matter of hours.
The exercise was intended to show that, even stripped of obvious identifiers, granular search queries contain enough biographical detail to unmask individuals. However, competitors disputed both the methodology and the conclusions.
“Google’s test was designed to raise alarm bells,” said a person familiar with rival firms’ responses. Third parties complain that the test data itself was never made public for outside scrutiny, a limitation that intensified skepticism about whether Google’s alarm was warranted or, as critics suggested, a strategic response to an unwelcome regulatory obligation.
Cybersecurity researchers, Vassilvitskii added, are “called paranoid until we’re not,” pointing to a long line of supposedly anonymized datasets — from AOL to Netflix to the fitness app Strava — that were later unpicked.
Some privacy campaigners agree that releasing vast amounts of search data into the wild, even if anonymized, is risky.
“Anonymization of these very large data sets is very, very hard, if not impossible,” said Jan Penfrat at digital rights group EDRi.
Still, Penfrat underlined that protecting privacy is a sliding scale, not an “on or off kind of thing.” The Commission had gone to lengths to build protections into the proposed search sharing measures “to make sure that there’s an acceptable or low privacy risk.”
Strong anonymization
That argument is now being fought, line by line, inside the Commission, and the EU’s referee is unusually well qualified.
Yves-Alexandre de Montjoye, a computational privacy specialist who is the chief technology officer at the Commission’s competition department, has been heavily involved in drafting the measures and soliciting feedback from third parties.
According to the Commission, the proposed measures set out a rigorous approach in which technical anonymization measures play a prominent role, developed “in collaboration with internal and external privacy experts.”
The data would not be made publicly available, and would be shared only with a limited set of eligible recipients — search engines and AI chatbots with search functionality — that already process similarly sensitive data, emphasized Regnier of the Commission.
“The Commission takes the protection of users’ data very seriously,” he said. “The goal remains to have a strong anonymization approach that enables key use cases for optimising search engines, while preserving the privacy of users.”

The startups say that Google’s privacy alarm is overblown, and a little rich. The data won’t be dumped online; it will go to a small, vetted set of firms, barred by contract from re-identifying anyone and audited by the Commission.
The likely recipients — privacy-first names like Proton and DuckDuckGo — “would be very dumb” to break those rules, said Lena Hornkohl, an assistant professor of competition law at the University of Vienna.
Moreover, the biggest privacy risk in the room, rivals argue, is the one that already exists.
“They know your doctor,” said Oels, who accuses Google of “misinforming European citizens” about a remedy built precisely “to allow for the emergence of competitors that don’t collect nearly the same amount of data.”
“You can build a safe system without a perfect one,” he argued, adding that the law asks for practical sufficiency and not completeness.
Privacy vs. competition
For the academics and activists who form the third side of this fight, the deeper question is whether privacy and competition were ever really opposed.
Filippo Lancieri, an associate professor of competition and privacy law at Georgetown University, argues that the trade-off is largely manufactured. The EU’s 2018 privacy law, the General Data Protection Regulation, was designed both to protect individuals’ personal data and to create common rules for data to move across the EU’s single market.
The data privacy law interacts with the DMA not as a contradiction but as a complementary framework, Lancieri explained, adding that just as the GDPR protects individuals’ rights over personal data, the DMA uses competition law to prevent single firms from hoarding data as a source of market power.
“Google and Apple really weaponize data privacy when they don’t want to do something,” said Lancieri, “and disregard it when they want to.”
Inge Graef, an associate professor of law at Tilburg University, argues the supposed clash is not even a legal one. In drafting the DMA, EU lawmakers already weighed privacy against openness — and settled on anonymization.
“It’s a balancing that the legislator has done,” Graef said, that should be struck by the enforcer, “not by a company that has its own commercial interests to defend.”
False binary
The goals of competition and privacy can be pursued “in union as opposed to in tension,” and treating the choice as a “zero-sum game” is itself a choice, said Alissa Cooper, a former internet engineer now at the Knight-Georgetown Institute.
The idea that Europeans must pick between the two, she said, is “a false binary” that “anyone living in a democratic society” should reject.
Prüfer is blunter about where the balance should fall. In the very large datasets at issue, he argues, meaningful anonymity is already an illusion — if Google wanted to re-identify someone, “they can do this anyway” — so the “gigantic” competitiveness gains should win out, “even if it comes at some cost to individuals’ privacy.”
That, ultimately, is the call the Commission must make by the end of July — and, as Cooper notes, it belongs to the regulators, not the company: “It’s up to the enforcers at the end of the day.”

Technology & Business Editor
Read more similar news:
Comments:
comments powered by Disqus