Brussels has developed a curious theory of digital privacy. Anonymous search queries need audits, screening, and a security cordon. Your messages, microphone, and screen can make do with a checkbox.
That is the logic running through two decisions the European Commission adopted last week involving the same company, under the same law, on the same day. Yet read side by side, they seem to come from different legal universes.
The first measure, issued under Article 6(11) of the Digital Markets Act (DMA), requires Google to share anonymized search data with rival search engines and AI chatbots. The Commission surrounded that dataset with an elaborate system of safeguards. Identifiers must be removed. Access is delayed by at least a week. Rare or revealing queries are excluded. Eligible firms must pass screening, undergo an independent audit before receiving any data, and submit to annual audits thereafter. They must also use ring-fenced processing environments, comply with purpose and retention limits, and clear checks for sanctions and control by high-risk third countries.
The second decision, issued under Article 6(7), requires Google to give rival AI assistants the same deep access to Android that Gemini receives. That includes ambient sensors, on-device app data, screen contents, and the ability to control other applications. The data concern identified users, include content, and arrive in real time. The main safeguard is a consent prompt.
One dataset gets an armed escort. The other gets a checkbox. The DMA’s internal logic can explain the difference. A consequentialist analysis has a harder time doing so.
A Walled Garden for Data, an Open Door for Devices
Understanding the mismatch requires a closer look at what each decision does.
The search-data decision implements Article 6(11), which requires Google to provide rivals with ranking, query, click, and view data on fair, reasonable, and nondiscriminatory (FRAND) terms. The Commission begins with technical anonymization. Google must remove direct identifiers and timestamps, suppress rare terms and unusually long queries, and place each user in a group of at least 1,000 people who share the same location, device type, and language. In the Commission’s telling, the result is a “haystack” of disconnected queries.
The decision goes much further. Because technical safeguards can only reduce the risk of reidentification, the Commission also regulates who may receive the data. Only genuine search businesses qualify.
A firm must have operated in the European Union for at least two years. A newer entrant may qualify if it has raised more than €50 million and serves at least 50,000 monthly European users. The decision excludes sanctioned entities and firms controlled by third countries that pose structural cybersecurity or data-protection risks. Before sharing any data, Google may also assess whether a particular recipient presents serious cyber or privacy risks.
Recipients must pass an independent audit before gaining access and submit to annual audits afterward. They must process the data in ring-fenced environments, use it only to improve search, refrain from training general-purpose AI models with it, and delete it on schedule.
These safeguards largely turn on the recipient’s identity and conduct. The result resembles a walled garden, the same basic architecture gatekeepers built for themselves and that the Commission is dismantling elsewhere. Yet Article 6(11) itself devotes only one word to protection: “anonymized.”
Article 6(7) takes a different approach. Its text expressly allows gatekeepers to adopt “strictly necessary and proportionate” measures to protect system integrity and security, provided they justify those measures. Yet in its March 2025 decisions involving Apple, the Commission reduced that protection to a narrow allowance. Interoperability solutions must work as well as Apple’s own and, according to the decision’s summary, “must not require more cumbersome system settings or additional user friction.”
Under Article 6(7), any developer may request access, and Apple must process those requests within fixed deadlines. The framework does not allow firms to screen applicants based on identity, business model, or data-handling history. Draft joint guidelines from the European Commission and European Data Protection Board (EDPB) would go further by barring gatekeepers from considering an applicant’s record of violations under the General Data Protection Regulation (GDPR).
The permitted safeguards focus on the product rather than the recipient. Gatekeepers may use consent prompts, encryption, and measures that preserve end-to-end encryption. They may not decide who gets through the door.
Against that background, last week’s Android AI decision comes as little surprise. Google must support any integrity measure with “objective and verifiable evidence” of risk and apply it equally to its own services. As I argued in May, that standard makes precaution against genuinely novel threats almost impossible.
The discrepancy is hard to miss. Where the statute says little about screening recipients, the Commission created an extensive vetting regime. Where the statute expressly permits protective measures, the Commission reduced them largely to prompts.
To be sure, the provisions are worded differently, and that difference carries legal weight. Article 6(11) imposes an affirmative duty to anonymize the data, which the Commission had to translate into operational rules. Query logs also contain personal data, so the GDPR applies directly. Article 8(1) of the DMA requires compliance measures to respect those obligations.
Article 6(7), by contrast, frames security protections as a limited exception available to the gatekeeper. The Commission therefore reads them narrowly to prevent evasion, as regulators often do with legal exceptions. The method is coherent enough. Commands receive broad effect. Exceptions receive little room to breathe.
The Best Case for the Double Standard
The Commission’s different readings of the two provisions are defensible, at least up to a point. The strongest case rests on user control and scale.
Start with user control. Under Article 6(7), each data flow begins with an identifiable user action, such as pairing a watch or tapping “allow.” That choice may provide a legal basis for the transfer through consent or contractual necessity. It also creates a transaction-specific safeguard through prompts, device-level permissions, and the ability to disconnect the service.
Article 6(11) works differently. No individual user chooses to share anything. Query data from millions of people moves in bulk, and no workable consent mechanism could cover it. The only path to lawful disclosure is to remove the data from the GDPR’s reach through anonymization.
Because anonymization carries so much legal weight, any threat to it becomes central. The most obvious risk is that a recipient could try to identify users again. Vetting, ring-fencing, and audits follow from that concern. The safeguards therefore track the legal basis for each form of access. Article 6(7) relies on the user’s choice. Article 6(11) relies on the recipient’s trustworthiness.
Scale offers a second defense. Article 6(11) separates the amount of data disclosed from the recipient’s own size. Even the smallest eligible firm receives data derived from nearly the entire population of Google Search users, then keeps a copy in its own environment for up to five years.
If anonymization fails, the harm can reach millions of users and cannot be undone. A leaked dataset cannot be unpaired, as AOL learned in 2006. Under Article 6(7), a third party receives data only from users who choose its service. Access grows with adoption, and users can revoke it.
These arguments make a stronger case for the Commission’s distinction than the decisions themselves do. They still do not carry the day.
When the Checkbox Becomes the Security System
That defense fails twice on its own terms, then a third time on a question it never asks.
Start with consent. Nothing moves until a user pairs a device or taps “allow.” But Article 6(7) requires Apple and Google to open their interfaces and process requests before any user makes that choice. By the time the prompt appears, the requester already has technical access and may look no different to the user than a legitimate accessory maker.
Attackers also work upstream of genuine consent. They can phish the prompt, spoof the accessory, or exploit the pairing process. As Miko?aj Barczentewicz warned before the DMA took effect, one determined bad actor can cause immense harm by exploiting an interoperability mandate. That risk weakens the case for treating privacy less carefully under Article 6(7) than under Article 6(11).
The contrast becomes sharper when the regimes are placed side by side. Under the Google Search decision, data recipients must earn trust. Under the Apple and Android AI decisions, the Commission presumes it. Anyone may apply, and firms may not reject applicants based on who they are. The remaining check is a prompt that users have little basis to assess.
We already know what an unvetted queue can contain. When Amazon reviewed applicants for DMA data access, more than 75% were based outside the European Union. Many appeared to be data brokers with murky privacy practices. Apple has reported interoperability requests broad enough to read every message and email on a user’s device.
The regimes also differ in what changes hands. A sensible privacy framework should match safeguards to the sensitivity of the data. More revealing data should receive stronger protection.
These decisions reverse that logic. Article 6(7) interoperability can expose the most sensitive material on a phone. The Android AI decision goes further by covering microphones, cameras, screen contents, and the ability of AI agents to imitate taps and complete transactions. Article 6(11), by contrast, covers week-old queries in which each individual is hidden among at least 1,000 others. The Commission has placed its lightest safeguards around the most sensitive data.
Nor is it clear that Article 6(11) always creates greater risks at a larger scale. Imagine a popular smartwatch app with five million users that gets hacked or turns out to have been malicious all along. Five million people could have their messages exposed at once, tied to their identities. Article 6(7) requires no audit, certification, or background check to prevent that outcome.
Now multiply that risk across hundreds of companies entitled to connect, each creating another point of failure. The unvetted crowd may pose a greater danger than the small number of heavily audited firms receiving Google’s search data. A regime that tracked actual risk would impose some checks everywhere and stronger ones where more people could suffer harm.
Recipient screening is hardly a Brussels invention. Platforms used gated access, screened counterparties, and revocable permissions long before the DMA. They built those protections, presumably, to meet consumer demand for privacy and security. The Commission now overrides those design choices without adequately accounting for the functions they served. Those functions must then be rebuilt through regulation.
Under Article 6(11), the Commission preserved that inherited machinery. Under Article 6(7), it dismantled it and replaced it with the one tool the rest of the statute treats with suspicion—a consent prompt. Elsewhere, the DMA assumes that user choice is weak and defaults are sticky. That is why it requires choice screens and restricts dark patterns. The same concern helps explain why markets often provide privacy and security through platformwide rules rather than one prompt at a time.
The consequences are concrete. Siri AI will not launch in the European Union, and Gemini on Android could meet the same fate. When openness mandates and privacy law press in opposite directions, rational firms reduce functionality to limit their exposure.
Fit for Purpose, Blind to Consequences
Why does Europe’s flagship digital law guard anonymous search queries like state secrets while leaving people’s messages, microphones, and screens behind a single tap?
The two-speed approach makes sense only if consequences do not count. There is a legal explanation for the gap. The provisions use different language, and each decision follows its own internal logic.
That may be defensible as statutory interpretation. It is nonetheless quite obviously poor privacy policy. The most sensitive data on a phone may receive the weakest protection, while less sensitive data comes wrapped in audits, screening, and access controls. No one designing a privacy regime from scratch would choose that result. Platforms had already built many of the missing safeguards under Article 6(7), and the Commission dismantled them.
The stakes are rising. AI assistants can read screens, press buttons, access microphones, and spend money. Article 6(7) now helps determine who may wield those powers. The costs are already visible. Rather than open their most sensitive features to any requester, firms are withholding products from European users.
The Commission’s own review called the DMA “fit for purpose.” That judgment depends on what the law actually produces. The search-data decision shows that the Commission knows how to protect users when it sees the risk. Its harder task is explaining why platforms may not do the same.
