Europe’s Privacy Paradox: Fort Knox for Search Data, a Checkbox for Your Phone
Brussels has developed a curious theory of digital privacy. Anonymous search queries need audits, screening, and a security cordon. Your messages, microphone, and screen can make do with a checkbox.
That is the logic running through two decisions the European Commission adopted last week involving the same company, under the same law, on the same day. Yet read side by side, they seem to come from different legal universes.
The first measure, issued under Article 6(11) of the Digital Markets Act (DMA), requires Google to share anonymized search data with rival search engines and AI chatbots. The Commission surrounded that dataset with an elaborate system of safeguards. Identifiers must be removed. Access is delayed by at least a week. Rare or revealing queries are excluded. Eligible firms must pass screening, undergo an independent audit before receiving any data, and submit to annual audits thereafter. They must also use ring-fenced processing environments, comply with purpose and retention limits, and clear checks for sanctions and control by high-risk third countries.
The second decision, issued under Article 6(7), requires Google to give rival AI assistants the same deep access to Android that Gemini receives. That includes ambient sensors, on-device app data, screen contents, and the ability to control other applications. The data concern identified users, include content, and arrive in real time. The main safeguard is a consent prompt.
One dataset gets an armed escort. The other gets a checkbox. The DMA’s internal logic can explain the difference. A consequentialist analysis has a harder time doing so.