The ever-growing digital economy relies extensively on all sorts of data to feed its growth, and personal data oftentimes find itself at the heart of companies’ core or emerging business practices. New personal data usages, leading to winner-takes-all positions for the initiating companies, are leading to brand new concerns from a competition law point of view.
Even if data protection and competition legal frameworks both evolved over decades with distinct objectives in mind, their goals do however align in ensuring, among other the protection of individuals’ well-being and freedom of choice, fairness and transparency and the reduction of power asymmetries.
Therefore, the need for an interplay between data protection and competition regulations has become undeniable. Recent developments at both EU and national member state levels highlight that cooperation between privacy and competition professionals within companies is becoming a necessity to match the regulators’ collaborative approach.
1. A European Framework for Cooperation
In recent years, the relationship between national data protection authorities (“DPA”) and competition authorities has caught the eye of European institutions. Starting with the Court of Justice of the European Union (“CJEU”), which opened the floodgate, recognizing the importance of “sincere collaboration” (A), while the European Data Protection Board (“EDPB” which gathers the DPA from all 27 EU Member States) followed and called for a stronger, more effective partnership between DPAs and competition authorities (B).
A. When data protection and market power collide before the Court
In 2019, the national German Competition Authority accused Facebook of abusing its dominant market position, due to the lack of GDPR compliance of its processing of user data, in particular with Art. 6 (1) and Art. 9 (2) GDPR. Facebook appealed on the basis that the German Competition Authority had no authority to enforce data protection rules under antitrust laws. The Court of Appeal requested a preliminary ruling from the CJEU, which established:
- the requirement for a sincere cooperation between competition authorities and DPAs, particularly concerning the use of consumers’ personal data by social media platforms (Meta Platforms Inc. e.a. v. Bundeskartellamt”, 21); and
- determined that Member States’ competition authorities have the authority to investigate and sanction GDPR violations if companies misuse their dominant market position. However, should the competition authority be uncertain about the scope of the decision by the competent DPA or if the decision is then under review by this authority, the competition authority must consult with it, thereby highlighting that cooperation between the two authorities will be, in some instances, mandatory.
In 2024, the CJEU clarified in its ruling “Lindenapotheke” (23) that Member States could implement provisions for competitors to challenge alleged GDPR infringements in court as a prohibited “unfair commercial practice”. Thus, competitors can also pursue civil proceedings for data protection violations subject to national law, due to the unfair advantage the infringing company would get from its lack of investment in GDPR compliance.
B. Building stronger bridges between DPAs and competition authorities
Noting this incentive, as well as sometime requirement, for both administrative bodies to apprehend certain practices, the EDPB followed up by setting up a dedicated task force focusing on the interplay between data protection, competition and consumer protection.
On 16 January 2025, the EDPB adopted its Position paper on Interplay between data protection and competition law, which aims at providing recommendations for further development of existing cooperation models between DPAs and competition authorities.
According to the EDPB analysis, several Member States have already implemented certain models for cooperation between these two authorities. The EDPB distinguishes between three different types of collaboration:
- Non-formalized cooperation: Member States that have not adopted legal provisions mandating or enabling formal cooperation between DPAs and competition authorities, have seen their authorities engage informally and voluntarily, by providing consultations during administrative procedures or through occasional joint projects where their regulatory responsibilities overlap;
- Semi-formalized cooperation: In absence of a legal requirements, some authorities have established cooperation through instruments such as jointly drafted cooperation protocols, joint declarations, or Memoranda of Understanding. While these arrangements may not be legally binding, they outline mechanisms for joint activities like workshops, training sessions, events, regular meetings, and the sharing of best practices. In addition, a few Member States have implemented explicit legal provisions that govern the collaboration between DPAs and competition authorities. These formal arrangements, though varying in scope and specific requirements, typically include the provision of opinions on cases at the request of one authority by the other; and
- Formalized cooperation: The highest level of cooperation is characterized by legal mandates and structured practical arrangements between the authorities to ensure effective coordination.
The EDPB continues to suggest several approaches to enhance collaboration between DPAs and competition authorities in its paper. First, the authorities could agree on holding informal or regular meetings, or even to set up specialized expert working groups to establish a unified framework. This could be achieved through administrative agreements, joint declarations, or Memoranda of Understanding. These agreements would outline key cooperation principles, methods, and rules, as well as provide guidance on how to consider past decisions and penalties issued by each authority. In addition, the EDPB calls upon national legislators and/or governments to recognize the growing needs for regulatory bodies to work more closely together in the digital domain. Internally, the paper proposes that authorities could establish a point of contact to streamline cooperation efforts. Besides, they should also work towards gaining a basic understanding of the regulatory frameworks overseen by their counterparts in the different legal field. Finally, in cases where more structured and consistent cooperation is required to ensure the coherent application of different EU regulations, establishing cooperation protocols between the relevant authorities may be essential. This will help facilitate reciprocal consultations at the appropriate time and with the necessary scope, ensuring compliance with the duty of sincere cooperation which has been recognized by the CJEU.
2. National initiatives: a focus on France and Germany
A. France: a multilateral semi-formalized approach
At national level, reports have been issued by the French DPA (“CNIL”) with other administrative authorities such as the French Competition Authority (“Autorité de la concurrence”) and the French Directorate-General for competition, Consumer Affairs and Prevention of Fraud (“DGCCRF”) to outline the standards of their collaboration and to develop new ways of sharing information to keep pace with changes in legislation and the economic challenges of the digital age.
i. The long-standing cooperation between the CNIL and the DGCCRF on consumer and data protection
In 2011, the CNIL and the DGCCRF signed their first cooperation protocol to ensure a better protection of consumer in the digital space. To promote this cooperation and adapt it to changes in the legal framework and the digital economy, the protocol was reviewed for the first time in 2019. The mains areas of cooperation included a raise of consumers awareness on the risks involved in communicating their personal data and disseminate best practices implemented by professionals, an easier exchange of information relating to non-compliance with consumer law and the protection of consumers’ personal data and the concerted approach of their analyses of legislative and regulatory developments relating to consumers and their personal data.
In November 2024, the CNIL and the DGCCRF finalized their second review of this cooperation protocol, called for by the constant growth of the digital dimension in economic exchanges. The two authorities aim in particular with this new protocol to deepen the exchange of information on non-compliance with consumer law and personal data protection (including cases handled at the European level), to share analyses of consumer and personal data protection legislation to develop harmonized interpretations between the two legal frameworks and ensure consistency in their application (for example, work will shortly begin on a shared definition of “dark patterns”) and to implement joint economic analyses, in particular to study the impact of the data economy on personal protection, or to analyze the effects on consumers of mechanisms such as manipulative processes on commercial sites (dark patterns).
This latest protocol also complements the cooperation agreement, which was signed by the French Regulatory Authority for Audiovisual and Digital Communication (“Arcom”), CNIL and DGCCRF in June 2024, which focuses on the scope of application of the new European regulation on online digital services (combating illegal content and complying with transparency obligations on the operation of algorithms). It represents a significant step in enhancing the collaboration between various authorities overseeing the digital economy, benefiting citizens, and strengthening synergies further through the digital regulators’ network established by the SREN law and is expected to be reinforced by the expected multilateral approach to the regulation and enforcement of the incoming EU AI Act .
iii. The emerging semi-formalized cooperation between the CNIL and the French Competition Authority
The enhancement of cooperation has also been of interest for the CNIL and the French Competition Authority. In December 2023, they released a joint statement confirming their commitment to improve and clarify the modalities of their collaboration.
In June 2024, the French Competition Authority highlighted in its opinion on competition within the generative AI sector, that companies may face practices involving denial or discriminatory restriction of access to data throughout the value chain. Furthermore, agreements in which large digital companies secure exclusive access to content creators’ data or pay them significant fees that are difficult for competitors to match could be considered anti-competitive, such as cartels or abuse of dominance. The French Competition Authority recognizes that access to user data remains a critical issue, several industry players reporting that major companies continue to employ strategies that restrict third-party access to user data, often leveraging legal frameworks like data protection or security concerns to do so.
In November 2024, the CNIL published its conclusion of the Lasserre report, which aimed to examine the implications of the connection between data protection and competition for the CNIL and its regulatory practices.
Regarding operational consequences for the CNIL, the report explains that even if GDPR is not, per se, an economic regulation, economic and competitional impacts are significant for its effectiveness. In practice, the CNIL must enhance its understanding of competition issues to integrate them into its work. To have a better understanding of the competitive stakes, cross-trainings sessions on competition and data protection issues for both authorities could be organized. When necessary, the CNIL could also seek the opinion of the French Competition Authority, as it did for the first time in 2023 as part of its recommendation about mobile applications. Concerning sanctions, the market position and data power of the involved entities would enable the CNIL to better calibrate penalties to the size of the companies and the risks their activities pose to individuals and privacy.
Furthermore, the report acknowledges that owning databases with personal data can provide competitive advantages, influencing companies’ behavior in terms of data collection and exploitation. Thus, with regard to the cooperation with the French Competition Authority, the mission encourages a formal or informal consultation of the CNIL when the combining of databases is at stake in an antitrust case, in order to examine whether any non-compliance with the GDPR in this area, even if motivated by a quest for efficiency, would not constitute an abuse of a dominant position. Concerning sanction, when the CNIL identifies potentially anti-competitive practices involving processing that is potentially non-compliant with the GDPR, the French Competition Authority could make it mandatory for a company to make a commitment to approach the CNIL with the aim of achieving compliance. Thus, whenever such practices involve personal data, the French Competition Authority could make it compulsory, after discussion with the CNIL to assess the appropriateness, to contact it. Generally, it may be advisable to informally consult the CNIL when drafting commitments related to privacy, data protection, and GDPR compliance.
C. Germany’s pioneering approach to competition and data protection convergence
Germany has been at the forefront of establishing connections between competition law and data protection, particularly through the landmark Meta Platforms case before the Court of Justice of the European Union. The German Competition Authority (Bundeskartellamt) took a groundbreaking step in 2019 by addressing Facebook’s data processing practices through the lens of competition law.
The Bundeskartellamt’s approach demonstrated how a competition authority could consider GDPR compliance as part of its assessment of abuse of market dominance. This innovative interpretation was ultimately validated by the CJEU in its 2023 Meta Platforms decision, which established the requirement for sincere cooperation between competition authorities and data protection authorities.
The German framework for cooperation between authorities is characterized by:
- Legal provisions enabling formal cooperation through Paragraph 50f(1) of the Law against restrictions on competition (GWB), which explicitly allows information exchange between competition authorities and data protection officers
- Practical implementation of cooperation mechanisms between the Bundeskartellamt and federal and state data protection authorities
- A proactive approach to addressing digital market challenges through combined privacy and competition enforcement
3. Conclusion
The convergence between data protection and competition law has become increasingly evident as personal data takes center stage in the digital economy. This evolution has led to the emergence of new regulatory approaches and cooperation frameworks between data protection and competition authorities.
Several key findings emerge from this analysis:
- The protection of personal data has become a significant parameter of competition, particularly in digital markets where data-driven advantages can reinforce dominant positions
- Cooperation between data protection and competition authorities is no longer optional but, in some cases, mandatory following the CJEU’s Meta Platforms decision
- Different models of cooperation have emerged across Member States, ranging from informal collaboration to legally mandated frameworks
- The effectiveness of regulation in the digital age requires a more integrated approach that recognizes the interconnected nature of privacy and competition concerns
Looking forward, the development of closer cooperation between data protection and competition authorities appears inevitable and necessary. This cooperation will need to be structured through formal frameworks while maintaining the distinct objectives and enforcement mechanisms of each field of law. The challenge lies in finding the right balance between preserving the independence of each regulatory framework while ensuring effective coordination to address the complex challenges posed by the digital economy.