Europe's data protection regulators told the European Commission in May that click data Google must hand to rival search engines was "highly unique", asked whether those rivals could train AI models on it, and suggested adding noise to it before any transfer. The seven-page letter, now posted on the European Data Protection Board's website, has drawn a sharp reading from Brussels lawyer Peter Craddock, who argues the board is holding the Commission to a looser standard than the one it set for everyone else in July.
In Short
Europe's privacy regulators sent the European Commission 33 comments in May on how Google must strip identifying details out of search records before sharing them with competing search engines and AI chatbots, and that letter is now public. It matters because the same regulators published general anonymisation guidelines in July that sound stricter, and a Brussels lawyer says the two documents do not line up. Several of the regulators' requests, such as deleting timestamps and limiting device types to three, appear in the final order, while others, such as adding noise to click data, do not appear in the accounts of the decision published so far.
Seven pages, sent four days after the consultation closed
The letter is dated May 5, 2026 and signed by Anu Talus, Chair of the European Data Protection Board. It is addressed to Alberto Bacchiega, Director for Digital Platforms at DG COMP, and Rita Wezenbeek, Director for Online Platforms: Economy at DG CNECT, and answers a Commission request of April 16, 2026, the day Brussels published its preliminary measures in the specification proceedings against Alphabet under Article 6(11) of the Digital Markets Act. The public consultation on those measures had closed on May 1.
The EDPB's website lists the document among its policy papers with a date of May 5, 2026, but its download link sits in a folder labelled September 2026. That places the upload about four months after the letter was sent and two months after the Commission adopted its final decision on July 16. The exchange was no secret: PPC Land's review of the full decision text earlier this month found that the Commission recorded receiving the board's written comments on May 5, and discussing anonymisation with the board on February 6, March 18, March 30 and June 15. What the board actually asked for had not been public.
"I would encourage the Commission to incorporate the suggestions included in the Annex," Talus wrote. The annex runs to 33 numbered paragraphs: five framing points and 28 specific comments. Its first footnote dates the draft joint guidelines on the interplay between the Digital Markets Act and the GDPR, which the board co-wrote with the Commission, to a "version submitted to public consultation on 8 October 2025"; PPC Land's coverage of the consultation responsesrecorded the consultation opening on October 9.
The framing paragraphs hedge with care. The board's comments "are highly contextual", paragraph 2 states, because Article 8(2) lets the Commission impose binding measures on a gatekeeper through an implementing act, and the measures "might not be easily transferrable or sufficient to achieve anonymisation in accordance with the GDPR in other cases where legal or practical circumstances differ." Paragraph 3 adds that the contribution "should not be interpreted as a comprehensive assessment or general endorsement", citing in a footnote "the limited time and information available at this stage of the process." National data protection authorities, paragraph 5 notes, keep their powers over Alphabet and over every recipient.
The lawyer's two questions
Those caveats are where Peter Craddock starts. A data, cyber and technology lawyer who joined Osborne Clarke in Brussels as a partner in September 2026, after four and a half years heading the EU data team at Keller and Heckman, he published his reading on LinkedIn this month. He called the letter "a careful yet awkward attempt to comfort the Commission" while sidestepping an open conflict with the board's Guidelines 02/2026 on Anonymisation, and reduced the dispute to two questions: "Whose data needs to be anonymised?" and "Which measures are sufficient for data to cease being personal data?"
On the first, the board sides with the Commission. Anonymisation under Article 6(11), paragraph 1 states, concerns "only anonymisation of the personal data of the end user generating the data". Anyone else identifiable in the data, including an end user who is searched for by someone else, stays within the GDPR, with Alphabet and each recipient acting as separate controllers. Craddock wrote that the board is "adding words to Art. 6(11) based on - in my view - a questionable reading of Recital 61", and found that remarkable given how hard, as he sees it, the board has fought against giving proper weight to Recital 26 of the GDPR. That recital, on means reasonably likely to be used for identification, sat at the centre of EDPS v Single Resolution Board in September 2025, and in February 2026 the board and the European Data Protection Supervisor objected to the Commission's proposed codification of that judgment. The letter itself cites the SRB ruling twice.
The second question carries more weight. The guidelines adopted on July 7, 2026, which replaced the 2014 Article 29 Working Party test, list investigative journalists, intelligence agencies, rogue employees and cybercriminals among entities that may be relevant to an identifiability assessment, and treat the assumption that people obey the law as rebuttable where, among other things, a prohibition is not effectively monitored or enforced. Craddock argues the letter looks only at authorised recipients. He quotes the guidelines as saying that "contractual measures can typically be subject to revision, or may even be disregarded entirely by the parties", and sets that mistrust against the letter's acceptance of contracts.
One citation in his post does not match the letter. Craddock attributes the phrase "highly contextual" to paragraph 7; in the published text it appears in paragraph 2. His references to paragraphs 9, 13 and 17 match.
Contracts in a supporting role
What the letter accepts is precise. Technical measures that alter the data "can be complemented by organisational, administrative and contractual measures, when they derive from legally binding requirements imposed on the gatekeepers through an implementing act", paragraph 7 states. "While, in some cases, a residual risk of re-identification remains, the result of an anonymisation process should be that such overall risk of re-identification is, in practice, insignificant."
From there, the board pushes on wording rather than principle. Paragraph 9 asks the Commission to state "that technical measures should play a prominent role in making the risk of re-identification insignificant". A footnote wants it made clear that other measures "are not sufficient, on their own, to render the likelihood of identification insignificant", citing paragraphs 36(e), 37 and 69 of the April draft and the title of its section 3.2.2 as examples. Paragraph 8 notes that some technical measures had already been tightened after early exchanges on an earlier version.
Is that a departure from the July guidelines, or an application of them? The letter rests its answer on the legal setting, and a footnote adds that the implementing act's effects "should be both durable and verifiable". The final decision layers ISAE 3000 assurance reports, access logging, segregated processing and Commission oversight on top of the contracts, while the guidelines' worry is prohibitions nobody enforces. The Commission's own residual-risk test also names an unintended outsider, alongside the recipient and a malicious employee, as a possible adversary, although the letter does not engage with it.
Craddock's objection is about predictability. Data protection, he wrote, "is hard enough to get right without regulators changing views from one context to the next". His closing line offers a binary: "Either the EDPB should stick to its principles and denounce the Commission's proposals as insufficient, or it should adapt its Guidelines." The argument overlaps with one Alphabet made in the proceedings, that contracts cannot compensate for identifiability that survives technical processing, but the post does not oppose the data sharing itself. One reply, from Uwe W. Fiedler, a retired chief privacy officer, asked where the logic would stop: "I wonder if the EU Clinical Trial Regulation could then also be defined as a specific, regulated environment".
Click data the board called "highly unique"
The most substantive technical comment is paragraph 17. Click data, as defined in section 2.1.3 of the draft, "is highly unique", the board observed, and if linked with other data could expose more about end users, "at least in some cases". It asked the Commission to consider "further transforming the sequence of viewed URLs/blocks", for example by "shortening/truncating URLs or introducing a threshold for removal, or adding noise to click data."
"If the risk remains, wouldn't the EDPB normally say it's personal data?" Craddock asked.
The same paragraph carries a detail for advertisers. The board said it understood from the Commission that "campaign or advertisement ID that are used by advertisers to measure advertisement performance would be deleted", and asked for that to be written into the text.
What reached the final decision? PPC Land's review of the decision found that ad URLs are removed and each paid result is replaced by a placeholder recording only that an ad appeared and its module type, such as a text ad block; it does not mention campaign identifiers specifically. Click-back times and interaction durations such as hovering and viewing are now binned at the 20th, 40th, 60th and 80th percentiles within each metadata group. For click-back times, that replaces six fixed intervals, from 0-10 seconds to more than 20 minutes, proposed in the April draft. The order and duration of clicks, clicks back to the results page, hovering, scrolls, swipes and expansions all stay in scope.
Neither that review nor the account by Damien Desfontaines, the privacy engineer who advised the Commission, describes noise or URL truncation for click data. Desfontaines wrote that formal guarantees of the kind differential privacy provides were ruled out as incompatible with reasonable utility, and linked the larger geographic regions, the higher metadata threshold and the exclusion of sponsored results to findings from Google's own testing.
Training AI models on the dataset
Paragraph 11 takes up one of the most contested eligibility points in the case. AI chatbots specialised in search, and general chatbots "to the extent that they provide search functionalities", could qualify as recipients, the board noted. "The inclusion of AI chatbots is likely to have various impacts both on the scope of the reuse of the Search Data and on the reasonably likely means of re-identification." Having first understood that recipients could train any AI model on the dataset, it invited the Commission "to clarify if and to which extent data could be used for training purposes."
Because the dataset may still hold personal data about people other than the searcher, paragraph 12 adds, each recipient needs a legal basis under Article 6 of the GDPR, and the board pointed to its Opinion 28/2024 on AI models for how legitimate interest applies. The letter dates that opinion to December 17, 2024; PPC Land's report at the time gave December 18. Paragraph 13 repeats the board's caution on extraction, with a footnote stating that "it is possible, in some cases, to use reasonably likely means to extract personal data from some AI models, or simply to accidentally obtain personal data through interactions with an AI model (for instance as part of a chatbot)."
Craddock reads a tension into that warning. If personal data could be extracted from models trained on the dataset, personal data must remain inside it, which sits awkwardly with accepting that end users' data was anonymised at all.
Paragraph 16 targets a carve-out. The draft's data governance requirements would not extend to cases where "the contribution of the Search Dataset is negligible, indirect or no longer reasonably traceable, provided that appropriate safeguards are in place". The board wanted the prohibitions on linking and re-identification to reach any models and outputs that could enable re-identification, and the safeguards specified in line with paragraphs 96 to 108 of Opinion 28/2024.
The final decision draws a line. Recipients may use the data to improve grounding and retrieval for AI chatbots, but a footnote excludes training the general-purpose language model underlying a chatbot. Any recipient that trains or fine-tunes models on the data, including ranking, retrieval or chatbot models, must test them before deployment to confirm they do not reproduce dataset content in a way that exposes users, and must document them. Whether the Commission also replaced "unrelated" purposes with "other" purposes, as paragraph 14 requested, is not visible in the published accounts.
The allowlist and the word combinations
Paragraph 18 raised a concern Alphabet also pressed. "The EDPB reminds that measures applied to the search data should consider not only individual attributes but also their combination," it states, suggesting an allowlist built "on groups of words and combination with entities."
No published account of the final design describes an allowlist of word groups. Personal data detectors extract names, addresses, phone numbers, coordinates, IBAN numbers, credit card numbers and similar identifiers as whole entities, and the rest of the text is split into single words. A record survives only if every entity in it, single words included, was used by more than 50 signed-in users across 13 months of European searches, and the query is shorter than the 95th-percentile length for its language. The decision answered Alphabet's version of the combination argument by noting that thresholds apply to entities, not only to words, and work alongside the other steps.
Two related comments did land. Paragraph 24 asked for both conditions to be cumulative, and the final text keeps a record only if it passes both. Paragraph 23 warned about detector false negatives; Alphabet must now tell the Commission which publicly available detectors it will use, with their confidence thresholds, and report their performance and suppression shares to recipients every quarter.
Paragraph 33 asked that thresholds form part of any periodic review. One has already moved: the metadata threshold rose from 50 signed-in users in the April draft to a floor of 1,000 users sharing a NUTS 3 region, device type and inferred language, which Desfontaines described as k-anonymity at work.
Housekeeping that reached the text
A cluster of drafting requests maps closely onto the adopted measures described in PPC Land's review:
- Timestamps. Paragraph 22 asked for timestamps to go entirely, with records tied only to a date. The final text drops the timestamp, keeps the day and ships data in daily batches.
- Device type. Paragraph 25 asked for a closed list of "mobile handsets, desktops and tablets". The decision uses desktop, mobile and tablet.
- Encryption. Paragraph 27 asked for "appropriate key management". The contractual terms require state-of-the-art encryption with proper key management.
- Attempts. Paragraph 15 asked that attempting to link or re-identify be banned, not only succeeding. The attempt alone is a breach, according to Desfontaines.
- Frequency. Paragraph 19 asked for daily sharing to be stated consistently. The decision requires daily batches, with a latency of no less than seven days.
Paragraph 28 was overtaken by events. The board wanted security measures on the sharing API, warning that "the API used internally is designed on the basis of specific assumptions that may no longer hold when it is exposed externally", and suggested requiring coverage of the top 10 OWASP API Security risks. The final decision dropped the API requirement altogether in favour of the method Alphabet uses internally, a change Alphabet welcomed.
What cannot yet be checked
Paragraphs 29 to 32 deal with suspension and termination: the meaning of "serious and irreparable damage to the anonymisation of end users' personal data", the tension between erasing a dataset after termination and preserving it for an investigation, and which lead supervisory authority must be notified under Article 56(1) of the GDPR. Because regulators would learn of a suspension at the same moment as the affected search engine, the board observed, "in practice it will be unlikely that they would have already taken any investigative steps". The copy of the decision PPC Land reviewed stops at recital (1130) on page 298, before those sections.
Paragraph 26 asked the Commission to confirm that Alphabet need not extend retention or collect new data, because "Article 6(11) DMA does not in itself provide a legal ground under Article 6(1) GDPR for Alphabet to initially collect personal data from end users." The published accounts do not address it. On review, the board warned that "the likelihood of re-identification typically increases over time", a point a footnote calls "particularly relevant in the context of AI". The decision provides for an evaluation within two years and allows reopening under Article 8(9) on new facts.
Alphabet had its own complaint about the channel. According to the decision, the company argued its right of defence was compromised in part by the refusal to share minutes of the Commission's meetings with the board. The newly posted letter covers the written comments, not those meetings.
Why the letter matters beyond Google
For search marketers, the practical content is narrow but concrete. The board's understanding that advertiser campaign identifiers would be deleted, together with the removal of ad URLs, means user behaviour around ad blocks can reach rival ranking systems while the identity of the advertiser behind each slot stays out. The board's insistence that national authorities keep full GDPR powers over recipients also puts every search engine or AI assistant that takes the data under ordinary privacy enforcement, on top of the Commission's contractual regime.
The wider stake is the standard itself. The board's anonymisation guidelines remain open for comment until October 30, 2026, and their treatment of contracts, legal prohibitions and relevant entities will shape how regulators assess pseudonymisation and anonymisation claims across clean rooms, identity graphs and measurement datasets. The Google letter shows the same regulator accepting a contract-backed model where an implementing act imposes it. Whether that stays confined to Article 6(11), as the letter insists, or shapes the final guidelines is the question Craddock has put on the record. Alphabet must finalise the anonymised dataset by November 2026 and its pricing by January 2027, under the schedule the Commission set in July.
Timeline
- December 17, 2024 - EDPB adopts Opinion 28/2024 on AI models, later cited in the letter on legitimate interest and data extraction
- September 4, 2025 - Court of Justice rules in EDPS v Single Resolution Board
- October 8-9, 2025 - Draft joint DMA-GDPR guidelines go to public consultation
- January 27, 2026 - Commission opens Article 6(11) specification proceedings against Alphabet
- February 6, March 18 and March 30, 2026 - Commission discusses the anonymisation measures with the EDPB
- February 10, 2026 - EDPB and EDPS object to the Commission's proposed change to the personal data definition
- March 13, 2026 - More than 100 responses to the joint DMA-GDPR guidelines consultation are published
- April 16, 2026 - Commission publishes preliminary measures and invites the EDPB to comment
- May 1, 2026 - Public consultation on the preliminary measures closes
- May 5, 2026 - Anu Talus sends the EDPB's 33 comments to DG COMP and DG CNECT
- June 15, 2026 - Commission holds a further discussion with the EDPB on anonymisation
- July 7-8, 2026 - EDPB adopts Guidelines 02/2026 on Anonymisation and opens consultation
- July 16, 2026 - Commission adopts the binding search data decision
- September 10, 2026 - Full decision text circulates and Damien Desfontaines publishes his account of the method
- September 2026 - The letter appears on the EDPB's website; Peter Craddock publishes his critique on LinkedIn
- October 30, 2026 - Consultation on Guidelines 02/2026 closes
- November 2026 - Deadline for Alphabet to finalise the anonymised dataset
- January 2027 - Deadline for Alphabet's final pricing offer
- By July 16, 2028 - Two-year evaluation of the measures
Related PPC Land coverage
- Google loses fight to strip 90%+ of unique queries from EU rivals' data - The full decision text, including the four-step anonymisation method, the model testing rule and the Commission's meetings with the EDPB.
- Searches with words used by under 50 people won't reach Google rivals - Damien Desfontaines' account of how the method was designed and what changed after Google's testing.
- EDPB replaces 2014 anonymity test with 3-part framework for ad data - The guidelines Craddock measures the letter against, with their list of relevant entities and treatment of legal prohibitions.
- EU moves to force Google to open search data to rivals under DMA - The April 2026 preliminary measures the letter comments on, including the six click-time intervals and the API.
- EU forces 90%-dominant Google to share its search data - The July 16, 2026 adoption of the binding decision and its deadlines.
- Brussels forces Google to hand rivals its search data - The Commission's rollout schedule and Google's same-day privacy objections.
- EU publishes 100+ responses on rules that could reshape big tech ad targeting - The joint DMA-GDPR guidelines the letter relies on for its anonymisation framework.
- Court clarifies personal data definition in pseudonymized transfers - The SRB judgment the letter cites twice.
- Europe's privacy watchdogs reject Commission's plan to narrow GDPR protections - The board's February 2026 resistance to codifying the relative approach to personal data.
- European data watchdog clarifies privacy rules for artificial intelligence models - Opinion 28/2024, which the letter cites on legitimate interest and model extraction.
- Europe's top court hands data controllers new weapon against privacy watchdogs - Earlier commentary from Craddock on challenges to EDPB opinions.
- EDPB's first-ever DPIA template finally lands - but experts want more - Craddock's criticism of another EDPB document in April 2026.
Summary
Who: The European Data Protection Board, through its Chair Anu Talus, writing to Commission directors Alberto Bacchiega (DG COMP) and Rita Wezenbeek (DG CNECT); Alphabet, the gatekeeper required to share Google Search data; rival search engines and AI chatbots eligible to receive it; and Peter Craddock, an Osborne Clarke partner in Brussels who published a critique of the letter.
What: A seven-page letter with 33 comments on the Commission's preliminary anonymisation measures for Google Search data sharing under Article 6(11) of the Digital Markets Act. It accepts contract-backed anonymisation in the specific setting of an implementing act, calls click data "highly unique", suggests noise or URL truncation, asks how far recipients may train AI models on the data, and requests numerous drafting fixes. Several of those fixes appear in the final decision, while others, including added noise and word-group allowlists, do not appear in published accounts. Craddock argues the letter is at odds with the board's July 2026 Guidelines 02/2026 on Anonymisation.
When: The letter is dated May 5, 2026, four days after the consultation closed and more than two months before the July 16, 2026 decision. The copy on the EDPB's website sits in a September 2026 upload folder, and Craddock's post followed the same month.
Where: Brussels, covering Google Search data generated by users in the European Union, with national data protection authorities across the EU retaining powers over recipients.
Why: The letter shows what Europe's privacy regulators asked for before the Commission fixed the rules on how Google's search logs are anonymised for competitors, and which requests survived. The dispute over whether contracts can stand in for technical anonymisation reaches beyond this case, because the board's general guidelines, still open for comment, will set the standard for advertising datasets across Europe.
Discussion