The European Commission's full reasoning behind its July 16, 2026 order on Google Search data runs to more than 300 pages, and it records Brussels rejecting Alphabet's anonymisation method, its value-based pricing, its three-year cap on access and its attempt to keep AI chatbots out of the programme.

In Short

Google has to give some of its search data to smaller search engines and AI chatbots in Europe, and the European Commission has now published its long explanation of exactly how. The explanation matters because it shows Google's own privacy method threw away almost every rare search, which made the data close to useless for the rivals it was meant to help. Under the new rules, rivals get fresher and far more detailed data, locked behind contracts and audits, at a price based on what the sharing costs Google rather than on what Google thinks the data is worth.

What the document is

The text is Commission Implementing Decision C(2026) 5091 final, adopted in Brussels on July 16, 2026, in case DMA.100209 under Article 8(2) of the Digital Markets Act. It is a non-confidential version. Business secrets have been replaced by square brackets, ranges or descriptive placeholders such as "[description of Alphabet's internal system processes]", and the decision states that only the English text is authentic.

When the decision was adopted, the Commission published the annex of final measures and said the full reasoning would follow later. That reasoning is what has now circulated. It is dense: 1,130 numbered recitals in the copy reviewed for this article, more than 1,300 footnotes, and a table of contents running to page 338.

A caveat belongs at the top. The copy examined here ends mid-sentence at recital (1130), on page 298, in the middle of the section describing a synthetic test dataset. Everything after that point is missing from the reviewed text. That includes the third test sample, the processes for finalising the dataset and pricing, the rules on refusing, suspending and terminating access, the provision on financial penalties, the proportionality assessment and the operative conclusion. Where this article refers to deadlines or procedures that sit in those pages, the information comes from earlier reporting, not from the document itself.

The decision does not find that Alphabet breached the law and imposes no fine. A specification decision does something narrower and, in operational terms, more intrusive: it writes out what compliance with an existing obligation must look like, down to the field level. The obligation here is Article 6(11) of the regulation, which requires a gatekeeper that runs an online search engine to give rival search engines, at their request, access on fair, reasonable and non-discriminatory terms to ranking, query, click and view data "in relation to free and paid search generated by end users". Any of that data which constitutes personal data must be anonymised.

The dataset almost nobody bought

To understand why Brussels intervened, it helps to start with what Google already offered.

The Commission designated Alphabet as a gatekeeper on September 5, 2023, according to the decision, listing eight core platform services including Google Search. PPC Land's earlier coverage, drawing on the Commission's press material, has dated the designation to September 6, 2023; the decision's own date is used here. From March 7, 2024, Alphabet had to comply with Article 6(11). It responded by opening what it calls the European Search Dataset Licensing Program on March 6, 2024, the day before the obligation applied.

The programme, as described in Alphabet's compliance report of March 6, 2026 and summarised in the decision, offers a dataset with a small number of fields: query string, country, device type (desktop or mobile and tablet, where anonymisation allows), query count, result, average rank, impression count and click count. For ordinary blue links the result field carries the exact URL. For anything else, such as a top text ad block or a knowledge panel, it carries only the type. There are no ads URLs, no URLs from embedded results, no interaction data beyond clicks, and no location finer than country.

Alphabet releases the data once a quarter with a lag of one quarter, so the information is on average 4.5 months old when a licensee receives it. It arrives as JSON downloadable from Google Cloud. The full European Economic Area file is approximately 1.5 TiB a quarter and contains around 30 billion rows. Buyers can take the whole EEA, single countries, or 10% or 50% samples. Access lasts a maximum of three years.

The privacy protection rests on two frequency thresholds. The first, which the decision calls the k-threshold, admits a query only if at least 30 signed-in users worldwide issued the identical text over the previous 13 months; a query that passes stays on an allow list for five years. The second, the m-threshold, releases rank, impression and click figures for a result only if at least five signed-in users viewed that result in a given country, on a given device type, during the quarter. Where that fails, Alphabet drops the device breakdown, then the country, and releases the figure at EEA level if it still qualifies.

The consequence is stark. According to Alphabet's reply to a Commission request for information dated December 22, 2023, the two thresholds remove between 90 and 100 percent of unique queries and between 30 and 40 percent of query volume. Both figures appear in the decision as redacted ranges.

Pricing is fixed per thousand queries and scales with the buyer's revenue. The decision puts the fee between EUR 1.50 and EUR 9 per thousand queries, which translates to an indicative price between EUR 1.6 million and EUR 9.9 million for a full quarterly EEA dataset. Alphabet told the Commission it built that schedule from three reference points: the price of scrapers selling data on search result impressions, ComScore's search query data, and Microsoft's syndication offering.

Contract terms add further conditions. Applicants must operate an online search engine, show a record of safeguarding user data, be financially viable, not be controlled directly or indirectly by a non-EEA state actor, and not run a search engine optimisation business. Licensees may use the data only to optimise a search engine aimed at EEA users, must meet data security requirements, may not attempt re-identification, must delete the data within a year and may not pass it on.

How many companies took the offer? The number of applicants is redacted. The number of licensees is not: one. That single licensee, the decision says, has so far acquired only a small sample. The Commission describes the take-up as "almost absent" despite significant interest from rival search engines, and it treats that fact as evidence that the programme does not achieve what Article 6(11) requires.

Why Brussels says the data matters

The decision's economic case is familiar to anyone who followed the United States search trial, but it is set out with unusual directness.

Search engine quality rises with the number of users, because operators store what people searched for, what results they were shown and how they interacted with those results, and then use that record to improve ranking. Google Search, the decision says, holds an estimated global share of around 90 percent, citing Statcounter data accessed on February 19, 2026, against around 5 percent for Microsoft Bing. That gap in scale produces a gap in data, and the data gap is, in the Commission's words, a considerable barrier to entry and expansion.

The Commission extends that argument explicitly to generative AI. Recital (16) states that chatbots such as ChatGPT, Mistral Vibe and Claude have innovative large language models, but that Alphabet's own chatbots surpass them at searching and retrieving web content because of the ranking, query, click and view data accumulated from Google Search. As AI chatbots with search functions compete with Gemini and AI Overviews on web-scale indexing, retrieval, relevance, ranking and freshness, the Commission warns that the underlying sectors risk becoming dysfunctional.

Most challengers, traditional or conversational, depend at least partly on syndication, sending their users' queries to a larger partner and displaying that partner's results. The decision lists four ways shared data could reduce that dependence.

The first is crawling and index building. Crawling the whole web is expensive and favours first movers, and many large sites restrict access to a handful of crawlers to save bandwidth. Nearly all websites admit Google's crawler, the decision notes, because disappearing from Google's index is not an option. Shared data would let a rival see which URLs users are shown and click on in Google that are missing from its own index.

The second is retrieval and ranking. Past interactions reveal which results satisfied which queries, and this is most valuable for low-frequency, or long-tail, queries that a small engine rarely sees at all.

The third is results page layout. Search data informs whether to show a knowledge panel, a direct answer, a carousel, tabs or rich image and video results, and where to place individual URLs.

The fourth is query understanding: spell checking, auto-suggestion, auto-completion and disambiguation. The decision's example is the query "jaguar", which could mean the animal or the car maker. If users who type one query frequently follow it with a similar second query without clicking anything in between, that pattern suggests the second query would make a useful suggestion.

The Commission also names who else it expects to benefit. Business users, recital (20) says, gain "additional sources of relevant organic web traffic" and "a more competitive marketplace for the placement of search ads". End users gain alternatives that could differ from Google, for example through a privacy model, support for environmental causes, or a conversational interface; the footnotes point to Qwant and Ecosia as illustrations of the first two.

Two and a half years of talks before the formal case

The record of engagement before the proceedings opened is long, and the Commission sets it out in detail because Alphabet argued that no genuine dialogue took place.

On December 12, 2023, at a high-level meeting, the Commission told Alphabet that its compliance proposal needed improvement. On September 18, 2024, it said the proposal required significant improvement, listing concerns that would later become the backbone of the decision: an anonymisation method leaving little or no useful data, aggregation that reduced utility, the exclusion of paid and advanced results, a sharing lag that appeared too long and commercial terms that made the offer unattractive. Further meetings followed on December 11, 2024, January 10, 2025 and November 11, 2025, alongside compliance workshops on March 21, 2024 and July 1, 2025. Between November 28, 2023 and November 13, 2025, the Commission sent Alphabet 12 requests for information on Article 6(11). It also engaged with more than 20 third parties over the same period.

One episode receives particular attention. On March 26, 2025, the Commission asked Alphabet for access to a representative one-week sample of Irish Google Search data plus accompanying statistics, so it could assess Alphabet's anonymisation approach itself. Effective access to the data came on July 1, 2025, and to the statistics on July 13, 2025. The Commission then found inconsistencies in the dataset, asked Alphabet to explain them on July 23, 2025, and received a new dataset on September 12, 2025. According to the decision, inconsistencies in the resubmitted statistics were flagged again and not addressed. The Commission's summary is blunt: Alphabet "has frequently provided delayed and incomplete replies" to its requests.

On January 26, 2026, the Commission told Alphabet it intended to open specification proceedings. It did so the next day, January 27, by Decision C(2026) 582 final. Article 8 of the regulation then imposed a timetable with little slack: preliminary findings within three months, a final implementing act within six.

A state-of-play meeting followed on February 5. On February 19, at Alphabet's request, the Commission sent a high-level outline of the anonymisation measures it was exploring. Topic meetings took place on February 11 (contractual terms), February 12 (fair, reasonable and non-discriminatory terms), March 2 (search infrastructure and data) and March 3 (anonymisation). Between the opening and the preliminary findings the Commission issued 11 more requests for information, bringing the total sent before the preliminary findings to 23.

Alphabet used the period to file two submissions of its own. On April 7, 2026 it sent a legal opinion on the interplay between the anonymisation requirement and the General Data Protection Regulation. On April 14 it sent a paper whose title states its position plainly: "Art. 6(11) does not require Google to support GenAI grounding".

On April 16, 2026, 11 days before the statutory deadline, the Commission communicated its preliminary findings and published a non-confidential summary for public comment. PPC Land covered those proposed measures at the time. Alphabet requested access to the file on April 17 and received the documents cited in the findings that day. Its external lawyers entered a data room at the Commission's premises on April 20. Access was extended to April 27, and the room stayed open until April 30 because, according to the decision, the report Alphabet's counsel produced on April 27 did not comply with the data room rules.

The consultation closed on May 1 with more than 140 contributions. Alphabet asked for more time to answer the preliminary findings, received an extension to May 15, asked again, and was given until the end of Sunday, May 17. Its response arrived on May 18. A letter setting out an alternative anonymisation approach followed on May 19.

The next weeks brought a sequence of procedural requests. On May 26 the Commission hosted a tripartite meeting between Alphabet and four redacted market participants on anonymisation. On May 27, Alphabet asked the Commission to carve anonymisation out of the proceedings altogether, arguing there was not enough time left to develop robust measures. Its letter of June 11 went further, proposing 60 days of development with an advisory privacy panel appointed by the Commission, 30 days of independent testing, and then a reopening of the proceedings under Article 8(9) to make the result binding.

The Commission refused. Article 8(2) contains no exception to the six-month limit, the decision says, and Article 8(9) allows reopening only for material changes in facts, incomplete or misleading information, or ineffective measures. Using it to buy time to assess facts already collected "would therefore constitute an abuse of the process", in the Commission's words. At a meeting on July 2 the Commission explained that position, and on July 5 it confirmed in writing that anonymisation would be specified in the decision.

In between, the Commission shared draft revised measures and an external testing report with Alphabet on June 8, followed by the underlying code on June 10. Alphabet filed observations on the revised measures on June 15 and on the testing report on June 18. Draft final measures went to Alphabet on July 3 and July 7, and a draft of the future review clause on July 6. Nine further requests for information were sent after the preliminary findings. The Commission also discussed the anonymisation measures with the European Data Protection Board on February 6, March 18, March 30 and June 15, 2026, and received the board's written comments on May 5.

Two small inconsistencies in the text are worth recording. Recital (44) places the publication of the consultation on April 16, 2026, while recital (1012), in the pricing section, refers to the consultation "opened on 28 April 2026". And recital (54) dates Alphabet's note on contractual measures to June 4, while recital (136) calls it a submission "dated 3 June 2026". Neither changes the substance, but both sit in a document that will be read closely in any court challenge.

The consultation campaign

The most unusual passage in the decision has nothing to do with data engineering. It concerns how Alphabet responded to the public consultation.

According to recital (47), after the consultation opened Alphabet contacted more than 60 third parties by email, calls and meetings. The list included privacy academics, think tanks, advertisers, publishers, and consumer and industry associations. Alphabet shared its criticism of the proposed measures, asked recipients to take part in the consultation and, in some cases, asked them to spread its views to others. Its materials were organised around at least three campaigns, on privacy risks, advertisers' concerns and publishers' concerns, plus a general paper titled "DMA search data sharing input" with a one-paragraph view on each section of the consultation.

The decision describes specific artefacts. A one-page infographic titled "Digital Markets Act 6(11) Privacy Concerns" went to at least 15 stakeholders. It stated that data would be released "in the wild" and described the anonymisation measures as "name scrubbing". It carried a call to respond and a QR code linking to the consultation page. A similar pamphlet on advertiser concerns, sent to at least 10 stakeholders, repeated the "in the wild" language and included a "Take Action Today" link. The Commission's characterisation is direct: these materials provided "a partial, distorted and biased view" of the preliminary measures, ignoring that the data would go only to eligible, audited search engines bound by contract.

What happened next is documented through Alphabet's own replies to requests for information dated May 19 and June 5, 2026. At least 30 recipients of the outreach made submissions or contacted the Commission, most expressing views similar to Alphabet's. Some shared draft submissions with Alphabet before filing. In one exchange quoted in the footnotes, Alphabet responded to a draft with the line: "I had our Europe legal team review the paper and they confirmed everything is good and accurate". In others, Alphabet appears to have proposed revisions. At least 18 respondents who were included in the outreach had, or had had within the previous two years, a relationship with Alphabet through membership, affiliation, sponsorship, funding, research affiliation or employment. And Alphabet "has also confirmed that several respondents were remunerated by Alphabet for their participation in the Public Consultation".

The decision adds a further observation. In one outreach exchange, before the consultation was discussed, Alphabet and the third party talked about other paid cooperation such as papers and events. Even where those parties were not paid for their submissions, the Commission writes, "it at least cannot be excluded that the potential future remuneration played a role".

A separate footnote addresses the volume of hostile individual submissions. More than 60 submissions that Alphabet identified as critical of the measures were very short, unsubstantiated responses from individuals. Several objected to data transfer in principle, or appeared to believe the Commission itself would receive search data. According to the decision, several appear to have been filed shortly after Alphabet told the Politico Pro Fair Play newsletter of April 27, 2026 that "it took its security team less than two hours to reverse-engineer the European Commission's proposed search-data sharing rules and link individual queries back to named users, including matching some to sensitive details like pregnancy".

Does the campaign change the outcome? The Commission says no. It states that it assessed every contribution on its merits "irrespective of whether contributions originated from organisations connected to Alphabet or of Alphabet's influencing campaign", and that it describes the campaign for transparency rather than as grounds to discount any input. Alphabet, for its part, had argued that the consultation was not fair and objective, that the Commission leaned on "self-interested third parties", and that some questions were leading. The decision rejects each claim, noting among other things that respondents were free to rate data types as "not important" and that several gave negative answers.

Who counts as a rival search engine

Eligibility was always going to be contentious, because it determines whether the obligation reaches the AI assistant market or stops at conventional search.

Alphabet's position was that AI chatbots with search functions are not online search engines within the meaning of the law. It classified them instead as virtual assistants, pointing to their different purpose of use and their alleged inability to answer navigational queries, meaning searches where a user types a site's name to reach it.

The Commission disagrees on each count. The definition in Article 2(5) of Regulation (EU) 2019/1150, which the Digital Markets Act borrows, covers a digital service that lets users input queries to search, in principle, all websites, on any subject, in any input form, and returns results in any format. The reference to "any subject", the decision reasons, concerns the topic of a query, not a classification by user intent. And chatbots can in fact handle navigational queries: they include links in answers, provide them when asked, or can be configured to do so, as with a custom instruction on an unnamed service directing it to return a site's main link whenever only a site name is entered.

The technical description of how these products work is notable in its own right. The decision describes a dual architecture in which a language model generates text, while a separate search component checks the current state of the web to retrieve information and avoid hallucinations. That retrieval process, commonly built with retrieval-augmented generation, is what the Commission calls grounding. In its view the search component "does not differ from that of traditional OSEs". It crawls, indexes, processes queries, retrieves and ranks. One unnamed market participant, the decision records, is building its own search engine to serve approximately 80 percent of its traffic from its own index, with syndicated results covering the rest. Grounding by a third-party chatbot, or by Gemini, therefore counts as a search engine function.

So the final measure requires Alphabet to share data with any undertaking providing an online search engine in the EU, and in the EEA once the regulation is incorporated into the EEA Agreement, "even if the OSE is provided as part of a broader service". Consultation responses were mixed on this point, the Commission notes, but largely argued policy rather than law.

Eligibility is not unlimited. Alphabet may reject an applicant on four grounds. The first is that the applicant is subject, directly or indirectly, to EU sanctions or restrictive measures, such as those imposed in response to Russia's actions in Ukraine or on North Korea. The second is control, legal or factual, by a third country posing a serious and structural non-technical cyber security or data protection risk; the decision gives four indicators, namely laws requiring companies to report software vulnerabilities to the state before they are known to be exploited, independent evidence of that practice, an absence of effective judicial remedies and democratic oversight, and substantiated incidents of state-controlled threat actors running malicious campaigns.

The third ground is that the applicant is not an established company or credible new entrant. That test is quantitative: either two consecutive years providing search services in the EU, or foundation less than two years ago with more than EUR 50 million in capital investment, and in both cases at least 50,000 average monthly users in the EU over the past year. The fourth applies where data would be transferred outside the EEA and Alphabet, as controller and exporter, cannot ensure a level of protection essentially equivalent to that in the EEA, following the logic of the Court of Justice's Schrems judgments.

Alphabet wanted a higher user bar. In its response to the revised measures, it argued that 50,000 monthly users would not filter out non-established providers and proposed a figure based on the smallest search engine that qualified for its Article 6(3) choice screen. That number is redacted. The Commission rejected the proposal because Article 6(3) expressly limits choice screens to the "main" providers, whereas Article 6(11) refers to "any" provider. It concedes that some genuine new entrants will fall below the thresholds, but suggests that recipients may improve the syndication they offer to smaller engines, which could in turn help those engines grow past the line.

Two further safeguards are layered on top. Alphabet may ask the Commission, under the exemption procedure in Article 10, to relieve it of the obligation for an individual applicant where there are credible indications of a threat to public security. And no eligibility check, transfer assessment or security request can replace the requirement that every applicant first obtain an independent assurance report. Alphabet had also argued that foreign governments, citing the United States in particular, could seize the data through intelligence laws; the Commission's answer is to fold due diligence on international transfers into the eligibility assessment.

Parity as the governing rule

The concept that drives almost every data measure in the decision is parity. Subject to anonymisation and technical feasibility, Alphabet must share ranking, query, click and view data on par with what it collects for the purpose of optimising its own search engine.

Alphabet contested the idea from the start. Article 6(11), unlike Articles 6(5) and 6(7), does not mention parity, it argued. The anonymisation requirement and the disclosure of only part of its data contradict the principle. The legislator chose not to impose horizontal interoperability. And more broadly, Alphabet claimed that the measures expropriate its intellectual property, because recipients could copy the output of its algorithms, imitate those algorithms and free-ride on its investment. It also argued that Article 6(11) is not clear or precise enough to justify what it described as an expropriatory disclosure, and that the Commission was usurping the legislator's role.

The Commission's answer is textual. Article 6(11) names the categories of data the legislator considered a barrier to entry when held by a gatekeeper, and nothing in the article or its recital suggests any limit on sharing beyond anonymisation. Any partial or filtered access to those categories, it concludes, "does not have a basis" in the provision.

What the query data now covers

The decision specifies the minimum. For query data, Alphabet must share, for each access point, the query as the user typed it, the query as modified by the user or by Google, the content of any query modifiers and an identifier of the type of modification, plus three metadata attributes: user location, query language and device, with mobile, desktop and tablet distinguished.

Modification here has a precise meaning. The current dataset already folds in queries changed through query shortcut chips, autocomplete, entity results, query suggestions, the "see results about" feature, autocorrect and advanced search filters, but it does not separate initial from modified queries and does not show the content of the modifications offered to the user. The decision requires both.

The larger fight was over access points. Google Search receives queries through its website, its mobile application including Circle to Search, the Android Search widget, Google Lens, Google Assistant, Gemini, AI Overviews, AI Mode and text search on Android. Alphabet's current dataset, by its own account, draws on all of these except Google Assistant in part, Gemini, AI Mode, Google Lens and Circle to Search.

Alphabet argued that Gemini is a separate product rather than an access point, that queries answered by Google Assistant itself fall outside the obligation, that queries issued through syndication partners are out of scope, and that location and device information is contextual data rather than query data.

The Commission split these arguments. It holds that Lens and Circle to Search are in scope, because the legal definition of a query covers "other input", including images. AI Overviews data is already included and AI Mode data must now be added. Assistant data is covered. Gemini, the Commission concludes, is also an access point to Google Search, but the modalities of sharing Gemini data are left to further regulatory dialogue, because its internal processing "presents several specificities" that are redacted in the published text. The measures in the decision therefore do not apply as such to Gemini. On syndication, the Commission agrees with Alphabet: data generated by partners on third-party websites is not required, and the preliminary findings had merely quoted Alphabet's own public description of that access route without bringing it into scope.

For marketers watching the growth of AI answer surfaces, the practical point is that interactions on AI Overviews and AI Mode, not only on classic results pages, will be part of what rival engines receive.

Article 6(11) refers to "free and paid search". Alphabet nonetheless argued that paid results are not part of the Google Search core platform service, that sharing them is disproportionate, that the URLs would expose its advertising customers, keyword performance and winning bidders, and that disclosing them would undermine anonymisation.

The Commission rejects the scope argument at length. "Paid search" is industry language for advertising-driven results, it notes, and a term Alphabet uses itself. Search is a two-sided market with users on one side and advertisers on the other. The regulation's definition of search results in Article 2(23) covers "a paid or an unpaid result". The designation decision of 2023 already held, with Alphabet's agreement, that displaying an ad is part of the service on which it appears. And the obligation covers paid search generated by end users "on" Google Search, whether or not a particular element belongs to the core platform service.

Why would a rival search engine care about ads it cannot sell? Market participants gave the Commission two answers. First, paid results reveal intent. One wrote that, on pages carrying ads from a large travel booking site, it might infer travel intent and then check whether its own organic results and instant answers ought to have included local results. Second, ignoring ads distorts click interpretation. The decision reproduces an example built around the abbreviation "odm", which might refer to hockey results or to original design manufacturers. If 70 percent of users click a sponsored hockey result whose URL is hidden, 10 percent click an organic hockey link and 20 percent click an organic link about manufacturers, a rival without the ad information could wrongly conclude the manufacturing meaning is the most relevant.

The Commission adds that Google typically displays around seven ads, three at the top and four at the bottom, and that a large part of the first results page and of user interactions relates to ads, putting that share at approximately 70 percent. Both figures rest on a Google Ads community support thread cited in a footnote rather than on Alphabet's internal data. Market participants rated paid result data at 4.4 on a scale of 1 to 5 for importance to search optimisation, where 5 means essential.

The outcome, however, is a compromise that matters for advertisers. Ad URLs are removed as part of the anonymisation measures. The decision says it does not need to engage with Alphabet's commercial confidentiality arguments because the specified measures require only a placeholder indicating a paid result, plus the fact that a paid module was displayed and its type, such as a text ad block or product ad block. The existence of each ad and the interaction data associated with it must be kept. In other words, rivals will be able to see where on the page ads appeared, how users behaved around them and whether they were clicked, but not which advertiser's landing page sat behind them. That was, the decision notes, Alphabet's own initial proposal.

Views, clicks, dwell time and hovering

The view data specification requires every URL on a results page that generated an impression, regardless of format, whether main or associated link, and across tabs including "Videos", "Short Videos", "News", "Forums", "Web", "Books" and "Images". The current dataset excludes the "Images" tab. Each element must carry identifiers for format (text, video, photo), position in the page structure, tab and result type, with advanced results broken into sub-types such as "Direct Answer" and "Knowledge Panel". The data must also describe visual elements: the display and text of query input areas, shortcut chips, entity results, suggestions and similar features, whether tabs were shown and which, and whether paid and advanced modules were displayed.

That level of detail requires a shared vocabulary. The Commission's classification of the SERP follows industry usage, dividing it into organic results, paid results and advanced results, the last covering enhanced free formats including direct answers. Every URL or visual element shared under the view data rules is called a SERP Element, and the click and ranking obligations are built around that unit.

Click data is where Alphabet's current offer falls furthest short. At present the dataset carries click counts, aggregated per organic result including its site links, and per block for advanced and paid results. The decision requires, for each SERP Element, the order and duration of clicks and clicks back to the results page, or their absence; how long the user viewed the element; the duration of hovering, or its absence; the number of scrolls; whether swipes occurred within swipeable elements; and whether elements were expanded.

Dwell time, meaning the time a user spent reviewing results after a query, is not in the current dataset at all. Market participants rated its importance at 4.2 out of 5. The Commission notes that for direct answers and knowledge panels, a long dwell time on the results page can be the best available sign of satisfaction, since there may be no click to measure. Alphabet does not have to tell rivals how it interprets dwell time. It must share the dwell time itself, or the raw data from which a recipient can calculate it.

Ranking data

The existing dataset gives each organic result, and each advanced result block, an average rank over three months. The decision replaces that with position data for every SERP Element as displayed on the user's device: its absolute whole-page position, such as top area, main column or right-hand column; its relative ordinal position among other elements in the same area, together with the identity of those other elements; and information about the page on which it appeared.

Alphabet did not address ranking data specifically in its response to the preliminary findings, according to the decision, beyond its general claims that detailed ranking data would let recipients copy the output of its algorithms and free-ride on its investment.

Invalid traffic, freshness and delivery

Several measures govern how the data is prepared and shipped rather than what it contains.

The first concerns invalid traffic. The decision defines it as queries, impressions and clicks that are not genuine human traffic or do not come from genuine interest, such as machine-generated, fraudulent or spam-like activity. Queries blocked before they produce a results page are already absent from Alphabet's dataset. But once a results page is generated, the dataset does not strip clicks that Google's own click-spam systems would flag, and it carries no invalid traffic identifier. The decision requires Alphabet to exclude invalid query, view, click and ranking data, using the same methods it applies in its ordinary business to the extent technically possible, and without incremental cost attributable to sharing. On request, Alphabet must explain how exclusion works and how it affects the dataset, without revealing business secrets.

Alphabet objected that its spam filtering systems represent significant investment, that removing invalid traffic from frequently shared data would let recipients reverse-engineer and defeat its anti-scraping protections, and that telling recipients how exclusion works outsources the Commission's monitoring role. The Commission's revision after the consultation added the requirement to use Alphabet's own methods, because third parties had warned that an invalid traffic rule could be used to over-exclude useful data.

The second concerns latency. This is where the gap between Alphabet's offer and the Commission's view was widest. Alphabet releases data quarterly with an average delay of 4.5 months, in quarterly batches with no timestamps. The preliminary findings proposed daily sharing. Alphabet argued that near-real-time sharing had no legal basis, could not be derived from parity, would harm Google and its users, and was technically impracticable.

The final measure requires sharing on par with Alphabet's own latency for optimising its search engine, to the greatest extent technically feasible, and sets a floor: no less than seven days. That floor, the decision explains, reflects the minimum time Alphabet needs to process the data plus some additional days to anonymise and share it. Whatever latency results, the data must come in daily batches with daily timestamps. Alphabet must communicate the final latency to the Commission with a technical justification showing it is the lowest achievable. The introduction of latency is one of the revisions the Commission credits to Alphabet's comments.

The third concerns the sharing method. The April draft required an application programming interface that would let recipients access only new data. That requirement is gone. The final measure asks Alphabet to use the method it uses internally, to the greatest extent technically feasible and without unnecessary cost or friction, provided the method enables effective sharing, and to provide technical support. According to the decision, Alphabet's response to the revised measures welcomed the removal of API-based access and asked for confirmation that the data would be downloadable. Alphabet had argued that an API would require new infrastructure, would allow rivals to copy Google's results, would distort the syndication market and could create a security pathway back into its systems.

The fourth concerns duration. Alphabet's programme offers a maximum of three years. The preliminary findings proposed a minimum of five. Alphabet argued an open-ended obligation was disproportionate and incompatible with licensing on fair terms, while conceding that up to five years was a reasonable period on the evidence; in its later observations it asked for a three-year maximum. The final measure lets each recipient choose its period, up to five years from the moment the data becomes effectively accessible to that recipient. Alphabet must keep offering the data for as long as Google Search remains designated, and the Commission reserves the right to revisit the five-year ceiling under Article 8(9) if it proves insufficient.

The fifth concerns search sessions. Users often refine a query several times, and engines treat such sequences as sessions to understand intent. Alphabet's dataset links no queries together, citing anonymisation. The Commission considers session data to fall within ranking, query, click and view data, since it adds no new data type, only a session identifier. But it limits sharing to what it calls mini-sessions of at most three queries, defined in the anonymisation measures.

Anonymisation occupies more than a third of the reviewed text, and the legal disagreement underneath it is sharper than the public statements from either side suggested.

Alphabet's position, supported by expert legal opinions it commissioned and dated November 18, 2024 and March 25, 2026, is that anonymisation under Article 6(11) must meet the objective GDPR standard, rendering identification practically impossible, and must be achieved before the data leaves Google. On that reading, recipients' incentives are irrelevant, and contracts cannot compensate for identifiability that survives technical processing. Alphabet made six further arguments against contractual safeguards: they conflict with the requirement to share data in anonymised form; they deprive users of GDPR rights while those users remain identifiable, replacing statutory rights with a contract to which users are not a party; they leave data in an indeterminate legal state if a breach turns it back into personal data; the residual risk is too high anyway; recipients are search engines holding their own search data, with a high overlap of users, which they will inevitably combine with Google's; and neither Alphabet nor the Commission could reliably detect re-identification carried out in breach of contract.

The Commission's framework differs in two respects that shape everything else. First, Article 6(11) requires anonymisation of end users' personal data, meaning the people who issued the queries. Personal data about other people who happen to be named in queries, such as a celebrity or a local business owner, remains subject to the GDPR in the recipient's hands, but it is not something the anonymisation requirement obliges Alphabet to scrub. Alphabet's current method, the decision says, aims to remove all personal data from query text, which is one reason it discards so much.

Second, the Commission follows the approach of the draft joint guidelines it has been preparing with the European Data Protection Board on the interplay between the Digital Markets Act and the GDPR. Those draft guidelines state that when choosing among ways to anonymise data shared under Article 6(11), gatekeepers "should select the one that preserves the most quality and usefulness of the data", and that anonymisation should be achieved through technical alteration "complemented by organisational, administrative and contractual measures to mitigate residual likelihood of identification". PPC Land reported on the more than 100 responses to the consultation on those guidelines in March 2026. The Commission's design uses technical measures to bring re-identification risk down to what it calls a residual level, then relies on contracts and audits to reduce the residual risk to an insignificant one.

What counts as residual? The decision adopts a test from the expert report the Commission commissioned. Risk is beyond residual if an adversary can pick a specific person and, with significant probability, retrieve some of their records with high certainty; if an adversary can pick a random record and, with significant probability, re-identify its author with high certainty; or if an adversary can re-identify a large number of users with high certainty using reasonably simple methods. The first describes a targeted attack; the second and third, untargeted ones. The adversary may be the recipient, a malicious employee or an unintended outsider.

This framing sits within a wider rethink of the concept in Europe. The data protection board opened a consultation on new anonymisation guidelines replacing its 2014 test on July 8, 2026, eight days before this decision was adopted. For practitioners in de-identification, the search data case is the most detailed worked example of how a European authority weighs technical suppression against contractual control.

Alphabet's alternatives

Alphabet put forward two alternatives during the proceedings, and the decision describes both.

The first came on March 3, 2026. Instead of one general dataset, Alphabet suggested several datasets optimised for specific uses, such as a query-heavy file for query analysis. The Commission notes that this was the first time Alphabet raised the possibility, eight weeks before the deadline for preliminary findings, despite knowing of third-party criticism since shortly after its programme opened. It says the idea was never developed, and identifies a structural flaw: Alphabet would control which uses were supported, and recipients would have to disclose competitively sensitive plans to Alphabet in the hope of getting a suitable file.

The second, dated May 18, 2026, had five parts. Rare queries would not be dropped but mapped, using language model technology, to the semantically nearest query that had passed the threshold of 30 users, with a similarity score attached. Exact interaction timings would be replaced by placeholders labelled served, viewed, considered and clicked. Metadata would be grouped in cohorts of 1,000 users, with an additional threshold of five signed-in users on the combination of generalised query and metadata, and a third threshold of two users on each combination of URL and metadata. There would be no session grouping. And all ad URLs would be suppressed. Alphabet presented this as stronger privacy with preserved utility. The Commission's analysis, placed in its section on the impact of Alphabet's approach, concluded that its own measures preserve more usefulness while holding risk to a residual level.

The four-step method

The technical measures adopted in the decision work on the data daily, at record level, with records shipped in random order. Each record starts as a query with its metadata and must pass four steps.

Attribute suppression comes first. Alphabet must remove any end user identifier, including account IDs, usernames, whether the user was signed in, IP addresses and device IDs. The timestamp goes, although the day of the query remains. So do the height and width of modules and results, their distance from the top of the page, and their share of the user's viewport. The access point and input format are dropped. Ad URLs are removed, while the existence of the ad and interaction data around it are kept. Advanced filters are removed. Results from Google services that directly include personal information stored in a user's account, such as Maps directions to or from home, or that expose a user's exact location, are removed, and Alphabet must submit a list of those result types for Commission approval. In AI Mode, only the first query of a session is shared. Image queries are replaced by a placeholder; where images and text are combined, only the image is replaced.

Query suppression is second, and it is where the Commission's approach departs most from Google's. Rather than requiring 30 users to have typed an identical query, it builds an allow list of entities. Every month, Alphabet must take 13 months of EEA queries from signed-in users and split each query into entities. Personal data detectors first identify addresses, names, phone numbers, location coordinates, IBAN numbers, credit card numbers and other well-known identifiers, and normalise them. The remaining text is split into words on whitespace, ignoring spaces between digits. The decision's worked example is the query "john doe 200 wetstraat brussel 04 12 34 56 78 communications department", which would yield a full name, an address, a phone number and two single words. An entity joins the allow list for five years if more than 50 signed-in users included it in their queries.

A second test caps length. Using 2025 queries from both signed-in and signed-out users in the EEA, Alphabet must calculate, for each inferred language, the character length below which 95 percent of unique queries fall. Every day, each search record from the previous 24 hours is kept only if every entity in the modified query is on the allow list and the query is shorter than that language's length threshold. If the user's original query differs from the modified one, the original is tested separately and dropped from the record if it fails. Query modifier text shown on the page is tested the same way.

Alphabet argued that this approach ignores the way combinations of common words can identify people, and that the length cap is arbitrary and will reveal longer queries over time as average length grows. The Commission's reply is that the method applies thresholds to entities, not just to individual words, and is combined with the other steps.

Metadata generalisation is third. Location is reported at NUTS 3 level, the EU's third tier of statistical territories. Alphabet must check whether at least 1,000 signed-in users issued a query with the same combination of inferred language, location and device type in the 24-hour release window. If not, location is generalised to country level. If the country-level group still has fewer than 1,000 users, the query and its results and metadata are removed. Within each metadata group, click-back times and interaction durations such as hovering and viewing are binned into four boundaries, at the 20th, 40th, 60th and 80th percentiles of their distribution. Alphabet's criticism of the April draft referred to a metadata threshold of 50; the decision records that the threshold was raised after the consultation, and the final figure is 1,000.

Mini-sessionisation is fourth. Records from the same user are ordered chronologically, and a record joins the previous group if the user clicked a query modifier on the previous page, such as a "Did you mean" suggestion, an autocomplete entry or a shortcut chip, or typed a new query that contains the previous query as a substring. A mini-session may contain at most three queries, sessions may not overlap, and clicked modifiers from the last query in a session are suppressed. All records in a session share a random identifier, and their location and device metadata are overwritten with those of the last record.

Everything else defined in the data scope must be included unaltered. Alphabet must also tell the Commission which personal data detectors and entity types it plans to use, with confidence thresholds and reasons for choosing them, and the computing cost of each step. Every quarter, it must tell recipients which detectors it used, their performance statistics and the share of unique queries and query volume suppressed or altered by each measure and each detector. The detectors must be publicly available ones, and the decision gives Google Sensitive Data Protection as an example.

How much data survives

The numbers the Commission uses to justify its design are largely redacted into ranges, but the ranges are wide enough apart to make the point.

Under Google's approach, the 30-user threshold on whole queries removes, absent the allow list, between 90 and 100 percent of unique queries. Under the Commission's entity threshold of 50 users, between 10 and 20 percent of unique queries are removed. At a threshold of 100 users, the figure stays within the same 10 to 20 percent band; a footnote says doubling the threshold adds fewer than 10 percentage points of suppression. The discarded queries matter most. The long tail, a third party told the Commission, is where smaller competitors "do not see these queries at all today due to their volume".

Alphabet's May 18 alternative fares little better in the Commission's arithmetic. Alphabet said its query generalisation would leave between 20 and 30 percent of unique queries in their original form, based on one week of Irish data. Across 13 months of EEA data, the full span a recipient could hold, the Commission calculates the figure would fall below 10 percent, because rare queries accumulate over time. The rest would arrive as a generalised version designed to preserve intent rather than wording, which defeats the use of search data to build query understanding models. The decision gives an example: "bus from dundrum to red cow" becomes "dundrum to red cow", with a similarity score of 0.97 despite a materially different meaning. Because between 80 and 90 percent of queries over 13 months worldwide are issued by a single user, the proposal's metadata thresholds would also bite hard. With daily releases, fewer than 10 percent of unique queries would carry their metadata intact, and between 80 and 90 percent would lose location beyond the EEA, device type and even language. A separate URL step would suppress between 50 and 60 percent of result URLs, the data a rival needs to decide what to crawl.

The decision lists the other quality gains. Record-level data replaces aggregates, which virtually all potential beneficiaries told the Commission are far less useful for training. Mini-sessions provide some view of how users reformulate queries, which one participant described as useful for query rewriting, intent classification and spelling correction. Daily releases replace quarterly ones. And NUTS 3 regions, which have populations of roughly 150,000 to 800,000 people, offer much finer geography than a single country figure, particularly in large member states. The metadata threshold is higher than Google's own five-user rule, but it does not apply to query text, which is where most of Google's losses arise.

The red team argument

Alphabet's public case against the measures rested heavily on its claim to have broken them quickly. The decision examines that claim in detail.

According to the Commission, Alphabet tested the preliminary measures on one week of Irish search data between receiving the findings on April 16 and replying on May 18, and continued testing into June, a period of at least two months. It used significant computing resources requiring management approval, a team of 10 to 15 engineers and external experts. Alphabet says that during the exercise it re-identified several individuals in under two hours.

The Commission's first objection concerns method. Alphabet ran what the decision calls atomic adversarial attacks in an environment without the security controls, logging or incident detection the contracts require. It modelled a large group of highly skilled experts, with prior knowledge of the dataset and unlimited compute, facing no safeguards. That is not red teaming by most definitions, the Commission argues, citing a 2023 Google blog on AI red teams that distinguishes end-to-end adversarial simulation from atomic adversarial testing of individual components. The exercise is useful for exploring worst cases but is a partial assessment.

The second objection is that none of Alphabet's examples meets any of the three criteria for risk beyond residual level. There was no targeted attack. There was no demonstration that random records could be re-identified with high probability; the examples were carefully chosen worst-case queries, often edge cases. And there was no re-identification at scale.

On addresses in query text, Alphabet's own analysis of a week of EEA data found around 2,400 queries containing a name and an exact address, without applying the entity threshold of 50. Given the size of the data, the Commission reads that as evidence such queries are exceedingly rare, and notes there is no indication how many of those addresses were private homes rather than, for example, doctors' offices. On names more generally, the decision says their presence in query text is expected, since most names in queries belong to people other than the searcher and fall outside the anonymisation requirement.

The Commission's own testing, conducted by two external experts in anonymisation and adversarial privacy, focused on re-sessionisation, the attempt to link separate queries back to the same user. One experiment used a language model to propose clusters of queries within a metadata bucket, targeting the most sensitive and re-identifiable material, and then manually reviewed the five most sensitive of 30,000 potential sessions. Many clusters were wrong, the decision says, and among those that were correct, which a real attacker would have no way of verifying, none directly allowed re-identification.

A second experiment measured success rates by query similarity and group size. For queries on a similar topic, with a similarity score between 0.3 and 0.7, the chance of a correct cluster in a group of 1,000 queries was as low as 10 percent. For dissimilar queries, below 0.3, success was close to a random guess. The Commission emphasises why that matters: the real danger of re-sessionisation lies in linking unrelated queries into a profile, which is what made the 2006 AOL search log release notorious, when a pseudonymous identifier let attackers combine one user's queries about numb fingers, single men, a local landscaper, a surname and a named subdivision. Because the final measures require 1,000 unique users per bucket rather than 1,000 queries, the Commission argues real success rates would be lower still.

Alphabet's observations attacked the testing report as conceptually and methodologically flawed, criticising its focus on English-language queries and same-day re-sessionisation. It also caught an error. A footnote in the decision acknowledges that the report stated a success rate of 20 percent for very similar queries at a group size of 5,000 when the correct figure is approximately 50 percent; the report had meant to refer to a group size of 50,000. The Commission calls this a clerical error that does not affect the findings.

The testing process itself became a grievance for both sides. The Commission says its experts gained effective access to the data it requested on February 11 only on April 8, after replies arrived in two instalments on March 13 and March 31 and after problems with Alphabet's cloud environment, which Alphabet called RIDGE. On March 17, Alphabet told the Commission the environment had reached its maximum number of accounts. The Commission contrasts those delays with the speed of Alphabet's own testing: within two weeks of the preliminary findings, it notes, Alphabet had told journalists it had reverse-engineered the measures. Alphabet responded that the environment was set up in May 2025 to answer a request for information and "was never intended as a platform for privacy testing", and that its own external experts had no difficulty using it. The Commission points out that most of Alphabet's testing was done by internal engineers who did not need the environment.

The contract every recipient must sign

Contractual measures fill four of the reviewed sections, and together they amount to a compliance regime that any interested search engine or AI company would need to build before touching the data.

The starting point is legal roles. Alphabet and each recipient must be recognised as independent controllers under Article 4(7) of the GDPR. Alphabet is controller for the processing needed to apply the technical measures and must share the data securely and, where relevant, in line with the GDPR's rules on international transfers. The recipient is responsible and liable for the lawful processing of personal data of people other than end users that remains in the dataset, for its subcontractors, and for any processing that results from breaching or circumventing the anonymisation contract. Alphabet may impose only the contractual measures specified in the decision and may not extend control over a recipient's independent processing.

The obligations placed on recipients fall into several groups.

On environment, the recipient must keep the dataset under its effective control and process it only in a logically and technically segregated environment, where it cannot be queried together with other datasets, cannot be copied, merged or synchronised with them, and where subcontractors must also work.

On prohibitions, the recipient may not attempt to link the dataset with other data at record level, may not attempt to re-identify users, including by working out which records came from the same person through semantic similarity or behavioural fingerprinting beyond the mini-sessions provided, and may not process the data in ways that reverse or weaken the anonymisation, including by reconstructing removed attributes.

On purpose, use is limited to optimising or improving search engine services. The decision lists refining retrieval and ranking, results page optimisation, crawling and index building, query analysis, spell checking, auto-suggestion and auto-completion, and, where relevant, improving grounding and search capabilities of AI chatbots that rely on retrieval. A footnote draws a firm line: training the general-purpose language model underlying a chatbot is excluded. Alphabet may also prohibit recipients from looking up and serving results to users directly from the dataset.

On model testing, a recipient that trains or fine-tunes machine learning models on the data, including ranking, retrieval or chatbot models, must evaluate them before deployment to ensure they do not reproduce dataset content in a way that exposes users to re-identification.

On retention and sharing, the recipient may keep the data for a maximum of 13 months, compared with one year under Alphabet's current contract, and may not disclose, share or sublicense any of it to third parties. It must document the automated systems accessing the data, material processing operations and any models trained on it, with test results.

On security, the recipient must encrypt the data at rest and in transit with state-of-the-art encryption and proper key management, restrict access on least-privilege and need-to-know principles, apply phishing-resistant multi-factor authentication, bind authorised staff to confidentiality and train them yearly, prohibit copies or downloads to any device including staff workstations, apply physical security, log all access with attribution to individuals or systems, keep logs for one year, securely erase the data when the 13 months expire, manage vulnerabilities within the segregated environment, and report breaches under Articles 33 and 34 of the GDPR.

Alphabet's current Data Security Requirements already cover some of this ground, such as physical controls, encryption and incident response, and one detail stands out: they limit administrator rights to no more than 10 senior employees. The decision's version is more specific on segregation, model testing and logging, and less prescriptive on headcount.

Audits before and after access

The verification mechanism rests on independent reasonable assurance reports prepared under ISAE 3000, the international standard for assurance engagements other than financial audits, or an equivalent framework. Reasonable assurance is a high but not absolute level of confidence expressed as a positive conclusion, the decision explains, as opposed to limited assurance, which only states that nothing suggests a problem.

Three assurance objectives apply. The first concerns whether the recipient has credible, documented plans to use the data to develop its own search engine. The second concerns controls ensuring compliance with the contractual obligations on use. The third concerns controls protecting the dataset's integrity and confidentiality.

Before initial access, the recipient must supply a Level 1 report giving reasonable assurance on the first objective and on the design and suitability of controls for the second and third. To keep access, it must supply a Level 2 report annually, giving reasonable assurance on the first objective and on the operating effectiveness of all controls, based on testing and sampling from a continuous operating period of at least 12 months. The first Level 2 report is an exception and may rest on a three-month period. Existing reports such as ISAE 3402, SOC 2 or ISO/IEC 27001 certifications must be taken into account where their scope covers the objectives, with targeted supplementary work to fill gaps.

The audit scope is deliberately narrow. It covers only the dataset and anything derived from it inside the segregated environment, the parts of the organisation and subcontractors that touch it, and, where needed, the people who plan and fund search engine development using the data. Units without access must be excluded, provided segregation is demonstrably maintained.

Alphabet wanted tighter oversight. It argued that the April draft's intervals, 15 months from the first Level 1 report to the first Level 2 report and 12 months between subsequent reports, would leave periods in which misuse could go undetected. It asked for the first gap to be cut to six months and for the right to trigger an interim audit when it had a reasonable, good-faith belief of a breach. PPC Land's July report on the decision described a mandatory independent audit within six months of a recipient starting to process the data, followed by annual audits. That matches Alphabet's request, and the decision elsewhere credits Alphabet with the introduction of an ad hoc audit process. The section that sets the final intervals, however, falls in the pages missing from the reviewed copy, so the text cannot confirm it.

Alphabet raised further process demands: the right to suspend or terminate access for copying its algorithms, index or results, or for material breaches of contract; the right to appoint an auditor at its own expense to verify deletion; the right to suspend access after a change of control until a new Level 1 report is filed; and the right to seek damages instead of relying on contractual penalties, which it said would be unenforceable in Ireland and the United Kingdom. How the Commission resolved those points is also in the missing pages.

Pricing: cost, not value

The pricing section is where the two sides start furthest apart.

Alphabet's view is that fair, reasonable and non-discriminatory pricing is a range of commercial outcomes determined by the value of what is licensed, not by internal cost, and that this is established practice in standard essential patent licensing. A cost-based approach, it argued, would strip the data of its value, would be expropriatory and could only be used if legislation expressly required it. The correct method, in its view, is benchmarking against comparable services in competitive markets, with any benchmark treated as a floor.

The difficulty, which Alphabet acknowledged, is that there are no obvious benchmarks. Its internal work tested revenue-share models, volume-based models priced per thousand queries, and dataset-size models using ComScore's qSearch product, third-party Google results datasets sold through the Datarade marketplace, and syndication offers from Google, Bing and Brave. The resulting totals spanned an enormous range, from a redacted low figure up to a redacted band of USD 20 to 25 billion. The per-beneficiary maxima modelled included a 25 percent share of incremental EU revenue, a 2 to 3 percent share of total EU revenue, a 50 percent share of incremental EU query volume at USD 1 to 10 per thousand, and total EU query volume at USD 0.02 to 1 per thousand. Dataset-size estimates ran from millions of dollars at USD 1 per thousand to billions at ComScore's price per query. Alphabet's own estimate under a cost-based approach is redacted, but the Commission notes that most value-based results were multiple times higher.

Alphabet settled on dataset size times a benchmark unit price. The tiers are EUR 3 per thousand unique queries for beneficiaries with EEA search revenue below EUR 500 million, EUR 6 between EUR 500 million and EUR 1 billion, and EUR 9 above EUR 1 billion, with a EUR 1.50 tier for revenue below EUR 50 million added in August 2024. In practice, a company under EUR 500 million would pay about EUR 300,000 for 10 percent of the full EEA quarterly dataset and about EUR 3.3 million for all of it; a company above EUR 1 billion would pay around EUR 1.0 million and EUR 9.9 million respectively.

Market participants, whose names are redacted, called those prices disproportionate and unaffordable. All considered a cost-based method conceivable, and most considered it the right one. They argued the data is a by-product of user interactions, that value-based pricing embeds hold-up value, and that in a competitive market pricing would converge on the cost of collecting and providing data. They pointed to the United States search case, where the court ordered data to be made available at marginal cost; PPC Land reported on those remedies when Judge Amit Mehta issued them on September 2, 2025. Most opposed any margin at all, and some proposed free access given Alphabet's missed compliance.

The Commission's measure lands between the two. Alphabet must charge compensation that strictly reflects the incremental cost of making the data available plus a reasonable return on the capital employed for that purpose, capped at Alphabet's weighted average cost of capital. Incremental costs include preparing and formatting the data, including anonymisation, storage used for sharing, and dissemination, including onboarding and operating access tools. Excluded are overhead, sunk costs, investment in data collection not attributable to sharing, speculative risks, ordinary compliance and legal dispute costs. Every cost must be objective, measurable, verifiable and proportionate.

There are two exceptions. Alphabet is not held to the cost-plus-WACC formula if it demonstrates that it could not cover the efficiently incurred costs of collecting the data, including a reasonable return, from its own commercial use of that data, or where a beneficiary operates at very large scale. A footnote defines very large scale by reference to the gatekeeper thresholds: EU turnover of at least EUR 7.5 billion in each of the last three financial years, or a market capitalisation of at least EUR 75 billion. In those cases Alphabet may add a margin no higher, in percentage terms, than the operating margin of its Google Search business, and only if the result remains fair, reasonable and non-discriminatory. Micro, small and medium-sized enterprises are protected from paying more than cost plus the capped return in all circumstances. And where the beneficiary is itself a designated search gatekeeper, Alphabet may negotiate a different price in good faith, without that negotiation altering the cost base allocated to everyone else.

The payment structure is a two-part tariff. A fixed fee, independent of duration, volume and timing, covers beneficiary-specific one-off costs and an equal share of common one-off costs, calculated from a justified estimate of the expected number of beneficiaries when access first opens. Late entrants pay the same fixed component. The fee can be spread over the contract, although Alphabet keeps the right to full payment if a beneficiary leaves early. A variable fee covers each beneficiary's recurrent costs and an equal share of recurrent common costs among those receiving access that year. Alphabet must document the calculation, provide non-confidential versions to beneficiaries on request and give both versions to the Commission, which may audit Alphabet's costs.

The Commission also explains why Alphabet's chosen benchmarks fail. Syndication, it says, is a direct input into a rival's live search product, priced per query event in an extremely concentrated market, and likely to carry an oligopolistic premium. Panel-based products such as ComScore's are not bought to optimise search engines. And Alphabet offered no method for adjusting any benchmark to the specific data at issue. The decision additionally draws on Article 9 of the EU Data Act, which allows compensation for making data available to include costs and, in some cases, a margin, as a reference for what reasonable compensation can contain. The concentration argument has a recent parallel: France's competition authority examined search syndication when rejecting Qwant's complaint against Microsoft in November 2025.

Testing before buying

Rival search engines cannot see the dataset before they commit, and the decision treats pre-purchase testing as part of fair access.

Alphabet currently offers a free 1,000-row sample containing 58 unique queries, sent as an Excel file by email with no retention limit, and a paid one-time 5 percent sample of a quarterly dataset, potentially several billion queries, under the full licence and a 365-day retention period. Between one and ten search engines have taken the small sample, a figure given as a redacted range. One has bought the large sample.

The decision requires three samples. Sample A preserves the free 1,000-row file, downloadable, with a permitted restriction on onward sharing. Sample B is a synthetic dataset of up to 10 million artificially generated unique queries and metadata, supplied in whatever size up to that ceiling a search engine requests, downloadable to its own servers. Access to Sample B may not depend on an assurance report or audit, but Alphabet may give it only to engines it has found eligible. Alphabet must explain clearly how Sample B was produced and ensure it faithfully represents the real dataset. The reviewed copy ends at that sentence. Sample C, described in the table of contents as a large representative sample, is not in the reviewed text; the April preliminary measures had proposed a 5 percent sample of the final dataset.

What changed after April

The decision identifies several revisions that respond to Alphabet or to the consultation. Latency was added in place of near-real-time daily sharing. Ad URLs were removed from the dataset. An ad hoc audit process was added. The invalid traffic measure was clarified to use Alphabet's own methods. The metadata threshold was increased, location and interaction data were coarsened, mini-sessions were capped at three queries, and transparency on personal data detectors was added. The API requirement was dropped. Among changes proposed in the consultation that the Commission declined were requests for extremely granular location data and for access only within an environment hosted by Alphabet, which the Commission rejected on the basis of its own difficulties with Alphabet's cloud environment.

Alphabet also argued that the implementation deadlines were too short. It listed six workstreams: new infrastructure, collecting and deriving data points, restructuring the dataset, building anonymisation, drafting contracts and developing pricing. Citing the Commission's own expert, it said anonymisation alone would take three to four months, which made a three-month deadline for the whole dataset disproportionate, and it pointed out that Apple had been given nine months in case DMA.100203. The decision confirms Alphabet has 45 days from notification to prepare the application form. PPC Land's coverage of the July announcement recorded the wider schedule the Commission published then: application form and information page by the end of August 2026, template licences and cost estimates by September, the finalised dataset by November, and final pricing by January 2027.

What the text leaves open

Several questions remain after 298 pages.

Gemini is the most obvious. The Commission holds that it is an access point to Google Search, then declines to apply the adopted measures to it and leaves the conditions to future dialogue. Given the decision's own argument that Alphabet's chatbots owe their retrieval advantage to Search data, the treatment of Gemini's data will determine how much of the AI search interaction record rivals ultimately receive.

The review mechanism is another. The decision's Article 2, quoted in recital (82), provides that "the effectiveness and impact of these measures will be evaluated within two years following the adoption of this Decision, taking into account technological developments". Article 8(9) allows reopening on material new facts, including independent third-party testing, and Article 10(4) allows urgent suspension of an obligation. The Commission's July announcement said it may amend the anonymisation measures in particular depending on market developments.

Legal challenge is a third. The decision records Alphabet's arguments that Article 6(11) cannot lawfully support what it calls expropriation of its data and intellectual property, that its right of defence was compromised by gaps in the case file and the refusal to share minutes of the Commission's meetings with the data protection board, and that the investigation was biased towards complainants. The Commission answers each, noting for example that 13 of the 56 documents added to the data room were routine registrations rather than missing files. Those exchanges read as preparation for a court record. Kent Walker, President of Global Affairs at Google and Alphabet, warned on the day of adoption that the decisions put privacy and security guardrails for Europeans at risk, and both decisions remain open to review by EU courts.

And the missing pages are a fourth, practical gap. Refusal, suspension and termination rules, penalties, the finalisation timetable and the proportionality assessment all shape how usable the programme will be, and none appears in the copy reviewed here.

Why it matters for search marketing

For advertisers and publishers, the decision's significance lies less in any single measure than in the shift in what a rival search engine can learn about Google's results page.

Until now, a licensee could see a query, a country, a device class, an average rank over three months and a click count. Under the specified measures, a qualifying rival would see daily records, NUTS 3 geography, page position, dwell and hover durations, scrolls, click order and clicks back to the page, including how users interacted with ad blocks and with AI Overviews and AI Mode. It would not see which advertiser bought a given slot. For any company that pays for Google ad placements, that means user behaviour around its ads will inform rival ranking systems in anonymised form, while the identity of the advertiser and its landing page stays out of the file.

The decision says openly that it expects benefits to reach business users through more organic traffic sources and "a more competitive marketplace for the placement of search ads". Whether that happens depends on who can use the data. The eligibility rules, the audit burden and the contractual regime favour companies that already run search infrastructure. An analysis published in July found that earlier contestability measures under the regulation had done more for Bing and Firefox than for European challengers, and the same risk applies here. European efforts such as the index that Ecosia began serving to French users on August 7, 2025 with Qwant would need to build the capacity to exploit record-level data. Microsoft's retirement of its Bing Search APIs on August 11, 2025, with a replacement costing 40 to 483 percent more, has raised the cost of the syndication alternative.

The inclusion of AI chatbots has a regulatory echo. The Commission designated ChatGPT a very large online search engine under the Digital Services Act on August 31, 2026, on a declared 159.1 million monthly EU users, treating an AI assistant as a search engine under a separate law. The search data decision applies the same logic to data access. Any chatbot that qualifies, however, may use the data only to improve retrieval and grounding, not to train its underlying general model.

The data licensing question also connects to Google's litigation posture elsewhere. In the United States, the company is appealing the search remedies that require it to share data with qualified competitors, and it is pursuing SerpApi over automated extraction of its results. The European decision prices lawful access to a structured, anonymised version of the results-and-behaviour record at cost plus a capped return. For marketers who have followed the pressure from 18 industry groups on Google's search compliance, the full text answers a question the July summary did not: how little of Google's own offer survived the Commission's review.

Timeline

Summary

Who: The European Commission, which adopted the decision; Alphabet and its Google Search service, the gatekeeper bound by it; rival search engines and AI chatbots with search functions that meet the eligibility rules; the European Data Protection Board, which commented on the anonymisation measures; and more than 60 third parties contacted by Alphabet during the public consultation.

What: The non-confidential text of Commission Implementing Decision C(2026) 5091 final in case DMA.100209, specifying how Alphabet must share anonymised ranking, query, click and view data under Article 6(11) of the Digital Markets Act. It replaces Alphabet's method, which removes between 90 and 100 percent of unique queries, with a four-step process removing between 10 and 20 percent; requires daily record-level sharing with at least seven days' latency; extends access to up to five years; includes AI chatbots, AI Mode and AI Overviews while deferring Gemini; removes ad URLs but keeps ad interaction data; imposes segregated processing, 13-month retention and ISAE 3000 audits; and sets pricing at incremental cost plus a return capped at Alphabet's cost of capital. The copy reviewed ends at recital (1130) on page 298.

When: The decision was adopted on July 16, 2026, after proceedings opened on January 27, 2026 and preliminary findings on April 16, 2026. An evaluation of the measures is due within two years of adoption.

Where: The European Union, and the European Economic Area once the Digital Markets Act is incorporated into the EEA Agreement, covering Google Search data generated by users in the EEA.

Why: The Commission found that Alphabet's European Search Dataset Licensing Program had attracted a single licensee since March 2024 because its anonymisation, latency, scope and pricing left the data of little use to rivals. Specifying the measures is intended to lower the data barrier that protects Google Search's roughly 90 percent share, including in AI search, and to give advertisers and publishers more competitive alternatives for traffic and ad placement.