Showing posts with label digital economy. Show all posts
Showing posts with label digital economy. Show all posts

Friday, 31 July 2026

The effectiveness of the Cloud and AI Development Act regarding data centres


 


Annelieke Mooij, Assistant Professor, Tilburg Law School

Photo: Facebook Clonee (Ireland) data centre

Photo credit: Thomas Nugent, via Wikimedia commons

 

1.    Introduction

The debate about sovereignty and specifically digital sovereignty is fierce. Member States, struggle to achieve digital sovereignty which impacts the continuity and safety of the digital services. To speed up the realization of the sovereign cloud the Commission has proposed a new act the Cloud and AI Development Act (CADA). The act covers three important facets: AI, Cloud and Data centres. This contribution is limited to the proposed rules regarding data centres and analyze their effectiveness. The proposed Regulation should not be considered a stand-alone Regulation but rather forms part of the European Union’s broader strategy to strengthen digital sovereignty. The EU aims to reduce dependence on foreign digital service providers and expand Europe’s cloud and data centre capacity. At its core, the proposed Regulation seeks to create the conditions necessary for a sovereign European cloud ecosystem. A system that can support economic growth, innovation, and public-sector resilience.

The pursuit of cloud sovereignty, however, depends on more than software, governance frameworks, or industrial policy. Cloud services, AI and other digital services ultimately rely on physical infrastructure. Data centres provide storage, computing power, and connectivity upon which cloud services and AI applications depend. Without sufficient data centre capacity, ambitions for European technological autonomy cannot be achieved. The Commission aims to stimulate the increase of the data centre capacity through the CADA. The CADA therefore introduces a regulatory framework aimed at accelerating the development of data centres.  The Commission aims for the EU capacity to have tripled by 2030, and by 2035, all critical infrastructure will be hosted in EU data centres. These objectives are ambitious but there are good reasons for the Commission to emphasize digital sovereignty.

2. Why Digital Sovereignty Is Necessary & Difficult

Before delving into the CADA, it is important to understand why digital sovereignty is important to the EU. Cloud computing provides its users with remote access to data storage, software, and computing resources hosted on external servers. By outsourcing storage and computing functions to the cloud, organizations can reduce the need to maintain their own IT infrastructure. Whilst benefiting from greater scalability and operational flexibility. Public authorities increasingly rely on cloud services for precisely these reasons.

At present, however, the European cloud market is heavily concentrated. American providers dominate the sector, with Amazon Web Services and Microsoft accounting for approximately 75% of the European market. The largest European provider holds only a marginal 2% share. This concentration creates a structural dependency on foreign companies for critical digital infrastructure. One of the principal objectives of CADA is therefore to reduce this dependency and strengthen Europe’s technological autonomy.

The strategic rationale for reducing dependence on non-European providers extends beyond concerns about market concentration. Control over cloud infrastructure increasingly translates into geopolitical influence. A recent example is that of the latest AI-model created by Anthropic. The US government prohibited Anthropic from releasing its newest and most powerful model to its European customers. The official reason was due to considered possibilities of jailbreaks. The possibility of this happening was strongly denied by Anthropic. The EU Commission, however, stressed the possible negative impact on EU cybersecurity and cyberdefense.  It has been illustrative of how the US can cut-off new technologies to the EU, without serious repercussions. These incidents have not remained limited to simply limiting foreign accessibility but also to demonstrate power to individuals and institutions. Illustrative of this is the disruption of e-mail communications involving the International Criminal Court. The ICC’s email was cut-off after President Trump disagreed with actions from its main prosecutor. The case illustrated how political pressure exerted through private technology providers, without court permission, may affect the continuity of essential digital services. This dependence can be dangerous for Europe as it includes technology that is necessary for military purposes.

To achieve the desired increased EU cloud and AI capacity, physical infrastructure (or hardware) is necessary. Cloud and AI systems require data centres to operate on. The CADA therefore introduces a framework to create the necessary infrastructure.

3. The CADA’s rules on achieving data centre capacity.  

3.1. Specific Objectives

The CADA seeks to establish what the Commission describes as a coordinated and integrated ecosystem approach to cloud computing and artificial intelligence. According to the Commission, divergent national approaches to data centre permitting barriers to the efficient functioning of the internal market and hinder the development of a competitive European cloud ecosystem.

Against this background, the Regulation aims to create the conditions necessary for the large-scale deployment of cloud and AI infrastructure throughout the Union. In addition to reducing regulatory fragmentation, the proposal seeks to strengthen technological sovereignty, improve operational resilience, and support public-order objectives. The Commission further presents the Regulation as an instrument for promoting innovation and sustainability in Europe's digital infrastructure.

Regarding data centres specifically, the proposal seeks to address perceived shortages in computing and storage capacity through a combination of harmonisation measures and accelerated deployment procedures. This should lead to a specific result namely; triple the data centre capacity by 2030 and have sufficient EU data centre capacity for critical infrastructure by 2035.

3.2 Role of the Commission

The responsibility for achieving the operational objectives established by the CADA rests primarily with the European Commission. To achieve its goals, the proposal relies heavily on existing and future funding programmes intended to stimulate the development of cloud and AI technologies. These programmes seek, among other things, to improve the efficiency with which computing resources are used.

Particular emphasis is placed on technological innovation. High Performance Computing (HPC), for example, may increase the amount of computing output generated from a given level of infrastructure. More efficient use of computing resources can reduce the relative amount of storage and processing capacity required to achieve a particular outcome. Nevertheless, such efficiency gains do not eliminate the need for physical infrastructure. High-performance computing still depends on data centres and therefore remains subject to the same underlying constraints relating to energy, water, and spatial planning.

The effectiveness of this strategy consequently depends largely on the success of research and innovation projects supported through European funding programmes. There is ample reason to believe these strategies can be successful, economic literature has long recognised that research subsidies can stimulate innovation by reducing investment costs and encouraging experimentation. The chance of success, however, depends on the knowledge of the subsidy provider. In the past EU subsidies have proven a successful strategy. It is to be expected that the aim of development through subsidies will be successful again.

3.3. Data centre Acceleration Zones

To facilitate the expansion of data centre capacity, the CADA introduces so-called Data Centre Acceleration Areas (article 10). Each Member State is required to designate at least one such area for the accelerated development of data centre infrastructure, within six months of the Regulation entering into force.

When identifying acceleration areas, Member States must consider existing and future infrastructure capacity, energy availability, and broader sustainability considerations. The proposal further requires national authorities responsible for spatial planning to consider future data centre development and the necessary supporting infrastructure in those zones.

A developer wishing to develop a data centre in such an acceleration zone, will have the right to be assisted by a single point of information (article 11). This single point of information can assist the developer by sharing and coordinating the necessary permits and environmental and habitat assessments. The latter will be a sped-up procedure in accordance with Regulation 2026/XXXX on speeding-up environmental assessments. This Regulation was proposed in December 2025 with the aim to simplify environmental assessments. These rules aim to ensure that new projects have completed the permitting procedures within a year. The latter is the maximum that permitting procedures are allowed to last.

Taken together, these measures are intended to reduce administrative burdens and increase legal certainty for developers. The underlying assumption is that lengthy and fragmented permitting procedures constitute a significant obstacle to data centre deployment. To the extent that regulatory complexity delays investment, the proposed measures may indeed facilitate development. It is, however, questionable whether regulatory procedures are the primary challenge. The extent to which these objectives can be achieved in practice is, however, less clear. The realization of data centres come with significant challenges. When in operation, data centres become increasingly hot. With temperatures rising to 70 degrees in an hour. To continue their operations data centres need to cool. The cooling process requires high amounts of energy and clean water. E.g. data centres in the Netherlands constituted for approximately 5% of electricity demand in 2024. Recently a data centre by Microsoft made headlines that it uses 1% of the total national energy in the Netherlands. This whilst on the other hand there are significant shortages in energy supply for new housing and net congestion is increasing. Thereby creating serious debates on whether power should be diverted to data centres. On an EU level the targets for energy consumption are not yet met. The reduction target is approximately 18% away from its 2030 target. In 2024 the EU was 17% from renewable energy targets for 2030. In 2024 data centres consumed roughly 3% of the EU’s energy. Tripling this number and increasing it further till there is sufficient capacity for digital sovereignty creates a significant challenge.

These concerns are not limited to energy, the Netherlands is estimated to have a drinking water shortage by 2030. This whilst the data centres require approximately 3.7 million tonnes of drinking water per year, roughly 0.3% of Dutch tap water consumption, in the EU it is estimated to total 5.747.764.000 (nearly 6 billion liters). The CADA does not provide solutions to these underlying constraints. Instead, it requires Member States to create data centre acceleration zones and take infrastructure into account when designating these zones. Within these zones permitting procedures must be conducted within 12 months. While this may improve planning and coordination, it does not generate additional electricity capacity, alleviate network congestion, or increase the availability of water resources. The permits may become a hollow factor. A good example of the potential irony is that of the data centre in the Netherlands. The data centre had the required planning permits but were put on a waiting list for their energy connection.

The requirements created by the CADA may seem with a large margin of discretion as it uses language such as “take into consideration”. This language does not exert pressure on Member States. The CADA, however, also includes the earlier mentioned hard objective to triple the data centre capacity by 2030. Here lies another difficulty with the proposed framework. The CADA does not introduce a division key for how much capacity must be realized by each individual Member State. There are, however, big gaps between Member States in the current capacity.

Hungary for example only has 7.3MW of total capacity whereas Germany has 2.6GW of IT power. Arguably the capacity can be divided equally over all Member States, using the GDP as percentage divider. GDP is an indication of how much IT power is consumed in the economy. Generally, the higher the GDP the higher the IT consumption is. There is, however, little data on the demand for critical infrastructure in the EU. This is likely to change as article 15 of the CADA charges the EU Commission with obtaining that data. From an environmental perspective it is, however, ineffective to simply divide along GDP. Countries with cold climates and large coastal areas can build new more efficient data centres as the can use ocean water or outside air to cool. A submerged data centre on the coast is more sustainable than a data centre in a desert. In theory, the incentive to build data centre capacity by these countries is profit. Countries with favorable circumstances can build capacity cheaper than others and sell the capacity for profit. This theory of absolute advantage seems undermined by the next section of the CADA; the introduction of the European Cloud Federation.

 

4. The European Cloud Federation

In addition to measures aimed at expanding data centre capacity, in articles 34 and 35 the CADA introduces the proposed EuroCloud Federation. Participation in the Federation is voluntary and open to EU institutions and public-sector bodies. The purpose of the Federation is to facilitate the sharing of public cloud and data centre resources among participating members.

The underlying rationale is straightforward. Public authorities do not always utilize their available computing resources at full capacity. By enabling participating organisations to share infrastructure, the Federation seeks to improve the utilisation of existing resources and reduce unnecessary duplication of investments. In principle, such an approach may contribute to a more efficient use of public infrastructure.

To facilitate this objective, the proposal establishes a framework governing access to and sharing of infrastructure within the Federation. A notable feature of this framework is the limitation placed on financial compensation. Under Article 35(5), members providing infrastructure may recover their costs but are not permitted to generate profit from sharing their capacity with other participants.

From the perspective of short-term efficiency, this approach is understandable. Allowing access at cost price reduces barriers for participating entities and may encourage greater use of available infrastructure. The arrangement may therefore improve the allocation of existing capacity within the public sector.

The longer-term effects are less clear. The development of additional infrastructure requires significant investment and involves financial and operational risks. Where providers are unable to obtain any return beyond cost recovery, but cost recovery is not guaranteed, the incentive to create surplus capacity that can later be shared within the Federation may be reduced. Public entities may conclude that it is more attractive to rely on the capacity of other participants than to invest in additional infrastructure themselves.

 

5. Conclusion: a failed attempt?

The aim of the CADA is to increase the total EU data centre capacity. The CADA, however, does not create a division key. This is a fundamental gap within the regulation, it is too easy to state that all Member States should triple their data centre capacity equally. At present there are high differences in capacity between the different Member States.

The proposed Cloud and AI Development Act represents an ambitious attempt to strengthen European digital sovereignty through the expansion of cloud and AI infrastructure. Central to this ambition is the objective of significantly increasing data centre capacity across the European Union. To facilitate this development, the Regulation requires Member States to designate acceleration areas, develop national cloud and AI strategies, and participate in a broader framework intended to support the growth of sovereign digital infrastructure.

The proposal therefore sends a clear political signal. Data centres are no longer regarded as purely commercial infrastructure but as strategic assets that are essential for economic competitiveness, public administration, and technological autonomy. In that respect, the CADA forms part of a broader shift in European policy towards reducing strategic dependencies in critical digital technologies. Nevertheless, the CADA does not solve issues regarding natural resources. The introduction of the EU Cloud Federation furthermore has the potential to undermine a sustainable and economically efficient capacity division.  

 

Saturday, 31 July 2021

Central Bank Digital Currency: The Legal Obstacles of the Digital Euro

 



Dr. (Annelieke) Anne Marieke Mooij, Tilburg University

The ECB has decided to launch the preparation phase for the digital euro. The digital euro is a digital currency (euro) issued by the ECB, a so called ‘Central Bank Digital Currency’ (CBDC). The ECB has currently evaluated different design options for the digital euro in its report. The designs vary from a limited form, only accessible to financial institutions. It could, however, also be designed to be accessible to all consumers via their national central banks. The ECB has not yet settled on a single design but the launch statement makes it unlikely that the ECB will opt for a digital euro only accessible by financial institutions. The different designs carry different legal obstacles. This blog will consider the main legal hurdles.

The power for the ECB to issue legal tender is founded in Article 128 TFEU, which provides the ECB with the exclusive power to issue banknotes. These are the only banknotes to carry legal tender. Secondary law refers to physical money such as banknotes and coins as carrying the status of legal tender. However, Grunewald et. al. consider that a purposive reading of Article 128 TFEU allows for a broader interpretation of this provision. The most convincing argument here is the change of financial systems. The possibility of digital legal tender was not expressly provided for because it was not yet a viable option when the Lisbon Treaty was adopted. Moreover, the Treaties do not provide any grounds for prohibiting the creation of digital legal tender. Therefore, it does not seem impossible that the ECB could issue digital banknotes based upon Article 128 TFEU.

Article 128 TFEU further raises a question of design, more specically can the digital euro accumulate interest? Grunewald et. al. conclude that digital notes should resemble cash, in the sense that no interest should be accumulated. The recent judgment of the CJEU in Dietrich & Häring v. Rundfunk, however, indicates that digital money under EU law may not have to resemble cash. Dietrich & Häring v. Rundfunk concerned the status of the cash money as legal tender. The CJEU considered that the “concept of ‘monetary policy’ is not limited to its operational implementation […] but also entails a regulatory dimension intended to guarantee the status of the euro as the single currency […]” (para 38). The Court furthermore argued that legal tender carries three criteria: mandatory acceptance, acceptance at full face value and the power to discharge debts (paras 48-49). Interestingly, the criterion on whether or not a currency accumulates interest – called ‘storage of value’ – is neither clarified by secondary legislation nor in the case law of the CJEU. Additionally, as the CJEU stated, the ECB’s authority is not limited to executing monetary policy but also includes a regulatory dimension (para 38). This regulatory dimension should be interpreted to include the design of legal tender, without violating the three primary criteria. Following the Court’s judgment in Dietrich & Häring v. Rundfunk, it seems likely that the ECB could introduce the digital euro as legal tender and include the use of interest rates.

The question of interest rates is particularly important when considering the potential use of the monetary policy. The first concern described by the ECB in their report is that of potential foreign currencies, i.e. other CBDCs and cryptocurrencies (see p. 9). If these currencies took hold in the Eurozone they could limit the transmission channels of the ECB. The ECB’s transmission of monetary policy depends on the euro as the dominant currency. If foreign CBDCs or commercial currencies such as Bitcoin became more prominent than the euro the ECB would not be able to influence monetary policy. A digital euro, however, could safeguard the status of the euro and the singleness of monetary policy in the Eurozone. Furthermore, economists doubt whether cryptocurrencies, as opposed to CBDCS, can provide price stability. As per Article 127(1) TFEU price stability is the primary objective of the ECB. To use a digital euro to prevent cryptocurrencies takingover would prevent the instability of cryptocurrencies. Such an objective is within the ECB’s monetary aim. Furthermore, the digital euro could provide a more direct transmission of monetary impulses. Currently the ECB influences interest rates in the real economy through the rates it charges commercial banks when they borrow from the ECB. Through a digital euro the ECB could directly change interest on the consumer accounts. To ensure the transmission of monetary impulses, the digital euro should be account-based and carry interest. Meaning that consumers would have access individual digital euro accounts with the ECB. Such accounts can be accessible through the commercial sector but consumers would have a claim upon the ECB or their national central bank. A design whereby the digital euro is only available to financial institutions carries limited legal questions. The account-based design, however, becomes more legally challenging. In such a system the digital euro might compete with commercial bank accounts.

It is clear that for the ECB to introduce the digital euro as part of its monetary policy, the ECB would have to comply with its monetary mandate established in Article 127 TFEU. According to the ECB’s monetary mandate under Article 127 TFEU, a measure must have a monetary aim and comply with the principle of proportionality. In Gauweiler, the CJEU considered the aim of the policy as the primary indicator of whether a policy is monetary or economic (para 46). In Weiss, the CJEU furthermore placed very few limits on the indirect effects of the ECB’s adopted policy. According to the CJEU in Gauweiler, the aim of safeguarding the status of the euro complies with the monetary aim of the ECB (para 48). The account-based and interest carrying design of the digital euro aims to introduce new transmission channels. The ECB will be able to directly change interest rates on consumer accounts through the digital euro. Whilst not being the same as restoring the available transmission channels, it does not render the design of a digital euro unlawful. The CJEU stated in Gauweiler that the “[…] objective of safeguarding an appropriate transmission of monetary policy […]” falls within the scope of monetary policy (para 49). The CJEU speaks of “transmission of monetary policy” rather than individual channels (para 49). There is clear evidence that current monetary policy transmission of the ECB? is not as effective as previously thought. The digital euro could improve transmission and reduce the concerns about the lower bound. The introduction of a digital euro should be considered as pursuing a monetary rather than economic aim. Even if fulfilling the monetary aim, the digital euro would still comply with the principle of proportionality.

The CJEU in Gauweiler and Weiss reviews the proportionality of an ECB measure by examining the  suitability and necessity of said measure (para 72). Regarding the suitability criterion, it should be noted that, at present, cryptocurrencies have never been implemented as a large-scale payment mechanism. The technology is, however, capable of facilitating such mechanisms in the near future. Economists, therefore, argue that the introduction of a CBDC is a natural progression of monetary policy. Whilst the effect of CBDCs on the markets is still debated, the ECB has been given a wide margin of discretion by the CJEU in adopting suitable measures. It is clear that the CJEU will only review whether the ECB has not made ‘a manifest error in judgment’ (Gauweiler, para 74). It seems unlikely that the Court would find the latter for the introduction of a digital euro.

This leaves the question of necessity. To comply with this second criterion, the digital euro may not go beyond what is necessary. The evaluation of this criterion depends on the aim that is pursued by the ECB: (1) the promotion of the euro as a single currency in light of commercial and foreign currencies, or (2) a more direct transmission of monetary policy. The first aim by itself would not justify the introduction of account-based and interest-bearing accounts. Commercial currencies are attractive because of their cheap and fast payment option. The potential for quick settlement through a digital euro does not require interest rates. Nor do cryptocurrencies accumulate interest rates, hence commercial euro accounts will remain attractive. Regarding international payments a mechanism of exchange using the digital euro and cryptocurrency should be considered. It is unlikely one cryptocurrency will take over the eurozone’s physical market. Meaning there will still be demand for a single currency in shops and restaurants. International payments are likely to be conducted with cryptocurrencies. An exchange mechanism can bridge the gap between euro’s and cryptocurrencies. Safeguarding the importance of both.  If one includes the introduction of a more direct transmission channel, the account-based system with interest rates would be necessary. Without individual accounts consumers cannot gather individual interest rates. The interest rates are necessary to transmit monetary impulses. This, however, does not yet settle the interest rate level that can be charged. In particular, the impact of the potential interest rate of a digital euro on commercial banks should be considered.

Economists disagree on the impact of CBDC on the commercial sector. Some argue that the uptake of CBDC will be limited. The introduction of CBDC will thus not have a large effect on the commercial sector. Whilst others argue that the ECB will have a competitive advantage due to their (perceived) stability, and thus the possibility for competition from the private sector is significantly decreased. It would therefore seem unlikely that the CJEU would qualify a digital euro which diminishes the commercial sector as necessary. The design of the digital euro should therefore allow the commercial sector to compete. The potential for competition stimulates technological growth and allows for consumer choice. A digital euro that diminishes the banking industry would reduce consumer options. This would not be beneficial to either consumers or the open market.

Based on the analysis above, the introduction of a digital euro thus seems legally possible. However, some questions remain. The interests that could be charged on the digital euro are not yet certain. Additionally, this post only considered a digital euro in a tiered system whereby consumer access would be realized through market infrastructer. The second option is a form of CBDC that is directly accessible through the national central banks. This system is considered a solution to the unbanked, i.e. consumers without a bank account. However, the number of such unbanked consumers in the EU is low. The aim of providing an inclusive banking sector is thus a primarily socio-economic rather than a monetary goal.

The economic objective of creating a digital euro which is directly accessible through national central banks is also not unlawful under EU law. In addition to its primary price stability mandate under Article 127 TFEU, this same Article states that the ECB also “shall support the general economic policies in the Union”. The scope of this secondary, economic mandate is not yet clear as there is no caselaw on this topic. However, it seems that the aim of economic inclusion fits the objectives of the Union. Article 153(j) TFEU includes the aim of social inclusion, which includes socio-economic inclusion. The economic mandate of the ECB, however, speaks of “support”. At present, no law or policy provides the authority for the ECB to introduce CBDC. It is furthermore unlikely that such a measure will be introduced.

At present access to a bank account is provided through Directive 2014/92. This directive focusses on increased competition within the EU to promote access to bankaccounts. A centralized approach to reduce the number of unbanked, through CBDC would require a 180 degree turn. The Dutch Central Bank (DNB) furthermore discovered there would be significant consumer uptake of CBDC. The DNB report states that 49% of consumers would open a CBDC account and, with an equal level of interests, 54% of consumer would deposit more than zero euro. This research was conducted when the concept of CBDC is relatively unknown (April 2021). When a CBDC becomes available and more known, the uptake should increase even further. The viability of the commercial sector would be in danger with such levels of uptake. The commercial banks require deposits from consumers to function. The deposits are used to provide loans and investments. Without consumer deposits the commercial banks would cease to exist. It is therefore unlikely that a centralized CBDC would comply with competition law.

Whilst consumers could be using a digital euro in the near future, it is unlikely that we will be banking with our national central banks. More likely the ECB will opt for a tiered-system whereby access to the digital euro is provided through market solutions.

For an extended analysis by the author click here.

Barnard & Peers: chapter 18

Photo credit: DXR, via Wikicommons media

Thursday, 14 January 2021

The proposed Digital Markets Act: overview and analysis


 


 

Professor Lorna Woods, University of Essex

 

Background

 

The Digital Markets Act (DMA) proposal is stable-mate to the Digital Services Act (DSA) proposal (discussed here) developed as part of a suite of actions to tackle concerns about the operation of the digital environment.  If enacted, it will form part of a complex tapestry of measures dealing with information society and electronic communications services of one form or another – found in to name but a few - the European Electronic Communications Code (which covers OTT voice services); the Audiovisual Media Services Directive (which covers video on demand potentially including some YouTube channels for example, as well as video sharing platforms); the P2B Regulation; and, of course, the e-Commerce Directive (which the DSA develops).  It will also be developed against a backdrop of increasing competition law enforcement actions against a number of large players in the market.  The EU is not the only actor taking steps and one important question will be how compatible these various initiatives are, as well as how effective.

 

Overview of the Proposal

 

Based on the recognition that platforms are a key structuring element of the current digital economy, the proposal provides for ex ante restrictions on an identified list of services, but only when those services are provided by operators which meet certain thresholds.  The Commission has enforcement responsibilities and powers, with similarities to those found in the competition field.

 

The relevant services are those which the Commission has identified as “core platform services” (CPS) (defined Art. 2(2)):

 

a)      online intermediation services;

b)      online search engines;

c)      online social networking services;

d)     videosharing platform services;

e)      number-independent interpersonal communication services;

f)       operating systems;

g)      cloud computing services; and

h)      advertising services provided by an operator which provides any of the services in (a)-(g).

 

While some of these terms are defined in other instruments (eg ‘information society service’, ‘online search engine’ and ‘video sharing platform service’, included no doubt to try to ensure coherence across the digital regulatory space, some are novel (eg ‘online social networking service’ and ‘software application stores’).  It remains to be seen how clear these definitions are.

 

The service operators who will be caught by the rules in this regulation are those designated as a “gatekeeper” according to Article 3. Article 3(1) contains a three stage test:

 

-          the existence of a significant impact on the internal market;

-          the operation of a CPS “which serves as an important gateway for business users to reach end users”; and

-          an entrenched and durable position in its operations.

 

These are assessed by quantitative criteria (based on turnover or market value, and user reach), producing a rebuttable presumption about the status of the operator, and refined by reference to qualitative criteria.  It is initially for the company itself to make this assessment and to notify the Commission.

 

Article 5 lists the obligations for gatekeepers and Article 6 contains a list of further actions that may be specified in respect of a gatekeeper. The obligations include positive obligations and prohibitions, essentially behaviours identified from previous competition investigations and against which competition rules seem insufficiently effective. These rules have been set down in some detail though the proposal envisages that the Commission may update the list of prohibited practices in the light of enforcement experience. This is important as otherwise closely specified rules could be overly rigid and not deal with developments in the market or practice. This, then, could introduce some element of future proofing.  The Regulation also provides for the possibility of exceptions, including exemption for overriding reasons of public interest (public morality, public health and public security).

 

            Prohibited Practices

 

-          refrain from combining personal data sourced from these core platform services with personal data from any other services offered by the gatekeeper or with personal data from third-party  services, and  from signing  in  end  users  to  other  services  of  the gatekeeper in order to combine personal data (this would catch, for example, the situation where logging into Gmail leads to you being logged into YouTube – this has come up in investigations into Facebook also) (Art5(a));

-          refrain from preventing or restricting business users from raising issues with any relevant public authority relating to any practice of gatekeepers (Art 5d);

-          refrain from requiring business users to use, offer or interoperate with an identification service of the gatekeeper (Art 5e);

-          refrain from requiring business users or end users to subscribe to or register with any other core platform services – this is a ban on tying (Art 5f);

-          refrain from using any not publicly available data about the activities of business users or their end users to compete with those business users, an issue that arose in the Amazon investigation (Art 6(1)(a));

-          Prevent end users from un-installing any pre-installed software applications (Art 6(1)(b));

-          Rank the own products of the gatekeeper more favourably than similar third-party products – this came up in the Google Shopping decision (Art 6(1)(d));

-          Technically restrict the ability of end users to switch between and subscribe to different software applications and services to be accessed using the gatekeeper’s operating system – ie, lock ins are not permitted (Art 6(1)(e)).

 

            Positive Obligations

 

-          allow business users to offer the same products or services to end users through third party online  intermediation  services  at  prices or  conditions  that  are  different  from those offered through the online intermediation services of the gatekeeper (MFN clauses) – currently platforms impose significant restraints on their business users in this regard as can be seen for example in the eBooks settlement (Art 5b));

-          allow  business  users  to  promote  offers  to  end  users  acquired  via  the  core  platform service, and to conclude contracts with these end users regardless of whether for that purpose they  use  the  core  platform  services  of  the  gatekeeper  or  not (so for example Apple’s requirement to use its in-app purchase system or even its app store) (Art 5c));

-          allow end users to access and use software application of a business user where software was  acquired  without using the core platform services of the gatekeeper (Art 5c));

-          provide  advertisers  and  publishers  to  which  it  supplies  advertising  services price information in relation to advertising services (Art 5g);

-          allow  the  installation  and  effective  use  of  third  party  software  applications  or software  application  stores  using,  or  interoperating  with,  operating  systems  of that gatekeeper  and  allow  these  software  applications  or  software  application stores  to  be accessed  by  means  other  than  the  core  platform  services  of  that gatekeeper (Art 6(1)(c));

-          apply FRAND conditions to rankings (Article 6(1)(d)), which might also reflect concerns in the P2B Regulation;

-          give business users and providers of ancillary services (eg payment processors, cloud hosts, digital identity providers, and ad-tech sellers) access to and interoperability with the same operating system, hardware or software features that are available or used by the gatekeeper itself (Art 6(1)(f));

-          provide data to allow independent verification of ad inventory (Art 6(1)(g));

-          ensure effective data portability – and real-time access (art 6(1)(h));

-          provide business users free of charge with effective, high-quality, continuous and real-time access to and use of aggregated and non-aggregated data (subject to GDPR) – this essentially ensures businesses can have access to their own business data (Art 6(1)(i));

-          provide third-party providers of search engines with access on fair, reasonable and non-discriminatory (FRAND) terms to ranking, query, click and view data generated by end users (Art 6(1)(j));

-          FRAND conditions for access for business users to the gatekeeper’s app store (Art 6(1)(k)).

 

By contrast to the position under competition law, in acting against these behaviours the Commission would not have to prove their impact on competition on the market, though the Commission’s ability to intervene under its competition powers remain unaffected.  The Commission seems therefore to have decided that concerns about pro-competitive effects of some behaviours (including self-preferencing) do not outweigh gains from clear rules for efficient enforcement. There have been some concerns that these closely defined prohibitions may not be appropriate for all gatekeepers, and it remains to be seen how the refinement levers of qualitative factors (as regards the designation as gatekeeper in the first place) and the obligations that are susceptible to specification (in Article 6) operate.

 

Note that these provisions apply to services that are offered across the gatekeeper’s core services; they do not require the interoperability of core services necessarily, nor benefit third party service providers who do not operate on the core services. 

 

The regulation also introduces provisions empowering the Commission to carry out market investigations for any of three purposes: identifying gatekeepers that are not captured by the quantitative thresholds of the DMA; identifying other services that should be added to the list of core platform services or new practices that may be unfair; identifying proportionate behavioural or structural remedies in the case of systematic infringement of the rules by a gatekeeper. Article 10 gives the Commission the power to adopt delegated acts to update the lists in Articles 5 and 6 when it discovers unfair practices in a market investigation.  This new tool is arguably less far reaching than the new competition tool originally envisaged because of competence issues and the limits of Article 114 TFEU.

 

The DMA obliges gatekeepers to inform the Commission of any proposed merger or acquisition involving another provider of core platform services or of any other services provided in the digital sector. For these purposes, it is irrelevant whether such an acquisition triggers a notification requirement under the EU (or national) merger control rules. This is not a specialist merger regime, but is to allow the Commission to review gatekeeper designations and obligations.

 

The DMA provides for up to 10 percent of a gatekeeper’s global annual revenue in fines for violating its rules, similar to those penalties available in competition cases.   Structural remedies remain a possibility in the case of ongoing problems or recalitrant actors (Article 16) but only where there are no equally effective behavioural remedies.

 

Comment

 

The Commission’s proposal is based on the assumption that there are problems and that reliance on competition tools is insufficient to deal with the problems, partly because of the length of time an investigation may take – for example, the Google Search case took in excess of 6 years.  The European Court of Auditors has recently published a report to similar effect.  Specifically as regards the DMA, the Regulation flags at Recital 10 the need to ensure contestability of markets – and in this it seems to reflect ordoliberal concerns found in many decisions where it has sought to protect the market, with knock on benefits perhaps to small and medium sized enterprises.  The proposal therefore adds additional measures as a complement to competition rules.  It seeks to introduce ex ante regulation to the generally ex post competition provisions and so avoid questions about the definition of markets, assessment of dominance and identification of the theory of harm (for example impact on nascent competition or on innovation).  Instead the key question is whether an operator is a “gatekeeper”.

 

Admittedly the cases that have come up under the competition rules in relation to the digital environment have been based on complex facts and raised difficult questions about application of the usual principles, but the resort to ex ante additional regulation is not new. This double pronged approach has been used before, notably in the not-so-very-distant field of telecommunications – though it should be noted that this approach is not unique to electronic communications sectors.  The EU approach to telecommunications can be seen as a model for the DMA as regards another aspect too: the decision not to embark on structural separation of big players, or at least not as a first port of call, but instead to rely on requiring them to open their platforms to providers of other services, whether direct substitutes or related services.  This approach can be seen in the liberalisation of the telecommunications sector from the late 80’s on, for example in the Access Directive.  As in the debate for data protection, there is the question as to whether financial penalties will ever be enough for companies as rich as the big tech companies.  Some (probably American commentators) see the unwillingness to break companies up as a significant weakness.

 

Another notable point is the role of the Commission.  By contrast to the telecommunications regime, where the national regulatory authorities have had a distinct and important role, enforcement powers lie with the Commission exclusively – perhaps reflecting the early position with regard to competition enforcement, where implementation of EU competition law was consolidated at EU level.  National authorities will however participate in a Digital Markets Advisory Committee that will assist the Commission.  This location of power at the EU level can be seen in other aspects of the proposal. The form of instrument proposed is a regulation, meaning it would be directly applicable in Member States’ legal systems without implementation. Moreover, the regulation seems to be envisaged as total harmonisation in this field.  Article 1(5) specifies that:

 

 “Member States shall not impose on gatekeepers further obligations by way of laws, regulations or administrative action for the purpose of ensuring contestable and fair markets”,

 

though the field to which this prohibition applies is restricted.  Nonetheless, this point is likely to be contentious.

 

As noted, a central question is the identification of gatekeepers and there are likely to be questions about the operators to which the DMA applies (and no specific platform has been named).Arguably, there will be difficulties in identifying criteria that work across the range of activities that platforms provide.  The assessment (which falls on the companies themselves) is a mix of assessing whether CPS are in issue and then looking at the Gatekeeper criteria.  Two points should be noted; the existing definitions are themselves complex and the developing market challenges them; secondly, it is unclear how the qualitative criteria will operate to rebut the presumptions based on the numbers.  There have been some comments that this definition will need to be improved as the proposal makes it way through the legislative process.

 

One final question relates to the relationship between this instrument (and its motivations) and that of the GDPR (and possibly the ePrivacy Directive) with their emphasis on the user and the user’s privacy.  While some of the ex ante prohibitions seem to flow in the same direction as data protection rules (notably the obligation to refrain from combining personal data as well as the tying of identity services), there might be some tension with data portability by businesses and access to user data, which will likely be – at least to some extent – subject to GDPR controls.  It remains to be seen how the two will operate together, and whether competition concerns operate to undercut data protection.

 

Photo credit: via Wikimedia commons