Competition Law And Access To Business User Data
Competition Law and Access to Business User Data
1. Introduction
Access to business user data has become an important competition-law issue in digital markets. Large platforms often act simultaneously as:
- infrastructure providers,
- marketplaces,
- intermediaries between businesses and customers, and
- competitors of the businesses using their platforms.
A platform may therefore obtain valuable information from a business user—such as sales volumes, prices, customer demand, product performance, inventory information, advertising data, or transaction information—and then potentially use that information in competition with the business user.
The central competition-law question is:
When does control over commercially important data give a dominant platform the ability or incentive to restrict competition, and when should competitors or business users receive access to that data?
Modern regulation increasingly addresses this issue directly. Under Article 6(10) of the EU Digital Markets Act (DMA), designated gatekeepers must provide business users and authorised third parties with free, high-quality and real-time access to certain data generated by business users and their customers, subject to the statutory conditions.
2. Meaning of Business User Data
Business user data generally means information generated through a business's use of a digital platform or intermediary service.
Examples include:
- Sales data
- number of transactions;
- quantities sold;
- transaction value.
- Customer-interaction data
- clicks;
- searches;
- engagement;
- customer behaviour relating to the business's products.
- Performance data
- conversion rates;
- advertising performance;
- product rankings;
- customer reviews.
- Operational data
- inventory;
- delivery information;
- fulfilment performance.
- Platform analytics
- traffic statistics;
- app engagement;
- user interaction reports.
The EU Commission specifically describes Article 6(10) DMA as covering data generated by the business user, anonymised end-user data, and certain personal data generated by end users where consent exists. The data must relate directly to the business user's products or services.
3. Why Data Access Matters Under Competition Law
Data can create several competitive advantages.
A. Information advantage
A dominant platform may observe the performance of thousands of businesses simultaneously.
For example, a marketplace may know:
- which products are selling rapidly;
- which prices attract customers;
- which products are losing demand;
- which suppliers have high margins.
A platform that also sells its own products could potentially use that information to compete against its business users.
B. Entry barriers
A new competitor may not have access to comparable datasets.
This can make it harder to:
- develop products;
- improve algorithms;
- understand consumer demand;
- offer personalised services.
C. Switching costs
Businesses may become dependent on the platform's historical data.
If a business cannot take its customer, sales or performance data elsewhere, changing platforms may become expensive.
D. Self-preferencing
The platform may use information obtained from business users to improve its own competing products or services.
E. Discrimination
The platform may give itself or selected businesses better access to valuable information while denying comparable access to competitors.
4. Competition-Law Theories Relevant to Data Access
Several doctrines can apply.
4.1 Abuse of dominance
Under Article 102 TFEU, a dominant undertaking must not abuse its dominant position.
Data-related abuse can potentially involve:
- refusal of access;
- discriminatory access;
- exploitative contractual terms;
- leveraging;
- self-preferencing;
- exclusionary conduct.
Dominance itself is not unlawful. The competition concern arises from abusive conduct by a dominant undertaking.
4.2 Essential Facilities Doctrine
The traditional essential-facilities doctrine concerns situations where a dominant undertaking controls an input or infrastructure that competitors allegedly need.
For access to be compulsory under the traditional doctrine, the European case law has generally imposed demanding requirements, including:
- the input must be indispensable;
- refusal must be capable of eliminating effective competition;
- there must be no objective justification.
The doctrine therefore does not mean that every commercially useful dataset must automatically be shared.
4.3 Data as an Essential Input
A dataset may be particularly important where:
- it cannot reasonably be replicated;
- it is generated continuously;
- competitors cannot obtain equivalent information elsewhere;
- access is necessary to compete;
- the dominant undertaking uses the data to compete downstream.
However, courts have generally treated compulsory access cautiously because mandatory sharing can affect property rights, investment incentives and freedom of contract.
5. Major Case Laws
Case 1 — IMS Health v NDC Health
Case: C-418/01, IMS Health GmbH & Co. OHG v NDC Health GmbH & Co. KG
Facts
IMS Health operated a system for pharmaceutical sales information divided into geographical areas. NDC Health wanted access to the system to compete in the pharmaceutical-information market.
IMS refused access.
Legal issue
The case concerned whether refusal to license intellectual property relating to an indispensable information structure could constitute abuse of dominance.
Principle
The Court identified stringent circumstances in which refusal to license an intellectual-property right could amount to abuse.
Important considerations included:
- the input being indispensable;
- refusal eliminating effective competition;
- absence of objective justification;
- the refusal preventing the emergence of a new product for which there was consumer demand.
Relevance to business data
The case is important because it demonstrates that commercially valuable information structures can raise access questions under Article 102, but compulsory access requires more than merely showing that the information is useful.
The case remains one of the foundational references for analysing access to information resources.
Case 2 — Microsoft v Commission
Case: T-201/04, Microsoft Corp. v Commission
Facts
Microsoft controlled the Windows operating-system environment.
Competitors producing work-group server operating systems required interoperability information to communicate effectively with Windows PCs and servers.
Microsoft refused to provide sufficient interoperability information.
Decision
The EU courts upheld the Commission's finding concerning Microsoft's refusal to supply interoperability information.
The case involved a refusal to provide information necessary for effective interoperability rather than a conventional database-access dispute.
Importance
Microsoft demonstrates that information controlled by a dominant digital company can become a competition-law issue when withholding it restricts interoperability and downstream competition.
Application to business-user data
The reasoning is relevant to modern platforms where:
- one company controls the infrastructure;
- business users depend upon that infrastructure;
- the platform controls information necessary to operate competing services.
Case 3 — Bronner v Mediaprint
Case: C-7/97, Oscar Bronner GmbH & Co. KG v Mediaprint
Facts
Mediaprint operated an extensive newspaper-delivery system.
Bronner, a competing newspaper publisher, wanted access to the delivery infrastructure.
Judgment
The Court established strict requirements for treating refusal of access as an abuse.
The facility had to be effectively indispensable, with no actual or potential substitute, and refusal had to be capable of eliminating competition while lacking objective justification.
Importance for data
Bronner is frequently used when considering whether a dataset or digital resource should be treated as an essential facility.
A business user cannot normally demand access simply because:
"The platform has valuable data and I want it."
The question is whether the legal conditions for compulsory access are satisfied.
Case 4 — Magill
Cases: Joined Cases C-241/91 P and C-242/91 P, RTE and ITP v Commission
Facts
Television broadcasters controlled copyright-protected programme information.
A competing publisher wanted to produce comprehensive television listings.
The broadcasters refused to provide the information.
Principle
The European courts recognised exceptional circumstances in which refusal to license intellectual property could constitute abuse.
The case is particularly important because it introduced the new-product requirement in the traditional intellectual-property refusal-to-license context.
Relevance
Modern platforms frequently control datasets that competitors could use to create:
- comparison services;
- analytical tools;
- recommendation services;
- complementary products.
Magill therefore provides historical foundations for analysing compulsory access to information resources.
Case 5 — Facebook / Meta Data Case
Authority: German Federal Cartel Office (Bundeskartellamt), Facebook proceeding, 2019
This is one of the most important modern data-related competition cases.
Facts
Facebook required users, as a condition of using its social network, to permit extensive combination of data originating from:
- Facebook;
- Instagram;
- WhatsApp;
- third-party websites;
- third-party applications.
The Bundeskartellamt considered Facebook's position in the German social-network market and examined the relationship between market power and data collection.
Decision
In 2019, the Bundeskartellamt prohibited Facebook from combining certain data from different sources without voluntary user consent.
The authority considered the extensive combination of data to contribute to Facebook's competitive strength.
Importance
This case demonstrates that competition law can address data practices themselves, rather than merely traditional prices or output restrictions.
It also illustrates the relationship between:
- market power;
- data accumulation;
- contractual conditions;
- consumer choice;
- competitive advantage.
The case subsequently generated extensive litigation before German courts and questions concerning the relationship between competition law and GDPR.
Case 6 — Amazon Marketplace
Case: AT.40462 — Amazon Marketplace
This is particularly relevant to business user data.
Facts
Amazon operated a marketplace where independent sellers competed with Amazon's own retail business.
Amazon obtained substantial information from third-party sellers through their use of the marketplace.
The Commission's 2020 Statement of Objections expressed the preliminary view that Amazon had systematically relied on non-public seller data to benefit its own retail business.
The information could relate to matters such as:
- products;
- sales;
- suppliers;
- inventory;
- prices;
- commercial performance.
Commitments
In 2022, Amazon offered commitments under Article 9 of Regulation 1/2003.
Among other things, Amazon committed not to use non-public data provided by third-party sellers, or derived from their use of Amazon marketplace services, for Amazon's own retail operations in competition with those sellers.
Importance
This case illustrates a central competition problem:
The platform can become an information intermediary while simultaneously competing with the businesses that supply it with information.
The remedy therefore focused not simply on giving sellers more data, but also on restricting the platform's use of commercially sensitive seller data.
Case 7 — Google Shopping
Case: Google Search (Shopping), Case C-48/22 P
Google operated a search engine while also offering its own comparison-shopping service.
The litigation concerned Google's treatment of competing comparison-shopping services within search results.
The Court of Justice issued its judgment on 10 September 2024.
Relevance to data access
The case is broader than a pure data-access dispute, but it is important for digital-platform competition because it concerns the relationship between:
- a dominant platform;
- information organisation;
- ranking;
- downstream services;
- competitors dependent upon platform access.
It demonstrates that competition analysis of digital ecosystems cannot always be reduced to the traditional essential-facilities test.
The Court's later case law continues to distinguish situations involving an ordinary refusal of access from situations involving discriminatory or exclusionary conduct within an already-open platform environment.
Case 8 — Alphabet / Android Auto
Case: C-233/23, Alphabet and Others (Android Auto)
Facts
Google's Android Auto platform allowed third-party applications to operate within the vehicle environment.
Energy-app developer Enel X sought interoperability with Android Auto.
Judgment
On 25 February 2025, the Court of Justice addressed the application of Article 102 TFEU to interoperability with a digital platform.
The Court's approach is significant because the strict Bronner criteria are not automatically applicable to every refusal involving a digital platform that is already designed to accommodate third-party services.
Importance for business users
This is highly relevant to modern platform ecosystems.
It suggests that competition analysis may differ where:
- the platform is already open to third-party complementors;
- access is technically contemplated by the platform;
- the dispute concerns discriminatory or unjustified interoperability restrictions.
This distinction can be very important for business users seeking access to platform-controlled data or functionality.
6. Digital Markets Act: A Major Development
Traditional Article 102 case law requires detailed economic and legal analysis.
The Digital Markets Act goes further for designated gatekeepers.
Article 6(10) — Business User Data
Gatekeepers must provide business users and authorised third parties with:
- free access;
- high-quality access;
- real-time access;
to specified categories of data generated through the business user's activities on the platform.
This includes:
1. Business-user-generated data
For example:
- sales;
- performance;
- interaction;
- platform activity.
2. Anonymised end-user data
Where the statutory conditions are satisfied.
3. Personal end-user data
Where appropriate user consent has been obtained.
7. Why Article 6(10) Is Different from the Essential-Facilities Doctrine
This distinction is very important.
Traditional Article 102 analysis
A business seeking access may have to establish factors such as:
- dominance;
- indispensability;
- elimination of competition;
- lack of objective justification.
DMA approach
For designated gatekeepers, the DMA creates a specific regulatory access obligation.
Therefore, the business user does not necessarily have to prove that the dataset satisfies every element of the traditional essential-facilities doctrine.
This represents a significant movement from:
case-by-case compulsory access
towards:
ex ante data-access regulation for designated gatekeepers.
The Commission expressly describes Article 6(10) as providing business users with access to relevant data in real time.
8. Data Portability and Business Users
Another important DMA provision is Article 6(9).
It provides data-portability rights for end users and authorised third parties.
The Commission explains that authorised third-party businesses can receive user data through portability mechanisms where the user authorises the transfer.
This can reduce:
- switching costs;
- platform dependence;
- customer lock-in;
- information asymmetry.
9. Google Search Data — Recent Development
The issue has now moved beyond business-user data into competitor access to search data.
Under Article 6(11) DMA, Google is required to share specified anonymised search data with eligible competing search engines on fair, reasonable and non-discriminatory terms.
In July 2026, the European Commission adopted measures specifying how Google must provide effective access to such search data. The measures address issues including anonymisation, eligibility, pricing and access procedures.
This is significant because search data can itself become a competitive input.
10. Key Legal Tests
When analysing access to business user data, several questions should be asked.
Question 1 — Who controls the data?
Is it controlled by:
- a marketplace;
- search engine;
- app store;
- cloud provider;
- payment platform;
- social network?
Question 2 — Is the undertaking dominant?
Traditional Article 102 analysis generally requires dominance in the relevant market.
Question 3 — Is the data indispensable?
Can the requesting business obtain comparable information from:
- customers;
- alternative platforms;
- public sources;
- independent market research;
- another provider?
Question 4 — Can the data be replicated?
A dataset that can easily be reproduced is less likely to justify compulsory access than a dataset that is unique and continuously generated.
Question 5 — What is the purpose of the refusal?
The competition analysis may differ between:
- legitimate privacy protection;
- cybersecurity;
- protection of confidential information;
and:
- exclusion of competitors;
- self-preferencing;
- discriminatory treatment;
- strategic foreclosure.
Question 6 — Is the platform competing with the business user?
This is especially important in marketplace situations.
A platform that merely provides infrastructure presents a different competitive problem from a platform that:
- collects sellers' data;
- observes their performance;
- competes against them;
- uses their confidential information to improve its own competing products.
11. Data Access vs Data Sharing
Competition law should distinguish between access and sharing.
Access
The business receives the ability to retrieve or use information.
Example:
An app developer receives analytics concerning its own application's users.
Sharing
The platform transfers information to another undertaking.
Example:
A gatekeeper provides anonymised search-query data to competing search engines.
Data portability
The user or authorised third party transfers data from one platform to another.
These mechanisms address different competition problems.
12. Confidentiality and Privacy Limitations
A right of access does not mean unrestricted disclosure.
Platforms may have legitimate concerns involving:
- personal data;
- trade secrets;
- cybersecurity;
- confidential business information;
- third-party rights.
The DMA itself incorporates safeguards. For example, the Commission's 2026 Google Search data-sharing measures include anonymisation and allow assessment of serious cybersecurity and data-protection risks before sharing.
Therefore, competition law must balance:
competition + innovation + access
against:
privacy + security + confidentiality + investment incentives.
13. Self-Preferencing and Business User Data
A particularly important scenario is:
Platform → collects business data → competes with business users → uses their data to improve its own product.
The Amazon Marketplace proceeding illustrates this concern directly.
The Commission's preliminary assessment focused on Amazon's use of non-public information obtained from third-party sellers for its own retail business.
The resulting commitments created a data-silo obligation preventing Amazon Retail from using certain non-public seller data against those sellers.
Thus, the remedy can take two different forms:
Access remedy
Give business users access to relevant data.
Data-use restriction
Prevent the platform from using certain business-user data against them.
Both approaches can address information asymmetry.
14. Competition Effects
Restricting business-user data can potentially produce several effects.
| Competition concern | Possible effect |
|---|---|
| Data foreclosure | Competitors cannot obtain important information |
| Entry barriers | New firms face difficulty entering |
| Customer lock-in | Businesses cannot easily move their data |
| Self-preferencing | Platform uses information to favour its own products |
| Discrimination | Some businesses receive better access |
| Reduced innovation | Developers cannot build complementary services |
| Information asymmetry | Platform knows more about business users than they know about themselves |
| Reduced multi-homing | Businesses become dependent on one platform |
15. Defences and Objective Justifications
A platform may argue that restricting access is justified because of:
- privacy;
- cybersecurity;
- trade secrets;
- technical limitations;
- disproportionate costs;
- prevention of misuse;
- contractual obligations;
- legitimate intellectual-property interests.
These arguments must be assessed in their legal and factual context.
A blanket claim that:
"The platform owns the data, therefore nobody can access it"
is not necessarily sufficient where competition law or sector-specific regulation imposes access obligations.
Conversely, the existence of valuable data does not automatically create a competition-law right to obtain it.
16. Remedies
Competition authorities or regulators can potentially use several remedies.
A. Data-access obligation
Require the dominant platform to provide specified data.
B. Data portability
Allow businesses or authorised third parties to transfer data.
C. Interoperability
Require technical systems to work with competing services.
D. Non-discrimination
Require equivalent access conditions.
E. Data-use restrictions
Prevent a platform from using confidential business-user data to compete against those users.
F. API access
Provide automated technical access.
G. Transparency
Require clear information concerning:
- available data;
- access conditions;
- technical procedures;
- eligibility.
17. Comparison of Important Cases
| Case | Main issue | Importance for data/access |
|---|---|---|
| Magill | Refusal to license information | Exceptional compulsory-access doctrine |
| IMS Health | Information structure/IP | Indispensability and new-product principles |
| Bronner | Refusal of infrastructure access | Strict essential-facilities conditions |
| Microsoft | Interoperability information | Access to information necessary for downstream competition |
| Facebook/Meta | Combining user data | Data accumulation and exploitative abuse |
| Amazon Marketplace | Seller data used by platform retailer | Direct business-user data competition issue |
| Google Shopping | Platform ranking and downstream competition | Digital-platform exclusionary conduct |
| Android Auto | Digital-platform interoperability | Modern approach to access in open digital ecosystems |
18. Core Legal Principle
The emerging legal framework can be understood through three layers:
Layer 1 — Traditional competition law
Article 102 TFEU
Focus:
Is the dominant undertaking's refusal or use of data abusive?
Layer 2 — Digital competition regulation
Digital Markets Act
Focus:
Does a designated gatekeeper have a specific statutory obligation to provide data access, portability or interoperability?
Layer 3 — Data protection and confidentiality
Focus:
Can the data legally be transferred, and what safeguards are necessary?
The three layers increasingly operate together.
19. Conclusion
Access to business user data is becoming a central issue in competition law because data can function as a strategic competitive input.
The most important developments are:
- Traditional essential-facilities doctrine establishes demanding conditions for compulsory access.
- Microsoft, Magill and IMS Health provide foundational principles for access to information and interoperability.
- Facebook/Meta demonstrates how data collection and combination can itself become a competition concern.
- Amazon Marketplace is particularly significant because it directly concerns a platform using non-public data generated by its business users while competing with them.
- Android Auto demonstrates that modern digital-platform access disputes may require analysis beyond the strict traditional Bronner framework.
- The DMA moves beyond traditional case-by-case access litigation by imposing specific data-access and portability obligations on designated gatekeepers.
- Recent EU enforcement concerning Google Search data shows that access to large-scale datasets is now being treated as an important component of digital-market contestability.

comments