Competition Law And Data Provenance Tracking In Investigations .
Competition Law and Data Portability Enforcement Architecture
1. Introduction
Data portability enforcement architecture refers to the legal, institutional, technical and remedial framework through which individuals and businesses can obtain, transfer, reuse or continuously access data generated or supplied through a digital service, particularly where refusal or restriction of portability can weaken competition.
In traditional competition law, the central concern was often price, output and market share. In digital markets, competition can instead be weakened through:
data concentration;
network effects;
switching costs;
user lock-in;
proprietary formats;
closed ecosystems;
API restrictions;
technical barriers to migration;
discriminatory data access;
tying of data across services.
Data portability therefore becomes a competition-enabling mechanism.
A useful formula is:
Effective Data Portability = Right to Access Data + Usable Format + Timely Transfer + Technical Interoperability + Privacy/Security + Non-Discriminatory Access + Effective Enforcement
The issue is particularly important in India because the Competition Commission of India has treated data concentration, network effects, privacy and switching difficulties as relevant competitive factors in its WhatsApp proceedings. (Competition Commission of India)
2. Meaning of Data Portability
Data portability means enabling a person or authorised third party to move data from one service or platform to another in a usable manner.
For example, a user should potentially be able to move:
contacts;
photographs;
messages;
transaction records;
playlists;
documents;
account information;
purchase histories;
activity data.
But portability can take several forms.
A. Download portability
The user downloads a copy of the data.
B. Transfer portability
Data is directly transferred to another provider.
C. Continuous portability
The receiving provider obtains continuing access to relevant data with the user's authorisation.
D. Functional portability
The transferred data remains useful and interoperable in the new service.
The last form is particularly important for competition.
A technically downloadable file may be legally portable but economically useless if the competitor cannot actually use it.
3. Why Data Portability Is a Competition Issue
Consider a dominant social-media platform.
A user has accumulated:
ten years of photographs;
thousands of contacts;
messages;
followers;
preferences;
recommendations.
The user wants to switch platforms.
If migration is extremely difficult, the platform obtains an artificial advantage:
Data accumulation → switching costs → user lock-in → stronger network effects → greater market power → more data accumulation.
Portability attempts to break this cycle.
Therefore:
Data portability can transform competition from competition for new users into competition for users who can realistically switch.
4. Data Portability and Data Interoperability
These concepts are related but different.
| Data Portability | Data Interoperability |
|---|---|
| Focuses on transferring data | Focuses on systems interacting |
| User can move data | Different services can communicate |
| Can be one-time | Often continuous |
| Reduces switching costs | Reduces ecosystem barriers |
| Example: export contacts | Example: messaging across platforms |
A mature competition framework may require both.
5. Legal Foundations in India
Competition Act, 2002
The principal competition-law provisions include:
Section 3
Deals with anti-competitive agreements.
Data-sharing arrangements may raise concerns if they:
facilitate collusion;
restrict competition;
exclude competitors.
Section 4
Deals with abuse of dominant position.
It is especially important where a dominant digital platform:
imposes unfair conditions;
denies market access;
discriminates against competitors;
leverages dominance;
restricts switching.
Sections 19 and 26
Provide the investigative framework through which the CCI can examine suspected anti-competitive conduct.
Section 27
Provides remedial powers following a finding of contravention.
6. Data Protection Dimension
Data portability cannot be considered independently of privacy.
The Digital Personal Data Protection Act, 2023 establishes a framework governing processing of digital personal data.
This produces an important legal balance:
Competition law may encourage portability, while data-protection law may restrict uncontrolled disclosure.
Therefore, an enforcement architecture must distinguish:
data that the user can legitimately transfer;
third-party personal data;
confidential business information;
trade secrets;
sensitive information;
information subject to statutory restrictions.
7. International Benchmark – Digital Markets Act
The EU Digital Markets Act provides an important example of an ex ante data-portability enforcement architecture.
Article 6(9) requires designated gatekeepers to facilitate portability of user-provided or user-generated data, including free tools and, in the relevant circumstances, continuous and real-time access. (Digital Markets Act (DMA))
The European Commission's 2026 implementation materials describe data portability as a mechanism designed to increase:
user control;
innovation;
contestability;
switching opportunities. (Digital Markets Act (DMA))
This differs from traditional Indian competition law, which generally intervenes after identifying anti-competitive conduct.
8. Enforcement Architecture – The Basic Model
An effective system can be divided into nine stages:
Stage 1 – Identify the relevant market
Stage 2 – Determine market power
Stage 3 – Identify the data controlled
Stage 4 – Determine the portability barrier
Stage 5 – Establish competitive harm
Stage 6 – Examine privacy/security limitations
Stage 7 – Select an appropriate remedy
Stage 8 – Monitor technical compliance
Stage 9 – Impose sanctions for non-compliance
Thus:
Competition analysis → portability obligation → technical implementation → monitoring → enforcement → review
9. Major Case Law
Case 1 – In Re: Updated Terms of Service and Privacy Policy for WhatsApp Users
CCI, 18 November 2024
This is one of the most important Indian decisions for the relationship between data, dominance and competition.
The CCI examined WhatsApp's 2021 privacy-policy update and its data-sharing relationship with Meta.
The Commission found violations under Section 4 and imposed a penalty of approximately ₹213.14 crore, together with behavioural remedies. (Competition Commission of India)
Competition significance
The CCI treated data concentration and privacy-related quality as potentially relevant non-price parameters of competition.
The case demonstrated that:
A "free" digital service may still compete through privacy, data practices and quality.
Portability significance
The CCI had earlier noted the difficulty of porting historical WhatsApp data and the significance of network effects and switching costs. (Competition Commission of India)
Therefore, the case provides an important Indian foundation for understanding:
data concentration + switching costs + network effects + competition.
10. Case 2 – Meta Platforms Inc. v. Competition Commission of India
NCLAT, 4 November 2025
The NCLAT largely upheld the CCI's findings concerning WhatsApp's 2021 privacy policy.
The Tribunal upheld findings concerning unfair conditions under Section 4(2)(a)(i) and denial of market access under Section 4(2)(c), while modifying the treatment of another statutory provision. (Indian Kanoon)
The remedial framework required important changes concerning:
explanation of data sharing;
purposes of data sharing;
user choice;
opt-out mechanisms;
future policy updates.
The decision is significant because it demonstrates that competition remedies can address how data is collected and shared, not merely traditional pricing behaviour. (Indian Kanoon)
Data-portability lesson
An enforcement system must not merely order a company to "allow portability."
It must specify:
what data;
in what format;
for which purposes;
to whom;
through what technical mechanism;
subject to what privacy safeguards.
11. Case 3 – Harshita Chawla v. WhatsApp Inc. & Others
CCI Case No. 15/2020
The CCI considered allegations concerning WhatsApp's position in the digital messaging ecosystem.
The case is important for understanding:
network effects;
digital-platform dominance;
data;
consumer choice;
competitive constraints.
The CCI's records identify the proceeding as an antitrust matter under Section 19(1)(a). (Competition Commission of India)
Relevance
Data portability is particularly important in markets characterised by strong network effects.
If users cannot practically transfer their social relationships and data, a competitor may struggle to attract users even if it offers a technically superior product.
12. Case 4 – Umar Javeed & Others v. Google LLC & Another
CCI – Android Ecosystem Proceedings
The CCI's Android proceedings examined Google's position across several interconnected digital markets.
The Android ecosystem involved:
operating systems;
app stores;
search;
mobile applications;
device manufacturers;
Google Mobile Services.
Competition principle
The case demonstrates the importance of ecosystem control.
A dominant platform may exercise power not simply through one product but through a network:
Operating system → application distribution → search → data → users → advertising.
Portability relevance
Data portability can become particularly important where consumers are effectively locked into an ecosystem.
The lesson is:
Portability enforcement must sometimes be ecosystem-wide rather than limited to a single application.
13. Case 5 – Microsoft Corp. v. Commission
Case T-201/04, General Court of the European Union
Microsoft is a foundational interoperability case.
The European Commission found that Microsoft had unlawfully refused to provide interoperability information necessary for competitors to compete effectively in the work-group server market.
The General Court upheld the central interoperability findings.
Relevance to data portability
Although the case primarily concerned interoperability information rather than modern consumer-data portability, it establishes an important principle:
A dominant undertaking's control over an important technological interface can become a competition problem when that control prevents effective competition.
Enforcement lesson
Portability enforcement cannot focus solely on whether data is technically exportable.
The regulator must examine whether:
The receiving competitor can actually use the exported information to compete.
14. Case 6 – United States v. Microsoft Corp.
253 F.3d 34 (D.C. Cir. 2001)
Microsoft's operating-system dominance and conduct affecting competing technologies were examined under U.S. antitrust law.
The case demonstrated the importance of:
network effects;
technological barriers;
platform power;
exclusionary conduct.
Relevance to portability
A dominant platform can strengthen its position by controlling the technological environment in which competitors operate.
Data portability can reduce one form of this lock-in by giving users greater ability to move.
15. Case 7 – Google LLC and Alphabet Inc. v. European Commission
Case T-604/18
The Google Android litigation examined Google's contractual arrangements and conduct across the Android ecosystem.
The case is important because it demonstrates how:
operating-system control;
app distribution;
search;
device manufacturers;
ecosystem effects
can reinforce market power.
Portability significance
A portability regime should consider the ecosystem, not merely the individual service.
For example:
If a user can export data from an app but cannot transfer identity, authentication, contacts or associated services, practical switching may remain difficult.
16. Case 8 – Bronner v. Mediaprint
Case C-7/97, CJEU
This case provides an important limitation on compulsory access.
The CJEU did not treat every economically valuable facility controlled by a dominant undertaking as automatically subject to compulsory access.
Relevance
This principle prevents data-portability law from becoming:
"Every successful company must give every competitor all its data."
Instead, compulsory access should normally be justified through factors such as:
indispensability;
inability to reasonably duplicate;
elimination of effective competition;
lack of objective justification.
17. Case 9 – IMS Health GmbH & Co. OHG v. NDC Health
Case C-418/01, CJEU
The case concerned refusal to license an intellectual-property-related system and the exceptional circumstances under which refusal may amount to abuse of dominance.
Relevance to portability
Data may exist within:
proprietary databases;
protected technological systems;
confidential architectures.
Therefore, portability obligations must respect legitimate intellectual-property interests.
The key principle is:
Competition law can require access in exceptional circumstances, but compulsory access must be carefully justified.
18. Enforcement Architecture in Detail
A. Complaint and Detection Layer
Potential cases may originate through:
consumer complaints;
competitor complaints;
market studies;
sector inquiries;
whistleblowers;
CCI suo motu information;
technological audits.
The WhatsApp proceedings demonstrate the importance of suo motu competition investigation in digital markets. (Competition Commission of India)
19. Market-Definition Layer
The regulator must identify the relevant market.
Potential markets include:
social networking;
OTT messaging;
online advertising;
cloud computing;
search;
mobile operating systems;
digital payments.
Traditional market-share analysis may be insufficient.
The regulator should also examine:
data advantages;
network effects;
switching costs;
multi-homing;
ecosystem dependence.
20. Data-Resource Identification Layer
The regulator should identify:
User-provided data
Information directly supplied by the user.
Observed data
Data generated by observing user activity.
Derived data
Data generated through analytics or algorithms.
Inferred data
Predictions concerning a user.
Third-party data
Information concerning another person or business.
This distinction matters because not all data should necessarily receive identical portability treatment.
21. Portability-Barrier Assessment
A regulator should ask:
Is the data technically exportable?
If yes, continue.
Is it machine-readable?
If no, portability may be ineffective.
Can the receiving provider use it?
If no, practical portability may be absent.
Is transfer excessively slow?
If yes, switching costs remain.
Are fees excessive?
If yes, the right may become illusory.
Does the dominant platform impose contractual restrictions?
If yes, investigate.
22. Competitive-Harm Assessment
The regulator should establish whether the portability restriction causes:
foreclosure;
entry barriers;
customer lock-in;
reduced innovation;
reduced consumer choice;
reduced quality competition;
data monopolisation.
A mere inconvenience is not necessarily an antitrust violation.
The restriction should have meaningful competitive significance.
23. Privacy Assessment
Portability cannot override legitimate privacy requirements.
Suppose a user's social-media account contains:
the user's own information;
another person's private messages;
third-party photographs.
The user may not automatically possess unrestricted authority to transfer all third-party information.
Therefore, an enforcement framework needs:
Competition test + data-protection test.
24. Technical Compliance Layer
A portability order should specify technical standards.
Possible requirements:
APIs;
machine-readable formats;
authentication;
encryption;
standard schemas;
transfer protocols;
documentation;
audit logs.
A vague order such as:
"Provide reasonable portability"
may produce years of technical disputes.
25. Monitoring Layer
Enforcement should continue after the order.
A dominant undertaking might technically comply while creating practical obstacles.
Examples:
API delays;
reduced functionality;
restrictive rate limits;
excessive authentication requirements;
unexplained technical errors;
incomplete datasets.
Therefore, regulators need:
technical audits;
compliance reports;
independent monitoring;
user testing.
26. Remedy Design
Possible remedies include:
1. Data-export obligation
Require downloadable copies.
2. Direct transfer
Require transfer directly to another provider.
3. Continuous access
Permit authorised third parties continuing access.
4. API interoperability
Require technical interfaces.
5. Non-discrimination
Prevent preferential treatment of the dominant firm's services.
6. Standardisation
Require interoperable formats.
7. Data-sharing restrictions
Prevent inappropriate use of ported data.
27. Sanctions and Enforcement
Effective enforcement requires consequences for non-compliance.
Possible mechanisms include:
monetary penalties;
behavioural directions;
compliance deadlines;
periodic reporting;
independent monitoring;
further proceedings for continuing violations.
The WhatsApp/Meta proceedings illustrate the use of substantial behavioural remedies in addition to monetary penalties. (Indian Kanoon)
28. Difference Between Ex Post and Ex Ante Enforcement
Ex Post
Traditional Competition Act approach:
Harm suspected → investigation → finding → remedy
Advantage:
flexible;
case-specific.
Disadvantage:
can be slow;
harm may already be entrenched.
Ex Ante
DMA-type approach:
Gatekeeper identified → predefined portability obligation → continuous compliance monitoring
Advantage:
preventive;
predictable;
faster.
Disadvantage:
can impose obligations even before conventional antitrust harm is fully established.
29. Indian Model vs EU Model
| Feature | Indian Competition Model | EU DMA Model |
|---|---|---|
| Basic approach | Primarily ex post | Ex ante + ex post |
| Main authority | CCI | European Commission |
| Dominance inquiry | Important | Gatekeeper designation framework |
| Data portability | Not a single comprehensive competition-law right | Express DMA obligation |
| Technical compliance | Case-specific | Detailed regulatory compliance |
| Monitoring | Investigation/order-based | Continuous gatekeeper supervision |
| Penalties | Competition Act framework | DMA sanctions and remedies |
| Privacy interaction | Competition + DPDP framework | DMA + GDPR + Data Act |
The EU model explicitly provides portability rights under Article 6(9), including tools designed to make transfers easy and, in relevant circumstances, continuous and real-time. (Digital Markets Act (DMA))
30. Data Portability and the Data Act
The EU Data Act, applicable from September 2025, complements the DMA by addressing broader data-access and switching issues, including connected-product data and cloud switching. (Digital Strategy)
This demonstrates an important regulatory architecture:
Competition law + ex ante digital regulation + horizontal data-access regulation + privacy law
rather than attempting to solve every data problem through competition law alone.
31. Data Portability and Cloud Competition
Cloud markets present major portability problems.
A business may spend years building its operations around:
AWS;
Microsoft Azure;
Google Cloud;
specialised SaaS services.
Switching can involve:
data migration;
application redevelopment;
identity migration;
API replacement;
employee retraining.
These are switching costs.
Therefore, portability enforcement may need to include:
export rights;
interoperable APIs;
migration assistance;
standard formats;
restrictions on technical lock-in.
32. Data Portability and Artificial Intelligence
AI markets create new questions.
Suppose a user has accumulated years of:
prompts;
model interactions;
preferences;
customised workflows;
generated content.
If these cannot be moved to another AI provider, switching costs increase.
At an enterprise level, AI portability can concern:
training data;
fine-tuning datasets;
embeddings;
workflows;
model configurations;
user-generated content.
Competition authorities may increasingly have to determine which of these should be portable.
33. Data Portability and Consumer Welfare
Portability can increase:
Choice
Users can switch providers.
Quality competition
Platforms must improve service quality.
Privacy competition
Platforms may compete through stronger privacy.
Innovation
New entrants can build complementary services.
Bargaining power
Consumers are less dependent upon one provider.
34. Data Portability and Small Businesses
Small businesses may be particularly affected by data lock-in.
A business could depend upon one platform for:
customer reviews;
advertising data;
transaction records;
customer relationships;
analytics.
If the business cannot move those assets, the platform may acquire significant bargaining power.
Therefore, portability can be a SME competition mechanism, not merely a consumer right.
35. Risks of Over-Enforcement
1. Privacy leakage
Transferred data may expose third parties.
2. Cybersecurity risks
APIs create attack surfaces.
3. Free-riding
Competitors may exploit another company's investment.
4. Innovation disincentives
Excessive sharing can reduce investment incentives.
5. Administrative burden
Small providers may struggle to comply.
6. Data-quality disputes
Parties may disagree about whether data is:
accurate;
complete;
derived;
personal;
proprietary.
36. Proportionality Test
A portability obligation should ideally satisfy four questions:
1. Legitimate objective
Does it promote competition or reduce lock-in?
2. Suitability
Will portability actually improve contestability?
3. Necessity
Is there a less restrictive alternative?
4. Balancing
Do competitive benefits outweigh:
privacy;
security;
intellectual-property;
innovation costs?
37. Ideal Indian Enforcement Architecture
India could develop a coordinated framework involving:
Competition Commission of India
Focus:
market power;
exclusion;
foreclosure;
abuse of dominance.
Data Protection Authority/competent data-governance institution
Focus:
lawful processing;
privacy;
data security;
user rights.
Sectoral regulators
Examples:
RBI for financial services;
TRAI for telecommunications;
sector-specific health authorities where applicable.
Technical standard-setting institutions
Focus:
APIs;
interoperability;
data formats;
cybersecurity.
This creates:
Competition regulator + data regulator + sector regulator + technical regulator
with coordination mechanisms.
38. A Proposed Data Portability Enforcement Flowchart
Complaint / Market Study
↓
Relevant Market Identification
↓
Dominance / Gatekeeper Assessment
↓
Identify Data and Portability Barrier
↓
Assess Network Effects and Switching Costs
↓
Determine Competitive Harm
↓
Privacy + Security + IP Assessment
↓
Proportionality Analysis
↓
Portability / Interoperability Remedy
↓
Technical Compliance Plan
↓
Independent Monitoring
↓
Penalty / Corrective Action for Non-Compliance
↓
Periodic Review
39. Important Case-Law Table
| Case | Court/Authority | Main Principle | Data-Portability Relevance |
|---|---|---|---|
| In Re WhatsApp Privacy Policy | CCI, 2024 | Data practices can affect competition | Strong Indian data-competition authority |
| Meta v. CCI | NCLAT, 2025 | Unfair data-related conditions and denial of market access | Behavioural data remedies |
| Harshita Chawla v. WhatsApp | CCI, 2020 | Digital-platform competition | Network effects |
| Umar Javeed v. Google | CCI | Android ecosystem dominance | Ecosystem lock-in |
| Microsoft v. Commission, T-201/04 | EU General Court | Interoperability can be required in exceptional circumstances | Technical access |
| US v. Microsoft | US Court of Appeals | Platform/network effects and exclusion | Technology lock-in |
| Google Android, T-604/18 | EU General Court | Ecosystem control and competition | Platform dependency |
| Bronner v. Mediaprint | CJEU | Limits of compulsory access | Prevents overbroad data-access duties |
| IMS Health v. NDC Health | CJEU | Exceptional compulsory access involving IP | Data/IP balance |
40. Critical Legal Issues
Issue 1 – Who owns the data?
Competition law should not simply assume that every economically valuable dataset belongs to the platform.
The analysis should distinguish:
user-generated data;
platform-generated data;
derived data;
inferred data;
third-party data.
Issue 2 – Should competitors receive the data?
Not automatically.
The regulator should establish:
necessity;
competitive significance;
proportionality.
Issue 3 – Should portability be free?
For consumers, free or low-cost portability can be essential to prevent switching barriers.
For commercial transfers, reasonable cost allocation may sometimes be appropriate.
The regulatory model must therefore distinguish between:
consumer portability;
business portability;
mandated third-party access.
41. Important Principle: Portability Must Be Effective
A company should not be able to say:
"We provide portability because users can download a 400-page PDF."
That may satisfy a formal requirement but not a substantive one.
Effective portability requires:
machine readability;
completeness;
timeliness;
usability;
compatibility.
Therefore:
Formal portability is not necessarily effective portability.
42. Important Principle: Portability Must Be Secure
A portability regime should establish:
authentication;
authorisation;
encryption;
access logging;
fraud prevention;
data minimisation.
Otherwise, a portability right could itself become a cybersecurity vulnerability.
43. Important Principle: Portability Must Be Non-Discriminatory
A dominant firm should not provide:
Fast + complete + high-quality data access to its own subsidiary
while giving competitors:
Slow + incomplete + restricted access.
Such discriminatory interoperability can itself create competitive harm.
44. Emerging 2026 Direction
The latest EU digital-market developments illustrate the movement toward technical enforcement rather than merely legal declarations.
The European Commission's 2026 materials report new portability mechanisms involving device data transfers and interoperability requirements for gatekeepers. (Digital Markets Act (DMA))
The Commission's 2026 DMA review also identifies continuing technical difficulties in making interoperability genuinely effective, showing that implementation quality is becoming as important as the legal right itself. (Digital Markets Act (DMA))
This is an important lesson for India:
A portability statute without technical enforcement capacity may create a right on paper but not meaningful competition in practice.
45. Examination-Oriented Analytical Framework
For a problem question, use this sequence:
Step 1
Identify the digital market.
Step 2
Determine whether the undertaking has substantial market power.
Step 3
Identify the relevant dataset.
Step 4
Determine whether users or competitors face switching costs.
Step 5
Identify the portability restriction.
Step 6
Determine whether the restriction forecloses competitors.
Step 7
Examine privacy, cybersecurity and IP limitations.
Step 8
Apply proportionality.
Step 9
Select the least restrictive effective remedy.
Step 10
Create a monitoring and enforcement mechanism.
46. Core Formula
Data Portability Enforcement = Market Power + Data Control + Switching Costs + Network Effects + Portability Barrier + Competitive Harm + Privacy/Security Safeguards + Proportionate Remedy + Technical Monitoring.
47. Conclusion
Competition Law and Data Portability Enforcement Architecture represents a shift from viewing data merely as an information asset toward recognising it as a potential source of market power, switching costs and competitive advantage.
The Indian WhatsApp/Meta proceedings demonstrate that data practices can form part of an abuse-of-dominance analysis and can result in substantial behavioural remedies. (Competition Commission of India)
The Microsoft, Google Android, Bronner and IMS Health jurisprudence provides broader principles concerning:
technological bottlenecks;
interoperability;
essential facilities;
refusal to supply;
intellectual-property interests;
proportionality.
The strongest enforcement architecture therefore should not rely exclusively upon traditional antitrust litigation.
It should combine:
Competition Law + Data Protection + Data Portability + Interoperability + Technical Standards + Cybersecurity + Sectoral Regulation + Continuous Monitoring.
The ultimate objective is contestable digital markets in which consumers and businesses can realistically leave a dominant platform without losing the accumulated value of their data.
Thus:
A data-portability right becomes a genuine competition remedy only when data is transferable, usable, interoperable, secure, timely, non-discriminatory and backed by an institution capable of enforcing those requirements.

comments