Competition Law And Data Provenance Tracking In Investigations .

Competition Law and Data Portability Enforcement Architecture

1. Introduction

Data portability enforcement architecture refers to the legal, institutional, technical and remedial framework through which individuals and businesses can obtain, transfer, reuse or continuously access data generated or supplied through a digital service, particularly where refusal or restriction of portability can weaken competition.

In traditional competition law, the central concern was often price, output and market share. In digital markets, competition can instead be weakened through:

data concentration;

network effects;

switching costs;

user lock-in;

proprietary formats;

closed ecosystems;

API restrictions;

technical barriers to migration;

discriminatory data access;

tying of data across services.

Data portability therefore becomes a competition-enabling mechanism.

A useful formula is:

Effective Data Portability = Right to Access Data + Usable Format + Timely Transfer + Technical Interoperability + Privacy/Security + Non-Discriminatory Access + Effective Enforcement

The issue is particularly important in India because the Competition Commission of India has treated data concentration, network effects, privacy and switching difficulties as relevant competitive factors in its WhatsApp proceedings. (Competition Commission of India)

2. Meaning of Data Portability

Data portability means enabling a person or authorised third party to move data from one service or platform to another in a usable manner.

For example, a user should potentially be able to move:

contacts;

photographs;

messages;

transaction records;

playlists;

documents;

account information;

purchase histories;

activity data.

But portability can take several forms.

A. Download portability

The user downloads a copy of the data.

B. Transfer portability

Data is directly transferred to another provider.

C. Continuous portability

The receiving provider obtains continuing access to relevant data with the user's authorisation.

D. Functional portability

The transferred data remains useful and interoperable in the new service.

The last form is particularly important for competition.

A technically downloadable file may be legally portable but economically useless if the competitor cannot actually use it.

3. Why Data Portability Is a Competition Issue

Consider a dominant social-media platform.

A user has accumulated:

ten years of photographs;

thousands of contacts;

messages;

followers;

preferences;

recommendations.

The user wants to switch platforms.

If migration is extremely difficult, the platform obtains an artificial advantage:

Data accumulation → switching costs → user lock-in → stronger network effects → greater market power → more data accumulation.

Portability attempts to break this cycle.

Therefore:

Data portability can transform competition from competition for new users into competition for users who can realistically switch.

4. Data Portability and Data Interoperability

These concepts are related but different.

Data PortabilityData Interoperability
Focuses on transferring dataFocuses on systems interacting
User can move dataDifferent services can communicate
Can be one-timeOften continuous
Reduces switching costsReduces ecosystem barriers
Example: export contactsExample: messaging across platforms

A mature competition framework may require both.

5. Legal Foundations in India

Competition Act, 2002

The principal competition-law provisions include:

Section 3

Deals with anti-competitive agreements.

Data-sharing arrangements may raise concerns if they:

facilitate collusion;

restrict competition;

exclude competitors.

Section 4

Deals with abuse of dominant position.

It is especially important where a dominant digital platform:

imposes unfair conditions;

denies market access;

discriminates against competitors;

leverages dominance;

restricts switching.

Sections 19 and 26

Provide the investigative framework through which the CCI can examine suspected anti-competitive conduct.

Section 27

Provides remedial powers following a finding of contravention.

6. Data Protection Dimension

Data portability cannot be considered independently of privacy.

The Digital Personal Data Protection Act, 2023 establishes a framework governing processing of digital personal data.

This produces an important legal balance:

Competition law may encourage portability, while data-protection law may restrict uncontrolled disclosure.

Therefore, an enforcement architecture must distinguish:

data that the user can legitimately transfer;

third-party personal data;

confidential business information;

trade secrets;

sensitive information;

information subject to statutory restrictions.

7. International Benchmark – Digital Markets Act

The EU Digital Markets Act provides an important example of an ex ante data-portability enforcement architecture.

Article 6(9) requires designated gatekeepers to facilitate portability of user-provided or user-generated data, including free tools and, in the relevant circumstances, continuous and real-time access. (Digital Markets Act (DMA))

The European Commission's 2026 implementation materials describe data portability as a mechanism designed to increase:

user control;

innovation;

contestability;

switching opportunities. (Digital Markets Act (DMA))

This differs from traditional Indian competition law, which generally intervenes after identifying anti-competitive conduct.

8. Enforcement Architecture – The Basic Model

An effective system can be divided into nine stages:

Stage 1 – Identify the relevant market

Stage 2 – Determine market power

Stage 3 – Identify the data controlled

Stage 4 – Determine the portability barrier

Stage 5 – Establish competitive harm

Stage 6 – Examine privacy/security limitations

Stage 7 – Select an appropriate remedy

Stage 8 – Monitor technical compliance

Stage 9 – Impose sanctions for non-compliance

Thus:

Competition analysis → portability obligation → technical implementation → monitoring → enforcement → review

9. Major Case Law

Case 1 – In Re: Updated Terms of Service and Privacy Policy for WhatsApp Users

CCI, 18 November 2024

This is one of the most important Indian decisions for the relationship between data, dominance and competition.

The CCI examined WhatsApp's 2021 privacy-policy update and its data-sharing relationship with Meta.

The Commission found violations under Section 4 and imposed a penalty of approximately ₹213.14 crore, together with behavioural remedies. (Competition Commission of India)

Competition significance

The CCI treated data concentration and privacy-related quality as potentially relevant non-price parameters of competition.

The case demonstrated that:

A "free" digital service may still compete through privacy, data practices and quality.

Portability significance

The CCI had earlier noted the difficulty of porting historical WhatsApp data and the significance of network effects and switching costs. (Competition Commission of India)

Therefore, the case provides an important Indian foundation for understanding:

data concentration + switching costs + network effects + competition.

10. Case 2 – Meta Platforms Inc. v. Competition Commission of India

NCLAT, 4 November 2025

The NCLAT largely upheld the CCI's findings concerning WhatsApp's 2021 privacy policy.

The Tribunal upheld findings concerning unfair conditions under Section 4(2)(a)(i) and denial of market access under Section 4(2)(c), while modifying the treatment of another statutory provision. (Indian Kanoon)

The remedial framework required important changes concerning:

explanation of data sharing;

purposes of data sharing;

user choice;

opt-out mechanisms;

future policy updates.

The decision is significant because it demonstrates that competition remedies can address how data is collected and shared, not merely traditional pricing behaviour. (Indian Kanoon)

Data-portability lesson

An enforcement system must not merely order a company to "allow portability."

It must specify:

what data;

in what format;

for which purposes;

to whom;

through what technical mechanism;

subject to what privacy safeguards.

11. Case 3 – Harshita Chawla v. WhatsApp Inc. & Others

CCI Case No. 15/2020

The CCI considered allegations concerning WhatsApp's position in the digital messaging ecosystem.

The case is important for understanding:

network effects;

digital-platform dominance;

data;

consumer choice;

competitive constraints.

The CCI's records identify the proceeding as an antitrust matter under Section 19(1)(a). (Competition Commission of India)

Relevance

Data portability is particularly important in markets characterised by strong network effects.

If users cannot practically transfer their social relationships and data, a competitor may struggle to attract users even if it offers a technically superior product.

12. Case 4 – Umar Javeed & Others v. Google LLC & Another

CCI – Android Ecosystem Proceedings

The CCI's Android proceedings examined Google's position across several interconnected digital markets.

The Android ecosystem involved:

operating systems;

app stores;

search;

mobile applications;

device manufacturers;

Google Mobile Services.

Competition principle

The case demonstrates the importance of ecosystem control.

A dominant platform may exercise power not simply through one product but through a network:

Operating system → application distribution → search → data → users → advertising.

Portability relevance

Data portability can become particularly important where consumers are effectively locked into an ecosystem.

The lesson is:

Portability enforcement must sometimes be ecosystem-wide rather than limited to a single application.

13. Case 5 – Microsoft Corp. v. Commission

Case T-201/04, General Court of the European Union

Microsoft is a foundational interoperability case.

The European Commission found that Microsoft had unlawfully refused to provide interoperability information necessary for competitors to compete effectively in the work-group server market.

The General Court upheld the central interoperability findings.

Relevance to data portability

Although the case primarily concerned interoperability information rather than modern consumer-data portability, it establishes an important principle:

A dominant undertaking's control over an important technological interface can become a competition problem when that control prevents effective competition.

Enforcement lesson

Portability enforcement cannot focus solely on whether data is technically exportable.

The regulator must examine whether:

The receiving competitor can actually use the exported information to compete.

14. Case 6 – United States v. Microsoft Corp.

253 F.3d 34 (D.C. Cir. 2001)

Microsoft's operating-system dominance and conduct affecting competing technologies were examined under U.S. antitrust law.

The case demonstrated the importance of:

network effects;

technological barriers;

platform power;

exclusionary conduct.

Relevance to portability

A dominant platform can strengthen its position by controlling the technological environment in which competitors operate.

Data portability can reduce one form of this lock-in by giving users greater ability to move.

15. Case 7 – Google LLC and Alphabet Inc. v. European Commission

Case T-604/18

The Google Android litigation examined Google's contractual arrangements and conduct across the Android ecosystem.

The case is important because it demonstrates how:

operating-system control;

app distribution;

search;

device manufacturers;

ecosystem effects

can reinforce market power.

Portability significance

A portability regime should consider the ecosystem, not merely the individual service.

For example:

If a user can export data from an app but cannot transfer identity, authentication, contacts or associated services, practical switching may remain difficult.

16. Case 8 – Bronner v. Mediaprint

Case C-7/97, CJEU

This case provides an important limitation on compulsory access.

The CJEU did not treat every economically valuable facility controlled by a dominant undertaking as automatically subject to compulsory access.

Relevance

This principle prevents data-portability law from becoming:

"Every successful company must give every competitor all its data."

Instead, compulsory access should normally be justified through factors such as:

indispensability;

inability to reasonably duplicate;

elimination of effective competition;

lack of objective justification.

17. Case 9 – IMS Health GmbH & Co. OHG v. NDC Health

Case C-418/01, CJEU

The case concerned refusal to license an intellectual-property-related system and the exceptional circumstances under which refusal may amount to abuse of dominance.

Relevance to portability

Data may exist within:

proprietary databases;

protected technological systems;

confidential architectures.

Therefore, portability obligations must respect legitimate intellectual-property interests.

The key principle is:

Competition law can require access in exceptional circumstances, but compulsory access must be carefully justified.

18. Enforcement Architecture in Detail

A. Complaint and Detection Layer

Potential cases may originate through:

consumer complaints;

competitor complaints;

market studies;

sector inquiries;

whistleblowers;

CCI suo motu information;

technological audits.

The WhatsApp proceedings demonstrate the importance of suo motu competition investigation in digital markets. (Competition Commission of India)

19. Market-Definition Layer

The regulator must identify the relevant market.

Potential markets include:

social networking;

OTT messaging;

online advertising;

cloud computing;

search;

mobile operating systems;

digital payments.

Traditional market-share analysis may be insufficient.

The regulator should also examine:

data advantages;

network effects;

switching costs;

multi-homing;

ecosystem dependence.

20. Data-Resource Identification Layer

The regulator should identify:

User-provided data

Information directly supplied by the user.

Observed data

Data generated by observing user activity.

Derived data

Data generated through analytics or algorithms.

Inferred data

Predictions concerning a user.

Third-party data

Information concerning another person or business.

This distinction matters because not all data should necessarily receive identical portability treatment.

21. Portability-Barrier Assessment

A regulator should ask:

Is the data technically exportable?

If yes, continue.

Is it machine-readable?

If no, portability may be ineffective.

Can the receiving provider use it?

If no, practical portability may be absent.

Is transfer excessively slow?

If yes, switching costs remain.

Are fees excessive?

If yes, the right may become illusory.

Does the dominant platform impose contractual restrictions?

If yes, investigate.

22. Competitive-Harm Assessment

The regulator should establish whether the portability restriction causes:

foreclosure;

entry barriers;

customer lock-in;

reduced innovation;

reduced consumer choice;

reduced quality competition;

data monopolisation.

A mere inconvenience is not necessarily an antitrust violation.

The restriction should have meaningful competitive significance.

23. Privacy Assessment

Portability cannot override legitimate privacy requirements.

Suppose a user's social-media account contains:

the user's own information;

another person's private messages;

third-party photographs.

The user may not automatically possess unrestricted authority to transfer all third-party information.

Therefore, an enforcement framework needs:

Competition test + data-protection test.

24. Technical Compliance Layer

A portability order should specify technical standards.

Possible requirements:

APIs;

machine-readable formats;

authentication;

encryption;

standard schemas;

transfer protocols;

documentation;

audit logs.

A vague order such as:

"Provide reasonable portability"

may produce years of technical disputes.

25. Monitoring Layer

Enforcement should continue after the order.

A dominant undertaking might technically comply while creating practical obstacles.

Examples:

API delays;

reduced functionality;

restrictive rate limits;

excessive authentication requirements;

unexplained technical errors;

incomplete datasets.

Therefore, regulators need:

technical audits;

compliance reports;

independent monitoring;

user testing.

26. Remedy Design

Possible remedies include:

1. Data-export obligation

Require downloadable copies.

2. Direct transfer

Require transfer directly to another provider.

3. Continuous access

Permit authorised third parties continuing access.

4. API interoperability

Require technical interfaces.

5. Non-discrimination

Prevent preferential treatment of the dominant firm's services.

6. Standardisation

Require interoperable formats.

7. Data-sharing restrictions

Prevent inappropriate use of ported data.

27. Sanctions and Enforcement

Effective enforcement requires consequences for non-compliance.

Possible mechanisms include:

monetary penalties;

behavioural directions;

compliance deadlines;

periodic reporting;

independent monitoring;

further proceedings for continuing violations.

The WhatsApp/Meta proceedings illustrate the use of substantial behavioural remedies in addition to monetary penalties. (Indian Kanoon)

28. Difference Between Ex Post and Ex Ante Enforcement

Ex Post

Traditional Competition Act approach:

Harm suspected → investigation → finding → remedy

Advantage:

flexible;

case-specific.

Disadvantage:

can be slow;

harm may already be entrenched.

Ex Ante

DMA-type approach:

Gatekeeper identified → predefined portability obligation → continuous compliance monitoring

Advantage:

preventive;

predictable;

faster.

Disadvantage:

can impose obligations even before conventional antitrust harm is fully established.

29. Indian Model vs EU Model

FeatureIndian Competition ModelEU DMA Model
Basic approachPrimarily ex postEx ante + ex post
Main authorityCCIEuropean Commission
Dominance inquiryImportantGatekeeper designation framework
Data portabilityNot a single comprehensive competition-law rightExpress DMA obligation
Technical complianceCase-specificDetailed regulatory compliance
MonitoringInvestigation/order-basedContinuous gatekeeper supervision
PenaltiesCompetition Act frameworkDMA sanctions and remedies
Privacy interactionCompetition + DPDP frameworkDMA + GDPR + Data Act

The EU model explicitly provides portability rights under Article 6(9), including tools designed to make transfers easy and, in relevant circumstances, continuous and real-time. (Digital Markets Act (DMA))

30. Data Portability and the Data Act

The EU Data Act, applicable from September 2025, complements the DMA by addressing broader data-access and switching issues, including connected-product data and cloud switching. (Digital Strategy)

This demonstrates an important regulatory architecture:

Competition law + ex ante digital regulation + horizontal data-access regulation + privacy law

rather than attempting to solve every data problem through competition law alone.

31. Data Portability and Cloud Competition

Cloud markets present major portability problems.

A business may spend years building its operations around:

AWS;

Microsoft Azure;

Google Cloud;

specialised SaaS services.

Switching can involve:

data migration;

application redevelopment;

identity migration;

API replacement;

employee retraining.

These are switching costs.

Therefore, portability enforcement may need to include:

export rights;

interoperable APIs;

migration assistance;

standard formats;

restrictions on technical lock-in.

32. Data Portability and Artificial Intelligence

AI markets create new questions.

Suppose a user has accumulated years of:

prompts;

model interactions;

preferences;

customised workflows;

generated content.

If these cannot be moved to another AI provider, switching costs increase.

At an enterprise level, AI portability can concern:

training data;

fine-tuning datasets;

embeddings;

workflows;

model configurations;

user-generated content.

Competition authorities may increasingly have to determine which of these should be portable.

33. Data Portability and Consumer Welfare

Portability can increase:

Choice

Users can switch providers.

Quality competition

Platforms must improve service quality.

Privacy competition

Platforms may compete through stronger privacy.

Innovation

New entrants can build complementary services.

Bargaining power

Consumers are less dependent upon one provider.

34. Data Portability and Small Businesses

Small businesses may be particularly affected by data lock-in.

A business could depend upon one platform for:

customer reviews;

advertising data;

transaction records;

customer relationships;

analytics.

If the business cannot move those assets, the platform may acquire significant bargaining power.

Therefore, portability can be a SME competition mechanism, not merely a consumer right.

35. Risks of Over-Enforcement

1. Privacy leakage

Transferred data may expose third parties.

2. Cybersecurity risks

APIs create attack surfaces.

3. Free-riding

Competitors may exploit another company's investment.

4. Innovation disincentives

Excessive sharing can reduce investment incentives.

5. Administrative burden

Small providers may struggle to comply.

6. Data-quality disputes

Parties may disagree about whether data is:

accurate;

complete;

derived;

personal;

proprietary.

36. Proportionality Test

A portability obligation should ideally satisfy four questions:

1. Legitimate objective

Does it promote competition or reduce lock-in?

2. Suitability

Will portability actually improve contestability?

3. Necessity

Is there a less restrictive alternative?

4. Balancing

Do competitive benefits outweigh:

privacy;

security;

intellectual-property;

innovation costs?

37. Ideal Indian Enforcement Architecture

India could develop a coordinated framework involving:

Competition Commission of India

Focus:

market power;

exclusion;

foreclosure;

abuse of dominance.

Data Protection Authority/competent data-governance institution

Focus:

lawful processing;

privacy;

data security;

user rights.

Sectoral regulators

Examples:

RBI for financial services;

TRAI for telecommunications;

sector-specific health authorities where applicable.

Technical standard-setting institutions

Focus:

APIs;

interoperability;

data formats;

cybersecurity.

This creates:

Competition regulator + data regulator + sector regulator + technical regulator

with coordination mechanisms.

38. A Proposed Data Portability Enforcement Flowchart

Complaint / Market Study

Relevant Market Identification

Dominance / Gatekeeper Assessment

Identify Data and Portability Barrier

Assess Network Effects and Switching Costs

Determine Competitive Harm

Privacy + Security + IP Assessment

Proportionality Analysis

Portability / Interoperability Remedy

Technical Compliance Plan

Independent Monitoring

Penalty / Corrective Action for Non-Compliance

Periodic Review

39. Important Case-Law Table

CaseCourt/AuthorityMain PrincipleData-Portability Relevance
In Re WhatsApp Privacy PolicyCCI, 2024Data practices can affect competitionStrong Indian data-competition authority
Meta v. CCINCLAT, 2025Unfair data-related conditions and denial of market accessBehavioural data remedies
Harshita Chawla v. WhatsAppCCI, 2020Digital-platform competitionNetwork effects
Umar Javeed v. GoogleCCIAndroid ecosystem dominanceEcosystem lock-in
Microsoft v. Commission, T-201/04EU General CourtInteroperability can be required in exceptional circumstancesTechnical access
US v. MicrosoftUS Court of AppealsPlatform/network effects and exclusionTechnology lock-in
Google Android, T-604/18EU General CourtEcosystem control and competitionPlatform dependency
Bronner v. MediaprintCJEULimits of compulsory accessPrevents overbroad data-access duties
IMS Health v. NDC HealthCJEUExceptional compulsory access involving IPData/IP balance

40. Critical Legal Issues

Issue 1 – Who owns the data?

Competition law should not simply assume that every economically valuable dataset belongs to the platform.

The analysis should distinguish:

user-generated data;

platform-generated data;

derived data;

inferred data;

third-party data.

Issue 2 – Should competitors receive the data?

Not automatically.

The regulator should establish:

necessity;

competitive significance;

proportionality.

Issue 3 – Should portability be free?

For consumers, free or low-cost portability can be essential to prevent switching barriers.

For commercial transfers, reasonable cost allocation may sometimes be appropriate.

The regulatory model must therefore distinguish between:

consumer portability;

business portability;

mandated third-party access.

41. Important Principle: Portability Must Be Effective

A company should not be able to say:

"We provide portability because users can download a 400-page PDF."

That may satisfy a formal requirement but not a substantive one.

Effective portability requires:

machine readability;

completeness;

timeliness;

usability;

compatibility.

Therefore:

Formal portability is not necessarily effective portability.

42. Important Principle: Portability Must Be Secure

A portability regime should establish:

authentication;

authorisation;

encryption;

access logging;

fraud prevention;

data minimisation.

Otherwise, a portability right could itself become a cybersecurity vulnerability.

43. Important Principle: Portability Must Be Non-Discriminatory

A dominant firm should not provide:

Fast + complete + high-quality data access to its own subsidiary

while giving competitors:

Slow + incomplete + restricted access.

Such discriminatory interoperability can itself create competitive harm.

44. Emerging 2026 Direction

The latest EU digital-market developments illustrate the movement toward technical enforcement rather than merely legal declarations.

The European Commission's 2026 materials report new portability mechanisms involving device data transfers and interoperability requirements for gatekeepers. (Digital Markets Act (DMA))

The Commission's 2026 DMA review also identifies continuing technical difficulties in making interoperability genuinely effective, showing that implementation quality is becoming as important as the legal right itself. (Digital Markets Act (DMA))

This is an important lesson for India:

A portability statute without technical enforcement capacity may create a right on paper but not meaningful competition in practice.

45. Examination-Oriented Analytical Framework

For a problem question, use this sequence:

Step 1

Identify the digital market.

Step 2

Determine whether the undertaking has substantial market power.

Step 3

Identify the relevant dataset.

Step 4

Determine whether users or competitors face switching costs.

Step 5

Identify the portability restriction.

Step 6

Determine whether the restriction forecloses competitors.

Step 7

Examine privacy, cybersecurity and IP limitations.

Step 8

Apply proportionality.

Step 9

Select the least restrictive effective remedy.

Step 10

Create a monitoring and enforcement mechanism.

46. Core Formula

Data Portability Enforcement = Market Power + Data Control + Switching Costs + Network Effects + Portability Barrier + Competitive Harm + Privacy/Security Safeguards + Proportionate Remedy + Technical Monitoring.

47. Conclusion

Competition Law and Data Portability Enforcement Architecture represents a shift from viewing data merely as an information asset toward recognising it as a potential source of market power, switching costs and competitive advantage.

The Indian WhatsApp/Meta proceedings demonstrate that data practices can form part of an abuse-of-dominance analysis and can result in substantial behavioural remedies. (Competition Commission of India)

The Microsoft, Google Android, Bronner and IMS Health jurisprudence provides broader principles concerning:

technological bottlenecks;

interoperability;

essential facilities;

refusal to supply;

intellectual-property interests;

proportionality.

The strongest enforcement architecture therefore should not rely exclusively upon traditional antitrust litigation.

It should combine:

Competition Law + Data Protection + Data Portability + Interoperability + Technical Standards + Cybersecurity + Sectoral Regulation + Continuous Monitoring.

The ultimate objective is contestable digital markets in which consumers and businesses can realistically leave a dominant platform without losing the accumulated value of their data.

Thus:

A data-portability right becomes a genuine competition remedy only when data is transferable, usable, interoperable, secure, timely, non-discriminatory and backed by an institution capable of enforcing those requirements.

LEAVE A COMMENT