Competition Law And Ecosystem Dependency Audits .
Competition Law and Ecosystem Dependency Audits
1. Meaning
An Ecosystem Dependency Audit is a structured competition-law investigation used to identify how strongly customers, suppliers, developers, distributors, complementors, or competitors depend on a particular business ecosystem.
It asks:
“Can participants realistically operate, switch, interoperate, or compete outside the ecosystem?”
An ecosystem may include:
platform
operating system
app store
payment system
cloud service
marketplace
search engine
data infrastructure
API
logistics network
digital advertising system
hardware/software combination.
Under current UAE competition law, Federal Decree-Law No. 36 of 2023 regulates restrictive agreements, abuse of dominant position and economic concentrations. Article 6 prohibits abusive conduct by a dominant undertaking where its object or effect is to distort, lessen, restrict or prevent competition. (Ministry of Education)
2. Core Formula
ECOSYSTEM DEPENDENCY =
Criticality + Switching Costs + Network Effects + Interoperability + Data Dependence + Gateway Control + Alternatives + Contractual Restrictions
The greater the dependency and the weaker the alternatives, the more carefully competition authorities may examine the ecosystem.
Important: High dependency alone does not automatically establish an antitrust violation.
3. Objectives of an Ecosystem Dependency Audit
An audit normally determines:
Who depends on the ecosystem?
What part of the ecosystem is essential?
Are realistic alternatives available?
How expensive is switching?
Can users multi-home?
Can competitors interoperate?
Who controls important data?
Who controls the gateway to customers?
Are contractual restrictions creating lock-in?
Can the ecosystem leverage power into another market?
Is self-preferencing occurring?
Are tying or bundling practices present?
Can rivals obtain access on reasonable terms?
Does the ecosystem create durable entry barriers?
What are the actual or potential competitive effects?
4. Main Dependency Indicators
| Indicator | What the audit asks |
|---|---|
| Market share | How large is the ecosystem? |
| User dependence | How many users rely on it? |
| Supplier dependence | Can suppliers survive outside it? |
| Customer dependence | Can customers easily leave? |
| Switching cost | What does migration cost? |
| Data dependence | Is important data trapped inside? |
| Network effects | Does size make the ecosystem more valuable? |
| Multi-homing | Can users use competing ecosystems simultaneously? |
| Interoperability | Can competing products connect? |
| Portability | Can users take their data elsewhere? |
| Gateway power | Does one firm control access to customers? |
| Contractual lock-in | Are exclusivity or long-term restrictions present? |
| Tying | Must one product be purchased with another? |
| Self-preferencing | Does the platform favour its own service? |
| Vertical integration | Does the ecosystem control multiple stages? |
| Data advantage | Does scale provide unique data advantages? |
| Entry barriers | Can a new competitor realistically enter? |
| Complementor dependence | Do developers/sellers depend on the platform? |
5. Ecosystem Dependency Score
For academic or internal audit purposes, a simple analytical model can be used:
EDI = C + S + N + D + I + G + E
Where:
C = Criticality
S = Switching cost
N = Network effects
D = Data dependence
I = Interoperability dependence
G = Gateway control
E = Entry barriers
This is an analytical tool, not a statutory UAE legal formula.
6. Step-by-Step Ecosystem Dependency Audit
Step 1 — Map the ecosystem
Identify:
Platform → Users → Suppliers → Complementors → Competitors → Data → Infrastructure
Example:
Cloud platform → businesses → software developers → APIs → data → applications → customers.
Step 2 — Identify the dependency point
Determine what participants cannot easily replace.
Examples:
unique API
operating system
app store
cloud infrastructure
customer database
payment network
marketplace access
specialised data
authentication system.
Step 3 — Measure switching costs
Consider:
migration expenses
technical redevelopment
employee retraining
lost data
contractual penalties
customer loss
integration costs
downtime
compatibility problems.
Simple formula
Total Switching Cost = Financial Cost + Technical Cost + Time Cost + Customer Cost + Risk Cost
7. Interoperability Audit
Interoperability is particularly important in digital ecosystems.
The auditor asks:
Is an API available?
Are technical standards open?
Can competitors connect?
Is access delayed?
Is access discriminatory?
Is functionality withheld?
Is interoperability technically possible?
Is a refusal objectively justified?
In Microsoft v Commission, T-201/04, the General Court upheld findings concerning Microsoft's refusal to supply interoperability information to competitors, together with separate tying conduct. (Infocuria)
In Alphabet and Others, C-233/23, the Court of Justice addressed refusal by a dominant digital-platform operator to ensure interoperability with a third-party application. The Court stated that such conduct can constitute abuse in appropriate circumstances, while recognising possible objective justifications such as platform security or technical impossibility. (curia)
8. Switching-Cost Audit
A dependency audit should distinguish between:
Low switching cost
Customer can change provider quickly.
Medium switching cost
Migration requires money and technical work.
High switching cost
Migration threatens business continuity.
Extreme lock-in
Leaving the ecosystem is practically or economically unrealistic.
High switching costs may strengthen an incumbent's market position, but they are not automatically unlawful.
9. Multi-Homing Audit
Multi-homing means users can simultaneously use competing ecosystems.
Example
A seller uses:
Marketplace A
Marketplace B
Marketplace C
This can reduce dependency.
Conversely:
Single-homing + high switching costs + network effects = greater dependency risk.
10. Data Dependency
An ecosystem may become powerful because participants accumulate data that competitors cannot easily reproduce.
Audit questions:
Who owns the data?
Who controls access?
Can customers export it?
Is the data portable?
Is historical data available?
Can competitors obtain equivalent data?
Does data scale improve the ecosystem?
Does data access create a feedback loop?
Data Flywheel
More Users → More Data → Better Service → More Users → More Data
This can strengthen ecosystem dependency.
11. Gateway Dependency
A gateway is a point through which businesses must reach customers.
Examples:
app store
search engine
marketplace
payment network
cloud platform
advertising exchange.
The audit asks:
“Can a competitor reach customers without passing through this gateway?”
If the answer is effectively no, gateway control becomes an important competition-law issue.
12. Contractual Dependency
Review:
exclusivity
minimum purchase obligations
loyalty requirements
non-compete provisions
long-term contracts
automatic renewal
termination restrictions
price parity clauses
most-favoured-customer clauses
restrictions on using competing platforms.
The objective is to determine whether contracts merely organise commercial relationships or materially reinforce exclusionary dependence.
13. Self-Preferencing Audit
The auditor checks whether the ecosystem operator:
gives its own downstream product/service better treatment than competing products.
Relevant indicators include:
ranking
search visibility
recommendation algorithms
access to customer data
pricing
commissions
technical access
advertising placement.
In Google and Alphabet v Commission (Google Shopping), C-48/22 P, the Court of Justice upheld the finding of abuse concerning Google's favourable treatment of its own comparison-shopping service in general search results. (curia)
14. Tying and Bundling Audit
Ask:
Must customers purchase Product A to obtain Product B?
Examples:
Operating System → Search Engine
Cloud → Software
Payment System → Marketplace
Hardware → Proprietary Service
The audit considers whether bundling increases ecosystem dependency and restricts competing suppliers.
The Google Android C-738/22 P judgment concerned contractual restrictions, tying, exclusive pre-installation payments and obstruction of Android forks; the Court of Justice delivered judgment on 2 July 2026. (curia)
15. Refusal-to-Deal Audit
A dominant ecosystem may sometimes control infrastructure or data that rivals need.
The audit therefore asks:
Is the facility/data/platform important?
Is access practically necessary?
Is there a realistic alternative?
Has access been refused?
Is the refusal discriminatory?
Is there an objective justification?
Could refusal eliminate or substantially weaken competition?
The test must be applied carefully because competition law does not normally require every business to deal with competitors.
16. Six Major Case Laws
1. Microsoft Corp. v Commission — T-201/04
Principle: Interoperability and ecosystem dependency.
Microsoft was found to have abused dominance through refusal to provide interoperability information and through tying Windows with its media player. The case demonstrates how control over a technological ecosystem can affect competing products. (Infocuria)
Audit lesson:
Check whether technical incompatibility is creating artificial dependency.
2. Google and Alphabet v Commission — C-48/22 P
Google Shopping, 2024
The Court upheld the finding involving preferential treatment of Google's own comparison-shopping service in general search results and maintained the €2.4 billion fine. (curia)
Audit lesson:
Examine whether ecosystem control is being used to favour the operator's own downstream service.
3. Google and Alphabet v Commission — C-738/22 P
Google Android, 2026
The case concerned contractual restrictions, tying, exclusive pre-installation payments and restrictions affecting Android forks. The Court of Justice dismissed Google's appeal and upheld the relevant infringement findings, with the fine adjusted by the General Court to approximately €4.1 billion. (curia)
Audit lesson:
Analyse whether contractual arrangements make users, manufacturers or developers excessively dependent on the ecosystem.
4. Alphabet and Others — C-233/23
Android Auto interoperability, 2025
The Court considered whether a dominant platform's refusal to ensure interoperability with a third-party app could constitute abuse. It recognised that objective reasons, including security and technical constraints, can justify refusal in appropriate circumstances. (curia)
Audit lesson:
Interoperability refusal should be analysed together with necessity, effects and objective justification.
5. IMS Health GmbH v NDC Health — C-418/01
This case involved access to a structured system for pharmaceutical sales data. The Court identified exceptional circumstances under which refusal by a dominant undertaking to license protected material can amount to abuse, including circumstances involving elimination of competition and prevention of a new product for which there is potential demand. (Infocuria)
Audit lesson:
Unique data structures can create dependency, but access obligations require careful application of the exceptional-circumstances doctrine.
6. Oscar Bronner v Mediaprint — C-7/97
The case concerned access by a competing newspaper to an established home-delivery network. It is a leading authority on the restrictive conditions for treating refusal to provide access to an infrastructure as abusive. (Infocuria)
Audit lesson:
Ask whether the infrastructure is genuinely indispensable and whether an alternative is realistically available.
7. Ohio v American Express — 585 U.S. 529 (2018)
The U.S. Supreme Court treated the credit-card system as a two-sided transaction platform and held that competitive effects had to be assessed across the two-sided market rather than simply by examining merchant fees in isolation. (Supreme Court)
Audit lesson:
Ecosystem dependency should be assessed across interconnected sides of a platform.
17. UAE Competition-Law Application
Under UAE Federal Decree-Law No. 36 of 2023, Article 6 prohibits abuse of dominant position where conduct has the object or effect of distorting, lessening, restricting or preventing competition. The provision expressly addresses conduct including discriminatory conditions, exclusionary below-cost pricing, unjustified refusal to transact, tying and restrictions affecting production, markets or technological development. (Ministry of Education)
The current UAE competition framework also includes regulations and decisions concerning implementation, thresholds and relevant-market analysis. (Ministry of Education)
Therefore, an ecosystem dependency audit in the UAE should particularly investigate:
Dominance → Dependency → Conduct → Foreclosure → Competitive Effects
18. UAE Ecosystem Audit Example
Suppose a dominant digital marketplace requires sellers to use its own:
payment service,
advertising system,
logistics network,
data analytics,
customer communication system.
The audit would ask:
A. Dependency
Can sellers operate independently?
B. Switching
Can sellers move to another marketplace?
C. Data
Can sellers export customer/business data?
D. Interoperability
Can third-party systems connect?
E. Contract
Are sellers prevented from using competitors?
F. Tying
Must sellers purchase additional services?
G. Self-preferencing
Does the marketplace favour its own products?
H. Effects
Are competing marketplaces being excluded?
Only after these questions should the competition-law assessment be made.
19. Ecosystem Dependency Risk Matrix
| Factor | Low dependency | High dependency |
|---|---|---|
| Alternatives | Many | Few/none |
| Switching cost | Low | Very high |
| Multi-homing | Easy | Difficult |
| Data portability | Strong | Weak |
| Interoperability | Open | Restricted |
| Network effects | Limited | Strong |
| Gateway control | Low | High |
| Contractual lock-in | Limited | Extensive |
| Entry barriers | Low | High |
| Customer access | Multiple routes | Single gateway |
20. Difference: Dependency vs Dominance
| Dependency | Dominance |
|---|---|
| Economic/technical reliance | Legal competition-law concept |
| Can exist without dominance | Requires assessment under applicable competition law |
| May concern individual customers | Usually concerns relevant market power |
| Indicates vulnerability | Indicates substantial market power |
| Audit indicator | Legal conclusion requires evidence |
Key point
Dependency ≠ Dominance ≠ Abuse
These are three separate analytical stages.
21. Dependency vs Lock-In
Dependency means reliance on an ecosystem.
Lock-in means leaving the ecosystem becomes difficult or costly.
Thus:
Dependency + high switching costs = Lock-in risk
But commercial lock-in is not automatically unlawful.
22. Dependency vs Essential Facility
An ecosystem can be highly important without satisfying the legal requirements for an essential-facility/refusal-to-deal theory.
The auditor must therefore distinguish:
Important → Difficult to replace → Indispensable → Legally actionable refusal
These are progressively different concepts.
23. Practical Audit Checklist
E-C-O-S-Y-S-T-E-M Audit
E — Entry barriers
Can new rivals enter?
C — Customer dependence
Can customers leave?
O — Openness
Is the ecosystem interoperable?
S — Switching costs
How expensive is migration?
Y — Your-data portability
Can users take their data?
S — Self-preferencing
Does the operator favour itself?
T — Tying
Are services bundled?
E — Exclusivity
Are users/suppliers restricted?
M — Market effects
Is competition actually or potentially weakened?
24. Ultra-Short Revision Table
| Issue | Question |
|---|---|
| Dependency | Who relies on whom? |
| Criticality | What cannot easily be replaced? |
| Switching | Can users leave cheaply? |
| Multi-homing | Can users use rivals simultaneously? |
| Data | Can data be transferred? |
| Interoperability | Can rivals connect? |
| Gateway | Who controls customer access? |
| Contracts | Is there exclusivity? |
| Tying | Are services bundled? |
| Self-preferencing | Is the ecosystem favouring itself? |
| Network effects | Does size reinforce power? |
| Effects | Are rivals or innovation being harmed? |
25. One-Line Exam Answer
An ecosystem dependency audit is a competition-law assessment of whether customers, suppliers, complementors or competitors have become sufficiently dependent on a business ecosystem through switching costs, network effects, data control, interoperability restrictions, contractual lock-in and gateway power, such that the ecosystem may reinforce market power or facilitate exclusionary conduct.
Memory Formula
DEPENDENCY =
Data
Entry barriers
Portability
Exclusivity
Network effects
Digital gateway
Exit costs
Nteroperability
Competitive effects
Y — dependency on the ecosystem.
Core sequence to remember:
DEPENDENCE → DOMINANCE → CONDUCT → FORECLOSURE → EFFECTS
The cases above are primarily comparative authorities, not UAE judgments specifically deciding an “ecosystem dependency audit”; their value for UAE analysis is as persuasive competition-law reasoning alongside the UAE statutory framework.

comments