In brief: Google has challenged two Digital Markets Act decisions before the EU's General Court. One requires Android access for competing AI assistants; the other covers anonymised search data for search services. Google's privacy argument primarily concerns residual re-identification risk, not the transfer of complete user profiles.
Two duties, one legal challenge
Google filed the actions on 28 September. It says the requirements weaken Android safeguards and force sharing of search histories without sufficient anonymisation. The Commission's 16 July decisions govern two areas.
In Android case DMA.100220, Google must open eleven operating-system features to alternative AI services. They cover invocation, context access, actions in apps, and computing resources. The solutions are due with Android 18 and no later than 1 August 2027; concurrent wake-word support follows with Android 19 by August 2028. Users must consent. For sensitive features, Google may impose objective, non-discriminatory security and privacy conditions that are independently certified.
Search-data case DMA.100209 instead covers ranking, query, click and view data. Eligible search engines and AI chatbots with search functions may use it only to improve search services — not to train general-purpose AI models, advertise or profile users. By January 2027, Google must finalise elements including the dataset, pricing offer and access process.
What is actually meant to be shared
The Commission specifies layered anonymisation: identifiers, IP addresses and precise timestamps are removed; long or rare queries containing names, addresses, passwords or account numbers are suppressed. Location, device type and language are grouped so at least 1,000 users share a cohort. Recipients must use a ringfenced environment, may not link other datasets, and need independent audits before access and annually thereafter.
Google's phrase “private search history” is therefore broader than the published technical requirement: the Commission says neither account information nor person-linked search histories are shared. The dataset still contains altered records derived from real searches. Whether suppression, grouping and contractual controls reduce re-identification risk far enough is the central testable dispute.
Pandorex Analysis: an appeal does not automatically stop implementation
The actions challenge concrete implementation duties, not the DMA as a whole. Unless the court suspends their effect, the milestones remain in force. Competitors need to know whether Google's challenge merely delays the timetable or materially changes the safeguards. For users, the issues should stay separate: Android interoperability concerns device permissions and system integrity; search-data access concerns anonymisation, purpose limits and recipient oversight.
