In a series of Insights and Studies, scholars at ECIPE have drawn attention to the increasingly conflictual relationship between new enforcement under the Digital Markets Act and data privacy regulation in the EU. Last week, the Commission presented its preliminary findings in a specification proceeding concerning Google and the DMA’s Article 6(11) – and, in our view, the findings should be reconsidered in light of their consequences for data protection. While a case can be made for reforming some provisions of the GDPR, as per the current Digital Omnibus, the proposed actions for Google are arguably a violation of core GDPR limitations on data sharing and the supporting jurisprudence that has developed over the years.
Article 6(11) requires gatekeepers that provide online search engines to grant third-party providers of online search engines access, upon request, to ranking, query, click and view data on fair, reasonable and non-discriminatory (FRAND) terms, while ensuring that such data is properly anonymised and that personal and commercially sensitive information is protected in accordance with EU law. To date, Google is the only designated gatekeeper for an online search engine as a core platform service (CPS) and is therefore subject to this obligation. According to the European Commission, Google’s current implementation measures have not fully met the expectations under Article 6(11). This has led the Commission to initiate specification proceedings under Article 8(2) of the DMA. Based on its preliminary findings, the Commission is expected to further specify the measures that Google must adopt to ensure effective compliance.
However, the specification measures are yet another example of how the conflict between regulations is growing. It is noticeable that the Commission is proposing actions that are based on an extreme and very far-reaching version of mandatory data sharing under 6(11). In our reading of the preliminary findings, it would also entail mandatory data sharing to any search engine or AI chatbot requesting access to basically real-time search functionalities, regardless of who it is, where it operates, what it will use the data for, and if it operates in a jurisdiction that follows a high standard of data privacy.
While the GDPR mandates strong restrictions on how personal data in the EU can be collected and used, these objectives seem to diminish at a remarkable speed under the DMA. Nor do Data Protection Authorities seem to have an influence in whether the proposed measures are compliant with GDPR, or if they are subject to risks in light growing opportunities by advanced data science to re-identify users in data sets supplied by other entities.
The proceeding also impacts on competition in AI chatbots, an increasingly important market for all platforms and that features a competitive landscape that is very different from, for instance, search engines. It mandates actions that clearly will have the impact of benefiting companies that are stronger than Google in AI chatbots, and that may have the impact of limiting smaller search providers.
In this Insight, we will start by explaining the Commission’s proposed measures. We will then argue that these measures are contradictory to the data protection laws, and that they will mandate actions with clear personal re-identification risks. As a minimum, these proposed measures should be vetted for data privacy risks by competent EU authorities. We will further argue that these measures will have undesirable effects on the AI and chatbot market, and that they will clearly establish an unlevelled playing field.
Specification Measures against Google: Granular Search Data and Regulatory Overreach
The specification measures under Article 6(11) of the DMA can be understood as covering four main categories of data: query, view, click, and ranking data capturing what users search for, what they see, how they interact with results, and how those results are ordered. The specification measures require Google to provide this information through an API-based feed for users in Europe, while ensuring that the data is anonymised.
In practice, this involves sharing highly detailed (granular) data, including search queries, timestamps, location and device information, as well as millisecond-level user interactions data such as clicks, scrolling, and swiping. It also includes the sequence of these activities over time, effectively linking together query, view, click, and ranking data to show how user behaviour unfolds step by step.
This implies that Google must share potentially sensitive search data with third-party providers of online search engines. While this obligation is framed as a pro-competitive intervention, as reflected in Recital 61 of the DMA, it reveals a striking tension between data utility and privacy. In particular, the requirement that such datasets be anonymised sits uneasily with their level of granularity, raising questions as to whether effective anonymisation can be achieved in practice.
Moreover, the categories of data described above are likely to qualify as personal data within the meaning of Article 4(1) of the GDPR, which defines personal data as any information relating to an identified or identifiable natural person. An identifiable person is one who can be identified, directly or indirectly, in particular by reference to identifiers such as a name, identification number, location data, or an online identifier, or to factors specific to their physical, behavioural, or social identity.
The Article 29 Working Party has further clarified that data may qualify as personal data where the purpose of the processing is to derive information about individuals. This has been described as “personal data by purpose.” In the present context, search data is inherently processed to analyse and predict user behaviour, meaning that it is specifically intended to relate to individuals. In the context of search data, highly detailed (“granular”) data and the way users interact with a search engine are not just technical information. They can reveal patterns of behaviour, interests, and activities. Even if the data does not directly identify a person, combining different elements may make it possible to indirectly identify or single out a user.
Competition Law and the Limits of Data Access: The Privacy Constraint
These risks highlight the need for balancing data access with shared protection. Under EU competition law, a right of access to another company’s data may arise on two main legal grounds: the prohibition of anti-competitive agreements under Article 101 TFEU and, more prominently, the prohibition of the abuse of a dominant position under Article 102 TFEU. It is primarily under the latter that access to data has been sought in practice, particularly in cases involving dominant digital platforms.
This is also the broader competition law context in which Google has been scrutinised, given its position in the online search market. However, within this framework, privacy considerations have traditionally played only a limited role in the Commission’s assessment of market power and competitive harm. Competition analysis has focused predominantly on market structure, barriers to entry, and the control of data as an economic asset, rather than on the implications of data access for the protection of personal data. While privacy has occasionally been considered as a dimension of quality, it has not generally been treated as a primary factor in competition enforcement. This approach is also reflected in the strict conditions under which access to data may be required under EU competition law.
In principle, access to data under EU competition law is justified only in exceptional circumstances. Most notably, the requesting party must demonstrate that the data constitute an “essential facility,” meaning that they are indispensable for its business activities and that there is no realistic alternative for obtaining them. Where the data at issue are consumer data, this threshold is particularly difficult to meet, as data controllers can often argue that competitors are capable of collecting comparable data through their own services.
Article 6(11) DMA obscures the ambiguity of its interaction with privacy safeguards. By applying data-sharing through a FRAND-based approach, it suggests that access seekers should be able to obtain relevant data without undue hindrance from gatekeepers’ terms. However, this provision is exceptional in that it concerns data generated through interactions between the gatekeeper’s search platform and end users, while access may be requested by an unrelated competitor that is not necessarily a business user of the gatekeeper.
End users are unlikely to be aware that data relating to their query and click behaviour may be transferred pursuant to such requests, rendering meaningful consent highly questionable. Article 6(11) thus reflects the regulatory assumption that competition in online search cannot be sustained without access to this data. This assumption is reinforced by the fact that online search has strong scale characteristics due to its extreme data intensity. Under established doctrine, a claimant must demonstrate that a refusal to grant access would eliminate all, or at least most, effective competition in the relevant market, a demanding threshold that is rarely met in practice. By contrast, the DMA appears to presume the indispensability of such data in the online search context, thereby lowering the evidentiary burden that would otherwise apply.
From Compliance to Compulsion: The Anonymisation–Utility Trade-Off in DMA Data Sharing
There is a delicate balance between sharing personal data that will maintain anonymity and sharing data that can be re-identified. It is delicate on both legal and technical grounds, and the Commission’s proposition that the balance can be upheld by contracts between Google and the data requestor is highly questionable. How is control technically going to be organised? It rather seems like a conflation of pseudonymous and anonymous data, effectively bypassing the GDPR’s strict approach to objective technical requirements. An entity sharing highly granular personal data cannot resolve through contracts how the receiving party will use the data unless they have engineering insight and control. Therefore, current practices of sharing of personal data work with different layers of control that, in the case of Google, DMA enforcers now want to disable
Consider the difference with the current approach. Prior to the implementation of the DMA, Google already provided limited access to search data through Google Trends, a tool that offers insights into query popularity based on aggregated real-time and historical data samples.
Following the compliance measures pursuant to Article 6(11) DMA, Google has introduced a European dataset licensing programme covering billions of search queries, including approximately one billion distinct queries across 30 European Economic Area (EEA) countries. The dataset encompasses query, click, view, and ranking data, and includes variables such as country, device type, search result and result type, as well as the average ranking of results for a given query. Access is made available to third parties under contractual arrangements, including a flexible licensing model that allows recipients to obtain subsets of the dataset tailored to their specific needs and geographic markets. Access is provided on differentiated levels, ranging from partial datasets (10 to 50 per cent) to full access, reportedly depending on the applicant’s EEA search revenue in the preceding year. This introduces a degree of proportionality in access conditions, while also enabling access to datasets with varying levels of granularity or country-specific segmentation, thereby limiting the volume of data shared per recipient. Access is subject to the payment of a fee, with pricing reportedly set at approximately €3 per 1,000 queries per country and increasing according to the applicant’s revenue. This pricing structure operates as an additional mechanism for calibrating access, suggesting that access is intended to be structured rather than indiscriminate and responsive to the specific data needs of the requesting party. In this sense, price functions not only as remuneration but also as a tool for regulating both the use and the perceived value of the service.
The contractual licensing framework further allows Google to impose safeguards on recipients, including limitations on use, access controls, and compliance requirements. This is particularly relevant where access is granted to entities based outside the EEA, as it provides a degree of oversight and accountability in cross-border data sharing. In accordance with data protection law, Google applies a range of technical and organisational measures to mitigate re-identification risks. These include frequency thresholding, whereby low-volume queries that are more likely to be linked to identifiable individuals are excluded from the dataset. As a result, only queries entered at least 30 times by signed-in users globally within the 13-month period preceding the relevant quarter are included. Google does not share millisecond-level timestamp data, which would be technically difficult to anonymise without increasing the risk of re-identification.
These limitations should not be understood as undermining the utility of the dataset, but rather as a necessary consequence of compliance with fundamental GDPR principles, including data minimisation (Article 5(1)(c)) and the protection of data subjects. They further constrain the extent to which behavioural patterns can operate as identifying “fingerprints” of individual users, thereby reducing the risk of re-identification. Such measures give effect to core requirements under Article 6(1) GDPR, which conditions lawful processing on, inter alia, necessity and proportionality. At the same time, this constraint highlights a structural tension with the objectives pursued under the Article 6(11) DMA. The competitive value of search data is closely linked to its granularity; yet it is precisely this level of detail that GDPR-compliant anonymisation and data protection safeguards are designed to limit.
The proposed DMA measures require the construction of an allowlist model from parts of search queries. Query elements that are identified as likely to contain personal data such as names, addresses, or phone numbers are grouped together and treated as a single protected unit, while the remaining terms are treated as ordinary words and may be included in shared datasets for a limited period. Because this approach operates at the level of query fragments rather than entire queries, a small risk of re-identification cannot be completely ruled out. That said, this risk should be assessed in light of the broader safeguards in place, such as aggregation and minimum thresholds, and does not in itself necessarily indicate non-compliance with applicable data protection standards. This gives rise to a fundamental trade-off: stricter anonymisation enhances privacy protection but diminishes the utility of the data for third parties seeking to develop or improve competing services. To the extent that the Commission’s approach under the DMA presupposes access to sufficiently rich and detailed datasets to ensure contestability, it is overlooking the constraints imposed by EU data protection law.
Anonymisation and Re-Identification Risk: Questioning the DMA’s Assumptions
The high threshold imposed by the GDPR means that data can only be considered anonymised where individuals are no longer identifiable. While the DMA requires the sharing of “anonymised” data, the GDPR sets a particularly stringent standard for anonymisation. Recital 26 in the GDPR makes clear that data can only be considered anonymised where identification is no longer reasonably possible, taking into account all means likely to be used, including the possibility of singling out individuals. By contrast, Recital 61 DMA requires gatekeepers to provide access to search data in a manner that prevents re-identification, while simultaneously preserving the quality and usefulness of that data.
In this sense, the DMA’s requirement of anonymisation appears to rely on a notion of irreversibility. However, irreversibility is not absolute, but contingent on the surrounding data environment. Article 6(11) DMA requires the sharing of data in a form that no longer qualifies as personal data, yet much of the relevant search context is inherently capable of identifying users, whether directly or indirectly. Even where data may be considered anonymised at the point of disclosure, this status is not static. Under data protection law, anonymisation must be assessed on an ongoing basis, taking into account the evolving data environment and the capabilities of recipients. The risk of contextual re-identification remains significant. In this respect, the DMA appears to assume the availability of a category of data that is both fully anonymised and highly informative—an assumption that is difficult to sustain in practice.
Third-party recipients may possess the technical means, auxiliary datasets, and commercial incentives to re-analyse the data they receive. In fact, many of those who are likely to receive the data under this DMA enforcement have the means to do so. In Opinion 03/2013 on purpose limitation, it is emphasised that data subjects’ legitimate expectations regarding further processing must be assessed in light of contextual factors, including the nature of the relationship between the data subject and the controller, applicable legal obligations, and the transparency of processing operations.
In the context of Article 6(11) DMA proceeding, this assessment reaches a breaking point. End users typically interact with a search service provided by Google for the purpose of obtaining information, and would not ordinarily expect that their query and click behaviour may be shared with unrelated third parties. In fact, the reasonable expectation of any user is that data connected to its use of online search is not indiscriminately shared with external online search engines and AI chatbots. To be clear, a European Data Protection Authority (EDPA) would most likely find the proposed practice to be a violation of the GDPR if Google had done it voluntarily and not in the context of a DMA enforcement.
A concern, highlighted by the Irish Data Protection Commission, is useful in our context that the notion of “third parties” extends beyond authorised recipients. It may also encompass actors who could, whether intentionally or inadvertently, identify a data subject from ostensibly anonymised data, as well as entities not originally intended to gain access. This considerably expands the relevant threat model for assessing anonymisation. The Commission’s approach under the DMA does not seem to fully account for the expectations of data subjects or the constraints imposed on the data controller. This creates a structural misalignment: the Commission mandates data access in the interest of competition, third parties seek to utilise that data for downstream purposes, while Google remains bound by GDPR obligations that require any further processing to remain compatible with the original purpose and within the reasonable expectations of users.
This trade-off is reflected in Opinion 05/2014 on anonymisation techniques, which emphasises that some degree of risk is inherent in any anonymisation process. The Opinion identifies three principal categories of risk. First, singling out, namely the possibility of isolating records relating to an individual within a dataset. Second, linkability, defined as the ability to connect at least two records concerning the same individual or group, whether within a single dataset or across multiple datasets; a technique may therefore prevent singling out while still permitting linkability through correlation. Third, inference, which refers to the possibility of deducing, with a significant degree of probability, sensitive attributes from other available data.
Taken together, these risks demonstrate that anonymisation is not a binary condition, but a matter of degree. In practice, ensuring that search data shared under Article 6(11) DMA is effectively non-identifiable remains particularly challenging in data-rich environments where re-identification techniques continue to evolve.
This position is reinforced by the Court of Justice’s judgment in Breyer v Germany, where the Court held that dynamic IP addresses may constitute personal data where identification is reasonably possible by means likely to be used in practice. By adopting a relative approach to identifiability, dependent on the capabilities of the relevant actor, the Court set a demanding standard for anonymisation: data will not be considered anonymous where re-identification remains realistically achievable in context.
Against this background, the design of the Commission’s data-sharing framework warrants closer scrutiny. Although the system relies on techniques (discussed above), these measures do not necessarily eliminate the relational structure of the data. As a result, the possibility remains that individual queries, particularly those containing distinctive or context-rich elements, could be re-associated with identifiable users when combined with additional information available to recipients. Even where data is treated as anonymised at the point of disclosure, its status may be contingent on the technical capabilities and auxiliary data available to third parties. In line with Breyer, anonymisation must therefore be assessed not in the abstract, but in light of the actual risk of re-identification in a given context.
This design choice is significant. Even where individual components are filtered or transformed, the retention of identifiers and the structured combination of query elements may still permit singling out or linkage, particularly when assessed from the perspective of a recipient with access to auxiliary data. The absence of a requirement for repetition at the level of the full query further complicates this assessment, as unique or rare combinations of otherwise common terms may persist. Accordingly, it is highly likely that the system operates on data that would continue to qualify as personal data under EU law, rather than on information that is effectively anonymised.
Empirical evidence has already illustrated the risks of re-identification through the combination of datasets with publicly available information. A well-known example is the Netflix Prize dataset, where researchers were able to re-identify individuals by linking supposedly anonymised viewing data with publicly available user ratings on IMDb. By comparing rating patterns and timestamps across the two datasets, they were able to infer the identities of specific users.
Moreover, advances in large language models (LLMs) have further highlighted the limits of de-identification. Such models may, in certain contexts, enable the re-identification of individuals based on patterns in past comments or other digital traces. This distinction underscores the limits of de-identification techniques. De-identification typically involves removing or altering personal identifiers through methods such as masking, redaction, or generalisation. However, it does not render a dataset fully anonymous. Where additional data sources are available, there remains a risk that individuals can be re-identified through data linkage or inference.
The scope of actors capable of attempting to (re-)identify individuals is both wide and difficult to delimit, a point reflected in both legislation and case law. Recital 26 of the GDPR makes clear that, in assessing identifiability, account must be taken of all the means reasonably likely to be used, not only by the controller but by “another person.”
In this context, the value of the data becomes a critical factor. Where datasets carry significant commercial, strategic, or informational value, recipients and other actors may have strong incentives to attempt re-identification. The more motivated such an actor is, the more likely it is that sophisticated or extreme identification methods will be employed. Striking a balance between effective anonymisation and meaningful data utility has long been recognised as inherently difficult. It is not possible to simultaneously achieve negligible privacy risk and maximum informational value: as privacy protections are strengthened, the utility of the data is correspondingly reduced, and vice versa.
Therefore, from a data protection perspective, the proposed DMA specification measures are striking in their breadth. While the EU has traditionally maintained a stringent approach to data protection, the current enforcement trajectory is changing that policy by effectively mandating large-scale data sharing under conditions that remain uncertain with respect to downstream use, security, and accountability. The combination of broad access rights and ambiguous anonymisation standards raises fundamental concerns regarding re-identification risks, particularly in light of modern data analytics capabilities.
Data Access and Competition in AI Systems
The Commission’s findings also raise questions about relevant market definitions. It is proposing these specifications with regard to the market for online search engines, but it is obviously constructed to impact a different market: AI chatbots and, more broadly, AI models. While the Commission has signalled an interest to expand the DMA into “new” services that were not part of the original DMA design, it is now attempting to do so implicitly without first generating an understanding of the nature of competition in the AI market and what the consequences of its action would be.
Reasonably, before it mandates an action that potentially can change competition in the AI chatbot and model markets – and not necessarily in a desirable direction – it should produce evidence for the motivation and effects of action. This view is reinforced by the fact that the AI market is different from online search engines. The characteristics of many large and global AI models and operators also exacerbate personal data re-identification risks: access to the Google search data will under the preliminary findings be allowed for companies with highly granular data about their often-registered users and information they share with the chatbots. In matters of sensitive personally information such as personal health and finance, re-identification will in several instances not be a technically demanding task.
AI Search and Traditional Search: Uneven Implications of Article 6(11) DMA
Article 6(11) is formally directed at promoting contestability in online search, but its practical effects may extend to AI markets that are not themselves designated as core platform services under the DMA. If AI chatbot providers are able to access search datasets, the principal beneficiaries may not be smaller search engines, but well-resourced AI firms with the technical capacity to integrate, process, and monetise data at scale.
Obviously, these larger AI companies have already managed to scale without access to the Google search data that the Commission now wants to entitle them. In economic terms, mandated access to search data may therefore “supercharge” AI chatbot providers and widen the gap between them and smaller, traditional search competitors. This is because the ability to benefit from such data depends not only on access, but also on complementary capabilities, including computing infrastructure, model architecture, engineering capacity, existing user bases, and the ability to combine search data with other forms of interaction data. The DMA may thus redistribute access to data without redistributing the capacity to turn that data into competitive advantage.
These concerns are reinforced by the fact that AI-based information services operate differently from traditional online search engines. Many such systems rely on retrieval-augmented generation, through which real-time web search or API access is used to supplement model outputs with up-to-date information. However, retrieval is not triggered for every user query. Because live search introduces latency and cost, AI providers typically rely on routing systems that determine, based on the prompt and its context, whether external retrieval tools should be deployed. As a result, “search” in AI systems does not function as a continuous query–response interaction in the same way as traditional search. This distinction matters for Article 6(11), as the competitive value of search data may differ depending on whether the recipient is a conventional search engine or an AI-native provider using search as one component of a broader generative system.
AI Providers have Distinct Data Advantages
By contrast, AI providers also derive competitive advantages from distinct data dynamics. Unlike traditional search engines, their position is not solely based on historical indexing and click data, but on large-scale model training and ongoing interaction data. Through repeated user engagement, these systems benefit from “data flywheel” effects, whereby increased usage improves model performance, which in turn attracts further users. Datasets with old and historic data, as mandated by the current proposals, are not directly useful for these models.
As users interact with these AI systems, the provider may obtain additional data that improves the quality, relevance and personalisation of outputs, thereby reinforcing user engagement. In traditional search, data network effects are closely tied to query volume and click behaviour. In AI systems, by contrast, competitive advantage may arise from model improvement, interaction histories, prompt-response optimisation, and the ability to convert user engagement into improved predictive capacity. This suggests that data access under Article 6(11) may not affect all potential recipients equally.
Market Changes and the Shift toward AI-mediated Search
This evolving landscape is reflected in recent market developments. Google’s share of global search traffic has fallen below 90 per cent for the first sustained period in nearly a decade, with more pronounced declines in desktop and European markets. Market expectations are clearly pointing to further decline.
At the same time, user behaviour is shifting towards longer and more complex queries, which are more likely to generate AI-produced summaries rather than conventional lists of links. Although traditional search engines continue to dominate user engagement, with approximately 5.5 billion daily visits in March 2025 compared to around 233 million for AI chatbots, these figures nevertheless indicate the emergence of competitive pressure. The significance of this shift is not that AI chatbots have displaced traditional search engines, but that alternative pathways for accessing information have developed and started to achieve scale. As users experiment with AI-generated answers and AI-mediated search tools, the competitive importance of search data may increasingly extend beyond the search market itself.
Data Utility, Privacy, and AI-specific Risks
Moreover, the type of data relevant for AI-driven search differs in important respects. It is not limited to click data, but extends to query formulation, result views, user prompts, and interaction patterns. These categories are particularly sensitive from a privacy perspective, because they may reveal intentions, preferences, vulnerabilities, or personal circumstances. As a result, they are likely to be subject to strict anonymisation constraints. This further complicates the balance between data protection and competitive utility.
The datasets most valuable for developing AI-based search services are also those most likely to be degraded through anonymisation. In smaller markets, or for long-tail queries, this problem becomes even more acute: the data most useful for improving relevance may be precisely the data most difficult to share lawfully. Any safe harbour would need to be grounded in demonstrable technical safeguards, rather than broad claims of anonymisation or de-identification. It would also need to recognise that privacy-utility thresholds are context-dependent, particularly where sensitive categories of user input.
Table 1: Summary of Key Structural Problems in the Commission’s Article 6(11) Approach
Source: Author’s own elaboration
Conclusions
The DMA has been premised on the assumption that access to data will facilitate contestability. However, it remains unclear whether such access, in practice, enables meaningful competition, particularly in markets characterised by scale, technical capabilities, and complementary assets. Moreover, the beneficiaries of such access may themselves possess significant market power, including large technology firms and emerging AI actors, raising questions as to whether the measures risk redistributing advantages rather than genuinely lowering barriers to entry.
Through these proceedings, the Commission appears to be attempting to enforce two potentially irreconcilable standards simultaneously. The more candid conclusion is that Article 6(11), as currently designed, cannot achieve its stated objectives without either compromising GDPR compliance or rendering the shared data competitively inert. An extreme interpretation of 6(11) and forced data sharing on the terms now proposed by the Commission is making this conflict even clearer.
A couple of specific recommendations follow from the analysis:
- Before the Commission finalises the proposed enforcement measures, it should wait for the conclusion of the European Data Protection Board’s finalisation of guidelines on anonymisation. There is no need to rush these measures: getting them right and having coherence is far more important for the future market development.
- Moreover, the Commission should subject the findings to a review by EDPA. Indiscriminate sharing of personal data with clear re-identification risks is generally a remarkable action to propose, but in this case it also does so without any limits on what online search engines and AI chatbots that can request this data from Google. It is already the case that gatekeepers are forced by the DMA to share anonymised personal data with companies in countries that do not have adequate data privacy protections and that have not been receiving adequacy status by the European Commission. Under the DMA, extreme policies are pursued turning European data into a data-colony like market that anyone can exploit. The current 6(11) proceeding is now taking this one step further.
- Finally, there is a great need to address the liability problems when actions are motivated under the DMA that risks the violation of core GDPR provisions. Users who feel their data protection rights have been violated cannot sue the European Commission for having forced data sharing by a private company. However, they can sue the company that did share the data – and if the frequency of GDPR litigation continues to grow, it is not unreasonable to assume that the proposed measures under this proceeding will become subject to civil litigation.
One response to “To Protect Data or Not to Protect: The Dilemma in the Commission’s Article 6(11) DMA Proceedings against Google”