Under Article 6(11) of the DMA, Google must share anonymised search data with eligible online search engines under fair, reasonable and non-discriminatory terms.
To assist Google in sharing search data, the Commission opened specification proceedings on 27 January 2026. These proceedings aim to specify measures that Google must implement to ensure effective search data sharing under Article 6(11) DMA with eligible beneficiaries, including AI chatbots offering search functionalities.
The final decision was adopted on 16 July 2026 and includes the measures that Google must implement to enable effective search data sharing.
Objective
What is the goal of sharing Google Search data with competitors?
- With a market share of more than 90% for decades, Google Search has a strong market position in Europe. Because of this, it has access to an unparalleled wealth of user data, which it uses to improve its search algorithm, thereby reinforcing its position. No other search engine can currently match Google Search.
- The DMA requires Google to share search data with other search engines, so that they can develop and optimise their own search services and compete with Google Search. This is particularly important with respect to AI chatbots with search functions to avoid that Google Search’s advantage extends to Google’s AI chatbots too.
- The Commission’s measures give both established online search engines and credible new entrants access to Google Search data, so that they can spark innovation and broaden choice for everyone to the benefit of EU citizens and businesses.
What does it mean for users?
- Better experience: With access to Google Search data, online search engines can improve the quality of their services.
- More choices: With access to Google Search data, a wider variety of online search engine services can flourish and users can express their preference, whether that be to support search engines with a focus on privacy, sustainability, societal causes or others combining search and AI services.
- More credible search alternatives will also mean more traffic sources and greater ad market competition for businesses.
Why is the Commission stepping in with specifications?
- Alphabet’s initial compliance proposal had numerous issues. For example, it was removing between 90 and 100% of unique search queries from the dataset. It was also unduly restricting the potential pool of beneficiaries by excluding AI Chatbots that provide search services. As a result, there has been no meaningful uptake by potential beneficiaries.
- Two years of talks with Alphabet showed that a specification process was the fastest way to ensure that the dataset is effective and meets the requirements of Article 6(11) DMA.
- By spelling out how data should be anonymised and shared, we help Google to meet its obligations quickly and reliably, without stalling the benefits for users and businesses.
What are eligible third-party search engines going to do with the data?
- The data is shared for the purpose of enabling third party search engines to develop and optimise their own search technology and services.
- However, the measures also specify clear limitations on the purpose of the use of search data. Beneficiaries should not go beyond using the data to develop and optimise their search services. In particular, they cannot use the data to train general-purpose AI models, improve services that are unrelated to online search engine services like consumer profiling and advertising, or use the data to systematically replicate Alphabet’s search results instead of developing and improving their own search technology.
- Optimisation of search services cover a wide variety of use cases, which can be enhanced through access to the dataset to be shared under Article 6(11) DMA. This dataset should therefore not be unduly restricted, and beneficiaries should be able to choose how to best use the data to improve their search technology and services. For example, beneficiaries may use the dataset to:
- Improve query understanding: search engines must understand the intent behind a user query to present useful results that match what the user is looking for. Query understanding also includes development of spelling suggestions, suggestions for related queries, and auto-complete suggestions.
- Improve ranking and retrieval systems: ranking systems evaluate the quality of websites so that the search engine can match the user’s query with the most relevant result. For example, AI chatbots rely on search retrieval systems to fetch most recent information from the web and ensure accuracy (so called ‘grounding’).
- Improve indexing: search engines rely on an index of websites that can be searched efficiently to respond to a search query. The dataset can help recipients understand which websites to prioritise.
Privacy protections
How is end users’ privacy protected?
- Article 6(11) DMA requires that personal data of users is anonymised when sharing search data with eligible online search engines. In this way, it ensures that the privacy of end users is protected.
- The requirement ensures anonymised end-users' personal data by imposing technical measures that alter the data. It is complemented by contractual protections that bring the residual risk of re-identification down to an insignificant level. It also requires a yearly audit mechanism to guarantee that these protections are consistently complied with over time.
- Together, these requirements ensure end users remain anonymous while maintaining the quality and usefulness of data for third-party online search engines to improve their services.
- This approach closely follows the guiding principles established by the draft joint guidance of the Commission and European Data Protection Board (EDPB) on the interplay between the DMA and the GDPR for the sharing of search data under Article 6(11) DMA (link here).
What technical and complementary contractual measures are applied to anonymise the data?
Technical measures
- Before sharing the search data, Alphabet must apply technical measures to alter the search data to protect end users against re-identification risks while preserving its utility for optimising online search services.
- The technical measures, which play an essential role in the anonymisation approach, include the following main steps (this is not an exhaustive list; the full description of technical measures can be found in the implementing decision and annex setting out the measures, once published):
- Step 1: Turning the dataset into a ‘haystack’ of loose queries, by removing direct identifiers (for example, Google usernames and IP addresses) and other identifying attributes from each record (for example, query timestamps, advanced filters and input format). This ensures that different queries cannot be readily attributed to the same user
- Step 2: Suppression of search records when queries contain rare terms (for example, full names, usernames, passwords, street addresses, bank account numbers) or are unusually long. These steps remove secrets and sensitive information from the query text.
- Step 3: Generalisation of metadata and suppression of queries so that each user is in a group with at least 1,000 users with the same location, device type and query language -- the so-called ’k-anonymity’ technique. The threshold of 1,000 is a strict minimum, and 95% of users will be in larger groups of at least 29,000 users.
Contractual measures
- The contractual measures complement the technical measures to further mitigate the reidentification risk to an insignificant level, ensuring anonymisation. They include the following requirements:
- that the dataset will only be made available to eligible beneficiaries with verified investment plans to improve online search services.
- technical and organisational requirements limiting the use of the search data to improving online search engine services only, preventing the linking of search data with other datasets by keeping the data in a ringfenced environment, prohibiting disclosure to any third party, prohibiting re-identification and attempts to reverse the technical measures, limiting the retention period, and imposing governance and documentation obligations.
- integrity and confidentiality requirements to protect the search data against unlawful access or disclosure.
- As a condition to access the data, beneficiaries will need to undergo an independent audit to verify that they have adequate safeguards and systems in place to comply with the requirements. They will have to subsequently undergo at least yearly audits to confirm that they effectively comply with the requirements.
Will the Commission re-evaluate this as use cases evolve and new attacks may impact the privacy analysis?
- The Commission will continue to monitor technical developments and engage with any new facts and testing.
- The measures will also be subject to biennial reviews to take into account practical experience and any new developments.
- At any time, Article 8(9) DMA allows the Commission to reopen proceedings where there has been a material change in any of the facts on which the decision was based, including based on results from new monitoring and testing of the effectiveness of the anonymisation measures such as independent third-party evaluation. The Commission will assess any such new facts within the framework and principles set out in the specification decision.
How is compliance with the technical and contractual measures ensured?
- It is Alphabet’s obligation to apply the technical measures to the data before being shared with the restricted pool of eligible third-party online search engines.
- To monitor effective compliance with the contractual measures, all eligible beneficiaries are subject to an independent verification mechanism. That mechanism consists of a comprehensive audit by independent, qualified practitioners. It should be conducted in accordance with internationally recognised standards before access to search data is granted, and throughout the duration of access (through a first compliance audit within six months of sharing the data and subsequent annual audits).
Why does search data need to be protected if it's anonymised?
- Article 6(11) DMA requires anonymisation of the personal data of users who issued the queries. For example, if an end-user searches for ‘Kylian Mbappé’, a personal name, the data to anonymise is not ‘Kylian Mbappé’, but rather the personal data relating to the end user who searched for him. Since the dataset still contains personal data relating to individuals other than end users (such as professionals, celebrities or other persons) who are searched for in those queries, the sharing of search data remains subject to the GDPR, and online search engines that access the data are controllers for those personal data.
How did the Commission elaborate and evaluate the anonymisation measures?
- The Commission closely followed the guiding principles established by the draft joint Guidelines of the Commission and European Data Protection Board (EDPB) on the interplay between the DMA and the GDPR for the sharing of search data under Article 6(11) DMA providing that anonymisation can be achieved by appropriate technical measures to alter the data complemented by organisational, administrative and contractual measures.
- The technical measures, which play a prominent role in the anonymisation approach, have been developed in collaboration with internal and external privacy experts and follow well-established anonymisation practices.
- The Commission has also collected extensive feedback on preliminary measures in the context of a public consultation and intensive engagement with Alphabet, which included several rounds of testing by Alphabet and the Commission.
- The contractual measures complement the technical measures to ensure anonymisation and address, among other, restrictions on data usage, prohibition on onward sharing, data retention, integrity and confidentiality measures as well as well independent auditing to ensure that the effects of the measures are both durable and verifiable in line with the joint Guidelines.
Conditions and process to access the data
Who can access the data?
- As a first filter, the measures contain a set of eligibility criteria to ensure that search data is only shared with online search engines that meet basic indicators of trustworthiness. Only those that provide online search services can access the data, and they can only use the data to optimise their online search technologies and services. This includes AI chatbots with online search functionalities.
- The eligibility measures allow Alphabet to conduct a review based on identified objective criteria to exclude undertakings designated as ‘high-risk’ under EU law because they are sanctioned entities or are controlled by a third country that poses serious and structural cyber security and/or data protection risk, and ensure that only genuine players active in the online search sector with the necessary record of handling sensitive search data or resources to do that can access the data.
- Alphabet may also only share data with undertakings that meet the conditions for international data transfer pursuant to Chapter V of GDPR.
- In addition, Alphabet can ask the Commission for an exemption from giving search data access to specific undertaking on grounds of public security pursuant to Article 10 DMA. The Commission may also grant this exemption on its own initiative.
- Beyond the first eligibility filter, undertakings will only get access to the data if they can demonstrate that they ensure compliance with a comprehensive set of contractual measures, including technical and organisational measures, ensuring anonymisation of search data and security requirements in the context of an initial independent verification mechanism to be repeated annually (see ‘How to meet the eligibility and audit conditions for accessing the data?’ below).
What is in the search data that Alphabet needs to share?
- Article 6(11) DMA has a well-defined scope aimed at covering important user data to optimise online search engine services. It covers anonymised ranking, query, click and view data that is generated by end users in relation to free and paid search.
- The measures lay out which concrete ‘ranking, query, click and view’ data Alphabet must offer to third parties providing online search engines, subject to anonymisation.
- As a basic principle, Google should share the data that it itself collects and uses to optimise its own search services. For instance, the Commission is specifying that Alphabet must give access to data such as queries entered by end users in Google Search on any access point, query metadata (for example, language and device type), URLs viewed by users, users’ actions interacting with search engine results, and information on where a search result is positioned (i.e. ranked) in the search results page.
- Unlike the data that Alphabet collects and uses, the data to be shared with third party search engines will undertake suppressions and alterations to ensure its anonymisation. For example, no user account information and no search histories are shared, the precise timestamp is not provided, very long queries and queries with rare words are suppressed, location data is generalised, precise interaction durations are aggregated and replaced by time intervals, URLs for paid results (i.e. ads) are removed, etc.
How will the search data be shared?
- The measures specify key parameters of sharing. For example, Alphabet must exclude invalid traffic from the dataset, and share the data via a method and with a latency that it uses itself internally to the greatest extent that is technically feasible for a duration of third-party online search engines’ choice and up to five years for each beneficiary. Latency should not be less than seven days, meaning that data is shared at least seven days after a user has entered a query, and it should not be more than the latency Alphabet uses internally to the greatest extent that it is technically feasible.
- In line with the allowed purpose of use, the minimum seven-day-latency for data access and the maximal duration of data access of five years, for each beneficiary, incentivise data recipients to develop their own search technology.
- The maximum duration of five years applies for each individual beneficiary from the moment when they start accessing the data, Google Search will be subject to the data sharing requirement as long as it is designated under the DMA.
Does this data sharing involve the sharing of Google’s search algorithm and technology?
- The measures do not require the sharing of Google’s algorithms or technology, but rather ranking, query, click and view data, that would allow third-party OSEs to develop their own search technology.
- The shared data is also only a subset of the user data that Alphabet collects and uses to optimise its own search engine given that the scope is more restricted and the data has to undertake significant alteration to meet the anonymisation standard.
- Google will therefore retain all incentives to innovate while third parties will be empowered in their own ability to innovate through the removal of a major barrier, namely the lack of search data at scale.
What is the implementation timeline?
The measures set out implementation milestones that Alphabet must meet for different obligations as follows:
- Within 1.5 months after the measures’ adoption (by end August 2026):
- Alphabet must submit the eligibility application form to the Commission for review
- Alphabet must publish a webpage informing beneficiaries of their rights and how to apply for the search dataset
- Within 2 months after the measures’ adoption (by September 2026):
- Alphabet must make available template licence agreements for the search dataset and test data samples
- Alphabet must submit cost items and estimates
- Within 4 months after the measures’ adoption (by November 2026):
- Alphabet must finalise the anonymised search dataset
- Alphabet must submit to the Commission technical information on latency of sharing and personal data detectors so the Commission can review
- Within 6 months after the measures’ adoption (by January 2027):
- Alphabet must finalise the pricing offer and communicate this to the Commission and third-party online search engines
How can potential beneficiaries meet the eligibility and audit conditions for accessing the data?
- Potential beneficiaries must offer online search engine services. They must also demonstrate that they:
- Provide an online search engine service as a genuine economic activity in the EU or are a credible new entrant into the online search engine industry: namely that the potential beneficiary either has provided online search engine services in the EU for at least the last two consecutive years at the time of applying for eligibility; or was founded less than two years ago but has received more than €50 million in capital investments;
- Have had at least 50 000 monthly average users of its online search engine services in the EU in the past year;
- Have not been subject to restrictive measures or other sanctions under EU law and are not controlled by a third country that poses serious and structural cyber security and/or data protection risk.
- Will process the search data in the EEA or, in case of transfer, can ensure a level of protection of that data essentially equivalent to that provided for in the EEA. These eligibility measures are complemented by an audit which is an independent verification mechanism. Third-party online search engines must prove to a suitably qualified independent auditor that they are complying with the safeguards specified in the measures.
- Third-party online search engines must pass this audit before they receive the search data, within six months of starting processing and annually after that. The Commission can order ad hoc audits outside this yearly window in case of concerns that a third-party online search engine is failing to comply.
- The eligibility and audit measures complement each other. They ensure that only genuine, trustworthy online search engines with the necessary scale and experience to process sensitive search data ever gain access, and that they continue to always comply with the necessary safeguards.
- Third-party online search engines that pose public security risks can also be excluded following a Commission decision.
How will the price of the data be determined?
- The measures on pricing terms specify the remuneration that Alphabet can claim from eligible beneficiaries under the fair, reasonable and non-discriminatory requirement of Article 6(11) DMA. The measures establish a clear, transparent and predictable framework for eligible beneficiaries and provide Alphabet with a fair opportunity to recover the incremental costs of providing access to the Search data.
- The measures specify that Alphabet must provide the search data to eligible beneficiaries against a compensation reflecting the incremental costs incurred by Alphabet for sharing the search data and a reasonable return on capital employed for that purpose. This capital must be understood as the incremental capital strictly necessary for making the search data available, and the remuneration shall not exceed Alphabets weighted average cost of capital (WACC).
- Exceptional circumstances may justify an additional margin, which however cannot exceed the operating margin (in percentage terms) of Alphabet’s Google Search business, in favour of Alphabet. In particular, this would be the case if at some point Alphabet demonstrates that it cannot cover the costs efficiently incurred in the collection of the data to be shared from its own commercial use of such data, or when an eligible beneficiary operates an online search engine at a very large scale (i.e., meets the thresholds for being designated as gatekeeper). This additional margin will in any event not be applied to micro, and small and medium-sized enterprises.
- The incremental cost items include:
- Costs pertaining to the preparation and formatting of the search data, including all costs directly attributable to the data-sharing-specific further processing of data already stored in Google’s databases;
- Costs of storing the data to the extent that the storage environment is used for storing data with a view to making it available to eligible beneficiaries; and
- Costs of dissemination or electronically transmitting the data, including technical onboarding costs and costs of operating data access tools.
- These incremental costs can be recurrent or one-off, and beneficiary-specific or common across beneficiaries.
- The per-beneficiary payment scheme includes a fixed and variable component:
- the fixed component covers the one-off beneficiary-specific costs and a share of the one-off common costs; and
- the variable component covers the beneficiary-specific recurrent costs and a share of the recurring common costs.
- Regarding the final allocation of the common costs:
- the per-beneficiary share of initial one-off common costs will be computed on the basis of the number of beneficiaries at the time the access mechanism is first made available, i.e. the number of third-party online search engines that have either initiated an audit or that have been assessed as eligible to receive the search data within six months following adoption. The computed per-beneficiary share will then be applied to all actual beneficiaries irrespective of the time they start having access;
- the recurrent common costs will be shared equally each year among the actual beneficiaries receiving access that year.
How can companies test the data before entering a license agreement?
- Alphabet must offer samples of the search dataset to allow beneficiaries to test the data and make an informed decision on whether to purchase the full search dataset.
- The measures specify the content and conditions of sharing for these test data samples. Alphabet will make available three types of test samples with different levels of scope and access conditions: a small real-data sample, a synthetic dataset, and a larger representative dataset. These samples can be downloaded and used in the beneficiary’s own secure environment to assess data quality and usefulness.
- Only potential beneficiaries that have received an auditor’s reasonable assurance report under the independent verification mechanism can access the larger representative sample. The other two samples can be accessed without this report.
- This testing framework ensures access on fair, reasonable and non-discriminatory terms.