BRUSSELS — European Commission officials are scheduled to make final decisions in July regarding two cases involving Google Search and Android interoperability under the Digital Markets Act. The European Commission published initial details in April and opened public consultations on how Google should share anonymized search data with rivals.

The Digital Markets Act, adopted by the European Union at the end of 2022, allows officials to designate tech companies with large market shares as "gatekeepers." Alphabet, Amazon, Apple, Booking, ByteDance, Meta, and Microsoft are designated as gatekeepers. With Google's search business estimated to constitute 90 percent of the worldwide search market, it is the only search engine designated as a gatekeeper.

The proposals require Google to provide online search engines with access to search data "on par" with the data Google collects, including query input and metadata. They also require Google to share click data and ranking results of search queries with competitors. Additionally, the proposals include requirements for companies receiving search data to undergo independent audits of their data security setups. The European Commission also proposes requiring Google to allow other AI services to have more access to the Android operating system.

Google stated its security red team could reidentify search users based on the proposed data sharing in less than two hours. The specific details of these security red team tests have not been published. Heather Adkins, Google's vice president of security engineering, said fraud could occur on Android if the proposals are implemented. "If implemented as described today, I think within a short period of time on Android, we'd see a significant increase in fraud in the EU," Adkins said.

Adkins added that the risk of fraud would emerge quickly. "The fraudsters are creative and informed. Past implementation, I would give it maybe weeks before we began to see an increase in fraud in Europe," she said. She also stated that Google would lose control of the data once shared. "Our working assumption is, if we are asked to hand over data we lose control of it, and we just have no functional execution capability to secure it once it's beyond the border of what we control."

David Lewis, Google's director of the company's privacy advisory for Europe, the Middle East, and Africa, addressed the anonymization requirements. "Privacy engineers have proved that this data can be easily reidentified. If data can be reidentified, it is not anonymous in the first place. And the law specifically requires it to be anonymized," Lewis said. He also raised concerns about user privacy. "Whether Google has a vested interest or not is irrelevant to the question of whether millions of people's most private questions may end up with someone they don't know and never expected would see their searches."