Article 48 GDPR and Competition Law: Toward an Integrated Enforcement Framework

Share

A blog post by Arletta Gorecka.

In an increasingly data-driven global economy, the cross-border flow of personal information has become both an engine of innovation and a source of legal conflict. Nowhere is this tension more visible than in the interplay between data protection rules and competition law. At the heart of this intersection lies Article 48 of the General Data Protection Regulation (GDPR), a provision that prohibits EU data controllers and processors from complying with foreign legal orders unless those demands are grounded in an international agreement. The recent EDPB Guidelines 02/2024 reaffirm the strict territorial nature of EU data protection law and frame Article 48 as a bulwark of European digital sovereignty. These developments carry significant implications—not only for data governance, but also for digital market competition.

This blog post offers an in-depth legal and policy analysis of Article 48 GDPR through the lens of EU competition law, especially in the context of the Digital Markets Act (DMA) and broader gatekeeper regulation. It explores the regulatory friction between foreign legal demands (such as those under the U.S. CLOUD Act or Chinese cybersecurity laws) and GDPR obligations, the potential misuse of privacy law by dominant firms to resist pro-competitive data sharing, and the emerging practice of data localisation as a regulatory workaround. In doing so, it addresses an urgent need: to reconcile the legitimate imperatives of data privacy with the structural goals of competitive digital markets.

Article 48 GDPR as a Cross-Border Blocking Statute”

EU law strictly limits any forced transfer of personal data to non‐EU authorities. Article 48 GDPR provides that “any judgment of a court or tribunal and any decision of an administrative authority of a third country” compelling an EU controller or processor to hand over personal data is only valid if based on an international agreement – for example a mutual legal assistance treaty (MLAT) – between the third country and the EU or a Member State. In practice, Article 48 GDPR is not itself a transfer mechanism but reinforces the ordinary Chapter V rules: any cross‐border disclosure must first satisfy the GDPR’s usual standards of lawful processing (Art. 6 GDPR) and then meet a Chapter V GDPR ground (adequacy, safeguards, or derogation). The European Data Protection Board (EDPB) Guidelines stress this “two-step test”: a request by a foreign authority does not override EU law, and cannot be treated as a de facto legal basis for transfer. In short, absent an applicable treaty or similar agreement, complying with a third-country order would violate the GDPR.

This strict rule makes Article 48 GDPR a powerful legal barrier to cross-border disclosures. As the EDPB warns, personal data held in the EU cannot simply be surrendered on a foreign authority’s say-so; any foreign request must be channelled through a recognised mutual assistance process. Indeed, the provision was often called a “blocking statute” in practice: it forecloses extraterritorial enforcement of non-EU subpoenas without prior EU approval. The Guidelines emphasise that no automatic exception exists: a U.S. court order, for example, “does not itself make the transfer lawful”. Instead, EU entities must rely on the very narrow derogations in Article 49 or adopt approved transfer tools (standard clauses, BCRs) if no international treaty governs the request.

The immediate effect is that third-country authorities generally cannot compel EU companies to hand over personal data unless an appropriate treaty (or adequacy decision) is in place. Even pending criminal or regulatory investigations, EU firms must resist direct foreign orders and use established mutual legal assistance channels where possible. Article 48 GDRP thus imposes a strong presumption against cross-border data disclosure: it insists on EU oversight (through MLATs or comparable international agreements) before data can lawfully leave the EU.

Conflicts for Gatekeepers: CLOUD Act and Chinese Cyber-Regulations

For large digital platforms operating globally, this “no-handout” rule can collide with other jurisdictions’ demands. In particular, U.S. and Chinese laws take very different approaches. Under the U.S. CLOUD Act (2018), American companies—even those storing data abroad—can be compelled by U.S. authorities to produce data for criminal investigations. Yet the GDPR says that unless there is an EU-US treaty, such production would violate Article 48. In effect, a U.S. warrant for data held on European soil cannot be obeyed by an EU‐based controller without running afoul of the GDPR. The tension is acute: Cloud Act executive agreements require EU data protection authorities to assess whether their terms meet GDPR standards, but to date no broad agreement parallels the US-UK or US-Australia accords. As commentators warn, absent a clear EU-US framework, compliance with a Cloud Act demand “would be a violation of the GDPR” and EU controllers are left in legal limbo.

 

At the same time, China’s cybersecurity and data protection laws push in the opposite direction. The Chinese Cybersecurity Law, Data Security Law and Personal Information Protection Law require local storage of certain “important data” and sensitive personal information, as well as regulatory approval (security assessment, certification or filings) for most exports of Chinese-collected data. For a European gatekeeper with operations in China, this means it may face Chinese orders to keep or hand over data that the EU would regard as personal. Conversely, Article 48 GDPR forbids non-EU regulators (e.g. China’s) from extracting EU citizens’ data absent an EU treaty. In practice this mutual assertiveness has led some firms to keep Chinese and European data largely separate. The net result on the ground is a growing “digital sovereignty” reflex: EU companies may avoid exporting Chinese data just as they shun storing EU data on U.S. servers.

These legal asymmetries create acute compliance pressures. Dominant platforms – often U.S.-incorporated or heavily reliant on U.S. cloud services – could technically be forced to choose: break EU privacy rules or defy a homeland security agency. Some EU institutions have already counselled caution: one German government IT agreement explicitly evaluates whether storing data in U.S. cloud will subject it to CLOUD Act orders. In practice, uncertainty over Article 48 GPDR has spurred a form of data “fragmentation” or de facto localisation: many EU entities now insist on Europe-based data storage to avoid potential U.S. orders, and major cloud clients deploy “GDPR-compliant” European data centres. Meanwhile in China, foreign firms often face rigid local hosting requirements for user data, effectively insulating Chinese data from EU companies’ hands. The upshot is that Article 48 – like China’s own outbound controls – contributes to a trend where data is increasingly tethered to its jurisdiction of origin.

Overlaps of Data Protection and Competition Law (The DMA Lens)

The new Digital Markets Act illustrates how competition policy can intersect with these data protection rules. The DMA imposes ex-ante obligations on “gatekeepers” (large platforms) to share data and interoperate in ways that explicitly involve personal information. For example, Article 6(9) DMA obliges gatekeepers to enable user data portability with “continuous and real-time access”, and Article 6(10) DMA requires them to give business users access to “aggregated and non-aggregated data, including personal data” generated through the platform. These DMA duties, if fully implemented, could force gatekeepers to disclose personal data to third parties or regulators at a rapid pace.

 

At first glance, this might clash with GDPR’s emphasis on privacy. The DMA text itself acknowledges this, stating that it “applies without prejudice” to the GDPR. In practice, regulators have noted that the two regimes are meant to complement each other. Commission officials point out that the DMA even uses GDPR definitions of “personal data” and “consent”, and oblige gatekeepers to obtain “GDPR-grade consent” for any novel cross-use of data (e.g. for targeting ads). On the other hand, the GDPR does not generally require controllers to adopt new technology merely to transfer data, whereas the DMA mandates real-time APIs and continuous portability.

These instruments share the goal of protecting individuals and market fairness – albeit from different angles. The EDPB and Commission recognise a common objective of safeguarding consumers (as users) while promoting contestable markets. Indeed, the CJEU recently emphasised that access to personal data has become “a significant parameter of competition” in digital markets, and excluding data protection from competition analysis would “undermine the effectiveness of competition law”. In other words, both fields acknowledge that data privacy and competition policy often overlap in the digital economy.

This overlap can work two ways. Privacy protections can sometimes limit data access that competition authorities seek; conversely, competition obligations (like those in the DMA) can drive more data sharing. Under EU law, however, one framework cannot be wielded to nullify the other. Notably, the TeliaSonera case (2011) holds that a dominant firm cannot invoke data protection rules to justify a refusal to supply a competitor. Conversely, competition enforcers must respect data protection: DMA obligations to share personal data are explicitly qualified by GDPR standards (e.g. requiring user consent and security safeguards). The sideline guidance suggests harmonisation: the EDPB recommends joint discussions and training between DPAs and competition authorities, and even “expert working groups” to iron out conflicts.

Article 48 as a Shield for Dominance (Risk of Abuse)

A particular concern is that dominant platforms might misuse Article 48 GDPR as a shield against pro-competitive data-sharing duties. For example, a gatekeeper could claim that sharing certain user data (with a rival or regulator) would trigger a foreign legal threat, and hence invoke GDPR to refuse. Because Article 48 GDPR covers any foreign request, it could be cited whenever data is stored or crosses a border – even if the counterparty is in the EU or the data is already in the EU. Without careful checks, this could become a pretext: dominant firms might argue that each data transfer required by DMA or by competition authority oversight implicates a potential third-country enforcement risk.

However, legal doctrine calls this bluff. Article 48 clearly targets third-country authorities, not EU obligations. It “does not apply” to transfers for compliance with EU law enforcement or regulatory decisions, which are outside its scope. Moreover, controllers still must find an independent GDPR basis for any data sharing (legal basis under Article 6 and transfer mechanism under Chapter V) even if Article 48 GDPR is silent on EU requests. The EDPB Guidelines explicitly note that a foreign authority’s demand cannot be folded into a GDPR Article 6(1)(b) or (c) legal basis; it remains only a “specific factor” when balancing safeguards. In other words, if no international agreement exists, the firm must rely on standard grounds (for example, anonymisation or consent) or derogations – not simply refuse outright.

Courts have similarly rejected over-broad uses of privacy to block competition. The CJEU has held that dominant firms cannot use personal data protection as an unjustified barrier to competition (as in TeliaSonera). By parity, invoking Article 48 GDPR to escape DMA duties would likely fail if the data sharing is actually mandated by EU law. Absent a genuine cross-border enforcement request, Article 48 GDPR should not be interpreted as creating a “de minimis” excuse for non‑compliance.

Policy Proposals

To reconcile these tensions, policymakers should aim for better alignment between data protection and competition law. Some concrete proposals include:

  • Joint guidance and consultations. The EDPB, national DPAs and competition authorities (including the European Commission’s DGComp) should issue joint guidelines interpreting DMA obligations vis-à-vis the GDPR. For example, a common opinion could clarify that compliance with EU mandates (like data portability to EU-verified third parties) is not obstructed by Article 48. Expert working groups or a permanent “data-competition” liaison network could be established to review cases where DMA and GDPR overlap. The recent EDPB position paper suggests exactly this kind of formal cooperation framework, including point-of-contact networks and consultation protocols.
  • Legislative clarifications. The law itself could be amended to ease the conflict. For example, a targeted recital or amendment to the GDPR might state that Article 48 “shall not prevent transfers of personal data required for compliance with obligations under Union competition or digital market regulations, provided that appropriate safeguards (such as pseudonymisation or secure interfaces) are in place.” Alternatively, the DMA regulation could expressly mandate that data-sharing obligations override the strict application of Article 48 in the case of requests from EU-defined authorities or users. The goal would be to ensure that Article 48’s narrow exception does not swallow an EU-imposed duty. (In practice, this might mean classifying DMA data sharing as a “public interest” requirement under Article 6(1)(e) or © GDPR.)
  • Technical interoperability and privacy-enhancing tools. Regulators could encourage use of privacy-preserving technologies to satisfy both regimes. For instance, the DMA’s data access requirements could be implemented via standardised APIs that automatically anonymise or pseudonymize personal identifiers, satisfying GDPR principles while still giving business users valuable insights.

 

Conclusions

Article 48 GDPR was designed as a narrow safeguard against uncontrolled foreign data demands. As the EDPB Guidelines make clear, it must not be read as a blanket ban on all international data flows, but as a condition precedent requiring valid grounds under EU law. In the context of the DMA and broader competition policy, this balance is crucial. Dominant platforms must be held to their pro-competitive sharing obligations, but without eroding personal data protection. The European legal order already provides tools for harmonising these aims: the DMA itself defers to the GDPR, and the EDPB urges regulators to coordinate.

To avoid a stalemate – where Article 48 becomes an excuse for data hoarding – EU policymakers should take proactive steps. Clear guidance can affirm that compliance with EU-mandated data sharing is a legitimate purpose. Technical solutions can demonstrate that privacy and openness need not conflict. And if necessary, legal fine-tuning can underscore that the GDPR’s blocking rule was never meant to undermine the EU’s own competition and market rules. By forging these synergies, the EU can ensure that its data protection and digital market laws reinforce rather than frustrate each other, promoting both consumer privacy and competitive choice in the digital age.