The Interface between Competition Law and Data Privacy Law Violation of Privacy as an Exploitative Theory of Harm under Article 102 TFEU

Share

Book overview: ”The Interface between Competition Law and Data Privacy Law Violation of Privacy as an Exploitative Theory of Harm under Article 102 TFEU” (Springer 2024)

Arletta Gorecka

Introduction

In today’s digital economy, data is currency—and Big Tech firms are thriving in a market that often trades consumer privacy for convenience. But can EU competition law, specifically Article 102 TFEU, rise to meet the challenges this creates?

That is the central question my monograph explores.

”The Interface between Competition Law and Data Privacy Law Violation of Privacy as an Exploitative Theory of Harm under Article 102 TFEU” (Springer 2024) examine whether the current EU competition law framework can accommodate privacy-related theories of harm—particularly through the lens of exploitative abuse of dominance. From zero-priced business models to aggressive data harvesting, I argue that privacy harms can and should be recognised as a form of exploitation under competition law.

Setting the context of the research

In the digital economy, personal data has become a vital asset. Digital platforms, particularly those classified as ”data-opolies”—dominant firms such as Google, Apple, Facebook, Amazon, and Microsoft (GAFAM)—rely heavily on extensive data collection to drive their business models. These firms offer users ostensibly ”free” services, monetised through data-driven advertising and analytics. However, this data-centric model raises critical questions about the interface between privacy rights and competition law, particularly in the context of exploitative abuse under Article 102 of the Treaty on the Functioning of the European Union (TFEU).

Article 102 TFEU prohibits dominant undertakings from engaging in abusive practices, including exploitative conduct that harms consumers. Traditional exploitative abuses involve excessive pricing or unfair trading conditions, but in data-driven markets, the nature of harm shifts from monetary to informational. A growing body of scholarship and regulatory concern suggests that certain data practices—such as the excessive collection, bundling, or repurposing of personal data—may amount to exploitative abuses when undertaken by firms with significant market power. The difficulty lies in determining whether such privacy intrusions can be assessed within the competition law framework, especially when those practices are simultaneously governed by data protection law, particularly the General Data Protection Regulation (GDPR).

Consent is central to the GDPR’s approach to data protection. Under Article 6(1), processing of personal data is lawful only when based on a valid legal ground, including the freely given consent of the data subject. Recital 32 specifies that consent may be indicated by ticking a box or another affirmative act, while Recital 43 clarifies that consent is not valid if there is a clear imbalance between the data subject and controller. This notion of informational self-determination aims to empower individuals by allowing them to control the flow and use of their personal data.

Yet, in digital markets, the voluntariness of consent is highly contested. Many digital platforms bundle consent to data processing with access to core services, leaving users with little genuine choice. Article 7(4) GDPR addresses this issue by stating that consent is not freely given if access to a service is conditional on data processing that is not necessary for performance of the contract. Despite these safeguards, consent often becomes a formalistic, box-ticking exercise rather than a meaningful expression of user autonomy. Users frequently lack the knowledge or power to understand or resist complex and opaque data practices, particularly when dealing with dominant platforms that offer indispensable services.

The interplay between competition law and GDPR is particularly relevant in cases where a firm’s market power may influence the conditions under which consent is obtained. The German Federal Cartel Office took this approach in its landmark case against Facebook.[1] The authority found that Facebook abused its dominant position by making access to its core social network conditional on consenting to the collection and combination of data from various sources, including third-party websites and apps. The BKartA argued that such consent was not truly voluntary and thus constituted an exploitative abuse of dominance under Article 102 TFEU. Although the case ultimately required interpretation by the Court of Justice of the European Union (CJEU), it sparked a broader debate about whether privacy-related harms can—and should—be evaluated through a competition law lens.[2]

The CJEU confirmed in its ruling that breaches of GDPR can be relevant in the context of a competition law investigation, provided they are assessed within the broader legal and economic framework. While non-compliance with the GDPR does not automatically imply a competition law infringement, the Court emphasised that such breaches can serve as indicators of market behaviour that may distort competition. This view reflects a more integrated understanding of the digital economy, in which data protection and competition policy converge around shared concerns for user autonomy, fairness, and market structure.

Transparency is another critical element in both legal regimes. Article 5(1)(a) GDPR enshrines transparency as a core principle, requiring data controllers to inform users clearly and promptly about data processing activities. Articles 13 to 15 further reinforce these obligations by requiring disclosures at the time of data collection. Without transparency, meaningful control is impossible—yet dominant firms often obscure the true extent of their data practices, further undermining the effectiveness of consent mechanisms. This lack of transparency not only weakens GDPR compliance but also contributes to a degradation in service quality that may harm consumers from a competition perspective.

Despite these overlaps, GDPR remains silent on market power considerations, and does not directly address the competitive implications of privacy erosion. Conversely, competition law has traditionally been hesitant to incorporate non-price dimensions like privacy into its analytical framework. However, as data becomes a key parameter of competition, and as users increasingly pay for services with personal information rather than money, the artificial separation between data protection and competition enforcement appears increasingly untenable.

This research adopts the position that privacy degradation can, under certain conditions, constitute an exploitative abuse of dominance under Article 102 TFEU. In digital markets, where few firms hold disproportionate control over user data and can impose take-it-or-leave-it terms, the ability of users to exercise informed and voluntary consent is limited. Such dynamics undermine both user autonomy and market competition. The notion of privacy as a non-price competitive parameter reflects the shift from traditional price-focused models to data-driven markets, where harm may manifest not in overcharging, but in over-collection and misuse of personal data.

Research Overview and the core argument

The book is structured into four substantive chapters, each aimed at exploring whether EU competition law can recognise privacy-related harms within the context of abuse of dominance under Article 102 TFEU.

In Chapter 2, I consider the theoretical intersection between competition law and privacy, emphasising that this relationship is still in its early stages. I present and explore three main theories regarding the link between competition law and privacy: integrationist, separatist, and value pluralism. I critically assess the limitations of both the separatist and integrationist views, arguing that neither provides sufficiently prescriptive guidelines for interpretation and application.

I also discuss the complexity of coordinating competition law and privacy policies, particularly because EU competition law is not a stand-alone statute but is integrated into the broader framework of the TFEU. This means that competition law is influenced by numerous factors beyond the mere presence of data in a specific market. I highlight the role of value pluralism, suggesting that competition law assessments should consider a range of values, including economic freedom, consumer welfare, fairness, and legal certainty. This approach allows competition authorities the flexibility to tailor decisions to the specifics of each case.

Through my analysis, I show that the most challenging cases arise when competition law and data privacy law intersect. These cases require nuanced analytical methods and trade-offs, going beyond simple associations and demanding a deeper understanding. While acknowledging that competition law and data protection laws have different scopes, I recognize that privacy concerns can be part of quality-based competition. I introduce value pluralism as a framework for balancing these two areas of law, providing a principled approach for courts and competition authorities when making case-specific decisions.

I also clarify that competition law is not a catch-all solution for privacy concerns. It can only address privacy issues when they relate to abuse in competition. Ultimately, I demonstrate that the most complex legal challenges stem from the intersection of competition law and data privacy law, rather than from a simple link between the two. Furthermore, I point out that the concept of consumer welfare in Article 102 TFEU is sufficiently broad to encompass harm theories that involve exploitation.

In Chapter 3, I consider instances where privacy issues have been addressed within antitrust investigations targeting data accumulation strategies. I discuss how decision-making practices have evolved, illustrating three key positions regarding the intersection between competition law and data protection: initially, the view that data privacy law is outside the scope of competition law; later, the consideration that competition law could potentially address privacy infringements within a broader legal and economic context. Through this three-phase approach, I show how EU courts have shifted their interpretation of the relationship between competition law and data protection law, moving from a strict separation of the two to an increasing recognition of privacy-related harms within competition law.

I argue that, up until now, competition law enforcers have typically adhered to a ”separationist” approach, which I attribute to the organisational structure of competition agencies and the economics-driven nature of antitrust enforcement. However, I point out that the challenges faced by competition authorities in the digital age underscore the necessity for competition law to no longer remain indifferent to the impact of other areas of law.

I use the Facebook case to highlight the inherent conflict between data protection and competition law. I discuss how the BKartA applied German competition law to assess whether Facebook’s requirement for consent to combine personal data from different sources constituted exploitative abuse by a dominant firm, using data protection law as a benchmark to establish Facebook’s abusive conduct. I contextualise the Facebook case and examine concerns raised by the BKartA, AG Rantos, and the CJEU, demonstrating that the incidental consideration of data privacy within competition law assessments could serve as a proxy for identifying exploitative abuse in a broader economic context.

Through this analysis, I raise two critical questions: first, whether consent, as defined under the GDPR, could be effectively given to a dominant firm; and second, whether the BKartA had the necessary authority to find a GDPR infringement during its competition law investigation. I also focus on how competition authorities are increasingly considering the GDPR in their work, emphasising that competition law enforcers can no longer ignore the influence of other disciplines if their indirect consideration helps capture competitive harm.

I challenge the view that privacy and antitrust have a complementary relationship and argue that the principles established in the Facebook case do not provide a definitive resolution to the issue. I employ a doctrinal methodology, analysing relevant case law, policy, and literature, to support my discussion.

Building on the findings from Chapters 2 and 3, I consider the application of exploitative theories of harm in competition law, which I note have been underdeveloped in relation to privacy concerns. I discuss the consumer-centred approach taken by the BKartA in the Facebook case, where consumers are seen as having a right to informational self-determination and are responsible for evaluating competitive offers. One of the key concerns I raise is how privacy violations could be considered when evaluating competition levels in the digital economy. I explore whether EU competition law should develop specific theories of harm related to privacy and emphasise the growing importance of protecting individual privacy as part of addressing abuse of dominance.

While most anticompetitive investigations related to data do not explicitly focus on privacy, I highlight how competition law agencies have begun to address new forms of digital market abuses. I discuss whether companies could use privacy improvements to avoid anticompetitive liability under Article 102 TFEU and explore this emerging issue in the relationship between competition law and data privacy law.

In Chapter 5, I consider the findings from my research to propose a new approach to interpreting the relationship between competition law and privacy. I introduce the ”privacy-trap theorem,” which I developed to demonstrate that, in certain cases, privacy infringements could serve as a trigger for competition law assessments. I argue that competition law should only address privacy concerns when they directly affect competition. My aim is to establish a practical connection between competition law and privacy protection, showing that competition authorities can no longer ignore the influence of data protection law.

I discuss how competition law and privacy law, while pursuing different goals—efficiency in competition versus protection of individual privacy—can be seen as complementary. However, I note that privacy regulations do not fully address the exploitation of personal data, particularly when it comes to long-term harm to platform users. I emphasise that dominant firms in the market have a unique responsibility to avoid misusing their position. The chapter highlights how the digital economy has raised important questions about the interaction between competition law and privacy and calls for a more nuanced approach to these two areas of law.

I stress that there is no established framework to define the relationship between competition law and data protection, especially when privacy concerns are involved. I argue that by recognising the aggregation of personal data as a potential source of market power, competition law enforcement can provide recourse when companies use their market power to harm privacy. This requires balancing competition law with data privacy considerations. In the case of Facebook, for instance, I argue that a consent-related violation of the GDPR does not automatically constitute an abuse of dominance. Instead, competition law must assess the impact on competitive dynamics and privacy protection.

I map out the intersection points between competition law and data protection, arguing that both deserve closer scrutiny. My analysis utilises doctrinal legal research to examine relevant EU legislation, case law, policy documents, and literature in both the fields of data protection and competition law.

Conclusion

This monograph demonstrates that Article 102 TFEU offers a sufficiently broad and flexible framework to address exploitative privacy-related harms, as it does not prescribe an exclusive list of harm theories. I explore whether privacy-related harms resulting from dominant firms’ practices, like coercive data collection or exploitation of users’ data, should be recognised as a form of abuse. While Article 102 traditionally focuses on price-related abuses, I argue that a broader interpretation of harm can be justified, beyond just economic consequences. I highlight that privacy reduction may not always constitute a competitive issue, as compliance with data protection laws could avoid a breach. The EU courts support a broader consumer welfare approach, where privacy-related harms may be indirectly considered as part of competition assessments. I conclude that while privacy protection is not the primary aim of competition law, when privacy concerns directly affect competition, they can be addressed through Article 102 TFEU. The incidental consideration of data protection rules under competition law does not expand its scope but ensures fair competition by addressing practices undermining competition.

Read more

[1] Case B6-22/16 Facebook, Exploitative business terms pursuant to Section 19 (1) GWB for inadequate data processing. Available at https://www. bundeskartellamt.de/SharedDocs/Entscheidung/EN/Fallberichte/ Missbrauchsaufsicht/2019/B6-22-16.html?nn=3600108

[2] Case C-252/21 Meta Platforms and Others (Conditions Générales d’Utilisation d’un Réseau Social); Case C-252/21, Request for a preliminary ruling, Meta Platforms and Others (Conditions générales d’utilisation d’un réseau social) ECLI:EU: C:2022:704, Opinion of AG Rantos