Data Privacy in Merger Regulation: A Non-price Parameter in Data-driven Acquisitions?

Mayannk Sharma and Shubh Jaiswal

Abstract

In an era of digital markets characterised by cut-throat competition, firms by and large compete on a variety of non-price parameters, namely quality, user interface, accessibility etc. However, the reluctance of the competition authorities to consider data privacy as a non-price parameter often leads to a veiled ignorance of concentration of personal data that the merging entities possess ex-post, which this paper intends to highlight in subsequent sections. In doing so, the author firstly delineates the emerging tendency of antitrust authorities to make data privacy a part of their competitive analysis while ascertaining the pro vs anti-competitive effects of a proposed merger or acquisition. Secondly, the author attempts to reconcile the various arguments in favour of evaluating data as a non-price parameter by focussing on two aspects, namely— aggressive competition among firms based on non-invasive privacy policies and the possibility of data privacy being considered as an objective justification for a firm’s refusal to share ‘essential’ data.

Introduction

In her seminal dissent against the Federal Trade Commission’s (“FTC”) decision to approve the Google/DoubleClick[1] merger, Commissioner Pamela Jones prophesised the inroads that data privacy is making in data driven mergers and acquisitions. Jones, as the sole dissenter stated that “If the Commission closes its investigation at this time, without imposing any conditions on the merger, neither the competition nor the privacy interests of consumers will have been adequately addressed.”[2] In an era that was dominated by traditional competition analysis, Jones theorised the prospect of exploring data privacy as a non-price parameter for Antitrust enforcement. Since the Google/DoubleClick merger, there has been an exponential increase in data-driven mergers and acquisitions in digital markets where regulatory authorities have begun to factor in data privacy in their antitrust analysis, particularly in the wake of the German Federal Cartel Office’s (Bundeskartellamt) investigation of Facebook in 2019 regarding the processing of user data.[3] Therefore, it becomes increasingly relevant to trace the emerging role of data privacy in the overarching antitrust framework since it lays down a foundation for analysing the various instances in which data has been considered as a non-price parameter in mergers and acquisitions.

Data Privacy as Part-and-Parcel of the Emerging Competition Framework

The debate surrounding the intersection of competition law and data privacy has given birth to two schools of thoughts, namely—the Separatists and the Integrationists.[4] As the name suggests, the Separatist school argues that there should be a strict separation of data protection and competition law and that the former should not form part of the competitive analysis that regulators of competition law undertake. The origin of this theory is attributable to the Court of Justice for the European Union’s (“CJEU”) decision in Asnef-Equifax[5] where the Court opined that the two fields are merely complementary, and not overlapping. The decision in Asnef-Equifax remains the sole authority by the highest court of the European Union on the strict separability of data privacy and competition law. Yet, domestic competition authorities have been actively seeking creative solutions to incorporate data privacy in their evaluation matrix of antitrust disputes.

Pursuant to the CJEU’s decision, a similar approach was followed by the FTC in its decision to approve the merger between Google/DoubleClick despite fervent criticism from Commissioner Jones.[6] A lesser renowned but equally important aspect of the FTC’s decision was Commissioner Leibowitz’s statement, which did not, unlike Commissioner Harbour’s unequivocal support for antitrust intervention, advocate for antitrust intervention, but rather on a more subtle note stated that “the Commission should consider how to address these privacy issues across industries and from multiple perspectives.”[7] Here, we see a diverging approach of the European Commission (“EC”) and the FTC towards data privacy vis-à-vis competition law. The decision by the FTC and the EC seems to be in consonance with each other insofar as the approval of the merger is concerned. However, through Commissioner Harbour and Leibowitz’s critique, the FTC seems to have opened the gates for discussions and deliberations on adopting a dynamic approach to investigating data privacy violations in mergers and acquisitions. However, the EC did not interfere with the reasoning laid down in Asnef-Equifax and continued to observe data privacy and antitrust concerns in a vacuum, albeit as complementary but not overlapping.[8]

The proposed merger between Microsoft and Yahoo[9] was a similar case of the EC’s failure to recognise or understand the impact that the proposed merger would have had on consumer privacy.[10] However, the concerns over possible data privacy intrusions in the case were more appropriate from the point of view of tracking online behaviour and targeted advertising through the usage of third-party tracking. The competitive analysis undertaken by the EC chose to ignore the possible privacy violations arising out of greater access to third party trackers (or cookies) and rather focussed on the conventionally utilitarian aspects of competition analysis such as content variety and relevance.[11] These would largely include the benefits that consumers derive when platforms compete with each other; for example the ability to offer a superior user interface, faster data processing, personalised content generation etc. However, in Microsoft acquisition of LinkedIn[12] , we see a subtle shift from established practices of competition authorities to observe data privacy violations in a vacuum. In the instant case, the Commission identified the nexus between data privacy and competition law for the first time, yet failed to take action citing that the theories posed no actual risk to competition. The Commission, for the very first time theorised that it is possible for data intensive mergers to pose a competitive concern either by increasing the merged entity’s market power by way of accumulation of data  and thereby raising barriers to entry; or if the merging entities used to compete intensively based on data, then the proposed merger or acquisition would impede competition in the market by an apparent reduction in the competitiveness between the parties.[13] The latter theory was a moot point in the Commission’s decision to approve the Verizon/Yahoo merger[14] as well where the Commission dismissed the possibility of raising barriers to entry for new entrants. However, the possibility of an increase in the market power of the merging entities by consolidation of data that the firms possessed and a consequential decrease in data competitiveness post the merger was explored by the Commission.

Finally, we come to the Federal Cartel Office’s (Bundeskartellamt)[15] investigation into Facebook’s policy surrounding the collection and processing of user data.[16] The investigation was a definitive proof of the evolving nature of antitrust authorities to include data privacy violations as part and parcel of the European competition law regime. The FCO, in its analysis was of the opinion that Facebook’s policy of “comprehensive processing of personal data” constitutes an abuse of its dominant position as per Section 19 of Germany’s domestic competition legislation, the ‘German Act against Restraints of Competition (“GWB”)’ which is similar to Article 102 of the TFEU. The FCO’s assessment largely revolved around an involuntary collection of user data since consumers did not ‘actually’ or ‘freely’ consent to Facebook’s data collection and privacy policies, but rather agreed to the same for the purposes of concluding the contract and gaining access to the social media network as a result of which user data can be extracted from multiple third-party sources without their explicit consent. This allowed Facebook to profile individual users by extracting data from multiple sources and building a unique database for individual users which it could then use for targeted advertising which, as per the FCO has the possibility of the market ‘tipping’ in favour of Facebook.[17] Although Facebook has appealed the findings of the FCO before the CJEU[18], it is interesting to see domestic competition authorities apply concepts such as ‘Free and Voluntary Consent’ (which are exclusive to GDPR)[19] to their competition evaluation framework and examine the exploitative and exclusionary conduct of ‘Big Data’ for the first time.

Therefore, it is undeniable from an overview of existing literature that with the advancement in data protection legislations, there has been a parallel increase in antitrust enforcement against big data from a data privacy standpoint. The CJEU once more, has the opportunity to revisit Asnef-Equifax against the backdrop of Facebook’s renewed privacy policies which have also been correlated with anticompetitive conduct by competition agencies and render a decision in favour of integration of data privacy in competition analysis. It is high time that the CJEU recognises that data privacy and competition law go hand in hand and erasing the strict boundary between competition and data privacy is bound to manifest itself in greater consumer choice and welfare.

Evaluating Data Privacy as a Non-price parameter

In view of the emerging regulatory trend to consider data privacy within the competitive framework, it becomes pertinent to evaluate the non-price based parameters within which data as a privacy concern can operate, should the CJEU overrule Asnef-Equifax and side with the FCO in its investigation against Facebook. Therefore, this section of the paper attempts to reconcile the various theories of harm in favour of evaluating data as a non-price parameter by justifying the need for inclusion of data as a non-price parameter; particularly when a merger leads to a reduction in the merging entity’s privacy policies.

  • Firms Compete Aggressively amongst each other based on their Privacy Policies

One way that firms have been increasingly and aggressively competing amongst one another is through consistent variation and innovations in their privacy policies; primarily with a view to appease consumers.[20] They often compete on various technological fronts (such as end-to-end encryption, instant deletion etc.) which offers consumers better conditions of data collection and processing.[21] Even Facebook’s initial strategy to implead consumers to switch to a ‘better’ social media platform were vested in offering a qualitatively superior platform in terms of its privacy policies that its primary competitor, MySpace was unable to offer.[22] For example, in the university spaces, Facebook enforced strict privacy policies by allowing only those users with a ‘.edu’ domain to register with Facebook and interact with others. This was unlike MySpace, which was open to anyone and therefore offered no privacy measures to its users. Because of other similar policy directives, which included inter alia ease in understanding Facebook’s privacy policies, commitments to ‘not’ track user activity across, and utilising cookies to collect any user’s private information, there was a migration of users from MySpace to Facebook at an exponential rate often termed as “The Facebook Effect”. By 2007, Facebook became the most visited social media website, whereas MySpace had to cease its operations shortly afterwards.[23] It is an altogether different debate whether Facebook upheld its commitments over the years following its rise; however, it became increasingly clear that sound privacy policies ‘tipped’ the scales in Facebook’s favour.

Similarly, in another leading example, it would be apt to analyse Facebook messenger’s privacy policies against that of WhatsApp’s prior to the latter’s acquisition by the former. To put WhatsApp’s rise into perspective, it is important to note certain key factors despite which WhatsApp managed to increase its consumer base by twice in comparison to the Facebook messenger by merely offering qualitatively superior privacy policies and data processing capabilities. In early 2010s,  Facebook enjoyed an entrenched position in the social media network market, whereas WhatsApp was relatively newer to the club. Moreover,  the Facebook messenger offered a more sublime user experience because it integrated core features of its social media services into its platform. To add a cherry to the top of all these benefits, WhatsApp users, in certain jurisdictions were obligated to pay a USD 1 user/subscription fees to continue using WhatsApp’s services.[24] Despite all these shortcomings, WhatsApp managed to acquire 600 million users where Facebook’s consumer base stagnated at 250-350 million despite the former’s late entry.[25]

Arguably, this could not have been possible if it were not for a factor that appealed to consumers more than the outstanding benefits that Facebook messenger had to offer. This tipping factor was the intrusive data collection and privacy policies that Facebook operationalised. As per the EC, there was a material difference in Facebook and WhatsApp’s privacy policies. Whereas WhatsApp merely stored limited user information viz. username, phone number etc., Facebook, on the other hand collected information such as birthplace, religion, occupation etc. which allowed it to offer targeted advertisements unlike WhatsApp. Essentially, it can be said that through its privacy policies, WhatsApp imposed significant competitive constraints on Facebook. Pursuant to the merger between the two, Facebook actively made changes to WhatsApp’s privacy policies by mandating users of WhatsApp to share data with Facebook and its group of companies, which was the material difference in the privacy policies that both used to offer. This shows that the non-invasive privacy policies that WhatsApp offered pre-merger imposed significant competitive constraints on the former and allowed WhatsApp to scale considerably (and rather surpass Facebook) within a short period of time.

  • Data, an Essential Facility and Data Privacy, an Objective Justification

The essential facilities doctrine promotes competition in markets that are characterised by indispensable inputs being possessed by a dominant player, by providing access to such indispensable facility to other competitors.[26] To put it simply, the essential facilities doctrine compels a dominant entity to share its resources, which are essential for the competitors’ survival with other competing entities in order to facilitate healthy competition in the relevant market. A facility is considered essential, if no reasonable alternatives are available and duplication of the facility is not feasible due to legal, economic or technical obstacles. The test for establishing a violation of the essential facilities doctrine was set out in Oscar Bronner[27], according to which a firm is considered to have violated the said doctrine in case the following three requirements have been fulfilled, namely:

  1. “The refusal [is] likely to eliminate all competition in the downstream market;
  2. access to the facility [is] indispensable to the competitor’s business, there being no actual or potential substitutes; and
  3. the refusal [is] not capable of being justified.”[28]

From a cursory reading it is apparent that threshold for an asset to be considered an essential facility is considerably higher. Thus, in absence of an objective justification, a dominant entity can be compelled to share such indispensable data without which it will be difficult for competition to survive. Similarly, Attorney General Jacobs while advocating a minimal application of the EFD in Oscar Bronner was of the opinion that the EFD would be applicable where it becomes impossible to duplicate such essential facility. Such impossibility has to manifest itself in the form of barriers to entry thereby preventing new entrants from entering the market.

Against the backdrop of the EFD, it becomes increasingly relevant to assess the status of ‘Data’ and whether there are instances that consider data to be indispensable enough to fall within the fold of the EFD. To that effect, while the status of data as an essential facility is a developing concept, there have been instances where refusal to supply data have been considered as an abuse of dominance under Article 102 TFEU. For example, in the English case of Attheraces[29], the refusal to supply pre-race data to businesses that utilised the same to maintain themselves was considered an abuse under Article 102 by terming such pre-race data as essential. Similarly, the Finnish authorities have adjudicated that refusal to share essential information with its competitors amounts to abusive conduct.[30] The Court did not accept the opposing party’s contention that data privacy served as an objective justification for such refusal making this case one of the first ones to balance essential data services against an objective justification of data privacy.

The argument that “data is ubiquitous and non-rivalrous” is rebuttable on two grounds. Namely that in case data were truly ubiquitous, firms would not offer free services at their personal expense with a view to access personal data of individuals. This is essentially what the Commission implies by terming exchange of personal data for services as ‘transactional.’[31] Moreover, for firms that operate in the business of providing ‘personalised experiences,’ there is hardly any raw data that is stored without any processing; thus, the same is inconsistent with the central argument of data being ubiquitous and non-rivalrous since as soon as data is processed, it loses its ubiquity.[32] Therefore in such (limited) instances, personal data has the capacity to exclude its rivals and thereby cause market foreclosure due to the high barriers of entry that the processed personal data raises. In such instances, data may very well satisfy the ‘essentiality’ requirement for it to be considered within the EFD.

Despite a service or a facility being considered as essential by competition authorities, firms can offer an ‘objective justification’ for their refusal to share such an essential facility.[33] The CJEU, while alluding to the defence of objective justification has opined that “prohibition set out in Article 102 TFEU does not prohibit conduct that is objectively justified and proportionate.”[34] In the context of data privacy, we have earlier seen that the same has not been accepted by Finnish authorities as an objective justification for the refusal of sharing essential data. However, in Epic Games, Inc. v. Apple Inc[35], privacy-as-justification has, of date been recognised as a valid objective justification for refusal to share data.[36] However, drawing upon existing literature, the Court held that such an objective justification would stand valid when the pro-competitive effects outweigh the possible harms arising out of such refusal.[37] Hence, despite limited application, data has not only emerged as a non-price parameter from an essential facility’s point of view, rather data privacy also has emerged as an objective justification for refusal to share such data. From an intersectional perspective, it is clear that data privacy and competition law go hand in glove, especially against the wake of a renewed importance of data privacy as a non-price parameter.

Conclusion

In view of the increasing trend of incorporating data privacy within a competitive framework, it becomes increasingly important that National Competition Authorities (“NCAs) factor privacy as a non-price parameter while assessing a merger. As argued above, firms have, by and large competed amongst each other based on their privacy policies and ex-post amended the privacy policies of the target company to bring them in line with the acquirer’s ex-ante privacy policies. This goes to show that competition authorities have failed to recognise this dilution of privacy policies from a competition law perspective pursuant to the proposed merger or acquisition. Another aspect which remains underexplored by NCAs in their competitive assessment is the intrinsic value of data vis-à-vis the Essential Facilities Doctrine against the backdrop of the value of data itself as an ‘essential facility’. Decisional practices indicate that not only has data found itself at a pedestal of essentiality akin to that of a ‘raw material’ in traditional competition, but also that ‘data privacy’ serves as an objective justification for a refusal to share essential data, which was earlier restricted to infrastructure related developments. Therefore, it is high time that NCAs recognise data privacy as a non-price parameter, for a failure to do so would be prejudicial to the analysis of data-driven mergers where there is a serious risk of data consolidation and accumulation in the hands of ‘big data’ ex-post. The same would ultimately be harmful for innovation in data intensive industries due to the exorbitant barriers to entry such consolidation would pose for fringe market players operating in the same industry.

 

[1] Google/DoubleClick (Case COMP M.4731) Commission Decision (OJ 2008 C184/10).

[2]Dissenting Statement of Commissioner Harbour In the Matter Concerning Google/DoubleClick, FTC File No. 071-0170 <https://www.ftc.gov/sites/default/files/documents/public_statements/statement-matter-google/doubleclick/071220harbour_0.pdf> accessed 12 April 2023. See also opinion of Commissioner Harbour who stated that the Commission forewent an opportunity to examine the effects of the merger on privacy as a form of non-price competition,

[3] Cf the merger and acquisitions in the following cases- Microsoft/Linkedin, Yahoo/Microsoft, Yahoo/Verizon.

[4] Arletta Górecka, ‘Competition Law and Privacy: An Opinion on The Future of a Complicated Relationship’ (Kluwer Competition Law Blog, 8 June 2022) <https://competitionlawblog.kluwercompetitionlaw.com/2022/06/08/competition-law-and-privacy-an-opinion-on-the-future-of-a-complicated-relationship/> accessed 12 April 2023.

[5] Case C-238/05 Asnef-Equifax v Asociacion de Usuarios [2006] ECR I-11125.

[6] Statement of the Federal Trade Commission Concerning Google/DoubleClick, FTC File No. 071-0170 (December 20, 2007), https://www.ftc.gov/system/files/documents/public_statements/418081/071220googledccommstmt.pdf. See also Supra (n 2) Dissenting statement of Commissioner Jones.

[7] Concurring Statement of Commissioner Leibowitz in the Google/DoubleClick Matter, FTC File No. 071-0170 (December 20, 2007) <https://www.ftc.gov/sites/default/files/documents/public_statements/concurring-statementcommissioner-jon-leibowitz-google/doubleclick-matter/071220leib_0.pdf.> accessed 15 April 2023.

[8] Asnef (n 5).

[9] See Case M 5727 Microsoft/Yahoo! 18 Feb 2010, para 163.

[10] Reuben Binns and Elettra Bietti, ‘Dissolving privacy‚ one merger at a time: Competition‚ data and third party tracking(2018) Information Privacy Law Journal <https://www.semanticscholar.org/paper/Dissolving-Privacy%2C-One-Merger-at-a-Time%3A-Data-and-Binns-Bietti/5e8baf3053a25cafe660949f50c0e41f90ef0672> accessed 18 April 2023. See also Robert H Lande, ‘The Microsoft-Yahoo Merger: Yes, Privacy is an Antitrust Concern’ (2008) University of Baltimore School of Law Legal Studies Research Paper No 2008-06 <https://papers.ssrn.com/sol3/papers.cfm?abstract_id=1121934> accessed 8 April 2023.

[11] Ibid.

[12] Microsoft/Linkedin (Case M.8124) <http://ec.europa.eu/competition/mergers/cases/decisions/m8124_1349_5.pdf.> accessed 16 April 2023.

[13] Binns and Bietti (n 10).

[14] Verizon / Yahoo Case COMP/M.8180 Commission Decision (OJ 2016 C184/10).

[15] The Federal Cartel Office is Germany’s national competition regulatory agency.

[16] Case B6-22/16 Facebook, Exploitative business terms pursuant to Section 19(1) GWB for inadequate data processing <https://www.bundeskartellamt.de/SharedDocs/ Entscheidung/EN/Fallberichte/Missbrauchsaufsicht/2019/B6-22-16.html?nn=3600108> accessed 21 April 2023.

[17] Ibid.

[18] Case C-252/21 (Meta Platforms v Bundeskartellamt) [Ongoing].

[19] Article 4 of the GDPR defines consent of the data subject as “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”.

[20] Samson Esayas, ‘Data Privacy in European Merger Control: Critical Analysis of Commission Decisions Regarding Privacy as a Non-Price Competition’  (2019) 40(4) ECLR < https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3498242> accessed 19 April 2023.

[21] Ibid

[22] Dina Srinivasan, ‘The Antitrust Case Against Facebook: A Monopolist’s Journey Towards Pervasive Surveillance in Spite of Consumers’ Preference for Privacy’ (2019) 16(1) Berkely Business Law Journal <https://economics.utah.edu/antitrust-conference/session_material/The%20Antitrust%20Case%20Against%20Facebook_%20A%20Monopolists%20Journey%20Towar.pdf> accessed 13 April 2023.

[23] Ibid.

[24] Italy, the UK, the U.S., Canada, Germany and Spain were jurisdictions where a USD 1 subscription fee was imposed by WhatsApp.

[25] Esayas (n 20) 10. See also Tal Zarsky, ‘The Privacy–Innovation Conundrum’ (2015) 19(1) Lewis and Clark Law Review <https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2596822> accessed 18 April 2023.

[26] Deirdre Ryan, ‘Big Data and the Essential Facilities Doctrine: A Law and Economics Approach to Fostering Competition and Innovation in Creative Industries’ (2021) UCL Journal of Law and Jurisprudence 95 <https://www.researchgate.net/publication/357609116_Big_Data_and_the_Essential_Facilities_Doctrine_A_Law_and_Economics_Approach_to_Fostering_Competition_and_Innovation_in_Creative_Industries Accessed 18 January 2023.

[27] Case C-7/97 Bronner (Oscar) GmbH & Co KG v Mediaprint Zeitungs- und Zeitschriftenverlag GmbH & Co KG (Oscar Bronner) [1998] ECR I-7791.

[28] Ibid; Paul Lugard and Lee Roach, ‘The Era of “Big Data” and EU/US Divergence for Refusals to Deal’ (2017) 31 (2) Antitrust Law Journal 58, 60.

[29] Attheraces Ltd & Anr and The British Horseracing Board & Anr [2005] EWHC 3015 (Ch).

[30] Market Court Judgment of 6 April 2009. Case MAO:178-179/09, para 4.

[31] Esayas (n 20).

[32] Jere Lehtioska, ‘Big Data as an Essential Facility: The Possible Implications for Data Privacy’ (Master’s Thesis, Faculty of Law, University of Helsinki 2018).

[33] Alison Jones, Niamh Dunne, and Brenda Sufrin, EU competition law (7th edn, Oxford University Press 2019) 499; Case T-486/11 Telekomunikacja Polska  [2015] ECLI- 1002, para 815.

[34] Johan Ysewyn, Katarzyna Sadrak, Laura van Kruijsdijk and Antoine Espinasse, ‘The CJEU sets out an analytic framework on exclusionary abuses in the context of market liberalisation’ (Covington Competition, 2 June 2022)

<https://www.covcompetition.com/2022/06/the-cjeu-sets-out-an-analytic-framework-on-exclusionary-abuses-in-the-context-of-market-liberalisation/> Accessed 27 April 2023.

[35] Epic Games Inc v Apple Inc 559 F Supp 3d 898, 1042–43 (ND Cal 2021).

[36] Erika M Douglas, ‘Digital Crossroads: The Intersection of Competition Law and Data Privacy’ (2021) Temple University Legal Studies Research Paper No 2021-40 < https://ssrn.com/abstract=3880737> Accessed 28 April 2023.

[37] Ibid.


Location

Kerwa Dam Rd., 
National Law Institute University, Bhopal
Madhya Pradesh, India. 462044​.