Anonymisation, Two Ways
The EDPB’s new guidelines complicate DG COMP’s Article 6(11) DMA playbook.
In an earlier post, Article 6(11) DMA Explained: Search Data, Contestability and Anonymisation, I described Article 6(11) as one of the most interesting stress tests in the EU digital rulebook: a provision that recognises the competitive importance of search-data feedback loops, but whose implementation depends on whether “anonymised” is treated as a real legal condition or a convenient compliance label. I developed the same point more formally in my Commission submission in Case DMA.100209, where I argued that the Commission can and should make Google Search data access work, but not by inventing a privacy fiction in which transformed record-level data plus contractual promises is treated as anonymisation.
This post picks up that argument from a slightly different angle. The EDPB’s new anonymisation guidelines were not written for Article 6(11), and they do not settle the Google Search data-sharing debate. But they do sharpen the central question. DG COMP is trying to build a useful competition remedy; the EDPB is trying to preserve the boundary between personal and anonymous data. Both objectives are legitimate, yet the word “anonymised” is now being asked to carry different institutional expectations. The question is whether the DMA can preserve contestability without quietly creating a sector-specific meaning of anonymisation that sits uneasily with the GDPR. It also engages the broader EU law requirement that instruments of equal rank and shared legal concepts be interpreted coherently rather than allowed to diverge by enforcement silo.
The EDPB’s new anonymisation guidelines did not arrive in a vacuum. They arrived at the very moment when DG COMP is trying to turn Article 6(11) of the Digital Markets Act from a legislative obligation into a working access regime for Google Search data. That coincidence matters because the same word, “anonymised”, is now doing work in two very different institutional settings: in the GDPR, it marks the boundary between personal and non-personal data; in the DMA, it is being operationalised as part of a competition remedy whose purpose is to make search markets more contestable.
The guidelines are not about Google Search, and they do not offer an easy answer to the Article 6(11) problem. They are not a privacy maximalist veto, nor are they a deregulation charter for data sharing under controlled conditions. Their more important move is to accept, with some care, that anonymity can be contextual: information may be personal data for one entity and anonymous for another, depending on access, auxiliary information, technical capability, legal context and the means reasonably likely to be used. That is a significant development, particularly after EDPS v SRB, because it rejects the idea that anonymisation must mean destruction of every possible human trace for every possible observer.
At the same time, the EDPB does not turn contextual anonymisation into a governance label. It does not say that a dataset becomes anonymous because recipients are licensed, audited, supervised or contractually prohibited from re-identifying individuals. It treats contractual and organisational measures as relevant to the context, but not as substitutes for changing the data. That is where the tension with DG COMP’s Article 6(11) approach begins, because the Commission’s practical task is to preserve sufficient query, click, view, and ranking signals for rival search engines to improve their services while also ensuring that personal data has been anonymised before it is shared.
The same word is being pulled in two directions.
The Article 6(11) debate is presented as a contest between privacy and competition, but that framing is too crude. The better way to see the problem is as a clash between two legal technologies. The EDPB is asking when information has crossed the boundary from personal data to anonymous data under the GDPR. DG COMP is asking how to design a data-access remedy that is sufficiently useful to support contestability in a market where scale in search data is part of the competitive moat.
The tension is not that DG COMP disregards privacy, or that the EDPB insists on a zero-risk standard. DG COMP is trying to prevent privacy from becoming a pretext for rendering the Article 6(11) access right nominal, and its model assumes that a tightly specified licensing, separation, and assurance scheme can confine the use of the Search Dataset to its intended pro-competitive purpose. The EDPB, by contrast, accepts that access restrictions and recipient controls matter to the context, but insists that anonymous status cannot be created by promising, monitoring or licensing good behaviour if realistic means of identification remain available. The issue is therefore whether DG COMP’s contractual perimeter merely governs the use of data that has already been anonymised, or whether it is being asked to complete the anonymisation itself.
Why Article 6(11) is the Hard Case
Article 6(11) is a particularly difficult test case because search data is not ordinary operational data. Paragraph 85 of the guidelines is particularly important here because it identifies the factors that should ordinarily be used to test the effectiveness of a re-identification technique: whether the data is aggregated or record-level; its dimensionality, resolution and diversity; the number of individuals represented in a record; and the amount of additional information available for combination. Search data often sits at the difficult end of that framework. It can preserve granular record-level traces across query text, ranking exposure, reformulation, clicks, timing, location and sequence, while recipients may also hold substantial auxiliary data. A search query may be banal, and many are. Still, a sequence of queries may reveal health concerns, financial distress, sexuality, religion, legal problems, political anxieties, family conflict, workplace issues, migration status or the identity of a third party named in the query. Even when direct identifiers are removed, those combinations may preserve enough structure to re-identify a user, whether by isolating a distinctive record, linking it to other data or drawing a specific and meaningful inference.
The privacy and utility problem, therefore, cannot be neatly separated. Still, the point does not depend on the claim that rare or long-tail queries are necessarily the most valuable data for rivals. The more defensible point is that many fields that create search utility (i.e., query wording, reformulations, ranking position, timing, click behaviour, language, location and limited sequence) also increase dimensionality, resolution, diversity and linkage potential under paragraph 85. The assessment must therefore examine combinations of fields and use cases, rather than assume that a field is safe merely because it appears innocuous in isolation.
This is the point that tends to get lost when the discussion is reduced to “anonymised search data”. Search logs do not become safe merely because names, account IDs, IP addresses and exact timestamps have been stripped away. That is necessary work, but not sufficient work. The legal question is whether the remaining data, in the hands of the relevant recipient and against the means reasonably likely to be used, still allows a person to be distinguished and treated differently. Paragraphs 29 and 51 of the guidelines require the assessment to include the properties of the data, the processing context, available auxiliary information and foreseeable technological developments, and to map information held by or accessible to relevant entities. If a recipient operates its own search service, stores user logs, participates in advertising or analytics markets, has browser or app data, trains AI systems, or can use public sources to link distinctive query patterns to individuals, those contextual facts fall within the anonymisation assessment rather than outside it.
What the EDPB Gives DG COMP, and What it Takes Away
The EDPB guidelines are useful to DG COMP in one important respect: they reject an absolutist account of anonymisation. The guidelines accept that anonymity can be assessed from the perspective of the relevant entity and that the likelihood of identification need not be zero, only insignificant in reality. They also make clear in paragraph 52 that failure of No Record Isolation, No Linkage, or No Inference does not automatically determine the legal status of the dataset; it triggers further analysis to determine whether the failure actually enables individuals to be distinguished and treated differently. This creates space for a contextual, recipient-specific access regime rather than forcing every assessment to proceed as if the data had been released to the world at large.
The same guidance also makes the easy version of the Commission’s position much harder. Paragraph 34 says that a contractual prohibition, even if legally binding, is not a prohibition by law and should only complement technical measures. Paragraph 90 adds that technical, organisational and contractual restrictions can help to limit access but are not, by themselves, sufficient to make data anonymous. The implication is not that contracts are irrelevant; in a controlled data-sharing environment they may be essential. The implication is that contracts cannot perform the decisive legal act of anonymisation where the dataset remains identifying in the relevant context by means reasonably likely to be used.
DG COMP’s Article 6(11) architecture operates through a three-stage logic: baseline re-identification risk before treatment; residual risk after the technical measures; and an insignificant likelihood after the contractual and organisational measures. The latter two stages are expressly set out in paragraph 19 of the preliminary measures, so this is not an incidental feature. A layered model is not wrong, and contracts may affect which means are reasonably likely to be used, but the Commission must explain how that logic is consistent with paragraphs 34 and 90 of the EDPB guidelines.
The key question is whether the technical layer has done the decisive anonymisation work, with the contractual layer reinforcing a technically sound result, or whether the recipient is being asked to move the dataset across the legal boundary.
In the latter case, the regime begins to look less like anonymisation and more like governed personal or pseudonymised data sharing.
The Real Contradiction
Paragraph 87 adds a further difficulty that is especially important for daily record-level search datasets. It says that a re-identification technique may be effective even if it succeeds against only one individual in a much larger dataset. That paragraph does not, by itself, say that one vulnerable record automatically makes every other record personal; the companion rule is paragraph 36, to which para 87 refers, and which provides that a dataset is anonymous only if anonymisation is effective for all included individuals. Where personal and anonymous parts cannot be treated separately, the entire dataset must be treated as containing personal data. The practical consequence is that average risk is not enough: the Commission must show either that vulnerable records are reliably suppressed or segregated, or that the dataset as a whole satisfies the anonymisation standard.
The central contradiction is therefore not that the DMA wants competition and the GDPR wants privacy. It is that DG COMP’s model assumes that licensing, separation, auditing and enforcement can confine the Search Dataset to its intended pro-competitive use and help bring risk to an insignificant level. At the same time, the EDPB treats those controls as contextual safeguards that cannot substitute for the conclusion that the data has been anonymised. Both positions can coexist, but only if the technical and contextual analysis (not the recipient’s promise!) does the decisive work.
This is where the EDPB guidelines are useful, but not in the way some people may want them to be useful. They do not say that Article 6(11) cannot be implemented. They do not say that search data can never be anonymised. They do not deny the relevance of context, access restrictions or recipient obligations.
What they do is require the Commission to demonstrate, rather than assert, that the record-level dataset survives the factors in paragraph 85, the single-individual test in paragraph 87, the contextual analysis in paragraphs 88 to 90 and the mixed-dataset rule in paragraph 36.
That makes it much more difficult to defend an access regime in which the legal status of the data depends too heavily on the promise that recipients will not use means that remain available to them in practice.
The Better Way Through
The better course is not to weaken Article 6(11), nor to pretend that search logs become anonymous by formula. The better direction is to treat Article 6(11) as an evidence-led access regime in which anonymisation is assessed first, utility is measured second, and access modality is chosen third. That ordering matters because Recital 61’s usefulness language should be read as requiring the preservation of utility after anonymisation has been achieved, not as permission to dilute the anonymisation threshold to preserve more signal.
In practical terms, the Commission should not treat ranking, query, click and view data as a single homogeneous category. Query text, refined queries, click-back behaviour, scroll events, ranking position, result URLs, location, device context and mini-session structure each carry different utility and privacy risks, and those risks change again when fields are combined. This is also the operational implication of paragraphs 51 and 85: map each field and the auxiliary information available to relevant entities, then assess record-level status, dimensionality, resolution, diversity and combination risk. A serious Article 6(11) architecture should therefore require field-level assessment, recipient-context testing, documented utility benchmarks and a clear explanation of why particular fields are exported, aggregated, delayed, suppressed, routed to controlled access or subjected to regulatory review.
This is where an Anonymisation and Utility Impact Assessment (which I suggested in my submissions to the EC) would be useful if properly designed. It should not become a mechanism for trading privacy down against utility, nor should it become the kind of paperwork exercise that turns a hard technical and legal question into a compliance appendix. It should be the evidence pack that operationalises the documentation requirement in paragraph 41 and the technical framework in paras 43 to 90: data mapping, relevant entities and auxiliary information, the three criteria, state-of-the-art attack testing, technique accuracy, safety margins, access controls and reassessment triggers. It should demonstrate, field by field and recipient context by recipient context, how the data has been rendered anonymous in accordance with the GDPR standard and what contestability value remains after that transformation is complete.
The access regime should also be tiered. Common, lower-risk, high-frequency data may be exportable after robust technical transformation. Aggregate or differentially private signals may be appropriate where market-entry, trend, language or geography information is useful without requiring record-level disclosure. Certain higher-value but higher-risk signals may require controlled API access, clean-room access to data that has already crossed the anonymisation threshold, output checking, query whitelisting, logging, and auditing. Some data may need suppression, and some suppressions should be reviewable by the Commission, a competent data protection authority, or trusted experts, subject to confidentiality. That is not a privacy veto; it is the architecture needed to keep the access right useful without turning “anonymous” into a word of convenience.
The Wider Lesson for the EU Digital Acquis
Article 6(11) is a useful test case because it exposes a wider problem in EU digital regulation. The GDPR, DMA, DSA, Data Act, AI Act, Data Governance Act, NIS2, DORA and the Digital Omnibus all rely on overlapping concepts: personal data, anonymous data, pseudonymised data, access, transparency, audit, risk, security, interoperability and contestability. If those concepts are operationalised differently in each regime, the EU will not achieve simplification; it will face semantic fragmentation managed by guidance, enforcement discretion, and sector-specific workarounds.
That is why the Article 6(11) anonymisation question is bigger than Google Search. It asks whether competition law can use data protection concepts without quietly redefining them for convenience, and whether data protection law can remain rigorous without making socially valuable data access impossible in practice. The right answer is a single standard, not a single technique. A single standard does not mean that every dataset, recipient, access environment or use case is treated alike; the EDPB itself has moved away from that kind of absolutism. It means that “anonymous” should not mean one thing in a DMA specification decision, another thing in GDPR guidance, and a third thing in the Digital Omnibus.
The EDPB guidelines therefore do not end the Article 6(11) debate; they make it more legally honest. DG COMP has a legitimate contestability problem to solve, and the EDPB has a legitimate boundary problem to protect.
The bridge between the two cannot be built on the proposition that useful data plus contractual promises equals anonymised data.
It has to be built on technical anonymisation assessed in context, supported by governance controls, documented through testing, preserved through tiered access, and reassessed as technology, auxiliary data and recipient capabilities change.
The final question is therefore not whether search data should be shared, because the DMA has already answered that at the level of legislative policy. The question is whether, when the Commission says that search data has been anonymised for Article 6(11), that term means what it means elsewhere in EU data protection law. That is the question DG COMP now has to answer, and the EDPB’s new guidelines make it much harder to answer by relying on contracts to do the work that anonymisation itself must do.






