Google must share Search click data from January 2027: what it changes for SEO

Google must share query and click data from January 2027, but the purpose limits are narrower than most coverage suggests.

Read time
15 min
Word count
2.2K
Sections
11
FAQs
8
Share
Google search data vault streaming anonymised query and click records to smaller rival search engines
From January 2027 Google must share anonymised query, click and view data with eligible EU search engines.
On this page · 11 sections
  1. What Google actually has to share
  2. The purpose limits are the story everyone missed
  3. Almost nobody qualifies, and that is deliberate
  4. The implementation calendar Alphabet is working to
  5. What this actually changes for SEO teams
  6. The measurement problem this creates
  7. Privacy: the part that stays uncomfortable
  8. India-specific considerations
  9. FAQ
  10. How eCorpIT can help
  11. References

Summary. On 16 July 2026 the European Commission adopted a binding specification decision requiring Google to share anonymised ranking, query, click and view data with eligible rival search engines, including AI chatbots that offer search. Sharing starts in January 2027. The Commission stepped in because Alphabet's own compliance offer had been "removing between 90 and 100% of unique search queries from the dataset" and excluding AI chatbots entirely, which produced no meaningful uptake after two years of talks. Google Search has held more than 90% market share in Europe for decades. The bar to receive the data is high: a rival must have run a search engine in the EU for two consecutive years or, if younger, have raised more than €50 million, and must show at least 50,000 monthly average users in the EU over the past year. The anonymisation floor is k-anonymity of 1,000 users per group, with 95% of users in groups of at least 29,000. Data arrives with a minimum seven-day latency and access is capped at five years per beneficiary.

Most coverage of this decision has framed it as Google being forced to hand its search advantage to ChatGPT. That is not what the measures say. The purpose limits are narrow, and they matter more to search professionals than the headline does.

What Google actually has to share

The obligation sits in Article 6(11) of the DMA, which requires a gatekeeper to share anonymised ranking, query, click and view data with eligible online search engines on fair, reasonable and non-discriminatory terms. The Commission opened specification proceedings on 27 January 2026 and adopted the final decision on 16 July 2026, alongside a second decision on Android AI interoperability.

The principle the Commission set is straightforward: Google should share the data it itself collects and uses to optimise its own search services. In practice that means queries entered on any Google Search access point, query metadata such as language and device type, the URLs users viewed, the actions users took on results, and where each result sat in the ranking.

What comes out the other side is considerably thinner, because anonymisation is applied before anything leaves Alphabet.

Data element Shared with rivals How it is altered before sharing
Query text Yes Rare-term and unusually long queries suppressed entirely
Query metadata Yes Language and device type generalised into k-anonymous groups
URLs viewed Yes, organic only URLs for paid results removed from the dataset
Ranking position Yes Retained as the position of the result on the page
User interactions Yes Precise durations aggregated and replaced by time intervals
Location Generalised Grouped so at least 1,000 users share a location, device and language
Timestamps No Precise timestamps not provided
User accounts and search history No Direct identifiers and search histories removed outright

The three anonymisation steps the Commission specified are worth reading in order, because they explain the shape of the dataset a rival engine will actually work with. Step one turns the records into what the Commission calls a "haystack" of loose queries by stripping direct identifiers such as Google usernames and IP addresses, plus attributes like query timestamps and advanced filters, so queries cannot be readily attributed to the same user. Step two suppresses records containing rare terms, naming full names, usernames, passwords, street addresses and bank account numbers, or queries that are unusually long. Step three applies k-anonymity with a strict minimum group size of 1,000 users sharing the same location, device type and query language, and the Commission notes that 95% of users will sit in groups of at least 29,000.

The practical consequence: this is a dataset of common intent at scale, with the long tail deliberately cut off. Head and mid-tail behaviour, not the unusual query that a single person typed once.

The purpose limits are the story everyone missed

The measures do not just say who gets the data. They say what it may be used for, and the exclusions are specific.

Use case Permitted What the measures say
Improving query understanding Yes Includes spelling suggestions, related queries and autocomplete
Improving ranking and retrieval Yes Explicitly includes grounding, where AI chatbots fetch current web information
Improving indexing Yes Helps a rival work out which sites to prioritise crawling
Training general-purpose AI models No Named as an excluded use in the measures
Consumer profiling and advertising No Ruled out as unrelated to online search engine services
Systematically replicating Google's results No Beneficiaries must develop their own search technology

Read that table again if you have seen a headline claiming this decision hands Google's data to ChatGPT for training. It does not. An AI chatbot with a search function can use the data to make its retrieval and grounding better, which is a real and useful improvement, but it cannot pour it into a foundation model. The Commission drew the line at search technology.

That is also why the frame of "Google's advantage is over" is wrong. What the decision removes is one specific barrier, described by the Commission as the lack of search data at scale. Google keeps its algorithms; the measures explicitly do not require sharing algorithms or technology. And the shared dataset is a subset of what Alphabet collects, heavily altered.

Teresa Ribera, Executive Vice-President for Clean, Just and Competitive Transition, put the objective in these terms: "We need to keep that process fair and ensure that our citizens have choice. Our decision will help smaller competitors, search engines, or AI assistants, to compete and provide that choice, while protecting the user's privacy."

Almost nobody qualifies, and that is deliberate

The eligibility bar filters the field down to a small set of serious operators.

Criterion Threshold What it screens out
Track record Search engine services in the EU for the last two consecutive years New wrappers built on someone else's index
Funding alternative for new entrants Founded under two years ago with over €50 million in capital investments Undercapitalised startups without the means to handle the data
Scale At least 50,000 monthly average users in the EU over the past year Hobby projects and pre-launch products
Sanctions and control No EU restrictive measures; not controlled by a high-risk third country Entities the Commission treats as security risks
Data location Processing in the EEA, or transfers with essentially equivalent protection Pipelines that move EU search data to weaker regimes
Independent audit Passed before access, again within six months, then annually Applicants without the governance to keep the safeguards

Alphabet may also ask the Commission for an exemption from sharing with a specific undertaking on public security grounds under Article 10 DMA, and the Commission can grant one on its own initiative.

The audit requirement is the heaviest ongoing cost. A beneficiary must prove to a suitably qualified independent auditor that it complies with the specified safeguards before it ever receives data, then again within six months of starting processing, then annually. The Commission can also order ad hoc audits outside that window. Access is contractually ringfenced: no linking the search data to other datasets, no onward disclosure, no re-identification attempts, bounded retention, and documented governance.

The implementation calendar Alphabet is working to

Deadline What Alphabet must deliver Who reviews it
End August 2026 Eligibility application form; public webpage explaining beneficiary rights European Commission
September 2026 Template licence agreements, test data samples, cost items and estimates European Commission
November 2026 Finalised anonymised search dataset; technical information on latency and personal data detectors European Commission
January 2027 Final pricing offer communicated to the Commission and to third-party search engines Commission and applicants
Ongoing First compliance audit within six months of sharing, annually thereafter Independent auditors
Every two years Biennial review of the measures against practical experience European Commission

Three test samples arrive with the September 2026 milestone: a small real-data sample, a synthetic dataset, and a larger representative dataset. The first two can be accessed without an auditor's report. The larger representative sample requires an auditor's reasonable assurance report first, which is the point at which a serious applicant has to commit real money.

Pricing follows a cost-plus formula rather than a market rate. Alphabet may recover the incremental costs of preparing, storing and transmitting the data, plus a reasonable return on the capital strictly necessary to make it available, capped at Alphabet's weighted average cost of capital. An additional margin is possible in exceptional circumstances, capped at the operating margin of Alphabet's Google Search business, and it cannot be applied to micro, small or medium-sized enterprises. Each beneficiary pays a fixed component covering one-off costs and a variable component covering recurring ones.

What this actually changes for SEO teams

Here is the uncomfortable part. In the near term, almost nothing about how you optimise a page changes. The decision does not alter Google's ranking systems, does not create a new surface to optimise for, and does not hand you a new data source. You are not eligible for this data; only online search engines are.

What changes is the medium-term shape of the demand you are optimising against. Four effects are worth planning around.

Rival retrieval gets better before rival ranking does. Grounding is explicitly named as a permitted use, and grounding is the weakest link in most AI search products today. An assistant that fetches more relevant pages will cite more accurately. If your GEO work has been tuned to how one or two engines retrieve, expect the retrieval behaviour of the smaller ones to converge upward through 2027 and 2028.

Query understanding improves fastest of all. Spelling correction, related queries and autocomplete are the cheapest wins in the permitted list, and they are exactly what makes a small engine feel broken today. Long-tail phrasings that only Google currently resolves correctly will start resolving elsewhere.

The long tail stays a Google-only advantage. Rare-term and unusually long queries are suppressed from the shared dataset by design. If your traffic is concentrated in genuinely unusual phrasings, the data rivals receive will not teach them about it. That is a durable structural gap, not a temporary one, and it argues for the same targeting logic we have written about in our click-survivability framework for keyword selection.

Paid data stays out entirely. URLs for paid results are removed. Nothing in this decision helps a rival engine understand commercial intent the way Google's ads data does.

The honest read for a growth team: this is a slow-moving structural change to the competitive set, not a tactical shift. Budget for measuring more engines by 2028, not for rewriting your content strategy in 2027.

The measurement problem this creates

If four or five engines and chatbots become genuinely usable in the EU, single-source reporting stops describing reality. Most teams still run their entire visibility picture through Google Search Console plus one rank tracker.

Two practical steps hold up. First, start recording which assistant or engine sent a session now, before the traffic mix moves, so you have a baseline rather than a step change you cannot explain. Second, separate ranking from citation in your reporting, because they are already different outcomes and will diverge further as retrieval systems diverge. We covered the gap between the two in our analysis of ranking position versus AI Overview citation data, and the same split applies to any engine that grounds its answers.

For teams already running multi-engine visibility work, our platform playbook for ChatGPT, Perplexity and AI Overviews covers the reporting structure that survives a widening field.

Privacy: the part that stays uncomfortable

One detail in the Commission's Q&A deserves attention from anyone handling this data downstream. Anonymisation under Article 6(11) protects the person who typed the query. It does not remove personal data about people named inside queries. The Commission's own example: if a user searches for a footballer by name, the data to anonymise is not the name in the query, it is the personal data of the user who searched for it.

The consequence is that the shared dataset still contains personal data relating to third parties, and any search engine receiving it becomes a controller for that data under the GDPR. The technical measures were built with the draft joint guidelines from the Commission and the European Data Protection Board on the interaction between the DMA and the GDPR, and the Commission has kept the ability to reopen proceedings under Article 8(9) DMA if new facts, including independent evaluation of the anonymisation, change the picture.

India-specific considerations

The decision binds Alphabet under EU law and the dataset covers queries entered by end users in relation to Google Search in the European Union. Indian search behaviour is not in scope, and Indian businesses cannot apply for the data.

The relevance for Indian teams is competitive and structural. Indian SaaS and D2C companies selling into Europe should expect their EU visibility to spread across more engines from 2028 onward, which means EU-market reporting needs to stop assuming one engine well before the traffic actually moves. Agencies serving European clients from India will be asked about multi-engine visibility in pitches through 2027, and the answer "we track Google" will start to lose deals.

There is also a policy read. The DMA obligation applies to a gatekeeper designated under EU law, so a search or assistant product built for the Indian market gets no comparable data on-ramp from this decision. Whatever narrowing of the gap between an entrant and an incumbent this produces will happen in Europe first.

On data handling, any Indian company that processes EU search-derived data on behalf of a European client inherits the contractual conditions attached to it, including the ringfencing and the prohibition on linking it to other datasets. That sits alongside, not instead of, obligations under the Digital Personal Data Protection Act 2023 for Indian user data in the same systems.

FAQ

How eCorpIT can help

eCorpIT is a CMMI Level 5 certified technology organisation in Gurugram whose senior teams build and measure search and AI-search visibility for Indian and global clients. We help growth teams baseline multi-engine visibility before the traffic mix moves, separate ranking from citation in reporting, and build the content and structured data that survives when several grounding systems compete. If you sell into Europe and want a reporting picture that still works in 2028, look at our GEO and AEO optimisation work or talk to our team.

References

  1. European Commission, Alphabet specification proceedings: sharing of Google Search data (Questions and Answers), 16 July 2026.
  1. European Commission, Commission provides guidance to Google for AI interoperability on Android and sharing of Google Search data under the Digital Markets Act, 16 July 2026.
  1. Insight EU Monitoring, full text of Commission press release IP/26/1634, including next steps and the quotes from Teresa Ribera and Henna Virkkunen, 16 July 2026.
  1. European Commission, Alphabet specification proceedings: interoperability for AI services (Questions and Answers), 16 July 2026.
  1. European Commission, Commission opens specification proceedings to assist Google in complying with interoperability and online search data sharing obligations, 27 January 2026.
  1. European Union, Article 6(11), Regulation (EU) 2022/1925 (Digital Markets Act).
  1. European Commission and European Data Protection Board, consultation on joint guidelines on the interaction between the DMA and the GDPR.
  1. European Commission, DMA case DMA.100209 (Google Search data sharing) case record.
  1. European Commission, Commission finds Apple and Meta in breach of the Digital Markets Act, 23 April 2025.
  1. European Commission, Digital Markets Act gatekeepers portal and compliance reports.
  1. European Commission, DMA developer portal: data access.

Last updated: 23 July 2026.

Frequently asked

Quick answers.

01 When does Google have to start sharing Search data?
Google must start sharing search data with eligible search engine providers from January 2027. Before that, Alphabet must publish a beneficiary webpage and submit an eligibility application form by end August 2026, provide template licences and test samples by September 2026, and finalise the anonymised dataset by November 2026.
02 What data is included in the shared dataset?
Anonymised ranking, query, click and view data generated by end users in relation to free and paid search. That includes queries entered on any Google Search access point, query metadata such as language and device type, URLs users viewed, user interactions with results, and the position each result held in the results page.
03 Can AI chatbots receive Google's search data?
Yes. The Commission specified that AI chatbots offering search functionalities are eligible beneficiaries, correcting Alphabet's earlier proposal which excluded them. They must still meet the eligibility criteria and pass the independent audit, and they may only use the data to improve search services.
04 Can rivals use the data to train AI models?
No. The measures prohibit using the shared search data to train general-purpose AI models, to improve services unrelated to online search such as consumer profiling and advertising, or to systematically replicate Alphabet's search results. Permitted uses are query understanding, ranking and retrieval including grounding, and indexing.
05 Who qualifies to receive the data?
An applicant must provide online search engine services in the EU for at least two consecutive years, or be under two years old with more than 50 million euros in capital investments. It also needs at least 50,000 monthly average EU users over the past year, no EU sanctions, and an independent audit before access.
06 How is user privacy protected in the dataset?
Direct identifiers and search histories are removed, rare-term and unusually long queries are suppressed, timestamps and precise interaction durations are stripped or aggregated, and k-anonymity groups at least 1,000 users with the same location, device type and language. The Commission says 95% of users sit in groups of at least 29,000.
07 Does this change how I should do SEO right now?
Not directly. The decision does not alter Google's ranking systems or create a new optimisation surface, and marketers cannot receive the data. The medium-term effect is a wider set of usable engines and chatbots in the EU, which argues for baselining multi-engine reporting before the traffic mix shifts.
08 Why did the Commission intervene rather than accept Google's offer?
Alphabet's initial compliance proposal was removing between 90 and 100% of unique search queries from the dataset and excluding AI chatbots that provide search services, so there was no meaningful uptake by potential beneficiaries. After two years of talks, the Commission concluded specification was the fastest route to an effective dataset.

About the author

Manu Shukla

Founder & Director

Founder of eCorpIT. Hands-on engineer leading senior-only delivery for AI apps, custom software, and cloud systems for global clients.

Subscribe

One engineering note a week. No fluff, no spam.

Senior-architect playbooks on AI agents, mobile apps, cloud, security, data, and marketing — delivered every Wednesday.

Past the reading

Read enough. Let's build something.

A senior architect responds in 24 working hours with scope, indicative cost, and a timeline. NDA before any technical conversation.