On this page · 11 sections
- What Google actually has to share
- The purpose limits are the story everyone missed
- Almost nobody qualifies, and that is deliberate
- The implementation calendar Alphabet is working to
- What this actually changes for SEO teams
- The measurement problem this creates
- Privacy: the part that stays uncomfortable
- India-specific considerations
- FAQ
- How eCorpIT can help
- References
Summary. On 16 July 2026 the European Commission adopted a binding specification decision requiring Google to share anonymised ranking, query, click and view data with eligible rival search engines, including AI chatbots that offer search. Sharing starts in January 2027. The Commission stepped in because Alphabet's own compliance offer had been "removing between 90 and 100% of unique search queries from the dataset" and excluding AI chatbots entirely, which produced no meaningful uptake after two years of talks. Google Search has held more than 90% market share in Europe for decades. The bar to receive the data is high: a rival must have run a search engine in the EU for two consecutive years or, if younger, have raised more than €50 million, and must show at least 50,000 monthly average users in the EU over the past year. The anonymisation floor is k-anonymity of 1,000 users per group, with 95% of users in groups of at least 29,000. Data arrives with a minimum seven-day latency and access is capped at five years per beneficiary.
Most coverage of this decision has framed it as Google being forced to hand its search advantage to ChatGPT. That is not what the measures say. The purpose limits are narrow, and they matter more to search professionals than the headline does.
What Google actually has to share
The obligation sits in Article 6(11) of the DMA, which requires a gatekeeper to share anonymised ranking, query, click and view data with eligible online search engines on fair, reasonable and non-discriminatory terms. The Commission opened specification proceedings on 27 January 2026 and adopted the final decision on 16 July 2026, alongside a second decision on Android AI interoperability.
The principle the Commission set is straightforward: Google should share the data it itself collects and uses to optimise its own search services. In practice that means queries entered on any Google Search access point, query metadata such as language and device type, the URLs users viewed, the actions users took on results, and where each result sat in the ranking.
What comes out the other side is considerably thinner, because anonymisation is applied before anything leaves Alphabet.
| Data element | Shared with rivals | How it is altered before sharing |
|---|---|---|
| Query text | Yes | Rare-term and unusually long queries suppressed entirely |
| Query metadata | Yes | Language and device type generalised into k-anonymous groups |
| URLs viewed | Yes, organic only | URLs for paid results removed from the dataset |
| Ranking position | Yes | Retained as the position of the result on the page |
| User interactions | Yes | Precise durations aggregated and replaced by time intervals |
| Location | Generalised | Grouped so at least 1,000 users share a location, device and language |
| Timestamps | No | Precise timestamps not provided |
| User accounts and search history | No | Direct identifiers and search histories removed outright |
The three anonymisation steps the Commission specified are worth reading in order, because they explain the shape of the dataset a rival engine will actually work with. Step one turns the records into what the Commission calls a "haystack" of loose queries by stripping direct identifiers such as Google usernames and IP addresses, plus attributes like query timestamps and advanced filters, so queries cannot be readily attributed to the same user. Step two suppresses records containing rare terms, naming full names, usernames, passwords, street addresses and bank account numbers, or queries that are unusually long. Step three applies k-anonymity with a strict minimum group size of 1,000 users sharing the same location, device type and query language, and the Commission notes that 95% of users will sit in groups of at least 29,000.
The practical consequence: this is a dataset of common intent at scale, with the long tail deliberately cut off. Head and mid-tail behaviour, not the unusual query that a single person typed once.
The purpose limits are the story everyone missed
The measures do not just say who gets the data. They say what it may be used for, and the exclusions are specific.
| Use case | Permitted | What the measures say |
|---|---|---|
| Improving query understanding | Yes | Includes spelling suggestions, related queries and autocomplete |
| Improving ranking and retrieval | Yes | Explicitly includes grounding, where AI chatbots fetch current web information |
| Improving indexing | Yes | Helps a rival work out which sites to prioritise crawling |
| Training general-purpose AI models | No | Named as an excluded use in the measures |
| Consumer profiling and advertising | No | Ruled out as unrelated to online search engine services |
| Systematically replicating Google's results | No | Beneficiaries must develop their own search technology |
Read that table again if you have seen a headline claiming this decision hands Google's data to ChatGPT for training. It does not. An AI chatbot with a search function can use the data to make its retrieval and grounding better, which is a real and useful improvement, but it cannot pour it into a foundation model. The Commission drew the line at search technology.
That is also why the frame of "Google's advantage is over" is wrong. What the decision removes is one specific barrier, described by the Commission as the lack of search data at scale. Google keeps its algorithms; the measures explicitly do not require sharing algorithms or technology. And the shared dataset is a subset of what Alphabet collects, heavily altered.
Teresa Ribera, Executive Vice-President for Clean, Just and Competitive Transition, put the objective in these terms: "We need to keep that process fair and ensure that our citizens have choice. Our decision will help smaller competitors, search engines, or AI assistants, to compete and provide that choice, while protecting the user's privacy."
Almost nobody qualifies, and that is deliberate
The eligibility bar filters the field down to a small set of serious operators.
| Criterion | Threshold | What it screens out |
|---|---|---|
| Track record | Search engine services in the EU for the last two consecutive years | New wrappers built on someone else's index |
| Funding alternative for new entrants | Founded under two years ago with over €50 million in capital investments | Undercapitalised startups without the means to handle the data |
| Scale | At least 50,000 monthly average users in the EU over the past year | Hobby projects and pre-launch products |
| Sanctions and control | No EU restrictive measures; not controlled by a high-risk third country | Entities the Commission treats as security risks |
| Data location | Processing in the EEA, or transfers with essentially equivalent protection | Pipelines that move EU search data to weaker regimes |
| Independent audit | Passed before access, again within six months, then annually | Applicants without the governance to keep the safeguards |
Alphabet may also ask the Commission for an exemption from sharing with a specific undertaking on public security grounds under Article 10 DMA, and the Commission can grant one on its own initiative.
The audit requirement is the heaviest ongoing cost. A beneficiary must prove to a suitably qualified independent auditor that it complies with the specified safeguards before it ever receives data, then again within six months of starting processing, then annually. The Commission can also order ad hoc audits outside that window. Access is contractually ringfenced: no linking the search data to other datasets, no onward disclosure, no re-identification attempts, bounded retention, and documented governance.
The implementation calendar Alphabet is working to
| Deadline | What Alphabet must deliver | Who reviews it |
|---|---|---|
| End August 2026 | Eligibility application form; public webpage explaining beneficiary rights | European Commission |
| September 2026 | Template licence agreements, test data samples, cost items and estimates | European Commission |
| November 2026 | Finalised anonymised search dataset; technical information on latency and personal data detectors | European Commission |
| January 2027 | Final pricing offer communicated to the Commission and to third-party search engines | Commission and applicants |
| Ongoing | First compliance audit within six months of sharing, annually thereafter | Independent auditors |
| Every two years | Biennial review of the measures against practical experience | European Commission |
Three test samples arrive with the September 2026 milestone: a small real-data sample, a synthetic dataset, and a larger representative dataset. The first two can be accessed without an auditor's report. The larger representative sample requires an auditor's reasonable assurance report first, which is the point at which a serious applicant has to commit real money.
Pricing follows a cost-plus formula rather than a market rate. Alphabet may recover the incremental costs of preparing, storing and transmitting the data, plus a reasonable return on the capital strictly necessary to make it available, capped at Alphabet's weighted average cost of capital. An additional margin is possible in exceptional circumstances, capped at the operating margin of Alphabet's Google Search business, and it cannot be applied to micro, small or medium-sized enterprises. Each beneficiary pays a fixed component covering one-off costs and a variable component covering recurring ones.
What this actually changes for SEO teams
Here is the uncomfortable part. In the near term, almost nothing about how you optimise a page changes. The decision does not alter Google's ranking systems, does not create a new surface to optimise for, and does not hand you a new data source. You are not eligible for this data; only online search engines are.
What changes is the medium-term shape of the demand you are optimising against. Four effects are worth planning around.
Rival retrieval gets better before rival ranking does. Grounding is explicitly named as a permitted use, and grounding is the weakest link in most AI search products today. An assistant that fetches more relevant pages will cite more accurately. If your GEO work has been tuned to how one or two engines retrieve, expect the retrieval behaviour of the smaller ones to converge upward through 2027 and 2028.
Query understanding improves fastest of all. Spelling correction, related queries and autocomplete are the cheapest wins in the permitted list, and they are exactly what makes a small engine feel broken today. Long-tail phrasings that only Google currently resolves correctly will start resolving elsewhere.
The long tail stays a Google-only advantage. Rare-term and unusually long queries are suppressed from the shared dataset by design. If your traffic is concentrated in genuinely unusual phrasings, the data rivals receive will not teach them about it. That is a durable structural gap, not a temporary one, and it argues for the same targeting logic we have written about in our click-survivability framework for keyword selection.
Paid data stays out entirely. URLs for paid results are removed. Nothing in this decision helps a rival engine understand commercial intent the way Google's ads data does.
The honest read for a growth team: this is a slow-moving structural change to the competitive set, not a tactical shift. Budget for measuring more engines by 2028, not for rewriting your content strategy in 2027.
The measurement problem this creates
If four or five engines and chatbots become genuinely usable in the EU, single-source reporting stops describing reality. Most teams still run their entire visibility picture through Google Search Console plus one rank tracker.
Two practical steps hold up. First, start recording which assistant or engine sent a session now, before the traffic mix moves, so you have a baseline rather than a step change you cannot explain. Second, separate ranking from citation in your reporting, because they are already different outcomes and will diverge further as retrieval systems diverge. We covered the gap between the two in our analysis of ranking position versus AI Overview citation data, and the same split applies to any engine that grounds its answers.
For teams already running multi-engine visibility work, our platform playbook for ChatGPT, Perplexity and AI Overviews covers the reporting structure that survives a widening field.
Privacy: the part that stays uncomfortable
One detail in the Commission's Q&A deserves attention from anyone handling this data downstream. Anonymisation under Article 6(11) protects the person who typed the query. It does not remove personal data about people named inside queries. The Commission's own example: if a user searches for a footballer by name, the data to anonymise is not the name in the query, it is the personal data of the user who searched for it.
The consequence is that the shared dataset still contains personal data relating to third parties, and any search engine receiving it becomes a controller for that data under the GDPR. The technical measures were built with the draft joint guidelines from the Commission and the European Data Protection Board on the interaction between the DMA and the GDPR, and the Commission has kept the ability to reopen proceedings under Article 8(9) DMA if new facts, including independent evaluation of the anonymisation, change the picture.
India-specific considerations
The decision binds Alphabet under EU law and the dataset covers queries entered by end users in relation to Google Search in the European Union. Indian search behaviour is not in scope, and Indian businesses cannot apply for the data.
The relevance for Indian teams is competitive and structural. Indian SaaS and D2C companies selling into Europe should expect their EU visibility to spread across more engines from 2028 onward, which means EU-market reporting needs to stop assuming one engine well before the traffic actually moves. Agencies serving European clients from India will be asked about multi-engine visibility in pitches through 2027, and the answer "we track Google" will start to lose deals.
There is also a policy read. The DMA obligation applies to a gatekeeper designated under EU law, so a search or assistant product built for the Indian market gets no comparable data on-ramp from this decision. Whatever narrowing of the gap between an entrant and an incumbent this produces will happen in Europe first.
On data handling, any Indian company that processes EU search-derived data on behalf of a European client inherits the contractual conditions attached to it, including the ringfencing and the prohibition on linking it to other datasets. That sits alongside, not instead of, obligations under the Digital Personal Data Protection Act 2023 for Indian user data in the same systems.
FAQ
How eCorpIT can help
eCorpIT is a CMMI Level 5 certified technology organisation in Gurugram whose senior teams build and measure search and AI-search visibility for Indian and global clients. We help growth teams baseline multi-engine visibility before the traffic mix moves, separate ranking from citation in reporting, and build the content and structured data that survives when several grounding systems compete. If you sell into Europe and want a reporting picture that still works in 2028, look at our GEO and AEO optimisation work or talk to our team.
References
- European Commission, Alphabet specification proceedings: sharing of Google Search data (Questions and Answers), 16 July 2026.
- European Commission, Commission provides guidance to Google for AI interoperability on Android and sharing of Google Search data under the Digital Markets Act, 16 July 2026.
- Insight EU Monitoring, full text of Commission press release IP/26/1634, including next steps and the quotes from Teresa Ribera and Henna Virkkunen, 16 July 2026.
- European Commission, Alphabet specification proceedings: interoperability for AI services (Questions and Answers), 16 July 2026.
- European Commission, Commission opens specification proceedings to assist Google in complying with interoperability and online search data sharing obligations, 27 January 2026.
- European Union, Article 6(11), Regulation (EU) 2022/1925 (Digital Markets Act).
- European Commission and European Data Protection Board, consultation on joint guidelines on the interaction between the DMA and the GDPR.
- European Commission, DMA case DMA.100209 (Google Search data sharing) case record.
- European Commission, Commission finds Apple and Meta in breach of the Digital Markets Act, 23 April 2025.
- European Commission, Digital Markets Act gatekeepers portal and compliance reports.
- European Commission, DMA developer portal: data access.
Last updated: 23 July 2026.