AI-Portable
Article image for The DMA Should Not Undercut Security & Privacy for Europeans Articles
Not Applicable

The DMA Should Not Undercut Security & Privacy for Europeans

Google warns that recent EU Digital Markets Act rulings could expose Europeans’ private searches to unfamiliar companies and weaken device security by forcing Android to grant sensitive permissions to external apps without adequate safeguards.

Condensed by AI-Portable from Editorial queue.

In a sharp public warning, Google’s president of global affairs cautions that the European Commission’s latest decisions under the Digital Markets Act (DMA) may seriously erode the privacy and security protections that millions of Europeans currently enjoy. The company says it has repeatedly proposed workable solutions that would meet the DMA’s market-opening goals without sacrificing user safety, but those offers were dismissed despite what it calls “extensive evidence of user harm.”

Android Permissions and the Breakdown of a Trusted Screening Model

At the heart of the dispute is how Android handles sensitive device capabilities. Today, AI assistants and other services can safely access Android functions because phone makers play a critical role in vetting those apps before they ever reach a device. This pre-installation screening process acts as a first line of defense against malware, data leaks, and abusive permissions. The DMA rulings, however, would force Android to grant external apps the same powerful permissions without any of these safeguards. An app from an unknown developer could suddenly gain deep access to system functions, bypassing the security checks that manufacturers have built into the platform over years. Google underscores that this is happening just as the EU’s own cybersecurity agency, ENISA, warns that “security fundamentals matter more than ever in the age of AI.”

Private Searches Exposed Without Anonymisation or Consent

A particularly acute concern is the handling of Europeans’ private searches. Under the new rules, search data could be routed to unfamiliar third‑party companies without proper anonymisation and without the user’s knowledge or explicit consent. Google warns that this would:

  • Weaken citizen privacy, as intimate search queries—health, finance, personal interests—would be exposed in raw form.
  • Risk business trade secrets, since employees’ research activities could be intercepted by competitors or hostile actors.
  • Endanger national security, as sensitive government‑related searches might fall into the wrong hands without any oversight.

The lack of anonymisation is the crux: today, even when search data is shared with partners, robust de‑identification processes protect individuals. The DMA’s implementation, as currently framed, could dismantle those protections overnight.

A Plea for Evidence‑Based Adjustments

Google acknowledges that the Commission’s decision itself recognises the need for “a flexible, evidence‑based process” to account for significant harms and to adjust measures accordingly. The company says it will continue to advocate for a balanced approach—one that preserves the privacy and security foundations that Europeans expect while still supporting the DMA’s goal of fostering competition. The underlying message is clear: opening up digital markets should not come at the cost of exposing millions of people to avoidable cyber risks and privacy violations.

Original source ↗