The right to data portability in the GDPR and EU competition law: odd couple or dynamic duo?


Aysem Diker Vanberg [1] and Mehmet Bilal Ünver [2] [3]


The EU General Data Protection Regulation (GDPR) was published in the Official Journal of the European Union on 4 May 2016 [4] . It will become applicable on May 25, 2018. The GDPR comprises a new right to data portability for individuals, which requires data controllers to ensure that they can hand over the personal data that has been provided by the data subject himself/herself, in a structured, commonly used and transferable format.

This paper critically examines the right to data portability and suggests that in order to ensure comprehensive data portability that reaches out to all relevant stakeholders, including businesses, the provisions in the GDPR need to be analysed by taking into account EU competition rules. It suggests that lessons can be drawn from EU competition law to limit the potential adverse consequences of the right to data portability particularly for small and medium-sized enterprises. It also asserts that EU competition rules, especially Article 102 TFEU and the essential facilities doctrine, can complement data portability by facilitating mandatory access to specific data.

Keywords: The General Data Protection Regulation; article 20 of the GDPR; article 102 TFEU; data; data controller; the right to data portability; API; controller to controller transfer; competition law; essential facilities doctrine; network effects; Data Protection Directive


1. Introduction

On 25 January 2012, the Commission proposed a reform of the EU's data protection rules by drafting the General Data Protection Regulation (GDPR) in order to strengthen online data protection rights and boost Europe's digital economy. It was also done to adapt to technological advancements that had taken place in the previous decade, following the introduction of the Data Protection Directive [5] . The reactions to the GDPR have been mixed. Some scholars [6] saw it as a welcome development, however while others [7] have raised concerns.

The right to data portability in the GDPR will require businesses to ensure that they can hand over the personal data provided by an individual himself/herself in a usable and transferable format [8] . The preamble of the GDPR demonstrates that the right to data portability is not just limited to social networking sites but will also be applicable to cloud computing, web services, smartphone systems and other automated data processing systems [9] . The right to data portability will apply to a wide range of areas such as social media, search engines, photo storage, email or online shops. It will be equally applicable to banks, pharmaceutical companies, energy providers, airlines - even small businesses like pizza shops or tailors if they are data controllers.

The final text of the GDPR was agreed in the trilogue between the Council, Parliament and the European Commission on 15 December 2015, and published on 4 May 2016 in the Official Journal of the European Union [10] . After a two-year transition period, the GDPR will be binding on all member states from 25 May 2018.

The right to data portability is contained under Article 20 of the GDPR. It can be seen as an extension of an individual's right of access under Article 15 of the GDPR [11] . It has two key elements: the right of the data subject to obtain a copy of personal data from the data controller and the right to transfer that data from one data controller to another. The text limits the scope of the right to data portability to a great extent by adding that the controller would only transfer the data to another controller, where such a transfer is 'technically feasible'. As explained below this is quite problematic as the GDPR provides no explanation as to what is meant by technically feasible, which might give significant leeway to data controllers who may wish to not transfer the data to another data controller. Furthermore, another limitation of the right to data portability, is that it only applies to personal data provided by the data subject him/herself.

Article 20 of the GDPR addresses the issue of data portability specifically from the perspective of the individual users and is not concerned with the rights of businesses, in particular other service providers and competitors. Arguably, due to the importance of data portability not only for individual users but for all stakeholders concerned particularly for businesses, the provision in this form is not sufficient to ensure data portability across the board and needs to be supplemented by existing EU competition law provisions.

This paper critically examines the right to data portability under the GDPR to establish whether EU competition law can be useful to complement the gaps in the GDPR. It also examines whether there are lessons to be drawn from EU competition law. The paper is divided into five sections. Section 2 critically analyses the issues raised by Article 20 of the GDPR and potential enforcement problems. Section 3 discusses the application and suitability of EU competition rules, particularly the essential facilities doctrine in the data portability context. Section 4 analyses key cases pertaining to data portability and the use of personal data. Finally in Section 5, conclusions are drawn as to the future of the right to data portability.

2. Critical review of the right to data portability

2.1 Key issues in the GDPR

2.1.1 Limitations on data generated by the data controller

Article 20 of the GDPR only applies to data provided by the data subject himself/herself. The Article 29 Working Party published a summary of the discussions that took place on July 26, 2016, at the Fablab Workshop [12] . It gives a good overview of the key issues in relation to data portability. As pointed out in this document, the interpretation of data that has been provided by the data subject himself/herself requires clarification, as a narrow interpretation of this would result in fewer benefits for individuals whilst a wide interpretation of this concept would be a concern for data controllers [13] .

As mentioned by Graef et al, despite the lack of clarity, Article 20 of the GDPR will potentially not cover the transfer of data that has been generated by the service provider for statistical and analytical purposes such as online reputations [14] .

As Graef et al point out, [15] in an auction website like eBay the contact information and the advertisements are provided by the seller (data subject) himself but the provider adds feedback scores to the seller's profile and these form part of the reputation that a seller has built on. Hence, a literal interpretation of the adopted text would only allow the users to move their personal information to another auction site whilst not being able to move their ratings and reputation to another auction site as the latter is provided by the service provider. For an online user it is crucial to show that he/she has built a good reputation when he/she moves on to a different platform. Without moving this reputation, it is highly unlikely that the seller would attract new buyers in a new platform. Ultimately, this might hinder users from moving to another platform.

In the light of above it might be argued that the wording of the Article 20 of the GDPR limits the scope of the right to data portability to a great extent.

2.1.2 Privacy rights of third parties

Another limitation of the right to data portability concerns the privacy rights of third parties. If the data requested by the data subject concerns information pertaining to other individuals, then such a request can be denied by the data controller as it might adversely affect the rights and freedoms of others. As noted by Engels, allowing one user to transfer a second user's information to another platform may violate the privacy rights of a second user [16] . For example, when several people appear in a photograph on Facebook, even if one data subject wants to import it to another social networking platform, this cannot be done, as it would impact privacy and data portability rights of other individuals appearing in that picture. This implication seems to have been taken into account by the legislators as paragraph 4 of Article 20 GDPR states that the right to data shall not adversely affect the rights and freedoms of others'. This delimitation is likely to discourage users from invoking Article 20 of the GDPR.

2.1.3 Technical feasibility of data transfer

As mentioned above, another challenge for the enforcement of the right to data portability concerns the 'technical feasibility' sought for the data portability across the platforms. Arguably, what is technically feasible for one data controller might not be technically feasible for another data controller. Given the wording of Article 20(2) of the GDPR it is likely that some data controllers will contend that such a transfer is technically infeasible. As a result of this wording the transfer of data may be undermined and overlooked by data controllers. As there is no reference to the Commission's authority to specify the electronic format necessary for data portability in the GDPR, collaboration among market players is crucial in devising industry norms and standards.

2.1.4 Disproportionate costs and efforts

Forcing data controllers to transfer personal data may incur disproportionate costs and efforts.

Article 20 of the GDPR requires an online service to write specialised code (export-import module, (EIM)) that will export data from that service and import it to another service. As noted by Swire and Lagos, many small and medium-sized companies do not have the resources to fully understand the GDPR, comply with it and write an EIM to move data to another provider [17] .

Neither the Commission nor other EU institutions have presented any figures as to the cost of complying with data portability requests. According to a study by Christensen et al, the GDPR reform would increase European small and medium-sized enterprises' annual IT costs by between approximately € 3.000 and € 7.200 depending on the industry the particular SME is operating in, representing between 16 and 40 per cent of their yearly average IT budgets [18] . It is not clear what percentage of this budget will be spent responding to data portability requests.

Swire and Lagos also support this point and argue that the GDPR would impose substantial costs on suppliers of software and apps [19] .

Whilst such costs may not be significant for large companies, the requirement is likely to create problems for small and medium-sized companies. It must be noted that complying with the GDPR should not to be taken lightly due to the heavy fines associated with failing to do so. According to Article 83(5) of the GDPR, a data controller that fails to comply with data portability provisions in the GDPR will incur administrative fines up to 20 million EUR or in case of an undertaking up to 4 per cent of the total worldwide annual turnover of the preceding year, whichever is greater.

The issue of disproportionate costs was also raised in December 2015 by Baroness Neville Rolfe, the UK's parliamentary Under-Secretary of State for the Department for Business, Innovation and Skills. She stated that data portability rules designed to enable consumers to move their data from one platform to another should not be too costly as they can serve as an entry barrier into markets, and this might have an adverse effect on innovation and competition [20] .

2.1.5 Transfer of data may compromise valuable proprietary information and intellectual property

If the personal data that needs to be transferred comprise valuable proprietary information and intellectual property, this might discourage companies/service providers from creating the proprietary information in the first place.

The case of True Fit [21] , an online digital service helping users of online clothing retailers such as House of Fraser to find the right cloth sizes for their shoppers, illustrates this point. The True Fit service asks shoppers to share a wide range of personal data such as height, weight, measurements, body type - and information like what brand and size their favourite clothing come from. Users share this information with True Fit, which then shares it with online retailers. If True Fit were to be required under the data portability provision to transfer this data to other retailers, its business model would become obsolete.

Recital 63 of the GDPR provides that the general right of access under Article 15 could be restricted if it adversely affects the rights and freedoms of others, including trade secrets and intellectual property rights. As the right to data portability can be seen as an extension of the right of access, arguably the limitation mentioned in Recital 63 should be applicable in the context of data portability requests. In other words, when faced with data portability requests companies, should be able to strip valuable data from the dataset if it adversely affects trade secrets and intellectual property.

Nevertheless neither recital 68 of the GDPR pertaining to the limitations of the right to data portability, nor Article 20 of the GDPR specifically suggests that the right to data portability can be limited if it is adversely affects trade secrets and intellectual property. Hence there is a need for further clarification as to whether the right to data portability might be restricted when it affects proprietary information and intellectual property rights.

If companies like True Fit stop creating valuable services based on personal data this will clearly have a stifling effect on competition and innovative solutions. This would ultimately have an adverse effect on consumers who would be deprived of choice and useful products.

2.1.6 Enforcement issues pertaining to the right to data portability

As noted by the Article 29 Working Party, there is a need for guidance on how the right to data portability is going to be enforced [22] .

The main objective of the right to data portability is to empower consumers so that they can get a copy of their electronic personal data, demand transmission of their personal data to another provider and switch to other providers [23] . Hence, the objective of the right to data portability overlaps with the objectives of other areas of law, e.g. competition law, consumer protection laws and so forth.

Similar to other data subject rights in the GDPR, data portability is a right, which needs to be invoked by the data subject and cannot be relied upon by parties such as small and medium sized businesses. For instance, a small business cannot demand data portability from its business bank but an individual can. This raises some problems regarding its legal and theoretical boundaries, as well as enforcement within the realm enshrined by the GDPR.

Furthermore, there is no clarity as to whether users will make use of the right to data portability. In order to ensure that the right is invoked effectively by data subjects, data subjects need to be informed as to what this right entails. Hence, Article 29 Working Party and particularly the national data protection agencies should have information on their websites in plain and simple language explaining users how they can approach the data controller for data portability requests and advise them how to make a complaint if the data controller refuses to provide the data. Making a complaint should be relatively easy and the data subjects should not incur substantial costs as this might discourage them from exercising their right.

2.1.7 Privacy and Data security risks

Security and privacy concerns arise when data is transferred from one data controller to another. Data can end up in the wrong hands if access is granted to the wrong person - an investigator making a pretext call, a conman engaged in identity theft, a hacker, or, in some instances, one family member in conflict with another [24] . Ironically, interoperable solutions as suggested in the GDPR [25] could aggravate security concerns at the expense of uniform rules and processes in this context. Although not seen as the main cause of the security vulnerabilities, interoperability is regarded as one of the factors that increases the number of opportunities for security breaches and the potential fall-out from such breaches [26] . Particularly for small and medium sized businesses (SME) with limited resources to invest in data security, this is a significant concern.

3. Data portability in the context of EU competition rules

As noted by the former Commissioner for Competition Joaquin Almunia, data portability goes to the heart of competition policy as in a healthy competitive environment consumers can switch from one provider to another by taking their own data with them [27] . Data portability will indeed have a significant impact on avoiding consumer lock-in and switching costs. If switching from one service provider to another is too costly, the users of a service face a lock-in effect [28] . For instance, without data portability a consumer using Yahoo's email service might not want to move to Gmail due to the risk of losing invaluable personal data. This type of consumer lock-in could be seen as creating a more fragile marketplace, as it is open to exclusionary acts of dominant players. As such, the right to data portability needs to be considered also from a competition law viewpoint.

3.1 Relevance and applicability of EU competition rules to data portability

Data controllers that refuse to move data to another controller can be subject to Article 102 Treaty on the Functioning of the European Union (TFEU) [29] investigations for the abuse of a dominant position.

Article 102 TFEU prohibits the abuse of a dominant position. The provision contains two key elements, namely the notion of dominance and the abuse of this dominant position. In order to apply Article 102 TFEU, firstly the undertaking in question needs to be in a dominant position in the relevant product market. The Court of Justice of the European Union (CJEU) defines dominance as a 'position of economic strength enjoyed by an undertaking which enables it to prevent effective competition being maintained on the relevant market by giving it the power to behave to an appreciable extent independently of its competitors, customers and ultimately of its consumers' [30] . In the past, the Commission and the European Courts relied on market share as evidence of a dominant position, particularly if it persisted over time. The Court of Justice stated the following in Hoffman-La Roche [31] :

Although the importance of market shares may vary from one market to another the view may legitimately be taken that very large shares are in themselves, and save in exceptional circumstances, evidence of the existence of a dominant position. An undertaking which has a large market share and holds it for some time ... is by virtue of that share in a position of strength [32] .

As noted by the former Competition Commissioner Mario Monti, the Commission uses 'market definition and market shares as an easily available proxy for the measurement of market power enjoyed by the firms' [33] . As the Commission's Guidance Paper on Article 102 TFEU (hereinafter Guidance) [34] suggests, if the undertaking's market share is below 40 per cent, it is unlikely that the company would be held dominant in the relevant market. This demonstrates that undertakings with a market share of 40 and above are likely to be seen as a dominant undertaking by the European Commission. It must be noted that in technology intensive markets such as social networks, communication services, high market shares may not necessarily be indicative of market power. According to the Guidance [35] market shares only provide a useful first indication, but the Commission needs to interpret market shares in the light of market conditions and in particular dynamics of the market, and to the extent to which the products are differentiated. This is an important point to note as in technology markets over-reliance on market shares might lead to finding dominance too readily. In the recent Microsoft/Skype merger case [36] and Facebook/Whatsapp cases [37] the Commission acknowledged that market shares only provide a limited indication of competitive strength, particularly in consumer communications services due to the fast, dynamic nature of the industry as market shares can change quite rapidly within a short time.

In technology markets where new entrants are in a position to be innovative and compete effectively, it is acknowledged that temporary monopolies could be allowed to emerge with a view to targeting inter-platform competition. This is particularly true when incumbent firms get locked into a particular value network so that they are not able to innovate radically after establishing platform standards. Due to either a propensity to exploit their own installed base or a fear of cannibalising their existing products, or a commitment to established perceptions, the failure of incumbents to introduce radical innovations often creates an opening for a new entrant to introduce a rival information platform [38] . In such situations, market shares do not necessarily reflect the market power attributable to dominant players and their potential to exclude their competitors.

3.2 Types of abuse relevant to data portability

Dominance or having market power is not a problem as long as an undertaking does not take advantage of its market power, to abuse its market power. Abusive conduct under Article 102 TFEU can roughly be divided into two categories. The first category is 'exploitative abuse', which is conduct that consists of using market power to obtain extra gains from customers such as unfair purchasing and selling prices (Article 102(a)) and by limiting supply to markets (Article 102(b)). The second category is 'exclusionary abuse, which is conduct that attempts to exclude rivals as stated in Article 102(c) (discriminatory conduct) and in Article 102(d) (tie-ins) [39] . Exclusionary abuses are identified more often than exploitative ones [40] .

As the judgment in Continental Can [41] clarified, the list of abusive conduct stated in Article 102 TFEU is not exhaustive. Through case law, the Court of Justice of the European Union(CJEU) has expanded the list of abuses to include refusals to supply [42] , margin squeeze [43] , predatory pricing [44] and tying and bundling [45] . In light of the above, it can be argued that a refusal of a dominant firm to enable data portability might be seen as a form of exclusionary abuse as it might drive its competitors out of a specific relevant market and increase market concentration.

3.3 Access to data as an essential facility

3.3.1 The essential facilities doctrine

As mentioned above, Article 102 TFEU articulates only limited types of abuse of dominant position and amongst them no particular reference is made to refusal by a dominant undertaking to deal with a consumer or competitor in the downstream market. While such an abusive conduct might be related to or overlap with the abusive conducts under Article 102 (b) and (c) of the TFEU, most encountered types of 'refusal to deal' have a more distinctive nature, requiring a more characteristic scrutiny. 'Refusal to deal' has emerged as a distinct abusive conduct finding itself a separate place under the Guidance [46] as well as former decisions mostly associated with the essential facilities doctrine.

The essential facilities doctrine is often encountered in relation to refusal to supply (deal) cases and refusal to license cases. The doctrine of the essential facilities originates in US antitrust law [47] . It can be traced back to the United States v Terminal Railroad Association case of 1912 [48] . The term essential facility often comes into play where an undertaking seeks access to a physical infrastructure such as a port, airport, railway network or pipeline and when access to the physical infrastructure cannot be reasonably duplicated for technical, legal or economic reasons [49] . In this regard, an obligation regarding 'duty to deal' or 'duty to share essential facilities' arises only if the competitor cannot obtain the goods and services in question elsewhere and cannot build or invent them itself, and unless the facility owner has legitimate business justification for the refusal [50] .

Hence, the 'essentiality' is the most controversial problem in the applicability of the essential facilities doctrine, which adds some difficulties to the traditional 'dominant position' test [51] . The doctrine might also be useful for technology markets and in network industries where a company controls crucial intellectual property or holds data. Hence, it might be argued that if the personal data held by a company is crucial to facilitate market access for other players in a specific industry such as online social networks, online search and online advertising the doctrine of essential facilities might be relevant.

In the EU, the essential facilities doctrine was developed much later than in the US by the application of Article 102 TFEU.

In the seminal case of Oscar Bronner, [52] the Court of Justice clarified its position as regards to a new competitor's access to an essential facility. Oscar Bronner was the publisher of a small daily newspaper which accounted for 3.6 per cent of the Austrian daily newspaper market [53] and was enjoying steady growth in new subscriptions and advertisement revenues [54] . On the other hand, Mediaprint was the publisher of two newspapers which together enjoyed 46.8 per cent market share in the Austrian daily newspaper market [55] . Bronner sought access to Mediaprint's established delivery scheme. When Mediaprint refused, Bronner filed a complaint before Austrian courts seeking an order requiring it to grant access to its delivery scheme for a reasonable payment [56] . The national court referred its preliminary questions to the CJEU.

The CJEU held that provided Mediaprint was found to have a dominant position in the nationwide delivery schemes market and its refusal could amount to an abuse if it satisfied the following criteria cumulatively:

i) First, refusal was likely to eliminate all competition in the daily newspaper market,

ii) Second, the service must be indispensable for carrying on the entrant's business in that there is no actual or potential substitutes for such delivery,

iii) Third, the refusal must not be objectively justified [57] .

Furthermore, in Bronner, the CJEU contended that a product and service is indispensable only if there are no alternative products or services and there are technical, economic or legal obstacles which make it impossible or unreasonable for an undertaking seeking to operate on the downstream market to develop products or services [58] .

The Bronner judgment reflects the highest threshold pertinent to the essential facilities doctrine in EU law. Following Bronner, in Magill [59] , IMS Health [60] and Microsoft case [61] the CJEU concluded that in order to grant mandatory access, the claimant needs to prove that the data or input requested is essential for the appearance of a new product and there is no other way to obtain or create it [62] .

3.3.2 The intersection of the essential facilities doctrine and data portability

The collection and analysis of user data, including information about the behaviour and preferences of users, enable platforms to optimise the user experience [63] . This drives customer satisfaction and loyalty as customers are prone to use platforms that offer a more personalised experience.

In applying the essential facilities doctrine to the context of data portability, it can be argued that if a dominant company holds specific data that are indispensable for other undertakings to enter a new market, and the dominant company's refusal to transfer that data eliminates all potential competition, then, in the absence of objective justifications, Article 102 TFEU could be relied on. Thus EU competition law emerges as a potential instrument for enforcing data portability objectives in the European Union in an effective way.

While no case involving the essential facilities doctrine and data portability has yet emerged in the EU, in the US, the courts have refused to give mandatory access to specific databases, particularly after the Trinko decision [64] which limited the use of essential facilities doctrine to a great extent.

The LiveUniverse, Inc. v. MySpace, Inc. [65] case related to one Social Networking Service (SNS) (MySpace) blocking a user of another SNS (LiveUniverse) from incorporating content from the second SNS's website called vidiLife into their MySpace profile. MySpace's deletion of all references to vidiLife and preventing its users from incorporating any kinds of such extensions was claimed by LiveUniverse to be contrary to US antitrust law. The District Court dismissed the alleged claims of exclusionary conduct, referring to the lack of a duty to deal which according to the Court requires existence of a voluntary agreement as defined in Supreme Court's Trinko decision (Verizon Communications Inc. v. Law Offices of Curtis V Trinko, LLP) . The District Court's dismissal as upheld by the Ninth Circuit affirmed Myspace's freedom of product design as well as its right to deal within the meaning of Section 2 of the Sherman Act [66] .

Facebook v. Power Ventures Inc. [67] related to Power Ventures' attempt to extract data (all kinds of social networking contacts of users) from SNS platforms including Facebook and display them on its own platform called In the face of Facebook preventing such an attempt and suing Power Ventures for breach of its terms of service, Power Ventures filed a counter case against Facebook based on exclusionary conduct [68] . However, Power Ventures' claims were not affirmed by the District Court which considered lack of interoperability outside the scope of Section 2 liability, referring to Facebook's 'right to manage access to and use of its website' [69] .

In PeopleBrowsr v. Twitter [70] , the dispute stemmed from PeopleBrowsr asking Twitter to grant it (full firehose) access to Twitter data to be able to offer analytics services and being denied this request. PeopleBrowsr filed a case with the claims based on private law and California's unfair competition law gave a result of a 'temporary restraining order' imposed on Twitter [71] . Twitter attempted to carry on the case at the federal (antitrust) level but this failed [72] . The parties eventually settled the case by agreeing that PeopleBrowsr could continue full firehose access until 2013 [73] . As the case ended with a settlement, it is unclear whether Twitter would have been obliged to give PeopleBrowsr full access to its data under US federal or state antitrust law.

US antitrust law and principles, particularly after the Trinko decision [74] , took a divergent path from mandatory access obligations, whether through the essential facilities doctrine or other tools (e.g. intent test, market leverage). Thus, proving the 'indispensability' or 'essentiality' of the requested input often poses the main difficulty for the plaintiffs to overcome. This is more persuasive in the ICT markets which reveal temporary monopolies within the sense of 'destructive' or in other words 'Schumpeterian' innovations. Less dependence on the incumbent platforms, reduction of total costs (e.g. thanks to the simplification of network architecture and capacity increases), and applicability of enhanced software applications by service providers may make economies of scale achievable and bottlenecks less relevant in the Internet ecosystem.

Platforms such as Google may prove to represent a counter thesis to this. The quality of search results and the targeting of advertising using Google Search relies to a large extent on personal data - i.e. the user's previous searches and search behaviour using the search engine - and also data shared through other services on the same platform such as Google Photos (with e.g. location data), Gmail (with email text analysis), Google Maps (travel data) and YouTube (interest data). Arguably Google's possession of this data amounts to a significant competitive advantage, one of such magnitude that it cannot realistically be replicated by other players in the market, even by digital giants such as Apple or Microsoft with their significant resources.

The portability of users' search histories and search behaviours in particular lies at the heart of this, and clearly at the intersection of both data and competition laws. It is worth noting that Google user search history can already be exported using Google Takeout. However it is not clear how many users make use of this opportunity. Arguably, users are uninterested in pure data export, as it is a complex and time-consuming process, with inherent uncertainty, as the data transferred may not be utilised by other data controllers due to technical and architectural constraints. In this respect, controller-to-controller data portability is crucial to safeguard the right to data portability - and thereby effective competition in platform based markets. The success of the GDPR in the context of data portability and platforms such as Google may rest on the ability to enforce effective controller-to-controller portability rather than simple export functionality.

As mentioned above, in the EU there has not been any precedent in which access to a database of personal data was seen as essential for the operation of a particular service where it would be commercially impossible for a competitor to operate without that personal data. Given the stringent nature of the essential facilities doctrine, it would be relatively difficult for an undertaking to demonstrate why they cannot develop their own database of personal information without access to the dominant competitor's data. However, as the below case law demonstrates, given the willingness of the European Commission and national competition authorities to take a closer look at markets that collect and process personal data, it is likely that there will be cases where refusal to give access to a specific data set could be considered an essential facility.

4. Analysis of competition cases relating to data portability and the use of personal data

4.1 Google case

An important case involving data portability is the pending competition investigation into Google.

In February 2010, several vertical search engines, such as Foundem, Ciao and (a French legal search engine) filed a complaint before the European Commission. These three complaints focused on abuse of dominance: that Google used its dominant search engine and its 'Universal Search Service' [75] to promote its own services whilst discriminating as well as demoting the search rankings of competing websites and other vertical search engines among its unpaid and paid search results [76] . In addition to its natural (organic) search results, Google also operates vertical search services which offer a specific search function for a category of products such as services and information. According to rival vertical search engines, Google prioritises its own vertical search services such as Google News and Google Shopping at the expense of its rivals' vertical search engines.

In addition to the first complaint in relation to Google's alleged prioritisation of its own services, in the scope of its investigation the European Commission is also investigating the following:

  1. Whether Google has imposed exclusivity obligations on advertising partners, hindering them from placing certain types of competing adverts on their websites, as well as on computer and software vendors with the aim of foreclosing competition for competing search tools,
  2. Whether Google has restricted the portability of online advertising data to competing online advertising platforms and
  3. Whether Google uses third party content, mainly websites whose content competes with its offerings whilst reducing competitors' incentives to invest in creating original content, to the detriment of consumers [77] .

As of April 2016, the Commission is also investigating whether Google is abusing its dominant position on the mobile devices market by imposing restrictions on Android device manufacturers and mobile network operators [78] .

For the purpose of this paper, attention will only be paid to Google restricting the portability of data from its AdWords platform to other competing online advertising platforms. The Commission is concerned that Google imposes contractual restrictions on software developers which prevent them from offering tools that would enable the seamless transfer of search advertising campaigns across Google's AdWords to other search advertising platforms [79] . In other words, according to the Commission, Google needs to refrain from exclusionary contracts which hinder data portability. Needless to say, such restriction is likely to lock-in advertisers to Google's online advertising platform and have an adverse effect on other online advertising platforms such as Bing's advertising platform. As the costs of recreating an online advertising campaign are high, most small and medium-sized companies will only use Google's AdWords platform. As a result, other advertising platforms are likely to be excluded from the online advertising market.

In order to resolve the competition law concerns concerning data portability, Google proposed that it would cease any written or unwritten obligations in its AdWords API terms and conditions that hindered advertisers from transferring and managing search advertising campaigns from Google's AdWords to other competing search advertisement services. On 14 July 2016, the Commission initiated antitrust proceedings against Google [80] . It is not clear whether the above remedy proposed by Google in relation to data portability will be considered an effective remedy.

It should be noted that Google was subject to a relatively similar antitrust investigation in the United States by the Federal Trade Commission (FTC) where in relation to the data portability concerns Google agreed to further facilitate the portability of AdWords data across other search platforms. However, as pointed out by Heiner, the FTC did not seek any feedback as to the effectiveness of this remedy, hence it remains to be seen whether the proposed remedy by Google will be sufficient to allow the smooth transfer of data from Google's AdWords platform to other advertising platforms [81] .

The Google case demonstrates the importance of the EU Commission in facilitating data portability in order to avoid consumer lock-in in concentrated markets such as online advertising and online search. As discussed earlier, Google, as a search engine, posses a vast amount of personal data such as user search history, search results and search behaviours, which enables it to deliver relevant and high quality search results. Arguably, by not sharing this data with its competitors Google prevents other search engines such as Bing from effectively competing with it. As suggested by Lianos and Motchenkova, if Google were to share search results with its competitors, this may enable its competitors to provide search results of at least similar degree of relevance to the consumers' questions [82] .

The Google case also illustrates that restrictions on data portability may qualify as an abuse of dominance under Article 102 TFEU(b) if it can proved that the dominant company limit markets and technical development to the prejudice of consumers [83] .

Finally, this case is significant as it clearly shows that Article 102 TFEU can expand the scope of the right to data portability under the GDPR by looking after the interest of businesses which normally cannot take advantage of the right to data portability under the GDPR.

4.2 Facebook

Another interesting, recent case is a German case that concerns Facebook. On May 2016, the Bundeskartellamt, the German competition authority, started investigating whether Facebook abuses its dominant position on social networks in the German market. The Bundeskartellamt alleged that Facebook's terms and conditions of service regarding how it makes use of user's personal data may amount to abuse of dominance in the social networking market [84] . Like any online service, in order to use Facebook consumers need to agree to its terms and conditions prior to using its services. According to the Bundeskartellamt, Facebook is allegedly imposing unfair trading terms on consumers contrary to Article 102 TFEU as consumers are not in a position to understand the scope and amount of data captured by the company for advertising and other purposes. Arguably, this can be seen as an exploitative abuse under Article 102(a) if it can be established that Facebook uses its market power to obtain extra gains from online users who are not in a strong position to negotiate the terms and conditions of Facebook's service.

Andreas Mundt, President of the Bundeskartellamt, stated the following on the case:

Dominant companies are subject to special obligations. These include the use of adequate terms of service as far as these are relevant to the market. For advertising-financed Internet services such as Facebook, user data are hugely important. For this reason it is essential to also examine under the aspect of abuse of market power whether the consumers are sufficiently informed about the type and extent of data collected. [85]

This was the first case in the EU where a dominant company was subject to a competition probe for allegedly infringing data protection laws. It must be noted that in January 2016 the European Competition Commissioner Margrethe Vestager stated that dominant technology platforms that harvest vast amounts of data might be considered in breach of EU competition rules if they are using this data to drive their competitors out of the market [86] . The Commissioner pointed out that if a dominant company's use of data was bad for competition, thus potentially outweighing any benefits to customers such as reduced costs, the Commission could step in to restore a level playing field [87] .

The Facebook case and the above statement of the Competition Commissioner demonstrate the interplay between data protection laws and competition law and how failure to comply with the relevant provisions of the GDPR, including the right to data portability, is likely to trigger competition law probes at EU level and in several EU member states. It is possible that in the future, online platforms such as Google, Facebook, Amazon, Apple which harvest a vast amount of personal data might be subject to competition investigations if they fail to comply with the GDPR, providing that such failure has an adverse effect on consumers and/or hinders market entry for potential competitors.

5. Conclusion

The right to data portability is no doubt a key concern for online users as well as for companies that wish to have a level playing field. Businesses cannot resort to Article 20 of the GDPR as the right to data portability is only available to living and identifiable individuals. Nevertheless, EU competition law and particularly Article 102 TFEU can be used to enforce data portability across platforms, thus filling this gap in the GDPR.

This article finds that the right to data portability under Article 20 of the GDPR might not deliver the intended results due to its ambiguity and due to the inherent limitations contained therein such as the rights and freedoms of other data subjects. As noted in Section 2, in its current form the right to data portability may create disproportionate costs for small and medium sized enterprises, compromise valuable proprietary information and intellectual property rights and lead to privacy and security breaches. In order to alleviate these concerns, the Article 29 Working Party should provide concrete guidelines explaining how to interpret key terms in Article 20 of the GDPR, such as what is meant by technically feasible, what is meant by data provided by the data subject himself/herself, as well as clarifying the delimitations of the right to data portability. Clear guidelines may encourage industry players to introduce solutions based on commonly accepted practices such as well documented APIs or de facto data standards and/or protocols, thus enabling controller to controller data transfer.

This article also points out that in order to ensure an effective right to data portability, the transfer of data from one controller to another is far more significant than the transfer of data from a controller to an individual, as such manual export and import of data could be well beyond the average user's technical ability and there is no clarity as to whether the exported data can be used by another data controller. Thus, the forthcoming guidelines should concentrate on how to strengthen and encourage controller-to-controller data portability. In this regard, further research is needed to determine whether users would prefer controller-to-controller data transfer and how such transfer could be made simple and technically feasible, such as by clicking a button or by following a few simple steps.

As discussed under Section 3 and Section 4, the main difference between the GDPR and competition rules is that EU competition rules only apply to dominant service providers whilst the rules contained in the GDPR can be enforced against all data controllers irrespective or their size and market shares. The right to data portability has many implications such as facilitating market access, preventing high switching costs and alleviating network effects that threaten potential competition in a marketplace. These implications necessitate this individual right to be analysed in the context of competition law rules and precedents. As Section 3 and Section 4 highlights, EU competition rules, particularly Article 102 TFEU, and the essential facilities doctrine can offer sensible solutions by enforcing mandatory data portability, where the data owned by an incumbent is necessary for the appearance of a new product or service and there is no other possibility for another competitor to obtain the data to perform its services and compete with the dominant undertaking.

In order to ensure legal certainty with regard to data portability, the Article 29 Working Group, the European Data Protection Supervisor, and the Data Protection agencies in the member states should assist the data controllers in their compliance efforts. Arguably, in limiting the potential harmful impact of the data portability provision for small and medium-sized enterprises some lessons can be drawn from EU competition law. As explained above, Article 102 TFEU only applies to dominant companies with significant market power. In a similar vein, the European Merger Regulation [88] is only applicable to mergers with a community dimension and where the undertakings have a significant turnover [89] . Perhaps, in order to alleviate the potentially harmful impacts of the right to data portability on small and medium-sized enterprises, undertakings with a limited market share or with an insignificant turnover can be exempted from data portability requirements.

In order to have effective data portability within the EU that covers all stakeholders, including users and businesses, the implementation of the GDPR must be in harmony with competition law and other relevant legislation such as consumer protection laws. This will require cooperation between the relevant competition authorities, the European Data Protection Supervisor, national data protection agencies and sector-specific regulatory authorities where necessary.

