Interoperability, Privacy, and the Limits of the Digital Markets Act
Interoperability, Privacy, and the Limits of the Digital Markets Act
Big Tech's walled gardens can keep users locked in through switching costs rather than superior service. While the EU's Digital Markets Act is forcing platforms open, interoperability creates its own privacy and security trade-offs that need careful handling.
- Tech giants spend billions keeping data within one ecosystem, and traditional antitrust tools built around price and output struggle to address this.
- A lack of competitive pressure can let platforms get away with poor practices like tracking and behavioural advertising.
- Under the DMA, the largest platforms now have to let rival companies plug into certain features that used to be theirs alone, from casting and device integration to letting people use non-default app stores.
- But there remain significant privacy challenges, and regulators and users alike need to stay alert to whose interests get served in that process.
Technology giants like Apple, Meta, Google, and Microsoft spend billions of dollars to keep you in their walled gardens.
The more data that is kept within one ecosystem, the harder it is to move to another, and the more challenging it is for an upstart to break into the fray
Someone who has bought all their apps on Apple’s App Store is less likely to swap to Google’s Android or Microsoft Windows. Similarly, someone with all their friends on Facebook will not have the same experience on TikTok or X.
The result is a set of digital fiefdoms where the cost of switching keeps users loyal, in a way that means these companies can rely on their existing reach to maintain their dominance.
Competition was more prevalent in the past - Facebook had MySpace and Google+, while AOL and MSN faced off against Messenger and Discord. But as these companies grew, they have been able to purchase their competitors in the case of Facebook and Instagram or exist in controlled harmony, such as one Apple employee telling a Google worker that “our vision is that we work as if we are one company.”
These services are rarely paid for in cash, but rather in the abstract value of a user’s network. As such, traditional antitrust laws which rely on the “consumer welfare standard,” - which focuses on raised prices or restricted outputs - are difficult to levy against tech platforms that offer free services.
But tight integration can be beneficial for security and privacy, provided those are qualities a company values. The data is kept within one ecosystem, after all.
Apple’s control over its hardware, software, and services, for example, means that there are fewer avenues for third-parties to break its privacy promises. This remains true with regards to recent updates about Apple’s integration with Google Gemini. Apple is renting compute capacity from Google to run parts of its AI systems, but this does not provide Google with information about user data, because users will either be interacting with Apple’s on-device models, or with Apple’s Private Cloud Compute servers, which keep user data separate from Google’s infrastructure.
As such, Apple’s control of the software and verification layer that sits on top of the hardware keeps the underlying processing and traffic cryptographically inaccessible to third-party owners of the machine.
On the other hand, a lack of competition can give companies carte blanche to implement poor practices for privacy, such as tracking and behavioural advertising, because they know the consumers have few other places to go.
The challenge is how to solve the harms of market dominance with measures that respect and protect privacy.
The arguments
Some digital rights groups and competition regulators tend to back interoperability as a way to break the deadlock of network effects. On the other hand, the platforms, and some security researchers, warn that opening up walled gardens can introduce privacy and security risks of its own.
We think both concerns are legitimate - which is why the detail of how interoperability is done matters as much as whether it is done at all. The situation is not uniform across all contexts and technologies. And certain cases - such as encrypted messaging - call for particular caution.
The case for interoperability rests on the claim that switching costs, not superior service, are often what keeps users in place.
Groups like the Electronic Frontier Foundation (EFF) frames it as dismantling the basic bind facing anyone who wants to leave a platform - having to choose between moving on at the expense of abandoning their network. In their view, “a well-crafted interoperability mandate should be a net benefit for privacy. Architects of new interoperability policy will have the opportunity to establish guardrails on the specific data-sharing pathways that policy creates”.
Open Rights Group (ORG) makes a similar case against complacency: once a platform reaches critical mass, users become effectively locked in, and interoperability is one of the few tools that can redistribute that power back toward users - though ORG is careful to note it isn’t a single fix, and its costs and benefits vary case by case.
The counter-argument is that interoperability does produce a number of risks. While it may be able to reduce switching costs, it also raises the probability of data breaches. Ross Anderson and Jenny Blessing highlight that interoperability requires an increased trust from users, due to the increased number of providers that can now interoperate with a service. This covers a number of technological necessities, such as authentic key handovers, content moderation, and the maintainance of secure software. A vulnerability in one interoperable system could result in vulnerabilities in others.
Alec Muffett, an internet security expert and software engineer, also posits that the “the whole point of a platform is to be a walled garden”, using the example of a Snapchat data breach sourced from a third-party interoperable service as a way that interoperability could increase security issues. Muffet also argues that opening up walled gardens exposes existing metadata to a wider range of third-party clients, creating a richer surveillance surface.
Clearly, any legislation needs rules robust enough to keep firms investing in security and keep people’s confidence in their products. Stringent application and enforcement of data protection laws is also a necessity. The potential harms on both sides are real and diverse, and navigating between them needs care.
The EU’s response
The European Union’s Digital Markets Act (DMA) has begun to mandate interoperability, identifying the largest platforms as “gatekeepers” and requiring them to open up to competitors in certain ways.
Introduced in 2022 and mandatory since 2024, the DMA is the EU’s flagship attempt to break this kind of lock-in across digital markets. In practice, this means gatekeepers must let rivals plug into some features they currently keep to themselves - from media casting, NFC and AI integration to, in the case of WhatsApp and Messenger, messaging itself.
“Interoperability” under the DMA is covered by several obligations: Article 6(7) requires gatekeepers to give third parties access to the same operating system, hardware, and software features that the gatekeeper makes available to its own services, though this provision does not prevent designated gatekeepers from taking necessary measures to ensure that interoperability does not compromise the integrity of the operating system, virtual assistant, hardware or software features. Article 6(4) covers installation of non-gatekeeper apps and app stores. Again, gatekeepers can take proportionate and justified measures to protect security and integrity.
Article 7 is a separate, narrower obligation specific to messaging (formally, “number-independent interpersonal communications services”), requiring designated gatekeepers to open up to smaller messaging platforms on request. The obligation is limited to a defined set of “basic functionalities”, including one-to-one text messaging, and sharing of images, voice messages, videos and files.
The Article also requires that the gatekeeper’s existing level of security, including end-to-end encryption, be preserved across the interoperable service, and gatekeepers must publish a “reference offer” setting out the technical terms on which they will interoperate.
The DMA itself hasn’t escaped criticism, including from the companies it targets. Apple, for example, has argued that forced interoperability could be weaponised by data-hungry rivals, pointing to more than a dozen requests from Meta for access deep enough - in Apple’s telling - to let it read a user’s messages and emails, see their calls, track their app use, and log their passwords.
Interoperability in action
We’ve already seen movement towards interoperability with regards to app stores and social networks.
Historically, Apple’s App Store has been the only way to install software on the iPhone, with paid software having to give 30% of in-app purchases to Apple. Only recently has Apple allowed external payment links.
Moreover, iOS has recently allowed third-party app stores on the platform — though this remains an EU-only change, enacted under DMA compliance, and does not apply to users outside that area. This is a step toward increased competition, but that could be taken further through other means such as Progressive Web Apps.
This could allow privacy-focused apps, which cannot monetise the data from their users as easily, to have a greater advantage. Since more private apps are structurally less able to rely on advertising or data-sale revenue — a “pay for privacy” model of the app ecosystem — they are disproportionately dependent on the commission-bearing side of the App Store such as subscriptions and one-time purchases.
Lower- or zero-commission alternatives remove or reduce that structural cost, narrowing the gap between what a privacy-respecting app and its ad-funded equivalent may keep from the same revenue.
Google, meanwhile, has long-allowed “sideloading” - the process of installing software or apps onto a device from sources outside the manufacturer’s official app store - and a range of third-party app stores on Android.
On the one hand, a controlled app environment allows the provider to vet for dangerous apps, including but not limited to those that trick users into installing it, or affect the user’s system in unexpected ways - such as collecting or transmiting private information without the user’s knowledge.
On the other, it also gives the providers the ability to remove applications from its stores at the behest of governments, which could limit the freedom and privacy-protecting intentions of both developers and users.
Recently, Google is now asking all developers to register identification details such as their legal name, physical address, phone number, and government ID which, as other organisations have argued, raises questions about how developers working on privacy-preserving or politically sensitive applications will be affected.
With regards to social media, the “network effect” can be a powerful lock-in effect. Many users do not stay on Facebook because they prefer Facebook, but because a lot of their social circle, and their data, is tied up in the platform.
Interoperability could open that lock, allowing users to migrate to platforms without disappearing from their communities. We’ve already seen this with tools like ActivityPub, allowing comments from one platform to be visible on another.
Why secure messaging is different
Providing interoperability across messaging platforms in particular is a difficult problem to solve because of the specificities regarding how they are built.
Encrypted messaging platforms like Signal, WhatsApp, and iMessage rely on an unbroken chain of trust between sender and recipient. Interoperability, done carelessly, risks breaking that chain by requiring messages to be decrypted and re-encrypted somewhere along the way.
One option is for competitors to adopt the same underlying protocol as the gatekeeper — as WhatsApp does with the Signal Protocol — which preserves end-to-end encryption without needing to decrypt messages in transit.
But shared encryption does not guarantee compatibility on issues such as identifiers, blocking and reporting tools, and group administration. These all vary by platform and are not covered by the protocol itself.
The more common approach is bridging: software that decrypts messages and re-encrypts them for another platform.
Some bridges do this on a server, which breaks end-to-end encryption and creates a potential target for surveillance, while others use the user’s own device. This preserves the encryption guarantee but requires people to actively seek out and install extra software, and is arguably closer to “integration” than interoperability.
Moreover, metadata issues and other privacy concerns still persist. WhatsApp collects substantial metadata — who a user messages, when, and how often — regardless of content encryption. But Signal does not - it uses a feature called Sealed Sender, meaning that even the server relaying a message doesn’t know who sent it. A system that bridges to or interoperates with a metadata-hungry platform like WhatsApp may still inherit its exposure. Interoperability proposals that focus entirely on content encryption risk missing this point.
Where this leaves the debate
While pushes for interoperability may be achievable in a privacy-preserving way, the technical groundwork must come first. Nowhere is this clearer than with messaging apps.
Interoperability built on open, auditable protocols - where every participant in the chain can be verified - is categorically different from interoperability bolted onto systems that were not designed for it.
Moreover, there is a reasonable concern that interoperability standards will be shaped by incumbents in ways that favour their existing architectures — locking in Meta’s metadata-heavy model as the baseline, rather than the more privacy-preserving approach taken by Signal, for example.
As such, regulators should be alert to the possibility that companies with the most to lose from reforms set the standard for how smaller, more vulnerable players must interoperate with them. They must be able to see which direction companies are pulling in: whether their standard is good for users, or good for themselves.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.