Skip to main content
Should Privacy Teams Report to Antitrust Counsel?Supervisory Authorities & Enforcement
4 min readFor Legal & Compliance Teams

Should Privacy Teams Report to Antitrust Counsel?

The question at hand

Your data protection officer just got a request from the competition law team. They want access to your data retention schedules, legitimate interests assessments, and consent management records. They're preparing for a potential market investigation and believe your privacy documentation could strengthen their position on user choice and data portability.

This scenario isn't hypothetical. As enforcement converges, organizations face a practical question: should privacy and antitrust functions operate separately, or is formal integration now necessary?

The European Commission's legislative push targeting Big Tech market dominance, along with Amazon's $888 million GDPR fine, signals that supervisory authorities and competition regulators are increasingly collaborating. Your organizational structure needs to reflect this reality.

The case for keeping them separate

Privacy officers argue that merging these functions dilutes focus. Article 39 of the GDPR assigns specific monitoring and advisory duties to the DPO role. Adding competition law obligations creates role confusion and potentially compromises the independence that Article 38(3) requires.

There's also a methodological mismatch. Privacy compliance focuses on individual rights, transparency, and lawful basis assessments. Competition enforcement examines market power, consumer harm, and barriers to entry. A controller processing health data under Article 9 follows different risk logic than a competition team evaluating whether bundled services constitute tying arrangements.

Resource constraints are another concern. Most privacy teams are already stretched managing DSARs, conducting data protection impact assessments, and maintaining records of processing activities under Article 30. Asking them to also track market share implications of data practices means neither function gets adequate attention.

Legal privilege matters too. In some jurisdictions, communications with in-house competition counsel receive stronger protection than privacy team correspondence. Blurring these lines could inadvertently waive privilege over sensitive strategic discussions.

The case for formal integration

The counterargument is that regulatory reality has already forced convergence, whether your org chart reflects it or not. When supervisory authorities evaluate whether your consent mechanism meets Article 7 requirements, they're also asking if it creates lock-in effects that harm competition. Treating these as separate compliance exercises means you're answering the same question twice with potentially inconsistent responses.

Consider legitimate interests assessments. Article 6(1)(f) requires you to balance your interests against data subject rights and freedoms. Competition regulators increasingly view that same legitimate interests assessment through a market lens: does your data processing create barriers that prevent competitors from offering similar services? If your privacy team conducts the assessment without competition input, you risk building a lawful basis that later becomes evidence of anticompetitive conduct.

Data portability under Article 20 illustrates the overlap. Your privacy team implements technical measures to fulfill portability requests. Your competition team worries about interoperability requirements and whether your data formats create switching costs. These aren't parallel workstreams; they're the same compliance obligation viewed from different regulatory angles.

Practitioners favoring integration argue that dual reporting creates accountability. When your DPO and competition counsel jointly review a new data processing activity, you're less likely to design systems that satisfy privacy law on paper but create competition concerns in practice. The Amazon fine demonstrates what happens when scale and market dominance amplify privacy violations; organizations with integrated compliance frameworks spot those risks earlier.

Where practitioners actually land

Most organizations haven't restructured reporting lines, but they've created informal coordination mechanisms. Privacy teams now routinely loop in competition counsel when evaluating processing activities that involve:

  • Cross-service data combination or profiling that could raise tying concerns
  • Consent mechanisms for platform services where users have limited alternatives
  • Data sharing arrangements with third parties that might foreclose market access
  • Retention periods that could entrench market position

The practical middle ground involves joint governance checkpoints rather than merged teams. When you're drafting a legitimate interests assessment for a new analytics use case, competition counsel reviews the market impact section. When you're responding to a supervisory authority inquiry about your consent implementation, your privacy team coordinates the response but competition counsel reviews for statements that could later complicate merger clearance or abuse of dominance investigations.

Documentation practices are converging too. Controllers are increasingly maintaining a single register that maps processing activities to both GDPR lawful bases and competition law implications. This doesn't mean your DPO reports to your general counsel's antitrust group, but it does mean your records of processing activities under Article 30 now include fields for market impact notes.

Our take

The regulatory trend is clear: supervisory authorities and competition regulators are coordinating. Your compliance structure should follow.

But formal reporting line integration creates more problems than it solves. The DPO role works because of its independence and narrow mandate. Diluting that with competition responsibilities weakens both functions.

The better approach is structured collaboration with clear trigger points. Define which processing activities require joint review, establish regular coordination meetings, and build competition impact assessment into your data protection impact assessment template for high-risk processing.

Your privacy team shouldn't report to antitrust counsel. But if they're not talking regularly, you're building compliance gaps that enforcement convergence will eventually expose. The question isn't whether to integrate these functions; it's how to coordinate them without compromising the independence and focus each role requires.

You Might Also Like