Vision

The Cyber Security Act in practice: the duty of care, ISO certification and the role of the board

On 23 March, the House of Representatives (Tweede Kamer) discussed the Cyber Security Act (Cyberbeveiligingswet; “Cbw”), the Dutch implementation of the Network and Information Security Directive (EU 2022/2555; “NIS2 Directive”). The aim is still to introduce the Act this quarter.  The hack on Odido and the recent hack at Ajax demonstrate that securing your information systems is not a luxury, but a necessity to prevent incidents. In the Odido hack, many people’s personal data was published on the dark web. This personal data can be used to send phishing emails, place orders or take out subscriptions in your name, or attempt to take over your bank account. Such cyber incidents can be prevented with robust cybersecurity. That is why, in this blog, we are focusing on the duty of care under the Cbw.

Various authorities have now shared information about the Cbw, such as the National Cyber Security Centre (Nationaal Cyber Security Centrum; “NCSC”) and the National Inspectorate for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur; “RDI”), which will act as the supervisory authority for many parties under the Cbw. The government therefore advises organisations to start implementing the rules set out in the Cbw now, as the risks of cyber incidents are already present.

Duty of care

One of the obligations under the Cbw is the duty of care set out in Article 21 of the Cbw. The duty of care under the Cbw means that essential and important entities must take appropriate and proportionate technical and organisational measures. Compliance with the duty of care is monitored by the designated supervisory authorities, including by requiring entities to document in writing what the entity does following a notification from the supervisory authority, the Computer Security Incident Response Team (“CSIRT”) or another government body.

The Cbw sets out a number of minimum measures to fulfil the duty of care:

  • Policy on risk analysis and the security of information systems
  • Incident handling
  • Business continuity, such as backup management, recovery plans and crisis management
  • Supply chain security, including security-related aspects concerning the relationships between the entity and its direct suppliers or service providers
  • Basic cyber hygiene practices and cybersecurity training
  • Security in the procurement, development and maintenance of network and information systems, including the response to and disclosure of vulnerabilities
  • Security aspects relating to personnel, access policies and asset management
  • Where appropriate, the use of multi-factor authentication or continuous authentication solutions, secure voice, video and text communications, and secure emergency communications systems within the entity
  • Policies and procedures regarding the use of cryptography and, where applicable, encryption
  • Policies and procedures to assess the effectiveness of measures for managing cybersecurity risks.

The NCSC in the Netherlands has now developed a number of guidance documents on its website that can assist with the implementation of these measures.

ISO certification as a tool for compliance

Another tool for implementing the Cbw are the ISO 27001 standards. ISO 27001 is the international standard for information security. ISO certification demonstrates that an organisation’s information security is well protected. An ISO certificate can support NIS2 compliance. Partly for this reason, both the European Union Agency for Cybersecurity (ENISA) and the Government Information Security Baseline have produced a table comparing the ISO standards with the Cbw. The Government Information Security Baseline contains basic standards for information security within the public sector (central government, local authorities, water boards and provincial authorities). ENISA is responsible for cybersecurity in Europe. Various measures, such as multi-factor authentication or incident response, fall under the ISO 27001 standards and are mandatory under the duty of care of the Cbw. Holding ISO 27001 certification can therefore help in meeting the obligations under NIS2, but is not sufficient to comply with the obligations under NIS2.

Greater responsibility for the board

Whereas the ISO standards only set requirements for the technology and its organisation, the Cbw also imposes requirements on an entity’s management. As described in a previous blog, Article 24 of the Cbw stipulates that directors bear ultimate responsibility for compliance with the Cbw obligations. The NIS2 does not address the definition of ‘management’. In the explanatory memorandum to the Cbw, the definition of ‘management’ is linked to the Digital Operational Resilience Act (‘DORA’), a regulation aimed at enhancing the digital resilience of financial institutions. It is inferred from this regulation that ‘management’ is understood to mean:

  • The day-to-day management and not a supervisory body (such as a supervisory board)
  • And in the case of a one-tier board, the executive directors and not the non-executive directors.

In the case of legal entities, ‘management’ is therefore the standard term used in Book 2 of the Dutch Civil Code (Burgerlijk Wetboek; “BW”). The duty of care under Article 24 of the Cbw therefore rests with the board of , a legal entity within the meaning of Book 2 of the BW. In line with this, the explanatory memorandum refers to the duties of the board of a public limited company (N.V.) and a private limited company (B.V.) under Articles 2:129 and 2:239 of the BW respectively.

Liability of the de facto manager under the General Administrative Law Act

In addition to directors, other natural persons may also be held liable for breaches of obligations under the Cbw. This concerns persons who, although they are not directors, in fact take the decisions and exercise control over compliance with the obligations under the Cbw. This liability is therefore not limited to directors, but may also apply to other persons within an organisation. NIS2 does not specify how this liability should be structured. In the Netherlands, this is addressed through administrative law enforcement, to which the General Administrative Law Act (Algemene wet bestuursrecht; “Awb”) applies. Under Article 5:1 of the Awb, if a legal person commits an offence, the person who ordered the act or the person who actually exercised control may also be subject to a sanction, such as an administrative fine. This is subject to the condition that the doctrine of actual control within the meaning of the Awb is satisfied.

Conclusion

The duty of care under the Cbw brings significant new obligations and responsibilities for directors of entities subject to the legislation. ISO standards can provide support in meeting the technical and organisational measures required by the Cbw.

For more information about the obligations that apply to directors and how to protect your organisation and position, please contact Machteld Robichon or Bente van Kan.

With thanks to Maartje Nelemans

Also read our other blogs:

Vision

Competition and Regulation of the Energy Transition

By 2050, the Netherlands aims to use only energy from renewable sources. The transition from fossil fuels to renewable energy sources is therefore a prominent topic in political debate and policy. This has already led to various changes in regulations and an increasingly active role for the Netherlands Authority for Consumers and Markets (Autoriteit Consument & Markt, ACM”) in this area. As the competition authority and regulator of the energy market, the ACM has recently (once again) placed the energy transition at the top of its agenda for 2026.

In order to steer the energy transition in the right direction and accelerate where possible, ACM’s supervision covers a wide range of topics. From tariff methods to consumer protection and from algorithmic trading to heat networks. The recent policy document ‘Focus on Energy 2026’ shows that the ACM will focus primarily on accelerating the transition, establishing supply security (including resilience) and ensuring affordability for consumers.

In this blog, we discuss a small selection of ACM’s broader energy supervision activities, focusing on the frameworks for network congestion, the development of hydrogen infrastructure, and enforcement of the REMIT Regulation. Finally, we will briefly discuss the application of more traditional competition law framework to sustainability collaborations between (energy) companies.

New energy legislation

Due to the many developments at national and European level in the field of sustainable and renewable energy, the new Energy Act (Energiewet) came into force in the Netherlands on 1 January 2026. The Energy Act implements Directive 2024/1711 of the European Parliament and of the Council of 13 June 2024 (amending Directives 2018/2001 and 2019/944 as regards improving the Union’s electricity market design). The reform of the European energy market (Electricity Market Design) is part of the well-known European Green Deal. The new Dutch legislation combines the old Gas Act (Gaswet) and the Electricity Act 1998 (Elektrictiteitswet 1998) and has as one of its objectives ‘the transition to a cleaner, reliable, secure and affordable energy supply’. It therefore contains new rules for, among other things, stronger consumer protection, improving the right to energy sharing, more efficient use of the transport network, a system for data exchange and protection of the wholesale energy market.

Congestion measures

The required transition from fossil fuels to electricity (to achieve abovementioned objectives) will logically lead to an increase in electricity consumption. At the same time, more and more sustainable (but less controllable) energy is being generated. These developments are putting increasing pressure on the electricity grid (referred to as ‘systems’ in the new Energy Act), which in some cases can lead to a capacity shortage. This shortage is referred to as ‘congestion’ and has consequences for both the consumption and generation of electricity.

Based on the (former) Electricity Act and the (current) Energy Act, the ACM has the authority to draw up rules for the energy market, known as codes. ACM has used this authority to adopt the ‘Netcode electricity’ (Netcode elektriciteit), which includes various congestion measures to promote flexibility.

Flexible contracts

Due to shortage in the electricity systems, the ACM has been looking for ways to make better use of the grid. In its overview and insight into congestion measures, updated in July 2025, the ACM discusses various options for alternative transport rights. This means that a connected party can choose to no longer have the right to access the system at all times.

The ACM has created various options in the Code Decision on Non-Firm Connection and Transport Agreements (Codebesluit non-firm aansluit- en transportovereenkomst, “ATO”), including a fully variable transport right, a time-limited transport right (85% of the year’s transport rights) and a timeslot-limited transport right (access to the grid on pre-agreed days). An existing connected party can also enter into a capacity restriction contract with the network operator. In such an agreement, the connected party agrees to temporarily make no or only limited use of the contracted capacity in exchange for compensation. This also frees up additional space on the system for other users.

To ensure that congestion measures are actually used more frequently, the ACM has instructed system operators to draw up improvement plans that provide better insight into network usage. System operators and (organisations representing) system users have also recently signed an agreement on a new regulatory method. The ACM believes that by removing legal disputes about the method, it will be possible to focus more effectively on implementing the necessary measures.

Furthermore, the ACM says it will take decisions in 2026 on time-dependent network tariffs (on regional grids) and is still investigating how companies that have battery systems (which can purchase extra power or feed it back at peak times) or electrolysers (which convert surplus power into hydrogen) can contribute to more efficient use of the grid, and what discounts/rewards should be offered in return.

Forms of energy sharing

Congestion can also be reduced by sharing a grid connection. In December 2025, the ACM introduced the possibility for large consumers to enter into a group transport agreement with other large consumers. In this agreement, they can distribute the supply and demand of transport capacity. This local coordination means that the group requires less capacity overall, reducing the pressure on the grid.

Another option that the ACM considers suitable is so-called ‘cable pooling’. In these instances, two or more connected parties located in close proximity to each other share a physical connection, which makes it more efficient. This option was developed primarily in view of combining a solar park and a wind farm (as complementary generators) with a battery and/or a consumer. In order to make use of this scheme, the cable poolers must submit an application to the relevant system operator and conclude an agreement. The ACM must then be notified of the shared connection.

Finally, last year, the ACM published a paper on opportunities in relation to energy sharing. Energy sharing is the simultaneous consumption of electricity by ‘energy receivers’ at the moment that ‘energy providers’ generate sustainable electricity (and does not consume it themselves). This will require an agreement to be concluded in which the tariff is determined by mutual agreement. Energy sharing can take place within an energy community or other group of consumers (neighbours). Energy sharing is becoming a right that must be facilitated by energy suppliers and system operators.

Right to a (new) connection

In principle, Article 23 of the Electricity Act 1998 stipulates that a system operator is obligated to provide anyone who requests it with a connection to the electricity grid within a reasonable period of time. At least one connection must be provided for each immovable property. In practice, however, (rapid) access to the system is no longer a given. Due to increasing congestion and an overloaded grid, the ACM has therefore drawn up new rules regarding the granting of connections. In the event of congestion, for example, the system operator has more flexibility with regard to the connection period for large users. In 2026, the ACM will also decide on (longer) connection periods for small users.

Because new connections can no longer be issued instantly, new applications end up on a waiting list. This poses a problem when essential businesses need a new connection. That is why the ACM has drawn up a social priority framework on the basis of which businesses can be given priority. The Trade and Industry Appeals Tribunal (College van Beroep voor het bedrijfsleven) recently ruled on the ‘Code Decision on Priority Space’. In its ruling, the Tribunal found that the ACM has the authority to draw up this priority framework and that this is also important in view of congestion problems, but that the ACM should further investigate and justify which party is given priority.

Hydrogen

In addition to traditional energy systems, (sustainable) hydrogen will play an important role in achieving the climate targets for 2050, particularly as a fuel for transport and for heating buildings as a replacement for natural gas. Because of the important role that (blue and green) hydrogen can play in achieving climate targets, the European Parliament and the Council have drawn up directives to ensure the proper functioning of the internal Jmarkets for natural gas and hydrogen. Directive (EU) 2024/1788 on common rules for the internal markets for renewable gases, natural gas and hydrogen states, among other things, that it is important for hydrogen users to have the same rights as natural gas customers and that unnecessary barriers to the market must be removed.

This idea is now also enshrined in Dutch legislation: the new Energy Act explicitly applies to hydrogen (which was not the case in the old Gas Act). An important change is that the Energy Act imposes an obligation on the transmission system operator to allow hydrogen into the gas network, provided that certain conditions are met.

Despite the high expectations for green hydrogen in the energy transition, major developments are lagging behind due to uncertainties on both the demand and supply sides of the hydrogen market. Uncertainties about volumes, prices and infrastructure mean that making large investments remains risky. The ACM emphasises the need for clear government regulation to stimulate the hydrogen market and has recently responded to this by drawing up policy on third-party access and tariff regulation.

Third-party access to hydrogen terminals

Potential users must be able to access the capacity of a hydrogen terminal on the basis of objective, transparent and non-discriminatory conditions, in accordance with European regulations. The ACM has developed a system for negotiated third-party access. It is therefore up to the hydrogen terminal operator and (potential) users to make agreements among themselves, whereby users must in principle be treated equally, albeit that objective justifications may exist for agreeing on more favourable conditions for a launching customer (an initial customer who has played an important role in the development of the infrastructure). Rules for third-party access can contribute to the possibility of scaling up the market, and to investment security. The ACM stated that it will provide further clarity on third-party access with follow-up publications in 2026.

Tariff regulation

The ACM is also investigating various regulatory instruments to prevent high hydrogen network tariffs. For example, European regulations offer the possibility of spreading the recovery of hydrogen transport network costs over time (intertemporal cost allocation), so that future users contribute to the initial costs. European legislation also allows for a temporary cross-subsidy whereby an additional levy is charged to users of gas transport networks in order to reduce hydrogen tariffs.

In 2026, the ACM will draw up an in-depth paper detailing the tariff regulation for hydrogen. It may make specific choices in this paper on how efficient costs should be distributed over time (e.g. by adjusting depreciation methods or the WACC system) and about the tariff structure, such as the distribution of costs between importers and customers (e.g. a 50/50 or 40/60 split), between location-independent versus distance-based tariffs, and between capacity or volume tariffs.

Finally, the ACM intends to present its vision on the regulation of CO2 transport and CCS (carbon capture, transport and storage) in the second half of this year.

Wholesale markets: REMIT

The ACM has recently stepped up its supervision of the wholesale markets for electricity and gas. This supervision is based on the Regulation on Wholesale Energy Market Integrity and Transparency (REMIT). Throughout the year, ACM publishes updates on indicators of its supervisory work under this Regulation. These show that ACM received 17 signals of possible prohibited trading in the first half of 2025 (similar to the previous period). Most of the signals related to possible market manipulation, such as marking the close, layering/spoofing, off-market orders, erroneous orders, capacity hoarding, quote stuffing, and wash trades.

The ACM can intervene with a warning or a fine. A year ago, for example, an international market participant was warned because of indications of market manipulation. This involved trading behaviour known as marking the close. This means that a market participant influences the reference price on the market by deliberately buying or selling just before the closing price is set, causing the price to shoot up. Contracts that were concluded earlier are then settled at this artificially inflated closing price.

The ACM also sees an active role for itself in 2026 in continuing to steer honest, transparent and increasing cross-border trade on the wholesale energy markets in the right direction. For example, the ACM has announced that it will take action if there are signs of market abuse, such as frustrating fair price formation or failing to disclose inside information or doing so late. When prioritising between the various signals, the ACM explicitly considers the impact of the behaviour on the energy transition.

Furthermore, ACM has the authority to request information regarding algorithmic trading from companies that use it. Algorithmic trading is increasingly being used as the generation of renewable energy sources is less predictable for traders. This increases the risks of, for example, algorithmic collusion or market manipulation. In 2025, the ACM investigated whether adequate systems are being used for algorithmic trading and whether companies are carrying out risk controls. According to the ACM, the investigation has led to greater awareness and visible improvements in compliance.

Competition law in the energy transition and sustainability

Competition law also plays a role in the establishment of partnerships between companies active in the field of energy transition in the broadest sense of the word. Particularly in emerging and developing markets with relatively high barriers to entry or growth, there are opportunities for cooperation between competitors or between suppliers and customers if this is necessary or if it brings (clear) efficiency gains. There is also much to be gained in terms of sustainability through more intensive cooperation between (other) companies (active outside the energy sector), according to a study by the ACM. In recent years, there has been increasing cooperation between large companies, but less so among small and medium-sized enterprises. The ACM considers that this could be due to lacking knowledge of competition rules amongst these undertakings.

Competition law offers various generic and sustainability-oriented frameworks within which cooperation is permitted. For example, the horizontal block exemptions and guidelines offer options for companies with a limited market share to join forces, for example by agreeing to produce jointly or to market sustainable products. Broadly speaking, it is important that the advantages outweigh the disadvantages of the agreement and that the restriction of competition does not go beyond what is necessary to achieve the (sustainability) benefits. Sustainability agreements can also be made in vertical relationships. In addition, there are specific regimes for sustainability standards and (only in the Netherlands) for environmental damage restrictions.

Informal assessments

In the past, ACM has expressed itself positively on various initiatives involving cooperation between companies in the energy sector. In 2022, for example, the ACM stated that companies were allowed to enter into joint multi-year contracts for the purchase of electricity from a wind farm (yet to be built): this allows companies to fix their price for green electricity for a longer period of time, while developers are assured of sales. System operators were also allowed to agree to apply a CO₂ price when making investment decisions, in order to make cleaner choices more attractive. The ACM assessed both initiatives on the basis of its (then draft) Guidelines on Sustainability Agreements.

Another example from 2022 is the informal assessment of a collaboration between Shell and TotalEnergies for large-scale CO₂ capture and storage (CCS) in the North Sea. The ACM considered that the benefits of this collaboration far outweighed the potential restrictions on competition. The collaboration was seen as crucial to the feasibility of the project (i.e. reducing the financial and operational risks for the parties involved and providing certainty about a minimum purchase). Although joint pricing would apply in the start-up phase, the ACM believes that sufficient competition will remain because the cooperation concerns only part of the total capacity and third parties will have fair and non-discriminatory access to the remaining capacity.

Furthermore, in recent years, the ACM has regularly expressed its support for numerous sustainability agreements in other sectors, including sustainability standards (asphalt, e-commerce), ESG reporting (banking sector), agreements between competitors on recycling (waste, coffee capsules) and making production (chains) more sustainable (metal, natural stone, clothing and textiles).

If you have or wish to enter into agreements with one or more other companies in the field of sustainability, we will be happy to assist you with the competition law assessment of the collaboration. We can also advise on the usefulness or necessity of informally submitting the self-assessment to the ACM via the special portal that the ACM has developed for this purpose.

 

Vision

Dawn raids in competition law: Recent developments and legal limits

Introduction

After a temporary decline during the COVID-19 pandemic, unannounced company inspections, better known as dawn raids, have returned with renewed intensity to the enforcement arsenal of regulators. Since our 2021 blog on the practical do’s and don’ts during an unannounced raid, we have seen significant legal developments concerning the legality, scope and procedural safeguards of dawn raids and the subsequent penalty decisions. Recently, several groundbreaking judgments by the Court of Justice of the European Union (“CJEU”) and the General Court of the European Union (“General Court”) have tightened the rules of the game.

In this blog, we analyse the most recent legal developments surrounding dawn raids and what they mean for businesses. We discuss when a raid is justified, what safeguards apply during a raid, and what the rights of defence are during and after a raid. In doing so, we base ourselves on recent high-profile cases such as those involving Red Bull, Michelin, Symrise, Qualcomm, Nuctech, and the French supermarket case.

Table of contents

When is a dawn raid justified?

Legal basis and conditions

Dawn raids may only take place when there are concrete indications of anti-competitive behaviour. The legal basis for a raid by the Netherlands Authority for Consumers and Markets (Autoriteit Consument & Markt, “ACM”) is enshrined in the General Administrative Law Act (Algemene wet bestuursrecht, “Awb”) and the Netherlands Authority for Consumers and Markets Establishment Act (Instellingswet Autoriteit Consument en Markt). For the European Commission (“Commission”), these powers derive from Regulation 1/2003. The powers are further defined and delimited by national and European case law.

Dawn raids by the ACM (whether or not in support of the Commission) may only take place if there are concrete indications of conduct such as:

  • Abuse of a dominant position;
  • Prohibited price or other cartel agreements between undertakings;
  • ‘Gun jumping’ (premature implementation of a notifiable concentration without approval);
  • Violation of the Digital Markets Act; or
  • Violation of the Foreign Subsidies Regulation (“FSR”).

These concrete indications may originate from various sources:

  • (Anonymous) reports from competitors, suppliers and/or customers;
  • Tips from former employees or other parties involved; and/or
  • Market studies by the ACM or the Commission.

For example, in early 2025, the ACM announced that it would launch five new market investigations into, among other things, digital learning resources and veterinary practices, which could ultimately lead to further investigations and possibly even unannounced company inspections.

Legality of dawn raids: new emphases in case law

The threshold for conducting a dawn raid is relatively low. Until recently, there were relatively few rulings by European and Dutch courts on the legality of raids, considering the particularly limited possibilities for bringing annulment actions in appeal. Despite this, recent developments in case law show that challenging dawn raids (and the decisions on which they are based) can nevertheless be successful. Following (European) case law, there has been increasing attention for procedural safeguards that protect undertakings against excessive investigative powers.

České dráhy case: broad but limited powers of the Commission in competition raids

On 30 January 2020, in the České dráhy case, the CJEU confirmed the Commission’s broad powers to carry out unannounced raids in competition investigations. The case concerned a dawn raid on the Czech railway company České dráhy, following information provided to the Commission by the Czech competition authority about possible abuse of a dominant position through predatory pricing.

The Commission carried out an initial raid on the basis of these indications. Following information obtained during this raid, the Commission decided to carry out a second raid. However, the CJEU ruled that there were insufficient concrete indications for the second raid. The decision did not meet the requirements of necessity and proportionality and was therefore partially annulled.

In this ruling, the CJEU furthermore emphasised a number of important principles regarding dawn raids. Firstly, the Commission does not need to examine exculpatory evidence when deciding to conduct a raid, as long as there is sufficient incriminating evidence. Secondly, information from a national competition authority may already provide sufficient grounds for a raid. Finally, the scope of the decision to carry out a search must be specific and not too broad, to ensure that the company under investigation can properly understand and exercise its rights.

This ruling confirms the Commission’s broad powers to carry out raids to enforce competition law, but also sets clear limits to prevent arbitrariness and disproportionate infringements of the right of defence.

French supermarket case: clear requirements for documentation and specific indications for a raid

An important ruling that has tightened the procedural requirements for dawn raids is the so-called French supermarket case. In 2017, the Commission carried out unannounced raids at several French supermarket chains, including Casino and Intermarché, in relation to suspected anti-competitive agreements.

The supermarkets in question argued that the Commission had not correctly recorded the interviews that served as the basis for the unannounced raids. For its file, the Commission had only prepared summaries of interviews with third parties, without including full reports of these conversations. The General Court had previously ruled that this obligation did not apply before the formal opening of an investigation.

In this judgment, the CJEU clarified that the General Court’s position is incorrect. The CJEU ruled that the obligation to record interviews does not depend on the stage of the proceedings, but rather on the purpose of the conversations. According to the CJEU, interviews conducted to gather information on the subject of the investigation – such as substantiating a reasonable suspicion justifying a dawn raid – must be properly documented by the Commission. This ruling strengthens the procedural safeguards for companies facing competition investigations and sets limits on the Commission’s investigation methods, including in the preparatory phase.

Telemarketing: whose door are we knocking on?

This formal approach is also followed in the Netherlands. In November 2021, as part of an investigation into compliance with consumer law in the telephone sale of energy contracts, the ACM decided to conduct an unannounced inspection at Global Marketing Bridge B.V. (“GMB”), an intermediary that recruits customers by telephone for energy suppliers. Although the ACM had learned from information provided by landlord Regus that GMB’s activities might have been continued under the company name Sales Innovators B.V. (“SI”), it only included GMB and its affiliated companies in its description of the dawn raid’s purpose. Upon arrival at the address, the persons involved informed the ACM that SI, rather than GMB, was now located at this location. Nevertheless, the ACM decided to continue its investigation and ultimately imposed a fine on SI and its manager for a violation of consumer law.

In December 2023, the preliminary relief judge ruled that the factual continuity (whether SI had taken over GMB’s activities) was not decisive for the description of the purpose. Since SI simply fell outside the scope of the (group of) undertakings that were the subject of the investigation, the inspection was unlawful as it violated Article 8 of the ECHR and Article 7 of the Charter. Since the supporting evidence used to establish the violation had been obtained during these company raids, the preliminary relief judge suspended the fine and publication decision. However, after the ACM withdrew the fine decision, the District Court of The Hague ruled in May 2025 that the ACM was not obliged to pay damages, as it was likely the ACM would have launched an investigation into SI even in the absence of that procedural error.

Red Bull: detailed complaint from competitor provides sufficient evidence

Apart from the strict requirements for the more formal aspects at the outset, the General Court has confirmed in recent case law that a dawn raid is not easily deemed unlawful based on substantive grounds, such as a lack of sufficient evidence or an overly broad description of the purpose.

In March 2023, the Commission carried out an unannounced raid at Red Bull’s premises for alleged anti-competitive practices aimed at excluding competing energy drink producers. Red Bull subsequently appealed the inspection decision and requested the Commission to pay damages for the allegedly disproportionate scope and duration of the investigation. According to Red Bull, the Commission seized an excessive amount of business data during the raid and the raid was based solely on the complaint of its largest competitor, Monster Energy. On appeal, Red Bull therefore complained, among other things, about the lack of justification for the inspection decision and the violation of its substantive rights of defence.

The General Court ruled in favour of the Commission and found that the inspection decision was sufficiently precise and reasoned. The Commission had sufficient concrete evidence, including an 80-page complaint from a competitor, supplemented by emails, meeting reports and several additional requests for information. Contrary to Red Bull’s arguments, the Court did not consider it necessary in this case to verify the information with other market participants. Moreover, the Court found the fact that the Commission used open formulations and cautious terms in its inspection decision is inherent to the early stage of the investigation.

The raid was also not disproportionate, as this was the only way to obtain information that Red Bull was not expected to provide voluntarily. According to the Court, objections to the conduct of the raid, such as the search of mobile phones and the behaviour of the officials involved, do not affect the legality of the inspection decision as such. Red Bull has since lodged an appeal with the CJEU.

Symrise v. Michelin: wide margin of discretion to combine evidence provided it is sufficiently specific

Fragrance supplier Symrise was also unsuccessful in its claim for annulment of the inspection decision in the course of 2025. On 30 April 2025, the General Court ruled that the Commission was entitled to rely on a combination of evidence, including responses to requests for information from third parties and intelligence reports, even if (part of) the evidence came from a single source. In doing so, the General Court confirmed that indications must be assessed in their mutual context and that the Commission was entitled to rely on information from previous ex officio investigations. The fact that Symrise was not mentioned in the requests for information received did not, in view of its market position, detract from the Commission’s justified suspicions. The General Court thus confirmed the existing line that competition authorities have a wide margin of discretion when taking inspection decisions.

For Michelin, however, things turned out differently. On 10 January 2024, the Commission carried out dawn raids at several tyre manufacturers, including Michelin, on suspicion of prohibited price fixing on the wholesale markets for new and replacement tyres for passenger cars and trucks. The Commission based its decision on, among other things, a large-scale analysis of so-called ‘public earnings calls’ and other public announcements that may have signalled future price increases. Michelin lodged an appeal against the inspection decision in March 2025, arguing that the Commission had not substantiated its suspicions sufficiently, particularly in relation to the beginning of the alleged cartel period, and that public earnings calls could not form a plausible basis for (a suspicion of) prohibited cartel agreements.

The General Court ruled that the Commission did indeed have sufficient concrete evidence to justify the raid and did not consider the raid to be disproportionate. Contrary to Michelin’s argument, the Commission was entitled to attach importance to the earnings calls, as the information contained therein could contribute to substantiating the suspected price coordination for part of the period under investigation. However, for an earlier period, the Commission had not provided any specific evidence showing possible coordination. The General Court therefore annulled those parts of the decision pertaining to the alleged infringement period.

These recent rulings underscore the importance for undertakings to critically analyse the description of the purpose of the dawn raid, as well as any other parts of an inspection decision (in the case of the Commission) and to be aware of their rights and obligations. Although the Commission can generally suffice with a fairly broad description of the purpose in an inspection decision, and can rely on various types of information as ‘indications’, it is nevertheless advisable to remain alert to both the substance and scope of the investigation, as well as to any potential procedural irregularities during the investigative process.

Safeguards during and after a raid

Obligation to cooperate and powers of supervisory authorities

In the event of a raid by the Commission or the ACM, companies have a legal duty to cooperate. Companies are obliged to provide complete and accurate information; failure to cooperate, or the provision of misleading information may result in fines up to 1% of the undertaking’s annual turnover. This obligation is limited to the purpose and subject matter of the investigation, as communicated at the outset.

The powers of the supervisory authorities during a raid are extensive and include the power to:

  • Enter the organisation’s buildings, premises and means of transport, accompanied by the police if necessary;
  • With the permission of the examining magistrate: enter third-party premises and private homes;
  • Inspect records and make copies thereof;
  • Affix seals;
  • Take statements from persons who consent; and
  • Request clarifications regarding facts or documents, provided these fall within the scope of the investigation.

Consequences of non-cooperation

Regulators take serious action against undertakings that withhold or delete information during a dawn raid. A severely sanctioned form of non-cooperation is the deletion of relevant communications, such as messages on mobile phones or via chat services.

In March 2023, the Commission and competition authorities from the US, the UK and Switzerland raided companies in the fragrance industry. Although the investigation is still ongoing, the Commission has already imposed a fine of €15.9 million on International Flavours & Fragrances after an employee deleted messages from his mobile phone during the raid.

Such conduct is also severely penalised in other countries. In September 2023, two companies in Poland were jointly fined approximately €2.6 million by the Polish competition authority for deleting WhatsApp messages during an investigation into alleged price fixing involving coffee machines. In 2019, the ACM also imposed a fine of €1.84 million on a company for deleting WhatsApp messages during an ongoing raid.

Nuctech: cooperation also required if information is stored on non-EU servers

In preliminary relief proceedings before the CJEU, Chinese manufacturer of detection equipment Nuctech challenged the Commission’s inspection decision requiring Nuctech to cooperate with raids. In the spring of 2024, the Commission raided Nuctech subsidiaries in the Netherlands and Poland on suspicion of anti-competitive foreign subsidies (based on the FSR). Nuctech requested a suspension of the Commission’s investigation, arguing that the Commission’s territorial investigative powers did not extend to mailboxes stored on servers in China. According to Nuctech, Chinese criminal law would prohibit and penalise granting access to such information.

The General Court and subsequently the CJEU considered these arguments to be insufficiently substantiated and, in balancing the interests involved, held that Nuctech – by carrying out activities in the EU – had chosen to submit to EU law. Nuctech is therefore, in principle, obligated to cooperate with an inspection decision in which the Commission requests access to business mailboxes used for the daily conduct of activities in the EU.

Legal protection during a dawn raid: three essential rights

The powers of the ACM and the Commission during a dawn raid are limited. Companies and their employees have three essential rights during a raid:

Right to legal assistance

A company has the right to legal assistance during a dawn raid by the Commission or the ACM. In its judgment of 6 September 2024, the Dutch Supreme Court held that, under the ECHR, administrative bodies such as the ACM are required to inform the parties concerned in a timely and active manner of this right as soon as it becomes apparent that a punitive sanction may be imposed. In this light, the question also arises as to whether the ACM’s policy of waiting a maximum of 30 minutes for a solicitor to arrive during a dawn raid, is still in accordance with the ECHR. If the person concerned is unable to effectively exercise their right to assistance before the raid begins, there is a risk that their right to a fair trial will be violated. This may raise questions about the sustainability of this approach under the current human rights framework.

Right to remain silent

Regulators are authorised to obtain information from employees in the context of the investigation. However, employees of a company suspected of having infringed competition rules are not obliged to answer questions that could incriminate themselves or the company. Before questioning begins, the official conducting the interview must inform the employee of their right to remain silent (‘cautie’). Employees therefore cannot be forced to make incriminating statements. This does not apply to factual information.

Legal privilege

Communication between a company and its external attorney is covered by what is known as legal privilege. No access may be demanded to correspondence, documents and advice exchanged between the company and its attorneys. Officials are also not permitted to make copies of this information.

Previously, ACM policy allowed ACM employees to briefly review privileged communications to assess whether legal privilege applied, but this policy was amended following the Dutch Supreme Court judgment of 12 March 2024. Since then, such material can be requested and is instead submitted to an ACM privacy officer for review. This remains controversial, as it is still an ACM official who decides on the applicability of legal privilege, rather than an independent third party.

Procedural errors in the presentation of evidence and rights of defence

The increased emphasis on procedural safeguards is reflected not only in challenges to the legality of dawn raids on undertakings, but also in objections to the working methods in the reporting phase after a raid (as a prelude to the decision to impose a fine). In several recent cases, the Commission’s penalty decisions have been overturned, not only because of substantive shortcomings, but also because of procedural flaws that affected companies’ right of defence. The case law below demonstrates that procedural fairness is essential throughout the investigation leading up to the final penalty.

Qualcomm case: procedural shortcomings in the evidence and scope of the Statement of Objections

On 15 June 2022, the General Court annulled a fine of nearly €1 billion imposed by the Commission on chipset developer Qualcomm. In 2018, the Commission had found that Qualcomm had abused its dominant position by making exclusivity payments to Apple for the purchase of LTE chipsets.

In addition to substantive deficiencies in the evidence (the Commission had failed to demonstrate that there were market foreclosure effects), the General Court found several procedural irregularities:

  1. The Commission had failed to document the exact content of all conversations, including meetings and conference calls with third parties; and
  1. The penalty decision ultimately only concerned one relevant market, whereas the Statement of Objections (“SO”) covered several markets. This affected the relevance of Qualcomm’s economic analysis, without Qualcomm being given the opportunity to respond.

According to the Court, these procedural errors violated Qualcomm’s right of defence and resulted in the complete annulment of the decision.

Sony case: relationship between Statement of Objections and final decision

On 16 June 2022, the CJEU emphasised the importance of a careful administrative procedure in the Sony case. The competition infringement concerned an alleged cartel between Sony, Quanta and the joint ventures of Toshiba and Samsung. In its decision, the Commission found that there was both a single continuous infringement and a number of separate infringements. However, these separate infringements were additional to those covered in the previously issued SO. Contrary to the judgment of the General Court, the CJEU concluded that this violated the cartelists’ rights of defence, as these separate infringements had not been sufficiently investigated and qualified in the SO, which denied the parties the opportunity to respond.

BEH and Others v Commission: inadequate evidence and procedural safeguards

A more recent example is the case of Bulgarian Energy Holding (“BEH”) against the Commission. On 25 October 2023, the General Court annulled the €77 million fine imposed in 2018 on the state-owned gas company for alleged abuse of a dominant position between 2010 and 2015. In addition to the fact that the Commission had failed to demonstrate that the specific requirements of the essential facilities’ doctrine had been met, the General Court found that the Commission had committed serious procedural errors:

  1. The Commission had failed to document certain minutes of meetings with third party Overgas; and
  2. Exculpatory meeting minutes with third parties, which later proved essential to BEH’s defence, were kept out of the case file.

These procedural flaws had prejudiced BEH in its defence, leading to the complete annulment of the fining decision.

The above cases illustrate the growing importance of procedural safeguards in European competition cases that result in punitive sanctions. The courts set high standards for the care with which the Commission conducts its investigations and the manner in which it guarantees the rights of defence of undertakings.

Conclusion and practical tips

Dawn raids are back and more intensive than ever. At the same time, recent rulings demonstrate that the authorities’ legal leeway is not unlimited. The (European) courts are imposing increasingly stringent requirements on the justification, proportionality and procedural diligence of dawn raids. This presents an opportunity for companies to successfully challenge a raid – or the subsequent decision to impose a fine – provided they invoke their rights in a timely and correct manner. For companies involved in competition investigations, it is crucial to be aware of their procedural (defence) rights from the outset. Practice shows that a strategic and legally sound approach during and after a raid can make all the difference.

A practical step-by-step plan for companies in the event of a raid:

  1. Preparation is crucial: Ensure that you have an up-to-date dawn raid protocol in place, including a contingency plan with internal and external contacts.
  2. Act immediately and in a legally sound manner: Request legal assistance immediately and wait to make any statements until an attorney is present. Inform the authority that you are aware of your rights.
  3. Document the raid yourself: Check the description of the purpose (and, if applicable, the inspection decision) before the authority enters and keep accurate records of what its personnel is doing, what questions are being asked and what documents are being viewed or copied.
  4. Avoid obstruction while protecting the boundaries: Cooperate, do not remove any materials, but remain alert to any overreach of authority. Seek clarification if requests are unclear, and do not respond hastily based on assumptions. Object where necessary and ensure this is formally documented.
  5. Know and exercise your rights: Remember your right to remain silent, your right to legal assistance and your legal privilege. Ensure that these rights are respected. For example, be vigilant about whether and, if so, when the ‘cautie’ is given and to whom, and make a note of this yourself.
  6. Consider objecting or appealing: Recent case law shows that raids and penalty decisions are increasingly being overturned due to procedural errors. Therefore, always have a legal review carried out to determine whether there are grounds to challenge the method or scope of the raid in court.

With thanks to our former colleague Lara Elzas.

Vision

Flash Forward Merger Control 2026

As the holiday season approaches, we are again looking ahead to developments in the field of merger control for the coming year. In this second edition of the Flash Forward Merger Control, we discuss a number of key themes and trends that we expect to play a role in 2026 (and beyond), and that may have an impact on your practice and clients.

In this edition, we discuss the following (expected) developments:


More investigations into non-notifiable acquisitions

As of 1 September 2025, Article 24(2) of the Dutch Competition Act (“Mw”) has been repealed. This provision stipulated that the national prohibition on abuse of a dominant position could not be applied in the assessment of acquisitions. As a result of its repeal, the ACM can now also investigate non-notifiable transactions (either pre- or post-closing) where the acquisition may constitute an abuse of the acquirer’s pre-existing dominant position. For acquiring parties, this entails an increased risk of (ex post) interventions, as well as the need to assess not only notification thresholds but also the potential dominance of the acquirer at an early stage.

Investigations of non-notifiable concentrations in the context of abuse of dominance (also referred to as the Towercast doctrine, named after the CJEU’s judgment in which it introduced this doctrine) are becoming increasingly common. For example, in March 2025, the ACM launched an investigation into the potentially anti-competitive acquisition of Ziemann by cash-in-transit company Brink’s. With the repeal of Article 24(2) Mw, it is likely that the ACM will more frequently assess whether an acquisition qualifies as an abuse of an (existing) dominant position.

In other countries, this practice has already become relatively common. The Belgian competition authority, for instance, has investigated several acquisitions for possible abuse of dominance (Proximus/EDPnet in 2023 and Live Nation/Pukkelpop in 2025). In November 2025, the French competition authority was the first to impose a fine for an abusive acquisition. This fine related to the acquisition by the online healthcare platform Doctolib of its competitor MonDocteur in 2018. Internal documents showed that Doctolib intended to eliminate its main competitor through this acquisition, in order to strengthen its dominant position (by expanding its customer base) and enable price increases.

Whether a potential acquirer holds a dominant position prior to a transaction is often difficult to determine with certainty. If there is an indication that the acquirer holds more than a 40% market share and intends to acquire a competitor, it is advisable to identify any Towercast-related risks. In this context, the role of internal (transaction) documents is becoming increasingly important, as these may also reveal potential concerns.

Finally, it is worth noting that competition authorities tend to broadly interpret their powers under the Towercast doctrine. Both the French competition authority and Belgian competition authority have applied the Towercast doctrine also to assess transactions under Article 101 TFEU, the cartel prohibition.

back to top


Legislative proposal introducing a call-in power for the ACM

On 25 June 2025, a legislative proposal was submitted to introduce a so-called ‘call-in power’ for the ACM. On the basis of this power, the ACM would be able to intervene ex ante in acquisitions that do not exceed the “general” turnover thresholds. This measure follows recent concerns related to the effects of private equity acquisitions, particularly in the following three sectors: general practitioner practices, veterinary practices and childcare. The proposal intends to enable the ACM to act against so-called ‘industry roll-ups’, serial acquisitions in small or niche markets that fall below the turnover thresholds, and ‘killer acquisitions’.

Under the current proposal, the ACM may request information about a transaction if at least one of the undertakings involved achieved a turnover of € 30 million in the Netherlands in the preceding year. As regards timelines and procedure, the following has been proposed:

  • the ACM may issue an information request within a four-week period starting from the earliest of the following moments: (i) the moment at which the intention to bring about the concentration is made public, (ii) the moment at which the ACM becomes aware of this intention, or (iii) six months after the agreement giving rise to the concentration has entered into force;
  • the ACM then sets a reasonable time limit within which the relevant information must be provided and, during that period, may request additional information;
  • after the expiry of this reasonable period, the ACM will in principle have four weeks to assess whether the concentration could significantly impede effective competition;
  • if so, the ACM will (i) require the undertakings concerned to notify the concentration, and (ii) impose a standstill obligation on the merging parties until four weeks after the concentration has been notified;
  • once the notification has been made, the regular time limits for the review of notifiable concentrations apply.

Considering the timelines set out in the legislative proposal, several months may pass before parties obtain clarity as to whether their proposed concentration is permissible. From the perspective of legal certainty, it is therefore advisable, if this proposal enters into force, to inform the ACM as soon as possible of a concentration that may be subject to a potential call-in, such as transactions in the sectors mentioned above.

On 1 October 2025, the Dutch Council of State published a critical opinion on the proposal, in particular as regards the proportionality of the call-in power and the legal uncertainty it creates. The ACM defended the proposed call-in power, though it suggested combining the call-in power with increasing the ‘general’ individual turnover threshold from € 30 million to € 50 million to prevent its administrative burden from growing substantially (as the Council of State warned about). After the opinion of the Council of State and the ACM’s response, it is now up to the legislator to decide on any subsequent steps.

back to top


Expansion of the Vifo Act to new sectors

In light of the rapidly changing geopolitical situation, a proposal has been under consideration since 19 December 2024 to expand the scope of the Vifo Act to new sectors and technologies. In short, the proposal adds the following new categories of sensitive technologies to the Decree on the Scope of Sensitive Technologies:

  • advanced materials technology;
  • nanotechnology;
  • biotechnology;
  • artificial intelligence;
  • sensor and navigation technology; and
  • nuclear technology for medical use.

Which technologies are specifically designated within these categories is further specified in the Decree and its explanatory memorandum. It is intended that all of these technologies will also be designated as highly sensitive, meaning that the threshold of significant influence (rather than decisive influence) will apply to investments in such technologies. In addition, the Ministry of Economic Affairs intends to designate several additional dual-use goods as highly sensitive, specifically certain advanced telecommunications and information security technologies.

The Council of State has yet to issue its opinion on the proposal. The amendments will therefore enter into force no earlier than early 2026. If the amendments are adopted, this will mean for M&A practitioners that mergers and acquisitions in an increasing number of sectors may become subject to investment screening by the Dutch Investment Screening Bureau (“BTI”). This thus requires an even more rigorous analysis of transaction risks, timelines and notification obligations when clients are active in, or involved with, vital or strategic sectors.

back to top


Legislative proposal for an investment screening mechanism for the defence industry

In addition to the expansion of the Vifo Act, a legislative proposal has been under consideration since 2024 to introduce, among other things, a separate investment screening mechanism for the defence industry (the Defence and Security-Related Industry Resilience Act). This screening mechanism is intended to strengthen the strategic position of the Dutch defence sector and focuses on investments, mergers and acquisitions within the armed forces’ supply chain. This new mechanism will coexist alongside the Vifo Act and, in doing so, will replace and broaden the current Vifo screening regime with respect to military goods, so that essential suppliers will also fall under regulatory oversight. The proposal contains provisions similar to those of the Vifo Act, such as a notification obligation, a standstill obligation, a nullity sanction and the possibility to impose conditions (see the previous edition of our Flash Forward for further details). The Council of State still needs to issue an opinion on this proposal. The ACM published a positive assessment of the proposal’s feasibility and enforceability in November 2025. The Dutch data protection authority, however, made a number of critical comments on the proposal.

back to top


Political agreement on strengthened FDI Regulation

At the EU level, a political agreement was reached mid-December regarding the strengthening of the FDI Regulation. The agreed framework entails the following changes:

  • all Member States will be required to have a screening mechanism in place for certain sensitive and strategic core areas (see below);
  • indirect investments will also fall within the scope of the FDI Regulation;
  • a strengthened cooperation framework between Member States, though screening decisions will remain the exclusive responsibility of the individual Member State;
  • streamlining of processes and enhanced interoperability, including filtering criteria, a new shared database and an optional single portal for the electronic filing of foreign investments; and
  • certain transparency improvements.

Compared to the Commission’s initial proposal, a number of technologies have been removed from scope. Although no final, more detailed list has yet been published, the Council has indicated that the following sensitive and strategic core areas will fall within the scope of the Regulation:

  • dual-use goods and military goods;
  • hyper-critical technologies, such as artificial intelligence (aligned with the definitions in the AI Act and focused on general-purpose artificial intelligence relevant to space or defence);
  • critical raw materials;
  • critical entities in energy, transport and digital infrastructure, based on a risk-based assessment by the Member State in which the EU target undertaking is established;
  • electoral infrastructures (such as voter databases, voting systems and election management systems);
  • a closed list of entities within the financial system, limited to central counterparties, central securities depositories, operators of regulated markets, operators of payment systems (excluding central banks) and systemically important institutions.

The revised framework is expected to enter into force in the first half of 2026, following formal approval by the Council and the European Parliament. Member States will then have eighteen months to implement the changes into their national legislation.

In the Netherlands, this is expected to result once again in amendments to the Vifo Act and/or the Decree on the Scope of Sensitive Technologies. For example, not all “critical raw materials” and electoral infrastructure are currently covered by the Vifo Act. Although it will take some time, it is therefore important for M&A practitioners to remain alert to the expected further expansion of the scope of the Vifo Act and to potential changes to timelines and other procedural aspects, including a formalisation of the “two-phase” system.

back to top


Reinforcement of the healthcare-specific merger assessment

Last summer, a legislative proposal to amend the Healthcare Market Regulation Act (“Wmg”) was opened for consultation. The proposal aims to significantly expand the healthcare-specific merger assessment by allowing the NZa not only to review the merger process, but also to assess the substantive effects of mergers and acquisitions in the healthcare sector. Under the new proposal, the NZa may refuse approval of a healthcare merger where the continuity of care is threatened. This power currently exists only in relation to critical care, such as ambulance services and emergency care, but may be extended under the new proposal to all healthcare services (as defined in the Health Insurance Act, the Long-term Care Act and the Forensic Care Act).

In addition, the NZa will be granted powers to block mergers where there are risks pertaining to the lawfulness of care, such as unlawful billing practices or weak financial management. The quality of care will also become an explicit assessment criterion: at the request of the NZa, the Dutch Health and Youth Care Inspectorate will issue an opinion where there are signals or ongoing enforcement measures, or where the concentration is of such a size that the ACM is also involved. If the Inspectorate’s opinion indicates that the standards for ‘good care’ or proper organisation of care may be breached, the concentration will not be approved. The NZa may furthermore revoke an approval granted on the basis of incorrect or incomplete information, and may impose fines in that context.

The proposed broadening of the assessment criteria means that not only procedural elements (i.e. the consultation of stakeholders) of a proposed merger will be scrutinised, but that the NZa will also play a more substantive role in determining whether a merger or acquisition is permissible. It is expected that this may result in some mergers being blocked in the future. The proposal may also lead to legal uncertainty, given the open-ended nature of the quality assessment standards, and to an increase in administrative burdens. The final legislative proposal is expected in early 2026.

back to top


More frequent ex officio investigations under the FSR

Under the FSR, a concentration must be notified where one of the merging parties, the target or the joint venture has an EU turnover exceeding € 500 million and all parties together received more than € 50 million in foreign financial contributions (“FFCs”) from third countries in the preceding three years. FFCs cover virtually all forms of financial support from non-EU countries, including remuneration for the provision of goods and services, regardless of the conditions under which such support was granted. In practice, the FFC reporting obligations – particularly for private equity funds – have proven to entail a heavy administrative burden, despite the Commission having published extensive Q&A guidance containing various simplifications.

The first completed cases illustrate how the FSR is applied in practice. In the case of e&/PPF Telecom Group, the Commission investigated substantial aid granted by the UAE to e&. Although the foreign subsidies did not distort the acquisition process itself, the Commission concluded that they could distort competition post-transaction. In order to obtain (conditional) approval, e& offered commitments, such as the removal of an unlimited state guarantee and to apply market-conform conditions. Similarly, the acquisition of Covestro by ADNOC triggered an in-depth investigation due to aid granted by the UAE. Recently, the Commission conditionally approved the acquisition after accepting commitments from ADNOC – such as granting access to Covestro’s patents for sustainable technologies.

FSR enforcement to date has primarily focused on strategic sectors such as telecommunications, infrastructure and renewable energy. Although the FSR has been criticised by third countries, particularly China, for allegedly creating trade barriers, oversight under the FSR is expected to increase if it is up to the Commission. In the current geopolitical climate, the expectation is that the FSR’s ex officio investigative tool will be used more frequently. In addition, with the forthcoming new (draft) FSR guidelines in January 2026, the Commission is likely to more actively call-in below-threshold concentrations where there is a suspicion of involvement of foreign subsidies (see the first draft of the FSR guidelines here).

For further developments in the area of the FSR, we refer to our recent blog.

back to top


Thank you for reading the second edition of the Flash Forward Merger Control. We wish you happy holidays and a successful new year!

Team Competition – bureau Brandeis

Bas Braeken (Partner) | Jade Versteeg (Attorney-at-law) | Timo Hieselaar (Attorney-at-law) | Demi van den Berg (Attorney-at-law) | Joost van Belois (Attorney-at-law) | Lisanne Kooijman (Paralegal)

Vision

Two years since the entry into force of the FSR: just a weapon or also a shield?

Introduction

Since 12 October 2023, undertakings are required to notify concentrations and bids for tenders involving funding from non-EU states to the European Commission (“Commission”) based on the Foreign Subsidies Regulation (“FSR”). A lot has happened in the field of FSR since then. In 2024 alone, 102 concentrations were notified under the FSR and more than two-thousand notifications of public tenders were received. This is seven times more than the Commission initially anticipated.

In previous blog posts, (see blog of 8 November 2021 and blog of 18 October 2023) we have already discussed the content of the regulation itself in detail. In this blog, we discuss the most recent developments: various investigations initiated (and completed) by the commission, of which the e&/PPF Telecom Group decision offers useful insights into the FSR’s assessment framework. Based on these developments, we also discuss the possibilities for third parties to use the FSR when they experience unfair competition from foreign-subsidised undertakings.

 

Overview


A quick refresher: what does the FSR entail?

The aim of the FSR is to contribute to economic sovereignty, including in the geopolitical sphere, and to create a level playing field between EU and non-EU companies operating in the EU. Under the FSR, the Commission has the power to investigate non-EU subsidies granted to an undertaking that carries out economic activities in the internal market. It can do so on its own initiative (ex officio) or following a mandatory notification of a concentration or tender.

The notification requirement applies to acquisitions, mergers or the creation of joint ventures where (i) at least one of the merging parties (in the case of mergers), the target company (in the case of acquisitions), or the joint venture is established in the eu and has a total EU turnover of at least € 500 million; and (ii) all the undertakings concerned (and the groups to which they belong) have collectively received more than € 50 million in foreign financial contributions (“FFC”) during the previous three years.

FFC is understood to mean any form of transfer of financial resources from a third country (public organization or private entity whose behaviour can be attributed to the government). In order to determine whether the second threshold has been met, the conditions under which the FFCs were provided are irrelevant. Whether the FCC involves an ‘advantage’ and ‘selectivity’ only plays a role in the substantive assessment.

The impact of the FSR, and in particular the administrative burden for reporting parties and the Commission itself, has proved to be considerably greater than initially expected. In order to address the many nuances and complexities involved in applying the FSR notification thresholds, and to limit the FFC reporting obligation where possible – particularly where private equity funds are involved – the Commission has drawn up a comprehensive Q&A on procedural and jurisdictional issues. An evaluation of the FSR is currently underway. In the context thereof the Commission has asked market participants for feedback and will, among other things, examine whether there are opportunities to simplify and clarify the process.

 

Call-in power

In addition to the notification thresholds, the FSR also provides the Commission with the power to require pre-closing FSR notification of a concentration if it suspects that foreign subsidies have been granted to the undertakings concerned in the three years prior to the concentration (Article 21(5) FSR). The Commission’s request must be made before the concentration is implemented. This call-in power can be useful when, for example, the Commission becomes aware of a concentration through a merger control filing which, although it does not meet the FSR thresholds, appears to involve foreign subsidies.

An example of this is the acquisition of Arbonia by the Chinese undertaking Midea. During the merger control assessment, the Commission sent an FSR information request to the parties involved. Though this ultimately did not lead to a request for notification, it does demonstrate the Commission’s willingness to exercise its call-in powers where necessary.

Pursuant to Article 46 FSR, the Commission must publish guidelines (FSR-guidelines) by 12 January 2026 at the latest. These guidelines will address, amongst other things, the Commission’s power to invoke concentrations or procurement procedures and clarify certain technical concepts. In March of this year, the Commission launched a public     consultation on this matter, and last summer, the Commission presented a first draft of the guidelines to the market. These guidelines indicate that the Commission believes that even concentrations well below the € 500 million EU turnover threshold can also be ‘called-in’, for example when strategic assets are involved or the buyer exhibits certain purchasing behaviour.

 

FSR in practice: the first completed and ongoing investigations

The Commission’s decision-making practice shows that it is focusing on sectors that are strategically important for the EU. In particular, transactions in the energy, telecoms and infrastructure sectors involving subsidies from Chine and the Gulf states are affected by FSR supervision.

The first FSR commitment decision: e&/PPF Telecom Group

On 26 April 2024, the proposed acquisition of PPF Telecom Group by e& was notified. Following an in-depth investigation, the Commission approved the acquisition on 24 September 2024, subject to conditions. The published decision provides important insight into the framework for the material assessment of internal market distortions caused by foreign subsidies.

e& is a telecommunications provider based in the United Arab Emirates (“UAE”). The UAE’s federal sovereign wealth fund, the Emirates Investment Authority (“EIA”), controls and holds a majority stake in e&. PPF Telecoms Group is a telecommunications operator active in Bulgaria, Hungary, Serbia and Slovakia. The decision states that e& benefited from (i) a loan from a consortium of banks (four state-controlled banks and one private entity), (ii) an unlimited state guarantee, (iii) direct subsidies and loans from the UAE Ministry of Finance, and (iv) a revolving credit facility from a consortium of UAE banks.

The Commission first examined whether these FFCs qualify as ‘foreign subsidies’ within the meaning of Article 3 FSR. Only the loan to e& (under (i)) was not considered a foreign subsidy as it was not considered an ‘advantage’. The next question is whether these foreign subsidies actually distorted the market (taking into account the legal presumptions in Article 5 FSR). To this end, the Commission first identified the activities concerned and thus the relevant market(s). In its assessment, the Commission distinguished between two situations: (i) distortion of competition during the acquisition process, and (ii) distortion of competition on the market (post-transaction).

To determine whether a market distortion has occurred or may occur, the Commission applies the two-step approach as set out in Article 4 FSR:

  • does the foreign subsidy improve the competitive position of an undertaking in the internal market; and
  • does it actually or potentially adversely affect competition in the internal market?

In the event of market distortion, the Commission balances on the one hand the positive effects of the subsidy (and the causal link between the effects and the subsidy) put forward by the merging parties and, on the other hand, the market distortion observed, in accordance with Article 6 FSR. In the present case, the Commission concluded that the foreign subsidies did not promote e&’s competitive position in the takeover process, but that e& could gain a competitive advantage after the transaction.

In order to address the Commission’s concerns, e& offered commitments at an early stage of the investigation. This enabled the Commission to take a decision without having to formalize its concerns in a Statement of Grounds. In accordance with Article 7(2) and (3) FSR, the commitments must remedy the distortion in the internal market completely, effectively and proportionately. The decision shows that the Commission has accepted several commitments, including the non-application of provisions in e&’s articles of association that deviated from bankruptcy law in the UAE (meaning that the unlimited guarantee would no longer be valid). Moreover, the parties have committed that e& (and its affiliates) may not finance any of the target’s EU companies and may only enter into transactions on market terms. The commitments are valid for a period of 10 years.

Ongoing FSR investigations

Recently, commitments were also offered in another second-phase investigation, as a result of which the Commission conditionally approved the proposed acquisition of Covestro by ADNOC on 14 November 2025. Covestro is a German undertaking that produces plastics and polymers for, among others, the automotive and construction industries. ADNOC is a state-owned oil giant from Abu Dhabi. The Commission came to the preliminary conclusion that the foreign subsidies ADNOC received from the UAE enabled an aggressive investment strategy that deterred other investors.

ADNOC has agreed to amend the unlimited state guarantee in its articles of association and to make Covestro’s patents for sustainable technologies available to third parties under transparent conditions. This brings the second in-depth concentration investigation under the FSR to an end well ahead of the March 2026 deadline.

Another investigation that has attracted a lot of attention is the ex officio investigation launched by the Commission on 23 April 2024 into Nuctech, a Chinese manufacturer of security equipment. The Commission raided Nuctech’s premises in the Netherlands and Poland and seized a large number of documents. In preliminary relief proceedings brought by Nuctech, the General Court ruled that there were no grounds to prevent the Commission from including the email correspondence obtained in its investigation. The General Court considered that EU regulators must have access to data stored outside the EU, for example on servers in China. The risk of fines and criminal charges under Chinese law for disclosing trade secrets does not justify suspending the Commission’s investigation, according to the EU judges. Nuctech’s appeal to the Court of Justice has also been rejected.

In addition to the EU court’s confirmation of a far-reaching obligation to cooperate in FSR raids, the Commission may also – in the event of lack of cooperation – conduct investigations on the basis of ‘available facts’ (Article 14(3)(b) FSR). The threat of basing an investigation on (unfavourable) information from competitors or customers will generally compel parties to cooperate.

The Commission has furthermore launched investigations into several tenders, namely:

  • A public procurement procedure by the Bulgarian Ministry of Transport and Communications for the supply of 20 electric push-pull trains and related maintenance and staff training-services. A subsidiary of the state-owned CRRC Corporation is alleged to have received € 1.7 billion in foreign subsidies to win the Bulgarian tender.
  • Two bids for a public contract for the development, construction and implementation of a solar park in Romania. The level of the bids submitted by Shanghai Electric and Longi Green Energy Technology (both linked to Chinese state-owned companies) compared to the bids submitted by other interested parties and to the value of the contract prompted the Commission to launch an investigation.
  • Goldwind Science & Technology, a Chinese supplier of wind turbines to wind farms in Spain, Greece, France, Romania, Bulgaria and Germany, is reportedly the subject of a Commission investigation after complaints by European companies.

CRRC Corporation, Shanghai Electric and Longi Green Energy have all ultimately withdrawn from the respective tendering procedures. In response, former European Commissioner for the Internal Market, Thierry Breton, emphasized that the importance of developing renewable energy sources for Europe should not come at the expense of industrial competition and European employment.

There has been considerable criticism from China regarding the investigations conducted under the FSR. On 9 January 2025, the Chinese Ministry of Commerce (MOFCOM) published a report claiming that the Commission’s actions and investigations into Chinese companies create major trade and investment barriers. The Commission’s investigations are said to lack transparency and a time limit. The China Chamber of Commerce for Import and Export of Machinery and Electronic Products (CCCME) has repeatedly urged the Commission to provide clarification so that investigations are conducted fairly and transparently on the basis of clear, pre-defined criteria.

 

Implications and opportunities for complainants

The Commission intends to enforce the FSR rigorously. Enforcement of the FSR is mentioned simultaneously with enforcement of competition and merger rules, with the aim of ensuring economic security and reducing dependence on non-European entities.

In view of the ex officio policy and the forthcoming clarifications on the use of the Commission’s call-in power, there will be (more) opportunities for third parties (complainants) to alert the Commission of companies receiving improper subsidies from third countries. Third parties, such as competitors of a company involved in a transaction or EU tender, can signal suspected cases to the Commission. For example, following complaints from Électricité de France (EDF), the Commission asked the Czech State formal questions about its award of a contract to South Korea’s Korea Hydro & Nuclear Power to build a nuclear power plant. EDF was one of the other bidders in the procurement procedure.

Third parties can also rely on the FSR in other cases. In times of trade wars, foreign undertakings are more inclined to avoid import duties, for example by opening production facilities within the EU. A well-known example concerns Chinese manufacturers of electric cars, such as BYD, opening a factory in Hungary. These companies can enjoy a competitive advantage in the internal market without their activities triggering an FSR notification. The Commission reportedly opened an FSR investigation into BYD in March 2025 (in addition to an ongoing anti-subsidy investigation). It is expected that such ex officio investigations – whether or not based on signals from the market – will play an even more important role in the future.

Undertakings in the European Union would therefore do well to be alert to the possible presence of non-European subsidies to their competitors, especially if they notice that this may distort the competitive playing field. In such cases, it is advisable to report this to the Commission, whether on a confidential basis or not.

Vision

DMA Enforcement: A Visual State of Play in Four Slides

The European Commission’s (“Commission”) enforcement of the Digital Markets Act (“DMA”) has progressed steadily since its entry into force late 2022. Public enforcement of the DMA has entered a phase where compliance-related activity is becoming more frequent and more complex. The Commission continues to assess which providers of a core platform service (“CPS”) should fall within the scope of the DMA, so far having resulted in the designation of seven undertakings as gatekeepers for various CPS. Alongside these designation decisions, the Commission also issued several decisions in which it identified services as CPS, but in which it ultimately decided to not designate the provider of the CPS in question as a gatekeeper (“non-designation decisions”).

Beyond designation and non-designation decisions, the Commission has increasingly focused on gatekeepers’ compliance with the DMA’s obligations and the measures these gatekeepers ought to take in that regard. This has led to a growing number of parallel investigations, non-compliance decisions and specification decisions, each addressing different aspects and obligations of the DMA. Many of the Commission’s decisions have furthermore been appealed and now sit at different stages of the judicial process – some pending before the General Court, others having already proceeded to the Court of Justice.

As the enforcement and appeal processes multiply, it has become more challenging for practitioners and other stakeholders to maintain a clear overview of the DMA’s “state of play”. In earlier blogs we have already paid attention to the DMA’s general mechanisms, its obligations and the potential for private enforcement. In this blog, we aim to provide you with a structured visual overview of the Commission’s actions to date, through a series of slides that summarise the key decisions and situate them within the broader procedural landscape.

 

Last updated: 3 December 2025

Vision

Directors and the Cyber Security Act

The Cyber Security Act (Cyberbeveiligingswet; Cbw) is expected to come into force in the second quarter of 2026. The aim of the Cbw is to strengthen the cyber obligations for entities in sectors of social or economic importance. The Cbw also contains provisions on supervision, enforcement and additional responsibilities for directors of so-called essential or important entities.

In this blog, we discuss the responsibilities of directors of so-called essential and important entities. We examine what the Cbw requires of directors, what knowledge and skills they must possess, and how they can divide their tasks with, for example, the Chief Information Security Officer (CISO).

The role and obligations of directors

The Cbw makes directors ultimately responsible for compliance with all Cbw obligations. Among other things, directors must ensure that the organisation is registered with the digital desk of the National Cyber Security Centre. In addition, directors maintain contact with supervisory authorities and Computer Security Incident Response Teams (CSIRTs) when significant incidents occur. The directors identify the relevant cyber risks, establish appropriate control measures, approve them and actively supervise their implementation.

Responsibility lies with the formal board or, in the case of a one-tier board, with the executive directors. In other legal forms, responsibility rests with the de facto directors. For government agencies, the minister, the mayor and aldermen or the executive committee are responsible.

Required knowledge and skills

Directors can only make decisions if they have sufficient knowledge of cyber security. They are therefore required to undergo regular training in cyber security. This training requirement enables them to understand risks, assess measures and their impact, and make informed decisions. From the date of entry into force of the Cbw, there will be a transition period of two years (or, in the case of new appointments, two years after taking office). After that, administrators must demonstrate that they are keeping their knowledge up to date, for example through training courses with certification.

Every director must have the knowledge and skills to:

  • Identify risks to the security of network and information systems;
  • Assess risk management measures; and
  • Assess the consequences of the risks and risk management measures for the provision of services.

In practice, this means that directors must:

  • Recognise and interpret typical threats and vulnerabilities. These include malware/ransomware, phishing, insider threats, supply chain risks, distributed denial of service attacks, misconfigurations and third-party dependencies;
  • Have an understanding of the risk management process: how risks are identified, analysed, prioritised and addressed, how the risk register and reporting lines function, and what risk appetite and thresholds the organisation applies; and
  • Be able to assess and prioritise risk management measures and weigh their impact against effectiveness, proportionality and costs.

The precise knowledge requirements may be further elaborated by order in council.

Specific administrative tasks

In addition to the requirements regarding knowledge and training, the Cbw also prescribes what directors must do in practice. The most important administrative tasks are:

  1. Integrating cyber risk management
  • Cyber security is a core component of the risk strategy.
  • The board is ultimately responsible for an effective risk management process that is continuously monitored and improved.
  1. Establishing and approving policy
  • The board establishes and approves the information security policy.
  • The policy covers preventive measures, incident response, training and supply chain security.
  1. Incident management and reporting obligation
  • The board ensures that there is a well-designed incident response procedure, including Operational Technology (OT) systems. A vulnerability in IT can have direct consequences for physical processes in OT. Directors must therefore ensure an integrated approach, in which incident response also includes OT scenarios and risks from both domains are managed in conjunction.
  • Significant incidents are reported in a timely manner to regulators and CSIRTs.

The role of the CISO

Many organisations appoint a CISO to implement and interpret their cyber security policy. Appointing a CISO is not mandatory, but it is recommended for large organisations.

The board remains ultimately responsible for compliance with the Cbw, with the CISO providing support. For example, a CISO can:

  • Advise: translate technical risks into strategic and operational impact;
  • Coordinate: monitor the implementation and progress of measures; and
  • Monitor: assess compliance with policy and report periodically.

Liability

Directors who fail to take sufficient responsibility for compliance with and implementation of the Cbw run the risk of being held civilly liable. In addition, supervisory authorities may take enforcement action against them.

Conclusion

The Cbw makes cyber resilience an important priority for directors. The new law brings with it many new obligations, responsibilities and risks for directors of essential and important entities. It is therefore important for directors to inform themselves and prepare in good time.

Would you like to know what obligations apply to you as a director and how you can protect your organisation and yourself legally? Please contact Bente van Kan, Machteld Robichon or Ole Oerlemans.

Want to know more about the Cbw? Read our other blogs:

Vision

The scope of the Cyber Security Act

Following the hack on the Public Prosecution Service, another major hack took place in the summer of 2025, this time on the Clinical Diagnostics medical laboratory. The hack resulted in the theft of the medical data of almost half a million women. Such organisations in the healthcare sector may fall within the scope of the upcoming Cybersecurity Act (“Cbw”).

In this blog, we will therefore zoom in on this scope and discuss which entities will soon have to comply with the Cbw.

Step 1: identifying essential and important entities

The Cbw implements the NIS2 Directive. The obligations in the NIS2 Directive apply to essential and important entities. These are entities that operate in sectors of particular social or economic importance, such as energy companies, data centres and hospitals. Entities that are considered essential or important in any case are listed in Annexes I and II to the NIS2 Directive.

The various sectors covered by the scope of the Cbw are listed in Annexes 1 and 2 to the Cbw. The annexes largely correspond to the annexes to the NIS2 Directive:

  • Entities in the following sectors may qualify as essential entities (Annex 1 Cbw):
  • Energy (electricity, gas, oil);
  • Drinking water supply;
  • Transport (aviation, rail, shipping, road transport);
  • Healthcare (hospitals, laboratories, clinics);
  • Digital infrastructure (cloud, data centres, internet hubs);
  • Government organisations and public administration; and
  • Financial sector (banks, market infrastructures, insurance companies).
  • Entities in the following sectors may qualify as important entities (Annex 2 Cbw):
  • Postal and courier services;
  • Food production, processing and distribution;
  • Chemical industry;
  • Waste and wastewater management; and
  • Digital platforms and marketplaces.

Step 2: determining the size of the organisation

Whether an entity falls under the Cbw depends not only on the sector, but also on the size of the organisation. The Cbw distinguishes between micro, small, medium-sized and large organisations:

Category Criteria Application of the Cbw
Micro and small organisations Fewer than 50 employees and annual turnover or balance sheet total ≤ £10 million In principle outside the scope, unless:
• Crucial role in a vital sector (e.g. sole provider)
• Designated by a government department
Medium-sized organisations 50–249 employees or• Annual turnover or balance sheet total ≤ £50 million Always fall under the Cbw
Large organisations  ≥250 employees or• Annual turnover > £50 million or balance sheet total > £43 million Always fall under the Cbw

 

Step 3: does an exception or special provision apply?

Regardless of the type of sector or the size of the entity, the Cbw determines for some entities whether they still fall under the scope of the Cbw or not.

The following entities always qualify as essential entities:

  • Government agencies, such as ministries, provinces, municipalities and water boards. However, government agencies that are primarily active in the field of national security, public safety, defence or law enforcement fall outside the scope of the Cbw. These include, for example, the Ministry of Defence, the MIVD, the AIVD, the police, the Public Prosecution Service and the security regions. These organisations are exempt because their digital security is already regulated by specific sectoral legislation, such as the Intelligence and Security Services Act, the Police Act and the Security Regions Act.
  • Qualified trust service providers, such as Qualified Trust Service Providers, digital trust services that issue qualified digital certificates, for example;
  • Providers of registries for top-level domain names;
  • DNS service providers;
  • Medium-sized and large providers of public electronic communications networks or services.

The following entities always qualify as important entities:

  • Micro and small providers of public electronic communications networks or services; and
  • Micro and small telecommunications providers. However, the Minister may also designate these entities as essential entities.

There is also a special arrangement for higher education institutions: these may be designated as essential or important entities by the Minister of Education, Culture and Science, regardless of their size.

Finally, the Cbw contains a link to the Critical Entities Resilience Act (Wwke). The Wwke regulates the physical security and resilience of vital organisations, such as energy and drinking water companies, against threats such as natural disasters, sabotage or terrorist attacks. Organisations designated as critical entities under the Wwke automatically qualify as essential entities under the Cbw. Designation is carried out by the minister responsible for the sector in question.

Essential or important entity? Distinction in supervision

It is important to determine whether an entity falls under the Cbw and whether it qualifies as essential or important. This not only determines whether the Cbw applies, but also has direct consequences for the supervisory regime.

Essential entities are subject to a stricter supervisory regime: supervisors will carry out structural proactive checks on these entities, for example by conducting audits. For important entities, supervision is lighter: here, the supervisor acts primarily reactively, when there are signs or indications that the rules are being violated.

Conclusion

The Cbw has a wide scope of application: from hospitals and laboratories to digital service providers and financial institutions. It is important for organisations to determine in good time whether they fall within the scope of the Cbw and whether they qualify as an essential or important entity.

Are you wondering whether your organisation falls within the scope of the Cbw? Please feel free to contact Bente van Kan, Machteld Robichon or Ole Oerlemans. Keep an eye on our website and read our other blogs, see for example:

Vision

The Cyber Security Act: a new legal foundation for digital resilience

The hack on the Public Prosecution Service in June 2025 once again demonstrates how vulnerable socially important organisations are to cyber attacks. Such an incident therefore emphasises once more the need for these organisations to properly organise and secure their information provision.

This need is addressed by the revised Network and Information Security Directive (EU 2022/2555; “NIS2 Directive”). The NIS2 Directive obliges Member States to adopt national legislation that guarantees a high level of cybersecurity for entities in essential and important sectors. In the Netherlands, the NIS2 Directive is being implemented in the Cybersecurity Act. The proposal for this new act was submitted to the House of Representatives on 2 June 2025.

The purpose of the Cybersecurity Act is to strengthen the obligations for entities in sectors of social or economic importance. In addition, the Act enshrines administrative responsibility and regulates supervision, enforcement and cooperation with so-called Computer Security Incident Response Teams (CSIRTs). These are specialised teams responsible for detecting, analysing, mitigating and resolving security incidents. The Cyber Security Act replaces the current Network and Information Systems Security Act.

The Cyber Security Act is expected to come into force in early 2026. The national government advises not to wait until the new Act comes into force. After all, the risks to organisations and systems already exist today. Want to take action now and prepare for the Cyber Security Act? We outline the most important obligations below.

Scope of the Cyber Security Act

The Cyber Security Act applies to essential and important entities. These are entities that operate in sectors of particular social or economic importance. Examples of essential and/or important entities include:

  • Energy companies;
  • Hospitals and healthcare institutions;
  • Drinking water suppliers;
  • Cloud and data centre services;
  • Digital service providers;
  • Financial institutions; and
  • Government organisations.

Main obligations under the Cybersecurity Act

The Cybersecurity Act has three main obligations, which are based on the NIS2 Directive:

  1. Duty of care (Article 21 of the Cybersecurity Act; Article 21 of the NIS2 Directive)

Essential and/or important entities must take appropriate measures to mitigate cyber risks. The Cybersecurity Act lists minimum measures and provides scope for sector-specific implementation through general administrative measures or ministerial regulations (Article 21(1)-(5)).

  1. Notification obligation (Article 25 et seq. of the Cybersecurity Act; Article 23 of the NIS2 Directive)

Significant incidents must be reported to a CSIRT and the competent authority (varies per sector and type of entity). The reporting takes place in phases: first, a warning is submitted, possibly followed by an interim update, and finally a final report is produced.

  1. Administrative responsibility (Article 24 of the Cybersecurity Act; Article 20 of the NIS2 Directive)

Managers of essential and/or important entities are given explicit tasks: they must establish cybersecurity policies, monitor their implementation, and undergo further training in the field of cybersecurity and risk management.

The first main obligation, the duty of care, comprises ten minimum measures that organisations must take to protect their network and information systems. These measures form the core of the duty of care and are essential for structurally safeguarding the digital resilience of organisations. In short, entities must:

  1. Draw up, maintain and periodically evaluate policies for the management of digital risks and the security of the information system.
  2. Implement security aspects for personnel, access policy and asset management.
  3. Establish procedures for business continuity, incident recovery and crisis management.
  4. Implement policies and procedures for the detection, reporting and handling of cyber incidents.
  5. Provide basic cyber hygiene and awareness training and education to employees.
  6. Security in the acquisition, development and maintenance of network and information systems.
  7. Establish and implement measures relating to supply chain security and supplier relationships.
  8. Drawing up policies for the use of cryptography and encryption (key management).
  9. Drawing up policies for access management and access control, whereby access to systems and data is restricted to authorised persons, for example through the use of multi-factor authentication.
  10. Draw up policies and procedures to assess the effectiveness of the measures taken and to review them regularly.

Preparing for the Cyber Security Act

In preparation for the ten measures, organisations are advised to do the following now:

  • Check whether they fall under the definition of an essential or important entity, and thus within the scope of the Cybersecurity Act;
  • Start drafting or updating their cybersecurity policy;
  • Join a CSIRT; and
  • Prepare internally for reporting procedures and audits.

Although the Cybersecurity Act has not yet entered into force, essential and important entities can already register with a CSIRT. For digital service providers, there is the CSIRT-DSP, for healthcare institutions there is Z-CERT, and for other sectors there is the National Cyber Security Centre (NCSC).

Registration with a CSIRT provides access to:

  • Incident response, which helps to limit the impact of a cyber incident, analyse the cause, prevent further damage and restore affected systems;
  • Early warnings about current threat information and cyber threats, such as new malware variants, phishing campaigns, and vulnerabilities in software or systems; and
  • Technical analysis and support in the event of suspicious or harmful cyber incidents.

The Cyber Security Act introduces a number of new obligations. We will keep you informed of developments via this website.

Do you have any questions about how the Cyber Security Act will apply to your organisation, or would you like to take preparatory measures? Please feel free to contact Bente van Kan, Machteld Robichon or Ole Oerlemans.

Vision

bureau Brandeis publishes practical DSA Step-by-Step Guide

Since 17 February 2024, all digital platforms and services must comply with the Digital Services Act (DSA). From major players like Meta to your own webshop — the DSA applies to almost all digital services. Chances are high that your business falls under this legislation. The DSA uses a smart tiered system: the greater your impact, the stricter the rules.

 

To help our clients and partners navigate this new regulation, we have developed a comprehensive and practical DSA Step-by-Step Guide. This guide takes you through each stage of the compliance process. Whether you’re encountering the DSA for the first time or are already working on compliance, this guide offers a clear and accessible roadmap.

 

With the new obligation to collect and report data using official templates starting from 1 July 2025, being well-prepared is now more important than ever.

 

Do you have questions about your DSA obligations, want to get started with compliance, or are involved in legal proceedings related to the DSA? Get in touch with us today. bureau Brandeis has extensive experience with digital intermediary regulations and is ready to assist you with both compliance matters and DSA-related disputes.

 

You can find the step-by-step guide here:

bureau Brandeis Step-by-Step Guide Compliance DSA 2025

Vision

Greener skies, higher costs: Recent developments in the Dutch aviation sector

Introduction

Following the recent announcement of Royal Schiphol Group’s (“RSG”) new airport charges and conditions for the upcoming period, the Dutch aviation sector once again finds itself in a state of heightened tension. After a critical period of losses, redundancies, and labour shortages caused by the COVID-19 pandemic, airlines and airport operators are now striving to restore operations and recover financially. At the same time, stricter environmental regulations — covering fuel use, noise emissions, and sustainability targets — are taking hold across the sector. These developments, coupled with the proposed capacity reductions at Schiphol Airport, place long-term sustainability firmly on the agenda both in the Netherlands and across Europe.

This blog explores three of the most significant current developments in the Dutch aviation sector:


Schiphol Airport Charges 2025-2027

On 31 October 2024, RSG announced an average 37% increase in airport charges for the 2025–2027 period. According to RSG, this rise is primarily driven by higher operating costs (including staff), significant inflation, planned investments (such as the new A-Pier), and settlements from previous periods. The new charges and conditions also introduce a more refined noise-based differentiation: the quieter and cleaner the aircraft, the lower the relative charges for the airline.

Under the Dutch Aviation Act (Wet Luchtvaart, “Wlv”), RSG, as the airport operator, is required to set airport charges and conditions every three years. These must be cost-related, reasonable and non-discriminatory. Before finalising the charges and conditions, RSG submits a cost allocation system for approval to the Dutch Authority for Consumers and Markets (“ACM”). This system determines which costs are allocated to aviation-related activities (and thus charged to airport users, i.e. airlines), and which relate to non-aviation activities such as retail, food services and parking. The ACM approved the 2025–2027 cost allocation system on 19 June 2024.

At the request of various airlines and representative organisations, the ACM reviewed the charges and conditions. On 27 May 2025, it concluded that the new charges were largely in accordance with the rules under the Wlv. The ACM rejected objections raised by airlines concerning a lack of transparency and consultation, the absence of efficiency incentives, insufficient justification for investments, and the significant price increase partly due to pandemic-related settlements. These arguments, it noted, had already been addressed in previous reviews and upheld by the Dutch Trade and Industry Appeals Tribunal.

Broader criticism of RSG’s stricter noise and emissions-based charge differentiation was also dismissed. According to the ACM, the Wlv does not require such differentiation to be strictly proportional to actual emissions or noise levels.

However, in line with an earlier suspension decision, the ACM ruled that RSG’s proposed outright ban on certain ‘noisy aircraft types’ is incompatible with the Wlv. Such a restriction constitutes an operating restriction not permitted under the Regulation 598/2014 and also contradicts the recent European Commission opinion within this Balanced Approach framework. As the Minister has already limited this ban to night operations based on that opinion, RSG is not authorised to impose a broader ban (e.g., during the day). Only once the ministerial regulation takes effect may RSG reflect the night-time ban in its airport charges and conditions.

The other new charges and conditions came into effect on 1 April 2025. The appeal period for the airport charges decision will expire shortly.

 

Capacity reduction at Schiphol

As noted above, the European Commission recently issued its decision on the Dutch government’s notification under the Balanced Approach procedure for Schiphol. This decision followed the State’s proposed measure to structurally reduce aircraft movements at the airport in order to limit noise pollution.

In 2023, the Minister of Infrastructure and Water Management introduced an experimental scheme (the so-called Experimenteerregeling Schiphol), aimed at reducing noise nuisance around the airport. The Scheme abandoned the ‘New Standards and Enforcement System’ used since 2010 — which prioritised the use of runways that generate the least noise — and instead reverted to the older system under the Schiphol Airport Traffic Decree (Luchthavenverkeersbesluit, LVB”), which defines specific ‘enforcement points’ near the runways. Under the Experimental Scheme, the maximum number of aircraft movements at Schiphol was set at 460,000 per year, instead of the previous 500,000. Because this was framed as an experiment and a reversion to existing legislation, the Minister argued that the consultation procedure outlined in the Balanced Approach Regulation did not need to be followed.

The aviation sector strongly opposed this reasoning. Multiple airlines initiated legal proceedings against the Dutch State (and RSG). Following judgments by the North Holland District Court and the Amsterdam Court of Appeal, the Dutch Supreme Court definitively ruled in July 2024 that the Experimental Scheme did constitute an ‘operating restriction’, for which the Balanced Approach must be followed. In short, the Supreme Court held that the State must first consult stakeholders and identify the noise problem before introducing any restriction. The Noise Regulation is not intended to support a reduction process as such, but rather to ensure effective noise abatement through the selection of the most appropriate and cost-effective measures, based on quantitative evidence.

While these court proceedings were still ongoing, the Minister commenced the consultation process with the European Commission. Initially, the Minister proposed reducing annual aircraft movements to 440,000, but later revised the figure to a cap of 478,000 movements per year.

As part of the Balanced Approach procedure, the European Commission issued its opinion on 5 March 2025. It concluded that the Dutch government had failed to sufficiently assess alternative measures, such as fleet renewal, before imposing a restriction which should be seen as a measure of last resort. The Commission also criticised the analysis for focusing only on commercial aviation, omitting general and business aviation (such as private and emergency flights). Furthermore, the Commission expressed concern about the lack of transparency in how future take-off and landing slots would be allocated. Reducing the number of aircraft movements inevitably means that some airlines must relinquish their so-called ‘historic slots’ under the EU Slot Regulation. In 2023, Airport Coordination Netherlands (“ACNL”) had already issued a policy rule explaining that in the event that available slots fall short of the total number of historic rights, slots will be allocated based on proportionality (see Policy Rule Slot allocation in case of exceedance of historic rights).

Despite the Commission’s partially negative opinion, the Dutch State proceeded with the capacity reduction. In response, several airlines and organisations initiated fresh legal proceedings. On 23 April 2025, the North Holland District Court declared these parties inadmissible in civil summary proceedings, stating that they could seek redress against the final LVB amendment through the administrative courts.

On 6 May 2025, the Minister officially published the amended Schiphol LVB, establishing a structural limit of 478,000 aircraft movements per year, including a maximum of 27,000 night-time movements. The decision will enter into force on 1 November 2025.

Administrative proceedings against this decision are still ongoing. The case is now before the highest administrative court (the Administrative Jurisdiction Division of the Council of State), which is expected to issue a final decision soon. The hearing is scheduled for Thursday 24 July 2025.

Meanwhile, RSG has already incorporated the new cap into its Capacity Declaration for the IATA Winter 2025/2026 season, published on 8 May. Based on this, ACNL will proceed with slot allocation this summer. In the meantime, with the expected final judgment on the capacity reduction still pending, it remains to be seen whether the final judgment will and can lead to any last minute changes in the slot allocation.

 

Intensified Regulation on Noise and Emission

Sustainable Aviation Fuel

In addition to noise reduction, lowering emissions and encouraging the use of more sustainable fuel remain key objectives. At the end of 2023, the European Parliament and the Council adopted the ReFuelEU Aviation Regulation (2023/2405), aiming to gradually increase the use of sustainable aviation fuel (“SAF”) at EU airports. From early 2025, fuel suppliers are required to blend at least 2% SAF into regular kerosene. This share will rise to 6% by 2030, 20% by 2035, and ultimately 70% by 2050. Furthermore, airlines are obliged to refuel at least 90% of their fuel requirements at their departure airport — preventing the circumvention of SAF obligations via so-called ‘tankering’ (carrying excess fuel from airports without such rules).

Tightening of Market Mechanisms

In line with these developments, the European Commission published a proposal in April 2025 to update the rules for monitoring, reporting and verification under the EU Emissions Trading System (“EU ETS”). The EU ETS is a market-based instrument designed to limit CO₂ emissions from various sectors, including aviation, by allocating emission allowances that companies can buy, sell or trade. By putting a price on emissions, the system encourages cost-effective reductions.

This update also aims to improve alignment with the international Carbon Offsetting and Reduction Scheme for International Aviation (“CORSIA”), developed by the International Civil Aviation Organization (“ICAO”). CORSIA similarly targets emissions from international flights through a market mechanism.

The proposed changes simplify how airlines report the use of SAF (where covered by CORSIA), as well as how they submit and verify reports for cancelling emission allowances. Definitions are also being clarified to better align with other new initiatives such as ReFuelEU.

Stricter standards for new aircraft

Furthermore, in March 2025 the ICAO member states reached agreement on a new set of binding global standards for fuel efficiency and noise reduction for newly certified aircraft. Awaiting formal adoption by the ICAO Council, the member states have agreed that certain noise standards will apply to aircraft certified from 1 January 2029, and certain fuel efficiency standards will apply from 31 December 2031. New commercial aircraft certified after these dates must meet global CO₂-standards requiring at least a 10% improvement in fuel efficiency compared to current standards. Compared to aircraft designs from the year 2000, new aircraft must be approximately 35% more efficient. Additionally, from 2029, aircraft must be at least 6 decibels quieter, equating to a 30% reduction in noise emissions.

 

Conclusion

With rising airport charges and increasingly demanding sustainability obligations, airlines and airport operators find themselves in an ever more complex and regulated environment. Meanwhile, the uncertainty surrounding Schiphol’s future capacity limits continues to cloud investment planning and long-term strategy. Now that the amended Schiphol Airport Traffic Decree has been formally published, a final decision on capacity reduction is in reach. This should provide greater clarity for all stakeholders across the travel sector in the near future. All in all, with Schiphol as a crucial economic hub, the airport remains an important public facility for Dutch travellers, and the travel sector continues to form a key pillar of the Dutch economy.

Vision

Private enforcement of the DMA: a lawyer’s paradise (or not)?

On 23 April 2025, the European Commission (“Commission”) imposed the first fines on gatekeepers for non-compliance with the Digital Markets Regulation, or ‘Digital Markets Act’ (“DMA”). Apple and Meta were fined €500 million and €200 million respectively. Apple violated the “anti-steering” obligation under the DMA; Meta violated its obligation to grant consumers the choice of a service that uses less of their personal data.

Although the obligations for so-called “gatekeepers” under the DMA have been in force since 7 March 2024, so far the focus has been on public enforcement of the DMA. With the Commission’s first non-compliance decisions, the important question arises what options are available for private enforcement of the DMA by victims. This blog provides an overview of the different remedies under (Dutch) civil law.

Overview

Relevant preliminary questions: direct effect and application of competition law concepts

An important preliminary question in the private enforcement of the DMA is whether private parties, such as natural persons (i.e., consumers) or legal persons (customers, competitors, etc.), can invoke the rights and obligations of the DMA against gatekeepers. This is only possible if there is horizontal direct effect.

This requires that the provisions of the DMA are sufficiently precise and unconditional to confer rights on individuals. This appears to be the case. The obligations under the DMA – as set out in particular in Articles 5, 6 and 7 of the DMA – do not require further detailed or implementing measures from the EU Member States. The fact that the obligations under the DMA have horizontal direct effect also appears to have been expressly intended by the EU legislator, given the explicit possibilities in the DMA for cooperation between the Commission and national courts in national proceedings (Article 39 DMA) and the inclusion of collective redress mechanisms (Article 42 DMA).

Another preliminary question concerns the relevance of competition law concepts in the application of the DMA. Although the DMA does not form part of generic competition law, it nonetheless shares several areas of overlap with (ex post) competition law enforcement. For example, a number of provisions in the DMA are substantively inspired by recent competition cases. Take for instance the prohibition of self-preferencing stipulated in Article 6(2) of the DMA and the recent competition law case concerning Amazon, or the prohibition of self-preferencing in the context of rankings as laid down in Article 6(5) of the DMA and the Google Shopping case.

Furthermore, the EU legislator seems to have deliberately aligned the definitions in the DMA with competition law. One of these is the concept of an undertaking. An undertaking within the meaning of the DMA is an entity engaged in an economic activity, regardless of its legal form and the way in which it is financed, including all affiliated undertakings or undertakings that form a group through the direct or indirect control of an undertaking by another. This concept is also used in competition law, in contrast to corporate law where terms such as “legal person” are used. The term “connected undertakings” used in the DMA is also consistent with its definition in other areas of law related to competition law, such as (European) State aid law.

It therefore appears that the DMA is in line with the competition law concept of an undertaking. This is important because this concept defines the group of entities that can be held (jointly and severally) liable. A relevant question is how this relates to the broad designation decisions, in which the Commission designates both the (ultimate) parent company, together with all its subsidiaries, as gatekeepers that must comply with the obligations of the DMA. For example, the designation decisions in respect of Alphabet stipulate that “Alphabet Inc., together with all legal entities directly or indirectly controlled by Alphabet Inc.” as such has been designated as gatekeeper. It can therefore be argued that all these entities are subject to the obligations under the DMA since they are included in the designation decisions. This could mean that each of the entities belonging to, in this case, Alphabet Inc. could be held directly and separately liable for (damages resulting from) non-compliance with the DMA.

However, whether this is the case remains unclear at this stage and is expected to be the subject of discussion before the national and European courts. Lastly, general principles of EU law relevant to the private enforcement of competition law, such as the principle of effectiveness, remain (also) fully applicable to the private enforcement of the DMA.

Jurisdiction of Dutch courts

The jurisdiction of (Dutch) courts is also a pivotal aspect of private enforcement. The international jurisdiction of the Dutch courts is determined pursuant to Brussels I bis (for defendants within the EU) or the section on private international law laid down in Articles 1-14 of the Rv (for defendants outside the EU and within the Netherlands). In both cases, the main rule is that the court of the defendant’s place of residence has jurisdiction.

In this respect, it is again relevant which entity or entities are designated as gatekeepers. As discussed above, these are the ultimate parent companies together with all their (direct and indirect) subsidiaries. This would mean that the Dutch court has jurisdiction to rule on claims brought under the DMA against a Dutch entity that is part of the designated gatekeeper under the main rule in Article 2 Rv. After all, that Dutch entity is being sued on the basis of its own “gatekeeper status”. An alternative would be to sue the (ultimate) parent company for its violations of the DMA and to base the jurisdiction of the Dutch court on special grounds of jurisdiction, such as the “anchor defendant rule” in Article 8 of Brussels I bis (cf. Article 7 of the Dutch Civil Procedure Act) or the “Erfolgsort/Handlungsort” in Article 7 of Brussels I bis (cf. Article 6(e) of the Code of Civil Procedure).

The anchor defendant rule entails that, in the event of multiple defendants, these defendants may be summoned to appear before the court of the seat of one of them (the anchor defendant). The idea is that the parent company (as gatekeeper) is sued in the Dutch courts together with its subsidiary established in the Netherlands (as anchor defendant). This requires that the anchor defendant be in the same position, in fact and in law, as the other defendant(s). In preliminary ruling proceedings, the CJEU emphasised that a parent entity can act as an anchor defendant if it controls virtually all the capital of the infringing subsidiary. Advocate General Kokott recently concluded more generally that the same factual and legal position exists when the anchor defendant belongs to the same undertaking as one of the other (infringing) defendants. The concept of an undertaking is explained in the Sumal judgment on the basis of two criteria: (i) the existence of legal, economic and organisational links and (ii) the existence of a concrete link between the economic activity of the entity in question and the subject matter of the infringement. If the DMA does indeed align itself with the competition law concept of an undertaking, international jurisdiction law must also be interpreted accordingly.

Alternatively, the jurisdiction of the Dutch court may be based on the (special) ground of jurisdiction under Article 7 of Brussels I-bis (cf. Article 6(e) of the Dutch Code of Civil Procedure). On that ground, the court of the place where the damage occurs or may occur has jurisdiction. This includes both the place where the damage occurs (Erfolgsort) and the place where the harmful event giving rise to the damage takes place (Handlungsort). The Erfolgsort is often linked to the place of residence or registered office of the victim of the infringement. Of particular interest in this regard are the preliminary questions referred by the Amsterdam District Court in the context of the application of jurisdiction rules in a digital context. The case concerns damages claims brought by three foundations on behalf of (Dutch) consumers as a result of Apple charging excessive commissions in its App Store. In that case, the court considered that for most users both the Handlungsort and the Erfolgsort were located in the Netherlands, because Apple specifically targets the Dutch market with its Dutch App Store. Consequently, the place where the harmful event occurred (charging excessive commissions) is therefore in the Netherlands. Preliminary questions on this interpretation are currently pending before the CJEU.

Follow-on or stand-alone

Civil proceedings against a gatekeeper may be brought on a stand-alone or follow-on basis. In a follow-on case, there is already a decision by the Commission establishing an infringement of the DMA by the gatekeeper. The unlawfulness of the conduct in question is therefore given; pursuant to Article 39 of the DMA, the national court may not deviate from the findings in that decision. The national civil proceedings then follow, as it were, on the Commission’s infringement decision. In a stand-alone case, on the other hand, the claims are brought without the existence of a prior infringement decision. the claimant will thus have to substantiate the actual conduct and its unlawfulness. In this context, it is relevant that Article 8 of the DMA leads to a reversal of the burden of proof in a public law context, as this article provides that the gatekeeper shall monitor and provide evidence of compliance with the obligations under Articles 5, 6 and 7 of the DMA. How this relates in practice to civil evidentiary law as laid down in Articles 149 and 150 Rv remains to be seen. Finally, it is important that, certainly in stand-alone cases, the national court always has the possibility to stay the proceedings, for example if the Commission initiates an investigation into the conduct in question while the national proceedings are (still) pending (Article 39(5) DMA). The Commission also has the option of joining a case as an amicus curiae (Article 39(3) of the DMA).

The existence of an infringement decision, as in the Meta and Apple cases, generally facilitates private enforcement. In the context of the DMA, it is relevant that the opening of an investigation into a gatekeeper’s compliance with the DMA also qualifies as a decision (Article 20 DMA). This is in contrast to competition law, where the opening of an investigation and the notification of objections are not formal decisions. The Commission has already taken a number of decisions against gatekeepers, launching investigations into their compliance with their obligations under the DMA. These investigations concern, among other things:

However, the value of these decisions to open an investigation for national civil proceedings seems limited as such. The decisions are relatively short and only describe the facts, such as the adjustments made by the gatekeeper that prompted the Commission’s investigation. The Commission also expressly states that the opening of an investigation does not prejudge the (il)legality of the conduct and the gatekeepers’ compliance with the DMA. For this reason, the limitation period will not start to run when a decision to open an investigation is taken. Such decisions do not contain any findings of unlawful conduct. For example, the Commission has since withdrawn a number of investigations, such as the investigation into Apple’s obligations regarding the possibility of removing apps and changing default settings within Apple’s iOS (Article 6(3) of the DMA).

However, it is possible to initiate civil proceedings pending the DMA investigation. Given the substantive overlap between the DMA and certain forms of abuse under Article 102 TFEU, it is therefore generally conceivable that proceedings could be brought against a gatekeeper on the basis of both the DMA and Article 102 TFEU. This could then be partly a stand-alone and partly a follow-on case, if a fine has already been imposed under the DMA or competition law. Involving competition law in a case concerning (alleged) DMA infringements has a number of advantages. The existence of a non-compliance decision under the DMA may make it easier to demonstrate an infringement of competition law and vice versa. It may also influence the amount of damages, as unlawful conduct under the DMA is limited in time (at most from March 2024), whereas the unlawfulness due to a breach of competition law may have continued for longer. This also makes it more attractive for litigation financiers to finance large cases against gatekeepers. Conversely, the decision to open a DMA investigation or a DMA infringement decision may be useful in determining the group of entities that are jointly and severally liable for the damage resulting from a competition decision.

Various possibilities for private enforcement

Victims of DMA infringements have various legal remedies available to them in the Netherlands.

Injunction or prohibition

Victims of DMA infringements can seek an injunction or prohibition against the gatekeeper. This can be done both in proceedings on the merits and before the preliminary relief judge in summary proceedings (Article 254 of the Code of Civil Procedure). A penalty payment may also be requested as an (additional) means of pressure. An urgent interest in the requested provisional relief is required.

Interim relief is particularly relevant when the gatekeeper’s unlawful conduct causes irreversible or difficult-to-recover damage to the victim, such as damage to the victim’s competitive position. Consider, for example, an order against the gatekeeper to achieve interoperability (Article 6(7) DMA) or to grant access to certain data (Article 6(10) DMA). A prohibition may be necessary, for example, where a gatekeeper competes on its platform with its business users and in doing so uses non-public data generated by those business users (self-enforcement), in breach of Article 6(2) of the DMA. If the Commission has already issued a non-compliance decision and the gatekeeper has not (yet) complied with that decision, it is likely that the interim measure will be granted. This is because the unlawfulness is then established and the national court is not permitted to deviate from the Commission decision pursuant to Article 39(5) of the DMA. However, even if no non-compliance decision has been taken, the obligations under the DMA can be enforced through the courts.

Of course, claiming an injunction or prohibition may be accompanied by a declaration for the court to rule on the matter and/or a claim for damages.

Damages

If damage has been suffered as a result of a breach of the DMA, damages may be claimed.

By violating the obligations under the DMA, the gatekeeper is acting in breach of a legal obligation (Section 6:162 of the Dutch Civil Code), for which both the damage suffered and the loss of profit can be claimed. Naturally, a declaration of law and/or an injunction can be sought as well.

As with competition law, quantifying the damage can be complex. This is often due to the complex (technical) market forces at play, which make it difficult to determine the correct counterfactual scenario. In addition, some obligations under the DMA relate to violations of data use, which is also complex to quantify as (monetary) damage. Finally, with regard to the quantification of damage, the obligations under the DMA will only take effect from March 2024 and the damage will therefore still be (relatively) minor. In that context, it may be useful to base claims for damages on generic competition law (Article 102 TFEU), as those obligations have been in force for some time and the unlawfulness has therefore persisted for longer.

When claiming damages for violations of the DMA, it is interesting to bundle claims. It is likely that gatekeepers’ conduct will quickly affect many parties simultaneously, from consumers to customers and competitors. In such cases, it is more efficient to bundle all claims, which are likely to be largely similar. This can be done using the “assignment model”, whereby a group of victims transfers their claims to a claim vehicle such as a foundation, for example by means of a power of attorney or assignment. The foundation then acts on behalf of these parties. If there is a large, perhaps not yet defined group of victims, initiating a collective action is a useful option for claiming damages (or possibly a declaration of law or an injunction).

Collective action

Under the WAMCA (Article 3:305a of the Dutch Civil Code), it is possible to claim damages in a collective action. Collective actions usually concern mass damage cases involving financial loss, but in principle the case may also have an intangible objective and relate, for example, to unlawful data use.

In a collective action, a foundation initiates proceedings in which it represents the interests of individuals. A number of admissibility requirements are imposed on this foundation, including in the areas of governance, financing and representativeness. See also this overview blog about the WAMCA and the process of a collective action.

As noted above, the European legislator has deliberately taken into account the possibility that violations of the DMA by gatekeepers may affect a large group of consumers. For this reason, Article 42 of the DMA declares the Directive on representative proceedings for the protection of collective consumer interests (2020/1828) applicable to the DMA. Most of the provisions of that Directive did not lead to any (significant) changes in the Netherlands, as they already applied through the WAMCA. What is new is that the Directive operates with a “list system” for representatives who wish to operate across borders and submit cross-border consumer claims. Member States must draw up a publicly accessible list of interest representatives (known as “competent bodies”) for cross-border claims. This list will then be forwarded to the European Commission. With this Directive, and its explicit application to (violations of) the DMA, it is possible to initiate domestic and cross-border collective actions on behalf of consumers against gatekeepers. For more information on how Directive 2020/1828 works, see this blog.

Conclusion

Whereas in the past year, since the entry into force of the obligations under the DMA, the focus has been mainly on public enforcement, the arrival of the first non-compliance decisions has (further) opened the door to private enforcement.

Although there is still some uncertainty about the exact scope and application of the DMA in national civil proceedings, it is clear that there are opportunities. Private enforcement of the DMA in the Netherlands is still in its infancy, but offers promising opportunities for market players to strengthen their position and enforce a level playing field, and for customers and consumers to safeguard their rights.

 

If you have any questions about the DMA and the possibilities for its enforcement, please contact Bas Braeken, Timo Hieselaar or Jade Versteeg.

Vision

ACM tightens supervision on pricing policies and fake reviews

Since the merging of the competition and consumer protection authority in 2013, the Dutch Authority for Consumers and Markets (“ACM”) has increasingly emphasised its role as a consumer watchdog. In this capacity, the ACM has intensified both its formal and informal supervision of B2C traders, especially in the field of e-commerce. Alongside a longstanding track record of penalising misleading and aggressive commercial practices, the ACM has recently shifted greater attention to the pricing strategies employed by online merchants, such as the use of fake discounts, the use of fake reviews and other aspects of ‘fair design’. Since 2022, stricter rules have applied to online sales, including the use of customer reviews. In addition, new rules on the display of discounts came into force from 1 January 2023, which are strictly enforced by the ACM. This blog deals specifically with this branch of consumer supervision, which continues to evolve rapidly.

Supervision on manipulative practices

For some time now, the ACM has been reprimanding online retailers for a lack of transparency, including on terms of sale (JD, Aliexpress, Vinted), terms of use (WhatsApp, Fletcher) and subscription terms (Museumjaarkaart, HelloFresh, Knaek, On that ass). However, the ACM believes that the current level of consumer protection in the digital environment remains inadequate and continues to actively address both existing and emerging forms of unfair commercial practices.

First of all, in 2022, the ACM published an update to its Guidelines on the Protection of the online consumer incorporating the Consumer Protection Modernisation Directive. Based on this directive, consumers should for example not be given the impression that they have to make a quick decision to buy something through the use of a countdown timer. Also, cancelling a subscription should be as easy as taking it up, and a consumer should not be misled in a ranking of results where certain companies have paid for a higher position. Last summer, Panteia published its research into compliance with the Guidelines on behalf of the ACM. It showed that while many online retailers are aware of the existence of consumer protection rules, they often consider the likelihood of the ACM detecting a breach to be relatively low. It also emerged that many online shops delegate the design of their websites to third parties. The ACM, however, emphasises that the webshop owner remains ultimately responsible for any violations.

During the same period, the ACM advocated for stricter (European) rules for consumer protection, including measures to ensure fair design and to limit personalised offers. Consumer protection in online sales is also a priority for the European Commission. For example, the Commission investigated manipulative practices in online shops and found that approximately 40% was engaging in such behaviour. Common practices included the use of fake countdown timers, concealing crucial information, and steering consumers towards specific choices.

Such investigations prompt EU consumer authorities, such as the ACM, to jointly roll out a unified policy and continue with (tightened) supervision of online consumer protection. In this blog, we discuss a selection of key developments from the ACM’s recent decision-making practice.

 

From/to prices: unclear legislation on unclear discounts

The ACM seems to be on a mission to make discounts as transparent as possible for consumers. It previously intervened against online sales platform Wish for using fake discounts. With the introduction of the Commission’s Guidance following the European Directive on the indication of the prices of products and its Dutch implementation in the Decree on Product Price Indication, the ACM has been closely monitoring several e-commerce sectors. The new rules require online retailers to display the discounted price only in relation to the lowest (‘from’) price in the past 30 days. This is to prevent online shops from artificially raising their prices and then offering a fake discount based on that inflated price, misleading consumers into thinking they are getting a better deal.

Some exceptions apply, for example for perishable products and other short-lived products, as well as for stacking discounts. When a product price is progressively reduced over a 3-month period consecutively – from 30% to 50% to, say, 70% off – the discount may be shown relative to the price that applied at the start of the sell-out period, even if more than 30 days have passed. However, no exceptions are made for typical or legitimate temporary discounts. For instance, the ACM recently reaffirmed that a temporary Black Friday discount must be shown relative to the lowest price 30 days prior. Similarly, a new discount offer within 30 days after Black Friday must be shown relative to the Black Friday price, not the standard or original price.

In the spring of 2024, following several general ‘warnings’ on its website, the ACM fined several larger online shops in the field of clothing, consumer electronics and bedding shops for incorrectly stating discounts. The ACM monitored the price movements of 10 to 15 selected products at several large webshops over a three-month period. The fining decisions show that in calculating the fine, the ACM takes into account whether there was an artificial temporary increase in price (fake discount) or erroneous discount prices that were actually applied before (legitimate discount). In the latter case, the ACM imposed a fine at the lower end of the applicable fine range. Moreover, the ACM took into account the relatively recent entry into force of the legislation by reducing the fines by 33%. Nevertheless, given their size – and despite the cooperation of three webshops in simplified settlement and capacity defences – substantial fines ranging from € 110,250 to € 176,250 were imposed.

No fines were issued for four companies investigated because the ACM’s inquiry found no actual violations or because the number of violations was fewer than four (the ACM decided to impose penalties only when there are more than four violations). Two webshops did not opt for the simplified procedure in exchange for a 10% fine reduction. While it is understandable that the ACM would prefer to handle seemingly straightforward infringements in a simplified way, it is not always advisable to admit fault and waive the right to appeal, especially when the standard has not been previously tested by the courts. After all, there is a chance that a(n) (administrative) court may come to a different interpretation than the ACM. Additionally, questions often arise in such proceedings about whether the decision complies with the general principles of good governance, such as whether imposing a fine immediately is proportionate or whether selectively fining certain webshops violates the principle of equality. One of the fined companies (Day Traders (Koopjedeal)) lodged an objection, arguing that the ACM had violated various principles of good governance. While the ACM rejected the objection, it will be interesting to see how the administrative court views the case.

Although the ACM initially proclaimed that the ‘standard’ is rather clear, in practice there still appears to be significant room for differing interpretations. For instance, while it is still permissible for online shops to display the recommended or original price in addition to the discounted price, they must not falsely imply that the discount is based on that price. For example, in the Aldi/Süd judgment, the Court of Justice ruled that the discount percentage may only be calculated in relation to the lowest price in the past 30 days, not in relation to an older (recommended) price. However, how this is implemented remains open to debate.

It seems that the ACM also recognised the need for further clarification. At a symposium in early November 2024, it took the view that – when displaying a reference price (such as a recommended retail price, a RRP (recommended resale price) or ‘original price’) –  it should always be clearly visible and static (not hidden behind an ‘i’ symbol) what that price represents. The ACM also stated that if an item is on sale for an excessively long time, continuing to present it as a discounted item could potentially be considered misleading. The determination of what constitutes an ‘excessive’ period will be assessed on a case-by-case basis, considering factors such as whether the product is seasonal.

During this symposium, the ACM announced that it is working to incorporate these principles into new guidelines, in cooperation with other European consumer authorities within the Consumer Protection Cooperation (“CPC”). Once these guidelines are published, it is likely that the ACM will again scrutinise online shops and launch a new round of enforcement.

Meanwhile, the ACM and other national consumer authorities have already taken action against the web shop Temu for, among other things, using fake discounts, countdown clocks, and scarcity claims.

 

Dynamic pricing

In addition to tackling fake discounts, the ACM has long been focused on ensuring transparent pricing, particularly in the telecom, travel, and used car sectors. For example, hiding costs behind an ‘i’ symbol is not acceptable to the ACM, and all unavoidable costs must be included in the total price.

A new focus in the ACM’s policy is addressing so-called price fluctuations in the travel industry. When selling package holidays, especially when they are put together virtually, a variety of travel elements from different suppliers are offered as a single package. The price of such packages can fluctuate regularly due to factors like increasing flight prices or sold-out room types. The ACM challenged several travel providers over this practice and ultimately imposed orders subject to periodic penalty payments on three of them.

However, in the preliminary injunction proceedings brought by these three providers, the orders for periodic penalty payments were suspended. The preliminary relief judge questioned whether the price fluctuations amounted to a misleading omission. The court noted that the ACM applies a different (stricter) interpretation of the rules on price displays in the travel sector than the European Commission in its Guidelines on the Unfair Commercial Practices Directive, as well as the Advertising Code Committee and its Board of Appeal, which all recognise the possibility of sudden price changes. This highlights that the ACM’s interpretation of broad standards does not always hold up in court.

Moreover, the court sided with the travel agents’ argument that the average consumer would not make a different decision about a contract based solely on possible price changes at the beginning of the search and booking process. Lastly, the court questioned whether the travel agents’ conduct distorted competition and whether enforcement was proportionate in this case.

 

Fair design: from fake reviews to fake countdown timers

The ACM considers the protection of digital consumers through ‘fair design’ to be a key strategic priority. Earlier, the ACM hosted a symposium on fair design in e-commerce, focusing on online influence tactics using so-called ‘dark patterns’. For instance, the rules on online influencing dictate that only the real order of search results and filters and reliable reports on availability and popularity may be shown. Explanations must be provided for personalised offers, and offering something ‘free’ cannot require payment in the form of personal data.

The ACM, in collaboration with consumer organisations and government bodies such as the police, launched an awareness campaign encouraging online shoppers to verify the reliability of unfamiliar websites by checking reviews first. According to research, 50% of consumers encounter problems when shopping online each year. The importance of reviews means consumers must be able to trust their authenticity.

The ACM already had the power to act against the use of fake customer reviews and, since mid-2022, has been empowered to take action against the sale of fake reviews. In August 2024, the ACM already issued a general warning on its website, which may soon be followed by specific enforcement actions.

Previously, the ACM has also taken informal action against the use of fake likes and fake followers on social media. For instance, in March 2022, it forced six influencers to stop using fake likes and followers. In summer 2023, the ACM also addressed dozens of online shops using misleading countdown timers. In that context, the ACM carried out an automated check of thousands of online shops, discovering at least 41 instances where, after a countdown timer expired, the same price was still available and a new timer began.

 

Look ahead

The ACM is increasingly expanding its consumer protection supervision, focusing on more subtle forms of (online) deception. With its enhanced digital detection capabilities, the ACM can easily monitor sector-wide compliance with consumer protection rules. While the ACM’s approach has been largely through informal discussions, giving online shops the chance to adjust their behaviour without imposing a sanction, this is not guaranteed. When the ACM considers the standard to be clear, when sufficient warnings have been issued, and/or when consumer harm is significant, the ACM may impose sanctions, including incremental penalty payments or direct fines. These fines can quickly amount to tens or even hundreds of thousands of euros for larger online shops. It is therefore crucial for businesses to stay well informed about developments in consumer protection regulations and ensure compliance without negatively impacting their operations.

 

If you have any questions about consumer protection or the powers of the ACM, please contact one of our specialists.

Vision

Flash Forward Merger Control 2025

With the festive season approaching, we look ahead to what the new year will bring in the field of merger control. In this first edition of the Flash Forward Merger Control 2025, we take you through some of the key developments that await us in 2025 and that will potentially affect your practice and clients.

In this short newsletter, we provide insight into the potential consequences of the intended repeal of the Article 24(2) of the Dutch Competition Act (“Mw”) which stipulates that a merger cannot amount to an abuse of dominance, and the possible additions to the competition law toolbox of the Dutch competition authority (“ACM”). We also discuss the expected extension of the scope of application of the Act on security screening of investments, mergers and acquisitions (Vifo Act”), and the possible introduction of a sector specific investment screening test for the defence industry.

 


Acquisition by dominant undertaking may soon constitute abuse dominant position

An important intended amendment is the repeal of Article 24(2) Mw, which currently precludes the application of the national prohibition on abuse of a dominant position to mergers. This exemption to the abuse prohibition is at odds with the Towercast judgment of the Court of Justice of the European Union (“CJEU”). In that judgment, the CJEU ruled that Article 102 of the Treaty on the Functioning of the European Union (“TFEU”)- the European prohibition on abuse of a dominant position – can indeed apply to concentrations that fall below the notification thresholds. The Dutch Article 24(2) Mw is currently blocking the application of this principle in purely national situations. Repealing this section achieves harmonisation with European competition law and realigns the national and European frameworks.

The legislative amendment means that in the future, the ACM can also retrospectively investigate transactions that were not subject to any notification obligation based on the turnover thresholds applicable for merger control, but where the acquiring party may have abused its dominant position with the transaction. This gives the ACM an additional tool to assess mergers and acquisitions that potentially raise competition law concerns. For M&A lawyers, this means that the risk of ex post interventions increases, even for transactions that are not notifiable. In the future, it will therefore not only be important to check the notification thresholds, but also to determine whether the buyer might have a dominant position and analyse the risk of a potential review under Article 24 Mw and/or Article 102 TFEU.

Following a positive opinion from the Council of State on 5 June 2024, the proposal was submitted on 11 June 2024. The standing committee on Economic Affairs reported on the proposed legislative amendment on 7 October 2024. On 23 October 2024, the Minister of Economic Affairs (“Minister”) requested an postponement for his response to that report. Although no date has yet been set for the entry into force of the amendment, this is expected to happen in 2025.

back to top


Legislative proposal investment screening test suppliers defence industry

Another legislative proposal that is currently pending relates to the introduction of an investment screening test specifically aimed at the defence industry. This proposal aims to strengthen, protect and better position the strategic and vital standing of the Dutch defence industry on an international level. The proposed act inter alia concerns a new sectoral screening test focusing on investments, mergers and acquisitions in the armed forces’ supply chain, including suppliers of military goods and transport. By doing so, the government aims to prevent these investments, mergers and acquisitions from endangering national security by, among other things, establishing notification requirements and approval procedures for acquisition activities that could affect the continuity of defence capabilities.

This investment test is expected to replace the current test for military goods under the Vifo Act, while complementing it by focusing on a broader group of target undertakings, namely those suppliers that are essential to the vital process of ‘Deployment Defence’ – or, in other words, the “ability of the armed forces to perform its tasks while acting with a degree of autonomy.” Suppliers are currently only covered by the Vifo Act when it comes to highly sensitive technologies. This means that the test for the defence industry will be broadened and specifically tailored to the unique requirements of the sector. The act also contains a number of provisions similar to the Vifo Act, such as a notification requirement, a standstill obligation and the possibility of imposing approvals or nullity sanctions.

The internet consultation has been completed this fall. The proposal is expected to receive further consideration in 2025.

back to top


Extending scope of application Vifo Act to new sectors

The Vifo Act, which came into force on 1 June 2023, allows the government to review investments and acquisitions of vital companies and providers of sensitive technologies for risks to national security (see also our first and second Competition Newsflash on the Vifo Act). In light of the rapidly changing geopolitical situation, a legislative proposal is pending to further extend the scope of the Vifo Act to new sectors and technologies. The explanatory memorandum explains that this extension aims to further safeguard the national security of the Netherlands.

The proposed act concerns an amendment to the Decree on the Scope of Application of Sensitive Technology, which regulates which sensitive technologies fall within the scope of the Vifo Act. The proposal sees the addition to that decree of biotechnology, artificial intelligence, advanced materials and nanotechnology, sensor and navigation technology and nuclear technology with medical use. In February 2024 a motion was carried requesting that the Dutch vegetable and seed breeding sector be included in the scope of the Vifo Act, given its crucial role in food security and innovation. The vegetable and seed breeding sector was nevertheless not included in this proposal.

For M&A lawyers, this development means that mergers and acquisitions in an increasing number of sectors may be subject to national security tests. This requires an even sharper analysis of transaction risks, timelines and notification requirements when clients operate in or are involved in vital or strategic sectors.

The internet consultation on the proposal will take place from 19 December 2024 to 31 January 2025. The proposal will then be submitted to the Council of State to deliver its opinion. The Ministry of Economic Affairs considers it possible that the act could then enter into force in the second half of 2025.

back to top


Call-in power non-notifiable transactions

An expected extension of the ACM’s powers concerns the so-called call-in power. This addition to the ACM’s toolbox aims to deal with transactions that do not meet the current turnover thresholds but still (potentially) raise competition law concerns. The ACM refers to large companies that gain or increase their market power through successive small acquisitions (roll-up acquisitions), or so-called killer acquisitions, where companies with a strong market position acquire potential competitors to prevent (or: ‘kill’) future competition. These transactions now remain largely outside the ACM’s supervision, which in certain cases can be detrimental to competition. The introduction of a call-in power would allow the ACM to assess transactions falling below the turnover thresholds if they raise competition concerns.

The ACM has stated on several occasions that it considers the introduction of a call-in power necessary. On 4 September 2024, a motion on its introduction was carried in the House of Representatives. The Minister has promised to study the potential introduction of the call-in power and present the results as well as possible legislative proposals in 2025.

back to top


Introduction New Competition Tool

In addition to adjustments to traditional competition instruments, such as the prohibition on abuse of a dominant position, the New Competition Tool (“NCT”) is gaining ground as an addition to the ACM’s current toolbox. This tool allows competition authorities to intervene in case of market failure, without there having to be a breach of competition law. Market failures, for example caused by specific market characteristics or the behaviour of companies, can lead to a lack of effective competition and can disadvantage consumers. For example, the ACM recently brought out a report on the savings market and found that limited competition led to low savings rates. Other than finding that (in its view) there is market failure, the ACM cannot currently intervene in such situations. With the NCT, regulators can address the cause of such problems and actively reform the market structure to promote healthy competition.

Unlike existing competition rules, the NCT does not focus on individual breaches or “wrongdoing” of undertakings, but on structural problems in the market that impede competition. The tool enables preventive action and faster intervention in the face of impending competition concerns. In doing so, regulators can take drastic steps, such as opening up markets or limiting market power. The UK Competition & Markets Authority has had similar powers for some time. The ACM is now actively advocating the introduction of an NCT in the Netherlands. For M&A lawyers, this would mean that market investigations by the ACM could be more frequent and new intervention measures could impact markets in which their clients operate, even without any wrongdoing.

Currently, the introduction of an NCT in the Netherlands is mainly a desire expressed by the ACM. The minister has promised to study the possible introduction of an NCT. The results of this study, as well as any legislative proposals, are expected in 2025.

back to top


 

Thank you for reading this first edition of the Flash Forward Merger Control and we wish you happy holidays and a successful new year!

 Team Competition – bureau Brandeis

Bas Braeken – Jade Versteeg – Lara Elzas – Timo Hieselaar – Demi van den Berg –  Joost van Belois

Vision

AI turns the world of competition law on its head

Introduction

Artificial Intelligence (“AI”) is booming. In San Francisco, robot taxis from Waymo, a subsidiary of Google’s parent company Alphabet, are already driving with great success. Siri and Alexa have become part and parcel of our daily lives. The vast majority of companies have equipped their products with AI to create smart technologies and services. Such as robots putting together packages for Zalando, ChatGPT from OpenAI, chatbots as customer service and AI in cancer detection. Companies are investing heavily in AI. According to the Financial Times, the biggest tech companies alone (Microsoft, Alphabet, Amazon and Meta) have already invested over 100 billion in AI in the first half of 2024.

AI is turning the world of competition on its head. With the rise of AI, traditional companies are suddenly being rivalled by big tech companies. Waymo and Uber, for example, have announced they are teaming up. With this, Waymo’s parent company Alphabet is suddenly entering the taxi market, competing with local taxi companies.

Competition authorities have been closely monitoring the rise of AI for some time. The German Bundeskartellamt, the French Autorité de la concurrence and the Dutch Authority for Consumers an Markets (“ACM”), among others, have already published several position papers on monitoring the use of algorithms (see here, here and here). The US government issued a presidential action on 30 October 2023 on secure and reliable development and use of artificial intelligence, stressing the importance of healthy competition in the AI market. (Former) European Commissioner Margrethe Vestager also warns about the competition risks of AI. Vestager stresses that swift and strong enforcement is needed to prevent monopolisation by the big tech companies on AI. The European Commission, the UK Competition and Markets Authority (“CMA”) and the US Federal Trade Commission (“FTC”) and Department of Justice (“DoJ”) also recognise that competition problems in AI are not limited to country borders. In their Joint Statement on Competition in Generative AI Foundation Models and AI Products, they discuss the competition risks of AI and indicate that they seek cooperation and share knowledge. Thus, competition law aspects of the AI market are receiving broad attention in the world of competition.

In this blog, we discuss four relevant competition law aspects of AI:

 

AI and market power of tech companies

Big tech companies like Apple, Microsoft and Google have the resources to develop and implement AI technologies faster. This can lead to a situation where these companies dominate the market. This poses competition risks.

The first is the fear by several competition authorities that dominant companies may abuse their market power by tuning algorithmic functions so that their own products and services receive preferential treatment. These fears stand in light of the Google Shopping case, in which Google was fined EUR 2.42 billion for giving preferential treatment to its own online marketplace Google Shopping on Google’s search engine.

In addition, several competition authorities fear that large tech companies are using their existing market power in adjacent markets to keep new entrants out of the AI market. AI systems often need access to large data sets to function effectively. Companies with access to large amounts of data can therefore gain an unfair competitive advantage. This creates high barriers to entry for startups. They are often forced to partner with one of the big tech companies to gain access to that data. This collaboration can lead to a series of anti-competitive practices, including tying, where the sale of one product is made conditional on the purchase of another. This dynamic allows the AI market to consolidate rapidly, as each of these companies incorporates an AI model and bets on its success. As a result, the barriers to entry in the AI market may become higher and higher, reducing competition.

As part of this concern, the Commission is investigating, for example, the cooperation agreement between Microsoft and OpenAI (the developer of ChatGPT). The Commission has requested additional information on the exclusive cloud agreement that is part of the cooperation. Indeed, Microsoft Azure, Microsoft’s cloud computing service, is OpenAI’s exclusive cloud provider. The CMA, DoJ and FTC are also investigating the partnership between Microsoft and OpenAI. In the US, the partnership between OpenAI and Microsoft is also being challenged civilly. On 29 November 2024, Tesla boss Elon Musk launched an action alleging OpenAI engaged in anti-competitive conduct in violation of US antitrust laws

A deal between Google and Samsung has also led to further investigation by the Commission. Samsung has agreed to build Google’s Gemini Nano AI model into the Samsung Galaxy S24. The Commission investigates, among other things, whether this deal means that no other AI systems can be installed on the Samsung device, whether interoperability between other chatbots and apps on the Samsung device is limited by this collaboration, and how this collaboration was established.

At the same time, AI also offers great advantages in the investigative work of competition authorities. For instance, AI tools can quickly and effectively analyse large data sets in the context of an investigation into possible abuse of a dominant position. As competition authorities have more data at their disposal, the use of AI allows them to detect early developments in the market that indicate reduced competition. This allows them to efficiently deploy their investigative capacity and more smoothly anticipate rapidly changing (digital) markets.

 

AI and the cartel ban

AI can also lead to cartel violations. For example, AI can be used to facilitate collusion. Collusion, in short, is the explicit or tacit coordination of competition-relevant behaviour between market participants.

The use of AI can facilitate existing forms of collusion. For instance, algorithmic functions can be used to better monitor an existing price cartel and more easily sanction deviant behaviour. With the increasing availability of large amounts of data on specific markets, these markets are also becoming more transparent. This may result in companies behaving less independently. The more transparent a market is, the less uncertain companies are about competitors’ market behaviour.

The use of AI may also foster new forms of collusion. In particular, regulators point to the use of algorithmic functions to automate competitively sensitive aspects of business operations, such as price, output and production. Algorithms, for example, allow constant monitoring of prices and quick reaction to price changes. For instance, in its investigation into the use of algorithmic trading in the energy market, the ACM points to the possibility that price algorithms can arrive at a higher average price level than if these algorithms were not used. In that case, there is tacit price alignment through the use of algorithms.

Currently, many companies still use so-called rule-based algorithms, simple algorithms in which the variables can easily be set and adjusted in advance. However, there is an increased use of learning-based algorithms, which can create the strange situation of algorithms themselves tuning prices to achieve equilibrium, whether or not outside the science or desire of companies. AI systems, for example, can use other companies’’ pricing as input to set prices. If several companies in the same market use a particular AI system, the fear is that prices will at some point reach an equilibrium at which profitability is optimised. Firms in such a situation no longer have an incentive to price competitively and thereby generate lower sales in exchange for a competitive pricing proposition, as long as the other firms do not do the same. How this kind of behaviour should be qualified under competition law is unclear, but what is clear is that in such a situation firms no longer compete on price, ultimately to the detriment of consumer welfare..

Detecting this kind of collusion is challenging. Due to the large amount of data that algorithms need to function adequately; collusion can be difficult to detect. The recently adopted AI Regulation may facilitate the supervisory function of authorities through the obligation introduced in Article 53(1) for providers of certain AI models to prepare and disclose sufficiently detailed summaries of the content used to train the AI model. Moreover, under Article 74(2) of the AI Regulation, market surveillance authorities report to national competition authorities and the Commission any information obtained in the course of surveillance activities that may be relevant to the application of competition rules. AI developers thus have a far-reaching transparency obligation and national and European authorities cooperate intensively to prevent or detect anti-competitive behaviour.

On the other hand, competition authorities are increasingly using AI to detect cartels. For example, the CMA introduced a screening tool that allowed it to easily detect cartels in tenders. The algorithms in the tool mapped tenders where bidrigging agreements were more likely. The tool is now no longer in use but there is a good chance that other competition authorities are also developing and using such tools without making it public. One reason for secrecy is that possible information on the factors on which tenders are selected will not be revealed to cartel participants and they could therefore circumvent cartel detection.

 

Merger control and AI

The dynamics described above between big powerful companies and AI developers also affect merger control. Due to the need for big data and pre-existing ecosystems, almost all serious AI developers enter into partnership agreements with large companies. The Commission sees the value of these partnerships, as they are essential for the development of AI models, but also warns of the potentially anti-competitive consequences. For instance, collaborations can lead to entrenched market positions, for example by agreeing on exclusivity rights. For example, a tech company may stipulate that in exchange for providing access to data and capital, the AI developer will only use the tech company’s services and align its AI model with the tech company’s services. This does not enhance competition in the AI market and adjacent markets.

In this context, the above-described cooperation between Microsoft and OpenAI was considered under the European merger control regime in addition to the potential competition infringement. However, the Commission concluded that the form of cooperation did not qualify as a concentration, as no lasting change of control was created within the meaning of Article 3(1) of the EU Merger Regulation.

The CMA also recently announced it was launching a formal investigation into the collaboration between Alphabet, Google’s parent company, and AI startup Anthropic. However, the investigation was soon abandoned when it was found that the revenue thresholds were not met. The CMA is actively investigating collaborations between tech companies and AI startups under the merger control regime. It also already investigated Microsoft’s investment in Inflection AI and Amazon’s partnership in Anthropic.

 

AI and the DMA

Investigations into an antitrust or abuse-of-dominant position violation by large tech companies can take a very long time due to the complexity. For example, the Google Shopping case above took more than 14 years. That is very long in a dynamic and fast-changing market, increasing the risk of significant and irreparable competitive harm.

The Digital Market Act (“DMA”) is intended to ease the rigmarole of market surveillance in the digital sector. Since 7 March 2024, all gatekeepers appointed by the Commission must comply with the obligations of Articles 5, 6 and 7 of the DMA (see also our earlier blogs of 5 December 2023 on the content of the DMA and 7 March 2024 on gatekeepers’ compliance with these obligations). These rules include the collection, processing and combination of (personal) data, interoperability obligations and the prohibition of parity clauses. Because the DMA entails so-called ex ante supervision, in principle it prevents designated gatekeepers from engaging in anti-competitive behaviour for years before it is stopped by the Commission. The DMA also contains far-reaching transparency obligations for designated gatekeepers to detail in compliance reports how the gatekeeper complies with all obligations. This provides the Commission with a wealth of information on the behaviour of these gatekeepers and the inter-operability of their various services.

The DMA also plays a role in the regulation of AI. Admittedly, AI is not one of the included core platform services that the DMA looks at. Nevertheless, the European Parliament has called for certain AI models to be included in the DMA as a core platform service. In the meantime, AI is already partially regulated by the DMA. In a statement dated 22 May 2024, the high-level group for the DMA outlined how the DMA influences the use of AI by designated gatekeepers. Once an AI model is integrated into another core platform service, such as Google’s search engine, Apple’s operating system or Facebook’s social networking service, the DMA applies to the AI model used in the context of the core platform service. A gatekeeper’s compliance with the obligations under the DMA should therefore take into account how AI models used are part of the core platform service in question.

Moreover, the DMA regulates whether and how gatekeepers may process personal, and business data generated on the core platform service. This curbs the previously described data dominance of large tech companies. For example, under the DMA, gatekeepers are not allowed to collect personal data of end users from third parties without prior consent. In addition, gatekeepers may not use personal data derived from the core platform service in other services offered by the gatekeeper. This limits the amount of data that gatekeepers can use to train their AI models.

Finally, the DMA contains a merger information requirement. Gatekeepers must inform the Commission of any proposed concentration in the digital sector, regardless of whether the proposed concentration must be notified to the Commission under the EU Merger Regulation or to a national competition authority. This information requirement was used by the Commission, among other things, to establish a so-called Article 22 referral. Through such a referral, the Commission could still, at the request of one or more member states, examine and possibly prohibit, or only approve subject to conditions, a non-notifiable concentration. This could prevent large powerful companies from acquiring a smaller, innovative and start-up AI competitor with the aim or effect of weakening innovation and/or eliminating potential competition (so-called killer acquisitions). The Court of Justice, in its Illumina Grail ruling on 3 September 2024, drew a line under the scope of Article 22, severely limiting its scope. Incidentally, in Germany and Austria, it is already possible to assess killer acquisitions because the value of the transaction is also taken into account. In addition, national competition authorities in Denmark, Hungary, Ireland, Italy, Lithuania, Slovenia and Sweden have introduced call-in powers. This allows them to still investigate mergers below the notification thresholds. These countries can also still refer transactions to the Commission under Article 22 of the EU Merger Regulation.

 

Conclusion

The effective enforcement of competition infringements related to AI faces significant challenges. The widespread use of AI can lead both to coordinated behaviour between firms and abuse of market power by dominant firms. Communications from various competition authorities on AI and competition law show that these authorities have learnt from the emergence of digital markets at the beginning of this century, and are making efforts to avoid making the same mistakes when supervising AI as when supervising Big Tech. Moreover, consideration is being giving about sharpening competition tools to meet the new reality. The DMA plays an important role in this matter, but, as Vestager also noted in her speech on 28 June 2024, the basic principles of competition enforcement are still the same. Monopolies are monopolies and price fixing is price fixing, whether we are dealing with car manufacturing, cement production or machine learning.

 

Bas Braeken and Lara Elzas

Vision

Update railway law: the 4th European Railway Package and competition on European railway markets

Introduction

In our blog of 26 May 2023, we discussed some developments in the field of railway law. The focus was in particular on the then upcoming concession for the Dutch Main Railway network (in Dutch: Hoofdrailnet, “HRN concession”) in light of the 4th European Railway Package. The HRN concession for the period 2025 to 2033 has now been directly awarded to the Dutch Railways (in Dutch: Nederlandse Spoorwegen, NS”) on 21 December 2023. In this blog, we will discuss the background and relevant legal framework of the unconditional direct award of the HRN concession. In doing so, we will also examine the European Commission’s (“Commission”) objections to the procedure by which the concession was awarded. Finally, we highlight several other recent developments regarding Dutch and European railway regulation.

4th Railway Package and the HRN concession

Central to assessing the legality of the HRN concession, and the award to NS, is the 4th Railway Package. This package consists of European law aimed at liberalising European passenger railway transport and is divided into two pillars. The technical pillar deals with the safety and interoperability of the European railway system. The market pillar deals with opening up the railway market. This pillar includes the SERA Directive (Single European Railway Area) and the PSO Regulation (Public Service Obligation), most of this legislation is implemented in the Netherlands in the Passenger Transport Act 2000 (Wp2000) and the Railway Act.

Prior to the entry into force of the 4th Railway Package, the Dutch railway network was divided into two tiers: one central and multiple (smaller) decentralised concessions. The HRN concession is the primary concession. All rail lines and services not covered by the central HRN concession are granted as decentralised concessions to (alternative) transport operators. Currently, several railway companies operate on decentralised concessions including Arriva, Connexxion, Syntus/Keolis, Qbuzz, Abellio and Eurobahn. Apart from small overlaps between the concessions, the concessionaires have an exclusive right over the relevant rail lines and services. Whereas decentralised concessions are publicly tendered, thus allowing for competition between railway companies, the HRN concession has, to date, always been awarded directly and privately to NS.

HRN-concessie en decentrale concessies

Figure 1: railway companies & concessions on the Dutch railway network

The 4th Railway Package brought change to this system. In principle, the entire railway network should be served by normal market conditions on the basis of open access. Infrastructure managers (ProRail in the Netherlands) must grant all railway companies access to their railway networks (Article 13 SERA Directive). This ensures maximum competition between railway operators. Nonetheless, the 4th Railway Package foresees that not all railway services benefit from unbridled competition. This is particularly the case where certain services are unprofitable and, therefore, provide an insufficient impetus for railway companies to operate those services. To ensure that these services, although perhaps commercially uninteresting for the operator but important for passengers, are also provided for, a Member State can designate them as a public service obligation.

Article 2(e) of the PSO Regulation explains that a ‘public service obligation’ is an obligation imposed on an operator by the relevant competent authority to provide railway services that it would not provide under normal circumstances (i.e. without compensation). A public service obligation can be granted under Article 1 Wp2000 and Article 3 PSO Regulation as an exclusive right, for example in the form of a concession. However, to promote competition even in the case of public service obligations, Article 5(6) PSO Regulation stipulates that their direct award was only possible before 24 December 2023. Public service contracts must in principle be awarded through a public tender procedure after 24 December 2024. Only under strict conditions is the direct award of a concession still allowed after that date (see articles 8 paragraph 2 sub iii and 5 paragraph 4a PSO Regulation). The HRN concession for the period 2025-2033 was awarded directly to NS on 21 December 2023 (on the basis of Article 19a and 19b Wp2000).

Infringement procedure European Commission

On 14 July 2023, the Commission sent a letter of formal notice to the Dutch government explaining that it considers the proposed HRN concession to be unlawful. The Ministry of Infrastructure and Water Management (“Ministry”) had previously received a formal warning from the Commission in relation to the HRN concession. This second letter constituted the initiation of an infringement procedure. The opening of the infringement proceedings by the Commission did not go unnoticed in Dutch politics and led to several questions from the House of Representatives. In response, the Ministry reiterated several times, such as in a letter to the House of Representatives, that it was sticking to its plan to directly award the concession to NS. Following the direct award of the HRN concession to NS on 21 December 2023, the Commission sent a supplementary letter of formal notice to the Dutch government on 13 March 2024.

In its letters of formal notice, the Commission identifies two concerns based on which it opposes the direct award. First, the Commission criticises the fact that the Ministry has already awarded the HRN concession 2025-2033 a year before its commencement, on 21 December 2023. The reason for this was that directly awarding the HRN concession would no longer be possible after 24 December 2023 without justification under strict conditions. However, the Commission sees no objective justification for this long period of time between the date of award and the date of commencement of the concession, and even considers it a circumvention of the obligation to initiate a public tender procedure.

The Commission’s second objection concerns the scope of the HRN concession. The Commission questions whether (parts of) the HRN concession actually qualify as a public service obligation. As explained above, the award of a public service contract requires the existence of a public service obligation within the meaning of Article 2(e) PSO Regulation, and must thus be limited to services that are not commercially beneficial to the concessionaire. According to the Commission, the Ministry should have conducted a market analysis to test whether parts of the HRN concession could be operated under normal commercial conditions and on the basis of open access. The fact that NS pays a tariff for the concession suggests, according to the Commission, that parts of it could be fulfilled under regular market conditions.

Interestingly, in doing so, the Commission seems to break with the ruling of the Trade and Industry Appeals Tribunal (“CBb”) of 9 February 2017. In that case, the CBb ruled that the HRN concession 2015-2025 as a whole constituted a public service obligation. The fact that part of that concession, specifically the HSL-South (high-speed rail line), could be profitable did not alter that. In the CBb’s view, Article 2(e) of the PSO Regulation does not prevent a concession from being “a mix of profitable and loss-making lines”. By contrast, in the Commission’s view, the Ministry is required to examine whether parts of that “mix” could be operated as an open access service.

For the time being, it is unknown how the Ministry responded to the second letter of formal notice, for which the deadline to respond has now expired, and if so, whether this was enough for the Commission to refrain from further pursuing the infringement procedure. If the Commission is not satisfied with the response, it may choose to send a reasoned opinion. If the Dutch government then fails to comply with the Commission’s requirements within a specified period, the Commission may refer the case to the Court of Justice of the European Union (“CJEU”). Several scenarios are conceivable should the CJEU rule in favour of the Commission. In the most drastic scenario, the HRN concession will have to be awarded through a public tender procedure after all. It is also possible that the Dutch government will have to decentralise parts of the current concession. In both cases, alternative railway operators will have the opportunity to compete for services currently provided by NS.

Scope of the HRN concession and open access services

In addition to the Commission’s objections, the scope of the HRN concession also came under scrutiny at the national level. The scope of the HRN concession is of particular importance in the context of the old Dutch system of concessions for railway operators wishing to offer train services on the Dutch railway network alongside NS. Against that background, at the time of our previous blog, it was not yet established whether the Groningen-Zwolle and Leeuwarden-Zwolle sprinter routes would become part of the 2025-2033 HRN concession. Besides NS, Arriva was also interested in running train services on those routes. In the end, the Ministry chose not to decentralise these services. State Secretary Heijnen considered that these routes are of great importance to regional travellers and that they should be protected against austerity or discontinuation of train services by commercial parties as a result of disappointing revenues. Although these routes will continue to fall under the HRN concession for the time being, the Ministry may decide halfway through the course of the HRN concession, during the mid-term review, to still decentralise these services.

The 4th Railway Package allows for a railway operator to offer train services even without a concession, and even if a concession has already been granted to another undertaking for the same route. It follows from Article 11(2) SERA Directive that the right to open access may only be limited if new (open access) services threaten the economic equilibrium of a concession. In the Netherlands, this threat primarily concerns the HRN concession, but also all decentralised concessions. Upon notification of a new service based on open access, the grantor (the Ministry), the concessionaire (NS) or the infrastructure manager (ProRail) may ask the ACM to carry out an objective analysis to examine whether the economic equilibrium of the relevant public service contract is disrupted (Article 10 Implementing Regulation 2018/1795).

In 2023 and 2024, a relatively large number of transport operators indicated their intention to use the Dutch railway network on an open access basis, especially for long-distance services within the Netherlands and internationally. For instance, Arriva has notified 26 new domestic train services and an international service between Groningen and Paris. Qbuzz has also notified new (international) train services, for example between Amsterdam and Berlin. In addition to these transport operators already operating in the Netherlands, Flixtrain has notified a new service between Rotterdam and Oberhausen, and new entrants Heuro and Flywise plan to offer international train services.

In response to each of these notifications, the Ministry and NS requested the ACM to conduct an economic equilibrium test (“EET”). The ACM declared those requests inadmissible in all cases. The ACM’s position is that it can only conduct an EET in respect of an existing public service contract (section 19a(2) Wp200), while the HRN concession 2025-2033 had not yet been granted at the time of the notifications. As an exception to that rule, the ACM can conduct an EET when a competitive tender procedure is initiated (Article 5(2) Implementing Regulation 2018/1795). However, as no competitive tender procedure has been carried out for the award of the upcoming HRN concession, this exception is not applicable. Without an EET, the ACM cannot prohibit the train services of alternative operators.

Competition in the European railway market

The 4th Railway Package is (also) stimulating increased competition on railway networks throughout the rest of Europe. Thanks to liberalisation of the European railway network, previously nationalised, incumbent railway operators are facing increasing competition from alternative operators on an open access basis.

Most developments are taking place in the area of European high-speed routes. The increase in competition among high-speed train service providers is partly driven by a growing desire among consumers to travel more environmentally conscious. Train travel is more likely to be seen as an alternative to low-cost flights than it was 20 years ago. In response, national railway operators Renfe (Spain), Trenitalia (Italy) and SNCF (France) are expanding their open-access high-speed services to neighbouring countries. In addition, several new high-speed service providers have become operational on the basis of open access, such as Nuovo Trasporto Viaggiatori in Italy and Iryo in Spain. To date, Eurostar has had a monopoly on the high-speed route connecting the UK to continental Europe via the Channel Tunnel, but this may change in the future. Several established railway operators as well as start-ups Evolyn and Dutch firm Heuro have announced plans to offer services between London, Amsterdam and Paris.

In contrast to the trend of international expansion by French, Spanish and Italian national railway operators, NS and Deutsche Bahn (“DB”) have in fact divested their foreign operations in recent years. DB received Commission approval for the sale of Arriva to I Squared Capital on 5 January 2024. In the Netherlands, the Ministry of Finance publicly announced on 23 April 2024 that NS will sell its subsidiary Abellio Germany to BeNEX. The primary consideration is that Abellio Germany plays no role in cross-border railway transport or international services between the Netherlands and Germany. For this reason, the subsidiary provides insufficient added value for Dutch travellers. Combined with the fact that Abellio Germany is loss-making, the Ministry of Finance, in its capacity as shareholder, approved the sale.


Are your business operations affected by developments regarding the HRN concession? Are you coming into contact with the ACM in a regulatory matter or dispute? Or are you curious about the impact of new regulations? If so, contact one of our specialists.

Bas BraekenJade VersteegJoost van Belois

Vision

Update Dutch FDI-screening (Vifo Act)

In our Competition Newsflash of 2 June 2023 we discussed the coming into force of the Act on security screening of investments, mergers and acquisitions (“Vifo Act”) on 1 June 2023. As a result of the Vifo Act, many transactions that previously escaped ex ante merger control are brought within the scope of a new, sometimes intensive, administrative process. Almost a year after the coming into force, the practice around the Vifo Act shows that there is much room for varying interpretations and uncertainty about the obligation to notify. In this Newsflash, we outline a number of insights drawn from publications by the Investment Screening Bureau (“BTI”) and our own practical experience set out in thirteen questions and answers.*

*The following information is not intended as legal advice. If you want to be certain of whether a transaction must be notified, please contact one of our lawyers.

Overview


Notification obligation

1. What is a target company established in the Netherlands?

2. Under what circumstances are chain partners in the up- and downstream market independently active in the field of sensitive or highly sensitive technology?

3. What constitutes acquisition of control?

4. How does acting through a consortium or a shareholder’s agreement relate to the notion of ‘acquiring or increasing significant influence’?

5. In which case does exerting influence on the composition of the board also lead to significant influence?

6. What about temporary shifts in equity interests in the context of multiple investment rounds and/or restructuring processes?

Process and timeline

7. How does the BTI apply the statutory time limits of the Vifo Act in practice?

8. How does the BTI gather information during the process?

Substantive risk analysis

9. Which countries may raise concerns about risks to national security for the BTI?

10. How does the BTI determine whether an intended transaction poses a risk to national security?

Remedies

11. At what times are parties allowed to provide input on the BTI’s investigation and offer remedies?

12. How does the BTI relate to the Minister of Economic Affairs & Climate?

13. What legal actions can parties take before, during and after the procedure at the BTI?


1. What is a target company established in the Netherlands?

To determine whether a company is established in the Netherlands, the focus is placed on the factual connection with the Netherlands rather than the formal, statutory reality. The location where the company conducts economic activities is decisive. In its guidance ‘being active in’ (only in Dutch), the BTI clarifies that the relevant production, research, and/or development activities must be carried out in the Netherlands to fall within the scope of the Vifo Act.

A Dutch sales office of a foreign-based company active in the field of sensitive technology will therefore generally not qualify as a target company within the meaning of the Vifo Act. This is different if the sales office has the capability and necessary legal rights to make improvements, adjustments or modifications to the relevant technology. In that case, it can no longer be considered a pure sales office. Additionally, a holding company located in the Netherlands which solely holds the shares in a subsidiary located abroad which engages in the relevant production, research, and/or development activities will also not qualify as a target company within the meaning of the Vifo Act.

back to top


 2. Under what circumstances are chain partners in the up- and downstream market independently active in the field of sensitive or highly sensitive technology?

After the coming into force of the Vifo Act, there was some confusion about when an undertaking can be considered to be ‘active in’ the field  of (highly) sensitive technology. In response, the BTI published the guidance ‘being active in’ (only in Dutch). In principle, companies that produce a semi-finished product that does not independently qualify as sensitive technology are not considered active in the field of sensitive technology. Likewise, chain partners in the up- and downstream market, such as suppliers, end-users, and wholesalers, are generally not considered active in the field of sensitive technology themselves.

According to the BTI, this is different when a company plays a role in the production process of technologies designated as highly sensitive in Annex 2 to the Decision on the scope of sensitive technology (only in Dutch): quantum technology, photonics technology, semiconductor technology, and High Assurance products. Given the broad description of these technologies, companies that provide products, machinery, know-how or services specifically tailored to the production process of these technologies fall (independently) within the scope of the Vifo Act.

By way of illustration: company X manufactures machinery for company Y, which develops semiconductor technology. Due to the need for precision and coordination of all steps in company Y’s production process, company X will be closely involved in company Y’s production process. In this case, the BTI considers that company X itself is also (independently) active in the field of semiconductor technology, and there is an obligation to notify an acquisition of or investment in company X to the BTI.

Lastly, end-users of High Assurance products can also be considered (independently) active in the field of highly sensitive technology. High Assurance products are software and/or hardware information security products aimed at information protection according to the highest international security standards. Some end-users of High Assurance products may further customise the product to fit their own business processes or feed the product with relevant data, resulting in a unique product. Such end-users are in principle also (independently) active in the field of highly sensitive technology. Therefore, there is also an obligation to notify an acquisition activity related to such end-users.

back to top


3. What constitutes acquisition of control?

For the concept of ‘control’, reference is made to the concept of ‘control’ as defined in Article 26 of the Dutch Competition Act (“DCA”): the ability to exercise decisive influence over the activities of an undertaking on the basis of factual or legal circumstances. However, there is a difference between the concept of ‘concentration’ in competition law and ‘acquisition activity’ in the Vifo Act. Unlike in competition law (Article 27 DCA), the Vifo Act does not require a change of control on a lasting basis. In its guidance on ‘internal restructuring’ (only in Dutch), the BTI for example explains that a temporary transfer of shares in a target company to a trust company, custodian or notary as part of a restructuring process generally qualifies as an acquisition activity under the Vifo Act.

back to top


4. How does acting through a consortium or a shareholder’s agreement relate to the notion of ‘acquiring or increasing significant influence’?

Article 4 Vifo Act includes thresholds for the acquisition or increase of significant influence in a target company active in the field of (highly) sensitive technology. Decisive for determining that influence is the number of votes in the general meeting of shareholders that the acquirer can cast. If a company can (or can have) cast at least 10%, 20% or 25% of the votes in the general meeting of a target company, this qualifies as significant influence. These are successive thresholds, meaning that exceeding any of the thresholds increases the significant influence of an acquirer and therefore must be notified to the BTI.

By way of illustration: if company X holds 15% of the voting rights in company Y and increases its share in the company to 21% during a new investment round, it exceeds the 20% threshold. This means that it increases its significant influence in company Y, even though it already had significant influence in company Y prior to the new investment. This increase in significant influence in company Y by company X is notifiable to the BTI if company Y qualifies as a target company within the meaning of the Vifo Act.  

The joint action of multiple shareholders in a target company can also result in significant influence. When determining the percentage of votes in the general meeting of a target company that an acquirer will have after an acquisition activity, the votes of collaborating parties are added together. This way, a shareholder who individually does not exceed a certain threshold can still engage in a notifiable acquisition activity by acquiring or increasing significant influence through the consortium.

By way of illustration: shareholders X, Y and Z hold 2%, 7% and 10% of the shares in company A respectively. Shareholders X, Y and Z are part of a consortium based on a cooperation agreement. Together, they hold 19% of the shares in company A. If shareholder X increases its share from 2% to 5%, it does not exceed the thresholds of Article 4 Vifo Act. However, the consortium does exceed the threshold, because the consortium’s share increases from 19% to 22% due to the acquisition activity of shareholder X. If company A is active in the field of sensitive technology within the meaning of the Vifo Act, there is an obligation to notify the increase of X’s share from 2% to 5% to the BTI.  

Just like the acquisition of control, it is not required for the acquisition or increase of significant influence to be on a lasting basis. Even a temporary acquisition or increase of significant influence is subject to a notification obligation under the Vifo Act.

back to top


5. In which case does exerting influence on the composition of the board also lead to significant influence?

In addition to exceeding the 10%, 20% and 25% threshold, the capability to influence the appointment and/or dismissal of one or more directors can also lead to significant influence. Considering the broad wording of Article 4(1)(d) Vifo Act, there does not need to be a direct power of appointment/dismissal. The (collective) power to promote the appointment/dismissal of certain individuals can also trigger a notification obligation. Significant influence pertains to the influence that can be exerted on the strategy, specific investments, and further development of the target company, which can also be achieved (indirectly) by having a say in the composition of the board.

While generic merger control also takes into account the appointment of non-executive directors or supervisory board members, the BTI recently informally indicated that, in its view, obtaining the right to appoint a non-executive director does not constitute significant influence. It is important, however, that the duties and powers actually reflect on a non-executive role. The name/title of the individual is not decisive. Hence, according to informal communication from the BTI, only the ability to influence the appointment and/or dismissal of executive directors would trigger a notification obligation.

back to top


6. What about temporary shifts in equity interests in the context of multiple investment rounds and/or restructuring processes?

Temporary shifts in equity interests in a company active in the field of (highly) sensitive technology must also be closely monitored. In practice, this can cause problems when raising capital in multiple financing rounds and complicated restructuring processes.

Start-ups and scale-ups are often seeking capital to expand, depending on the stage of development of the company. If this occurs in multiple (sometimes closely spaced) rounds, the equity interests within the company can shift multiple times. The BTI holds that the thresholds of Article 4 Vifo Act must be strictly adhered to, and that temporarily exceeding the thresholds is also subject to notification.

This also means that if shareholders drop below a certain threshold during multiple financing rounds that do not follow each other closely and then rise above the threshold again, the increase in shares must in principle be notified (again). However, the BTI has informally indicated that when a shareholder’s interest temporarily decreases and then increases again because shares are issued in multiple closely following rounds, the subsequent increase above one of the thresholds does not need to be notified. However, it is required that the temporariness and short duration are already predetermined, for example, because specific (contractual) commitments have already been made upfront.

By way of illustration: company A intends to attract new financing from both new and existing investors and has already concluded all necessary agreements in that regard. Because the existing investors need slightly more time to finalise their financing, their shares will be issued a few days later (closing 2) than the shares for the new investors (closing 1). As a result, the interest of shareholder X dilutes from 12% to 9% at the time of ‘closing 1’. However, a few days later, his interest increases again to 12%. Strictly speaking, this exceeds a threshold. However, in this case, the BTI seems to take the position that this does not need to be notified.

The strict application by the BTI of the thresholds of Article 4 Vifo Act can also lead to some complications in restructuring processes. The BTI explains in its guidance on ‘internal restructuring’ (only in Dutch) that interests can shift (whether temporarily or not) during a restructuring process, which may require notification to the BTI. This is the case, for example, when, as part of a restructuring process, the target company is temporarily placed under the administration of a trust company. The shifting of interest to another investment fund controlled by the same managers can also trigger a notification obligation, as there may be different investors participating in the other fund. The entry of new minority shareholders who acquire significant influence over the target company during a restructuring process also constitutes a notifiable acquisition activity.

back to top


7. How does the BTI apply the statutory time limits of the Vifo Act in practice?

After receiving a notification, the Minister of Economic Affairs and Climate (“Minister”)/BTI has eight weeks to decide whether a review decision is required (the “notification phase”). This eight-week period can be extended by up to six months if the BTI needs more time to conduct further investigation. This period can be extended by an additional three months if the FDI Screening Regulation applies (in the case of direct investments by foreign (i.e., non-European) natural or legal persons). In that case, the BTI requires extra time to inform the relevant EU Member States and the European Commission (“Commission”).

If the Minister decides that a review decision is required and one of the parties subject to notification has submitted an application for a review decision, the Minister has eight weeks to adopt a review decision (the “review decision phase”). This period can also be extended by up to six months, minus the extension the BTI has used in the notification phase. Just as in the notification phase, the ‘clock stops running’ if the BTI has additional questions for the parties, from the moment of asking those questions until the moment the BTI receives a response from the parties. Overall, the process at the BTI from the initial notification to a review decision can easily take almost a year.

It is noteworthy that the BTI can use (significant) deadline extensions already in the notification phase. Even if the process ends with the Minister’s decision that no review decision is required, the process at the BTI can (in the most extreme case) still last almost a year. For the M&A-practice, this can lead to more deal uncertainty as acquirers may include unconditional approval by the BTI as a resolutory condition for the agreement. On the other hand, the selling parties may increasingly demand a breakup fee or another form of compensation in case the BTI does not (unconditionally) approve an acquisition activity.

To reduce the processing time at the BTI, parties are advised to explain clearly and comprehensively the relevant technology to the BTI, as well as the economic and non-economic motives behind that intended acquisition activity, as early as possible in the process. This can help prevent the BTI from requiring extensive time in the notification phas

back to top


8. How does the BTI gather information during the process?

First, the BTI obtains information through the notification submitted by the parties. This form is included in Annex 1 to the Regulation on security screening of investments, mergers and acquisitions (only in Dutch).

After parties have notified the intended acquisition activity to the BTI, the BTI may want to ask clarifying questions to the parties. This can be done either orally or in writing. If the BTI sends a written information request to the parties, the statutory decision-making period stops to run until the questions are answered. The questions posed by the BTI to the parties can provide an indication of the focus of the BTI’s investigation and potential risks perceived by the BTI. In addition to written questions, the BTI may also schedule a (physical) meeting with the parties. For example, they may suggest to meet at the location of the Dutch target company to gain more insight into the products or services involved.

Additionally, the BTI collects information through chain partners and government institutions to gain a better understanding of the target company, the acquirer, and the relevant technology. The notifying parties are not given insight into the input from third parties, as this often involves confidential information.

Finally, the FDI Screening Regulation provides for a mechanism for the exchange of information between the BTI, the Commission and other national authorities (Article 6(1) FDI Screening Regulation). The BTI informs the Commission and other EU Member States of all transactions concerning an FDI. EU Member States can share information with or submit comments to the BTI if they believe the transaction may have implications for their national security or public order. The Commission may also provide advice to the BTI if it believes the transaction may have implications for the security of more than one EU Member State. The Commission shares this advice with other EU Member States. Finally, authorities from other Member States and the Commission can request additional information from the BTI. If the BTI does not have this information itself, this request for information may be redirected to the parties. The statutory decision-making period stops until parties have answered the questions.

The additional three-month extension period if the acquisition activity falls within the scope of the FDI Screening Regulation is intended to give the BTI time to go through the abovementioned procedures without losing time to investigate the transaction itself.

back to top


9. Which countries may raise concerns about risks to national security for the BTI?

Prior to the enactment of the Vifo Act, the impression was given that the Act was primarily aimed at countries such as China, Russia and Iran. In this context, both the Dutch legislator and the BTI referred to the report ‘Threat Assessment State Actors 2’ (only in Dutch, “DSA-report”) drawn up by Dutch intelligence agencies AIVD, MIVD and NCTV. The DSA-report highlights,  in particular, Russian entities taking preparatory actions for disrupting and sabotaging Dutch infrastructure, Dutch dependence on Russian oil and gas, Iranian methods of acquiring Dutch technology, and China’s threat to Dutch intelligence security.

However, in practice, it turns out that other countries, including Western countries like the United States, can also raise concerns in the view of the BTI for Dutch national security. It is also possible that an acquisition activity by an acquirer with its registered office in another EU Member State or even the Netherlands could lead to risks according to the BTI. This will depend, amongst other things, on who the Ultimate Beneficial Owner (“UBO”) is and the nature of the acquisition activity.

In short, there appears to be no safe harbour under the Vifo Act for acquirers from specific countries. The Vifo Act only provides an exception if the acquirer is the Dutch State, a local government, or another pubic body under Dutch law.

back to top


10. How does the BTI determine whether an intended transaction poses a risk to national security?

An intended acquisition activity poses a risk to national security if it:

  • disrupts the continuity of vital processes;
  • affects the integrity and exclusivity of knowledge and information containing critical or strategic information for the Netherlands; or
  • creates an unwanted strategic dependence of the Netherlands on other countries.

Articles 19, 20 and 21 of the Vifo Act contain additional factors that the BTI takes into account when assessing whether an acquisition activity could pose a risk to national security. These factors include transparency of ownership structures and relations, criminal history, export policy and the security situation of the acquirer’s county. It should be noted that these are merely factors that can be considered when assessing risks to national security. Practice learns that these factors are by no means exhaustive and the BTI is flexible in its approach.

Ultimately, the BTI conducts a risk analysis. There is no clear standard of proof for this risk analysis, meaning there is no specific level of probability required for the risks to materialise. According to the wording of Article 12 Vifo Act, the Minister requires a review decision if an acquisition activity could pose a risk to national security. Generally, it can be assumed that the risk analysis is relative: the actual occurrence of the risk may not need to be highly probable if the consequences would be very serious. In the review decision phase, the standard of proof seems to be higher: according to Articles 23 and 24 Vifo Act, the Minister can impose certain requirements or conditions on an acquisition activity if it poses risks to national security.

back to top


11. At what times are parties allowed to provide input on the BTI’s investigation and offer remedies?

At the end of the notification phase, the BTI issues a positive or negative advice to the Minister. A negative advice means that the BTI advises the Minister that a review decision is required for the acquisition activity, because the acquisition activity could pose risks to national security.

If the BTI intends to issue a negative advice, it first presents parties with a draft advice, outlining the national security risks it has identified. Parties are given the opportunity to respond to the draft advice by submitting their views. To avoid a review decision, parties can mitigate the identified risks. For example, the BTI might have misrepresented the relevant technology or made unjustified assumptions about its relevance for the Dutch national security. Parties can also address the concerns of the BTI by making certain informal commitments that compensate for the identified risks. For example, parties can ensure the continued availability of the products or services involved by making certain changes to the structure of the transaction. The BTI can adjust its advice to the Minister accordingly.

If the parties’ views do not adequately address the identified concerns, the BTI will advise the Minister to decide that a review decision is necessary. In general, this advice is followed by the Minister.

back to top


12. How does the BTI relate to the Minister of Economic Affairs & Climate?

The BTI only considers potential risks to national security arising from a proposed acquisition activity. Subsequently, it advises the Minister on the course of action to take. Ultimately, it is the Minister who conducts a risk analysis as well as a broader political assessment to determine, first, whether to require a review decision for an intended transaction and, second, whether to (unconditionally) approve or disapprove the intended transaction.

Because the Minister takes a broader perspective than just the security risks associated with a proposed acquisition activity, it can also consider other political and economic arguments. Therefore, the fact that the BTI has identified risks to national security does not necessarily mean that an intended transaction will be prohibited or subject to conditions.

back to top


13. What legal actions can parties take before, during and after the procedure at the BTI?

Interested parties have recourse to administrative legal review according to the procedures of the General Administrate Law Act (“Awb”). This means that interested parties can file an objection and file an appeal against decisions of the Minister, and in the context of those proceedings, also request the court for preliminary relief to suspend a decision. If the Minister’s decision is found to be unlawful, partes can request compensation for damages.

In a recent ruling (only in Dutch) by the Rotterdam District Court, a party (the “applicant”) successfully requested a preliminary relief to suspend a decision of the Minister. The Minister had required parties to report an acquisition activity carried out in April 2021 on the basis of Article 58 Vifo Act, because the Minister suspected that the acquisition activity could pose a risk to national security. The applicant first lodged an objection and then an appeal against this decision. According to the applicant, there was no acquisition of control (and thus no acquisition activity within the meaning of the Vifo Act) because no voting rights were transferred in the transaction. The District Court found that the voting rights indeed remained with the same party. Since the competence of the BTI laid down in Article 58 Vifo Act to call in prior acquisitions applies only to acquisition activities, the District Court grants suspension of the contested decision until a decision is made on appeal in the main proceedings.

back to top


For all your questions regarding (EU) competition law, bureau Brandeis would be happy to assist.

Bas Braeken (Partner) | Jade Versteeg (Senior Attorney) | Lara Elzas (Attorney) | Timo Hieselaar (Attorney) | Demi van den Berg (Attorney) | Coen Vermeij (Lawyer) | Joost van Belois (Paralegal)

Vision

Developments 5G and fixed networks: new battle for access?

Introduction

The further development and roll-out of new telecommunications networks is still high on the European and Dutch agenda today. Following the much-discussed auction of the radio frequencies, 5G frequencies are expected to go under the hammer in the Netherlands in 2024. As touched upon in our earlier blog, there have been several legal proceedings in recent years that have delayed the process enormously. With the final decision on the allocation of frequencies published in February 2024, the 5G auction is finally in sight.

Besides the development of 5G, the roll-out of fibre-optic networks and access to fixed networks have been important agenda items for the Netherlands Authority for Consumers and Markets (“ACM”). In 2023, it published several decisions regarding the access of third-party providers to fixed copper and fibre-optic networks, thereby confirming the envisaged shift towards further deregulation in the area of wholesale access to the local loop (“local access”).

In this blog, we discuss recent competition and regulatory developments in the field of mobile and fixed telecommunications networks.


Developments 5G

Roll-out and development of 5G networks

In its February 2024 White Paper on digital infrastructure policy, the European Commission (“Commission”) once again calls attention to the (technological) investments needed to realise ‘Europe’s Digital Decade’ by 2030. The aim is to have the full 5G network rolled out in all populated areas of the EU by 2030. The associated costs are estimated at around € 400 billion. In that context, several mobile network operators (“MNOs”) expressed their concerns about rising costs due to the increase in network traffic. They argue that they do not have enough resources to invest (quickly) in the further development and roll-out of their networks. According to them, large online service providers, including some Big Tech and video streaming companies, should contribute towards the costly rollout of fibre-optic and 5G networks, as they are responsible for much of the network traffic.

The Commission therefore recently launched a consultation on the possibility of levying a certain ‘internet toll’ or ‘fair share’. The Dutch Ministry of Economic Affairs and Climate Policy (“Ministry”) already expressed a negative view on this initiative in 2023. Citing an Oxera report, the Ministry argues that any such tolls will not effectively lead to new or additional network investments. Moreover, price increases due to tolls will be mainly felt by consumers and such tolls are (potentially) in conflict with the European Net Neutrality Regulation (see our earlier blog on that subject). The interests of consumers – and not telecom parties – should come first, the Ministry said.

In recent years, the ACM has commented on competition and telecoms supervision of 5G-related issues in several papers and studies. In its paper “5G and the Netherlands Authority for Consumer and Markets“ of 12 December 2018, the ACM already took the position that R&D cooperation and mobile infrastructure sharing can be pro-competitive, provided that innovation and competition are not unnecessarily restricted. The ACM also states that the Net Neutrality Regulation provides ample room for the implementation of new 5G technologies. Furthermore, the ACM says it is aware of a possible increase in applications around number issuance and increasing complexity of mobile subscriptions for consumers.

With the increase in 5G applications, the ACM also expects an increase in demand for locations to erect antennas for mobile networks. However, in its July 2022 market review, the ACM concluded that it did not see any market-wide risks of potential scarcity in the supply of antenna sites. The ACM takes into account the expansion of the possibilities for shared use in the Dutch Telecommunications Act (“Tw”) and emphasises that reasonable requests for shared use must be granted. The ACM sees its dispute settlement powers as a means of dealing with any issues that could arise during such requests.

 

Freeing up frequency space

In the meantime, Dutch authorities are working on freeing up more frequency space for 5G. Already back in 2021, the Dutch Minister of Economic Affairs and Climate Policy (“Minister”) decided to amend the National Frequency Plan 2014 (“NFP”) to free up the 3.5 GHz band for the development of the 5G network from 1 September 2022 onwards. Satellite provider Inmarsat – which (until recently) made use of this frequency band – filed a preliminary injunction. The Rotterdam District Court ruled on 30 June 2021 that the Minister’s decision had been negligently prepared by failing to take into account the importance of undisturbed continuation of the emergency, urgent and safety communications (“EUS communications”) that Inmarsat secures via its ground station in Burum. The interim relief judge deemed it advisable for the Minister to first enter into consultations with Inmarsat and other parties to reach a solution that safeguards the continuance of EUS communications, and therefore suspended the amendment of the NFP.

Taking this ruling into account, the Minister published a temporary amendment to the NFP on 23 February 2023, in which the 3.5 GHz band was earmarked for both fixed satellite links and national mobile communications (also known as dual use). This decision was appealed by several parties for different reasons. According to MNOs VodafoneZiggo, Odido, KPN, as well as local parties such as Schiphol Airport, Port of Rotterdam and Europe Container Terminals, the Minister’s amended policy does not provide sufficient safeguards to make large-scale investments in 5G. Some locally active companies such as Venus & Mercury, Greenet Network (provider of private mobile networks) and VSC Observation (camera surveillance) also complained about the loss of protection for existing licence holders of (private) business networks and camera networks. They also argued that the auction policy favours larger parties and MNOs in particular. In a parliamentary letter dated 3 July 2023, the Minister subsequently informed the Dutch Parliament about the potential scenarios and possible further delay of the auction process, pending the appeal process.

In its ruling of 29 November 2023, the Rotterdam District Court dismissed all appeals. The court stated that the Minister enjoys a wide degree of discretion when determining the efficient use of frequency space. According to the court, the Minister did in fact prepare the decision carefully and gave sufficient reasons for his considerations.

After a consultation in the third quarter of 2023, a new decision amending the NFP was finally published on 8 January 2024, thereby permanently removing fixed satellite links for EUS communications on the 3.5 GHz band from 1 February 2024. As of 1 February 2024, Inmarsat’s operations have moved from Burum to Greece.

 

Frequency auction

After years of delay, the now vacant frequency space will soon be auctioned off by the Dutch Authority for Digital Infrastructure (“RDI”), formerly known as the ‘Telecom Agency’ (Agentschap Telecom). In the Auction Regulation of 14 February 2024, the Minister published the rules regarding the set-up and conditions of the auction and the minimum prices. The Auction Regulation provides that participating market parties can control a maximum of 40% of the total available frequencies. With this cap, the Ministry aims to maintain effective competition as at least three parties will be able to acquire frequency space. The proposed reserve prices for the licences, i.e. starting prices in the auction, total around € 170 million.

In practical terms, the licences will be distributed through a multi-round auction. In the primary phase, the total number of licences will be distributed among the auction participants. In doing so, three 60 MHz licences will be auctioned first (at a reserve price of € 39.22 million each), followed by (in principle) twelve 10 MHz licences (at a reserve price of € 4.36 million each). In the subsequent allocation phase, the ‘winning’ parties can express their preferences about placement within the spectrum band and, accordingly, it will be determined which part of the frequency space will go to which party. After the auction, the Minister will announce the winning parties and publish the entire bidding process.

Registrations for the frequency auction closed on 13 March. The RDI is currently assessing the registrations of the telecom companies. The intention is to start the auction this summer so that the auctioned frequencies can be put into use from August.

back to top


General deregulation of local access

In addition to 5G developments, the (re)regulation of (access to) fixed networks has also been high on the ACM’s agenda recently. After the CBb annulled the ACM’s 2018 Market analysis decision on Wholesale Fixed Access (“WFA”) in 2020, the ACM launched a new market analysis. According to the CBb, the ACM had not sufficiently substantiated that KPN and VodafoneZiggo possessed joint significant market power (“SMP”). As a result of the annulment, the obligations for KPN and VodafoneZiggo to meet reasonable requests for providing access ceased to have effect. The ACM subsequently launched a new investigation to assess whether (re)regulation of access is necessary on the basis of the Tw and/or the Dutch Competition Act (“Mw”).

After the 2022 KPN/Glaspoort Commitment Decision, the ACM published its new market analysis decision for access to the local loop in late 2023, in which it concludes that it sees no need for additional regulation. This is most likely also related to the new possibility to submit a specific access request to the ACM as referred to in Article 6.3 Tw (based on the European Telecom Code). Indeed, in December 2023, the ACM published its first decisions based on this new power in response to an access request by YouCa. These three decisions will be discussed consecutively.

 

KPN/Glaspoort commitment decision

Alongside its investigation into the general regulation of local access, the ACM investigated the access conditions of KPN and joint venture Glaspoort on the wholesale market under Article 24 Mw/102 TFEU. According to the ACM, they potentially abused their dominant position on the wholesale market for local access (ODF, MDF and VULA) to their copper and fibre-optic networks by not ensuring (effective) access to parties like Odido. On 25 August 2022, the ACM declared the commitments offered by KPN and Glaspoort to be binding. KPN and Glaspoort committed to offer alternative providers local access (VULA, ODF and ‘WBT local’) to their existing and new fibre-optic networks under improved (tariff) conditions until 2030. An overview of the specific conditions and tariffs can be found here. In view of the increasing fibre-optic coverage and migration offerings of the parties, the ACM does not consider it necessary to require commitments in respect of the copper network.

Interestingly, whereas in the WFA-decision the ACM assumed a single broad wholesale market for both (virtual) unbundled access and wholesale broadband access (“WBA”), the ACM now considers that central access forms such as WBA and wholesale multiplay (“WMP”) are insufficient substitutes for forms of access to the local loop. For parties that have already invested in rolling out backbone and equipment to local fibre-optic exchanges, for example, the provision of WBA or WMP is not an alternative. The ACM stresses that the market for local access should be the centre of competition, as (alternative) providers can exercise control over internet speed, retail price and other product characteristics instead of merely acting as a reseller.

 

Market analysis local access

Upon publication of the Commitment Decision, the ACM already announced that it saw no reason to additionally regulate the behaviour of KPN and Glaspoort through a market analysis for the time being. After an extensive consultation, the ACM published its new ‘Market analysis decision for access to the local loop‘ in December 2023, confirming its earlier intention.

In addition to the market for business network services (which we will not discuss here), the ACM assumes in the decision the retail market for internet access delivered over a fixed connection (i.e. copper, fibre-optic and cable networks). Based on the network coverage in the various PC-6 postal code areas, the ACM identifies five different relevant markets, namely:

  1. KPN/Glaspoort fibre-optic network;
  2. Third-party fibre-optic network – urban (with both cable and copper as alternatives);
  3. Third-party fibre-optic network – outlying areas (with copper as only alternative);
  4. Cable network (with copper as only alternative); and
  5. Copper network KPN (without alternative).

The ACM concludes that there is no risk of SMP for one or more parties in any of these relevant markets. In the areas where KPN/Glaspoort has rolled out a fibre-optic network (market 1), the ACM finds that the commitment decision provides sufficient safeguards for local access. Where third parties such as Delta Fiber and Open Dutch Fiber have rolled out their fibre networks (markets 2 and 3), these also provide wholesale access and, according to the ACM, alternative providers can compete effectively on the retail market. In areas where there is only a cable network (market 4) or a copper and cable network (market 5), the ACM foresees that any potential risks will be mitigated by the planned fibre-optic rollout in those areas, thus tending towards the (non-problematic) competitive situation as in markets 1 and 2. Although VodafoneZiggo has a solid position in market 4 and there are indications that point to the existence of a less competitive market, the ACM expects that, by the end of 2025, the Netherlands will be almost fully covered with one or more fibre-optic networks. This will rapidly reduce VodafoneZiggo’s market share in these areas, the ACM said.

As the ACM deems the retail market “effectively competitive” in view of the above, there is no risk of SMP and the ACM sees no reason to further regulate local access to any of the networks. The ACM does however indicate that it will continue to closely monitor both the retail and wholesale markets.

As to the market for fixed and mobile call termination, the ACM recently announced that it does see reason to maintain the current regulatory regime. In its recent draft decision, the ACM concludes that there is (still) a risk of SMP for call termination providers that have both separate fixed and mobile networks. It therefore proposes that the existing access and transparency obligations will continue to apply to KPN, Odido and VodafoneZiggo. An additional tariff obligation is proposed for KPN. For all other operators, the ACM  intends to withdraw the obligations. Interested parties can submit their views (digitally) until 8 April 2024.

 

Access requests based on Article 6.3 Tw

During the same period of the market analysis investigation, the ACM dealt with YouCa’s request for so-called symmetrical access to VodafoneZiggo’s cable network in Amsterdam based on Article 6.3 Tw. In our earlier blog, we already discussed this relatively new power of the ACM to impose access obligations in case of barriers to replication, in accordance with the European Telecom Code.

The ACM published two separate decisions for the two different bases provided by Article 6.3 first and third paragraph Tw. With regard to Article 6.3 first paragraph Tw, the ACM can order access based on a reasonable request for access to facilities inside buildings or the first concentration or distribution point (“FCP”) outside a building. Although YouCa actually needs the requested network access, has made real attempts to obtain access on a voluntary basis through negotiations, and replication by YouCa itself is economically inefficient, the ACM concludes that it is disproportionate to oblige VodafoneZiggo to provide access. This is mainly due to the fact that within VodafoneZiggo’s network, the street cabinets (or multitap) should be considered as the FCP. With the street cabinets not allowing for access facilities, VodafoneZiggo would have to expand the current sites. Not only does this bring about significant costs for VodafoneZiggo, it also seems unrealistic for YouCa to get access at the multitap sites. Thus, the ACM rejects YouCa’s request for access on the basis of Article 6.3 first paragraph Tw.

With regard to article 6.3 third paragraph Tw, access to a higher point in the network can be enforced, but only if there are high and non-transitory entry barriers that significantly limit competition in the retail (consumer) market. Following the new market analysis decision for access to the local loop, in which the ACM did not identify any risk of SMP, the ACM finds that there is (also) sufficient effective competition in the Amsterdam region. A relevant factor in that context is that KPN and Open Dutch Fiber have concluded a covenant with the municipality of Amsterdam to significantly accelerate the roll-out of fibre-optic networks in Amsterdam. Based on this prospective analysis, the ACM concludes that the market in Amsterdam is (or at least: will become) effectively competitive soon, so that there is no basis for imposing obligations on the basis of Article 6.3(3) Tw. In the end, YouCa will thus not get access to VodafoneZiggo’s cable network.

back to top


Conclusion

With the KPN/Glaspoort commitment decision and the ACM’s new powers to impose symmetric obligations to meet reasonable requests for providing access, the need for general ex ante regulation of local access on the basis of a market analysis decision seems to have faded. However, the question arises whether the ACM’s review of these individual access requests is too strict by linking the competitive situation to its market analysis. After all, the ACM has already decided that it sees no risk of SMP due to the increase of fibre-optic coverage, and established that there is (or at least: will be) effective competition on a wholesale level. This will render it difficult for third party providers to argue that individual access is necessary to maintain effective competition on the market.

2024 is nevertheless expected to mainly revolve around 5G. The upcoming frequency auction will reveal which parties manage to secure a spot on the spectrum, and whether the new mobile networks will be subject to a truly competitive playing field in the coming years.

Vision

DMA-obligations come into force; a bird’s-eye view of the (technical) changes by the designated gatekeepers

Compliance Day; as of today, all gatekeepers designated by the European Commission (“Commission”) must comply with the provisions of the Digital Markets Act (“DMA”). In the run-up to this deadline, gatekeepers have been aligning their core platform services (“CPS”) with the provisions of the DMA. At the time of drafting, Apple and Meta have published their compliance reports. It is expected that more will follow in the course of today.

In addition to the adjustments required to comply with the DMA, there have been other interesting developments. In our previous blog, we already touched upon the appeals brought by Apple, Meta, and ByteDance against the designation of one or more of their services as CPS. Meanwhile, the Commission has alsop decided not to designate certain CPS, and new gatekeepers have reported themselves to the Commission.

This blog provides an overview of the recent developments and the adjustments that gatekeepers will introduce or have already introduced to comply with the obligations under the DMA.


Overview of general substantive obligations for gatekeepers

On 6 September 2023, the Commission designated the following gatekeepers and CPS:

source: https://ec.europa.eu/commission/presscorner/detail/nl/qanda_20_2349

Some obligations stemming from the DMA are only relevant to a particular CPS. For example, the interoperability of number-independent interpersonal communication services is relevant to WhatsApp and Facebook Messenger, but not to Chrome or iOS. However, a number of obligations from the DMA apply to, and are relevant to, any kind of CPS and/or concern the interrelationship between (the use of) different CPS. The following provisions are particularly noteworthy in that context.

  • Article 5(2) DMA generally prohibits gatekeepers from combining personal data obtained from various (core platform) services without the end-user’s consent. Gatekeepers must thus obtain prior consent to combine and use personal data from different services in order to personalise ads and content. On the basis of Article 15 DMA, gatekeepers should furthermore provide a yearly audited description of any techniques for profiling of consumers that they apply (see for example Meta’s first report here).
  • Pursuant to Article 5(4) DMA, gatekeepers are required to allow business users to make offers (free of charge) to end-users acquired through the CPS or through other channels, and to conclude contracts with those end-users. Put differently, a gatekeeper may no longer prohibit business users from contracting or making offers for their services to end-users outside of the CPS. Also, the gatekeeper must – in accordance with Article 5(5) DMA – allow end-users to access and use certain services, content, subscriptions, features or other items through its CPS, even though the enduser acquired such access from the relevant business user directly (outside the CPS).
  • Article 5(8) DMA provides that gatekeepers may not require users to subscribe to or register with other CPSs as a condition for using or accessing a CPS of that gatekeeper (such as tying and/or bundling practices).
  • For consumers (end-users), Article 6(9) DMA is particularly relevant. Under this article, gatekeepers must allow end-users (upon request) to transfer the data they have provided or generated, and end-users must be given continuous real-time access to that data (data portability). The equivalent of this data portability obligation towards business users is contained in Article 6(10) DMA.
  • Finally, in general, under Article 6(6) DMA, gatekeepers may not impose technical or other restrictions on end-users switching to other software applications and services accessed through the gatekeeper’s CPSs. In the same light, under Article 6(13) DMA, gatekeepers may not impose disproportionate general conditions for terminating the provision of a CPS. Moreover, these termination conditions must be exercisable without undue difficulty.

As these obligations apply in any case, they are not in principle elaborated in the overview below. However, the relevant provisions of the DMA are discussed when the gatekeeper has explicitly proposed adjustments to meet these obligations.

back to top


Alphabet

 

Alphabet is the gatekeeper with the most CPS. As a result, there are many changes that need to be implemented to comply with the DMA.

To comply with Article 5(2) DMA, Alphabet will now let end-users decide whether to keep all CPS linked. If the CPS are linked, end-user personal data can be exchanged. In addition, a “consent or pay” option – where consumers consent to the use and combining of their personal data or pay a (monthly) fee to use the CPS – is still under discussion with the Commission.

In light of Article 6(9) DMA, regarding data portability, Alphabet has already been using Google Takeout for a while now. This tool allows users to download or transfer their data to another platform free of charge. To bring this process in line with the provisions of the DMA, Alphabet will soon test a new API (‘Application Programming Interface’) to facilitate the download and transfer of data. Alphabet has also announced to launch a data portability software in Europe this week, making it easier for developers to move user data to a third-party app or service.

Another significant change for Alphabet is the effect of Article 6(5) DMA, which in short prohibits self-promotion in rankings and requires the gatekeeper to use transparent, fair and non-discriminatory terms for those rankings. For Alphabet, this particularly affects the CPS Google Search, Google Maps, Google Shopping, and Youtube. For Google Shopping, Google Maps, and Youtube, Alphabet has announced that these services will henceforth no longer be linked to Google Search’s search results page by default. However, end-users can choose to link (one of) these services to (the search results of) Google Search by default.

As for Google Search itself, Alphabet says it is adding a tab to the search screen. This will not only allow users to filter by things like videos and images, but also by comparison services. In addition, Alphabet will remove its own specialised results window for flight searches (see below).

Instead, a carousel is displayed showing links to various comparison websites. Alphabet has shared the following possible examples.

For categories like hotels, Alphabet is starting to test a dedicated space for comparison sites as well as direct suppliers to display more detailed results, including images and reviews.

With regard to Alphabet’s advertising service, the tech giant’s most lucrative (core platform) service, Alphabet is required under Articles 5(9), 5(10) and 6(8) DMA to provide certain data to advertisers when they request it. The announced compliance plans for this are still being coordinated with the Commission.

For Google Android and Google Chrome end-users should be allowed to change their default settings pursuant to Article 6(3). End-users should also be allowed to switch browsers under Article 5(7) DMA. Alphabet has indicated that it will add a choice screen for the default search engine and browser during the initial setup of a device using Alphabet’s CPS, as illustrated below.

Finally, Alphabet must now also allow end-users to use other app stores under Article 6(4) DMA. As regards its Play Store, Alphabet has announced that app developers will be able to use alternative payment methods.

back to top


Amazon

 

Like Alphabet, Amazon also has a lucrative advertising service. Thus, Amazon too has to provide certain data to advertisers upon request under Articles 5(9), 5(10), and 6(8) DMA. Amazon has indicated that from 7 March 2024, it will provide comprehensive reports detailing ad costs paid by advertisers and received by publishers, displayed on third-party websites and applications. According to Amazon, these reports provide insight into the financial transactions between advertisers and publishers. The reports can be accessed by advertisers through the ‘Amazon Ads dashboard’, and by publishers through the ‘Amazon Publisher Services portal’. In doing so, advertisers and publishers can choose whether to disclose their cost data, or whether the data will be included in standard aggregated metrics. This flexibility allows users to adjust the level of transparency based on their preferences and business needs, Amazon said.

Amazon’s main obligation with regard to its best-know service, Amazon Marketplace, can be found in Article 6(2) DMA. This article prohibits the gatekeeper from using non-public data generated by competing business users for its own CPS. Article 6(5) DMA furthermore contains a prohibition on self-preferencing relating to the ranking of competing products and services on the gatekeeper’s platform. These provisions reflect the Commission’s 2022 investigation into Amazon’s Buy Box and Prime Programme. The investigation was eventually concluded through commitments.

back to top


Apple

 

Apple appealed its gatekeeper designation, as well as the App Store’s qualification as a CPS, on 16 November 2023. Nonetheless, Apple must comply with its obligations under the DMA as of today. It has therefore announced the following changes for its CPS. These will be briefly discussed below. In addition, Apple has published its first compliance report on 7 March. In this document, it sets out the specific obligations and (proposed) changes in more detail.

The App Store brings consumers and app developers together. For developers, the following will change. They will have options to use (other) payment services to finalise in-app purchases. Until now, Apple only enabled app developers to use its own payment system. In 2021, the ACM already imposed an order subject to a penalty payment on Apple for the mandatory use of its own in-app payment system for dating app providers. Apple eventually incurred the maximum amount of € 50 million in penalty payments. In accordance with Article 5(7) DMA, there will also be new options for processing payments via referrals: end-users can then complete a transaction for digital goods or services on the developer’s external website. There is still an ongoing discussion on the (other) conditions Apple imposes for the use of the App Store. For example, Apple envisages to maintain the ‘Core Technology Fee’ it charges to app developers in order to make use of the App Store.

These features are accompanied by a number of other changes. For example, Apple is introducing labels on the App Store product page that inform users when an app uses an alternative payment processing method (compared to Apple’s). There will also be so-called in-app ‘disclosure sheets’, which alert users when they are no longer making transactions through Apple, but using an alternative payment service. In addition, Apple is coming up with new processes to check whether developers accurately communicate information to end-users about transactions using alternative payment services. These changes are being introduced to protect consumers, Apple said.

Regarding the iOS operating system, Apple has indicated that new options are coming for distributing iOS apps through alternative app marketplaces. It will also become possible, using a new framework and new APIs, to develop alternative app stores and/or browser engines for iOS. Previously, only WebKit, the browser engine behind Apple’s Safari, could be used.

As for Safari itself, Apple is introducing a new selection screen that appears when users first open Safari in iOS 17.4 or later. On that screen, EU users are asked to choose a default browser from a list of options. It allows end-users to change their default settings and switch browsers (Articles 5(7) and 6(3) DMA).

All these CPS will also come with the ability to transfer/retrieve data, in line with Article 6(9) DMA. For instance, end-users will be able to retrieve and export new data on their use of the App Store to an authorised third party on Apple’s Data & Privacy site. App developers can use a form to submit requests for interoperability with iPhone and iOS hardware and software features.

Finally, Apple has indicated that it is introducing a number of adjustments in relation to iMessage, even though Apple’s service has not been designated as a CPS following a Commission investigation. Apple has pledged to improve iMessage’s interoperability with other communication services by implementing an RCS (‘rich communication services’) system. RCS includes features such as read receipts and type indication, which are already used with, for instance, WhatsApp. Green messages (messages between Apple and Android, for example) will also get these functionalities. Blue messages are those between devices of iOS users.

back to top


ByteDance

 

ByteDance, the company behind social network TikTok, unsuccessfully sought an interim injunction to suspend its designation as gatekeeper. In short, the President of the European General Court ruled in his order that ByteDance had not claimed, let alone demonstrated, that the alleged financial damage was serious and irreparable. This lacks the urgency required for an injunctive relief.

Thus, ByteDance too has to comply with the DMA’s obligations from today onwards. On 4 March, ByteDance published several changes on its website relating to the DMA. With TikTok’s ‘Download Your Data’ tool, end-users can request a copy of their TikTok data for access and portability purposes. TikTok has also launched a new ‘Data Portability API’, which allows registered developers to request end-users permission to transfer a copy of their TikTok data. End-users can allow for either a one-time or recurring transfer, and will be able to select specific categories of data or their full archive. TikTok also offers certain in-app and web analytics allowing business accounts to measure their performance. This includes an ‘Accounts API’ where businesses can access data related to their TikTok accounts.

back to top


Meta

 

Meta has also appealed the qualification of some of its services as CPS on 15 November 2023. For instance, Meta disagrees with the Commission that Facebook, Facebook Messenger and Facebook Marketplace qualify as CPS. Nevertheless, in the meantime, Meta must comply with its obligations under the DMA.

Meta shows its proposed changes on its website. On 6 March 2023, Meta has furthermore published its first consumer profiling report and compliance report in which it further explains and illustrates the changes, mostly applicable as of today.

First of all, with regard to all of Meta’s CPS, it is not allowed to combine personal data from different (core platform) services without end-user consent (Article 5(2) DMA). Therefore, Meta now gives its end-users the choice to exchange data between Meta’s different (core platform) services. For example, end-users who have already chosen to link their Instagram and Facebook accounts can now choose to keep their accounts connected via the ‘Accounts Centre’, so that their information is used between their Instagram and Facebook accounts, or to manage their Instagram and Facebook accounts separately, so that their information is no longer exchanged. The same goes for Facebook Marketplace, for example. The compliance report contains specific examples.

With regard to Facebook and Instagram, end-users also have the option to use these social networks for free with ads, or to subscribe for a fee to stop seeing ads. If people subscribe to stop seeing ads, their information will not (no longer) be used for ads. This had previously been introduced by Meta as a result of the Digital Services Act coming into force. Although under the Digital Services Act, the Commission has now sent a formal information request to Meta in response to these ad-free subscriptions.

For WhatsApp, Article 7(1) DMA is particularly relevant. This article requires interoperability between number-independent interpersonal communication services. That means, simply put, that end-users should be able to chat with each other on for example WhatsApp via Facebook Messenger, or Apple’s iMessage, discussed above. Meta has requested the Commission for a six-month extension to the obligation to make WhatsApp interoperable.

To comply with this, Meta envisages to add a section to WhatsApp’s messaging service. If the end-user goes to this section, they will arrive at third-party chat services. WhatsApp is now testing this feature on iOS and Android. The examples below show what this could look like.

Meta has not yet announced any concrete changes on Facebook Messenger’s interoperability with other number-independent interpersonal communication services.

Finally, in relation to its advertising services, Meta Ads, Meta is required to provide data to advertisers under Articles 5(9), 5(10), and 6(8) DMA. Meta’s compliance report contains the first suggestions in that regard.

back to top


Microsoft

 

Microsoft has displayed and explained all its planned changes for Windows on its website and in a separate blog post.

Microsoft is prohibited by Article 5(2) DMA from combining personal data from different (core platform) services. This applies to both Windows and LinkedIn. Microsoft now asks users if they want to synchronise their Microsoft account with Windows so that their data is available on other Windows devices and in Microsoft products where users log in (see also the image below). The information stored in the Microsoft account of an end-user who also uses other Microsoft products is then also available in Windows. This makes it possible for an end-user to restore settings, apps and passwords from another device, as well as synchronise set preferences between devices.

With regard to Windows, Articles 6(3) and 6(4) DMA additionally require that end-users be given the option to change their default settings. Microsoft indicates that end-users will be enabled to remove the Microsoft Edge browser. It also adds new ‘integration points’ for applications in Windows, allowing end-users, for example, to add a search application to the search bar on the Windows taskbar. In this way, end-users can switch from the Bing search engine to another search engine of their choice.

Microsoft will also stop giving recommendations to set Edge as the default browser, including during the configuration process when users first set up or update Windows.

Finally, all (default) apps in Windows can be uninstalled, such as the camera and photo app, Cortana (virtual assistant), Bing’s web search, and Microsoft Edge.

back to top


Possible new gatekeepers and CPS: Booking.com, X and ByteDance

Just before Compliance Day, Booking.com and X (formerly Twitter) notified the Commission that they meet the quantitative criteria to be designated as gatekeepers. ByteDance, already designated as a gatekeeper with TikTok as CPS, notified its advertising services, TikTok Ads, to the Commission.

Online intermediation service Booking.com said it expects to meet the DMA’s turnover thresholds from the end of 2023 and thus qualify as a gatekeeper. The reason that Booking did previously not meet the quantitative thresholds is probably mostly due to the (aftermath of the) COVID-19 pandemic, which put a heavy strain on the travel and hotel industry. Of particular relevance to Booking.com would be Article 5(3) DMA, which prohibits it from imposing (narrow or broad) parity clauses on corporate users. This use has already been investigated and fined at national level in recent years, and is now before the CJEU following a preliminary reference from the Amsterdam District Court (see our earlier blog for a further explanation of parity clauses). Regarding X, the most relevant obligation can be found in Article 6(12) DMA pursuant to which it has to apply FRAND criteria for access to its social network.

The Commission now has 45 working days to designate the companies as gatekeepers. If the Commission designates them as gatekeepers, the brand-new gatekeepers will have six months to comply with the obligations under the DMA.

Conclusion

With the substantive obligations for the first six gatekeepers coming into force, the Commission will be primarily occupied with their proposed and/or implemented amendments in the coming months. Especially the adjustments of Meta and Apple have received strong criticism so far. The coming period will show to what extent there is still room for a regulatory dialogue, or if the Commission has shut the door and will initiate enforcement. In addition, the new rules also enable third parties to initiate (private) enforcement against any of the Gatekeepers on the basis of (alleged) infringements of the DMA.

back to top

Vision

Private equity under the microscope of competition authorities

In a recent radio interview with BNR, chairman of the ACM Martijn Snoep explicitly expressed its concerns regarding roll-up acquisitions, whereby private investment companies (“private equity firms”) successively acquire several smaller companies within a given sector. For a long time, competition authorities paid little attention to private equity firms. That has changed. Both the ACM and other national competition authorities announced that they will take a (more) critical look at the role of private equity firms in acquisitions. Apart from merger control, private equity firms must also take into account important developments including foreign direct investment (“FDI”)-screening legislation, foreign subsidies and public and private liability for cartel violations of portfolio companies.

In this blog, we dive into four recent competition law and regulatory developments that private equity firms and institutional investors should consider, namely:


Tighter scrutiny of roll-up acquisitions and gun-jumping

Roll-up acquisitions

Recently, competition authorities have focused their attention on private equity firms that sequentially acquire small firms within a specific sector. According to the authorities, these roll-up acquisitions can create or reinforce (local) dominant positions, which can lead to higher prices and/or a decrease in quality or consumer choice. In the Netherlands, there have been some concerns about a consolidation trend by private equity firms in the areas of childcare, veterinary clinics and specialised clinics in the healthcare sector (see for example the Parliamentary questions on the growing role of private equity in healthcare and childcare).

Although the ACM wishes to act against roll-up takeovers, its enforcement options are rather limited for the time being. Dutch merger control offers little or no relief. Many acquisitions by private equity firms do not fall under the notification obligation because they do not meet the Dutch turnover thresholds. The ACM does theoretically have the possibility to refer transactions that are not subject to notification in the Netherlands to the European Commission (“Commission”). Under a relatively recently introduced Commission policy on the application of Article 22 EU Merger Regulation (“EUMR”), one or more national competition authorities may refer a concentration to the Commission for examination where the transaction (i) affects trade between Member States, and (ii) threatens to significantly impede competition in the territory of the Member State(s) submitting the request.

In practice, however, Article 22 EUMR offers limited scope for the ACM to tackle roll-up acquisitions. This is because many of the companies acquired in a roll-up only operate on local markets. If the buyer and target are furthermore not active around border areas, the transaction will thus usually not affect trade between Member States. Such acquisitions would then not be eligible for referral. Yet, even if there would be a (potential) cross-border element, it remains to be seen whether the Commission is willing to assess such (generally rather small) transactions. The Commission has previously indicated that a referral under Article 22 EUMR is particularly intended for acquisitions of promising start-ups where the turnover of the start-up does not accurately reflect the current or future potential of the company. So far, the Commission also seems mainly interested in referrals of transactions in the pharma industry and digital markets. Therefore, it is relatively unlikely that the Commission will assess small and (very) local roll-up acquisitions under Article 22 EUMR. This also seems to be in line with the ACM’s position. For instance, the ACM’s board chairman said in a speech last year: “At the moment we cannot do anything about small transactions that fall below the notification thresholds, but that do lead to local competition issues (…) we cannot send a merger-to-monopoly in a small town to Brussels.” (freely translated)

At this moment, private equity firms engaging in small acquisitions do not yet have much to fear from the ACM. However, this may soon change with two legislative changes the ACM seems to be pushing for:

  • Removal of Article 24(2) Dutch Competition Act (“Mw”). In the Towercast-judgment, the Court of Justice of the European Union (“CJEU”) ruled that a non-notifiable concentration can constitute an abuse of a dominant position. At present, the Dutch Competition Act still provides that bringing about a concentration cannot be regarded as an abuse of a dominant position (Article 24(2) Mw). This deviates from European case law, which is likely to result in an amendment to the Dutch Competition Act.
  • Introducing a ‘call-in power’. In addition, the ACM argues for the introduction of a so-called ‘call-in power’, providing the ACM the power to indicate, within a certain period of time, that an acquisition must be notified despite the fact that the turnover thresholds are not met. Competition authorities in Sweden, Iceland, Norway, Italy and Ireland already have such a power. This legislative change is a lot more far-reaching and controversial than the first mentioned legislative change and is therefore unlikely to take place in the short term.

Gun-jumping by private equity

Concentrations that exceed certain turnover thresholds may only be implemented after approval is obtained from the ACM. Competition authorities have in recent years strictly enforced violations of the notification- and standstill obligations laid down in (European) merger control rules, so-called ‘gun-jumping’. Based on the latest case law, private equity firms should take into account the following points (for a detailed overview, see also our blog on gun jumping):

  • If a takeover is notifiable, parties may only exercise control over the target company upon the ACM’s approval. However, the buyer and seller may enter into agreements necessary to protect the value of the target. Recently, telecom company Altice did not comply with these rules and was fined € 124.5 million by the Commission. It established that, before the Commission’s approval, Altice already exercised decisive influence over PT Portugal as it was given certain veto rights regarding the appointment of senior management at PT Portugal, pricing policy and several key contracts. The fine was later upheld by the CJEU.
  • A so-called warehousing structure can entail significant competition risks. A warehousing structure involves temporarily ‘parking’ the target company with an interim buyer with a view to resell to the ultimate buyer once the relevant competition authority has given its approval. Warehousing structures are regularly used by private equity firms to minimise the time between signing and closing. Canon for example used such a warehousing structure in its acquisition of TMSC (a subsidiary of Toshiba). According to the Commission, both steps constituted one concentration within the meaning of European competition law. The implementation of the first step of the warehousing structure therefore already led to the partial realisation of the concentration. According to the Commission, this violated the standstill obligation under the Merger Regulation. Canon was fined EUR 28 million, which was upheld by the General Court.
  • Gaining de facto control also triggers a notification and standstill obligation. The Commission for example fined Norwegian salmon farm Marine Harvest for carrying out a concentration without prior approval. Marine Harvest acquired a 48.5% stake in Morpol. Marine Harvest then made a public offer for the remaining shares in Morpol and notified the transaction to the Commission. However, the Commission found that in acquiring a 48.5% stake, Marine Harvest had already acquired de facto control. Given the fragmentation of the remaining shares and attendance figures at previous shareholder meetings, Marine Harvest already gained a majority at those meetings, the Commission said. Marine Harvest was fined EUR 20 million, which was upheld by the CJEU.

Private equity firms operating in the healthcare sector should also bear in mind that, pursuant to Article 49a (1) of the Health Care Market Regulation Act, there is an obligation to report to the Dutch Healthcare Authority (“NZa”) if the concentration involves a company that employs or contracts at least 50 healthcare providers. In November 2023, a number of companies of the Dutch Pharmaceutical Pharmacy Fund were fined by the NZa for failing to report several concentrations.

back to top


Increased FDI-screening

Over the years, more and more states have introduced specific FDI-legislation. On 1 June 2023, the Dutch FDI Screening Act (Wet Veiligheidstoets investeringen, fusies en overnames (“Vifo Act”)) entered into force. This law introduces a security test for investments, mergers and acquisitions that may pose a risk to national security. Below, we provide a brief explanation of what the Vifo Act’s implications are for private equity firms and other investors (for a more detailed description of the Vifo Act, see this blog).

On the basis of the Vifo Act, there is an obligation to report to the Bureau for Verification of Investments (Bureau Toetsing InvesteringenBTI”), part of the Ministry of Economic Affairs and Climate Policy, any acquisition activity in vital providers, managers of corporate campuses and undertakings active in the field of sensitive technology. This also applies when the acquirer is based in the Netherlands.

If a notification requirement applies, the BTI examines whether the acquisition activity leads to undesirable strategic dependencies, an impairment of the continuity of vital processes or an impairment of the integrity and exclusivity of knowledge and information. The BTI’s investigation focuses not only on the (direct) acquirer but also on the ownership structure and relationships with other parties. If a private equity firm is involved in a transaction covered by a notification obligation, the BTI specifically asks for detailed information on limited partners (whose involvement in an investment is often limited to providing capital to the company). The BTI wants to ascertain what the influence of these limited partners is and what their actual motives are. Sometimes it turns out that limited partners have greater influence than usual and, for example, that they have a strategic intent to combine the technologies of various companies in which they hold an interest. The BTI takes this into account in its assessment.

The BTI will then decide whether the acquisition activity poses a risk to national security. If such is the case, it may impose certain conditions or, as an ultimate measure, even ban the acquisition activity altogether.

The Vifo Act has a major impact on private equity firms, including venture capital investors, because it is in particular among companies developing innovative technologies that there is a high demand for venture capital, which is often provided by private equity and venture capitalists. The Vifo Act applies when acquiring or increasing significant influence over companies operating in the field of ‘highly sensitive technology’. The Scope of Application of Sensitive Technology Decree of 4 May 2023 qualifies as highly sensitive technologies certain specific dual-use and military products, in addition to quantum technology, photonics technology, semiconductor technology and High Assurance products (e.g. information security software). Significant influence already exists if the acquiring party can cast 10% of the votes in the general meeting and/or it can influence the appointment/dismissal of board members. Moreover, (another) subsequent notification must be made if the voting rights of the acquiring parties increase to 20% and to 25% of the votes. In short, only a relatively small investment in, for instance, a start-up or scale-up operating in the field of highly sensitive technology, can already trigger a notification obligation under the Vifo Act.

When making investment decisions, private equity firms should therefore consider the following points:

  • Check in advance whether the obligation to notify under the Vifo Act applies. It is not always obvious (at first glance) whether a duty to notify exists and this sometimes requires a more extensive analysis. It is important to seek advice on this in advance. Parties that fail to report a transaction risk a fine of € 900,000 or a fine of 10% of the annual turnover.
  • Be prepared for longer timelines for implementing the proposed transaction/investment. A transaction may be delayed up to nine months due to a BTI investigation. The transaction may not be implemented until approval is obtained. Private equity firms (as well as targets) will have to take these timeframes into account when choosing a long stop date in their transaction documents.
  • The outcome of the BTI’s investigation is generally difficult to predict. The BTI’s assessment does not include strictly defined investigative questions and is also influenced by (geo)political considerations. Parties should take into account that an extensive investigation may take place with the final verdict that the transaction may only take place under certain conditions or even be prohibited altogether.

back to top


Notification obligation for foreign subsidies

In addition to merger control rules and FDI legislation, private equity firms must from 12 October 2023 onwards also take into account the obligation to notify concentrations or participations in public procurement procedures in light of previous funding from non-European governments (“third countries”). This notification obligation is laid down in the Foreign Subsidies Regulation (“FSR”), and applies if certain financial thresholds are met (for a detailed discussion of the FSR, see our blog). For private equity firms, the following thresholds are relevant:

  1. at least one of the merging parties (in case of mergers), the target company (in case of acquisitions), or the joint venture is based in the European Union and has a total EU turnover of at least € 500 million;
  2. the undertakings concerned have collectively received more than € 50 million in financial contributions from third countries during the three years preceding the conclusion of the agreement. For mergers, the undertakings concerned include the merging parties; for acquisitions, both the buyer(s) and the target; and for joint ventures, the joint venture partners and the joint venture itself.

In addition to these specific ‘triggers’, the Commission also has an ex officio power to examine certain foreign financial contributions (read more here).

Private equity firms would therefore do well to consider the following points:

  • While most FSR notifications will not be problematic and are approved in the first phase of a Commission investigation, private equity firms should be aware that the FSR may delay the proposed merger. For mergers, the Commission has 25 working days after the notification to decide whether to launch an in-depth investigation. This investigation can take 90 working days (which can be extended by 15 working days). The M&A process can therefore be delayed by 130 working days in some cases.
  • It is a lot of work to collect all information on foreign contributions and assess whether a notification is required. It is therefore advisable for companies to get their financial records in order so that it can be quickly assessed whether a notification is required and the required information for notifications can be gathered quickly. Foreign financial contributions are defined broadly and even include the supply or purchase of goods or services to third countries.
  • If a notification requirement applies under the FSR, provisions relating to Commission’s approval procedure will also need to be included in the purchase agreement.

back to top


Public and private liability of private equity firms for cartel violations

Private equity firms are not only subject to ex ante merger control supervision and FDI-legislation, but may also increasingly face both public and private liability for cartel violations by portfolio companies.

Public liability

It has long been established that a parent company can be held liable for a cartel infringement by its subsidiary even if the parent company was not involved in the cartel (doctrine of attribution). For instance, in its 2009 Akzo-Nobel judgment, the CJEU ruled that there is a presumption of (indirect) decisive influence of a parent company over a subsidiary and thus liability for a cartel infringement of its wholly-owned subsidiary. However, it was unclear for a long time whether investment companies and private equity firms could also be held liable for a cartel violation of a portfolio company. In many cases, private equity firms are relatively distant from the (day-to-day) operations of portfolio companies. In 2021, the CJEU confirmed in the Goldman Sachs judgment that the doctrine of a parent company’s liability for a subsidiary’s antitrust infringement also applies in full to investments made through an investment fund (and thus also to private equity).

According to the CJEU in the Goldman Sachs judgment, a company that holds all the voting rights of the subsidiary’s shares is in a similar position to a company that holds (almost) 100% of the share capital. In both cases, there is a presumption that the parent company can exercise decisive influence over the subsidiary, the CJEU ruled. US investment bank Goldman Sachs held 100% of the voting rights in an indirect portfolio company that had participated in the so-called powercable cartel. At the start of the cartel infringement, Goldman Sachs initially held 100% of the share capital, but during the infringement period its stake eventually fell to just 33%. Even during the period that Goldman Sachs held only 33% of the share capital, it continued to exercise decisive influence over the subsidiary given its 100% voting rights, according to the CJEU. To reach that conclusion, the CJEU considered it important that the parent company could appoint and dismiss the board and convene the shareholders’ meeting. The Commission imposed a fine of € 37 million.

In the Netherlands, the attribution doctrine has been applied to investment companies before. In 2017, the Rotterdam District Court upheld a fine imposed on private equity investor Bencis for the participation of its subsidiary in the so-called flour cartel.

Private cartel damages claims

The extension of the attribution doctrine affects not only the liability of the parent company in the context of public enforcement (i.e. liability for a cartel fine) but also liability for private cartel damages claims. In the Skanska-judgment, the CJEU ruled that a subsidiary can, under certain conditions, be held liable for damages resulting from a cartel infringement committed by its parent company. This means that a private equity firm that is part of an undertaking held liable under an infringement decision of the Commission (or a national competition authority) can also be held civilly liable in follow-on cartel damages proceedings.

Key take aways liability private equity for cartel infringement

In light of this attribution doctrine, private equity firms would do well to specifically examine whether the target might be (or have been) involved in a competition infringement during its due diligence investigation However, it is not unlikely that infringements will not (directly) come to light when performing a due diligence investigation. It is therefore always advisable to include sufficient warranties and indemnities in the purchase agreement. Since both the competition authority and private parties have some discretion as to which entity to address for an infringement and can also choose to fine the buyer, even when it was not exercising control (yet) at the time of the infringement period, it is wise to take this into account when formulating any indemnities.

back to top


Final remarks

Private equity firms are fully in the crosshairs of competition authorities. Key developments in merger control, FDI-legislation, foreign subsidies and private equity firms’ liability for cartel violations highlight the importance for private equity firms to take into account the competition rules when deciding on an investment. Although the ACM still has few options under the current merger control rules to review roll-up acquisitions, it is lobbying for legislative reforms that may bring about some fundamental (jurisdictional) changes rather soon. In addition, FDI-screening laws force private equity firms to take into account (additional) disclosure obligations and strategic risks when investing in critical sectors. Recent case law confirms that private equity firms can be held liable for cartel violations by portfolio companies.

In view of these developments, it is advisable for private equity firms to thoroughly investigate whether the proposed investment triggers any notification obligation under merger control, FDI rules and/or the FSR, and to investigate competition risks, including appropriate warranties and indemnities in the transaction documents.

Vision

MaaS: a (digital) revolution in the mobility sector

MaaS: a (digital) revolution in the mobility sector 

The convergence of the mobility sector with competition law is becoming more pronounced. In our earlier Competition Flashback and blog, we delved into the cartel damages in the trucks cartel, and the current battle for liberalisation of the railway market. Another development in the mobility sector where competition law plays an increasingly prominent role is the EU-wide emergence of Mobility as a Service (“MaaS”).

MaaS is a type of service that revolves around the planning, booking, and payment of a ‘multimodal’ journey through a single app or website. A multimodal journey may consist of a combination of public transport, a shared car, scooter or bike, taxi or alternative transportation modes. Additional services such as parking, refuelling and charging can also be made available through MaaS. There is a growing demand among end-users in the mobility sector for enhanced convenience, aiming for a streamlined and personalised journey experience that is both up-to-date and optimised.

Functioning as a multi-sided digital platform, MaaS services bring together various mobility services, payment services, and travellers. This development, like other aspects of the digital economy, raises competition law concerns. The combination of vertically integrated and often dominant (public transport) companies, platform accessibility, interoperability, and the exchange of commercially sensitive information, make MaaS noteworthy from a competition law perspective. This blog explores some key points.

The essence of MaaS

As mentioned, MaaS aims to provide a personalised journey through integrating various mobility services. This is realised through a digital platform (“MaaS platform”) where consumers can fully plan, book and pay for their journeys. A MaaS platform is typically presented as either an application or website, like 9292.nl. The platform consists of two key components: the frontend, representing the user interface, and the backend, encompassing the technical infrastructure. The technical infrastructure facilitates the integration of services and products, including (real-time) information relating to use of these services and products (“mobility data”). This way, customers are offered a wide range of transportation options.

When MaaS functions effectively, it has the potential to enhance market dynamics within the mobility sector by directly linking supply with demand and creating more competition. By introducing variability on the supply side of mobility services, MaaS can streamline an inflexible transportation system. Beyond the typical market-related benefits, MaaS also brings additional advantages, such as enhancing accessibility in rural areas, mitigating congestion, and promoting more sustainable modes of transportation. The European Green Deal recognizes multimodal transportation as one of the main spearheads of environmentally friendly transportation.

Providers of MaaS services (“MaaS providers”) rely on mobility service providers, particularly public transportation and shared transportation providers (“transport companies”). MaaS providers can only offer an integrated selection of travel options if these transport companies authorise the inclusion of their services and products on the MaaS platform. Moreover, for the effective functioning of MaaS, it is imperative that transport companies supply relevant mobility data, encompassing e.g. travel times, delays, updates, occupancy rate in trains, congestion status of roads, and real-time availability of shared vehicles or charging stations. Without such vital information, MaaS providers cannot deliver (competitive) multimodal travel experiences.

Potential abuses of MaaS providers in Spain, Germany and Italy

Due to vertically integrated, dominant (public) transport companies with a dual role in MaaS, competition authorities in Europe have closely monitored MaaS since several years. Competition law concerns are primarily related to exclusionary abuses, particularly the denial of (effective) access to transport products and associated mobility data by these dominant companies.

Commission enforces commitments from Renfe 

For instance, on 17 January 2024, the European Commission (“Commission”) concluded an investigation into Renfe, the Spanish national train operator, with binding commitments. Renfe functions not only as railway company but also as a MaaS provider, selling its tickets through various channels, including its own MaaS platform (dōcō). In addition, Renfe’s tickets are offered on other (third party) MaaS platforms in Spain, such as Omio.com.

The Commission’s investigation was prompted by concerns about Renfe’s refusal to grant competing ticket sellers, including MaaS providers, access to the complete range of tickets and (real-time) mobility data. Notably, Renfe did provide its own MaaS platform with access to all ticket options and associated mobility data. The Commission preliminary found that Renfe exploited its dominant position in the market for train passenger services in Spain and the market for online passenger rail ticket distribution in Spain.

To address the Commission’s concerns, Renfe made a series of commitments in June 2023, which now have been made legally binding. As of 29 February 2024, Renfe is obligated to provide competing ticket sellers with access to the complete, current and future range of tickets, along with all the (real-time) data available on Renfe’s own platforms. Renfe is also prohibited from imposing unfair, unreasonable, or discriminatory commercial or technical conditions that hinder access to its content and data. Furthermore, any new content and data, as well as changes in technical specifications, must be announced at least 4 and 2 months before implementation, respectively. Additionally, Renfe must apply a less stringent Look-to-Book (“L2B”) ratio to competing ticket sellers. The L2B ratio reflects the relationship between the number of availability requests related to potential sale of tickets made by third parties into Renfe’s ticket sales system (‘look’) and the number of actual sales (‘book’) during a given period of time. Lastly, Renfe must not exceed the maximum Error Rate (“ER”) and the maximum margin for ticket unavailability (unavailability rate, “UR”). Implementing a maximum ER and UR contributes to increased reliability of sales through third-party platforms. All commitments are in force for an indefinite period and subject to review every 10 years.

 Bundeskartellamt imposes measures on Deutsche Bahn 

In Germany, the Bundeskartellamt (“Bka”) has ordered the German national train operator, Deutsche Bahn (“DB”) to change its conduct in the summer of 2023. In addition to its role as train operator, DB offers MaaS services via its app (DB Navigator). The Bka’s investigation, initiated in 2019, reveals that DB is leveraging its key position in the mobility market to restrict competition from other MaaS providers. For instance, DB failed to provide competing MaaS providers with continuous, non-discriminatory access to (real-time) essential information related to its train services. Consequently, these competitors lacked access to details on delays, cancellations, maintenance, etc. Moreover, DB imposed advertising bans and enforced resale price maintenance in contracts with competing MaaS providers, and refused to pay commissions to third party resellers for facilitating the booking and payment of a DB ticket.

Following lengthy negotiations, the Bka has ordered DB to cease its behaviour through a formal decision. Four compliance measures have been imposed. DB is now prohibited from applying advertising and discount bans, and is required to pay commissions to parties facilitating the booking, payment, or mediation processes for DB. Additionally, the Bka demands that DB, to ensure competitors have access to essential mobility data, implements fair terms, both technically and commercially, for providing this data within a specified timeframe. The Bka emphasises that DB and its partners retain the freedom to define the precise conditions. The implementation term for these measures has not yet commenced due to DB’s appeal against the Bka’s decision. DB asserts that the Bka’s decision contradicts the principle of commercial freedom.

Trenitalia’s commitments accepted by the Italian competition authority 

In May 2023, the Italian Competition (“AGCM”) concluded a competition investigation into Trenitalia with commitments. Trenitalia holds a legal monopoly in the market for regional (“RG”) and inter-city (“IC”) rail travel in Italy. It also operates as a MaaS provider. Following a complaint received in March 2022 regarding Trenitalia’s practices, the AGCM officially initiated an investigation in July 2022.

The investigation revealed that Trenitalia was leveraging its dominant position in the RG and IC train travel market to extend and preserve its market power in the high-speed (“HS”) train travel market. In that market Trenitalia competes with Italo, which is the only other supplier of HS train services in Italy and a competing MaaS provider. Trenitalia refused to give Italo access to essential data relating to its RG and IC train services. This hindered Italo from offering a multimodal journey in which Trenitalia’s services were combined with its own HS train services.

Despite an agreement reached between Trenitalia and Italo during the AGCM investigation to eliminate these barriers, the AGCM asserted that Trenitalia persisted in distorting competition between the two vertically integrated train operators. Eventually, Trenitalia committed to providing Italo with access to essential data about its RG and IC tickets. In May 2023, AGCM officially declared these commitments binding, thereby concluding the investigation.

 MaaS in the Netherlands 

The recent examples discussed above illustrate how dominant transport companies – mainly national train operators – in Europe regularly display anti-competitive behaviour towards competing MaaS providers that depend on them. The Consumer and Market Authority (in Dutch: Autoriteit Consument en Markt, “ACM”) acknowledges these risks and has also previously expressed concerns. In its MaaS Market Study of 8 May 8 2021 (“Market Study”), the ACM highlights concerns about an undesirable winner-takes-all scenario, where a dominant (tech) company, such as a vertically integrated public transport entity, consolidates excessive power. This situation could lead to the exclusion of other companies, stifle innovation, and result in increased prices. The ACM previously voiced similar concerns in a few merger decisions, notably in NS/Pon and NS/Municipal Transport Companies. Public transport companies, in response, complained about potential revenue loss if their services were available on competing MaaS platforms. This reinforces the incentive to restrict (competing) MaaS providers’ access to their services, or impede competition in other ways.

Recently, the ACM conducted research, commissioned by the Dutch government, into the wholesale train ticket policy of the national train operator, NS. The research assesses whether NS’ wholesale policy allows for a level playing field between the MaaS activities of NS, and those of third party resellers, such as MaaS providers. In its report, published in October 2023, the ACM concludes that NS’ policy is in principle suitable to safeguard a level playing field. NS applies a margin test to determine the distribution discount on wholesale prices for NS train tickets. As a result, third party MaaS providers that are as efficient as NS can match NS’ retail offer, and recover their (variable) costs. The ACM, however, notes that there is room for improvement in the calculation method for the distribution discount, in order for resellers to also recoup their fixed costs. That way, a true level playing field will arise. ACM’s research does not constitute a competition analysis. This raises the question whether this is the correct standard from a competition law perspective. Regardless, the outcome of this study is likely to play a role in the future granting of the 2025-2033 Main Railway Concession which includes requirements to be MaaS-proof (see also our previous blog).

In 2022, the Ministry of Infrastructure and Water Management (in Dutch: Ministerie van Infrastructuur en Waterstaat, “Ministry of IenW”) concluded the MaaS program after five years. Through seven MaaS pilots, the MaaS concept was tested in the Netherlands. The evaluation report identifies several challenges in the development and implementation of MaaS in the country. Among these challenges are the need for adjustments to the current concession policy, standardisation of mobility data exchange, and alignment of the MaaS concept in the Netherlands with (future) European regulations.

Sector-specific regulations

Companies operating in the mobility sector must not only consider competition rules but also sector-specific regulations. At the European level, significant legislation that pertains to MaaS has been enacted or revised in recent years. Below, we discuss the most relevant regulations.

The revision of the Intelligent Transport Systems Directive (“ITS Directive”) stemming from 2010 was approved by the European Parliament and the European Council on 24 October 2023. Intelligent Transport Systems (“ITS”) serve as the technological backbone of MaaS and play a crucial role in seamlessly integrating various modes of transportation. Through ITS, MaaS providers can share (real-time) information on availability, routes, and fares. The revised directive imposes obligations on Member States, such as promoting service interoperability, collaboration among companies active in the MaaS sector, and the availability of certain mobility data. While the ITS Directive does not impose obligations on MaaS providers or transport companies themselves, governments may, based on this directive, introduce obligations for transport companies. Since the directive has not been published and thus not yet entered into force, the two-year implementation period has not yet commenced.

Since the implementation of the ITS Directive in 2010, the Commission has adopted various delegated regulations to further clarify and achieve the specific objectives of the ITS Directive. Examples include the Multimodal Travel Information Services Regulation (“MMTIS Regulation”) and the recently revised Real-time Traffic Information Services Regulation (“RTTI Regulation”). These regulations compel governments and private entities to make certain mobility data available through a National Access Point (in the Netherlands this is called the ‘Nationaal Toegangspunt Mobiliteitsdata’, NTM”). Currently, this obligation only applies to non-real-time mobility data that can easily be read and processed by a computer. Starting from 2025, mobility data containing real-time information must also be made available. The MMTIS Regulation is currently under revision. After this revision, obligations will be expanded, both in terms of the type of mobility data to be made available through the NTM and the manner in which that information should be provided.

To reduce fragmentation of mobility data within the EU, the Commission has proposed the establishment of the European Mobility Data Space (“EMDS”). The EMDS aims to provide a framework for interoperability among various sources of mobility data.

Finally, the Commission intended to propose the ‘Multimodal Digital Mobility Services’ Regulation (“MDMS Regulation”) in the fall of 2023 (after several postponements). The MDMS Regulation is anticipated to create a European framework governing the reservation, booking, payment and issuance of tickets for multimodal journeys. Despite the passing of the self-imposed deadline and pressure from the BEUC and several European travel organisations, the Commission has not submitted the proposal as of yet.

Conclusion

Overall, ensuring fair competition, data, and platform accessibility in the digitising mobility sector will require significant attention from competition authorities. Promoting multimodal mobility – and thus the concept of MaaS – is a crucial priority for the European Commission, as evident in its policy goals (such as the Green Deal). Due to the strong connection with national transportation systems, national competition authorities, such as the ACM and the Bka, are likely to continue playing a significant role in shaping the MaaS landscape in different member states.

Vision

Untangling the DMA in seven questions and answers: a new phase in Big Tech regulation

On 6 September 2023, the European Commission (“Commission”) designated Alphabet, Amazon, Apple, Meta, Microsoft, and ByteDance (the parent company of TikTok) as gatekeepers under the Digital Markets Act (“DMA”). The DMA imposes additional obligations on online platforms that enjoy significant economic power and act as an important gateway for business users to reach end users (see also our earlier blog on the DMA). The substantive obligations of the DMA will enter into force in March 2024, subjecting the undertakings designated as ‘gatekeepers’ to a stricter regulatory regime.

In the meantime, Apple, Meta, and ByteDance have already appealed their designation decisions to the General Court of the European Union (“General Court”), and the Commission is conducting market investigations into possible additional designations. ByteDance has also filed an application for the suspension of its designation with the President of the General Court. In this blog, we discuss the scope and obligations of the DMA through seven questions and answers. We also cover recent developments regarding the designations, enforcement issues, and the role of third parties.

  1. What is the DMA?
  2. To whom does the DMA apply?
  3. Which undertakings have been designated as gatekeepers so far?
  4. What obligations does the DMA impose on gatekeepers?
  5. When does the obligation to inform the Commission about concentrations apply?
  6. How is the DMA enforced?
  7. Does the DMA facilitate private damages claims?

1. What is the DMA?

The DMA is an EU regulation that seeks to safeguard competition on digital markets by ensuring that digital markets remain ‘fair’ and ‘contestable’. The previous years, several online platforms have become so sizeable and powerful that new entrants face significant challenges when competing with these incumbents. Moreover, large online platforms typically possess such a vast and all-encompassing ecosystem that provides them with a significant advantage in reaching end users and enables them to effectively exclude other market participants. Furthermore, the vast amounts of data the gatekeepers generate further reinforce the competitive advantage gatekeepers typically enjoy over their competitors. As a result of the foregoing, innovation and quality in digital markets are diminished as existing competitors are unable to keep up, and new entrants are discouraged from entering the market.

The use of Articles 101 and/or 102 TFEU has not always proven to be effective in tackling these structural issues. Although both the Commission and national competition authorities (“NCAs”) have pursued several investigations in digital markets in recent years (for the Commission, think about the Amazon Buy Box and three investigations into Google), these investigations are often complex and time-consuming. The Commission’s investigations into Apple Pay and Apple’s App Store (music services), launched in 2020, are for example still ongoing. Ex post enforcement action based on Articles 101 and/or 102 TFEU may thus – in the view of the European legislator – in some cases come too late to repair the harm to the competitive playfield. The DMA seeks to close this enforcement gap by providing an ex ante regulatory framework for large online platforms (see also our earlier blog on this subject).

 

2. To whom does the DMA apply?

The DMA applies to gatekeepers. A gatekeeper provides one or more so-called core platform services (“CPSs”) The DMA distinguishes the following CPSs:

A CPS provider qualifies as a gatekeeper if a number of qualitative requirements are met. A gatekeeper is not necessarily dominant within the meaning of EU competition law. Instead, an undertaking is qualified as a gatekeeper if it (i) has a significant impact on the internal market, (ii) it provides a CPS which is an important gateway for business users to reach end users, and (iii) has or is expected to have an entrenched and durable position. An undertaking is subsequently presumed to satisfy the abovementioned requirements if it meets the following quantitative criteria:

If an undertaking meets the quantitative criteria, it is obliged to notify the Commission within two months after those thresholds are met. Upon notification, undertakings that qualify as gatekeepers can try to rebut this presumption. So far, Alphabet, Microsoft, and Samsung have successfully argued that they should not be designated as gatekeepers as regards their Gmail, Outlook, and Samsung Internet Browser, despite meeting the DMA’s quantitative thresholds. The Commission conceded to the objections and refrained from designating Alphabet, Microsoft and Samsung as gatekeepers with respect to these services.

Where the arguments challenging a designation fall short of outright refuting the designation, but do cast sufficient doubt, the Commission may conduct a market investigation. The Commission is currently conducting investigations in order to establish whether Microsoft Bing, Microsoft Edge, Microsoft Advertising, and Apple’s iMessage ought to be designated under the DMA. In the reverse, the Commission can also designate an undertaking as a gatekeeper on the basis of a market investigation if the undertaking does not meet the DMA’s quantitative thresholds.

A designation by the Commission is not temporally limited. The Commission can, upon request or on its own initiative, reconsider, amend, or repeal a designation if there has been a substantial change in any of the facts underlying the designation, or where it is found that the designation was founded on incomplete, incorrect, or misleading information. The Commission may later also designate new gatekeepers. There is for example already some talk about the potential designation of Booking.com in the near future. So far, Booking eluded the DMA’s quantitative thresholds – in large part due to the COVID-19 pandemic – but is already considered to be a prime candidate for a gatekeeper designation in the media.

 

3. Which undertakings have been designated as gatekeepers so far?

On 6 September 2023, the Commission designated six undertakings as gatekeepers in respect of twenty-two CPSs. The image below provides an overview.

Source: https://ec.europa.eu/commission/presscorner/detail/nl/qanda_20_2349

The Commission’s gatekeeper designations could be appealed until 16 November 2023. Microsoft, Amazon, and Alphabet (Google) expressed that they will not appeal their designations. Apple, ByteDance, and Meta did appeal their designation decisions. In its appeal, ByteDance essentially argues that TikTok does not enjoy an entrenched and durable position and that it does not meet both the DMA’s turnover and capitalisation thresholds (unlike all other gatekeepers so far designated). Meta specifically appealed the designation of ‘Facebook Marketplace’ and ‘Facebook Messenger’. Apple, in its turn, appealed all gatekeeper designations and also filed a complaint against the Commission’s decision to initiate a market investigation into whether Apple’s iMessage should be included in the designation decision. These appeals will probably be decided on next year.

Third parties may join the appeal proceedings before the General Court if they can establish an interest in the General Court’s decision. The ongoing proceedings will reveal whether competitors, customers or other third parties have a sufficient interest already in the stage of the gatekeeper’s designation, or whether this interest only arises in the event of a gatekeeper’s non-compliance with the DMA.

 

4. What obligations does the DMA impose on gatekeepers?

Articles 5, 6 and 7 of the DMA introduce a wide range of obligations for gatekeepers. Many of the obligations relate to the collection, processing, and combining of (personal) data. Without the express consent of the end user, a gatekeeper is for example prohibited to collect the personal data of end-users using services of third parties for advertising purposes. Additionally, a gatekeeper is prohibited from cross-using personal data generated by a CPS in other services provided separately by the gatekeeper and vice versa. The gatekeeper is furthermore precluded from (re)directing end-users that access a specific service of the gatekeeper into signing on to other services of the gatekeeper with the aim of combining the user’s personal data. Gatekeepers must furthermore provide end users with effective data portability.

The DMA also contains obligations to provide business users, advertisers and publishers insight into the data generated by and/or for them. The gatekeeper may not use the non-public data generated by business users in competition with these users, for example on a downstream market. With regard to advertisers and publishers, there is also an obligation to provide daily information on the ads placed upon their request, free of charge. For online search engines (i.e. for the time being only Google Search), there is an additional obligation to grant third-party search engines, upon their request, access to anonymised ranking, query, click and view data under fair, reasonable and non-discriminatory conditions (also: “FRAND”-conditions).

In addition to these rules on the processing and accessing of data, gatekeepers must abide by many different obligations that, at their core, concern the interaction between different services and the application of fair trading conditions. To this end, the DMA contains both certain do’s – for example, in the context of interoperability of certain hardware and communication services – and don’ts (think of the express prohibition of self-preferencing and the mandatory use of certain identification or (in-app) payment systems). Gatekeepers are also barred from engaging in tying and bundling practices, for example by making the use of one CPS contingent upon the registration or subscription to another. A gatekeeper should enable end users to easily install and uninstall software applications (including third-party app stores) and allow end-users to easily change the default settings. End users should not be (technically) prevented from switching to or additionally using other software applications or services, and should be able to terminate their service with the gatekeeper without undue difficulty.

Furthermore, the gatekeeper should not prevent business users from offering the same products or services to end users through their own direct sales channel and/or third-party services at prices or conditions that are different from those offered through the online intermediation services of the gatekeeper. More generally, the gatekeeper should not prevent business users and end users from going around the gatekeeper and contracting with other parties (e.g. also indirectly by denying access to certain content or features upon doing so). Specifically with regard to app stores, online search engines and online social networking services, the DMA includes the obligation to apply general FRAND access conditions for business users, which should also contain an alternative dispute settlement mechanism.

Finally, to encourage effective enforcement, the DMA explicitly prescribes that the gatekeeper may not restrict or prevent business users and end users from reporting breaches of the DMA or other EU law rules to a competent authority. A full overview of the obligations the DMA imposes can be found in Articles 5 – 7 of the DMA. The designated gatekeepers must bring their operations into compliance with the DMA by March 2024. Gatekeepers must also submit a compliance report to the Commission and establish an independent compliance function.

 

5. When does the obligation to inform the Commission about concentrations apply?

Another unique feature of the DMA that has so far received rather little attention is the obligation for gatekeepers to inform the Commission of any proposed concentration in the digital sector, regardless of whether the proposed concentration must be notified to the Commission under the EU Merger Regulation (“EUMR”) or to a national competition authority. This duty to inform reflects the increasing emphasis of the Commission on preventing so-called killer acquisitions. It complements the Commission’s use of Article 22 EUMR to examine mergers that do not meet EU and/or national merger thresholds (read more here), and the CJEU’s recent Towercast-judgment, where the CJEU ruled that certain non-notifiable mergers may qualify as an abuse of dominance under Article 102 TFEU.

As the DMA merely introduces a duty to inform the Commission, it does not provide the Commission with additional powers to investigate these concentrations, and hence, to potentially veto them. Upon ‘notification’, the gatekeeper is required to provide a description of the concentration and the activities of the undertakings involved, as well as the annual EU turnover, the value and rationale of the transaction, the number of annual active users and the number of monthly end users. This will allow the Commission to monitor whether new CPSs need to be designated. The DMA also explicitly states that this information could potentially be used for a subsequent Article 22-referral.

 

6. How is the DMA enforced?

The primary responsibility for enforcement of the DMA lies with the Commission. In addition to the market investigation mentioned above, the DMA provides the Commission with various investigative powers, such as the possibility to request information and conduct inspections (similar to those under Regulation 1/2003). In doing so, the Commission can also impose interim measures. In case of an infringement of the DMA, the Commission, after issuing its preliminary findings, can impose substantial fines and periodic penalty payments, as well as behavioural remedies. These fines can amount to 10% of an undertaking’s annual turnover and may be doubled to up to 20% for repeat offenders. In case of systemic non-compliance (more than three infringement decisions in eight years), the Commission may also impose structural measures (including, for example, a temporary ban on new acquisitions), following a market investigation.

NCAs only play a supporting role in the enforcement of the DMA by monitoring compliance. In the Netherlands, the Digital Markets Regulation Implementation Act (“Implementation Act”) designates the Dutch Competition Authority (Autoriteit Consument en Markt, “ACM”) as the competent national authority responsible for overseeing compliance with the DMA. The ACM possesses various supervisory powers and may initiate investigations into possible breaches of the DMA on its own initiative. Yet ultimately, the ACM reports back to the Commission, and only the Commission can initiate enforcement proceedings under the DMA.

The ACM’s supervisory powers end where the Commission’s investigation begins. It might nevertheless be difficult to establish clear boundaries as these supervisory and investigative powers could overlap. In its recent advice on the Implementation Act, the Dutch Council of State already indicated that the powers of the Commission, the ACM, and the Dutch Data Protection Authority’s (Autoriteit Persoonsgegevens, AP”) potentially overlap with one another (for example regarding the enforcement of the Platform-to-Business Regulation and the Data Protection Regulation). Also, many obligations from the DMA bear close similarities to (or even: mirror) previous cases that were addressed under ‘regular’ competition law (think of the specific ban on self-preferencing in the DMA following the Google Shopping case). At the same time, the DMA prevents national authorities from taking decisions contrary to a decision adopted by the Commission on the basis of the DMA. In light of these ambiguities, the Dutch Council of State has advised the (Dutch) legislator to complement the explanatory memorandum of the Implementation Act on these points.

Public enforcement of the DMA may also be initiated on the basis of complaints and signals from third parties, including competitors, business users, and end users. Under Article 27 of the DMA, third parties may directly report possible breaches of the DMA to both the competent national authorities and the Commission. The DMA also encourages whistleblowers to report infringements by gatekeepers to the competent authorities. The Commission stresses that whistleblowers can play a crucial role in the enforcement of the DMA as they alert the competent authorities of potential infringements. To encourage employees to ‘blow the whistle’, the Commission has asserted that whistleblowers need to be protected from retaliation. Consequently, the EU Whistleblower Directive is also applicable to the DMA.

 

7. Does the DMA facilitate private damages claims?

As of now, still little is known about private enforcement of the DMA. On the basis of Article 288 TFEU, all EU Regulations, hence including the DMA, enjoy direct effect throughout the Member States. Individuals can invoke the rights enshrined in an regulation in civil proceedings where the rights granted to the individual are sufficiently clear, precise, and relevant to the individual’s situation. Given that most obligations in the DMA are formulated in a rather specific and precise fashion, it can be assumed that such is the case (also confirmed by the Commission), although Article 6 of the DMA contains obligations that may “be further specified”.

If a third party suffers damages as a result of a gatekeeper’s infringement of the DMA, it may initiate civil proceedings before a national court. Article 39 of the DMA provides for cooperation between the national competition authorities and the Commission in the national application of the DMA. A national court may request the Commission to provide information and issue guidance when applying the DMA in national proceedings. The Commission can also intervene on its own initiative if the coherent application of the DMA so requires. Additionally, Member States must forward to the Commission a copy of any written judgment of national courts deciding on the application of the DMA.

Throughout the legislative process, it has been stressed that the DMA is not a competition law instrument. Also considering the legal basis of the DMA, the procedural guarantees and (material) presumptions that Regulation 1/2003 and the Cartel Damages Directive provide, are inapplicable. The DMA therefore explicitly stipulates that national courts shall not give a decision which runs counter to a decision adopted by the Commission under the DMA. It can thus be inferred that the unlawful conduct (as one of the elements for establishing a tort action under the Dutch Civil Code) is irrefutably established before a national court after a DMA- infringement decision by the Commission (just as it is on the basis of Article 16 of Regulation 1/2003). This will facilitate a follow-on damages claim following a non-compliance decision based on the DMA.

 

Conclusion

After many years of negotiations, the practical entry into force of the DMA is nearly in sight. Six undertakings have so far been designated as gatekeepers and the first legal proceedings challenging these designations are already pending before the General Court. In the meantime, the Commission is conducting market investigations to determine whether other services provided by these gatekeepers should be designated under the DMA. Given the thin dividing line between the DMA on the one hand and European and national competition rules on the other, national authorities will need to consider how to most effectively shape cooperation among themselves and with the Commission. Third parties such as the gatekeepers’ competitors and customers may also want to prepare for the new rules that are set to apply to their competitors/business partners in March 2024. During the legislative process of the DMA, the legislator strengthened their role in the enforcement of the DMA by providing for an explicit complaint option as well as by implementing several additional rules on how the DMA is to be applied in national civil proceedings. Third parties are therefore expected to play a crucial role in overseeing the enforcement of the DMA.

 

More questions about the DMA? Please contact one of our competition law specialists.

Vision

New notification obligation under the Foreign Subsidies Regulation

This is the Competition Newsflash by bureau Brandeis (see the original version here).

Would you like to receive Competition Flashback by e-mail in the future? You can subscribe to our mailing list here.

New notification obligation onder de Foreign Subsidies Regulation

From 12 October 2023, companies are required to report large concentrations or participations in public procurement procedures involving funding from non-European public authorities (“third countries”) to the European Commission (Commission”). This notification obligation is set out in the Foreign Subsidies Regulation (FSR”), and applies if certain financial thresholds are met. The FSR has been in force since 12 July 2023, but the notification obligation only applies since 12 October 2023.

The FSR marks another significant step by the European Union in strengthening its merger control regime (detailed in our blog). In recent years, the Commission has introduced the Foreign Direct Investments Regulation (“FDI”, detailed in our blog), and has eased its policy regarding the referral of non-notifiable mergers by national authorities under Article 22 of the European Merger Regulation (detailed in our blog). In addition, the European Court of Justice’s recent judgement in Towercast clarified that a non-notifiable concentration can constitute an abuse of a dominant position. All of the above shows that competition authorities have rapidly acquired an expanding toolkit to evaluate the effects of concentrations on the competitive landscape.

By answering ten questions, we offer a concise overview of the primary changes introduced by the new rules of the FSR.

Ten questions and answers 

  1. What is the purpose of the FSR?
  2. When are companies obliged to notify under the FSR?
  3. What financial contributions qualify as foreign (non-European) subsidies?
  4. Can the Commission also launch ex officio investigations?
  5. What is the assessment procedure of the Commission, and what are its powers?
  6. Does the FSR include a standstill obligation?
  7. What is the Commission’s time limit when investigating?
  8. What happens if a company does not fulfil its notifying obligation?
  9. Does the FSR apply to concentrations or public procurement procedures that took place before 12 October 2023?
  10. What can companies do to make the M&A or public procurement process as smooth as possible?

1. What is the purpose of the FSR?

According to the European Commission, subsidies from non-European public authorities (“foreign subsidies“), such as interest-free loans or tax breaks, have regularly distorted competition in the European market in recent years. Such foreign subsidies were able to be provided unlimitedly to companies in the European Union, while subsidies from European governments (“European subsidies“) are subject to the stringent rules on state aid (see our blog).

Recent examples have occurred in the soccer industry. In August 2023, Spain’s La Liga has filed a complaint with the Commission, alleging that Paris Saint-Germain (“PSG”) has been benefiting from foreign subsidies provided by the Qatar government. These subsidies allegedly enabled PSG to “sign top players and coaches well above its potential in a normal market situation.”

In the past foreign subsidies have created an uneven playing field between those who receive foreign subsidies, and those who do not (as outlined in the Commission’s White Paper). The FSR aims to address this imbalance by regulating the beneficiaries of foreign subsidies, thereby fostering a level playing field for all companies operating in the European Union.

back to top


2. When are companies obliged to notify under the FSR?

The FSR contains a notification obligation for certain concentrations or participations in public procurement procedures.

Notification threshold for concentrations

Companies acquiring, merging or setting up a joint venture with another company must notify the Commission if they meet the following two conditions:

  1. at least one of the merging undertakings (in the case of mergers), the acquired undertaking (in the case of acquisitions), or the joint venture is established in the European Union and generates an aggregated turnover in the Union of at least € 500 million; and
  2. the relevant undertakings were granted combined aggregated financial contributions of more that € 50 million from third countries in the three years preceding the conclusion of the agreement, the announcement of the public bid, or the acquisition of a controlling interest. For mergers, relevant undertakings include the merging parties; for acquisitions, both the buyer(s) and the target; and for joint ventures, the joint venture partners and the joint venture itself.

The notification obligation must be satisfied prior to the completion of a concentration.

Notification threshold for public procurement procedures

Companies participating in public procurement procedures are required to notify the Commission of foreign financial contributions if the following thresholds are met:

  1. the estimated value of the public procurement is at least € 250 million; and
  2. the bidder, including its subsidiaries, holding companies, and main subcontractors and suppliers involved in the bid, was granted aggregate financial contributions of at least € 4 million per third country. These contribution(s) have been granted in the three years prior to participation.

In public procurement procedures, companies subject to the notification obligation must submit the notification to the contracting authority together with its bid. The contracting authority will then transfer the notification to the Commission without delay.

back to top


3. What financial contributions qualify as foreign (non-European) subsidies?

Under the FSR, a foreign subsidy is a financial contribution that is provided directly or indirectly by a third country, conferring an indirect or direct benefit to the receiving company which is limited in law or in fact to one or more companies or industries.

A foreign financial contribution is a broad concept, including capital injections, interest-free loans, unlimited guarantees, preferential tax treatment, grants or tax credits. Furthermore, if an undertaking sells its products or services to a third country, the sales income is considered to be a foreign financial contribution. These foreign financial contributions do not necessarily qualify as foreign subsidies under the FSR, but do count for the FSR’s notification threshold.

The concept of a “third country” includes the central government of a country, but also other non-European government entities whose actions can be attributed to the central government. These may include, for example, municipalities, or private entities acting on behalf of the government.

back to top


4. Can the Commission also launch ex officio investigations?

The Commission may on its own initiative examine information from any source, including Member States, a natural or legal person or association, regarding alleged foreign subsidies distorting the internal market. The Commission can still do so after a concentration is implemented. In regard to public procurement procedures, the Commission can only launch ex officio investigations if the public contract has already been awarded. These powers of the Commission are limited to ten years after the foreign subsidy has been awarded.

After an ex officio investigation, the Commission can prohibit a proposed concentration or require the undertakings to dissolve the completed concentration. The latter can be realised through the restoration of the situation prevailing prior to the concentration, or if not possible, by adopting measures appropriate to achieve such restoration as far as possible. In the context of ex officio investigations into public procurement procedures, the Commission cannot revoke the decision awarding a contract, nor can it terminate a contract. Timewise, the Commission must aim to adopt a decision within 18 months from the opening of the in-depth investigation. No standstill obligation applies during an ex officio investigation.

back to top


5. What is the assessment procedure of the Commission, and what are its powers?

Commission’s investigations involve a preliminary review and, if there is sufficient evidence of a distortive foreign subsidy, an in-depth investigation. In its investigations, the Commission will assess whether a financial contribution qualifies as a foreign subsidy within the meaning of the FSR and whether it (will) distort(s) the Single Market. To determine whether a distortion exists, the Commission can take various elements into account, such as the size of the foreign subsidy or the goal of the foreign subsidy. For example, if a foreign subsidy covers a substantial part of the purchase price in case of concentrations, it is considered to likely cause a distortion. A foreign subsidy granted for operating costs is more likely to cause a distortion than a subsidy that is granted for investment costs. The characteristics of the market, and in particular the competitive conditions on the market should be taken into account when investigating potential distortions.

If the Commission finds that a foreign subsidy (will) distort(s) the Single Market, it will balance the negative effects of the (potential) distortion against the positive effects of the foreign subsidy on the development of the relevant subsidised economic activity. Member States, as well as any natural or legal person can submit information on the positive effects, on which the Commission must base its considerations. Positive effects relate to the development of the subsidised economic activity and (the Union’s) relevant policy objectives, such as sustainability and R&D. The negative effects are the effects of the established (potential) distortion.

If the negative effects outweigh the positive effects, the Commission can accept commitments from the companies concerned to remedy the (potential) distortion. If no (adequate) commitments are offered, the Commission may impose redressive measures itself. Commitments as well as redressive measures must fully and effectively address the (potential) distortion and be proportionate. They can be structural, such as divestiture of certain assets, or behavioural, such as reduction of market capacity, sharing of critical infrastructure or business information, or licensing.

The most far-reaching power of the Commission is to prohibit the concentration or award of a public contract before it takes place. If a concentration has already been implemented and remedial measures cannot remedy the disruption, the Commission can order to dissolve the concentration. During the investigations, the Commission has the power to impose interim measures if that is necessary to prevent irreparable harm to the internal market.

back to top


6. Does the FSR include a standstill obligation?

Yes, the FSR contains a standstill obligation during the Commission’s investigations, if not initiated ex officio. A concentration cannot be completed until it has been authorised by the Commission. A public contract cannot be awarded to the notifying company until the Commission has approved its participation.

back to top


7. What is the Commission’s time limit when investigating?

In regard to concentrations, the Commission has 25 working days after the notification to decide whether to open an in-depth investigation. This in-depth investigation can take up to 90 working days. This period can be extended by 15 working days. M&A processes could thus be delayed by 130 working days.

In regard to public procurement procedures, the Commission has 20 working days after the notification to decide whether to launch an in-depth investigation. This period can be extended by 10 working days. The in-depth investigation can take 110 working days, and can be extended by 20 working days. Public procurement procedures could thus be delayed by 160 working days.

back to top


8. What happens if a company does not fulfill its notifying obligation?

If the notifying obligation is not fulfilled, the Commission may impose a fine of 10% of the total turnover or 5% of the average daily turnover. If incorrect information is provided, the Commission may impose a fine of 1% of the total turnover or 5% of the average daily turnover. In imposing fines, the Commission shall take due account of the principles of proportionality and appropriateness.

back to top


9. Does the FSR apply to concentrations or public procurement procedures that took place before 12 Octrober 2023?

The notification obligation also applies to concentrations that were concluded on or after 12 July 2023, but had not yet been implemented before 12 October 2023. For participations in public procurement procedures, the notification obligation only applies from 12 October 2023.

back to top


10. What can companies do to make the M&A process or public procurement procedure as smooth as possible?

Companies that regularly receive financial contributions from non-European governments should be aware of potential delays in M&A processes or public procurement procedures due to the Commission’s extensive decision deadlines and the substantial efforts required for fulfilling a notification obligation.

To minimise delays, thorough preparation is essential. The gathering of the information required for FSR notifications is not part of standard business operations. It is therefore advisable for companies to organise their records related to foreign financial contributions in order. This proactive approach facilitates the quick gathering of the required information for notifications.

When a concentration needs to be notified to the Commission under regular merger control, it is prudent to do this concurrently with the FSR notification. The FSR decision deadlines are roughly the same as those applicable in merger control, enabling them to run in parallel. This approach helps minimise potential delays in the M&A process.

Last, companies are able to consult with the Commission prior to the submission of an actual notification. Such pre-notifications serve as informal preparation for FSR notifications and speed up the notification process. Currently, the Commission has already conducted 17 pre-notification meetings with companies concerning an FSR notification related to concentrations.

back to top


Vision

Competition Flashback Q3 2023: EU and Dutch competition law developments

This is the Competition Flashback Q3 2023 by bureau Brandeis, featuring a selection of the key EU and Dutch competition law developments of the past quarter (see the original version here).

Would you like to receive Competition Flashback by e-mail in the future? You can subscribe to our mailing list here.

 

Overview Q3 2023


Merger control

Cartels and vertical restraints

Abuse of a dominant position

Damage claims for competition law infringements

Regulated markets and consumer law 


Commission fines seller (Grail) for the first time for gun-jumping, buyer (Illumina) receives record fine of € 432 million

European Commission, press release of 12 July 2023

On 12 July 2023, the European Commission (“Commission”) imposed a record fine of € 432 million on biotech company Illumina for prematurely implementing the acquisition of Grail.

The Commission launched an in-depth investigation into this transaction in 2021 based on a referral from several European Member States under Article 22 of the EU Merger Regulation (“EUMR”) (see our blog on Article 22 here). The General Court of the European Union (“General Court”) had already confirmed, in its judgment of 13 July 2022, that the Commission was entitled to exercise this power under Article 22 EUMR. Subsequently, the Commission decided to prohibit the transaction in its entirety (for more on this, see Competition Flashback (“CF”) Q3 2022).

In parallel with the substantive assessment of the transaction, the Commission opened an investigation into a possible violation of the standstill obligation by Illumina in 2021 and already imposed interim measures at that time. During the Commission’s investigation, Illumina publicly announced that it had completed its acquisition of Grail. In its decision of 12 July 2023, the Commission confirmed its preliminary view that Illumina and Grail knowingly breached the standstill obligation.

According to the Commission, there was a deliberate strategy on Illumina’s part, as it strategically weighed the risk of a gun-jumping fine against the risk of paying a considerable breakup fee if it did not acquire Grail. The Commission considered this to be an unprecedented and very serious infringement that undermines the effective functioning of the European merger control system. Therefore, a high and deterrent fine is justified. Additionally, the Commission decided to impose a symbolic fine of € 1,000 on target Grail for its active role in the infringement. This marks the first time that a target in a transaction has been fined by the Commission for violating the standstill obligation (read more here).

 

Back to top


Rotterdam court confirms ACM’s ban on PostNL takeover of Sandd

Rotterdam District Court, judgment of 29 September 2023

On 29 September 2023, the Rotterdam District Court ruled that the Dutch Authority for Consumers and Markets (Autoriteit Consument en Markt, “ACM”) rightly decided not to grant postal operator PostNL a licence to acquire rival postal operator Sandd in 2019. At the time, the ACM refused to grant a licence because PostNL’s takeover of Sandd would strengthen PostNL’s dominant position. The ACM also expected a price increase for business mail of 30% to 40% after the transaction. The ACM’s market investigation also showed that, although the volume of physical mail will decrease, there will still be a substantial demand for physical mail in the long term.

PostNL requested the Minister of Economic Affairs and Climate Policy (“Minister”) to still grant a licence under Section 47(1) and (2) of the Dutch Competition Act and also appealed the ACM’s decision. The hearing of that appeal was suspended until the licence application was irrevocably decided by the Minister. On 27 September 2019, the Minister granted a licence, which was subsequently reversed by the court of first instance and on appeal (see also CF Q2 2022). With that, PostNL’s appeal against the ACM’s decision revived, which has now been decided by the court.

The court declared PostNL’s appeal unfounded. The court ruled that the ACM had correctly defined two national markets for consumer mail and business mail. Contrary to PostNL’s argument, the ACM was indeed allowed to use data from its quantitative and qualitative research as well as internal PostNL documents, as PostNL also used these itself in its strategic documents and forecasts. In addition, the court held that the ACM correctly assumed the counterfactual that PostNL would remain profitable in the short and long term, whilst Sandd would continue to exert competitive pressure if the acquisition did not take place.

The possible horizontal effects of the merger on the markets for business mail and consumer mail – such as the elimination of the only competitor with a national network and an increase in the price for bulk mail – have also been made sufficiently plausible by the ACM. The same applies to the vertical effects for business mail, namely the ability and incentive for PostNL to foreclose competitors from its delivery network. According to the court, the efficiency defence raised by PostNL was also thoroughly examined and rightly rejected by the ACM. Finally, the court agreed that PostNL had not convincingly demonstrated that it could not perform the universal postal service (profitably) absent the merger. The court thus fully upheld the ACM’s decision not to grant a licence.

Back to top


CJEU nuances SIEC-test in appeal CK Telecoms/Hutchison and refers back to General Court

Court of Justice, judgment of 13 July 2023

This summer, the Court of Justice of the European Union (“CJEU”) overturned the General Court’s controversial judgment in CK Telecoms v Hutchison, which set a high standard of proof and strict requirements for prohibiting mergers in oligopolistic markets. In 2020, the General Court annulled the Commission’s decision to prohibit the merger between the two mobile network operators in the United Kingdom. In 2016, the Commission found that the 4-to-3 merger would lead to a significant impediment to effective competition (“SIEC”) in three different markets. Upon appeal, the General Court held that the Commission had not applied the SIEC-test correctly and that its analysis could not support the conclusions in the prohibition decision.

The CJEU overturns the General Court’s judgment. It ruled that the same standard of proof applies to both the prohibition and the approval of a merger. Given the inherent uncertainty of prospective analyses, it is sufficient for the Commission to demonstrate that it is more likely than not that a merger will lead to a restriction of competition. The SIEC-test has no specific, cumulative requirements. With regard to the concepts of ‘important competitive force’ and ‘close competitors’ as included in the Horizontal Merger Guidelines, the CJEU agrees with the Commission that the General Court applied too strict a standard. The General Court ruled that (one of) the merging parties must hold a special position, for example by a particularly aggressive pricing policy, and that the parties should be ‘particularly close competitors’. However, within an oligopolistic market, several companies can actually exert significant competitive pressure, and not only with regard to prices, the CJEU states. Furthermore, the General Court disregarded the function of efficiency benefits in merger control when it ruled that the Commission should automatically take them into account in its assessment. The CJEU emphasises that concentrations do not automatically lead to efficiency benefits and it is up to the merging parties to substantiate these. Assuming that efficiency benefits (can) occur would wrongly lead to a reversal of the burden of proof.

Lastly, the CJEU finds that the General Court failed to fully weigh all the Commission’s evidence before annulling the prohibition decision. Due to the gross disregard of the law and the failure to discuss various grounds at first instance, the CJEU refers the case back to the General Court.

 

Back to top


CJEU clarifies scope of FDI Screening Regulation and possible restrictions of freedom of establishment

Court of Justice, judgment of 13 July 2023

In response to a preliminary reference from a Hungarian court, the CJEU clarifies that Regulation 2019/452 (“FDI Screening Regulation”) applies only to direct investments by foreign companies, and determines that a prohibition decision based on a broad screening mechanism may violate the freedom of establishment. In 2020, the Hungarian Minister of Innovation and Technology prohibited the acquisition of the raw materials extraction company Janes es Tarsa (“JeT”) by construction materials company Xella Magyarország (“Xella”). Since Xella is indirectly owned by a top holding company registered in Bermuda, the acquisition was seen as a risk to the security of supply of these strategic raw materials, as stated by the minister. Xella challenged this prohibition decision before the national court, which had to assess whether there this infringes the FDI Screening Regulation and/or the provisions on free movement.

First, the CJEU determines that the FDI Screening Regulation does not apply in this case, as it only covers foreign direct investments and Xella is a Hungarian undertaking. Although the regulation provides that the ownership structures of the acquiring party can be taken into account, the CJEU clarifies that this pertains to whether the investor is (in)directly controlled by the government of a third country.

Since Xella, as a Hungarian undertaking, is prohibited from acquiring a shareholding in another EU company, the CJEU concludes that there is a restriction on the free movement of establishment. Such a restriction is only permissible if justified. According to the CJEU, the protection of public order and/or public security can serve as justification only in the case of a genuine and sufficiently serious threat to a fundamental interest of society. The CJEU has previously found justifications in cases involving companies providing public services in the petroleum, telecommunications, and energy sectors. In the case at hand, the CJEU finds that the objective of ensuring the security and continuity of supply to the construction sector does not constitute a public security reason. Moreover, the CJEU does not consider the risks outlined by the minister to be plausible, as Xella already purchases 90% of JeT, and the market value of these raw materials is relatively low compared to the transport costs, so that it is unlikely they would be withdrawn from the Hungarian market.

 

Back to top


Overview highlights merger cases

By its decision of 25 September 2023, the Commission prohibited Booking Holdings’ (“Booking”) acquisition of online travel agent (“OTA”) Flugo Group Holdings AB (“eTraveli”). The Commission finds that this acquisition of the ‘best-in-class’ flight OTA enables Booking to strengthen its dominant economic position on the hotel OTA market and further expand its ecosystem of travel services. It considers that, as the first step in planning a trip, a flight OTA acts as an important customer acquisition channel and generates significant traffic for Booking’s website(s). Additionally, Booking is already active in the market for metasearch services, primarily through its price comparison platform KAYAK. The Commission considers that the acquisition would thus enhance network effects and raise barriers to entry and expansion in the hotel OTA market, potentially resulting in higher prices for hotels and consumers.

During the second-phase investigation, Booking proposed to display a ‘carousel’ of offers from various competing hotel OTAs (“Carousel”) on the confirmation page after booking a flight. Given that the Carousel would only be displayed on the flight confirmation page (and therefore does not exclude other cross-sell opportunities), and would be driven by Booking’s own, non-transparent KAYAK algorithm, the Commission found that the Carousel did not fully address its concerns and subsequently decided to prohibit the acquisition altogether. Booking has already announced that it will appeal the prohibition decision.

* Bas Braeken, Demi van den Berg and Jade Versteeg represented an OTA in formulating its objections to this transaction.

 

Following an extensive Phase II-investigation (see also CF Q4 2022), Broadcom was given green light to acquire VMware, yet subject to conditions. Broadcom is mainly active in hardware (such as Fibre Channel Host-Bus Adapters (“FC HBAs”), Network Interface Cards and storage adapters). VMware is a provider of virtualisation software that can be used with a wide range of hardware, including Broadcom’s hardware.

In the second-phase investigation, the Commission found that the transaction would restrict competition in the global market for the supply of FC HBAs. To address the Commission’s concerns, Broadcom committed that competitor Marvell Technology and other potential future competitors would have access to the source code of FC HBAs for ten years. In doing so, Broadcom committed that the FC HBAs it now offers will remain interoperable with VMware virtualisation software. In view of the Commission, this sufficiently addresses its competition concerns.

 

Amazon/iRobot

On 6 July 2023, the Commission announced the launch of a second-phase investigation into Amazon’s acquisition of robot vacuum cleaner manufacturer iRobot. The Commission has expressed concerns that this acquisition would allow Amazon to restrict competition within the robot vacuum cleaner market and to strengthen its position as provider of an online marketplace.
During the initial investigation, the Commission found that Amazon is an important sales channel for robot vacuum cleaners in several Member States. With the acquisition of iRobot, Amazon would gain access to iRobot’s users’ data, thereby obtaining a significant competitive advantage over other providers of robot vacuum cleaners that also sell their products on Amazon’s platform. According to the Commission, this could give Amazon both the ability and incentive to exclude iRobot’s competitors in various ways. In the second-phase investigation, the Commission will further investigate the effects of the proposed transaction.

 

Qualcomm/Autotalks

The Commission recently announced its investigation in Qualcomm’s proposed acquisition of Autotalks. This investigation was initiated following a referral from 15 national competition authorities, including the ACM, pursuant to Article 22 of the EUMR. Qualcomm is a global manufacturer known for producing chips used in various applications, including driver assistance systems. Two different technical standards apply to these specific chips. Israel’s (innovative) Autotalks is currently the only company in the world producing chips that comply with both standards. The Commission emphasises the critical role played by both parties’ chips for the development of driver assistance systems. These systems have far-reaching implications, including the reduction of CO2-emissions and the advancement of autonomous vehicles. It is important that the chips of both Qualcomm and Autotalks remain available at competitive prices and terms to support continued innovation in this sector, according to the Commission.

 

EEX/Nasdaq

Following yet another Article 22 referral, this time from Denmark, Finland, Sweden and Norway, the Commission has announced its investigation into the acquisition of Nasdaq Power by European Energy Exchange’s (“EEX”). Both companies are active in the Norwegian energy market. The Commission notes that EEX and Nasdaq Power are key to creating stable and predictable energy prices, and that the acquisition appears to combine the only two providers that can realise the conclusion of long-term energy contracts with fixed prices. Given the ongoing energy crisis, the Commission underscores the importance of ensuring the efficient operation of energy markets. EEX/Nasdaq marks the third transaction in which the Commission has accepted an Article 22 referral, in line with its Article 22 guidelines.

Back to top


Rotterdam court upholds € 82 million cartel fine for cigarette manufacturers

Rotterdam District Court, ruling of 18 July 2023

On 18 July 2023, the Rotterdam District Court declared the appeals of Philip MorrisJT InternationalBritish American Tobacco and Van Nelle Tabak against the tobacco cartel decision of the ACM, unfounded. In 2020, the ACM imposed fines on the four cigarette manufacturers for exchanging information on future prices of cigarette packs through wholesalers. By asking wholesalers for future price information from competing manufacturers and/or not objecting to receiving this information, the ACM found there was a concerted practice aimed at restricting competition in the Dutch cigarette market.

In their appeals, the manufacturers challenge, inter alia, the existence of a concerted practice, a single and continuous infringement, and a restriction of competition by object. According to the manufacturers, the excise tax system makes the market highly regulated and transparent, and there was a legitimate reason to provide the future price lists to wholesalers. The court rejects all of these arguments and endorses the ACM’s view that this does not prevent the qualification of a restriction of competition by object and the seriousness of the violation. According to the ACM and the court, the core of the infringement consists of maintaining a practice of indirect information exchange, thereby removing uncertainty in the market.

The manufacturers also objected against the amount of the fine imposed by the ACM and the way the ACM conducted its investigation. The court does not follow these arguments either. However, the manufacturers’ argument that the ACM wrongly applied the 2009 Fining Guidelines when the 2007 Penalty Code was in force for part of the infringement period does succeed. Since the application of the old policy rules would nevertheless not have led to a more favourable result for the manufacturers, the court still declared the manufacturers’ appeal unfounded in its entirety.

 

Back to top


Television manufacturer LG receives a fine of nearly € 8 million for resale price maintenance

ACM, decision of 11 July 2023

After Samsung, the ACM has now also decided to impose a fine of nearly € 8 million on television manufacturer LG  for influencing resale prices of seven large retailers of LG televisions. LG provided retailers with a recommended price and monitored whether retailers adhered to the recommendation. It did this partly by monitoring retailers’ price comparison websites and web shops. LG was also tipped off by competing retailers. When a retailer maintained a lower price than the recommended price, LG contacted the relevant retailer via email or Whatsapp and urged him to adjust the different price to LG’s desired level. According to the ACM, LG hereby coordinated the consumer price level for LG televisions in the Netherlands and tried to prevent price drops.

According to LG, the price recommendations were in fact, only recommendations. LG also argued that it did not exercise coercion and did not offer incentives to actually adjust the price to the recommended price. The ACM nevertheless held that exercising coercion and giving incentives are not imperative in order to induce retailers to adhere to the ‘recommended price’, as they trusted other retailers to do the same. This secured their margins.

When calculating the fine, the ACM took into account as an aggravatig circumstance that LG systematically and frequently intervened in the pricing of televisions over a long period of time; almost three years. As a mitigating circumstance, the ACM does consider the lack of coercion and/or incentives and that it has not previously imposed a fine for resale price maintenance during the infringement period. While Samsung was fined for a similar infringement in 2021, LG’s infringement period had already ended by then. Finally, the ACM sees reason to further mitigate the fine due to the particularly long period (almost two years) between the investigation report and the fining decision. This eventually resulted in a fine of € 7.9 million.

Back to top


Court confirms multi-million fine for Valve over geo-blocking

General Court, judgment of 27 September 2023

The General Court recently confirmed the fine imposed by the Commission in 2021 on Valve – the company behind the video game platform Steam – for engaging in geo-blocking practices with five game publishers: Bandai NamcoCapcomFocus Home, Koch Media (now Plaion) and ZeniMax. The fines in total amount to almost € 8 million. The game publishers decided not to challenge their fines.

According to the Commission’s decision, these game developers restricted cross-border sales of PC video games by placing territorial restrictions on certain PC games. By doing so, they tried to prevent PC games from being bought in countries where prices were lower, notably the Baltic States and some countries in central and eastern Europe, while subsequently being played elsewhere.

According to the General Court, the Commission correctly concluded that there was an agreement or concerted practice having the object of restricting trade between Member States. The geo-blocking therefore did not pursue an objective of protecting the copyright of the game publishers, as Valve argued. The General Court stressed that although copyright intends to ensure that the holders thereof can commercially exploit their protected material – for example, by licensing it – it does not guarantee them the opportunity to claim the highest possible remuneration or to artificially create price differences by partitioning national markets. That is irreconcilable with the internal market. The General Court dismisses the action brought by Valve.

Back to top


ACM fines traffic sign cartel

ACM, decision of 12 July 2023

On 20 July 2023, the ACM fined traffic sign manufacturers Brimos and Agmi for fixing prices in four different tenders for the production of traffic signs. The National Guide Signing Service (an alliance of the different government bodies in the Netherlands, in Dutch: Nationale Bewegwijzeringsdienst) regularly calls for tenders from a number of companies to produce traffic signs. In 2020, Brimos and Agmi agreed on the prices they would charge in their tenders prior to submitting them. They also discussed who should win which tender.

Brimos reported the agreements to the ACM through a leniency application and was therefore granted a complete exemption from a fine of € 135,000. Following dawn raids by the ACM, Agmi also submitted a leniency application and cooperated in a simplified settlement procedure. Agmi was therefore granted a 60% reduction of the fine and ended up paying € 56,000.

Back to top


Commission imposes € 1.2 million fine on Diehl for participating in hand grenade cartel

European Commission, decision of 21 September 2023 (press release available)

The Commission has imposed a € 1.2 million fine on defence company Diehl for participating in a cartel in military hand grenades. Diehl and competitor RUAG entered into market-sharing agreements for 14 years, and sought mutual consent to conduct business within each other’s territories. This fine is the first in the defence sector, serving as a clear signal that cartelisation will not go unpunished, even within strategic sectors amidst shifting geopolitical dynamics. Notably, the Commission has deviated from the standard method of calculation in its Guidelines, and has imposed a higher fine to create a stronger deterrent effect.

The investigation into this cartel began after RUAG applied for leniency with the Commission in mid-April 2021. After the Commission conducted a dawn raid on Diehl on November 13, 2021, Diehl also applied for leniency. As RUAG was the first to file a leniency application, it escaped a fine of approximately € 2.5 million. Diehl received a 50% reduction. This is a significant reduction, but justified by the timing of Diehl’s cooperation and the extent to which it provided essential evidence, according to the Commission. Moreover, the Commission reduced the fine by 10% due to the acknowledgement of involvement and liability by both cartel participants in this regard. This is in line with its Notice on Settlement Proceedings in Cartel Cases.

 

Back to top


Jan Linders becomes franchisee of Albert Heijn subject to commitments

ACM, decision of 31 August 2023

In its decision of 31 August 2023, the ACM declared the commitments of Albert Heijn and Jan Linders, relating to a proposed cooperation, binding. The two supermarket chains entered into a cooperation agreement on 13 December 2022 as a result of which Jan Linders will operate its stores as a franchisee of Albert Heijn. Additionally, Jan Linders will sell its distribution centre to Albert Heijn. Furthermore, as part of the franchise agreement, Albert Heijn is selling ten shops to Jan Linders to be operated as Albert Heijn franchises; this acquisition has already been approved by the ACM.

During the informal investigation into the cooperation agreement, the ACM raised potential competition risks in several local markets within the catchment areas surrounding five Jan Linders supermarkets. For the purpose of a quick resolution and to avoid further investigation, Jan Linders agreed to sell the five supermarkets in question to competitors. Moreover, Jan Linders and Albert Heijn will not operate these divested supermarkets for a period of ten years. One of these shops will continue as a Spar franchise, the sale of the remaining four shops to Jumbo has already been approved by the ACM.

Back to top


ACM reduces fine Leadiant for excessive pricing of CTX-drug by over € 2.5 million

ACM, decision of 22 June 2023 (summary)

In its decision on objection of 22 June 2023, the ACM reduced the fine imposed on pharmaceutical company Leadiant by over € 2.5 million. In 2021, the ACM fined Leadiant over € 19.5 million for charging excessive prices for its drug ‘CDCA-Leadiant,’ which is a life-saving drug for patients suffering from the rare metabolic disease cerebrotendinous xanthomatosis (“CTX”). Where the first CDCA-based drug (Chenofalk) was sold by Leadiant for € 46 per package in 2008, the price for the CDCA-Leadiant launched in 2017 amounted to € 14,000 per package (representing € 153,300 per patient per year). As Leadiant was granted the exclusive right to supply a CDCA-based drug in the European market from June 2017 to December 2019, and no alternative medicines were available during that period, the ACM concluded that Leadiant held a dominant position, and had abused this position by the excessive and unfair price of € 14,000 per package.

In its objection, Leadiant argues, inter alia, that there was a collective boycott on the part of health insurers, that the ACM used incorrect calculation methods, and that the ACM wrongly included the prices of the earlier versions of the CTX-drug in its assessment. The ACM did not accept these arguments. Although the ACM took into account the required investments and financial risks involved with Leadiant’s exclusive right, it concludes that any calculation method would result in an excessive and unfair price. The ACM does, however, accept the argument that between 1 April 2018 and 26 July 2018, a magistral (pharmacy-prepared) version of the CDCA-drug was also available in the Netherlands, which means that Leadiant was not dominant during that period. This leads to an adjustment of the established infringement period, and thus, the total amount of the fine.

 

Back to top


European Commission re-imposes fine on Intel after annulment by General Court

European Commission, press release dated 22 September 2023

The Commission has re-imposed a fine on Intel for the company’s abuse of its dominant position in the market for computer chips. Intel, one of the largest producers of computer chips, gave rebates to computer manufacturers on the condition that they would buy (almost) all of Intel’s chips. In addition, Intel paid them to halt or delay the launch of specific products containing chips of competitors, so-called ‘naked restrictions’.

The abuse was previously identified and fined by the Commission: it already fined Intel for € 1.09 billion in 2009. However, this decision was overturned by the General Court in January 2022. The General Court held that the Commission had made an incomplete analysis regarding the conditional rebates so that it could conclude that this practice brought about (potential) anticompetitive effects. The General Court subsequently held that, because of the partial annulment of the decision in so far it relates to the conditional rebates, it was not in a position to establish the amount of the fine relating to the ‘naked restrictions’. The General Court therefore annulled the fine in its entirety.

The Commission has now imposed a new fine on Intel of € 376 million which only relates to the ‘naked restrictions’. The appeal against the General Court’s judgment annulling the decision on the conditional rebates is still pending before the CJEU.

Back to top


Breach of data protection rules can be taken into account when assessing competition law infringements

Court of Justice, judgment of 4 July 2023

In response to preliminary questions referred by a German court, the CJEU rules that a (national) competition authority must take into account any decision or investigation by the competent data protection authority. In 2019, the German competition authority, the Bundeskartellamt (“Bka”), decided that Meta Platforms Ireland (“Meta”) abused its dominant position on the market for social networks by collecting and combining data about Facebook users’ activities inside and outside its social network. Users had to accept these terms and conditions in order to use Facebook. By collecting, using and merging this data, Meta violated the General Data Protection Regulation (“GDPR”) and also abused its dominant position, according to the Bka. Meta contested this decision before the German court, who questioned whether the Bka – as part of its investigation into the abuse of dominance – was entitled to test whether the data processing violated the GDPR.

The CJEU ruled that a competition authority, in this case the Bka, may be required to check whether certain conduct complies with legal standards other than those concerning competition law, including the GDPR. In doing so, the Bka does not take the place of the authority supervising the GDPR, as it only assesses the compliance with the GDPR to determine whether there is an abuse of dominance. However, the CJEU stresses that consultation and sincere cooperation between competition and data protection authorities is crucial. If the data protection authority has already taken a decision on the conduct in question, the competition authority should not deviate from it.

 

Back to top


Court assumes international jurisdiction against Apple and declares a foundation inadmissible

Amsterdam District Court, judgment of 16 August 2023

The District Court of Amsterdam intends to refer preliminary questions to the CJEU on the relative jurisdiction of national courts in situations where different national courts have relative jurisdiction at the same time. In this case, foundations RCJ, ASC and CCC brought collective actions, so-called WAMCA claims, against Apple for charging (too) high commission rates in the Apple App Store and the fact that in-app payments could only be made through Apple’s own payment system. According to the foundations, these practices violate Articles 101 and 102 TFEU.

RCJ, ASC and CCC represent the interests of consumers and/or app developers. RCJ was the first to issue its writ of summons on 4 October 2021, which initiated the three-month period for filing a competing class action. The second foundation, ASC, and third foundation, CCC, issued their writs of summons later, after those three months. Only ASC, however, had requested an extension of the three-month period. The court held that this extension did not have general effect, so that it could therefore not be invoked by CCC. The court consequently held that CCC had no cause of action.

The court further assumed international jurisdiction based on the Handlungsort and the Erfolgsort, because the place of the harmful event could be located in the Netherlands. Although commission fees are charged in the App Store worldwide, the existence of a Dutch App Store demonstrates that there is a Dutch market. Even if the geographical market in which the abuse of dominance is implemented is broader than (just) the Netherlands, the Dutch court has jurisdiction as part of that market, the court said. Moreover, Apple deliberately targeted the Dutch market by setting up several storefronts, including the one in the Netherlands (Handlungsort). The place where the damage occurred is also in the Netherlands for Dutch consumers (Erfolgsort).

The court is, however, less certain about its relative jurisdiction. The underlying consumers represented by the foundations are spread all over the Netherlands and there is no concrete indication pointing to a single district court. Since Article 7(2) of the Brussels I bis Regulation simultaneously designates the absolute and relative competent court, this would mean that possibly every district court in the Netherlands would have relative jurisdiction, which would not benefit procedural economy and efficiency. The court is therefore considering asking the CJEU for some guidance on this issue.

 

Back to top


European Commission designates six gatekeepers under the DMA

European Commission, press release dated 6 September 2023

On 6 September, 2023, the Commission officially designated six gatekeepers under the Digital Markets Act (“DMA”). Under the DMA, gatekeepers are companies that have consistently provided a core platform service over at least the past three years, that serves as an important gateway for business users to reach end users. This is presumed to be the case if the undertaking has at least 45 million monthly active end users and 10,000 yearly active business users within the EU. Additionally, a gatekeeper must have a size that impacts the internal market, which is presumed at an annual turnover in the EU of € 7.5 billion, or a market value of € 75 billion, while also providing a core platform service in at least three Member States. Core platform services include, for example search engines, online social networking services, web browsers, operating systems and online intermediation services such as app stores.

AlphabetAmazonAppleByteDance (TikTok), Meta and Microsoft have all been designated as gatekeepers for various core platform services. Collectively, they offer a total of 20 core platform services that must comply with the DMA’s rules of conduct and obligations. The primary goal of these rules is to foster an open and fair European digital market (outlined in our blog of 22 December 2022). The DMA imposes both positive obligations, for example in the context of interoperability and data portability, as well as negative obligations, including bans on self-preferencing and the combining of personal data. Also, gatekeepers must inform the Commission of any proposed concentration in the digital sector. These designated gatekeepers have until 6 March 2024 to align their services and behaviour with the provisions of the DMA.

It’s worth noting that the Commission decided not to classify Apple and Microsoft as gatekeepers in relation to Apple’s messaging service (iMessage) and Microsoft’s web browser (Bing), following protests by the two tech giants. The Commission initiated market surveys to further assess the arguments presented by Apple and Microsoft in that regard. Furthermore, the Commission is investigating whether Apple should be designated as a gatekeeper for its iPadOS, despite that this service does not meet the quantitative criteria from the DMA mentioned above.

 

Back to top


American Express and Visa appeal over interchange fees inadmissible

Trade and Industry Appeals Tribunal, ruling of 13 September 2022 (publication date: 29 August 2023)

The Trade and Industry Appeals Tribunal (“CBb”) recently declared American Express’ and Visa’s appeal against the annulment of the order subject to penalty payments imposed on Mastercard and ICS inadmissible. By decision of 22 October 2020, the ACM imposed an order subject to penalty payments on Mastercard and ICS for charging excessive interchange fees for handling transactions within a four-party payment card scheme with co-branding partner Bijenkorf. In first instance, the court ruled that the interchange fees paid by ICS to Bijenkorf and Mastercard to ICS were not covered by the Regulation on interchange fees for card-based fees and therefore did not have to comply with the maximum fee of 0.3% of the transaction value per transaction set by that regulation. Since this case involved four parties as well as a co-branding partner, the Regulation was not applicable as such, and exceeding the 0.3% limit for payments to co-branding partners did in this case not lead to consumer harm, the court said.

American Express and Visa appealed the annulment of the order subject to penalty payments. In its recent ruling, the CBb declared the appeal inadmissible as the Bijenkorf Card had since then been cancelled and, thus, there was no longer a violation. Enforcement action is therefore no longer possible, according to the CBb.

 

Back to top


Outsourcing to call centres does not preclude liability for unfair trading practices during marketing calls

Rotterdam District Court, ruling of 23 August 2023

The Rotterdam District Court recently upheld the € 400,000 fine imposed by the ACM on energy supplier DGB for conducting unfair trading practices during phone calls made by call centres on behalf of DGB. In an attempt to recruit more consumers, DGB decided to actively target sales to consumers through telemarketing calls. The court agreed with the ACM that essential information was not provided during these call, or was provided too late. For example, the commercial purpose of the call was not always disclosed. Also, it was not always clear on whose behalf the call centre agent was calling and information regarding the product, any associated actions, and the right of withdrawal was not provided or was provided too late. All this information should be provided to the consumer right at the beginning of the marketing call, and telemarketers should not slowly entrap consumers by providing faulty information, the court said.

DGB argued that the ACM wrongly attributed the conduct of the commissioned call centres to DGB. The court disagreed and ruled that DGB was aware of the practice, or in any case, could have been aware. Moreover, as could reasonably be required of a legal person, DGB enjoys a duty of care to supervise the call centres and prevent the conduct in question. The fact that DGB had outsourced customer acquisition to a call centre does not affect DGB’s liability under the Dutch Drijfmest-criteria, the court said.

 

Back to top


For all your questions regarding (EU) competition law, bureau Brandeis would be happy to assist.

 

Bas Braeken – Jade Versteeg – Lara Elzas – Timo Hieselaar – Demi van den Berg – Coen VermeijGayle Lutchman

Vision

Landmark case in the UK: standard third party funding agreements in collective actions appear to be unenforceable

On 26 July 2023, the UK Supreme Court rendered a landmark decision on third party funding agreements in collective actions proceedings. This case concerned follow-on damages proceedings in the renowned truck cartel case. In this decision, the Supreme Court qualified the (standard) funding agreements that the claimants use as “damages-based agreements” (“DBAs”), which is a type of contingency fee arrangement in UK law for ‘representatives and those providing other services in relation to the making of the claim’.  The Supreme Court now decided that funders offer such services and therefore should follow DBA regulations.

Under UK law, DBAs are regulated, especially in cases before the Competition Appeal Tribunal (“CAT”). Claim vehicles are not allowed to use DBAs at all in opt-out proceedings (where a claim vehicle starts proceedings on behalf of a defined group, but group members may opt-out) and they can only use them when they comply with a specific regulatory regime in opt-in proceedings (proceedings that parties should actively join). By qualifying standard third party funding agreements as DBAs, the agreements cannot be used to fund opt-out proceedings and should be changed in order to comply with the regime for opt-in proceedings.

Effect on the current funding practice in the UK

This decision therefore has far-reaching effects for all current and future cartel damages proceedings in the UK. At this moment, 31 collective action cases are pending before the Competition Appeal Tribunal (“CAT”). Most, if not all, of these cases are funded by a third-party funder using such agreements. Claimants and funders of these cases should now reconsider their funding agreements. They might have to renegotiate the funding agreements or even find new ways to fund class action litigation.

The impact of this decision is therefore enormous, as funders face difficulties in recouping their investment after a settlement or an award. That might lead to difficulties for claimants to find funding for their cases. That is acknowledged by the Supreme Court, but it does not change the decision. Lord Sales notes that the Court has been informed that “the likely consequence in practice would be that most third party litigation funding agreements would (…) be unenforceable as the law currently stands”. However, the fact that claimants and funders were under the impression that such agreements did not fall within the definition of a DBA when they concluded these agreements “would not justify the court in changing or distorting the meaning of ‘claims management service’”.

As for the current collective action proceedings, it cannot be ruled out that some opportunistic claimants at the end of proceedings with enough many in the bank will try to conclude the case without paying their funders. UK class action proceedings can cost up to several million pounds, which is normally paid by these funders in advance, so that can save a lot of money.

On the other hand, we need to add some nuance. Since proceedings are so expensive, it is unlikely that the current practice of third party funding will stop at all. However, if the UK parliament will not change the law – and funders are probably lobbying for that already – it might be more difficult to invest in such cases and it is well possible that funders shift their focus to more funder-friendly countries, such as the Netherlands.

What are the Dutch rules?

Under Dutch law, there are only rules on financing opt-out cases, which aim to protect damaged parties (often consumers) that cannot instruct the claim vehicle representing them. These damaged parties are possibly not even aware of the case. These rules, however, do not apply to opt-in cases where claimants litigate on the basis of assignments. This was confirmed in one of the trucks cases in July 2022. The Dutch Court of Amsterdam ruled that the opt-out regulations are not applicable to opt-in proceedings started by claim vehicles, as they claim on behalf of professional parties that made a free choice to join the proceedings and who may instruct the claim vehicle. They don’t need the legal protection that is provided for the opt-out cases.

To
top