The European Data Protection Board, the EU's data protection advisor, says Google's acquisition of Fitbit entails “a high level of risk” to privacy rights
Context & Ripple Effects
In February 2020, the European Data Protection Board warned that Google's proposed acquisition of Fitbit carried "a high level of risk" to privacy rights — an early signal from the EU's advisory body that the deal would be judged on data concentration, not just market share. The concern centered on what a search-and-ads giant could do with years of granular health and activity data.
That warning set the arc the rest of the coverage traces: the European Commission opened an in-depth investigation into the data question mid-year, sources reported the EU pressed Google to keep Fitbit data out of its search ranking and to grant third parties access, and by December the Commission cleared the $2.1B deal only against binding privacy and consent commitments.
First-order effects
- Google's path to closing the Fitbit purchase now runs through Brussels rather than just antitrust clearance — the EDPB's assessment hands privacy authorities a formal seat at the review table alongside competition enforcers.
- Fitbit users' health and activity records become the explicit subject of regulatory scrutiny, raising the bar for any consent or data-handling changes Google proposes during the review period.
Second-order effects
- The EU's demands reshape the deal's economics: per the reporting, Google is asked not to use Fitbit data to reinforce its search advantage and to open equal access to third parties — conditions that cap the advertising value of the acquisition even if it closes.
- Rival wearable makers and health-data platforms gain a negotiating precedent: if Europe forces data-separation terms on Google-Fitbit, similar terms become the ask in any future big-tech bid for sensor or health datasets.
Third-order effects
- If the pattern holds, large acquisitions of behavioral or biometric data businesses in Europe close only with enforceable data-use commitments attached — making conditional approval, not outright blocking, the standard remedy for data-concentration deals.
- Privacy regulators like the EDPB are positioned as standing gatekeepers whose early risk assessments effectively pre-shape merger terms, shifting deal design toward negotiable data boundaries before regulators ever file a formal objection.
The trend: EU regulators are converging on a playbook where big-tech acquisitions of personal-data businesses get approved only under binding data-use commitments, with privacy advisors shaping terms before the competition authority rules.