HomeIntelligenceBrief
BREACH BRIEF🟠 High Advisory

Google Fined €890 M Under EU Digital Markets Act for Search Self‑Preferencing and Play Store Steering Restrictions

The European Commission fined Google €890 million for violating the Digital Markets Act by favoring its own services in Search and blocking developers from steering users to cheaper alternatives on Play Store. This underscores the need for continuous vendor‑risk monitoring and SOC 2‑aligned third‑party controls.

LiveThreat™ Intelligence · 📅 July 25, 2026· 📰 securityaffairs.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Google Fined €890 M Under EU Digital Markets Act for Search Self‑Preferencing and Play Store Steering Restrictions

What Happened — The European Commission imposed two fines on Google totaling €890 million for breaching the Digital Markets Act (DMA). One fine (€460 M) addresses preferential placement of Google’s own services in Search results; the other (€430 M) targets restrictions that prevented app developers from directing users to cheaper alternatives outside the Play Store.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how regulator‑driven “fair‑play” rules can translate into material financial penalties for platform providers, underscoring the need for continuous third‑party risk monitoring.
  • Highlights the importance of documenting vendor‑management controls (e.g., SOC 2 CC6.1 – “Monitoring of third‑party services”) and maintaining audit‑ready evidence of due‑diligence.
  • Aligns with Verisq’s Vendor Risk capability, which provides continuous monitoring and compliance evidence for critical SaaS providers.

Who Is Affected – Large‑scale digital platforms, SaaS providers, and any organization that relies on Google Search or Play Store for core business processes (e.g., e‑commerce, travel, hospitality, mobile app distribution).

Recommended Actions

  • Review contracts and service‑level agreements with Google to ensure clauses covering fair treatment and compliance with DMA‑type obligations.
  • Map the DMA findings to SOC 2 vendor‑management controls (CC6.1, CC6.2) and collect evidence of ongoing monitoring.
  • Deploy continuous third‑party monitoring to detect changes in Google’s service behavior and receive alerts on regulatory developments.

Technical Notes – The enforcement stems from the EU’s Digital Markets Act, a competition‑focused regulation rather than a technical vulnerability. No CVEs or exploit details are involved; the impact is regulatory and financial. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/195963/laws-and-regulations/google-fined-e890m-under-eu-digital-markets-act-over-search-and-play-store-practices.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →