Google Fined €890 M Under EU Digital Markets Act for Search Self‑Preferencing and Play Store Steering Restrictions
What Happened — The European Commission imposed two fines on Google totaling €890 million for breaching the Digital Markets Act (DMA). One fine (€460 M) addresses preferential placement of Google’s own services in Search results; the other (€430 M) targets restrictions that prevented app developers from directing users to cheaper alternatives outside the Play Store.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how regulator‑driven “fair‑play” rules can translate into material financial penalties for platform providers, underscoring the need for continuous third‑party risk monitoring.
- Highlights the importance of documenting vendor‑management controls (e.g., SOC 2 CC6.1 – “Monitoring of third‑party services”) and maintaining audit‑ready evidence of due‑diligence.
- Aligns with Verisq’s Vendor Risk capability, which provides continuous monitoring and compliance evidence for critical SaaS providers.
Who Is Affected – Large‑scale digital platforms, SaaS providers, and any organization that relies on Google Search or Play Store for core business processes (e.g., e‑commerce, travel, hospitality, mobile app distribution).
Recommended Actions
- Review contracts and service‑level agreements with Google to ensure clauses covering fair treatment and compliance with DMA‑type obligations.
- Map the DMA findings to SOC 2 vendor‑management controls (CC6.1, CC6.2) and collect evidence of ongoing monitoring.
- Deploy continuous third‑party monitoring to detect changes in Google’s service behavior and receive alerts on regulatory developments.
Technical Notes – The enforcement stems from the EU’s Digital Markets Act, a competition‑focused regulation rather than a technical vulnerability. No CVEs or exploit details are involved; the impact is regulatory and financial. Source: Security Affairs