Germany’s Federal Cartel Office just handed Apple a problem: the company’s App Tracking Transparency feature, which Apple marketed as a privacy win for users, is actually an anticompetitive design that steers people away from third-party apps.
The regulator ordered Apple to change how it presents data collection consent prompts to iPhone and iPad users. The issue isn’t that Apple asks for permission. It’s that the prompts are designed in a way that makes Apple’s own apps look safer by comparison.
This matters because ATT has already reshaped the internet economy. When Apple launched the feature with iOS 14.5, it cost social media companies nearly $10 billion by making cross-app tracking largely opt-in. Facebook, Instagram, and others suddenly couldn’t follow users around the web without explicit permission, and most users said no.
At the time, Apple framed this as privacy protection. Critics called it a power play. The German regulator is saying both things can be true, and the way Apple implemented ATT crosses a line.
Apple is designated as a “gatekeeper” under the EU’s Digital Markets Act, which means it faces extra scrutiny over whether its platforms provide fair competition. The DMA doesn’t just ban anticompetitive behavior. It requires large platforms to actively avoid favoring their own services.
The Cartel Office’s action suggests that ATT’s design fails that test. When a prompt makes third-party apps look invasive while Apple’s services appear more trustworthy, that’s not neutral privacy protection. It’s using privacy as cover for competitive advantage.
Apple hasn’t said exactly how it will change the prompts, but whatever redesign it comes up with will need to pass muster with German regulators who are clearly watching for any hint that Apple is putting its thumb on the scale.
Over in the US, the Supreme Court just refused to help Verizon get out of paying a $47 million FCC fine for selling customers’ device-location data.
Verizon wanted the money back. The Court said no, which means the fine stands.
What makes this interesting is Verizon’s continued insistence that selling device-location data isn’t actually illegal. The company lost its case, lost its appeal, and just got turned away by the highest court in the country. And carriers are still claiming the underlying conduct was fine.
That’s not a legal strategy. That’s a signal about what the industry thinks it should be allowed to do, regardless of what regulators say.
The FCC fined Verizon because the company sold real-time location data about its customers to third parties without proper consent or safeguards. This wasn’t aggregated, anonymized data. It was specific enough that bounty hunters and other dubious actors could track individual people.
Verizon argued the FCC overstepped its authority. The courts disagreed. But instead of accepting that selling this kind of data requires better controls, the industry is still arguing it shouldn’t be restricted at all.
Both cases are about the same core tension: companies want to monetize user data, and regulators are increasingly saying the way they’re doing it isn’t acceptable.
In Germany, Apple is learning that privacy features don’t get a free pass if they also happen to kneecap competitors. In the US, Verizon is learning that “we don’t think this should be illegal” isn’t a legal defense.
The difference is that Apple has to change how it does business in the EU. Verizon just has to pay the fine. Whether that’s enough to actually change carrier behavior is another question entirely.
One email at dawn. The five stories that mattered, with the bits removed and the meaning kept. Free, for now.