1. Introduction. The ATT Policy under the AGCM’s Scrutiny
The Italian Competition Authority, the “Autorità Garante della Concorrenza e del Mercato” (AGCM), fined Apple Inc., Apple Distribution International Ltd and Apple Italia S.r.l. (hereinafter, “Apple”) more than EUR 98.6 million, for abusing its dominant position under Article 102 TFEU.
The decision, announced by the AGCM on 22 December 2025, concerns App Tracking Transparency (ATT), introduced by Apple on iOS as of 26 April 2021. This policy requires third-party app developers distributing their apps through the App Store – but not Apple’s own apps – to obtain specific user consent for collecting and linking data for advertising purposes through a screen imposed by Apple, the so-called ATT prompt (Baviskar et al., 2024). However, this prompt does not meet the requirements of data protection law, so third-party developers must also use their own consent-gathering tool, the CMP prompt. As a result, for the same advertising-related processing activity, users are asked to provide consent twice.
The proceedings were opened on 2 May 2023 following a complaint submitted by Meta, the company controlling the social networks Facebook and Instagram, as well as the instant messaging services WhatsApp and Messenger.
The investigation then developed within a broader context of European coordination, involving the European Commission, other national competition authorities – in particular the French Autorité de la concurrence and the German Bundeskartellamt – and the Italian Data Protection Authority. The AGCM did not challenge Apple’s decision to strengthen user protection, but the way that objective was pursued, namely through a policy imposed only on third-party developers and considered disproportionate, since the same result could have been achieved through measures less restrictive of competition.
Apple contested the decision and has already announced its intention to appeal. The case therefore offers an opportunity to examine the relationship between privacy protection, data access and platform power within closed digital ecosystems.
2. In-App Advertising and the Centrality of Data
To understand the competition-law relevance of the case, it is necessary to start from the economic model of apps. Many developers distribute apps for free or at a low price and monetise them by selling in-app advertising space. Advertising is therefore not an ancillary element, but one of the main sources of funding for the provision of digital services (Li and Tsai, 2026).
The AGCM reconstructs the context by starting from online mobile in-app advertising, namely advertising addressed to mobile-device users and delivered through apps. In this area, non-search personalised advertising is particularly relevant. Unlike search advertising, it does not depend on searches carried out by the user, but on data previously collected about the user, the device and browsing activity. When personalised, this form of advertising requires collecting and linking user data, enabling the creation of advertising profiles and the targeting of ads to individuals potentially interested in the advertised product, service or app.
The decisive step is “targeting”, an IT procedure that matches advertising content with the user’s profile according to affinity-based criteria. The greater the quantity and quality of the available data, the greater the ability to reduce scatter loss, avoiding ads being shown to uninterested users. Data availability therefore affects the economic value of advertising. If operators cannot collect, link and use sufficient data, advertising becomes less effective. This results in lower revenues for developers selling advertising space, higher costs for advertisers purchasing it, and difficulties for advertising intermediation platforms. Apple’s conduct thus affects access to the data that fuel personalised advertising and the economic balance of the in-app advertising value chain.
3. IDFA and Tracking within the iOS Ecosystem
If data are the essential input for personalised advertising, it is necessary to identify the tools used to collect and link them within the iOS ecosystem. For third-party developers, the key tool is the IDFA (Identifier for Advertisers), a unique device identifier made available by Apple (Lomborg, Helles and Lai, 2023). It links activities carried out across different apps and contexts to a single device and, therefore, generally to the same user, making it possible to connect browsing data and deliver personalised ads.
With the introduction of the ATT policy, access to the IDFA became subject to user consent collected through the ATT prompt. If the user consents, the developer can access the identifier and use it, together with advertising partners, for personalisation and measurement. If consent is denied, the IDFA cannot be used for advertising and the developer must rely on alternative tools, such as SKAdNetwork, which provides more aggregated, less timely and less useful data for measuring campaign effectiveness.
The issue is not merely technical. ATT affects third parties’ ability to collect and link data across different apps and services. For developers, this adds to the consent already required through the CMP prompt, necessary to comply with privacy-law obligations, resulting in double explicit consent, or double opt-in. This creates an asymmetric user experience compared with both Android, where the CMP prompt alone remains sufficient, and Apple itself.
Indeed, Apple does not use the ATT prompt for its own advertising services, but relies on a different Personalized Ads prompt, shown only once and worded differently, without mentioning “tracking” and referring only to personalised advertising. Apple justifies this difference by arguing that it uses only first-party data collected through its direct relationship with users, and not third-party data. According to the AGCM, however, this distinction reinforces the asymmetry of the iOS ecosystem: third parties’ access to data is restricted, while Apple continues to operate from a privileged position, based on its control over iOS, the App Store and its own advertising services.
4. Double Consent and the Principle of Proportionality. The Role of the Italian Data Protection Authority
Data tracking activities and their use by developers lie at the intersection of competition law and data protection (Kox, Straathof and Zwart, 2017). The relevant legal framework consists of the GDPR (Regulation (EU) 2016/679) and the ePrivacy Directive (Directive 2002/58/EC). The former governs consent to personal data processing and sets out the conditions for its lawfulness (Articles 4 and 6); the latter requires, under Article 5, the user’s prior consent to store information or access information already stored on the user’s terminal equipment, as with advertising identifiers.
This intersection is confirmed by the dialogue with the Italian Data Protection Authority, consulted following two requests: on 2 April 2024 and 23 June 2025. Its opinion was issued on 4 August 2025. Interestingly, Apple and Meta interpret the Authority’s position in opposite ways to support their respective arguments. The Authority adopts a cautious and nuanced position. On the one hand, it welcomes measures strengthening privacy protection, including beyond the legal minimum; on the other hand, it clarifies that such measures do not constitute compliance with legal obligations, but rather a discretionary choice by Apple.
The problem does not concern the objective of privacy protection, but how it was pursued. Starting from Apple’s own approach, according to which the developer remains the data controller, the Italian Data Protection Authority emphasises the developer’s autonomy in determining the form, content and means of the consent request. This is where the principle of proportionality becomes relevant (Caravita di Toritto, 2021): the Authority does not rule out that separate consents may be required, but observes that they could have been requested in a single step, through an information flow ensuring granular user choices. The duplication of the ATT prompt and the CMP prompt therefore does not appear necessary considering the objective pursued.
5. Relevant Markets and the Abusive Conduct
The AGCM’s assessment starts from the definition of the relevant markets. The “primary” market in which the abuse originates is the market for the provision to developers of platforms for the online distribution of apps intended for iOS users, where Apple holds a dominant position. The online advertising markets, by contrast, are the connected markets where the harmful effects of the conduct materialise. The market for smart mobile devices remains in the background, as the context of Apple’s closed ecosystem.
Within this framework, the lack of proportionality is one of the constituent elements of the abuse (Licastro, 2022), together with the unilateral imposition of ATT and the ability of the conduct to harm Apple’s commercial partners.
The harm concerns, first, third-party developers that monetise their apps through in-app advertising. Reduced data availability lowers the effectiveness of personalised advertising and, consequently, the value of advertising space sold to advertisers. This effect is particularly significant for smaller operators, which have less first-party data and therefore greater difficulties in profiling users. The conduct also affects developers that purchase advertising to promote their apps within other apps, as well as advertising intermediation platforms.
Against this backdrop, the AGCM also identifies advantages for Apple. On the one hand, the reduced profitability of the ad-funded model encouraged a shift towards paid models or in-app purchases, increasing the commissions collected by Apple through the App Store. On the other hand, third parties’ reduced ability to offer personalised advertising strengthened the attractiveness of Apple’s advertising services, based on its control over the iOS ecosystem.
6. When Privacy Becomes a Market Rule
The Apple-ATT case shows that, within closed digital ecosystems, privacy may serve a function beyond user protection. It may also become a private market rule, where the dominant platform unilaterally defines the conditions for accessing data, technical functionalities and users.
The point, therefore, is not to set privacy against competition: data protection remains a legitimate and central objective in the governance of digital platforms. The problem arises when a tool presented as pro-privacy is designed asymmetrically or disproportionately: more burdensome for third parties, less onerous for the platform imposing it, and capable of affecting competitors’ ability to operate in the market.
This perspective fits within a broader regulatory framework. Apple was designated as a gatekeeper under the DMA for the App Store, iOS and Safari in September 2023, and for iPadOS in April 2024. The issue of non-discriminatory access to the components of the Apple ecosystem is therefore also central to EU digital markets regulation.
This is confirmed by the recent proceedings opened by the AGCM, in cooperation with the European Commission, concerning interoperability between iOS/iPadOS and alternative cloud services. In that case, the Authority hypothesised that third-party consumer cloud providers are not placed on an equal footing with iCloud, particularly as regards access to the components enabling full backup of data stored on Apple devices.
Read from this perspective, the ATT decision does not concern only consent to advertising tracking, but the way an integrated platform can turn technical choices and privacy rules into conditions of market access. It is on this terrain that the relationship between data protection, competition and the contestability of digital ecosystems is being played out.