Chrome, Competition and Your Data: What Smaller Companies Should Adjust Now
Developments around Chrome, the tech giants, and several federal legal actions are redrawing the rules on competition and data sharing.
For smaller Canadian companies, whether the concern is privacy, IT, finance, or security, the message is clear: you need to adapt your vendor contracts and tighten your data governance, to limit risk while taking advantage of the new openings.
The context: openness rather than breakup
Several recent decisions are shifting the balance. Google avoided being forced to sell Chrome, but will have to open up certain assets and features. Found to hold a monopoly, it is being compelled to share some search data to rebalance competition. Separately, Cogeco has sued the federal government over competition-related decisions.
These signals point to a more interventionist framework: fewer dramatic breakups, more obligations around openness, portability, and transparency.
For a smaller company, that means two things. Anticipate technical changes at your vendors, whether in APIs, export policies, or terms of use. And negotiate, without delay, clauses that protect your access, your audit rights, and the portability of your data.
Direct impacts
The data flowing through your SaaS vendors is the first place to look. You need to know precisely what information (customer, financial, HR) moves through which systems, and in which countries.
That exercise exposes dependencies on proprietary formats, hidden exit fees, and export limitations. The goal is simple: documented APIs and complete exports, in standard formats such as CSV, JSON, or Parquet.
Portability and security have to become reflexes:
- Contract for portability in open formats, and test your restores regularly
- Clarify anonymization and pseudonymization methods, aligned with recognized standards such as NIST or ISO
- Govern data access with precise roles, strong authentication (MFA), and exportable logs for your audits
These questions extend to your tools. In CRM and marketing, the ability to plug in new connectors could become a competitive advantage. In analytics, favour warehouses where you remain the owner of the information and hold your own encryption keys. Hold partners and integrators to the same security and portability obligations as your primary vendors.
Vendor contracts: the clauses to prioritize
A few clauses deserve particular attention during contract review:
- Data portability: guaranteed in open formats, without prohibitive fees
- Security: strong encryption, multi-factor authentication, ISO or SOC 2 compliance
- Transparency on the subprocessor chain, with a right to object to critical changes
- Incident notification that is fast, ideally within 24 to 72 hours, with a useful minimum of detail
- Audit rights letting you verify compliance and access the relevant reports
A 90-day action plan
A short calendar beats a vague intention:
- Weeks 1 and 2: inventory and map your data to identify the gaps.
- Weeks 3 and 4: assess the risks and prioritize critical vendors.
- Weeks 5 to 8: revise contracts, test portability, verify backups.
- Weeks 9 to 12: stand up active governance (a data and security committee), train the teams, run an incident simulation.
What to take away
Regulators now favour openness and portability over breakups. For smaller companies, two levers matter: vendor contracts that guarantee portability, security, and auditability, and data governance that is rigorous, tested, and documented.
Review your data and cybersecurity contracts this quarter. Those who adapt quickly will gain resilience and agility as regulation and technology keep shifting.