Italy Probes Apple for Restricting Rival Cloud Backups

Italy Probes Apple for Restricting Rival Cloud Backups

Italian regulators are acting as local experts under Article 38(7) of the DMA to gather evidence for a broader European Union enforcement action against the tech giant. The investigation by the Autorità Garante della Concorrenza e del Mercato, commonly known as the AGCM, represents a significant escalation in the ongoing regulatory scrutiny of the mobile ecosystem within the European economic area. This probe specifically targets the way Apple manages its proprietary cloud services compared to independent competitors on both iOS and iPadOS. At the heart of the matter is the fundamental question of whether a hardware manufacturer should be permitted to design its operating system in a way that provides its own secondary services with a seamless user experience that is technically impossible for third-party developers to replicate. By focusing on the “full-device backup” feature, the AGCM is highlighting a critical friction point where users find themselves increasingly unable to migrate their digital lives to alternative platforms without significant manual effort or data loss. The Italian authority is examining whether these practices constitute an abuse of a dominant position and a direct violation of the rules established to foster a more contestable digital market.

Technical Barriers and System Access Disparities

The core of the AGCM inquiry stems from allegations that Apple intentionally reserves high-level system permissions for its own iCloud service while denying similar access to competitors. When a user chooses to back up an iPhone or iPad, iCloud can perform a comprehensive image of the device, capturing everything from system settings and home screen layouts to application data and encrypted credentials. This process occurs with a single interaction and requires no further management from the user. In contrast, third-party applications such as Dropbox, Microsoft OneDrive, or Google Drive are often relegated to basic file-level synchronization. This means that if a consumer wishes to switch their primary backup provider away from Apple, they cannot simply press a button to secure their entire digital environment. Instead, they must manually ensure each app is syncing correctly, a process that is not only time-consuming but frequently results in the loss of metadata and specific configuration details that iCloud effortlessly preserves.

Furthermore, the investigation is scrutinizing the specific Application Programming Interfaces, or APIs, that govern how data is extracted from the operating system. Whistleblower reports and developer complaints suggest that Apple has maintained a closed set of tools for its own use, effectively creating a “fast lane” for data transfer that is invisible to the user. While iCloud can synchronize vast amounts of data silently in the background while the device is connected to power and Wi-Fi, third-party apps often face aggressive background execution limits. These restrictions frequently force a backup to pause or fail if the user moves the app to the background or locks their screen. This creates a technical environment where rival services appear less reliable or more cumbersome than the native solution. By engineering this friction into the platform, the AGCM argues that Apple may be unfairly nudging its massive user base toward its own subscription services by making the alternatives seem technically inferior through artificial limitations.

The Legal Framework of the Digital Markets Act

This investigation is firmly rooted in the requirements set forth by Article 6(7) of the Digital Markets Act, which was designed to prevent gatekeepers from using their control over essential platforms to favor their own adjacent businesses. The law explicitly mandates that companies designated as gatekeepers must provide third-party service providers with the same level of interoperability that they provide to their own products. This includes access to hardware and software features, such as the neural engine, secure enclave, and the specific synchronization protocols used for cloud storage. The AGCM is looking to prove that Apple has failed to meet these interoperability standards, thereby maintaining a “walled garden” that prevents effective competition. Because Apple is a designated gatekeeper for iOS and iPadOS, the legal burden is on the company to demonstrate that its restrictions are necessary and that it has made a good-faith effort to provide equivalent access to its competitors.

While the European Commission in Brussels serves as the primary enforcer of the DMA, the collaboration with national authorities like the AGCM is a vital component of the regulatory strategy. The Italian investigation serves as a specialized fact-finding mission that utilizes local legal expertise and direct access to regional market data. Under the cooperative structure of the DMA, the findings of the AGCM will be shared with the European Commission to inform a broader decision that could have ramifications across all member states. This decentralized yet coordinated approach allows regulators to tackle the immense technical complexity of modern operating systems by pooling resources and evidence. By focusing on the specific nuances of cloud backup in Italy, the AGCM is helping to build a comprehensive case that could force Apple to fundamentally redesign how iOS interacts with third-party servers, ensuring that the promise of a more open digital market becomes a technical reality for consumers.

Economic Stakes and the Cloud Storage Market

The financial implications of this regulatory action are immense, particularly as Apple has increasingly shifted its business model toward recurring services revenue. As hardware upgrade cycles have lengthened, the “Services” segment, which includes iCloud+ subscriptions, has become a cornerstone of the company’s growth strategy and profitability. In the current European market, cloud storage is no longer a luxury but a fundamental utility for modern life, with the regional sector projected to reach a valuation of over €36 billion by the end of this year. When a user reaches the storage limit of the free 5GB tier offered by Apple, they are faced with a choice. If the system makes it difficult or impossible to utilize a different cloud provider for a full-device backup, the path of least resistance is to pay for an iCloud+ upgrade. This dynamic creates a “lock-in” effect where consumers pay for services not necessarily because they are the best or most affordable, but because they are the only ones that function seamlessly with their hardware.

Regulators are particularly concerned that this lack of competition leads to higher prices and stifled innovation within the cloud storage sector. If specialized storage providers cannot compete on the quality of the user experience because of platform-level restrictions, they have less incentive to invest in the European market. The AGCM has pointed out that many users already pay for other ecosystem subscriptions, such as Google One or Microsoft 365, which include significant amounts of cloud storage. However, because these services cannot perform a “full-device backup” on an iPhone, many Italian consumers end up paying for two separate storage subscriptions just to ensure their phone data is safe. This duplication of cost represents a direct economic harm to consumers and prevents a level playing field where companies compete on features, security, and pricing rather than on who owns the operating system. The investigation seeks to break this cycle by ensuring that any cloud provider can offer a comprehensive backup solution.

Procedural Timeline and Potential Enforcement Actions

The procedural roadmap for this investigation is clearly defined, providing Apple with an opportunity to present its defense while maintaining a strict schedule for resolution. Following the formal opening of the probe in June 2026, Apple and its subsidiaries were granted a 60-day window to respond to the initial allegations and request a hearing. During this period, the company must provide detailed documentation regarding its API management and the technical specifications of the iCloud backup process. The Italian Digital Platforms and Communications Directorate will be responsible for reviewing these submissions and conducting any necessary inspections of internal protocols. The AGCM has set a definitive deadline of March 31, 2027, to conclude its proceedings and issue a final report. This timeline ensures that the investigation moves with the speed required by the rapidly evolving technology sector while allowing for a thorough and fair evaluation of the evidence.

If the findings of the AGCM confirm that Apple has violated the DMA through anti-competitive restrictions, the consequences will be severe. Under the current legal framework, the Italian report will be transitioned to the European Commission for final adjudication and the imposition of penalties. The Commission possesses the authority to levy fines reaching up to 10% of a company’s total global annual turnover for a first-time violation. Given the scale of Apple’s global operations, such a penalty could reach tens of billions of dollars. For repeated non-compliance, the fine can escalate to as much as 20% of annual turnover, and the Commission may even impose structural remedies, such as forcing the company to sell parts of its business or change its core software architecture. These potential sanctions serve as a powerful deterrent and a clear signal that the European Union is willing to use its full economic weight to ensure that gatekeepers do not abuse their market positions to the detriment of competition and consumer choice.

Privacy and Security as a Defense Strategy

In its anticipated defense, Apple will likely emphasize that its closed ecosystem is a deliberate design choice intended to protect user privacy and enhance device security. The company has a long history of arguing that allowing third-party applications deep, system-level access to sensitive data could open the door to malware, data breaches, and unauthorized surveillance. From this perspective, a full-device backup contains some of a user’s most private information, including health data, messaging history, and Wi-Fi credentials. Apple maintains that by keeping the backup process entirely within its own encrypted infrastructure, it can guarantee a level of security that would be impossible to maintain if the same “hooks” were opened to third-party developers. This argument positions the iCloud-only backup not as an anti-competitive hurdle, but as a critical safety feature that protects the integrity of the entire platform for the benefit of the user.

However, the AGCM and other European regulators have expressed increasing skepticism toward these “security-washing” arguments. The challenge for Apple will be to provide empirical evidence that the security risks are insurmountable and that no less-restrictive alternative exists. Regulators are looking for proof that the company could not have created a secure, sandboxed API that allows rivals to gather backup data without compromising the overall stability of the operating system. There is a growing consensus among policy experts that security and interoperability are not mutually exclusive goals. The investigation will examine whether the security concerns are a genuine technical necessity or a convenient justification for maintaining a profitable monopoly over device data. By demanding a higher level of transparency regarding the inner workings of iOS, the AGCM is pushing for a future where platform owners must prove that their “walled gardens” are built for protection rather than for profit.

Future Implications for the Digital Ecosystem

The investigation into cloud backup restrictions represented a pivotal moment in the evolution of digital governance and platform accountability. By challenging the technical barriers that favored proprietary services, regulators sought to redefine the relationship between hardware manufacturers and independent software developers. This case highlighted the transition toward an era where the concept of “user ownership” of data began to take precedence over the control exerted by device ecosystems. The focus shifted away from simple hardware sales toward the long-term management of digital identities and personal archives, ensuring that consumers were not permanently tethered to a single provider by the complexity of their own data. This regulatory pressure encouraged a more modular approach to mobile software, where essential utilities became standardized and interchangeable across different brands and services.

Looking back, the insights gained from the Italian probe provided a clear blueprint for how technical interoperability could be enforced without compromising the core security of a device. It became evident that the industry needed to move toward open standards for mobile backups, similar to the protocols that govern email or web browsing. Developers and platform owners began to collaborate on secure, authenticated pathways that allowed for the seamless transfer of entire digital environments between competing cloud infrastructures. This shift not only empowered consumers with greater flexibility but also fostered a new wave of innovation among cloud storage providers, who were finally able to compete on the merits of their encryption, speed, and organizational features. The legacy of this period was the establishment of a digital market where the convenience of a “one-click” experience was no longer a proprietary advantage, but a basic standard available to everyone regardless of the logo on their smartphone.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later