What the Digital Markets Act Means for Default Tracking on Phones
A modern phone is both a communications device and a sensor platform. It records location signals, app activity, browsing habits, purchases, contacts and movement between services. Much of this data collection is presented as a convenience: maps become more useful, adverts become more relevant and accounts work across different products. Yet the default settings often decide how much information is shared before a person has made a meaningful choice.
The European Union’s Digital Markets Act (DMA) changes that balance for the largest technology companies. It does not create a universal ban on tracking, and it does not automatically make every phone private. Instead, it limits how designated gatekeepers can combine personal data, imposes obligations around consent and choice, and challenges the idea that a platform may quietly make surveillance the easiest option.
For people in Australia, the law matters even when it does not apply directly. Australians use the same iPhones, Android devices, app stores and advertising systems as people in Europe. Changes made for the European market can influence global software design, while the DMA also gives policymakers a practical example of how competition rules can address privacy problems that conventional data protection law has struggled to contain.
Why phone tracking became a competition issue
Default tracking is rarely the result of a single setting. It is usually created by an ecosystem. A phone manufacturer controls the operating system, an app store distributes software, an advertising company operates analytics tools, and a large platform connects identity across search, video, maps, email and payments. When one company controls several of these layers, it can observe activity across services and use that information to strengthen its position.
The DMA focuses on companies with a particularly powerful role as “gatekeepers” in digital markets. It covers core platform services such as operating systems, app stores, search engines, online advertising and certain messaging services. The concern is that a gatekeeper can make access to one service conditional, in practice or in design, on accepting data practices linked to another service.
This matters because privacy choices are affected by market power. A person may technically be free to refuse personalised advertising, but that choice has little value if the alternative is confusing, buried in menus or accompanied by repeated prompts. A small app developer also cannot easily avoid a gatekeeper’s tracking infrastructure when access to an app store, advertising network or mobile operating system is essential.
The DMA therefore treats data combination as part of a broader platform problem. It asks whether a company is using control over one service to extract information for another, rather than treating every consent screen as an isolated transaction.
What the DMA changes about personal data
One of the most significant rules restricts the combination and cross-use of personal data from different core platform services and other services offered by a gatekeeper. In broad terms, the company must obtain user consent before combining data in ways covered by the law. Consent must be requested in a clear and specific manner rather than being treated as an automatic consequence of opening an account.
The practical effect is important for services such as search, video, advertising, maps and social networking. A company may still collect data needed to provide a service, comply with law or perform certain limited functions. The DMA is not a requirement to stop all analytics or contextual advertising. Its focus is on preventing powerful platforms from freely merging datasets simply because their products sit inside the same corporate ecosystem.
The law also says that refusing consent should not mean that the person loses access to the core service altogether. A gatekeeper may offer an equivalent alternative with less personalised functionality, although the precise design of these alternatives has become a major area of dispute. The quality of the choice matters: an option that is technically available but deliberately inconvenient can still undermine genuine consent.
This is where the DMA intersects with European data protection law, including the GDPR. The GDPR asks whether processing has a lawful basis and whether information is collected fairly and transparently. The DMA adds a market-power perspective. It is concerned with the leverage a gatekeeper has when asking for permission, as well as the privacy implications of the processing itself.
What changes on an iPhone or Android device
The most visible result may be a wider set of choice screens and default options. In the European Economic Area, Apple has introduced changes involving alternative app marketplaces, browser choice and payment systems, while Google has adjusted search preference screens and data-sharing controls for some services. These measures respond to several DMA obligations rather than a single “turn off tracking” switch.
A choice screen can affect defaults without eliminating surveillance. If a person selects a different search engine or browser, less activity may flow to the incumbent provider. If separate services no longer share identifiers by default, advertising profiles may become less comprehensive. However, individual apps can still request permissions, use their own analytics tools and send information to advertising partners, subject to other legal and platform restrictions.
Apple’s App Tracking Transparency framework is also separate from the DMA. It asks many apps to request permission before tracking activity across companies’ apps and websites. The DMA does not replace that system, and it does not mean that accepting one permission prompt allows every form of tracking. Android has its own advertising controls, privacy dashboard and permission model, but these settings also require careful interpretation.
The geographic limitation is significant for Australians. A person using an iPhone in Melbourne or an Android phone on a train in Sydney will generally receive the settings configured for the Australian market, not automatically the full set of European options. Companies may decide that maintaining one global design is simpler, but they may also keep some changes regional to preserve revenue or comply with local rules.
What it means for Australian users and regulators
Australia does not have a direct equivalent of the DMA’s gatekeeper regime. The Privacy Act 1988 sets rules for handling personal information, and the Australian Competition and Consumer Commission (ACCC) examines competition and consumer harms. The Privacy Act review and subsequent reform efforts have put greater attention on consent, targeted advertising, children’s privacy and the ability of large platforms to collect information at scale.
The Australian market has its own pressure points. Many people use Google Search, YouTube, Android or Chrome alongside an iPhone, while Meta’s services remain deeply embedded in social communication and small-business marketing. A café in Brisbane, a tradesperson in Perth or a retailer in Adelaide may rely on platform advertising to reach customers, even as the same platforms build extensive behavioural profiles about the people viewing those adverts.
Everyday travel illustrates the same tension. Opal, Myki and other transport systems make commuting around Sydney or Melbourne more convenient, but location-linked records can reveal routines when combined with phone identifiers and app activity. A user might approve location access for navigation, accept advertising cookies in a browser and sign into a major account without seeing how those separate signals can be connected.
The DMA may influence Australia in two ways. First, global companies may eventually apply privacy-preserving defaults more broadly because separate European and Australian systems are expensive to maintain. Second, Australian regulators and lawmakers can use the European experience to identify weak points in consent design, data combination and digital market concentration. The result will not be automatic legal protection, but it can raise the standard for what Australian consumers expect from a phone.
A useful comparison is the debate over a national privacy framework. The arguments outlined in Europe’s privacy lessons show why formal rights matter, while enforcement and institutional capacity determine whether those rights affect daily technology. Rules must reach the systems that collect and combine data, not merely require longer notices that few people read.
The limits of default privacy reform
Changing a default can have a large effect because most people do not repeatedly inspect every permission, account setting or advertising preference. Defaults shape behaviour through convenience. A privacy-friendly option selected automatically can protect people who lack time or technical knowledge, while an opt-in tracking setting can quietly expand the data available to a platform.
Still, defaults cannot solve every problem. Apps may use device fingerprints, coarse location, purchase records or logged-in identifiers to infer interests without relying on one obvious advertising switch. Data brokers can combine information obtained from many companies. A person who disables personalised advertising may still encounter extensive measurement, fraud detection and profiling within services they continue to use.
There is also a risk that consent becomes a form of interface theatre. A gatekeeper can display two options while making one brightly coloured and the other difficult to find. It can repeat a request until a person gives up. It can offer a less personalised service that is materially worse, or ask for permission at a moment when refusing appears likely to interrupt an urgent task.
Security and privacy decisions also involve concentration. A centralised password manager, for example, may reduce the risk of reusing weak passwords while creating a valuable store of sensitive information. The trade-off is explored in the privacy costs of using a centralised password manager. The same principle applies to phone platforms: convenience can reduce some risks while increasing the amount of trust placed in one provider.
The DMA is therefore best understood as a structural intervention rather than a complete privacy solution. It makes certain data practices harder for gatekeepers and gives regulators leverage over powerful platforms. It does not remove the need for app permissions, browser protections, careful account choices or stronger national rules.
The concrete effect of the Digital Markets Act on default tracking will depend on enforcement, interface design and whether regulators reject superficial compliance. For Australians, the most useful near-term response is to treat European changes as a signal of what may become possible elsewhere, rather than assuming that a new phone automatically offers meaningful privacy.
On your next phone privacy check, open the advertising and app-permission settings, disable cross-app tracking where available, and remove location access from every app that does not need it.