How secrecy in new EU data-center rules could tilt the balance toward big tech

The European Union recently moved to create a common reporting and rating scheme for data centres while simultaneously allowing important facility-level metrics to be withheld as confidential. That change,embedded in implementing measures for the Energy Efficiency Directive and its delegated act,has prompted scrutiny from journalists, watchdogs and policy experts who say the provision was shaped by industry lobbying and risks limiting public oversight.

This article examines how secrecy in the new EU rules could shift competitive leverage toward the largest cloud and hyperscale firms, what it means for environmental accountability and market openness, and which policy corrections could preserve transparency without undermining legitimate security or commercial concerns. Several recent investigations and position papers give clarity on how the rule was written and who influenced it.

What changed in the EU rules?

The Energy Efficiency Directive (EED) already obliges data‑centre operators above certain power thresholds to report standardized key performance indicators,metrics such as energy consumption, power usage effectiveness and water usage,so the Commission can build a European database and a common rating scheme. The aim is to measure and improve sustainability across a sector expected to grow rapidly.

However, the implementing Delegated Act accompanying the scheme includes language that allows facility‑level information to be treated as trade secrets or otherwise confidential, effectively permitting operators to avoid publishing detailed, site‑specific KPIs in public form. That carve‑out alters the practical transparency of the reporting regime and determines what the public, competitors and local authorities can see.

Member States retain some discretion in transposition, but the Delegated Act’s framing of confidentiality has a strong harmonizing effect: it sets expectations about what counts as protected information and how the European database will publish aggregated results rather than granular facility data. That aggregation reduces the comparability of individual data centres.

How secrecy was inserted and who lobbied

Investigations by major outlets and NGOs show that large cloud providers and their trade groups actively sought confidentiality language during the drafting of the Delegated Act. Reporting attributes specific amendments and suggested formulations to industry actors and lobby coalitions that argued for protecting commercially sensitive facility‑level data.

Organisations such as DigitalEurope, whose membership includes Amazon, Google and Microsoft, submitted position papers urging that the reporting regime clarify the confidential nature of certain KPIs and align with existing business‑secrecy protections. Internal and public consultations reflected those priorities and appear to have left a measurable imprint on the final drafting.

Watchdogs and transparency advocates have pointed out that the drafting process,in which industry proposals were adopted or echoed in Commission text,raises legal and democratic questions about undue influence and whether public interest considerations were sufficiently protected. Some commentators note potential tensions with transparency obligations under EU and international law.

Mechanisms by which secrecy benefits big tech

Secrecy over facility‑level KPIs reduces the amount of comparable public data available to rivals, independent researchers and policy makers. Large cloud providers operate at a scale and with engineering capabilities that already produce efficiency advantages; opaque reporting lets them preserve proprietary cooling designs, workload management techniques and supplier contracts that are part of that competitive edge.

When only aggregated or anonymized metrics are published, the signal that smaller operators need,explicit, site‑level benchmarks to demonstrate parity or superiority,vanishes. That raises barriers for new entrants seeking to prove their sustainability credentials to customers and regulators, thereby reinforcing incumbents’ market positions. Economic literature from past regulatory episodes (for example, after GDPR) shows how complex compliance regimes can favour large, resource‑rich firms.

Finally, confidentiality provisions can be invoked selectively. Large operators can absorb the legal and administrative costs of securing confidentiality claims and, when necessary, litigate to defend them,an option less available to small and medium providers. The combined effect is a shift in bargaining power toward scale players.

Impacts on competition, innovation and market structure

Reduced transparency undermines the ability of competitors to benchmark and iterate. In a market where access to compute, energy efficiency and waste‑heat reuse are competitive levers, missing data can blunt market signals that otherwise would reward innovation in cooling, software optimization and local integration. That dampens dynamic competition and can slow the diffusion of best practices.

Investors and corporate customers also rely on reliable, comparable metrics to make procurement and financing decisions. Aggregated or withheld information increases due diligence costs and may bias procurement toward established hyperscalers that can supply bespoke reporting under NDA,again privileging incumbents. This has implications for the EU’s broader industrial strategy and for smaller cloud and hosting firms across member states.

Over time, concentration in infrastructure can feed concentration in services: control of physical capacity contributes to data‑moat effects for AI, cloud services and platform offerings. As big tech continues to commit very large investments to AI and data infrastructure, regulatory asymmetries in transparency risk accelerating that concentration.

Environmental accountability and democratic oversight at stake

Data centres have important local environmental footprints,energy demand, water use for cooling and waste‑heat management are matters of public interest, especially where new builds strain grid capacity or affect local resources. Facility‑level KPIs enable communities and regulators to assess cumulative impacts and to plan grid upgrades or water allocations accordingly. Confidentiality therefore weakens environmental governance.

Transparency advocates argue that the EU’s commitments under environmental access‑to‑information norms could be at risk if wide confidentiality exceptions become routine. That may generate legal challenges and erode public trust in both industry disclosures and in the EU’s ability to enforce sustainability objectives. Public scrutiny is a central enforcement mechanism in environmental policy; secrecy reduces that lever.

At the same time, legitimate confidentiality concerns exist,cybersecurity, supplier agreements and genuinely sensitive commercial information must be protected. The policy challenge is to design narrow, well‑defined exceptions and robust oversight rather than broad carve‑outs that are easy to exploit. The current Delegated Act has been criticised precisely because it leaves that boundary insufficiently clear.

Policy options to rebalance transparency and protection

Policymakers can refine the delegated rules to require the publication of standardized, site‑level KPIs while allowing narrowly tailored redactions for demonstrable security or contractual harms. Independent verification mechanisms,third‑party audits or anonymized machine‑readable disclosures with verification stamps,could preserve commercial confidentiality without silencing comparability.

Another option is differential access: publish detailed data to qualified public authorities, researchers under strict protocols, and civil‑society auditors, while providing aggregated public dashboards for general audiences. That preserves public‑interest scrutiny and technical research value without exposing raw contractual details. Such graduated access models are used in other infrastructure sectors.

Finally, stronger procedural safeguards in the rulemaking process,clearer disclosure of meetings and submitted amendments, limits on revolving‑door influence, and mandatory impact assessments of confidentiality clauses on competition,would reduce the risk that future technical acts embed private advantage. If the EU wishes to promote digital sovereignty and an open industrial ecosystem, rule design must reflect those goals.

The decision to permit broad confidentiality in data‑centre reporting shifts more than disclosure practice; it shapes who benefits from Europe’s infrastructure build‑out. Without corrective measures, the balance between public accountability and commercial protection risks tilting toward the hyperscalers that already control the largest pools of capital and compute.

Policymakers still have tools to narrow exceptions, introduce verified disclosure modalities and protect competitive parity. Doing so would reconcile legitimate privacy and security concerns with the EU’s stated objectives on sustainability, competition and digital sovereignty,and ensure that transparency serves the public interest rather than private advantage.

nexustoday
nexustoday
Articles: 277