Skip to content

Self-Preferencing Firewall

Separation protocol — instantiates Bottleneck Power Governance

Walls off the arm that operates the bottleneck from the controller's downstream business — separating data, staff, and decisions — so it can't quietly steer access to favour its own side.

A Self-Preferencing Firewall is for the case where the bottleneck controller also competes in a market that depends on the bottleneck. Rather than break the company apart, it draws an internal boundary — separating the data, the staff, and the decision rights of the access-operating arm from those of the downstream arm — so that the arm running the chokepoint cannot see, or act on, information that would let it tilt the field toward its own affiliate. Its defining move is that it keeps the firm whole and instead governs the flow of information and decisions across an internal wall, backed by monitoring. That makes it lighter than structural separation and heavier than a paper rule: the firm stays integrated, but the specific channels through which self-preferencing happens — a peek at a rival's data, a nudge to the ranking — are cut and watched.

Example

A large online marketplace hosts thousands of independent sellers and also sells its own private-label products in the same aisles. Two levers let it self-preference: its retail team could study individual third-party sellers' sales data to decide which products to clone, and it could hand-tune search ranking so its own items float while rivals sink. A self-preferencing firewall addresses both without splitting the company. Third-party seller data is walled off — the private-label team is barred from seeing individual-seller sales figures and works only from aggregate, market-wide numbers. Ranking is governed by rules the retail arm cannot reach in and adjust, and the boundary is enforced by separate reporting lines and access controls.

Behind the wall sits a monitor: ranking outcomes are audited for systematic own-brand favouritism, and data-access logs are checked for reach-arounds. When a spot-audit shows the private-label share of the top results drifting up without a matching quality change, that is a flag the firewall exists to raise — the point being to catch the tilt in the machinery, not to wait for a seller to complain.

How it works

  • Locate the leak points. Identify exactly which data flows and which decisions (ranking, defaults, interconnection priority) could be used to favour the affiliate — the specific power the controller can actually exercise.
  • Draw the internal boundary. Separate the access-operating arm from the downstream arm across those channels: distinct teams, access-controlled data, decision rules the competing arm cannot reach.
  • Instrument the wall. Log data access and record the outputs (rankings, allocations) so favouritism becomes measurable rather than merely alleged.
  • Monitor for breach. Audit outcomes and access trails on a cadence, because an internal wall leaks quietly and only surveillance keeps it real.

Tuning parameters

  • Wall height — informational only (data separation) versus operational (separate staff, systems, reporting lines). Higher walls block more leakage but sacrifice the coordination that made integration valuable.
  • Data granularity allowed across — from raw individual-rival data (porous) to aggregate-only (tight). Aggregation preserves useful analytics while denying the rival-specific detail that enables targeted self-preferencing.
  • Monitoring intensity — periodic spot-audits versus continuous outcome surveillance. More intensity catches subtler tilts but costs more and demands access to sensitive internals.
  • Enforcement teeth — whether a detected breach triggers a warning, a penalty, or escalation toward structural separation. Weak teeth make the wall decorative; strong teeth make integration itself precarious.

When it helps, and when it misleads

Its strength is proportionality: where full separation would destroy real efficiencies of an integrated firm, a firewall neutralizes the specific self-preferencing channels while leaving the rest intact. It is the natural fit when the controller's integration is genuinely useful and the harm runs through a few identifiable conduits.

Its weakness is intrinsic to being a conduct remedy rather than a structural one: the incentive to self-preference is untouched — only the visible channels are blocked — so the firm keeps probing for gaps the wall doesn't cover, and enforcement depends on continuous, well-resourced monitoring that regulators struggle to sustain.[1] Walls are porous by default; informal contact, shared leadership, and clever proxies route around them. And the firewall is easily run as reassurance theatre — announced loudly, audited weakly, breached quietly. The discipline is to instrument the wall so breaches are detectable, tie penalties to detected favouritism, and treat persistent leakage as the trigger to escalate to structural separation rather than patching the same wall forever.

How it implements the components

  • control_locus_and_power_boundary — the firewall is the internal boundary: it pins down which data and decisions the bottleneck-operating arm may touch and walls off the rest from the competing arm.
  • abuse_and_exclusion_monitor — the audit of rankings, allocations, and access logs is the standing monitor that detects self-preferencing and exclusion where the wall leaks.

It enforces the anti-self-preferencing norm but does not author the non-discrimination rule itself — that is stated by the Non-Discrimination Access Tariff — and it deliberately stops short of breaking the firm apart, which is Structural Separation or Unbundling.

Notes

The firewall and structural separation are the same intervention at two intensities: the firewall governs the information-and-decision channel and leaves ownership intact; separation removes the incentive by removing common ownership. Reach for the firewall first when integration is valuable and the leak points are few and observable; treat repeated, un-fixable breaches as evidence the lighter remedy has failed.

References

[1] The standard antitrust distinction between structural remedies (which change who owns what) and conduct or behavioural remedies (which police how a firm behaves): conduct remedies leave the incentive to abuse intact and therefore require ongoing monitoring and are more easily evaded — the core reason a firewall demands instrumentation and an escalation path.