Technology · Digital regulation
US tech firms wrote EU confidentiality clause shielding datacentre emissions from public view
Microsoft and industry groups secured a near-verbatim secrecy provision in EU rules that blocks access to individual datacentre environmental data, prompting legal warnings of Aarhus convention violations.
A confidentiality clause written almost verbatim by Microsoft and European tech lobby groups has been adopted into EU regulation, shielding the environmental footprint of individual datacentres from public scrutiny. The provision, inserted into the European Commission's delegated act on datacentre sustainability reporting in 2024, obliges the Commission and member states to keep all key performance indicators for specific facilities confidential on commercial grounds.
Documents obtained by Investigate Europe, a cross-border journalism cooperative working with the Guardian and other media partners, reveal that the final legal text differs by only a handful of words from the language submitted by Microsoft, DigitalEurope and Video Games Europe during a public consultation in January 2024. The clause states that the Commission and member states "shall keep confidential all information and key performance indicators for individual datacentres that are communicated to the database" and that such information "shall be considered confidential information affecting the commercial interests of operators and owners of datacentres."
How the clause emerged from industry lobbying
The chain of events begins with the 2023 revision of the EU's energy efficiency directive, which introduced a requirement for datacentre operators to report key performance indicators on energy consumption, water usage and carbon emissions. The Commission's subsequent guidance proposed publishing aggregated environmental metrics to increase transparency. But when the executive opened a public consultation on the implementing rules in January 2024, industry submissions pushed for a blanket confidentiality designation.
Microsoft argued that disclosing facility-level data would reveal commercially sensitive details about infrastructure design, capacity and operational efficiency. DigitalEurope, whose membership includes Google, Amazon and Meta alongside Microsoft, echoed the demand. Video Games Europe, representing companies including Microsoft and Netflix, added its weight. The Commission's final delegated act, adopted later in 2024, incorporated the industry wording with minimal alteration.
A Commission email sent to national authorities last year, citing the new clause, reminded them of their obligation to "keep confidential all information and key performance indicators for individual datacentres." The official noted that the Commission had already received multiple access-to-documents requests from journalists and the public, all of which had been refused.
Legal experts warn of Aarhus convention breach
The Aarhus convention, to which the EU and all member states are parties, guarantees public access to environmental information held by public authorities. It requires that such information be made available systematically and proactively, with refusals limited to narrowly defined exceptions. The convention's compliance committee, which oversees implementation, has consistently ruled that commercial confidentiality cannot serve as a blanket shield for environmental data.
Prof Jerzy Jendrośka, who spent 19 years on that committee and teaches environmental law at the University of Opole in Poland, said: "In two decades, I cannot recall a comparable case. This clearly seems not to be in line with the convention." Luc Lavrysen, emeritus professor at Ghent University and former president of the Belgian constitutional court, reached the same conclusion, stating the clause "is clearly in violation" of both EU transparency rules and the Aarhus convention. Kristina Irion, associate professor of information law at the University of Amsterdam, argued the "sweeping presumption of confidentiality" incorrectly privileges corporate interests and that any protection should be determined case by case.
Datacentre boom outpaces transparency
The secrecy provision arrives as the EU pursues an aggressive expansion of datacentre capacity. The Commission has set a target to triple the bloc's datacentre footprint within five to seven years, positioning Europe as a global leader in artificial intelligence. The United States and China have led the AI infrastructure race to date, but European construction is accelerating. Chip-filled facilities consume vast quantities of electricity, a growing share of which is met by fossil gas generation, undermining the bloc's climate commitments.
Researchers attempting to quantify the environmental impact of this build-out have long relied on fragmented, aggregated data. Alex de Vries-Gao of Vrije Universiteit Amsterdam said public information is "extremely limited" and that he has had to "bend over backward to come up with any numbers." The new database was meant to change that. Instead, the confidentiality clause locks facility-level data behind a commercial-interest exemption that cannot be pierced even by freedom-of-information requests.
Compliance already low before secrecy clause
The Commission's internal justification for the clause, according to sources close to the process, is that mandatory public disclosure would discourage operators from reporting at all. Yet EU data shows that only 36% of eligible datacentres have complied with the existing reporting requirements introduced in 2023. The low uptake suggests the confidentiality guarantee has not secured the cooperation the Commission anticipated.
Ben Youriev of InfluenceMap, a non-profit that tracks corporate climate lobbying, described the episode as illustrative of a broader shift. "Where the industry was previously outspoken in its support for clean energy and emissions reductions, many firms have since fallen silent," he said. "Instead, they appear to be prioritising the rapid build-out of datacentre infrastructure globally over supporting clean energy and rapid emissions reductions."
Microsoft responds while Commission plans next phase
Microsoft told Investigate Europe that it "supports greater transparency around datacenters as sustainability disclosures can help drive better outcomes and build public trust," adding that it is "taking further steps to increase openness, while protecting confidential business information." DigitalEurope did not respond to requests for comment. The Commission and Video Games Europe declined to comment on the record.
The executive regards the current regulation as a first step toward a common EU rating scheme for datacentres. A second phase, for which public consultation closes this month, would publish sustainability scores drawn from the database to "make it easier to compare different datacentres in a same region and promote new designs or appropriate efficiency." Under the current proposals, however, the majority of what operators report would remain confidential, leaving the scoring methodology opaque.
What the clause conceals
The withheld indicators include power usage effectiveness (PUE), water usage effectiveness (WUE), carbon usage effectiveness (CUE), renewable energy factor, and total energy consumption per facility. At national level, only aggregated summaries will be published, making it impossible to identify which operators or locations are performing well or poorly. Researchers, local authorities and communities living near new facilities lose the ability to assess local air quality impacts, water stress or grid constraints.
The practical effect is already visible. In Ireland, where datacentres accounted for 21% of metered electricity consumption in 2023 according to the Central Statistics Office, planning objections have cited the absence of facility-level emissions data. In the Netherlands, a moratorium on new hyperscale datacentres in the Amsterdam region was partly driven by uncertainty over cumulative environmental impact. The EU database was designed to resolve such information gaps; the confidentiality clause preserves them.
The Commission's willingness to adopt industry language wholesale raises questions about the independence of EU rule-making in the digital sector. When the same companies that stand to benefit from secrecy draft the legal text that guarantees it, the regulatory process ceases to mediate between competing interests and instead ratifies the preference of the best-resourced lobbyists. The datacentre confidentiality clause may be the clearest example yet of that dynamic in action.
For now, the database exists but the public cannot see inside it. The Commission's next move, whether to open the data or entrench the secrecy, will signal whether the EU's digital ambition is matched by its commitment to environmental accountability.
Sources
People mentioned
Jerzy Jendrośka
Luc Lavrysen
Alex de Vries-Gao
Ben Youriev
Organisations
European Commission · Microsoft · DigitalEurope · Video Games Europe · Investigate Europe · Aarhus Convention