When Security Becomes a Defence: The Liability-Remedy Divide under Section 4 of Competition Act 2002
- Varuni Savanur, Pratyaksh Jain
- 2 days ago
- 6 min read
[Varuni and Pratyaksh are students at Maharashtra National Law University, Mumbai, and West Bengal National University of Juridical Sciences, respectively.]
The dispute between Apple and the Competition Commission of India (CCI) is regularly characterised as an argument over commission. Such characterisation is inadequate. The pricing disagreement aside, there is a much harder Section 4 question in cases where a dominant platform relies on the need to maintain security while engaging in exclusionary conduct: can such justification be relied upon to absolve liability, lessen the penalty, or merely influence the remedy? Indian competition law has never addressed such a problem.
The Gap Under Section 4
Section 4 of the Competition Act 2002 offers no general efficiency or objective-justification defence. Beyond the vague "meeting competition" clause in Section 4(2)(a), the statute is silent as to when a dominant enterprise could justify conduct which would otherwise deny market access or exclude competitors.
Precedents in India have been inconsistent, not incremental. In CCI v. Fast Way Transmission (Fast Way), the Supreme Court of India affirmed a finding that dominant cable companies denied market access in violation of Section 4(2)(c) but refused to levy any penalty because the act of denial was "otherwise justifiable." The problem here is that justifications were made after liability determination and as part of penalty imposition. In the 2019 Intel case investigation conducted by the CCI, the same issue arose again in a case where there was no clear indication of whether the CCI was really trying to determine liability, penalty, or remedy. In the Google Android investigation, this has never even come into question.
Under Indian law, there is no guidance for a leading digital platform on whether a security-based justification bars an abuse conclusion or can only be considered once abuse has been established. The issue is not that Indian law evolves incrementally. An incremental approach provides a sense of direction, since later cases would take their cues from earlier ones. In this case, however, the three cases do not evolve into one another; they stand at separate points in the analysis of whether abuse exists, and none helps the next platform ascertain which point applies to it. That uncertainty carries practical consequences, as a company implementing a restriction today cannot foresee how the law will treat its justification as a defence or otherwise. It carries costs for the CCI as well, since similar justifications could be treated differently simply because of the bench and which case happens to raise them.
The Fast Way defence admitted the underlying facts and pleaded only for a lighter punishment. This is not what Apple is doing here. The position of Apple does not seem to be that developers have an equally good route to reaching iPhone customers. It does not look like the Directorate General's conclusions on foreclosure, issued in July 2024, are in any way disputed on these grounds. Apple's argument is that the challenged conditions are necessary to prevent security threats.
According to Fast Way, a justification may remain relevant even after an abuse is established. Apple asks a different question: whether security can prevent an abuse from occurring in the first place. A justification, which is considered after liability, may mitigate the penalty imposed, but cannot help a company in deciding how it should act before the decision, since the company can learn whether its justification was successful only after being found liable. In contrast, a justification, which may be relevant at the liability stage, would operate oppositely: it would instruct the company on which restriction would be recognised as legal before any action is taken. Fast Way responds to the first question. It remains silent about the second one.
What India Should Borrow
India does not have to blindly copy the EU or US doctrine. But there are valuable insights to consider from both systems. There is an important one from the EU, once the anticompetitive effect is established, the burden of proving necessity and proportionality shifts to the dominant enterprise. Not even the EU's codified test of strict necessity and proportionality of measures under the Digital Markets Act 2022 (DMA) could save Apple. Apple's anti-steering rules failed that test twice over: the European Commission fined Apple Euro 1.84 billion in 2024 under ordinary EU competition law for anti-steering rules found neither necessary nor proportionate, and then fined Apple a further Euro 500 million in 2025 for breaching the DMA's own codified necessity and proportionality standard for the very same conduct, deemed unnecessary for security reasons. This approach would work well for India too. The CCI will face the same problem of informational asymmetry that the European Commission faced: only the firm itself knows its own technical structure.
There is a second insight from the US in Epic Games Inc. v. Apple Inc. (Epic): the necessity test must remain fact-sensitive and revisable, not settled once and for all. For the time being, Apple's defence in the initial 2021 case succeeded in part because Epic failed to show that a less restrictive option was available. In 2025, the defence became unsustainable because Apple's actual practice had by then been shown to be a mere pretence. Once accepted, a defence should not confer immunity from further action if it turns out that the company has actually employed stricter measures than those it had earlier justified.
Neither legislation justifies indiscriminate borrowing. The 2023 judgment of the National Company Law Appellate Tribunal in the Google appeal censures the CCI for its uncritical borrowing of EU law concepts, such as "gatekeeper," that lack any statutory basis. Apple could have made this criticism against the CCI in its defence.
A Framework For Security Justifications
Rather than treating security as an all-or-nothing defence, the CCI should ask four questions of any restriction a dominant platform defends on security grounds.
First, is the threat particular and concrete, or just hypothetical? If this question is not asked, merely claiming a security threat would be enough, allowing any dominant firm to rely on vague security concerns to justify its conduct.
Secondly, is the restriction imposed by the firm a response to that specific threat of harm, and not something else? While the firm can certainly have legitimate security concerns, it can still implement a restriction that goes beyond addressing them.
Thirdly, is there some less restrictive measure that can provide equivalent protection from that threat? This is the very question raised in Epic and omitting it from the framework effectively decides the most frequently litigated form of this dispute.
Finally, does the restriction leave as much space for competition as possible while ensuring the achievement of the security objective?
This burden must be on the platform's shoulders on each issue, since this platform alone has the technical evidence to back up its claims. And the defence, even if successful, applies only to the restriction being defended, not to the entire business model surrounding it. This is possible in the case of Apple, where it could prove that its developer verification requirement is necessary, but could fail to do so with respect to its ban on external payment links.
The strongest response is that closure is intrinsic to the product. Customers buy an iPhone because Apple manages the App Store, reviews applications, and restricts other ways to access the iPhone. This objection carries real force: competition law must not require a product to be redesigned just because a competitor wants a different design.
However, the objection fails to grasp how the framework works. None of the four questions considers whether the iPhone should exist in its current closed version. Instead, each question considers whether a specific restraint is required to fulfil the purpose identified by Apple itself. The obligation imposed on Apple to allow a certified third-party payment processing company does not mean that Apple has to stop reviewing applications. It is sufficient to demonstrate that one specific restraint is essential to reach the goal set by Apple. Checking the necessity of a specific restraint is much less demanding than redesigning a product.
Conclusion
The inquiry against Apple will finally come to a conclusion one day. However, the dilemma that the inquiry has brought to light will remain unresolved. This question of legality will crop up again in cases related to app stores, AI infrastructure, cloud computing, payments platforms, and many other digital chokepoints, since the vocabulary of security exists and is yet to be tested against Indian competition law. Until Section 4 tells us where we can fit these justifications, every future case will simply rely on intuition. What makes the Apple inquiry significant is the location in which it places security under Section 4.
Comments