Review public-sector requests under Data Act Chapter V before exporting data: identify the exceptional need, check the requester, narrow the dataset, protect personal data and trade secrets, and record the response.
Based on Regulation (EU) 2023/2854, the Commission Data Act explainer, and Commission Data Act FAQs. Use it as implementation support, not for legal interpretation.
Chapter V of the EU Data Act lets public sector bodies, the Commission, the European Central Bank, and Union bodies request data from data holders only where an exists. The route is narrow: the request must be written, justified, proportionate, purpose-limited, protective of confidentiality and trade secrets, and closed with deletion or onward-sharing records.
1
Section 1
When a Chapter V exceptional-need request can be used
A Data Act B2G request starts with Article 14: the requester must demonstrate an for certain data, including metadata needed to interpret and use it, to carry out statutory duties in the public interest. The data holder must be a legal person other than a and must hold the requested data.
Article 15 limits to two routes. The first is data necessary to respond to a when the requester cannot obtain it by alternative means in a timely and effective way under equivalent conditions. The second is a non-emergency route for only, where a legally assigned public-interest task cannot be fulfilled without specific data and the requester has exhausted other means, including market purchase where available. That non-emergency route does not apply to microenterprises or small enterprises.
A must be an officially determined or declared exceptional situation that is limited in time and risks serious, lasting effects on living conditions, stability, or economic assets. Article 2 examples include a public-health emergency, a natural disaster, a human-induced major disaster, and a major cybersecurity incident; an event label alone does not satisfy the Article 15 necessity and alternative-means test.
Classify the request as public-emergency response or non-emergency before scoping data.
For non-emergency requests, check that the requested data is non-personal and that the requester explains the legal public-interest task.
Treat mitigation or recovery from a as a non-emergency Article 15(1)(b) case unless the request is for direct emergency response.
Do not direct a non-emergency Article 15(1)(b) request to a microenterprise or small enterprise.
Do not treat Chapter V as a general procurement shortcut, open-data route, audit power, or investigative authority.
Chapter V does not replace reporting duties, access-to-information rules, or powers used to demonstrate or verify compliance under other Union or national law. A requester should use the legal route that actually grants the power instead of relabelling an existing obligation as .
Chapter V also does not apply when public bodies, the Commission, the European Central Bank, or Union bodies act to prevent, investigate, detect, or prosecute criminal or administrative offences, execute criminal penalties, or administer customs or taxation. Those activities remain governed by their own Union and national laws.
Identify the statutory task and confirm whether another reporting, audit, investigative, customs, taxation, or access-to-information power controls the request.
Return a request for clarification when the stated purpose mixes Chapter V with a separate enforcement power.
Keep the Chapter V analysis limited to the public-interest task and exceptional-need facts stated in the request.
Article 17 makes the request itself the control point. It must identify the data required, the metadata needed to interpret it, the , the purpose and intended use, the expected duration of use, the data holder chosen, any onward recipients, the legal provision assigning the public task, and the deadlines for both delivery and any decline or modification response.
The request must be written in clear, concise, plain language. It must be specific about data type, correspond to data the holder controls at the time of the request, and be proportionate in granularity, volume, and frequency. It must also address trade secrets, cost and effort, penalties for non-compliance, publication by the relevant data coordinator or EU body, and supervisory-authority notice where personal data is requested.
For a request directed to a data holder established in another Member State, Article 22 requires the requester to notify the competent authority in that Member State first. That authority examines the request and either transmits it to the data holder, with coordination advice where needed, or rejects it on substantiated Chapter V grounds.
Require requester identity, authority, public-interest task, purpose, requested data fields, metadata, period, and deadline.
Ask for the Article 15 facts that justify , not just a reference to the Data Act.
Check whether onward sharing with another body, researcher, statistical body, or third party is named in the request.
For a cross-border request, keep the prior notification, the establishment-state authority's examination, and its transmission, advice, or rejection.
Record whether the request was or should be made publicly available, unless publication would create a public-security risk.
For response, the request should seek first. Personal data may be requested only if non-personal data is shown to be insufficient for the emergency need, and the request must specify necessary and proportionate technical and organisational measures, including pseudonymisation and whether anonymisation can be applied before disclosure.
For non-emergency , Chapter V is limited to . The request should therefore be narrowed to the specific data and metadata needed for the public-interest task, with unsuitable fields removed before extraction.
Separate non-personal, anonymised, pseudonymised, and personal data before delivery approval.
For emergency personal-data requests, document why is insufficient and whether anonymisation is possible.
For non-emergency requests, decline or seek modification if the request includes personal data.
Record source systems, fields, time range, format, metadata, transformations, exclusions, and unavailable data.
How data holders can comply, decline, or seek modification
Article 18 requires the data holder to make data available without undue delay, taking account of technical, organisational, and legal measures. It also gives a controlled route to decline or seek modification where the holder does not control the data, a similar same-purpose request is already outstanding without erasure notice, or the request does not meet Article 17 requirements.
The response window is shorter for public emergencies: a decline or modification request must be made without undue delay and no later than five working days after receipt. For other exceptional-need requests, the outer limit is 30 working days. If the matter cannot be resolved by modification, either side may refer it to the competent authority in the Member State where the data holder is established.
Answer with delivery, narrowing questions, modification request, refusal, or competent-authority escalation.
Use the five-working-day outer limit for emergency decline or modification decisions.
Use the 30-working-day outer limit for other exceptional-need decline or modification decisions.
If relying on a previous same-purpose request, identify the earlier requester and keep the missing erasure notice in the file.
Confidentiality, trade secrets, and use restrictions
Data received under Chapter V does not become open public-sector information. Article 17 bars reuse under the Data Governance Act and Open Data Directive frameworks, and Article 19 limits use to the purpose stated in the request. The receiving body must protect confidentiality, integrity, transfer security, personal data rights, and trade secrets.
Trade secrets may be disclosed only to the extent strictly necessary for the Article 15 purpose. The data holder or trade secret holder should identify protected data, including relevant metadata. Before disclosure, the public body or EU body must take necessary and appropriate technical and organisational measures to preserve confidentiality.
Mark trade-secret fields and confidentiality restrictions before transfer.
Require transfer-security, access-control, confidentiality, and deletion terms in the delivery note.
Do not allow the recipient to use data or insights to develop or improve a competing connected product or related service.
Do not treat Chapter V data as open-data material unless another lawful route independently applies.
Compensation rules and cost records for B2G disclosures
For response, Article 20 requires data holders other than microenterprises and small enterprises to provide the necessary data free of charge, with public acknowledgement if requested. A microenterprise or small enterprise responding to an emergency request may claim fair compensation under the Article 20(2) calculation: technical and organisational costs, including specified transformation costs, plus a reasonable margin.
For non-emergency exceptional-need requests under Article 15(1)(b), the data holder is entitled to the same fair-compensation calculation. However, Article 15(2) excludes microenterprises and small enterprises from that non-emergency request route. No compensation is due for an official-statistics task where national law does not allow purchase of the data.
Classify the request before discussing compensation because emergency and non-emergency rules differ.
Keep a cost basis for extraction, security, transformation, anonymisation, pseudonymisation, aggregation, and technical adaptation.
Record whether the data holder is a microenterprise or small enterprise.
Escalate disputes about compensation to the competent authority where the data holder is established.
This guide helps structure intake, legal review, data scoping, safeguard terms, delivery or refusal records, compensation notes, and deletion evidence for Data Act B2G requests.
The response file should close the loop. Article 19 requires the public body or EU body to erase data once it is no longer necessary for the stated purpose and to inform the data holder and onward recipients without undue delay, unless archiving is required under public-access-to-documents law.
Onward sharing is possible only within Chapter V limits. Article 21 allows sharing for compatible scientific research or analytics, or with national statistical institutes and Eurostat for official statistics. The data holder must be notified of onward sharing, including recipient identity, purpose, use period, and protection measures. Research or statistical recipients must follow the same core obligations and may keep the data for up to six months after the original recipient erases it.
Keep the original request, legal task, exceptional-need classification, data scope, and requester correspondence.