Comparison GuideEU data sharing lawData Act and DGA
EU Data Act vs Data Governance Act Access rights vs trusted sharing frameworks
Separate mandatory Data Act access, contract, B2G, and cloud-switching duties from Data Governance Act rules for protected public-sector data reuse, neutral data intermediation, and data altruism.
Use the legal trigger and actor role to choose the correct workstream. A project can fall under both regulations, and GDPR, sector law, intellectual-property rights, trade-secret rules, and national access law may still control parts of the same data flow.
Use the Data Act when the issue is a right or duty to access, use, or share covered data, an unfair data-sharing term, an exceptional-need public-sector request, cloud switching, or interoperability. Use the when the issue is reuse of protected data held by a public-sector body, operation of a , recognised data altruism, or the supporting registers and authorities. The Data Act has applied generally since 12 September 2025; its Article 3(1) access-by-design duty applies to connected products and related services placed on the market after 12 September 2026. The Data Governance Act has applied since 24 September 2023. Neither regulation creates ownership of data, requires every dataset to be shared, or displaces GDPR or other applicable sector, confidentiality, intellectual-property, competition, or national-security law.
Side-by-side comparison
EU Data Act vs Data Governance Act: what changes in practice
This matrix helps decide whether the work is a Data Act access, contract, B2G, or cloud-switching obligation, a reuse, intermediary, or altruism governance issue, or both.
Mandatory rights and obligations for access to and use of data, especially connected-product data, third-party sharing, B2B fairness, B2G exceptional need, cloud switching, and interoperability.
Second framework
Data Governance Act
Trust and governance framework for reuse, neutral data intermediation, data altruism, single information points, registers, and EDIB coordination.
EU Data Act vs Data Governance Act: what changes in practice
Covers fair access to and use of data, including connected products and related services, user and third-party access, B2B data-sharing terms, B2G exceptional-need requests, switching between data processing services, and interoperability for data spaces and smart contracts.
Chapter II covers public-sector data protected by commercial or statistical confidentiality, third-party intellectual-property rights, or personal-data rules where that data falls outside the Open Data Directive. Other chapters govern data intermediation services, recognised data altruism organisations, single information points, registers, and EDIB.
Use Data Act controls when a covered product, related service, contract, public-sector request, cloud service, or interoperability duty drives the work. Use DGA controls when the issue is protected public-sector reuse, neutral intermediation, altruistic data sharing, or DGA governance infrastructure.
Key roles include users, data holders, data recipients, third parties, manufacturers, related-service providers, public-sector bodies, Union bodies, providers of data processing services, competent authorities, data coordinators, and EDIB for consistent application.
Key roles include public-sector bodies, reusers, providers, recognised data altruism organisations, data holders, data users, competent authorities for intermediation and altruism, the Commission, and EDIB.
Create two role maps when a project touches both regimes. The same organisation can be a Data Act data holder, a DGA data holder, a reuser, a cloud customer, or an intermediary participant depending on the exact service and dataset.
Creates duties around making product and related-service data accessible, sharing with users or third parties under conditions, protecting trade secrets proportionately, preventing unfair B2B terms, responding to valid B2G requests, enabling data processing service switching, and meeting interoperability requirements.
Creates governance conditions for reuse, neutrality and structural separation for data intermediaries, notification to competent authorities, recognised labels and registers, not-for-profit and safeguard expectations for data altruism, and common consent-form support.
Do not merge the obligation lists. Data Act work usually changes product, API, contract, support, procurement, or cloud-exit operations. DGA work usually changes reuse conditions, intermediary structure, transparency, registration, consent, or public-sector metadata operations.
Does not create the DGA intermediary or altruism model. It can still affect reuse projects where connected-product data, B2B access terms, public-sector exceptional-need requests, data-space interoperability, or cloud-switching rights are part of the same project.
Sets conditions for reuse of covered but does not itself require a public-sector body to permit reuse. It also regulates covered data intermediation services and provides a voluntary recognition framework for eligible not-for-profit data altruism organisations.
For , identify the Union or national rule under which the body may or must permit reuse before applying DGA safeguards. For a marketplace, data trust, or data donation project, confirm that the service meets the DGA definition before treating notification or recognition as applicable.
Keep the Data Act source article or chapter, product or service facts, data category, access request or delivery record, recipient terms, trade-secret safeguards, contract review, B2G request file, switching plan, interoperability note, complaint record, or authority correspondence.
Keep the DGA basis, protected-data category, reuse decision, secure-processing or confidentiality safeguards, intermediary notification and neutrality evidence, altruism transparency and consent materials, register entry, single-information-point metadata, and competent-authority correspondence.
A combined EU data-sharing file should contain two labeled evidence indexes. One proves Data Act access, contract, B2G, switching, or interoperability handling; the other proves DGA reuse, intermediation, altruism, register, or EDIB-related governance handling.
The Data Act has applied generally since 12 September 2025. Article 3(1), which requires covered product and related-service data to be readily accessible by design, applies to connected products and related services placed on the market after 12 September 2026. Separate transitional rules apply to Chapter III and Chapter IV contracts.
The DGA has applied since 24 September 2023. A public-sector body must decide a reuse request within two months, subject to a possible extension of up to 30 days for exceptionally extensive and complex requests. A data intermediation provider must notify the competent authority before starting a covered service.
Record the relevant product placement date, contract date, reuse-request date, or proposed intermediation start date. Do not treat the general application date as the deadline for every duty.
Member States designate competent authorities and, where relevant, data coordinators. The Data Act includes complaint rights, judicial remedies, information requests, cooperation between authorities, and Member State penalty rules that must be effective, proportionate, and dissuasive.
DGA supervision depends on the activity: competent authorities monitor data intermediation services and recognised data altruism organisations, while public-sector bodies and competent bodies administer protected-data reuse. Member States set effective, proportionate, and dissuasive penalties for specified infringements.
Escalate through the route for the activity at issue. Neither regulation supplies one EU-wide fine table; verify the applicable Member State penalty rules.
Choose the Data Act analysis when the next action is to give or refuse access, provide data to a third party, protect trade secrets, review a B2B term, answer an exceptional-need public-sector request, switch a data processing service, or meet interoperability duties.
Choose the DGA analysis when the next action is to permit reuse, run a neutral , register or operate a data altruism organisation, prepare single-information-point metadata, or rely on DGA governance structures.
If the answer affects product design, access delivery, cloud exit, or contract terms, Data Act owners should lead. If the answer affects reuse safeguards, intermediation neutrality, altruism safeguards, registers, or information points, DGA owners should lead. If both are true, keep two cited conclusions.
The Data Act includes interoperability requirements for common European data spaces and support from EDIB on standards, common specifications, smart contracts, and data processing service interoperability.
The DGA created EDIB to share best practices on data intermediation, data altruism, use, and prioritisation of cross-sectoral interoperability standards.
For a common European data space, distinguish technical interoperability and access duties from the governance trust model. EDIB appears in both laws, but its role does not collapse Data Act access rights and DGA trust structures into one obligation.
Covers fair access to and use of data, including connected products and related services, user and third-party access, B2B data-sharing terms, B2G exceptional-need requests, switching between data processing services, and interoperability for data spaces and smart contracts.
Data Governance Act
Chapter II covers public-sector data protected by commercial or statistical confidentiality, third-party intellectual-property rights, or personal-data rules where that data falls outside the Open Data Directive. Other chapters govern data intermediation services, recognised data altruism organisations, single information points, registers, and EDIB.
Operational implication
Use Data Act controls when a covered product, related service, contract, public-sector request, cloud service, or interoperability duty drives the work. Use DGA controls when the issue is protected public-sector reuse, neutral intermediation, altruistic data sharing, or DGA governance infrastructure.
Key roles include users, data holders, data recipients, third parties, manufacturers, related-service providers, public-sector bodies, Union bodies, providers of data processing services, competent authorities, data coordinators, and EDIB for consistent application.
Data Governance Act
Key roles include public-sector bodies, reusers, providers, recognised data altruism organisations, data holders, data users, competent authorities for intermediation and altruism, the Commission, and EDIB.
Operational implication
Create two role maps when a project touches both regimes. The same organisation can be a Data Act data holder, a DGA data holder, a reuser, a cloud customer, or an intermediary participant depending on the exact service and dataset.
Creates duties around making product and related-service data accessible, sharing with users or third parties under conditions, protecting trade secrets proportionately, preventing unfair B2B terms, responding to valid B2G requests, enabling data processing service switching, and meeting interoperability requirements.
Data Governance Act
Creates governance conditions for reuse, neutrality and structural separation for data intermediaries, notification to competent authorities, recognised labels and registers, not-for-profit and safeguard expectations for data altruism, and common consent-form support.
Operational implication
Do not merge the obligation lists. Data Act work usually changes product, API, contract, support, procurement, or cloud-exit operations. DGA work usually changes reuse conditions, intermediary structure, transparency, registration, consent, or public-sector metadata operations.
Does not create the DGA intermediary or altruism model. It can still affect reuse projects where connected-product data, B2B access terms, public-sector exceptional-need requests, data-space interoperability, or cloud-switching rights are part of the same project.
Data Governance Act
Sets conditions for reuse of covered but does not itself require a public-sector body to permit reuse. It also regulates covered data intermediation services and provides a voluntary recognition framework for eligible not-for-profit data altruism organisations.
Operational implication
For , identify the Union or national rule under which the body may or must permit reuse before applying DGA safeguards. For a marketplace, data trust, or data donation project, confirm that the service meets the DGA definition before treating notification or recognition as applicable.
Keep the Data Act source article or chapter, product or service facts, data category, access request or delivery record, recipient terms, trade-secret safeguards, contract review, B2G request file, switching plan, interoperability note, complaint record, or authority correspondence.
Data Governance Act
Keep the DGA basis, protected-data category, reuse decision, secure-processing or confidentiality safeguards, intermediary notification and neutrality evidence, altruism transparency and consent materials, register entry, single-information-point metadata, and competent-authority correspondence.
Operational implication
A combined EU data-sharing file should contain two labeled evidence indexes. One proves Data Act access, contract, B2G, switching, or interoperability handling; the other proves DGA reuse, intermediation, altruism, register, or EDIB-related governance handling.
The Data Act has applied generally since 12 September 2025. Article 3(1), which requires covered product and related-service data to be readily accessible by design, applies to connected products and related services placed on the market after 12 September 2026. Separate transitional rules apply to Chapter III and Chapter IV contracts.
Data Governance Act
The DGA has applied since 24 September 2023. A public-sector body must decide a reuse request within two months, subject to a possible extension of up to 30 days for exceptionally extensive and complex requests. A data intermediation provider must notify the competent authority before starting a covered service.
Operational implication
Record the relevant product placement date, contract date, reuse-request date, or proposed intermediation start date. Do not treat the general application date as the deadline for every duty.
Member States designate competent authorities and, where relevant, data coordinators. The Data Act includes complaint rights, judicial remedies, information requests, cooperation between authorities, and Member State penalty rules that must be effective, proportionate, and dissuasive.
Data Governance Act
DGA supervision depends on the activity: competent authorities monitor data intermediation services and recognised data altruism organisations, while public-sector bodies and competent bodies administer protected-data reuse. Member States set effective, proportionate, and dissuasive penalties for specified infringements.
Operational implication
Escalate through the route for the activity at issue. Neither regulation supplies one EU-wide fine table; verify the applicable Member State penalty rules.
Choose the Data Act analysis when the next action is to give or refuse access, provide data to a third party, protect trade secrets, review a B2B term, answer an exceptional-need public-sector request, switch a data processing service, or meet interoperability duties.
Data Governance Act
Choose the DGA analysis when the next action is to permit reuse, run a neutral , register or operate a data altruism organisation, prepare single-information-point metadata, or rely on DGA governance structures.
Operational implication
If the answer affects product design, access delivery, cloud exit, or contract terms, Data Act owners should lead. If the answer affects reuse safeguards, intermediation neutrality, altruism safeguards, registers, or information points, DGA owners should lead. If both are true, keep two cited conclusions.
The Data Act includes interoperability requirements for common European data spaces and support from EDIB on standards, common specifications, smart contracts, and data processing service interoperability.
Data Governance Act
The DGA created EDIB to share best practices on data intermediation, data altruism, use, and prioritisation of cross-sectoral interoperability standards.
Operational implication
For a common European data space, distinguish technical interoperability and access duties from the governance trust model. EDIB appears in both laws, but its role does not collapse Data Act access rights and DGA trust structures into one obligation.
For connected-product data, identify the user, data holder, product placement date, requested data, recipient, and any trade-secret or GDPR limits.
For protected public-sector reuse, identify the Article 3 category, any exclusion, the legal basis for permitting reuse, the safeguards, and the two-month decision period.
For intermediation or altruism, confirm that the service meets the DGA definition before assigning notification, separation, recognition, transparency, or recordkeeping duties.
1
Section 1
Start with the legal trigger
A connected-device access request, a cloud exit, and a neutral data marketplace raise different compliance questions. The Data Act asks whether a user, data holder, third-party recipient, public-sector body, or data processing service provider has a specific access, use, contract, or switching obligation. The asks whether a protected public-sector reuse process, , or data altruism structure needs DGA safeguards.
A DGA reuse framework does not itself create a right to reuse . Member States decide whether that data is made accessible, subject to Union or national rules that may independently require access. Likewise, a DGA intermediary or altruism model does not create a Data Act right to product-generated data.
Use the Data Act path for connected-product data, related-service data, user and third-party access, B2B unfair terms, B2G exceptional-need requests, data processing service switching, and interoperability duties.
Use the path for reuse, data intermediation services, recognised data altruism organisations, national single information points, and DGA governance bodies.
Run both analyses only when the same project actually contains both fact patterns, such as a data space that also needs Data Act product-data access or cloud-switching terms.
Under the Data Act, the actor map usually starts with the user of a connected product or related service, the data holder, any third-party recipient, a product manufacturer or related-service provider, a public-sector requester, or a provider of data processing services. Under the , the actor map usually starts with the public-sector body holding protected data, the reuser, a provider, a recognised data altruism organisation, a competent authority, or the European Data Innovation Board.
Some names overlap, especially user, data holder, and competent authority. Do not assume the same organisation has the same legal role in both regimes; a company can be a Data Act data holder for connected-product data and separately use a DGA intermediary or participate in a data altruism project.
For Data Act work, record the product or service, the user, the data holder, the requested data, the recipient, the use purpose, trade-secret concerns, and any cloud or B2G context.
For DGA work, record whether the project is public-sector protected-data reuse, intermediation, altruism, or data-space governance, and identify the competent authority or register interaction.
Keep a separate role line where GDPR, sector law, trade-secret protection, public-sector confidentiality, or cloud-contract obligations affect the same dataset.
Separate access rights from sharing infrastructure
The Data Act can require covered products and services to be designed for access, data to be made available to users or eligible third parties, data to be supplied to public bodies in cases of exceptional need, and data processing services to support switching. The sets conditions for protected public-sector reuse, neutral intermediation, and recognised data altruism.
The required records and controls also differ. A Data Act project may need product data inventories, access interfaces, user notices, recipient terms, trade-secret safeguards, contract remediation, B2G request files, or switching documentation. A DGA project may need reuse conditions, secure processing arrangements, confidentiality terms, intermediary notification analysis, structural-separation controls, altruism registration materials, or single-information-point metadata.
Do not use a DGA data intermediary label to bypass Data Act access, trade-secret, or recipient checks for product-generated data.
Do not use Data Act language to overstate rights to ; the DGA reuse framework depends on safeguards and the underlying legal basis for reuse.
For data spaces, document both the Data Act interoperability or access issue and the DGA governance mechanism if both are present.
The evidence file should show which regime applies and why. For the Data Act, connect the data flow to a covered product, related service, data holder, recipient, contract term, public-sector request, or data processing service switching obligation. For the , connect it to , an intermediary service, an altruism organisation, or a single-information-point process.
Keep a short, cited record that product, legal, security, procurement, and data-governance teams can use to approve an access response, contract clause, reuse condition, intermediary model, or altruism workflow.
Data Act evidence: dataset inventory, access method, user instructions, recipient terms, trade-secret safeguards, refusal or suspension basis, compensation or contract review, B2G request record, and switching plan.
DGA evidence: protected-data category, reuse basis, public-sector decision record, secure processing or confidentiality conditions, intermediary notification and neutrality controls, altruism transparency safeguards, and register correspondence.
Shared evidence: GDPR assessment, sector-rule note, data-space participation terms, interoperability references, and competent-authority correspondence where those issues apply.
Turn this comparison into a working issue list for product data access, cloud switching, protected public-sector reuse, intermediary services, data altruism, and data-space participation.
The Data Act requires Member States to designate competent authorities, handle complaints, cooperate across borders, and set effective, proportionate, and dissuasive penalties. It also gives affected natural and legal persons complaint and judicial-remedy routes. The published source support used for this page does not provide a single EU-wide Data Act fine table, so this comparison should not state unsupported fixed penalty amounts.
The requires Member States to set penalties for specified infringements, including unlawful transfers of non-personal data to third countries, breaches of intermediation notification and operating conditions, and breaches by recognised data altruism organisations. Member States determine the rules, so there is no single EU-wide DGA fine table either. Identify the competent authority and national penalty rule for the activity.
Escalate Data Act disputes through the competent authority, complaint, judicial remedy, contract, or dispute-settlement route that matches the affected chapter.
Escalate DGA issues through the competent-authority, register, reuse-condition, intermediary-notification, or altruism-recognition process that matches the activity.
Avoid penalty thresholds or guaranteed outcomes unless the exact Member State rule and source are available.
Product and IoT teams should treat the Data Act as the primary source for user access, related-service data, third-party sharing, trade-secret handling, and access-by-design changes. Cloud, SaaS, and procurement teams should treat the Data Act as the primary source for switching, exportable data, contractual transparency, and international governmental access safeguards for non-personal data held in the Union.
Public-sector, research, data-space, and data-platform teams should use the when they are designing protected public-sector reuse, single information points, neutral intermediation, or altruistic data sharing. Where these projects also involve connected products, data processing services, or B2B data contracts, add a separate Data Act workstream instead of blending the regimes into one generic policy.
For connected products, ask what data the user can access, how it is delivered, whether a third party receives it, and what trade-secret safeguards are proportionate.
For cloud and data processing services, ask what switching, export, interface, transparency, charge, and functional-equivalence duties apply.
For public-sector and data-space projects, ask whether the activity is protected-data reuse, neutral intermediation, altruism, common European data-space participation, or a separate Data Act access case.
Supports the Data Act obligation list in plain language, including access, third-party sharing, trade secrets, unfair terms, B2G access, and switching.