FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
470of470items
Across 39 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
Data Act and Data Governance Act Overlap

What is the core difference between the Data Act and the Data Governance Act?

The Data Governance Act is mainly a governance framework for trusted data sharing. It covers reuse of certain protected data held by public sector bodies, rules for data intermediation services, and voluntary data altruism for objectives of general interest.

The Data Act is more direct about access and use. It gives users of connected products and related services access to data they generate, sets conditions for mandatory B2B data sharing, creates an exceptional-need route for public-sector requests to businesses, and regulates switching between data processing services such as cloud and edge services.

A useful routing question is: is the organisation asking how to make a trusted sharing mechanism available, or is someone asserting a Data Act access, sharing, request, contract, or switching right?

  • Use the Data Governance Act for protected public-sector reuse, neutral intermediation services, data altruism, and related registers or competent authorities.
  • Use the Data Act for connected-product data access, user-directed sharing to third parties, mandatory B2B sharing terms, exceptional-need B2G requests, and cloud switching.
  • Use both only when the same programme combines a DGA mechanism with a Data Act access, use, interoperability, or cloud obligation.
Citations
Data Act and Data Governance Act Overlap

Which actors belong to the Data Act regime and which belong to the Data Governance Act regime?

Data Act actor mapping usually starts with a user, data holder, data recipient, public sector body, or provider of data processing services. In connected-product cases, the user may be a consumer, business, or public sector body that owns, rents, leases, or receives a related service for the product.

Data Governance Act actor mapping is different. It focuses on public sector bodies holding protected data, potential reusers, data intermediation service providers, data holders and data users using those services, data altruism organisations, competent authorities, and registers.

The same organisation can appear in both maps. For example, a public authority may be a Data Act user of connected equipment in one workflow and a DGA public sector body making protected data available for reuse in another.

  • Start Data Act routing with user, data holder, data recipient, public-sector requester, customer, and data-processing-service provider roles.
  • Start DGA routing with public sector body, reuser, data intermediary, data altruism organisation, data holder, data user, competent authority, and register roles.
  • Do not assume that a company acting as a data holder under the Data Act is also a DGA intermediary; intermediary status depends on the specific DGA service model.
Citations
Data Act and Data Governance Act Overlap

How do the data-sharing mechanisms differ in practice under the Data Act?

The Data Act often starts from a legally recognised access or sharing route. A connected-product user can access certain raw and pre-processed data that is readily available to the data holder and can ask for it to be shared with a third party of the user's choice, subject to the Data Act limits.

The Data Governance Act does not create that connected-product access route. Its mechanisms are trust and reuse infrastructure: protected public-sector data can be reused under safeguards where other law allows reuse, intermediaries can organise data sharing under neutrality rules, and altruism organisations can collect voluntary data contributions for general-interest objectives.

If a request asks for sensor or related-service data generated by use of a connected product, start with the Data Act. If it asks to reuse protected public-sector data, register or operate a neutral data intermediary, or structure voluntary data altruism, start with the DGA.

  • Data Act product access: identify the connected product, related service, user, data holder, readily available data, third-party recipient, and any trade-secret or security limit.
  • DGA public-sector reuse: identify the public sector body, protected data category, legal basis for reuse, safeguard, fee approach, single information point, and reuser conditions.
  • DGA intermediation or altruism: identify whether the service is neutral intermediation or voluntary data contribution for general-interest purposes.
Citations
Data Act and Data Governance Act Overlap

What should teams record, who should own the choice, and when should they review a Data Act and DGA routing decision?

Under the Data Act, keep a short decision pack that shows why the team chose Data Act only, DGA only, or both. The pack should name the route, the trigger, the actors, the date, and the source URL used for the interpretation so a reviewer can recreate the decision later.

Assign one accountable owner who can change the affected workflow - usually legal, product, procurement, cloud, support, or security depending on the issue. Capture consulted teams separately so responsibility does not get blurred across functions.

Review the answer again when the product, service model, dataset, customer role, public-sector request path, or contract wording changes, or when a new source note or implementation issue creates a different boundary question.

  • Keep the official source URL, decision date, owner, affected workflow, and any follow-up evidence in one place.
  • Use one accountable owner per decision and list consulted teams separately.
  • Set a review trigger for product, service, dataset, role, or contract changes so the answer does not go stale.
Citations
Data Act and Data Governance Act Overlap

Does the Data Act change how a data intermediation service registered under the Data Governance Act operates?

A data intermediation service notified under the Data Governance Act still follows the DGA conditions for neutrality and separation. It can also provide the channel through which a connected-product user directs readily available data to a third party under the Data Act. The DGA governs the intermediation service; the Data Act governs the access and sharing right.

Keep the intermediary's role separate from the data holder's role. Operating the channel does not by itself make the intermediary the data holder, but the same group may carry both roles through different activities or entities.

  • Keep DGA intermediary neutrality duties separate from any Data Act third-party sharing the service handles.
  • Confirm whether the intermediary is acting only as a channel or has become a data holder with its own duties.
Citations
Data Act and Data Governance Act Overlap

How does a public sector body decide between a Data Act exceptional-need request and a Data Governance Act reuse route?

Under the Data Act, a public sector body uses the Chapter V exceptional-need route to require a business to provide data it cannot get otherwise, mainly in emergencies or to fulfil a specific legal task. The Data Governance Act route is different: it governs how protected data the body already holds can be made available for reuse under safeguards.

Direction of flow controls the route. A Data Act exceptional-need request pulls data into the public body from a business, while the DGA reuse route makes the body's protected data available to a reuser.

  • Use the Data Act Chapter V route when the body needs to obtain business data for an exceptional public task.
  • Use the DGA reuse route when the body is making its own protected data available to a reuser.
Citations
Data Act and Data Governance Act Overlap

Where do the Data Act and the Data Governance Act both apply to a single data space project?

Under the Data Act, a data space project can rely on DGA mechanisms for trusted intermediation and altruism while still being subject to Data Act access, use, and interoperability obligations where connected-product data or data processing services are involved. A mature data space often needs both regimes at once.

Teams should map each function of the project to the regime that governs it, so the interoperability and access duties from the Data Act are not assumed to be covered by the DGA governance layer alone.

  • Map each data space function to the Data Act or the DGA rather than assuming one covers the other.
  • Apply Data Act interoperability and access duties where connected-product data or cloud services are in scope.
Citations
Data Act and Data Governance Act Overlap

Do the Data Act and the Data Governance Act treat trade secrets and protected data the same way?

Under the Data Act, trade secrets are preserved through identification and proportionate safeguards before a connected-product disclosure, whereas the Data Governance Act focuses on safeguards for categories of protected public-sector data such as confidential or commercially sensitive information held by a public body. The protected interests overlap but the mechanisms differ.

A team handling sensitive data should apply the Data Act safeguard analysis for product and B2B sharing and the DGA safeguard analysis for protected public-sector reuse, rather than reusing one set of controls for both.

  • Apply Data Act trade-secret identification and safeguards to connected-product and B2B disclosures.
  • Apply DGA reuse safeguards to protected public-sector data, keeping the two control sets distinct.
Citations
Data Act and Data Governance Act Overlap

How should a company that is both a data holder and a data intermediary separate its Data Act and DGA duties?

Under the Data Act, a company that holds connected-product data has data-holder duties, and if it also runs a registered DGA data intermediation service it must keep that service neutral, which the DGA largely prevents from also commercialising the data it intermediates. The duties must be kept on separate sides of the business.

Use structural and contractual separation to keep the data-holder role from compromising the neutrality required of the DGA intermediation service.

  • Keep the Data Act data-holder role structurally separate from any DGA intermediation service.
  • Document which entity or function carries each duty so neutrality and holder obligations do not merge.
Citations
Data Act and Data Governance Act Overlap

Which competent authorities and enforcement routes differ between the Data Act and the Data Governance Act?

Under the Data Act, Member States designate competent authorities to enforce its access, sharing, and cloud-switching rules, while the Data Governance Act has its own competent authorities for intermediation registration and data altruism oversight. A complaint should be routed to the authority for the regime that actually governs the issue.

Teams should record which authority oversees each workflow, because a Data Act access dispute and a DGA intermediation complaint can fall to different bodies even within the same Member State.

  • Route Data Act access, sharing, and switching disputes to the Data Act competent authority.
  • Route DGA intermediation and altruism matters to the relevant DGA competent authority.
Citations
Data Act and Data Governance Act Overlap

How do the Data Act and the Data Governance Act each handle international transfers of non-personal data?

Under the Data Act, Article 32 guards against unlawful third-country government access to non-personal data held in the EU, while the Data Governance Act sets safeguards for international transfers of protected public-sector data and for intermediaries and altruism organisations. Both address cross-border risk but at different points in the data lifecycle.

A team moving non-personal data abroad should check the Data Act safeguard for data processing services and the DGA safeguard for protected public-sector data separately, since the triggers are not identical.

  • Apply the Data Act Article 32 safeguard to non-personal data in EU data processing services.
  • Apply DGA international-transfer safeguards to protected public-sector data and intermediation flows.
Citations
Data Act and Data Governance Act Overlap

When should a team re-run its Data Act and Data Governance Act boundary analysis as a programme evolves?

Under the Data Act, the boundary analysis should be repeated whenever the programme adds a connected-product data flow, a cloud switching dependency, an intermediation service, or a public-sector reuse element, because each can pull a new regime into scope. A change in actors or data categories is the usual trigger.

Teams should also re-run the analysis after new Commission guidance or a competent-authority decision, since either can shift where the Data Act ends and the DGA begins for a given workflow.

  • Re-run the analysis when a new connected-product, cloud, intermediation, or public-sector element is added.
  • Recheck the boundary after new guidance or a competent-authority decision changes the interpretation.
Citations
Data Act Audit Evidence and Request Logs

What should a Data Act request log prove?

A request log should show the route from intake to outcome. For connected-product and related-service data, record whether the requester is the user, a party acting on the user's behalf, or a third party chosen by the user. The log should identify the product or related service, requested data and metadata, format, timing, delivery route, and any refusal, suspension, limitation, compensation, or dispute route.

Keep the log narrow. The Data Act allows data holders to verify user or third-party status, but it also says they should not require more information than necessary and should not keep access information beyond what is necessary for execution, security, and maintenance of the data infrastructure.

  • Minimum fields: request ID, requester identity and role, product or related service, data category, metadata needed to interpret the data, request channel, decision, delivery or refusal date, responsible owner, and cited Data Act article.
  • For user access, record whether data were directly accessible or had to be made available by the data holder in a structured, commonly used, machine-readable format.
  • For third-party sharing, record the user's instruction, third-party identity check, delivery format, and any Article 8, Article 9, trade secret, security, or GDPR condition that changed the response.
Citations
Data Act Audit Evidence and Request Logs

How should teams record trade secret and security safeguards under the Data Act?

Trade secret handling needs its own evidence trail. The log should identify the data marked as trade secrets, the trade secret holder, the agreed technical and organisational measures, and whether the measures were accepted, not implemented, undermined, or still insufficient in exceptional circumstances.

A refusal or suspension should not be logged as a bare legal conclusion. The Data Act requires written substantiation for withholding, suspension, or case-by-case refusal based on serious economic damage, and notification to the competent authority in specified trade secret refusal scenarios.

  • Record the protected data, relevant metadata, trade secret holder, confidentiality measures, user or third-party commitments, and reviewer approval.
  • For withholding or suspension, keep the written reason, measures not agreed or not implemented, affected trade secrets, authority notification status, and user challenge route.
  • For security-based restrictions under Article 4, record the security requirement, expected serious adverse effect, scope of restriction, authority notification, and any narrower alternative offered.
Citations
Data Act Audit Evidence and Request Logs

What evidence belongs in a B2G exceptional need request file under the Data Act?

For public-sector exceptional-need requests, keep the incoming written request and a structured review record. The record should show the requesting body, legal task, exceptional-need basis, specific data and metadata requested, purpose, intended use, deadline, erasure expectation, onward-sharing plan, and whether personal data, trade secrets, or cross-border procedure steps are involved.

The Data Act gives data holders short challenge windows for these requests. A holder may decline or seek modification no later than five working days after receiving a public-emergency request, and no later than 30 working days for other exceptional need requests, when the statutory grounds apply.

  • Log whether the request is for a public emergency or another legally defined public-interest task, and whether the Article 15 conditions are demonstrated.
  • Check that the request is written in clear language, specific, proportionate, tied to data the holder controls, and transmitted or published through the required public channel.
  • If declining or seeking modification, keep the ground relied on, response date, prior similar request details if relevant, correspondence, and competent-authority referral status.
Citations
Page 1 of 32
Previous12345...32Next