FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
470of470items
Across 39 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
EU Data Act B2G Exceptional Need

How should a data holder document, share, and review an EU Data Act exceptional-need request?

A data holder should keep the written request, the basis for accepting or challenging it, the response deadline, the data disclosed or withheld, and the safeguards applied to the transfer. The record should also show any cross-border notification and any competent-authority contact.

If the data holder relies on a refusal or a request for modification, it should record the reason and the relevant Article 18 ground. If the request is fulfilled, the record should include the purpose limitation, security measures, any trade-secret identification, and later erasure or onward-sharing notices.

  • Keep the Article 17 request elements together with the Article 18 response and any authority correspondence.
  • Record whether the request was for a public emergency or another exceptional need, because the deadline to decline or seek modification is five or 30 working days depending on that distinction.
  • Preserve evidence of erasure, notification, or authorised onward sharing so the file shows how the data was used after disclosure.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 17, 18, 19, and 21 set out the request record, decline-or-modification windows, safeguards, erasure duties, and onward-sharing notices that should be retained.

EU Data Act B2G Exceptional Need

Can a Data Act B2G exceptional-need request include personal data?

For non-emergency requests, only non-personal data may be requested. For public-emergency requests, the request must concern non-personal data unless those data are demonstrably insufficient. If personal data are required, Article 17 requires the request to seek them in pseudonymised form and specify the safeguards; Article 18 requires the data holder to anonymise the data unless compliance requires disclosure of personal data, in which case the holder must pseudonymise them.

Where personal data is involved, the request must identify the technical and organisational safeguards needed to protect data-protection principles, and the relevant supervisory authority must be notified.

  • Check whether the request is emergency or non-emergency before reviewing any personal-data fields.
  • Require a clear explanation of why non-personal data is insufficient and why the personal-data element is strictly necessary.
  • Keep the anonymisation or pseudonymisation decision, the safeguards named in the request, and any supervisory-authority notification where personal data is involved.
Citations
EU Data Act B2G Exceptional Need

When may a data holder refuse or ask to modify a Data Act B2G exceptional-need request?

A data holder may decline or seek modification without undue delay, and in any event within five working days for data necessary to respond to a public emergency or within 30 working days for other exceptional-need requests.

The Data Act gives three listed grounds: the data holder does not control the requested data; a similar request for the same purpose was previously submitted by another eligible public body or EU institution and the data holder has not been notified that the earlier data was erased; or the request does not meet the Article 17 requirements.

  • Use the correct decline-or-modification clock: five working days for public-emergency response data and 30 working days for other exceptional-need requests.
  • If relying on a previous similar request, identify the earlier requesting body or EU institution.
  • If the requester challenges a refusal, or the data holder challenges the request and no modification resolves it, the matter goes to the competent authority where the data holder is established.
Citations
Regulation (EU) 2023/2854 (Data Act)

Article 18 sets the five-working-day and 30-working-day decline-or-modification windows, refusal and modification grounds, and competent-authority challenge route.

EU Data Act B2G Exceptional Need

How do confidentiality, trade secrets, and onward sharing work for Data Act B2G exceptional-need data?

Data received under Chapter V does not become open public-sector information for general reuse. It must be used only for the purpose stated in the request, protected with technical and organisational measures, and erased once no longer necessary for that stated purpose unless archiving is required under Union or national public-access law in the context of transparency obligations.

Trade secrets may be disclosed only to the extent strictly necessary for the Article 15 purpose. The data holder or trade-secret holder must identify the protected data, including relevant metadata, and the requesting body must take necessary and appropriate measures to preserve confidentiality before disclosure.

  • Do not treat Chapter V data as open data or general public-sector information for reuse.
  • Identify any public bodies, EU bodies, or third parties that will receive the data in the original request or in the later Article 21 notification.
  • For trade secrets, record the identified protected data, confidentiality measures, transfer controls, and the stated purpose that makes disclosure strictly necessary.
Citations
EU Data Act B2G Exceptional Need

Can businesses receive compensation for making data available under a Data Act B2G exceptional-need request?

For a public-emergency request, data holders other than microenterprises and small enterprises must make the necessary data available free of charge, but may request public acknowledgement. Article 20(3) applies the Article 20(2) compensation rule when a microenterprise or small enterprise makes a claim, so the calculation covers the technical and organisational costs incurred to comply plus a reasonable margin. Those enterprises may also request public acknowledgement.

For non-emergency exceptional-need requests under Article 15(1)(b), the data holder is entitled to fair compensation covering technical and organisational costs, including anonymisation, pseudonymisation, aggregation, and technical adaptation where applicable, plus a reasonable margin. There is an exception where the task is official statistics and national law does not allow purchase of the data.

  • Separate the compensation record by request type: public emergency or non-emergency exceptional need.
  • For non-emergency requests, document the cost calculation basis and reasonable margin because the requester may ask for it.
  • Do not charge for the data itself; keep compensation tied to the costs and margin allowed by Article 20.
Citations
EU Data Act B2G Exceptional Need

What evidence should a data holder keep for a Data Act B2G exceptional-need request?

Keep enough evidence to show whether the request was valid, how the company responded, what data was made available or withheld, and which safeguards governed the data after transfer. Build the evidence file around the Article 17 request contents and the Article 18 response, not generic compliance notes.

A useful record includes the written request, requester identity, statutory task and legal provision, exceptional-need route, a public-emergency determination or declaration, or a non-emergency exhaustion analysis, data scope and metadata, personal-data analysis, trade-secret identification, timestamps, refusal or modification reasons, compensation calculation, delivery logs, onward-sharing notices, erasure notice, and competent-authority communications.

  • For emergency requests, keep the public-emergency basis, alternative-means analysis, five-working-day decline-or-modification record, and any public-acknowledgement request.
  • For non-emergency requests, keep the non-personal-data classification, exhausted-means evidence, market-purchase record where relevant, 30-working-day decline-or-modification record, and compensation basis.
  • For safeguards, keep anonymisation or pseudonymisation decisions, security measures, trade-secret protections, purpose limitation, onward-sharing notifications, and deletion confirmations.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 17 through 21 define the request fields, decline-or-modification windows, safeguards, compensation records, onward-sharing notices, and erasure obligations that drive the evidence file.

EU Data Act B2G Exceptional Need

What records should teams keep to support a Data Act B2G exceptional-need decision?

Keep one decision record that maps each incoming request to Articles 14 through 18. It should identify the requester, the legal-person data holder, the Article 15 route, the statutory public-interest task, the data and metadata requested, control over those data, purpose, duration, response deadline, and the reviewer who accepted, challenged, or modified the request.

Attach the public-emergency determination or declaration, or the non-emergency exhausted-means analysis, the cited legal provision assigning the task, any market-purchase evidence, and unresolved assumptions. That record lets a later reviewer distinguish a valid exceptional-need request from ordinary procurement, regulatory reporting, law enforcement, customs, or taxation access.

  • Record the exact Article 15 branch, Article 17 request fields, and Article 18 response ground beside the cited Data Act source URL.
  • Keep the data-scope map, personal-data and trade-secret analysis, compensation position, authority correspondence, and delivery or refusal evidence in the same file.
  • State every unresolved fact and assign a deadline and owner for resolving it before disclosure.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 17 through 21 define the request fields, decline-or-modification windows, safeguards, compensation records, onward-sharing notices, and erasure obligations that drive the evidence file.

EU Data Act B2G Exceptional Need

How should teams assign ownership for Data Act B2G exceptional-need implementation work?

Assign one request owner with authority to control the five- or 30-working-day decline-or-modification clock and coordinate legal, privacy, security, data engineering, finance, and records teams. Give separate named owners the legal-validity review, data extraction, confidentiality controls, compensation calculation, and authority communications.

The requesting body retains responsibility for the Article 17 request, purpose limitation, security, onward-sharing notices, and erasure. The data holder should name internal owners who obtain and preserve the evidence needed to challenge a defective request or prove a compliant disclosure.

  • Name the person who starts and monitors the applicable Article 18 decline-or-modification clock on receipt.
  • Assign legal review, data preparation, safeguards, compensation, and external communication to named roles with due dates.
  • Identify who may approve disclosure and who may send a decline or modification request to the requester.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 17 through 21 define the request fields, decline-or-modification windows, safeguards, compensation records, onward-sharing notices, and erasure obligations that drive the evidence file.

EU Data Act B2G Exceptional Need

Which records make the Data Act B2G exceptional-need answer usable later?

A usable file shows what happened after the legal classification. Preserve the signed or transmitted request, receipt timestamp, validation checklist, modification or refusal correspondence, disclosed dataset and metadata, transfer proof, safeguards, compensation workpaper, onward-sharing notices, and erasure confirmation.

Keep the actual version of each artifact, not only a policy template. For a cross-border request, include the notification to the competent authority in the data holder's Member State and the authority's examination outcome under Article 22.

  • Link the source clause and decision memo to the exact request, data extract, transfer record, and closure evidence.
  • Retain the Article 21 recipient notice if data went to a research organisation, national statistical institute, or Eurostat.
  • Record the named owner and the event that will reopen the file if use, recipients, retention, or request scope changes.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 17 through 21 define the request fields, decline-or-modification windows, safeguards, compensation records, onward-sharing notices, and erasure obligations that drive the evidence file.

EU Data Act B2G Exceptional Need

When should the Data Act B2G exceptional-need FAQ answer be reviewed again?

Reassess the decision if the requester, statutory task, exceptional-need branch, requested data, availability of alternative means, data-holder control, personal-data content, trade-secret scope, intended recipients, or use period changes. A revised or repeated request needs its own Article 17 and Article 18 review.

Reopen the file when the public emergency ends, the stated purpose is completed, an onward transfer is proposed, erasure becomes due, a similar request arrives, or a competent authority challenges the request or response. Use both a review date and these event triggers.

  • Review immediately when facts affecting validity, scope, compensation, safeguards, or the response deadline change.
  • Check purpose completion and erasure instead of treating delivery as the end of the workflow.
  • Keep the owner, next review date, trigger list, and cited source URL with the request record.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 17 through 21 define the request fields, decline-or-modification windows, safeguards, compensation records, onward-sharing notices, and erasure obligations that drive the evidence file.

EU Data Act Cloud Switching Procurement

What should procurement check first under the EU Data Act cloud-switching rules?

Start by confirming that the supplier is providing a data processing service to a customer, such as cloud or edge services using configurable, scalable computing resources. The Commission FAQ explains that the Data Act concept covers common IaaS, PaaS, and SaaS delivery models when the service has the Article 2(8) characteristics.

Then ask whether the contract removes the obstacles listed in Article 23: termination after the permitted notice and successful switch, new contracts with another provider, porting exportable data and digital assets, functional equivalence where applicable, and technically feasible unbundling.

  • Record the service model reviewed: IaaS, PaaS, SaaS, edge service, custom-built service, or limited test service.
  • Identify the source provider, possible destination provider, and whether the buyer may also switch to on-premises ICT infrastructure.
  • Check whether any custom-built or non-production exemption is claimed, and request the supplier's explanation before contracting.
Citations
EU Data Act Cloud Switching Procurement

Which mandatory cloud-switching contract terms should be visible before signature under the Data Act?

Article 25 requires the customer's switching rights and the provider's obligations to be set out clearly in a written contract that the customer can store and reproduce before signing. Exit language found only in a help-center article, commercial slide, or support policy outside the contract pack does not satisfy that contract-content requirement.

The contract should cover at least switching or porting on request, support for the customer's exit strategy, termination mechanics, a maximum notice period, exportable data categories, provider-internal data exemptions, a retrieval period, erasure after retrieval or an agreed later date, and any permitted switching charges.

  • Ask for a clause matrix against Article 25(2)(a) to (i), with contract references for each item.
  • Require a maximum notice period for initiating switching that does not exceed two months.
  • Confirm that the contract states when termination occurs after a successful switch or after erasure where the customer does not switch.
Citations
EU Data Act Cloud Switching Procurement

What exit and export support should a buyer require from a cloud provider under the Data Act?

For switching or porting, Article 25 requires reasonable assistance, due care to maintain business continuity, clear information on known continuity risks, and high security during transfer and retrieval. Ask for named support channels, technical documentation, migration tooling, continuity risk notices, and security controls during the switch.

Article 26 adds a separate information obligation: the provider must give switching and porting procedures, methods, formats, known restrictions, technical limitations, and a reference to an up-to-date online register for data structures, data formats, relevant standards, and open interoperability specifications.

  • Request the export runbook, supported export formats, API or interface documentation, and known technical limitations.
  • Ask for evidence of the online register covering data structures, formats, standards, and open interoperability specifications.
  • Require the supplier to state what assistance is included in the Data Act switching obligation and what extra services would be separately chargeable.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 25 and 26 support the procurement checks for assistance, continuity, security, switching procedures, formats, restrictions, and the online register.

EU Data Act Cloud Switching Procurement

What implementation records and review triggers should teams keep after agreeing the Data Act answer?

For cloud switching procurement checklist, the Data Act record should identify the source clause, Commission guidance, affected service, decision owner, and the evidence used to approve the supplier's switching terms. Keep the contract pack, supplier redlines, export tests, fee schedule, and online-register snapshot together so the decision can be checked later.

Review the checklist again when the service architecture, supplier documentation, standards references, or renewal timetable changes. A later reviewer should be able to see what was agreed, why it was acceptable, and what would require a fresh review.

  • Save the signed clause set, supplier responses, approval notes, export tests, fee schedule, online-register snapshot, and erasure confirmation requirements.
  • Assign procurement, legal, security, architecture, and service-owner sign-off for high-risk services.
  • Set a renewal review date and an event trigger for changes to the service model, export path, or provider documentation.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 25 and 26 support the procurement checks for assistance, continuity, security, switching procedures, formats, restrictions, and the online register.

EU Data Act Cloud Switching Procurement

How should procurement test a cloud provider's switching charges and egress fees under the EU Data Act?

Under the Data Act, Article 29 phases out switching charges, including data egress fees, so that from 12 January 2027 providers cannot impose them, and in the interim period any charge must not exceed the provider's costs directly linked to the switching process concerned. Procurement should ask the supplier to confirm which date its contract reflects and how any interim charge is calculated.

A buyer should reject open-ended egress pricing and require the contract to state that switching charges fall away on the statutory date, so the cost of leaving is predictable rather than a lock-in lever.

  • Confirm the contract removes switching charges from 12 January 2027 and caps any interim charge at the provider's costs directly linked to the switching process concerned.
  • Ask for the cost basis of any reduced switching charge so it can be checked against the Article 29 limit.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 25 and 26 support the procurement checks for assistance, continuity, security, switching procedures, formats, restrictions, and the online register.

Page 14 of 32