How should teams assign ownership for Data Act Public Emergency Requests implementation work?
Assign one accountable owner for the Data Act legal assessment and one for the operational response, then keep the rest of the stakeholders as consulted teams. The legal owner should assess Article 15, Article 17, Article 18, and Article 19 issues; the operational owner should coordinate data extraction, security controls, delivery, and recordkeeping.
If the request is cross-border or involves personal data, the ownership file should also show who is responsible for notifying the competent authority or supervisory authority and who tracks the response deadline.
- Use one owner for legal review, one for technical delivery, and one for records retention.
- Record the business unit that controls the requested data and the people who can approve disclosure or refusal.
- Track the review trigger and any escalation path separately so the workflow does not depend on ad hoc decisions.
Articles 17 to 21 support the recommended records: request content, response grounds, safeguards, erasure, compensation, and onward sharing.
Explains the once-only principle and publication of requests by the data coordinator, subject to security concerns.
The Commission FAQ explains that requested data do not become public sector information for open reuse.