How does the GDPR affect third-party sharing?
The Data Act does not supersede GDPR. It complements Union data-protection and privacy law and does not create a new legal basis for providing access to personal data where the user is not the data subject. If personal data generated by a connected product or related service is to be made available to a third party and the user is not the data subject, the data holder needs a valid Article 6 GDPR legal basis and, where relevant, conditions for special-category data and ePrivacy terminal-equipment rules.
Where data contains several people's personal data, teams should separate, anonymise, pseudonymise, or otherwise control delivery as needed. The Commission FAQ also warns that privacy-enhancing technologies should not be used simply to circumvent Data Act sharing obligations where data remains readily available.
- Classify whether the requested dataset contains personal data and whether the user is the data subject.
- Document the GDPR legal basis before sharing personal data with the third party.
- Use anonymisation, pseudonymisation, or data separation where needed, but do not use privacy measures as a pretext to avoid Article 5 when the data remains readily available.
Recital 7 and Article 5 explain that the Data Act is without prejudice to data-protection law and does not itself create a GDPR legal basis where the user is not the data subject.
Commission FAQ explains GDPR portability overlap and how anonymisation, pseudonymisation, and privacy-enhancing technologies interact with Data Act access requests.