FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
470of470items
Across 39 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
EU Data Act Third-Party Data Sharing

How does the GDPR affect third-party sharing?

The Data Act does not supersede GDPR. It complements Union data-protection and privacy law and does not create a new legal basis for providing access to personal data where the user is not the data subject. If personal data generated by a connected product or related service is to be made available to a third party and the user is not the data subject, the data holder needs a valid Article 6 GDPR legal basis and, where relevant, conditions for special-category data and ePrivacy terminal-equipment rules.

Where data contains several people's personal data, teams should separate, anonymise, pseudonymise, or otherwise control delivery as needed. The Commission FAQ also warns that privacy-enhancing technologies should not be used simply to circumvent Data Act sharing obligations where data remains readily available.

  • Classify whether the requested dataset contains personal data and whether the user is the data subject.
  • Document the GDPR legal basis before sharing personal data with the third party.
  • Use anonymisation, pseudonymisation, or data separation where needed, but do not use privacy measures as a pretext to avoid Article 5 when the data remains readily available.
Citations
Regulation (EU) 2023/2854 (Data Act)

Recital 7 and Article 5 explain that the Data Act is without prejudice to data-protection law and does not itself create a GDPR legal basis where the user is not the data subject.

EU Data Act Third-Party Data Sharing

Can the data holder charge for third-party sharing under the Data Act?

Article 5 says the data must be made available to the third party free of charge to the user. Separately, Article 9 allows reasonable and non-discriminatory compensation agreed between a data holder and a data recipient in business-to-business relations, and says compensation may include a margin.

There is a special cap for SME data recipients and not-for-profit research organisations that do not have linked or partner enterprises outside the SME category: compensation must not exceed the costs incurred for making the data available. The data holder must provide enough detail on the calculation basis for the data recipient to assess whether Article 9 requirements are met.

  • Do not charge the user for Article 5 third-party sharing.
  • If charging a data recipient, keep compensation reasonable, non-discriminatory, and documented.
  • Apply the Article 9 cost-only cap where the recipient is an eligible SME or not-for-profit research organisation.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 5 and 9 support free-of-charge sharing to the user, reasonable recipient compensation, SME and research-organisation caps, and calculation transparency.

EU Data Act Third-Party Data Sharing

What practical workflow should teams follow for a third-party sharing request under the Data Act?

Use a simple sequence: first confirm the request comes from the user or someone acting on the user's behalf, then confirm the recipient is eligible, then check the data scope and any GDPR issues. If the request is valid, make the data available without undue delay and in the required format. If trade secrets or security concerns apply, use the Article 5 or Article 4 safeguards, and if the issue cannot be resolved, withhold, suspend, or refuse only within the conditions in the Data Act.

A good implementation workflow also records the request, the data categories shared, the legal checks performed, the confidentiality measures agreed, the delivery date, and any authority notification or dispute route used.

  • Intake: verify user authority, recipient eligibility, and the specific request.
  • Review: check scope, GDPR, trade secrets, and security limits before releasing data.
  • Action: share, or if the legal test is not met, withhold, suspend, or refuse and document why.
Citations
EU Data Act Third-Party Data Sharing

What records should teams keep for a third-party sharing request under the Data Act?

Keep a request record that shows the user authority, recipient identity and eligibility, requested data categories, personal-data assessment, trade-secret and security assessment, recipient purpose, delivery route, delivery format, compensation position if any, and final outcome. These records should be enough to explain why data was shared, limited, suspended, withheld, or refused.

For recipient misuse, Article 11 supports remedies such as erasure of data and copies, ending production or use of goods or services produced from unlawfully used data where the legal test is met, informing the user of unauthorised use or disclosure, and compensation for misuse or disclosure of unlawfully accessed or used data.

  • Log the Article 5 request, verification facts, data scope, and recipient commitments.
  • Keep written substantiation for trade-secret withholding, suspension, or refusal and any competent-authority notice.
  • Record misuse response steps if a recipient uses deceptive means, unauthorised purposes, unlawful onward disclosure, or removes agreed protection measures.
Citations
EU Data Act Third-Party Data Sharing

How should teams assign ownership for Data Act third-party sharing implementation work?

Assign one accountable owner for the Data Act request workflow, with clear support from legal, privacy, security, product, and operations as needed. The owner should be the person who can actually change the affected process and decide whether the request is fulfilled, limited, suspended, or refused.

Keep consulted teams and evidence dependencies separate from the accountable owner so the process stays traceable without creating overlapping ownership.

  • Name one accountable owner for each sharing request workflow.
  • Track legal, privacy, security, product, and operations inputs as consults, not as duplicate owners.
  • Store the approval, refusal, or suspension rationale with the request record.
Citations
EU Data Act Trade Secret Safeguards

Does the EU Data Act let data holders protect trade secrets during data access and sharing?

Yes. The Data Act says trade secrets must be preserved when product data or related-service data is disclosed to a user or to a third party chosen by the user. The data holder, or the trade secret holder if different, must identify the protected data before disclosure, including in relevant metadata where needed.

That protection is not a general veto. The Commission FAQ explains that a data holder can decide which data it considers trade secrets, but that claim is not enough by itself to prevent Data Act access rights from being exercised.

  • Identify the specific fields, records, metadata, or outputs that are claimed to contain trade secrets.
  • Separate trade-secret material from data that can be shared without special confidentiality controls.
  • Record whether the request is a user-access request under Article 4 or a third-party sharing request under Article 5, because the recipient obligations differ.
Citations
EU Data Act Trade Secret Safeguards

What safeguards should be agreed with users before trade-secret data is disclosed under Article 4 under the Data Act?

Before disclosure to a user, the data holder and user must take necessary measures to preserve confidentiality, especially where third parties may later be involved. The Data Act gives examples: model contractual terms, confidentiality agreements, strict access protocols, technical standards, and codes of conduct.

The safeguard should match the actual risk. For example, a limited export file, named-user access, encryption, logging, recipient training, onward-sharing limits, or secure API controls may be relevant when they preserve confidentiality without making access unnecessarily difficult.

  • Define the data covered by the safeguard and the permitted purpose for the user.
  • State the confidentiality duties, access controls, onward-sharing limits, and incident or misuse reporting route.
  • Keep evidence that the user accepted and implemented the safeguards before disclosure.
Citations
EU Data Act Trade Secret Safeguards

How should teams document EU Data Act trade-secret safeguards, ownership, and evidence for later review?

Keep a short decision record that ties the request to the specific Data Act article, the trade-secret holder, the agreed safeguard package, and the person who approved the decision. That record should also show the request date, the data category, and whether the outcome was disclosure, withholding, suspension, or refusal.

For later review, save the source URL, the notice sent to the user or third party, the written reasons, and any authority notification together with the supporting evidence. A clear record makes it easier to show that the safeguard was proportionate and limited to the data actually at issue.

  • Store the source clause, decision date, approver, and affected data category in one file.
  • Keep the recipient notice, competent-authority notification, and non-confidential explanation with the supporting evidence.
  • Update the record if the safeguard package or the responsible owner changes.
Citations
EU Data Act Trade Secret Safeguards

What is the common mistake to avoid when using trade-secret safeguards under the EU Data Act?

The main mistake is treating trade-secret status as a broad reason to block or delay a Data Act request. The safer operational approach is to identify the specific trade-secret data, agree proportionate safeguards, share the remaining data where possible, and reserve withholding, suspension, or refusal for the limited conditions in the Data Act.

A second mistake is using confidentiality language that the product, support, security, or partner team cannot actually implement. A safeguard that exists only in contract text will not support a withholding, suspension, or refusal decision if the practical controls and evidence are missing.

  • Avoid blanket refusals based only on the phrase trade secret or confidential business information.
  • Avoid asking users or third parties for more information than is necessary to verify whether they qualify as a user or third party.
  • Avoid publishing recipient-facing explanations that disclose the trade secret while trying to justify the safeguard.
Citations
EU Data Act Trade Secret Safeguards

How should a data holder identify the exact trade-secret fields it wants protected under the EU Data Act?

The Data Act expects identification before disclosure rather than a vague claim afterwards, so the holder, or the trade-secret holder where they differ, should map the precise fields, calculated values, calibration parameters, or metadata that reveal the secret. Identification at this granularity is what later justifies a proportionate safeguard rather than a broad refusal.

A practical approach is to classify the dataset element by element, marking each field as shareable, shareable with a control, or genuinely secret, so the access route stays open for everything that is not actually confidential.

  • Tag the specific columns, signals, or derived outputs that disclose a formula, method, or model feature.
  • Keep the identification list with the request so a later reviewer can see what was protected and why.
Citations
European Commission - Data Act explained

Commission overview source for Data Act user access, third-party sharing, trade-secret protection, security limitations, competent-authority notices, and challenge routes.

EU Data Act Trade Secret Safeguards

When may a data holder suspend trade-secret data sharing after a confidentiality breach under the EU Data Act?

Under the Data Act, suspension is available where a user or third party fails to implement the agreed confidentiality measures or breaches them, and it must be accompanied by written reasons to the recipient and a notification to the competent authority. It is a temporary, breach-driven response rather than a way to reverse the access right.

The holder should tie the suspension to a concrete failure and reopen sharing once the agreed measure is implemented again, keeping the suspension proportionate to the confidentiality risk that triggered it.

  • Record the specific safeguard that was not implemented or was breached before suspending.
  • Send written reasons and notify the competent authority without undue delay, then restore access on remediation.
Citations
European Commission - Data Act explained

Commission overview source for Data Act user access, third-party sharing, trade-secret protection, security limitations, competent-authority notices, and challenge routes.

EU Data Act Trade Secret Safeguards

What objective evidence supports refusing a trade-secret data request in exceptional cases under the EU Data Act?

Under the Data Act, a data holder may refuse a specific request only in exceptional circumstances and only where it demonstrates with objective evidence that disclosure is highly likely to cause serious economic damage despite the agreed measures. The assessment is per request, not a standing policy across all telemetry.

A defensible refusal points to the particular data, the recipient, and the reason the agreed safeguards were insufficient, rather than a general worry about competition or a blanket label over an entire interface.

  • Scope any refusal to the precise fields that would cause serious economic damage if disclosed.
  • Assess the objective factors named by the Data Act: enforceability of trade-secret protection in relevant third countries, the nature and level of confidentiality of the requested data, and the connected product's uniqueness and novelty.
  • Keep case-specific evidence, give the recipient the duly substantiated written decision without undue delay, and notify the competent authority while preserving the challenge route.
Citations
European Commission - Data Act explained

Commission overview source for Data Act user access, third-party sharing, trade-secret protection, security limitations, competent-authority notices, and challenge routes.

EU Data Act Trade Secret Safeguards

How do trade-secret safeguards bind a third party that receives shared data under the EU Data Act?

Under the Data Act, when a user directs sharing to a third party under Article 5, the confidentiality undertakings, access controls, and onward-disclosure limits should bind that recipient too, and Article 6 restricts the third party from using the data to build a competing connected product. Safeguards agreed for user access should carry through to the third-party path.

The agreement with the third party should state the permitted purpose, the confidentiality duties, and the onward-sharing limits in writing, so the protection does not stop at the first recipient.

  • Extend the same confidentiality controls into the third-party contract, not only the user-facing route.
  • Bind the recipient to Article 6 use and onward-sharing restrictions before any disclosure.
Citations
European Commission - Data Act explained

Commission overview source for Data Act user access, third-party sharing, trade-secret protection, security limitations, competent-authority notices, and challenge routes.

EU Data Act Trade Secret Safeguards

How should teams keep trade-secret safeguards proportionate rather than over-restrictive under the EU Data Act?

Under the Data Act, technical and organisational measures must be necessary and proportionate, so the right safeguard is the least restrictive control that still protects the identified secret. A measure that blocks the whole access route, or is far broader than the risk, can itself breach the prohibition on hindering Data Act rights.

Matching a control to a named risk and a named field makes proportionality easier to defend than a blanket refusal, and it keeps the access right usable for the rest of the dataset.

  • Match each control to a specific protected element rather than the entire export or interface.
  • Prefer scoped, reversible controls over measures that make the access right impractical.
Citations
European Commission - Data Act explained

Commission overview source for Data Act user access, third-party sharing, trade-secret protection, security limitations, competent-authority notices, and challenge routes.

EU Data Act Trade Secret Safeguards

How do trade-secret safeguards interact with personal data and the GDPR under the EU Data Act?

Under the Data Act, trade-secret protection is a separate question from personal data protection, and the Regulation is without prejudice to the GDPR, so a confidentiality control that shields a secret does not remove the need for a valid legal basis where the same dataset includes personal data. Both analyses can apply to one export.

Run the two assessments in parallel: identify the secret elements and proportionate measures, and separately identify the personal data, the GDPR basis, and minimisation, keeping the records distinct so neither limit is over-applied.

  • Classify each field for both trade-secret sensitivity and personal data content before disclosure.
  • Apply a GDPR basis and minimisation to personal data even when confidentiality controls are in place.
Citations
European Commission - Data Act explained

Commission overview source for Data Act user access, third-party sharing, trade-secret protection, security limitations, competent-authority notices, and challenge routes.

Page 28 of 32