FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
470of470items
Across 39 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
EU Data Act Vehicle Data Guidance

How should repair, maintenance, mobility, and aftermarket use cases be handled under the Data Act?

Start with the vehicle-data field, not the market label. The Data Act can support access to readily available vehicle data for aftermarket uses, but the guidance also explains that the Data Act does not create access rights to vehicle functions or resources.

For independent repair shops and other independent service providers, the guidance is explicit that access quality should not be lower than the quality made available to the data holder, subsidiaries, authorised partners, dealers, or repairers. Access must also be easy, without undue barriers, costs, or procedural hurdles.

  • For repair and maintenance, separate data access from access to vehicle functions, resources, or commands.
  • For mobility services, identify whether the service only uses data or also affects vehicle operation through a related service.
  • For aftermarket access, compare the requested data and interface with what the data holder uses or gives to authorised channels, including completeness and whether the data are up to date.
Citations
EU Data Act Vehicle Data Guidance

Does the Data Act always require direct access through the vehicle?

No. Direct access under Article 3 applies where relevant and technically feasible. If users cannot access data directly from the vehicle, the data holder must provide indirect access to readily available data under Article 4 and make readily available data accessible to a third party at the user's request under Article 5.

The dates differ. Chapter II and the request-based Articles 4 and 5 have applied since 12 September 2025. The Article 3(1) design obligation applies to connected products and related services placed on the Union market after 12 September 2026, so record the individual vehicle's placing-on-the-market date before treating direct access as a design requirement.

The Data Act is technology-neutral about the access method. The guidance mentions remote backend solutions, onboard access, and data intermediation as possible routes, but the chosen method must still satisfy the Data Act conditions, including access to data of the same quality as available to the data holder.

  • Record the vehicle's Union placing-on-the-market date and distinguish the 12 September 2025 request rights from the post-12 September 2026 Article 3(1) design trigger.
  • Document whether the route is direct user access, indirect access through the data holder, or third-party access at the user's request.
  • If using an OBD-II route, do not require the user to buy a specialised tool or have advanced technical skills.
  • If using a backend or API route, check that it does not make the data less accurate, complete, reliable, relevant, or up to date than what the data holder has.
Citations
EU Data Act Vehicle Data Guidance

How do trade secrets, safety, and cybersecurity affect vehicle-data access under the Data Act?

Trade-secret and security concerns should be handled as specific safeguards, not as blanket refusals. The Data Act contains mechanisms for protecting trade secrets and allowing appropriate technical and organisational measures, while the vehicle guidance stresses that access still has to remain easy and non-discriminatory.

For vehicle data, the record should identify the protected interest, the precise data or interface affected, the measure applied, and what data remains available. Safety, cybersecurity, and trade-secret controls are most defensible when they are proportionate to a documented risk and do not turn an access right into a dead end.

  • Use field-level controls, access conditions, logging, authentication, and recipient commitments where they address the real risk.
  • Escalate refusals or heavy limitations to legal, cybersecurity, safety, and product owners before communicating them externally.
  • Avoid unsupported statements that all diagnostic, location, or component-status data is too sensitive to share.
Citations
EU Data Act Vehicle Data Guidance

Where is the GDPR boundary for connected vehicle data under the Data Act?

The Data Act does not supersede the GDPR. Where vehicle data is personal data, GDPR rules apply to the processing, and the Commission FAQs state that GDPR rules on personal-data protection prevail in the event of conflict.

This means an access workflow can be within Chapter II of the Data Act and still need a GDPR basis, data-subject analysis, minimisation, security, and recipient controls. Location data, driver behavior, charging history, and vehicle-use patterns should be assessed carefully because they can often identify or relate to a person depending on context.

  • Classify each field as personal, non-personal, or mixed before release.
  • Check whether the requesting user is the data subject or whether another GDPR legal basis is needed.
  • Keep the GDPR assessment separate from the Data Act scope assessment so neither one hides the other.
Citations
EU Data Act Vehicle Data Guidance

Which adjacent automotive rules should be checked under the Data Act?

The vehicle guidance is limited to the Data Act. It does not interpret or displace sector-specific automotive rules, including the Type Approval Regulation, rules on on-board diagnostics information or vehicle emissions data, competition rules for motor vehicle repair and spare parts, or other sector guidance.

A practical vehicle-data review should therefore mark whether the request is a Data Act Chapter II access request, a sector-specific access request, a GDPR issue, or a combined case. That prevents a team from using Data Act language to narrow rights that already exist under another rule, or using another rule to ignore Data Act access duties.

  • Check sector rules for OBD information, vehicle emissions data, roadworthiness testing information, repair information, and spare-parts distribution issues.
  • Use the Data Act for product data and related service data access where no more specific rule controls the exact question.
  • Document which rule controls each field, interface, recipient, and refusal or limitation reason.
Citations
EU Data Act Vehicle Data Guidance

What evidence should a vehicle-data access workflow keep under the Data Act?

Keep a vehicle-data access matrix that lists the data field, vehicle or service source, role map, raw or pre-processed classification, inferred or derived exclusion if relevant, personal-data status, access route, recipient, safeguards, source citation, decision, and delivery or refusal outcome.

For recurring aftermarket or mobility requests, also keep interface evidence: API specification, data dictionary, quality comparison, authentication model, recipient terms, support script, and logs showing what was delivered and when. The point is to make later complaints, partner disputes, or authority questions answerable without rebuilding the decision from memory.

  • Record the reason when a requested field is excluded as inferred, derived, not readily available, not designed to be retrievable, or controlled by another rule.
  • Keep the same-quality check where independent repairers or service providers receive data through a different route than authorised partners.
  • Retain escalation records for safety, cybersecurity, trade-secret, and GDPR limitations.
Citations
EU Data Act Vehicle Data Guidance

What source records should teams keep for a Data Act vehicle-data guidance decision for later review?

Keep the source clause, Commission guidance reference, actor role, dataset, request trigger, and approving owner together so the decision can be checked later. A short record is enough if it points to the exact Data Act source and the specific vehicle-data field or workflow that was reviewed.

Also keep the cited external URL, decision date, reviewer, unresolved assumptions, and implementation artifact with the decision file. That makes the answer auditable without forcing teams to reconstruct the reasoning from email threads.

  • Link the decision to a cited Data Act source URL and the relevant vehicle-data field or workflow.
  • Store the owner, affected workflow, evidence artifact, and review trigger in the same record.
Citations
EU Data Act Vehicle Data Guidance

Which team should own a Data Act vehicle-data guidance implementation task and confirm the fix?

Assign one accountable owner who can actually change the affected process under the Data Act, such as legal, product, procurement, cloud, support, or security. That owner should be the person who can approve the interpretation, coordinate the fix, and confirm the workflow now matches the guidance.

Use consulted teams and evidence dependencies to support the owner, but keep them separate from the single accountable owner. That helps teams avoid stalled decisions and makes follow-up reviews easier when the vehicle-data workflow changes.

  • Name one accountable owner per action.
  • Record consulted teams, evidence artifacts, and review triggers separately.
  • Use the owner record to follow up on any access, quality, or safeguard change.
Citations
EU Data Act: Non-Personal Data and Mixed Datasets

What does non-personal data mean under the EU Data Act, and how does it differ from personal data?

The Data Act defines non-personal data as data other than personal data. Classify by substance and context, not by the dataset label. A machine telemetry export, support log, vehicle dataset, or cloud export can contain non-personal fields alongside fields that identify or relate to a natural person. A field that appears anonymous in isolation can still be personal data when combined with other reasonably available information.

For connected products and related services, the Data Act access analysis should start with raw and pre-processed data that is readily available to the data holder, plus metadata needed to interpret and use it. Inferred or derived information, highly enriched outputs, protected content, and material outside the connected-product or related-service boundary should be marked separately instead of silently included.

  • Classify each field and relevant field combination as personal or non-personal, then separately mark inferred or derived information, trade-secret-sensitive data, and material outside the request.
  • Record whether the field is product data, related-service data, relevant metadata, or another data category.
  • Do not rely on internal labels such as telemetry, operational data, customer data, or analytics unless the field-level classification is visible.
Citations
EU Data Act: Non-Personal Data and Mixed Datasets

Does the EU Data Act override GDPR when a dataset contains both personal and non-personal data?

No. The Data Act complements EU data-protection and privacy law and must not be interpreted to diminish personal-data rights. When a mixed dataset contains personal data, GDPR, the EU institutions data-protection regulation, and ePrivacy rules continue to control the personal-data processing layer.

The Data Act also does not create a new legal basis for collecting or generating personal data. If the user requesting data is not the data subject, personal data generated by a connected product or related service may be made available to the user or a third party only where a valid GDPR legal basis exists and any relevant special-category or ePrivacy conditions are satisfied.

  • Treat Data Act access and GDPR processing as separate questions that must both be satisfied for personal-data fields.
  • If the requester is not the data subject, document the GDPR legal basis before releasing personal data.
  • Where possible, separate, anonymise, or limit personal-data fields instead of blocking access to non-personal fields that remain in scope.
Citations
Regulation (EU) 2023/2854 (Data Act)

States that the Data Act is without prejudice to data-protection and privacy law and does not create a new legal basis for personal-data collection or generation.

EU Data Act: Non-Personal Data and Mixed Datasets

Which Data Act roles matter when handling non-personal data and mixed datasets?

The main roles are user, data holder, third party, and data recipient. A user owns a connected product, has a temporary contractual right to use it, or receives a related service. A data holder has the right or obligation under the Data Act, applicable Union law, or qualifying national legislation to use and make data available. A third party established in the Union can receive data at the user's request and may be a data recipient for business-to-business sharing rules.

Do not assign roles once for the whole company. The same organisation can be a user in one workflow, a data holder in another, and a data recipient in a supplier or aftermarket-service workflow. Role classification controls who can request data, who must make it available, who may use it, and who must preserve trade secrets or delete data when it is no longer needed.

  • Name the user, data holder, third party, data recipient, and any data subject for each request.
  • Check whether the relevant organisation is a manufacturer, related-service provider, provider of data processing services, public undertaking, or another party with a Data Act duty.
  • Keep the role map with the request log because role errors change the access, sharing, GDPR, and evidence analysis.
Citations
EU Data Act: Non-Personal Data and Mixed Datasets

What mixed-dataset access must a data holder provide to a user under the EU Data Act?

Where the user cannot directly access the data from the connected product or related service, the data holder must make readily available data and necessary metadata accessible without undue delay, in the same quality available to the holder, securely, free of charge, and in a comprehensive, structured, commonly used, machine-readable format. Access must be continuous and real-time only where relevant and technically feasible.

That duty covers both personal and non-personal data only when the personal-data layer is lawful. If GDPR conditions are not met for a personal-data field, the data holder should not treat that as a reason to suppress the non-personal fields that can lawfully be made available.

  • Deliver in-scope non-personal fields and metadata in the required format and quality.
  • For personal fields, confirm whether the user is the data subject or has a valid GDPR basis for receiving them.
  • Document any excluded field by category: personal-data restriction, inferred or derived data, trade secret, security requirement, unavailable data, or out-of-scope content.
Citations
EU Data Act: Non-Personal Data and Mixed Datasets

Can a user ask the data holder to share a mixed dataset with a third party under the Data Act?

Yes, but the same boundaries apply. At the user's request, the data holder must make readily available data and relevant metadata available to a third party under the Data Act conditions. A gatekeeper under the Digital Markets Act is not an eligible third party for this user-requested Chapter II sharing route.

For personal data, the data holder may disclose to the third party only where the GDPR and any relevant ePrivacy conditions are met. The third party may use received data only for the purposes and conditions agreed with the user. It must erase the data when no longer necessary for that purpose, unless the user agrees otherwise for non-personal data.

  • Tie third-party sharing to a specific user request and a stated user-approved purpose.
  • Screen the requested recipient for the Data Act gatekeeper exclusion where Chapter II third-party access is used.
  • Add recipient controls for purpose limitation, onward sharing, deletion, trade secrets, security, and non-use for competing connected products.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 5 and 6 set user-requested third-party sharing duties, gatekeeper exclusion, GDPR limits, purpose controls, deletion, and onward-sharing restrictions.

EU Data Act: Non-Personal Data and Mixed Datasets

What are the main boundaries for non-personal data use by data holders and third parties under the Data Act?

A data holder may use readily available non-personal data only on the basis of a contract with the user. The holder must not use those data to derive insights about the user's economic situation, assets, production methods, or product use in a way that could undermine the user's commercial position.

Third parties that receive Data Act data at the user's request also face limits. They may not use the data to develop a competing connected product, make it available to a Digital Markets Act gatekeeper, or use non-personal product or related-service data to derive commercial insights about the data holder. These restrictions should be visible in contract terms and recipient controls, not buried in a generic data-sharing policy.

  • Check the user contract before using non-personal product or related-service data internally.
  • Separate permitted aftermarket or related-service use from prohibited development of a competing connected product.
  • Prohibit commercial insight extraction about the user, data holder, or third party where the Data Act restricts it.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 4 and 6 limit data holder and third-party use of non-personal product and related-service data, including competitive-product and insight restrictions.

EU Data Act: Non-Personal Data and Mixed Datasets

How should trade secrets and security concerns be handled in mixed datasets under the Data Act?

Trade secrets are not a blanket reason to deny a Data Act request. The data holder or trade-secret holder must identify protected data, including relevant metadata, and agree proportionate technical and organisational measures with the user or third party. Examples in the Data Act include contractual terms, confidentiality agreements, strict access protocols, technical standards, and codes of conduct.

Withholding, suspension, or refusal needs a written, substantiated basis. A refusal based on trade secrets is exceptional and must be assessed case by case. Security limits are also narrow: users and data holders may restrict or prohibit access, use, or further sharing where processing could undermine legally-laid-down security requirements of the connected product and cause serious adverse effects to health, safety, or security.

  • Identify trade-secret fields and metadata before applying confidentiality measures.
  • Use proportionate safeguards first; reserve withholding, suspension, or refusal for the Data Act conditions that support them.
  • Keep the written reason, affected fields, measures requested, measures implemented, and any competent-authority notification.
Citations
Regulation (EU) 2023/2854 (Data Act)

Articles 4 and 5 require trade-secret identification, proportionate confidentiality measures, written substantiation, and competent-authority notification for withholding, suspension, or refusal.

Page 31 of 32