---
title: "EU Data Act FAQ: scope, access rights, B2G, cloud switching, GDPR, and dates"
canonical_url: "https://www.sorena.io/artifacts/eu/data-act/faq"
source_url: "https://www.sorena.io/artifacts/eu/data-act/faq/items/page/31"
author: "Sorena AI"
description: "EU Data Act FAQ index covering connected-product access, third-party sharing, B2G exceptional need, cloud switching, smart contracts, GDPR boundaries, unfair terms, and application dates."
published_at: "2026-05-06"
updated_at: "2026-07-25"
keywords:
  - "EU Data Act FAQ"
  - "Data Act scope"
  - "connected product data"
  - "B2G data sharing"
  - "cloud switching"
  - "GDPR Data Act"
  - "EU Data Act"
  - "Data Act FAQ"
  - "Regulation (EU) 2023/2854"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU Data Act FAQ: scope, access rights, B2G, cloud switching, GDPR, and dates

EU Data Act FAQ index covering connected-product access, third-party sharing, B2G exceptional need, cloud switching, smart contracts, GDPR boundaries, unfair terms, and application dates.

*FAQ* *EU* *Data Act*

## EU Data Act FAQ hub

Answers to the recurring EU Data Act questions that decide whether connected-product data, related-service data, B2G requests, cloud contracts, or smart-contract tooling need a compliance review.

This index helps orient product, legal, cloud, procurement, data protection, security, and public-sector request teams before opening the deeper topic modules.

The Data Act, Regulation (EU) 2023/2854, has applied generally since 12 September 2025. It gives qualifying users access to readily available data from connected products and related services, sets terms for mandatory business-to-business data sharing, creates a narrow public-sector exceptional-need route, and regulates switching between data processing services. It also addresses unfair contract terms, unlawful third-country government access to non-personal data, interoperability, and smart contracts. GDPR and sector-specific EU rules continue to apply alongside it.

## Definitions

### EU Data Act

**Term:** Data Act

The Data Act is Regulation (EU) 2023/2854, a directly applicable EU regulation on access to and use of data. It covers connected-product and related-service data, legally required business-to-business data sharing, exceptional public-sector requests, switching between data processing services, unfair data-contract terms, interoperability, and smart contracts.

**Why it matters here:** The applicable chapter depends on the actor, data, product or service, and transaction. The regulation has applied generally since 12 September 2025, but several duties have separate transition rules.

Sources:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io)

## Browse sub-FAQ modules

### [Data Act and Data Governance Act Overlap FAQ](/artifacts/eu/data-act/faq/data-governance-act-overlap.md)

FAQ explaining where the EU Data Act and Data Governance Act overlap, how they differ, and how to route product, cloud, public-sector reuse, intermediary, and data altruism workflows.

- 12 items

### [Data Act Audit Evidence and Request Logs FAQ](/artifacts/eu/data-act/faq/audit-evidence-and-request-logs.md)

FAQ for Data Act request logs covering user and third-party access, B2G exceptional need requests, cloud switching records, contract terms, trade secrets, and GDPR boundaries.

- 12 items

### [Data Act Cloud Switching Contract Terms FAQ](/artifacts/eu/data-act/faq/cloud-switching-contract-terms.md)

FAQ on EU Data Act cloud switching contract terms: Article 25 clauses, assistance, notice, transition, charges, export, termination, interoperability, and records.

- 12 items

### [Data Act Cloud Switching Fees and Deadlines FAQ](/artifacts/eu/data-act/faq/cloud-switching-fees-and-deadlines.md)

FAQ on EU Data Act cloud switching charges, 2027 fee removal, notice periods, transition windows, data retrieval, contract terms, and evidence records.

- 12 items

### [Data Act Complaints and Dispute Settlement FAQ](/artifacts/eu/data-act/faq/complaints-and-dispute-settlement.md)

FAQ on EU Data Act complaints, competent authorities, dispute settlement bodies, B2B data-sharing disputes, B2G requests, cloud switching disputes, and evidence records.

- 12 items

### [Data Act Exportable Data and Metadata FAQ](/artifacts/eu/data-act/faq/exportable-data-and-metadata.md)

FAQ explaining which product, related service, metadata, and cloud switching data must be exportable under the EU Data Act, and which data can be excluded.

- 12 items

### [Data Act FAQ for Aftermarket Repair and Mobility Services](/artifacts/eu/data-act/faq/aftermarket-repair-and-mobility-services.md)

FAQ on EU Data Act vehicle-data access for repairers, independent service providers, fleets, insurers, and mobility services.

- 12 items

### [Data Act SME Exceptions and Startups FAQ](/artifacts/eu/data-act/faq/sme-exceptions-and-startups.md)

FAQ on where the EU Data Act gives micro, small, medium-sized, startup, and SME actors narrower treatment for access duties, compensation, and B2B terms.

- 12 items

### [Data Act Trade Secret Technical Protection Measures FAQ](/artifacts/eu/data-act/faq/trade-secret-technical-protection-measures.md)

FAQ on how EU Data Act data holders can protect trade secrets with confidentiality safeguards, technical measures, limited withholding, suspension, refusal, and evidence.

- 12 items

### [EU Data Act and Common European Data Spaces FAQ](/artifacts/eu/data-act/faq/data-act-and-common-european-data-spaces.md)

FAQ on how EU Data Act interoperability duties, Data Governance Act rules, and sector data-space governance fit together without treating participation as a general obligation.

- 12 items

### [EU Data Act and GDPR: Personal Data Overlap FAQ](/artifacts/eu/data-act/faq/gdpr-personal-data-overlap.md)

FAQ on how the EU Data Act works when connected-product or related-service data includes personal data, mixed datasets, GDPR roles, lawful basis, trade secrets, and third-party sharing.

- 12 items

### [EU Data Act Application Dates and Transition FAQ](/artifacts/eu/data-act/faq/application-dates-and-transition.md)

FAQ on when the EU Data Act applies, which obligations are delayed, and what product, contract, cloud, and evidence records teams should maintain.

- 12 items

### [EU Data Act Article 32: Foreign Government Access FAQ](/artifacts/eu/data-act/faq/international-government-access.md)

FAQ on EU Data Act safeguards for non-EU government access to non-personal data held in the Union by data processing service providers.

- 12 items

### [EU Data Act Article 36 Smart Contract Controls FAQ](/artifacts/eu/data-act/faq/article-36-smart-contract-controls.md)

FAQ explaining when EU Data Act Article 36 applies to smart contracts for data-sharing agreements and what controls, conformity evidence, and limits it requires.

- 12 items

### [EU Data Act B2B Data Sharing Compensation FAQ](/artifacts/eu/data-act/faq/compensation-for-b2b-data-sharing.md)

FAQ on when Data Act data holders may charge B2B data recipients, what reasonable compensation can include, SME limits, unfair terms, disputes, and trade secret safeguards.

- 12 items

### [EU Data Act B2G Compensation and Costs FAQ](/artifacts/eu/data-act/faq/b2g-compensation-and-costs.md)

FAQ on when Data Act B2G exceptional-need requests are free, when fair compensation may be claimed, which costs can be included, and what records to keep.

- 12 items

### [EU Data Act B2G Exceptional Need FAQ](/artifacts/eu/data-act/faq/b2g-exceptional-need.md)

When public-sector bodies can request business-held data under the EU Data Act, what a valid request must contain, and how data holders handle limits, trade secrets, compensation, and evidence.

- 13 items

### [EU Data Act Cloud Switching Procurement FAQ](/artifacts/eu/data-act/faq/cloud-switching-procurement-checklist.md)

Procurement checklist FAQ for EU Data Act cloud switching: contract terms, exit support, exportable data, switching charges, interoperability, termination, and supplier evidence.

- 12 items

### [EU Data Act Connected Product Scope FAQ](/artifacts/eu/data-act/faq/scope-connected-products.md)

FAQ explaining when connected products, related services, generated data, EU market placement, and SME exceptions fall within EU Data Act scope.

- 12 items

### [EU Data Act data spaces interoperability FAQ](/artifacts/eu/data-act/faq/data-spaces-interoperability.md)

FAQ explaining Article 33 Data Act interoperability requirements for data-space participants, common European data spaces, standards, APIs, metadata, and architecture evidence.

- 12 items

### [EU Data Act Direct Access by Design FAQ](/artifacts/eu/data-act/faq/direct-access-by-design.md)

FAQ for product and legal teams designing user access to connected-product and related-service data under the EU Data Act.

- 12 items

### [EU Data Act Enforcement and Competent Authorities FAQ](/artifacts/eu/data-act/faq/enforcement-and-competent-authorities.md)

FAQ on who enforces the EU Data Act, how complaints work, how Member States set penalties, when dispute settlement can be used, and when GDPR authorities remain responsible.

- 13 items

### [EU Data Act Functional Equivalence: IaaS Switching FAQ](/artifacts/eu/data-act/faq/functional-equivalence.md)

FAQ on Data Act functional equivalence for cloud switching: IaaS scope, customer outcomes, export support, interoperability duties, limits, and evidence.

- 12 items

### [EU Data Act Indirect Access Request Workflow FAQ](/artifacts/eu/data-act/faq/indirect-access-request-flows.md)

FAQ for Data Act teams handling user and third-party data requests when direct connected-product access is unavailable, incomplete, or limited.

- 12 items

### [EU Data Act Interoperability Standards: Articles 33-36](/artifacts/eu/data-act/faq/interoperability-standards.md)

FAQ on EU Data Act interoperability standards for data spaces, cloud switching, smart contracts, harmonised standards, common specifications, and M/614.

- 12 items

### [EU Data Act Model Terms and Cloud Clauses FAQ](/artifacts/eu/data-act/faq/model-contractual-terms.md)

FAQ on the EU Data Act non-binding model contractual terms for data access and use, cloud switching clauses, B2B use, unfair terms, and evidence.

- 12 items

### [EU Data Act Non-Emergency Public-Sector Request FAQ](/artifacts/eu/data-act/faq/non-emergency-public-sector-requests.md)

FAQ on EU Data Act requests where a public body claims exceptional need outside a public emergency, including scope, request contents, limits, compensation, confidentiality, and evidence.

- 12 items

### [EU Data Act Pre-Contractual Information FAQ](/artifacts/eu/data-act/faq/pre-contractual-information.md)

FAQ on EU Data Act Article 3 pre-contract information for connected products and related services, including data categories, access methods, data holder identity, third-party sharing, and GDPR boundaries.

- 12 items

### [EU Data Act Product Data vs Related-Service Data](/artifacts/eu/data-act/faq/product-data-and-service-data.md)

FAQ explaining how the EU Data Act separates connected product data, related service data, readily available raw and pre-processed data, metadata, and inferred or derived outputs.

- 12 items

### [EU Data Act Public Emergency Request FAQ](/artifacts/eu/data-act/faq/public-emergency-requests.md)

FAQ on EU Data Act public emergency requests: exceptional need, request content, timing, data holder response, compensation, confidentiality, and records.

- 12 items

### [EU Data Act Readily Available Data FAQ](/artifacts/eu/data-act/faq/readily-available-data.md)

FAQ on what counts as readily available data under the EU Data Act, including product data, related service data, metadata, inferred data, and access mechanics.

- 12 items

### [EU Data Act Related Services FAQ](/artifacts/eu/data-act/faq/related-services.md)

FAQ explaining when software is a Data Act related service, how it links to connected products, which product and service data are in scope, and what exclusions apply.

- 12 items

### [EU Data Act Smart Contracts for Data Sharing FAQ](/artifacts/eu/data-act/faq/smart-contracts-for-data-sharing.md)

Answers on Article 36 Data Act smart-contract requirements for data sharing: scope, robustness, access control, termination, archiving, conformity assessment, contract terms, and standards status.

- 12 items

### [EU Data Act Third-Party Data Sharing FAQ](/artifacts/eu/data-act/faq/third-party-data-sharing.md)

FAQ on user-directed third-party data sharing under the EU Data Act, covering data holder duties, recipient limits, trade secrets, security, GDPR, and gatekeepers.

- 12 items

### [EU Data Act Trade Secret Safeguards FAQ](/artifacts/eu/data-act/faq/trade-secrets-safeguards.md)

FAQ on protecting trade secrets when handling EU Data Act user and third-party data access requests, including safeguards, withholding, suspension, refusal, notices, and records.

- 12 items

### [EU Data Act Unfair Contractual Terms FAQ](/artifacts/eu/data-act/faq/unfair-contractual-terms.md)

FAQ on Article 13 of the EU Data Act: B2B unfair contract terms, unilateral take-it-or-leave-it clauses, always-unfair terms, presumed-unfair terms, SMEs, model terms, and review evidence.

- 12 items

### [EU Data Act Users, Data Holders, and Recipients FAQ](/artifacts/eu/data-act/faq/users-data-holders-and-recipients.md)

FAQ explaining Data Act users, data holders, data recipients, connected products, related services, user access, third-party limits, and GDPR boundaries.

- 12 items

### [EU Data Act Vehicle Data Guidance FAQ](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)

FAQ on EU Data Act vehicle data guidance for connected vehicles, aftermarket repair, mobility services, third-party access, trade secrets, security, and GDPR boundaries.

- 12 items

### [EU Data Act: Non-Personal Data and Mixed Datasets](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md)

FAQ on how the EU Data Act treats non-personal data, mixed datasets, GDPR precedence, user and third-party access, trade-secret limits, and evidence records.

- 12 items

Browse all indexed questions: [/artifacts/eu/data-act/faq/items](/artifacts/eu/data-act/faq/items.md)

## All FAQ items

*Page 31 of 32. Showing 15 of 470 items.*

### [How should repair, maintenance, mobility, and aftermarket use cases be handled under the Data Act?](/artifacts/eu/data-act/faq/vehicle-data-guidance.md#how-should-repair-maintenance-mobility-and-aftermarket-use-cases-be-handled-under-the-data-act)

*Module: [EU Data Act Vehicle Data Guidance](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)*

Start with the vehicle-data field, not the market label. The Data Act can support access to readily available vehicle data for aftermarket uses, but the guidance also explains that the Data Act does not create access rights to vehicle functions or resources.

- For repair and maintenance, separate data access from access to vehicle functions, resources, or commands.
- For mobility services, identify whether the service only uses data or also affects vehicle operation through a related service.
- For aftermarket access, compare the requested data and interface with what the data holder uses or gives to authorised channels, including completeness and whether the data are up to date.

Sources for this answer:

- [Commission guidance on vehicle data - Official Journal](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) - Addresses aftermarket service providers, independent repair shops, access quality, and the boundary between vehicle data and vehicle functions.
- [European Commission - Data Act FAQs v1.4](https://ec.europa.eu/newsroom/dae/redirection/document/108144?ref=sorena.io) - Explains that users can access and use connected-product data and share it with third parties to provide services.

### [Does the Data Act always require direct access through the vehicle?](/artifacts/eu/data-act/faq/vehicle-data-guidance.md#does-the-data-act-always-require-direct-access-through-the-vehicle)

*Module: [EU Data Act Vehicle Data Guidance](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)*

No. Direct access under Article 3 applies where relevant and technically feasible. If users cannot access data directly from the vehicle, the data holder must provide indirect access to readily available data under Article 4 and make readily available data accessible to a third party at the user's request under Article 5.

- Record the vehicle's Union placing-on-the-market date and distinguish the 12 September 2025 request rights from the post-12 September 2026 Article 3(1) design trigger.
- Document whether the route is direct user access, indirect access through the data holder, or third-party access at the user's request.
- If using an OBD-II route, do not require the user to buy a specialised tool or have advanced technical skills.
- If using a backend or API route, check that it does not make the data less accurate, complete, reliable, relevant, or up to date than what the data holder has.

Sources for this answer:

- [Commission guidance on vehicle data - Official Journal](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) - Clarifies direct access, indirect access, third-party access, OBD-II access, technology neutrality, and same-quality access.
- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Sets the Chapter II access duties in Articles 3, 4, and 5 for product and related service data.

### [How do trade secrets, safety, and cybersecurity affect vehicle-data access under the Data Act?](/artifacts/eu/data-act/faq/vehicle-data-guidance.md#how-do-trade-secrets-safety-and-cybersecurity-affect-vehicle-data-access-under-the-data-act)

*Module: [EU Data Act Vehicle Data Guidance](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)*

Trade-secret and security concerns should be handled as specific safeguards, not as blanket refusals. The Data Act contains mechanisms for protecting trade secrets and allowing appropriate technical and organisational measures, while the vehicle guidance stresses that access still has to remain easy and non-discriminatory.

- Use field-level controls, access conditions, logging, authentication, and recipient commitments where they address the real risk.
- Escalate refusals or heavy limitations to legal, cybersecurity, safety, and product owners before communicating them externally.
- Avoid unsupported statements that all diagnostic, location, or component-status data is too sensitive to share.

Sources for this answer:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Contains the Data Act trade-secret protection mechanism and competent-authority complaint context.
- [European Commission - Data Act FAQs v1.4](https://ec.europa.eu/newsroom/dae/redirection/document/108144?ref=sorena.io) - Explains that the Data Act does not modify existing trade-secret protections and adds a trade-secret protection mechanism.
- [Commission guidance on vehicle data - Official Journal](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) - Connects automotive implementation with interoperability, security, fair competition, and non-discriminatory access quality.

### [Where is the GDPR boundary for connected vehicle data under the Data Act?](/artifacts/eu/data-act/faq/vehicle-data-guidance.md#where-is-the-gdpr-boundary-for-connected-vehicle-data-under-the-data-act)

*Module: [EU Data Act Vehicle Data Guidance](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)*

The Data Act does not supersede the GDPR. Where vehicle data is personal data, GDPR rules apply to the processing, and the Commission FAQs state that GDPR rules on personal-data protection prevail in the event of conflict.

- Classify each field as personal, non-personal, or mixed before release.
- Check whether the requesting user is the data subject or whether another GDPR legal basis is needed.
- Keep the GDPR assessment separate from the Data Act scope assessment so neither one hides the other.

Sources for this answer:

- [European Commission - Data Act FAQs v1.4](https://ec.europa.eu/newsroom/dae/redirection/document/108144?ref=sorena.io) - Clarifies that the GDPR applies to personal-data processing under the Data Act and prevails where personal-data rules conflict.
- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Preserves GDPR application and assigns personal-data monitoring to data-protection supervisory authorities.
- [Commission guidance on vehicle data - Official Journal](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) - States that the vehicle guidance does not affect application of the GDPR.

### [Which adjacent automotive rules should be checked under the Data Act?](/artifacts/eu/data-act/faq/vehicle-data-guidance.md#which-adjacent-automotive-rules-should-be-checked-under-the-data-act)

*Module: [EU Data Act Vehicle Data Guidance](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)*

The vehicle guidance is limited to the Data Act. It does not interpret or displace sector-specific automotive rules, including the Type Approval Regulation, rules on on-board diagnostics information or vehicle emissions data, competition rules for motor vehicle repair and spare parts, or other sector guidance.

- Check sector rules for OBD information, vehicle emissions data, roadworthiness testing information, repair information, and spare-parts distribution issues.
- Use the Data Act for product data and related service data access where no more specific rule controls the exact question.
- Document which rule controls each field, interface, recipient, and refusal or limitation reason.

Sources for this answer:

- [Commission guidance on vehicle data - Official Journal](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) - Identifies sector-specific automotive laws and other EU rules that the guidance does not interpret or affect.
- [European Commission - Data Act FAQs v1.4](https://ec.europa.eu/newsroom/dae/redirection/document/108144?ref=sorena.io) - Explains how the Data Act interacts with sector-specific EU data-access rules.

### [What evidence should a vehicle-data access workflow keep under the Data Act?](/artifacts/eu/data-act/faq/vehicle-data-guidance.md#what-evidence-should-a-vehicle-data-access-workflow-keep-under-the-data-act)

*Module: [EU Data Act Vehicle Data Guidance](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)*

Keep a vehicle-data access matrix that lists the data field, vehicle or service source, role map, raw or pre-processed classification, inferred or derived exclusion if relevant, personal-data status, access route, recipient, safeguards, source citation, decision, and delivery or refusal outcome.

- Record the reason when a requested field is excluded as inferred, derived, not readily available, not designed to be retrievable, or controlled by another rule.
- Keep the same-quality check where independent repairers or service providers receive data through a different route than authorised partners.
- Retain escalation records for safety, cybersecurity, trade-secret, and GDPR limitations.

Sources for this answer:

- [Commission guidance on vehicle data - Official Journal](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) - Supports the evidence categories needed for vehicle-data scope, access routes, quality, and limitations.
- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Gives competent authorities information-request powers and complaint-handling roles for Data Act compliance.

### [What source records should teams keep for a Data Act vehicle-data guidance decision for later review?](/artifacts/eu/data-act/faq/vehicle-data-guidance.md#what-source-records-should-teams-keep-for-a-data-act-vehicle-data-guidance-decision-for-later-review)

*Module: [EU Data Act Vehicle Data Guidance](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)*

Keep the source clause, Commission guidance reference, actor role, dataset, request trigger, and approving owner together so the decision can be checked later. A short record is enough if it points to the exact Data Act source and the specific vehicle-data field or workflow that was reviewed.

- Link the decision to a cited Data Act source URL and the relevant vehicle-data field or workflow.
- Store the owner, affected workflow, evidence artifact, and review trigger in the same record.

Sources for this answer:

- [Commission guidance on vehicle data - Official Journal](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) - Primary source for automotive vehicle-data guidance under Chapter II of the Data Act, including scope, examples, access routes, quality, sector-rule boundaries, and aftermarket considerations.
- [European Commission - Vehicle data guidance page](https://digital-strategy.ec.europa.eu/en/library/guidance-vehicle-data-accompanying-data-act?ref=sorena.io) - Commission publication page confirming the guidance is for automotive stakeholders implementing Chapter II.
- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Binding Data Act text for Chapter II actor definitions, access duties, safeguards, GDPR preservation, application from 12 September 2025, and the Article 3(1) design-duty timing.
- [European Commission - Data Act FAQs v1.4](https://ec.europa.eu/newsroom/dae/redirection/document/108144?ref=sorena.io) - Commission FAQ support for raw and pre-processed data, readily available data, connected-product flows, GDPR boundaries, trade secrets, and sector-rule interactions.
- [European Commission - Data Act explained](https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained?ref=sorena.io) - Commission overview for Data Act chapters, connected-product access, B2G requests, cloud switching, interoperability, and implementation support.

### [Which team should own a Data Act vehicle-data guidance implementation task and confirm the fix?](/artifacts/eu/data-act/faq/vehicle-data-guidance.md#which-team-should-own-a-data-act-vehicle-data-guidance-implementation-task-and-confirm-the-fix)

*Module: [EU Data Act Vehicle Data Guidance](/artifacts/eu/data-act/faq/vehicle-data-guidance.md)*

Assign one accountable owner who can actually change the affected process under the Data Act, such as legal, product, procurement, cloud, support, or security. That owner should be the person who can approve the interpretation, coordinate the fix, and confirm the workflow now matches the guidance.

- Name one accountable owner per action.
- Record consulted teams, evidence artifacts, and review triggers separately.
- Use the owner record to follow up on any access, quality, or safeguard change.

Sources for this answer:

- [Commission guidance on vehicle data - Official Journal](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) - Primary source for automotive vehicle-data guidance under Chapter II of the Data Act, including scope, examples, access routes, quality, sector-rule boundaries, and aftermarket considerations.
- [European Commission - Vehicle data guidance page](https://digital-strategy.ec.europa.eu/en/library/guidance-vehicle-data-accompanying-data-act?ref=sorena.io) - Commission publication page confirming the guidance is for automotive stakeholders implementing Chapter II.
- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Binding Data Act text for Chapter II actor definitions, access duties, safeguards, GDPR preservation, application from 12 September 2025, and the Article 3(1) design-duty timing.
- [European Commission - Data Act FAQs v1.4](https://ec.europa.eu/newsroom/dae/redirection/document/108144?ref=sorena.io) - Commission FAQ support for raw and pre-processed data, readily available data, connected-product flows, GDPR boundaries, trade secrets, and sector-rule interactions.
- [European Commission - Data Act explained](https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained?ref=sorena.io) - Commission overview for Data Act chapters, connected-product access, B2G requests, cloud switching, interoperability, and implementation support.

### [What does non-personal data mean under the EU Data Act, and how does it differ from personal data?](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md#what-does-non-personal-data-mean-under-the-eu-data-act-and-how-does-it-differ-from-personal-data)

*Module: [EU Data Act: Non-Personal Data and Mixed Datasets](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md)*

The Data Act defines non-personal data as data other than personal data. Classify by substance and context, not by the dataset label. A machine telemetry export, support log, vehicle dataset, or cloud export can contain non-personal fields alongside fields that identify or relate to a natural person. A field that appears anonymous in isolation can still be personal data when combined with other reasonably available information.

- Classify each field and relevant field combination as personal or non-personal, then separately mark inferred or derived information, trade-secret-sensitive data, and material outside the request.
- Record whether the field is product data, related-service data, relevant metadata, or another data category.
- Do not rely on internal labels such as telemetry, operational data, customer data, or analytics unless the field-level classification is visible.

Sources for this answer:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Defines non-personal data and the key product, related-service, user, data holder, and data recipient terms used for field classification.
- [European Commission - Data Act explained](https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained?ref=sorena.io) - Explains that Chapter II covers raw and pre-processed readily available data, including metadata, and excludes inferred or derived data.

### [Does the EU Data Act override GDPR when a dataset contains both personal and non-personal data?](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md#does-the-eu-data-act-override-gdpr-when-a-dataset-contains-both-personal-and-non-personal-data)

*Module: [EU Data Act: Non-Personal Data and Mixed Datasets](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md)*

No. The Data Act complements EU data-protection and privacy law and must not be interpreted to diminish personal-data rights. When a mixed dataset contains personal data, GDPR, the EU institutions data-protection regulation, and ePrivacy rules continue to control the personal-data processing layer.

- Treat Data Act access and GDPR processing as separate questions that must both be satisfied for personal-data fields.
- If the requester is not the data subject, document the GDPR legal basis before releasing personal data.
- Where possible, separate, anonymise, or limit personal-data fields instead of blocking access to non-personal fields that remain in scope.

Sources for this answer:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - States that the Data Act is without prejudice to data-protection and privacy law and does not create a new legal basis for personal-data collection or generation.
- [European Commission - Data protection overview](https://commission.europa.eu/law/law-topic/data-protection_en?ref=sorena.io) - Provides Commission context that EU personal-data protection is based on GDPR, the Law Enforcement Directive, and the EU institutions data-protection regulation.

### [Which Data Act roles matter when handling non-personal data and mixed datasets?](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md#which-data-act-roles-matter-when-handling-non-personal-data-and-mixed-datasets)

*Module: [EU Data Act: Non-Personal Data and Mixed Datasets](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md)*

The main roles are user, data holder, third party, and data recipient. A user owns a connected product, has a temporary contractual right to use it, or receives a related service. A data holder has the right or obligation under the Data Act, applicable Union law, or qualifying national legislation to use and make data available. A third party established in the Union can receive data at the user's request and may be a data recipient for business-to-business sharing rules.

- Name the user, data holder, third party, data recipient, and any data subject for each request.
- Check whether the relevant organisation is a manufacturer, related-service provider, provider of data processing services, public undertaking, or another party with a Data Act duty.
- Keep the role map with the request log because role errors change the access, sharing, GDPR, and evidence analysis.

Sources for this answer:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Defines user, data holder, data recipient, product data, related-service data, and related Data Act roles.
- [European Commission - Data Act explained](https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained?ref=sorena.io) - Explains Chapter II roles in practice, including users, third parties, and typical data holders for connected products and related services.

### [What mixed-dataset access must a data holder provide to a user under the EU Data Act?](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md#what-mixed-dataset-access-must-a-data-holder-provide-to-a-user-under-the-eu-data-act)

*Module: [EU Data Act: Non-Personal Data and Mixed Datasets](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md)*

Where the user cannot directly access the data from the connected product or related service, the data holder must make readily available data and necessary metadata accessible without undue delay, in the same quality available to the holder, securely, free of charge, and in a comprehensive, structured, commonly used, machine-readable format. Access must be continuous and real-time only where relevant and technically feasible.

- Deliver in-scope non-personal fields and metadata in the required format and quality.
- For personal fields, confirm whether the user is the data subject or has a valid GDPR basis for receiving them.
- Document any excluded field by category: personal-data restriction, inferred or derived data, trade secret, security requirement, unavailable data, or out-of-scope content.

Sources for this answer:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Article 4 sets user access duties for readily available product data, related-service data, and metadata, including format and quality requirements.
- [European Commission - Data Act explained](https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained?ref=sorena.io) - Summarises the Chapter II user-access right and the scope of readily available raw and pre-processed data.

### [Can a user ask the data holder to share a mixed dataset with a third party under the Data Act?](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md#can-a-user-ask-the-data-holder-to-share-a-mixed-dataset-with-a-third-party-under-the-data-act)

*Module: [EU Data Act: Non-Personal Data and Mixed Datasets](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md)*

Yes, but the same boundaries apply. At the user's request, the data holder must make readily available data and relevant metadata available to a third party under the Data Act conditions. A gatekeeper under the Digital Markets Act is not an eligible third party for this user-requested Chapter II sharing route.

- Tie third-party sharing to a specific user request and a stated user-approved purpose.
- Screen the requested recipient for the Data Act gatekeeper exclusion where Chapter II third-party access is used.
- Add recipient controls for purpose limitation, onward sharing, deletion, trade secrets, security, and non-use for competing connected products.

Sources for this answer:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Articles 5 and 6 set user-requested third-party sharing duties, gatekeeper exclusion, GDPR limits, purpose controls, deletion, and onward-sharing restrictions.
- [European Commission - Data Act explained](https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained?ref=sorena.io) - Explains that users may share connected-product data directly or ask the data holder to share it with a third party of their choice, excluding gatekeepers.

### [What are the main boundaries for non-personal data use by data holders and third parties under the Data Act?](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md#what-are-the-main-boundaries-for-non-personal-data-use-by-data-holders-and-third-parties-under-the-data-act)

*Module: [EU Data Act: Non-Personal Data and Mixed Datasets](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md)*

A data holder may use readily available non-personal data only on the basis of a contract with the user. The holder must not use those data to derive insights about the user's economic situation, assets, production methods, or product use in a way that could undermine the user's commercial position.

- Check the user contract before using non-personal product or related-service data internally.
- Separate permitted aftermarket or related-service use from prohibited development of a competing connected product.
- Prohibit commercial insight extraction about the user, data holder, or third party where the Data Act restricts it.

Sources for this answer:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Articles 4 and 6 limit data holder and third-party use of non-personal product and related-service data, including competitive-product and insight restrictions.
- [European Commission - Data Act explained](https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained?ref=sorena.io) - Explains limits on using Data Act data to develop a competing connected product and distinguishes related or aftermarket services.

### [How should trade secrets and security concerns be handled in mixed datasets under the Data Act?](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md#how-should-trade-secrets-and-security-concerns-be-handled-in-mixed-datasets-under-the-data-act)

*Module: [EU Data Act: Non-Personal Data and Mixed Datasets](/artifacts/eu/data-act/faq/non-personal-data-and-mixed-datasets.md)*

Trade secrets are not a blanket reason to deny a Data Act request. The data holder or trade-secret holder must identify protected data, including relevant metadata, and agree proportionate technical and organisational measures with the user or third party. Examples in the Data Act include contractual terms, confidentiality agreements, strict access protocols, technical standards, and codes of conduct.

- Identify trade-secret fields and metadata before applying confidentiality measures.
- Use proportionate safeguards first; reserve withholding, suspension, or refusal for the Data Act conditions that support them.
- Keep the written reason, affected fields, measures requested, measures implemented, and any competent-authority notification.

Sources for this answer:

- [Regulation (EU) 2023/2854 (Data Act)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) - Articles 4 and 5 require trade-secret identification, proportionate confidentiality measures, written substantiation, and competent-authority notification for withholding, suspension, or refusal.
- [European Commission - Data Act explained](https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained?ref=sorena.io) - Explains that trade-secret protection and security restrictions are limitations on access, not broad exemptions from Data Act sharing.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/eu/data-act/faq/items](/artifacts/eu/data-act/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 31 of 32

Pages: [1](/artifacts/eu/data-act/faq/items.md) | [2](/artifacts/eu/data-act/faq/items/page/2.md) | [3](/artifacts/eu/data-act/faq/items/page/3.md) | [4](/artifacts/eu/data-act/faq/items/page/4.md) | [5](/artifacts/eu/data-act/faq/items/page/5.md) | [6](/artifacts/eu/data-act/faq/items/page/6.md) | [7](/artifacts/eu/data-act/faq/items/page/7.md) | [8](/artifacts/eu/data-act/faq/items/page/8.md) | [9](/artifacts/eu/data-act/faq/items/page/9.md) | [10](/artifacts/eu/data-act/faq/items/page/10.md) | [11](/artifacts/eu/data-act/faq/items/page/11.md) | [12](/artifacts/eu/data-act/faq/items/page/12.md) | [13](/artifacts/eu/data-act/faq/items/page/13.md) | [14](/artifacts/eu/data-act/faq/items/page/14.md) | [15](/artifacts/eu/data-act/faq/items/page/15.md) | [16](/artifacts/eu/data-act/faq/items/page/16.md) | [17](/artifacts/eu/data-act/faq/items/page/17.md) | [18](/artifacts/eu/data-act/faq/items/page/18.md) | [19](/artifacts/eu/data-act/faq/items/page/19.md) | [20](/artifacts/eu/data-act/faq/items/page/20.md) | [21](/artifacts/eu/data-act/faq/items/page/21.md) | [22](/artifacts/eu/data-act/faq/items/page/22.md) | [23](/artifacts/eu/data-act/faq/items/page/23.md) | [24](/artifacts/eu/data-act/faq/items/page/24.md) | [25](/artifacts/eu/data-act/faq/items/page/25.md) | [26](/artifacts/eu/data-act/faq/items/page/26.md) | [27](/artifacts/eu/data-act/faq/items/page/27.md) | [28](/artifacts/eu/data-act/faq/items/page/28.md) | [29](/artifacts/eu/data-act/faq/items/page/29.md) | [30](/artifacts/eu/data-act/faq/items/page/30.md) | [31](/artifacts/eu/data-act/faq/items/page/31.md) | [32](/artifacts/eu/data-act/faq/items/page/32.md)

[Previous page](/artifacts/eu/data-act/faq/items/page/30.md) | [Next page](/artifacts/eu/data-act/faq/items/page/32.md)

*Recommended next step*

*Placement: before sources*

## Turn a Data Act FAQ answer into a scoped review

Review one product, dataset, cloud contract, public-sector request, or smart-contract deployment against the cited Data Act source and keep the scope, role, evidence, and unresolved questions together.

- [Open Research Copilot](/solutions/research-copilot.md): Check Data Act scope, GDPR boundaries, cloud switching, and contract questions with cited source outputs.
- [Talk through Data Act implementation](/contact.md): Review one connected product, data-sharing contract, cloud switch, or public-sector request before committing to an implementation path.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/data-act/faq/items/page/31.md
