How do public-sector requests change the treatment of non-personal data and mixed datasets under the Data Act?
Chapter V is separate from ordinary user and third-party access. Public-sector bodies, the Commission, the European Central Bank, and Union bodies may request data from legal-person data holders because of an exceptional need, but the request must be limited in time and scope and tied to statutory duties in the public interest.
For public emergencies, Article 17 requires the requester to start with non-personal data and demonstrate that those data are insufficient before requesting personal data in pseudonymised form with protection measures. Article 18 requires the holder to anonymise requested data unless compliance requires personal-data disclosure, in which case the holder must pseudonymise them. Non-emergency exceptional-need requests are limited to non-personal data and require exhaustion of other means.
- Separate Chapter V public-sector requests from Chapter II user or third-party requests.
- For emergency requests, record why non-personal data is sufficient or why personal data is necessary and anonymisation is or is not possible.
- For non-emergency requests, verify that the request is for non-personal data and that the requester has documented the public-interest task and failed alternatives.
Articles 14 and 15 define exceptional-need requests and limit non-emergency exceptional-need requests to non-personal data.
Explains Chapter V emergency and non-emergency handling, including the focus on non-personal data and anonymisation where possible.