FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
470of470items
Across 39 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
EU Data Act: Non-Personal Data and Mixed Datasets

How do public-sector requests change the treatment of non-personal data and mixed datasets under the Data Act?

Chapter V is separate from ordinary user and third-party access. Public-sector bodies, the Commission, the European Central Bank, and Union bodies may request data from legal-person data holders because of an exceptional need, but the request must be limited in time and scope and tied to statutory duties in the public interest.

For public emergencies, Article 17 requires the requester to start with non-personal data and demonstrate that those data are insufficient before requesting personal data in pseudonymised form with protection measures. Article 18 requires the holder to anonymise requested data unless compliance requires personal-data disclosure, in which case the holder must pseudonymise them. Non-emergency exceptional-need requests are limited to non-personal data and require exhaustion of other means.

  • Separate Chapter V public-sector requests from Chapter II user or third-party requests.
  • For emergency requests, record why non-personal data is sufficient or why personal data is necessary and anonymisation is or is not possible.
  • For non-emergency requests, verify that the request is for non-personal data and that the requester has documented the public-interest task and failed alternatives.
Citations
EU Data Act: Non-Personal Data and Mixed Datasets

What should cloud and data-processing-service teams know about non-personal data under the Data Act?

The Data Act also contains rules for data processing services and international governmental access to non-personal data held in the Union. Providers of data processing services must take adequate technical, organisational, and legal measures, including contracts, to prevent third-country governmental access or transfer of non-personal data where it would conflict with Union or Member State law.

This cloud rule should not be confused with connected-product user access. It is a separate control for providers of data processing services and is relevant when a cloud provider receives a third-country decision or request concerning non-personal data held in the EU.

  • Classify whether the workflow is connected-product access, cloud switching, or third-country governmental access.
  • For third-country governmental access, keep the request, legal basis, conflict assessment, minimisation decision, customer notice analysis, and any national-authority consultation.
  • Do not use cloud-access rules to narrow a user's Chapter II access to connected-product data.
Citations
EU Data Act: Non-Personal Data and Mixed Datasets

What evidence should teams keep for Data Act non-personal data and mixed-dataset decisions?

Keep evidence that proves the classification and the outcome, not a generic compliance memo. The minimum useful record is a field-level data inventory, the Data Act role map, the requester and recipient identity checks, the GDPR basis or exclusion for any personal-data fields, and the final delivery or refusal file.

For each excluded or limited field, preserve the reason and source: outside product or related-service data, not readily available, inferred or derived, personal-data restriction, trade secret, security requirement, public-sector-request condition, cloud third-country access rule, or other Union or national law. The record should let a reviewer understand what was delivered, what was withheld, why, who approved it, and what was communicated.

  • Keep the data dictionary, request log, role map, field classification, recipient purpose, and delivery manifest together.
  • Attach GDPR, anonymisation, trade-secret, security, and third-country-access assessments only where those issues affected the result.
  • Store written substantiation and competent-authority or dispute records for withholding, suspension, refusal, or challenged restrictions.
Citations
Regulation (EU) 2023/2854 (Data Act)

Supports evidence fields for user access, third-party sharing, GDPR limits, trade-secret measures, security restrictions, technical protection measures, and dispute routes.

EU Data Act: Non-Personal Data and Mixed Datasets

What source evidence should teams keep for a Data Act mixed-dataset decision?

For mixed datasets, the decision record should point to the exact Data Act article or recital, the Commission guidance used, the actor role, and the specific dataset or workflow reviewed. That makes it easier to explain why some fields were shared, some were excluded, and which law controlled each part of the decision.

Keep the cited source URL, decision date, reviewer, unresolved assumptions, and implementation artifact together so the page remains auditable and easy to update when the underlying Data Act process changes.

  • Map the mixed-dataset decision to a cited Data Act source URL.
  • Store the owner, affected workflow, evidence artifact, and review trigger.
  • Keep article-level references with the field-level inventory so reviewers can connect the rule to the decision.
Citations
Regulation (EU) 2023/2854 (Data Act)

Supports evidence fields for user access, third-party sharing, GDPR limits, trade-secret measures, security restrictions, technical protection measures, and dispute routes.

EU Data Act: Non-Personal Data and Mixed Datasets

Which team should own a Data Act mixed-dataset implementation decision and keep it current over time?

For mixed datasets, the Data Act workflow should name the legal, product, procurement, cloud, support, or security owner who can change the affected process. The owner should be the person who can approve the field-level classification, route any GDPR or trade-secret review, and close the request with a documented outcome.

For mixed datasets, use one accountable owner per action, then record consulted teams and evidence dependencies separately so the handoffs remain clear if the decision is reviewed later.

  • Assign one accountable owner for the classification and one for the response if the workflow spans multiple teams.
  • Record the legal, product, procurement, cloud, support, and security inputs alongside the final decision.
  • Keep the owner with the cited Data Act source URL and the request log so the decision can be reproduced.
Citations
Regulation (EU) 2023/2854 (Data Act)

Supports evidence fields for user access, third-party sharing, GDPR limits, trade-secret measures, security restrictions, technical protection measures, and dispute routes.

Page 32 of 32
Previous1...303132Next