FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
470of470items
Across 39 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
Data Act FAQ for Aftermarket Repair and Mobility Services

What access quality must a data holder provide to independent repairers or service providers chosen by the user under the Data Act?

For indirect access under Article 4 and third-party sharing under Article 5, the Data Act requires readily available data to be made available without undue delay, in the same quality available to the data holder, easily, securely, free of charge to the user, in a comprehensive, structured, commonly used and machine-readable format, and where relevant and technically feasible continuously and in real time.

The vehicle-data guidance makes that practical for the automotive sector: access methods can vary, including remote backend access, onboard access, or data intermediation, but the chosen method must not give users or independent service providers lower-quality data than the data holder, subsidiaries, authorised partners, dealers, or authorised repairers receive in comparable circumstances.

  • Compare quality, accuracy, completeness, relevance, and timeliness against the data available to the data holder itself.
  • Avoid access routes that create undue barriers, costs, procedural hurdles, or specialist-tool dependencies for the user or chosen third party.
  • Record any format, latency, API, portal, or onboard-access limitation and the cited reason for it.
Citations
Data Act FAQ for Aftermarket Repair and Mobility Services

Can a manufacturer or data holder refuse aftermarket data access for trade-secret, safety, or security reasons under the Data Act?

A trade-secret label is not enough by itself to block access. The Data Act requires trade secrets to be preserved through proportionate technical and organisational measures, such as confidentiality agreements, strict access protocols, technical standards, model contractual terms, or codes of conduct. Withholding or suspension is possible where measures are not agreed or implemented, and refusal is reserved for exceptional case-by-case situations where serious economic damage is highly likely despite safeguards.

Safety and security are also limited grounds. Article 4 allows users and data holders to restrict or prohibit access or further sharing only where processing could undermine legally laid down security requirements of the connected product and result in a serious adverse effect on health, safety, or security. Decisions to refuse, withhold, or suspend should be reasoned, written, notified to the competent authority where required, and open to challenge through competent authorities, dispute settlement, or courts.

  • Identify the exact trade-secret data or security requirement, rather than relying on broad confidentiality or cybersecurity wording.
  • Choose proportionate controls first; refusal should be reserved for the narrow situations supported by Articles 4 and 5.
  • Keep written reasons, safeguard terms, authority notifications, and the user or third-party challenge route in the request file.
Citations
Data Act FAQ for Aftermarket Repair and Mobility Services

What may a third-party repairer, insurer, fleet provider, or mobility service do with vehicle data it receives under the Data Act?

Article 6 limits third-party use to the purposes and conditions agreed with the user, subject to data-protection law where personal data is involved. The request should therefore state the service purpose: diagnosis, repair estimate, maintenance alert, fleet optimization, insurance product, charging support, leasing service, or another specific use.

The third party may not use the data for prohibited purposes such as developing a competing connected product, making the data available to a Digital Markets Act gatekeeper, using the data for profiling unless necessary to provide the requested service, undermining security, disregarding agreed trade-secret measures, or passing the data onward except on the permitted contractual basis.

  • Tie each data field to the user-agreed service purpose and erase it when no longer necessary unless otherwise agreed for non-personal data.
  • Do not use Article 5 access to build or improve a competing connected product.
  • Prevent onward sharing to gatekeepers and require any permitted onward recipient to maintain agreed trade-secret safeguards.
Citations
Data Act FAQ for Aftermarket Repair and Mobility Services

How should teams handle GDPR when vehicle data contains driver, passenger, or location data under the Data Act?

The GDPR boundary is central. Article 1(5) says the Data Act is without prejudice to EU and national personal-data law, and the Commission FAQ states that GDPR rules prevail in a conflict. The Data Act can complement GDPR access and portability rights, but it is not a free-standing legal basis for giving personal data to a user who is not the data subject or to a third party.

In vehicle contexts, personal data can appear in location data, driving behaviour, user accounts, in-vehicle preferences, and multi-user or rental situations. If the user is not the data subject, the data holder must assess a valid GDPR legal basis, relevant special-category conditions where applicable, and ePrivacy limits where relevant, or provide anonymised data where that is the compliant route.

  • Separate personal data, non-personal data, and mixed datasets before fulfilling an aftermarket or mobility request.
  • Where multiple users or data subjects are involved, avoid exposing another person's personal data without a valid legal basis.
  • Use anonymisation, pseudonymisation, minimisation, and purpose limits where needed, but do not use privacy techniques to evade valid Data Act access rights.
Citations
Data Act FAQ for Aftermarket Repair and Mobility Services

What should an aftermarket vehicle-data request record contain under the Data Act?

A useful request record should support a later complaint, dispute, authority question, or contract review. It should show who the user is, who the third party is, who the data holder is, which vehicle or related service is involved, which data fields and metadata were requested, which fields were delivered or excluded, and why.

For high-volume repair, fleet, insurance, and mobility workflows, maintain an access matrix rather than deciding from scratch each time. The matrix should identify common use cases, standard data categories, GDPR status, trade-secret or security safeguards, access route, expected latency, compensation position for B2B recipients where relevant, refusal or escalation triggers, and evidence owner.

  • Log the user request or user authorisation, recipient identity, requested purpose, data categories, access method, decision, delivery date, and safeguards.
  • Keep written reasons for excluded inferred or derived data, unavailable data, trade-secret restrictions, safety/security restrictions, and personal-data limits.
  • Review the matrix when vehicle architecture, backend storage, partner access, authorised repairer access, service design, or Commission guidance changes.
Citations
Data Act FAQ for Aftermarket Repair and Mobility Services

What Data Act source evidence should teams keep for the Aftermarket Repair and Mobility Services FAQ decision?

For aftermarket repair and mobility services, the Data Act record should keep the cited Article 4, 5, 6, or 7 basis, the Commission vehicle-data guidance reference, the actor role, the data categories affected, the request or contract trigger, and the approver who signed off on the interpretation.

Keep the external source URL, decision date, reviewer, unresolved assumptions, and implementation artifact together so the answer stays auditable when the same repair or mobility case returns later.

  • Link each decision to the specific Data Act clause or vehicle-data guidance passage used.
  • Record the owner, affected workflow, evidence artifact, and any follow-up review date.
  • Store the reasoning for why a field was included, excluded, or treated as in scope or out of scope.
Citations
Data Act FAQ for Aftermarket Repair and Mobility Services

How should teams assign ownership for Data Act Aftermarket Repair and Mobility Services implementation work?

For aftermarket repair and mobility services, the Data Act workflow should name a single accountable owner for each operational change, such as legal, product, procurement, cloud, support, or security.

That owner should coordinate the affected workflow and decision record, while consulting other teams as needed and keeping evidence dependencies separate so implementation can be updated without reopening the whole legal analysis.

  • Assign one owner per action and one backup reviewer for the vehicle-data workflow.
  • Record the teams consulted, the system or contract touched, and the current status of implementation.
  • Tie each ownership record to the same cited Data Act source URL used for the decision.
Citations
Data Act FAQ for Aftermarket Repair and Mobility Services

Which Data Act implementation evidence makes the Aftermarket Repair and Mobility Services answer usable later?

For aftermarket repair and mobility services under the Data Act, the most useful evidence is the material that lets a later reviewer reconstruct the decision without guessing. That usually means the source article or guidance cited, the data inventory or request log, the contract clause or access rule, the security or trade-secret control used, and the approval record.

If the workflow changes, the evidence should show what changed and when. That makes it easier to compare a repair request, fleet request, or mobility-service request across versions instead of re-litigating the same scope question from scratch.

  • Keep source URLs, request logs, contract clauses, technical controls, notices, and approval records in one file set.
  • Note which evidence supports scope, which supports access method, and which supports security or privacy limits.
  • Retain the review trigger and the date of the last substantive decision.
Citations
Data Act FAQ for Aftermarket Repair and Mobility Services

When should the Data Act Aftermarket Repair and Mobility Services FAQ answer be reviewed again by the team?

For aftermarket repair and mobility services, the Data Act answer should be reviewed whenever the product architecture, service model, dataset, customer role, or contract terms change in a way that could change who controls the data or how it is shared.

It should also be revisited when Commission guidance, the vehicle-data implementation approach, or the security and privacy setup changes, because those are the points most likely to affect repair, fleet, insurance, or mobility workflows.

  • Set a review date plus event triggers for product, service, and contract changes.
  • Review again after architecture changes, new data fields, new third-party recipients, or updated compliance guidance.
  • Keep the owner and reviewer on the record so the next review has a clear accountable path.
Citations
Data Act SME Exceptions and Startups

Does the Data Act give startups or SMEs a blanket exemption?

No. The Data Act gives targeted size-based treatment, not a general exemption for startups or SMEs. The answer depends on the chapter, the actor's role, and whether the company is the manufacturer, designer, related-service provider, data holder, data recipient, user, or contracting party.

Startups should not rely on the word startup alone. The binding Chapter II carve-out is framed around microenterprises, small enterprises, and a limited transition for medium-sized enterprises by reference to Commission Recommendation 2003/361/EC, not around venture stage, funding round, age of incorporation, or headcount labels used in sales systems.

Apply both the staff and financial tests to the relevant enterprise data. A microenterprise has fewer than 10 staff and turnover or balance-sheet total of no more than EUR 2 million; a small enterprise has fewer than 50 staff and turnover or balance-sheet total of no more than EUR 10 million; the SME ceiling is fewer than 250 staff and turnover of no more than EUR 50 million or balance-sheet total of no more than EUR 43 million. Then include partner and linked-enterprise data as the Recommendation requires before deciding the category.

  • Use company size only after mapping the Data Act role and chapter.
  • Treat startup status as context, not as a legal exemption by itself.
  • Record whether the question is about Chapter II access, Chapter III compensation, Chapter IV unfair terms, or Chapter V public-sector requests.
  • Retain the reference accounting period, staff calculation, turnover, balance-sheet total, ownership links, partner-enterprise percentages, and linked-enterprise facts used for the size decision.
Citations
Data Act SME Exceptions and Startups

When do micro and small enterprises fall outside Chapter II connected-product access obligations under the Data Act?

Article 7 says Chapter II business-to-consumer and business-to-business access obligations do not apply to data generated through connected products manufactured or designed by a microenterprise or small enterprise, or related services provided by one, when the Article 7 conditions are met.

The carve-out is narrow. It is lost if the micro or small enterprise has a partner or linked enterprise that does not itself qualify as a microenterprise or small enterprise. It also does not apply where the micro or small enterprise is subcontracted to manufacture or design the connected product or provide the related service.

  • Check whether the data comes from the company's own connected product or related service.
  • Check partner and linked-enterprise status, not only the legal entity signing the contract.
  • Check whether the company is acting as a subcontractor for another enterprise's product or service.
Citations
Data Act SME Exceptions and Startups

What transition applies when an enterprise has recently become medium-sized under the Data Act?

Article 7 also gives limited treatment to data generated through connected products manufactured by, or related services provided by, an enterprise that has qualified as medium-sized for less than one year. For connected products, the same treatment applies for one year after the product was placed on the market by the medium-sized enterprise.

This should be managed as a dated transition record, not as a permanent SME exception. The record should show when the enterprise first qualified as medium-sized, which connected products or related services are affected, and when the transition ends for each product or service.

  • Keep the date the enterprise first qualified as medium-sized.
  • Keep the placing-on-the-market date for each affected connected product.
  • Move the product or service into the ordinary Chapter II workflow when the one-year transition no longer applies.
Citations
Data Act SME Exceptions and Startups

Can a micro or small enterprise still have Data Act duties in another role?

Yes. The Chapter II carve-out is not a whole-Regulation exclusion. Recital 41 states that a microenterprise or small enterprise may still be subject to Data Act requirements as a data holder where it is not the manufacturer of the connected product or the provider of related services.

For implementation, avoid writing contract language that says a small supplier is exempt from the Data Act. Write the exact role: for example, small related-service provider for its own service, SME data recipient seeking data under Chapter III, or enterprise challenging a unilaterally imposed data clause under Chapter IV.

  • Do not copy a Chapter II exception into Chapter III, IV, V, cloud switching, or interoperability workflows.
  • Classify the entity separately for each request, contract, and product line.
  • Retain the role analysis with the access request or contract review.
Citations
Regulation (EU) 2023/2854 (Data Act)

Recital 41 explains that micro and small enterprises may still be subject to requirements as data holders outside the protected manufacturer or related-service provider situation.

Data Act SME Exceptions and Startups

How does SME status affect B2B compensation for making data available under the Data Act?

In mandatory B2B data sharing, Article 9 allows agreed compensation to be reasonable and non-discriminatory and to include a margin. The SME protection is on the data-recipient side: if the data recipient is an SME or a not-for-profit research organisation, and it does not have partner or linked enterprises that do not qualify as SMEs, compensation must not exceed the Article 9(2)(a) costs.

The Commission FAQ explains the practical effect: there is no general upper or lower compensation number, but reasonable compensation cannot include a profit margin when the recipient is an SME or a non-profit research organisation. Data holders must also provide enough calculation information for the recipient to assess whether Article 9 is met.

  • Check SME status of the data recipient, not only the data holder.
  • Exclude margin where Article 9(4) caps compensation for an SME recipient.
  • Ask for the compensation calculation basis before accepting a fee as reasonable.
Citations
Data Act SME Exceptions and Startups

Do the unfair contractual terms rules protect only SMEs under the Data Act?

No. Article 13 applies to covered terms unilaterally imposed by one enterprise on another enterprise. The Commission FAQ says Chapter IV does not specifically address SMEs, even though it is expected to particularly support SMEs because they often have weaker negotiating positions.

The rule is about the term and how it was imposed. It covers terms concerning access to and use of data, or liability and remedies for breach or termination of data-related obligations. It does not turn every unfavorable commercial term into a Data Act issue.

  • Confirm that both parties are enterprises.
  • Confirm the term concerns data access, data use, or data-related liability or remedies.
  • Confirm the term was supplied on a take-it-or-leave-it basis or otherwise unilaterally imposed.
Citations
Page 6 of 32