FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
470of470items
Across 39 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 6, 2026
Updated
Jul 25, 2026
Data Act SME Exceptions and Startups

What contract evidence should an SME keep when challenging an unfair data term under the Data Act?

Keep evidence that the challenged clause is in Article 13 scope: the contract, negotiation history, requested changes, the final refused or imposed wording, and the link between the clause and data access, data use, or data-related liability or remedies.

Then classify the term. Some terms are always unfair under Article 13(4), such as excluding liability for intentional acts or gross negligence by the imposing party. Others are presumed to be unfair under Article 13(5), such as inappropriate remedy limits, significantly detrimental access to the other party's data, or unilateral changes to substantive data-sharing conditions without a valid reason and termination right.

  • Save the imposed clause and any attempted negotiation.
  • Mark whether the issue is an Article 13(4) always-unfair term or an Article 13(5) presumed-unfair term.
  • If the imposing party disputes the issue, preserve the record for a competent authority, court, or agreed dispute settlement body.
Citations
Data Act SME Exceptions and Startups

How do micro and small enterprise rules work for public-sector exceptional-need requests under the Data Act?

Chapter V has a different size rule. Article 15(2) says the non-emergency exceptional-need route in Article 15(1)(b) does not apply to microenterprises and small enterprises. A non-emergency public-sector request under that route is therefore not an ordinary obligation for a micro or small company.

For public emergencies, Article 20 treats micro and small enterprises differently on compensation. Data holders other than micro and small enterprises must make data necessary for public-emergency response available free of charge, but Article 20(3) allows the fair-compensation rule to apply where a microenterprise or small enterprise claims compensation.

  • Separate public emergency requests from other exceptional-need requests.
  • For non-emergency Article 15(1)(b) requests, check whether the data holder is micro or small.
  • For public-emergency requests to micro or small enterprises, preserve compensation calculations and any acknowledgement request.
Citations
Data Act SME Exceptions and Startups

How should teams document SME status and startup treatment in a Data Act status file?

Create one status file per Data Act workflow, not one generic SME certificate for the whole company. The useful record names the legal entity, partner and linked-enterprise position, Data Act role, affected product or related service, data request or contract, chapter relied on, date of status review, and source used.

For startup teams, the record should also note that startup status is not itself a legal category in the Data Act. The practical question is whether the entity qualifies as a microenterprise, small enterprise, or medium-sized enterprise under Commission Recommendation 2003/361/EC, and whether the Article 7 or Article 9 conditions actually apply.

  • Keep one record for Chapter II product and related-service treatment.
  • Keep one record for Chapter III compensation decisions and any SME recipient cap.
  • Keep one record for Chapter IV contract reviews and the unfair-term analysis.
Citations
Data Act SME Exceptions and Startups

Which source records should support an SME or startup decision?

For SME exceptions and startups, the Data Act record should identify the source clause, Commission guidance, actor role, dataset, request or contract trigger, and the owner who approved the interpretation.

For SME exceptions and startups, keep the cited external URL, decision date, reviewer, unresolved assumptions, and implementation artifact together so the answer remains auditable.

  • Map the SME exceptions and startups decision to a cited Data Act source URL.
  • Store the owner, affected workflow, evidence artifact, and review trigger.
Citations
Data Act SME Exceptions and Startups

How should teams assign ownership for Data Act SME exceptions and startup treatment?

For SME exceptions and startups, the Data Act workflow should name the legal, product, procurement, cloud, support, or security owner who can change the affected process.

For SME exceptions and startups, use one accountable owner per action, then record consulted teams and evidence dependencies separately.

  • Map the SME exceptions and startups decision to a cited Data Act source URL.
  • Store the owner, affected workflow, evidence artifact, and review trigger.
Citations
Data Act SME Exceptions and Startups

Which evidence makes an SME or startup decision reviewable?

For SME exceptions and startups, the Data Act evidence should be concrete enough for a later reviewer to reconstruct why the team classified the product, service, request, or contract in scope.

For SME exceptions and startups, useful evidence includes source URLs, data inventories, contract clauses, request logs, technical controls, customer notices, and approval records.

  • Map the SME exceptions and startups decision to a cited Data Act source URL.
  • Store the owner, affected workflow, evidence artifact, and review trigger.
Citations
Data Act Trade Secret Technical Protection Measures

Can an EU Data Act data holder use trade secrets to block product or related service data access?

Not as a blanket answer. Articles 4 and 5 preserve trade secrets, but they require the data holder or trade secret holder to identify the protected data and agree necessary, proportionate technical and organisational measures before disclosure. The Commission FAQ is explicit that a trade secret claim by itself is not enough to defeat Data Act access rights.

For implementation, treat trade secret protection as a scoped safeguard process: identify the exact data fields or metadata that reveal the secret, decide whether access is to the user or to a third party, and define the controls that preserve confidentiality while leaving the Data Act access route available.

  • Do not mark an entire export, API, log stream, or dataset as unavailable without identifying the trade secret elements.
  • Record whether the issue arises under Article 4 user access or Article 5 sharing with a third party, because the recipient and challenge route differ.
  • Separate trade secret protection from personal data, product security, and competitive-use restrictions so each limit has its own legal basis and evidence.
Citations
Data Act Trade Secret Technical Protection Measures

What technical and organisational measures can protect trade secrets under the EU Data Act?

The Data Act points to proportionate technical and organisational measures such as model contractual terms, confidentiality agreements, strict access protocols, technical standards, and codes of conduct. Article 11 also allows technical protection measures, including smart contracts and encryption, to prevent unauthorised access or disclosure and to support compliance with Articles 4, 5, 6, 8, and 9.

Useful measures are specific to the access path. Examples include field-level redaction, role-based access, secure API authentication, encryption at rest and in transit, read-only workspaces, recipient access logs, download limits, time-bound credentials, confidentiality undertakings, and controls on onward disclosure. The measure should preserve confidentiality without discriminating between recipients or hindering the user right to obtain, retrieve, use, or share data.

Users, third parties, and data recipients must not alter or remove Article 11 controls without the data holder's agreement. If a recipient obtains data through deception or coercion, uses it for an unauthorised purpose, discloses it unlawfully, fails to maintain agreed trade-secret safeguards, or removes protection measures without agreement, Article 11 can require erasure, cessation of specified goods or services where the legal test is met, notice to the user, and compensation.

  • Tie each measure to a named risk: exposure of a formula, calibration logic, production method, model feature, supplier know-how, or confidential process.
  • Show why the measure is proportionate: enough to protect the secret, but not more restrictive than needed for the requested access.
  • Keep the access design usable: a technical protection measure should not become a disguised refusal or an unreasonable access barrier.
  • Record any agreed removal or change to an Article 11 control and preserve the evidence for any misuse remedy requested under Article 11(2)-(4).
Citations
Data Act Trade Secret Technical Protection Measures

What should teams document when they rely on EU Data Act trade secret safeguards or technical protection measures?

Under the Data Act, the record should show what data was requested, which parts were identified as trade secrets, which proportionate measures were agreed, who must implement them, and how the data was delivered. If the holder withholds or suspends sharing, it should also document the missing agreement, the unimplemented measure, or the confidentiality incident, plus the written reasons and authority notification required by Articles 4 and 5.

If the holder refuses access in exceptional circumstances, the record should also include the objective evidence supporting serious economic damage, the specific data refused, and why the agreed technical and organisational measures were still insufficient.

  • Keep the written decision and the evidence trail together so the record is usable for a complaint, court review, or dispute settlement.
  • Store the exact trade-secret fields or metadata that were protected, not just a generic label such as confidential data.
  • Retain the notification sent to the competent authority and the user or third party without undue delay.
Citations
European Commission - Data Act Explained

The Commission explanation confirms that users and third parties can challenge trade secret withholding, suspension, or refusal through courts, competent authorities, or dispute settlement.

Data Act Trade Secret Technical Protection Measures

When may a data holder withhold data while trade secret measures are agreed under the EU Data Act?

A data holder may withhold or suspend the identified trade-secret data where necessary safeguards cannot be agreed, the user or third party fails to implement agreed measures, or confidentiality is breached. The holder must give a duly substantiated written decision without undue delay and notify the competent authority. Withholding or suspension is a narrow response to the safeguard failure, not the default response to a trade-secret claim.

The decision should be tied to a concrete failure: a missing confidentiality agreement, an unimplemented control, or an actual breach. The holder must still keep the access route open once the safeguard is in place again, because suspension is meant to be temporary and proportionate to the risk.

  • Document the specific safeguard that was not implemented before treating sharing as suspended.
  • Send written reasons to the user or third party and notify the competent authority without undue delay.
  • Reopen access once the agreed measure is implemented; do not convert a suspension into a permanent block.
Citations
European Commission - Data Act Explained

The Commission explanation confirms that users and third parties can challenge trade secret withholding, suspension, or refusal through courts, competent authorities, or dispute settlement.

Data Act Trade Secret Technical Protection Measures

When can refusal of access be justified in exceptional cases under the EU Data Act trade secret rules?

Under the Data Act, a data holder that is also the trade-secret holder may refuse a specific request only in exceptional circumstances, where it demonstrates with objective evidence that disclosure is highly likely to cause serious economic damage despite the agreed technical and organisational measures. Refusal must be assessed per request and supported by demonstrable, case-specific reasoning.

This is a high bar. A generic concern about competition or a broad assertion that all telemetry is sensitive will not meet it. The holder should show why the agreed safeguards were insufficient for that particular data and recipient, and keep the refusal scoped to the data that actually carries the risk.

  • Limit any refusal to the precise data fields that would cause serious economic damage if disclosed.
  • Keep objective evidence of likely serious economic damage rather than a general competitive worry.
  • Notify the competent authority of the refusal and preserve the user or third-party challenge route.
Citations
European Commission - Data Act Explained

The Commission explanation confirms that users and third parties can challenge trade secret withholding, suspension, or refusal through courts, competent authorities, or dispute settlement.

Data Act Trade Secret Technical Protection Measures

How do technical protection measures interact with third-party sharing under the EU Data Act?

Under the Data Act, technical protection measures applied under Article 11 must not be used to prevent a user from exercising the right to share readily available data with a third party, and must not discriminate between data recipients. The same controls that protect a trade secret in user access should carry through to the third-party path under Article 5.

When data goes to a third party, the confidentiality undertakings, access controls, and onward-disclosure limits should bind that recipient as well. The third party is also restricted by Article 6 from using the data to develop a competing connected product or to share it onward outside agreed terms.

  • Carry confidentiality controls into the third-party agreement, not only the user-facing access path.
  • Bind the third party to Article 6 use restrictions and onward-sharing limits in writing.
  • Avoid measures that single out particular recipients or make the sharing right impractical to use.
Citations
European Commission - Data Act Explained

The Commission explanation confirms that users and third parties can challenge trade secret withholding, suspension, or refusal through courts, competent authorities, or dispute settlement.

Data Act Trade Secret Technical Protection Measures

How should trade secret safeguards be coordinated with personal data rules under the EU Data Act?

Under the Data Act, trade secret protection is a separate question from personal data protection, and both can apply to the same export. The Regulation is without prejudice to the GDPR, so a confidentiality control that protects a secret does not remove the need for a valid legal basis when the same dataset contains personal data.

In practice, run the two analyses in parallel: identify the trade secret elements and the proportionate measures, and separately identify the personal data and the GDPR basis, minimisation, and recipient duties. Keep the two records distinct so each limit has its own justification.

  • Classify each field for both trade secret sensitivity and personal data content before disclosure.
  • Apply a GDPR basis and minimisation to personal data even when trade secret controls are already in place.
  • Keep the trade secret record and the data protection record separate so neither limit is over-applied.
Citations
European Commission - Data Act Explained

The Commission explanation confirms that users and third parties can challenge trade secret withholding, suspension, or refusal through courts, competent authorities, or dispute settlement.

Data Act Trade Secret Technical Protection Measures

Which controls help keep EU Data Act trade secret measures proportionate rather than over-restrictive?

Under the Data Act, technical and organisational measures must be necessary and proportionate, so the right control is the least restrictive one that still protects the identified secret. A measure that effectively blocks all access, or that is far broader than the risk, can itself breach the prohibition on hindering Data Act access rights.

Proportionality is easier to demonstrate when the control is matched to a named risk and a named data element. Field-level redaction, scoped credentials, and recipient confidentiality undertakings are usually more defensible than a blanket refusal to expose an entire interface.

  • Match each control to a specific protected element rather than the whole dataset or interface.
  • Prefer scoped, reversible controls over measures that make the access right impractical.
  • Review whether a less restrictive control would still protect the secret before applying a stronger one.
Citations
European Commission - Data Act Explained

The Commission explanation confirms that users and third parties can challenge trade secret withholding, suspension, or refusal through courts, competent authorities, or dispute settlement.

Data Act Trade Secret Technical Protection Measures

What source evidence should teams keep for an EU Data Act trade secret protection decision later?

Under the Data Act, the evidence file should let a later reviewer rebuild the decision: the Article 4, 5, or 11 basis relied on, the identified trade secret fields, the agreed measures, the delivery method, and any withholding, suspension, or refusal record. Each factual claim about scope or risk should map to a cited source.

The record should also capture the date of the decision, the assumptions made about the recipient, and the controls actually implemented, so the file remains auditable if the product, contract, or data flow later changes.

  • Map the protection decision to a cited Data Act source URL and the specific article relied on.
  • Store the identified secret fields, agreed measures, and the implemented controls together.
  • Record the decision date and recipient assumptions so the file can be rechecked after changes.
Citations
European Commission - Data Act Explained

The Commission explanation confirms that users and third parties can challenge trade secret withholding, suspension, or refusal through courts, competent authorities, or dispute settlement.

Page 7 of 32