Which team should own EU Data Act trade secret safeguard work and keep the measures current over time?
Under the Data Act, one accountable owner should be able to change the access design and the safeguard set, with security, legal, product, and data operations recorded as consulted teams. Spreading the decision across functions without a named owner is how confidentiality measures drift out of date.
The owner should be the person who can approve a new control, update the confidentiality terms, and trigger a fresh review when a product release, API change, or new recipient alters the risk picture.
- Name a single owner who can change both the access design and the confidentiality controls.
- Record security, legal, product, and data operations as consulted rather than co-owners.
- Give the owner authority to trigger a new review when the product, API, or recipient changes.
Articles 4(7), 4(8), 5(10), 5(11), 10, and 37 support written reasons, competent-authority notifications, and challenge routes.
The FAQ lists confidentiality agreements, strict access protocols, technical standards, codes of conduct, and model terms as possible trade secret safeguards.
The Commission explanation confirms that users and third parties can challenge trade secret withholding, suspension, or refusal through courts, competent authorities, or dispute settlement.