What does non-personal data mean under the EU Data Act, and how does it differ from personal data?
The Data Act defines as data other than . Classify by substance and context, not by the dataset label. A machine telemetry export, support log, vehicle dataset, or cloud export can contain non-personal fields alongside fields that identify or relate to a natural person. A field that appears anonymous in isolation can still be personal data when combined with other reasonably available information.
For connected products and related services, the Data Act access analysis should start with raw and pre-processed data that is readily available to the data holder, plus metadata needed to interpret and use it. Inferred or derived information, highly enriched outputs, protected content, and material outside the connected-product or related-service boundary should be marked separately instead of silently included.
- Classify each field and relevant field combination as personal or non-personal, then separately mark inferred or derived information, trade-secret-sensitive data, and material outside the request.
- Record whether the field is product data, related-service data, relevant metadata, or another data category.
- Do not rely on internal labels such as telemetry, operational data, customer data, or analytics unless the field-level classification is visible.
Defines non-personal data and the key product, related-service, user, data holder, and data recipient terms used for field classification.
Explains that Chapter II covers raw and pre-processed readily available data, including metadata, and excludes inferred or derived data.