Loading…
Loading…
The Data Governance Act establishes four interlocking regimes:
Public-sector bodies holding data protected by commercial confidentiality, statistical confidentiality, intellectual-property rights, or personal-data rules may make that data available for re-use under harmonised conditions. Key elements:
searchable register of available data assets and route re-use requests to the competent sectoral body.
re-users are prohibited (or capped at a maximum of 12 months), preventing capture of public data by a single commercial player.
statistical records, trade-secret-protected public contracts) may be made available under conditions ensuring technical protection (anonymisation, aggregation) but only within the EU or to countries that offer equivalent data-protection safeguards (Art 5(12) — extending GDPR-style transfer concerns to non-personal data for the first time at EU level).
Any legal entity providing data-sharing services between data holders and data users (B2B, B2C, or cooperative/data-pooling models) must:
and any own-account data business (prohibiting simultaneous intermediation and use of the data intermediated).
including non-exclusive licences and cost-oriented pricing.
transaction.
The regime creates a new regulated category in EU financial-market terms analogous to AIF or payment-institution licensing — a notification-based operating licence for data-broker and data- marketplace platforms. National competent authorities maintain a public register of notified providers (updated in the European Data Innovation Board cross-border register under Art 29).
Voluntary "recognised data-altruism organisations" (RDAOs) may collect and aggregate data from natural persons and legal entities for general-interest research/innovation purposes. Key elements:
recognition across member states.
overseen by national data-protection authorities to ensure GDPR compliance.
downstream re-use.
data pools, agricultural sensor data aggregation, and smart-city data cooperatives for academic/public-interest users.
Commission-chaired expert group composed of national competent authorities, EDPB, ENISA, and sectoral representatives. Core functions:
standards and semantic-interoperability frameworks.
states.
non-personal data (Art 5(12) assessments).
(European Health Data Space, Agri-Data Space, Finance Data Space, etc.).
The DGA sits in the EU data-economy legislative sequence as:
| Statute | Date | Scope |
|---|---|---|
| GDPR (Reg 2016/679) | 2018-05-25 applicable | Personal data |
| DGA (Reg 2022/868) | 2023-09-24 applicable | Data intermediation + public re-use |
| Data Act (Reg 2023/2854) | 2025-09-12 applicable | Connected-product data access + cloud switching |
The DGA is the parent statute for the common-data-space programme and the foundational governance framework enabling subsequent horizontal (Data Act) and sectoral (EHDS, Open Finance) data-sharing instruments.
in a notification-based regulatory perimeter — compliance overhead comparable to PSD2 for fintechs: new registration obligations, structural-separation requirements, and annual reporting. New entrant barrier but also legitimacy signal for incumbents.
international-transfer constraint on non-personal public-sector data: a government dataset licensed for re-use under the DGA may not flow to a US-based cloud environment without an adequacy finding or technical safeguards — a soft data-localization pressure that compounds the GDPR transfer constraints.
are all predicated on the DGA notification and altruism frameworks as the enabling layer. Delays in EDIB guideline adoption flow through to delays in sectoral space launch timelines.
ecosystems — federated health-data consortia (e.g., 1+Million Genomes initiative), mobility-data cooperatives, and agricultural IoT-data pools now have a formal legal wrapper for cross-border consent aggregation.
incomplete as of mid-2026; the practical boundary between "technical-safeguard" adequacy and formal third-country adequacy decisions for non-personal data is unresolved.
notified data intermediaries has not been tested by a major Commission or national-authority enforcement action; the grey zone between "pure intermediation" and "own-account data use" (especially in AI-training contexts) is live controversy.
obtained national recognition; cross-border registry under EDIB has been slow to operationalise.