Law360 – What to expect from EU's Data Governance Act
By Alain Strowel, Ophélie Snoy and Solène Festor (November 21, 2022)
The European Commission’s 2020 European Strategy for Data aims to establish an EU data marketplace for both personal and non-personal information, positioning data as essential for innovation and artificial intelligence development.
The Data Governance Act (DGA), adopted by the European Parliament and Council on May 30 and published as Regulation 2022/868 on June 3, takes effect September 24, 2023, except for data intermediation service requirements which enter force two years later.
Three main objectives
The DGA addresses three key areas:
- Improving reuse conditions for public sector data not classified as open data under the 2019/1024 Open Data Directive;
- Establishing frameworks for data intermediation services, a new digital intermediary category, including notification and supervision systems;
- Setting registration rules for non-profit entities collecting data for altruistic purposes.
Relation with existing legislation
The DGA complements rather than replaces existing frameworks including GDPR, electronic privacy directives, and open data rules. “In case of conflict between the DGA and the GDPR, the GDPR prevails,” per Article 1.
Three sets of applicable rules
Public sector bodies
Public sector entities holding valuable data must grant access under “non-discriminatory, transparent, proportionate and objectively justified conditions.” They may employ anonymisation, randomisation, aggregation techniques, or request consent to protect sensitive information while enabling data reuse.
Public bodies can verify reuser processing, require confidentiality agreements, and charge proportionate fees with discounts for research or SMEs. Member states must establish one-stop-shop interfaces referencing available data resources.
Data intermediation services
These operators facilitate commercial relationships between data holders and users through marketplaces and pools. They must:
- Remain independent legal entities separate from other services;
- Refrain from repurposing shared data;
- Ensure fair, non-discriminatory access terms;
- Avoid conditioning intermediation services on using other offerings;
- Guarantee interoperability with competing intermediaries;
- Implement security measures for non-personal data comparable to GDPR standards for personal data.
Providers undergo national notification procedures and may earn the “DIS provider recognised in the Union” certification label.
Data altruism organisations
Non-profits can voluntarily collect personal and non-personal data for general interest purposes like healthcare, climate action, or mobility improvement. They must operate on a not-for-profit basis, maintain independence from for-profit entities, functionally separate altruism activities, and comply with forthcoming Commission rulebooks.
Data transfers of non-personal data
Safeguards protect rights regarding personal and non-personal data transfers internationally. Model contractual clauses could certify adequate third-country protections, similar to personal data frameworks.
Governance and next steps
Member states designate competent authorities monitoring compliance with potential “effective, proportionate and dissuasive fines.” The European Data Innovation Board assists the Commission in policy development and promoting interoperability standards.
The DGA establishes foundational data governance while implementation challenges remain uncertain, particularly regarding compliance burdens and clarification on intermediation service definitions.