The EU Data Act aims to create a coherent framework for sharing non-personal data in the European Union (EU), which means that organisations and public bodies will be able to store and process non-personal data wherever they choose. The General Data Protection Regulation (GDPR) already provides for the free movement of personal data within the EU. The European Union Data Act is supposed to complement the Data Governance Act and is expected to benefit citizens and both public and private organisations. The European Commission adopted a proposal for the free flow of non-personal data on 23 February 2022.
The act will include measures to curb abuse of imbalances that hinder data sharing in contracts. Small to medium enterprises (SMEs) will be protected against unfair terms that stronger counter-parties impose in their agreements. The Commission will also ensure fairness in the negotiations of data-sharing contracts. There will also be means for public sector bodies to access and use data held by the private sector that is necessary for specific public interest purposes.
A summary of how the EU Data Act will work
There will be more legal certainty about which data is transferrable. By allowing users to transfer their data more easily, the Data Act will give people and businesses more control over the data they generate. This will hopefully lead to increased participation, competition, and innovation in the data economy. The new rules will also set the framework and conditions for customers to effectively switch between different providers of data-processing services in the EU cloud market.
Who will the EU Data Act apply to?
- Manufacturers and providers of connected products or services placed on the market in the EU.
- Users of those products and services (both natural and juristic persons).
- Data holders making data available to data recipients in the EU.
- Public sector bodies and EU institutions and agencies.
- Providers of data processing services offered in the EU.
What kind of data will the EU Data Act apply to?
- Data concerning the performance, use, and environment of products and related services.
- Private sector data that must be available by law.
- Private sector data that forms part of contracts between businesses.
- Any non-personal data held in the EU by providers of data processing services.
Data-sharing
Manufacturers must design their products in a way that makes data easily and securely accessible by default and be transparent about this accessibility. Where data is not directly accessible by a user, a data holder is to make the data available without “undue delay, free of charge and, where applicable, continuously and in real-time.”
Public sector bodies
The EU Data Act describes unique situations where public bodies can get data. Essentially, data holders will make data available to public bodies to prevent, or recover from, a public emergency or where there is an “exceptional need”. Non-compliance by a data holder could result in penalties. Micro, small and medium-sized companies are exempted from some obligations. In practice, it could be difficult to determine which circumstances require data sharing to respond to a public emergency. We are yet to see the standard that will apply when making this decision. The European Union Data Act is a step towards a single digital market in the EU. According to the European Commission, it is also fully consistent with and builds on GDPR rules.
Do South African organisations need to comply?
If you’re a South African company providing data processing services in the EU, do you need to comply with the Data Act? The act does provide some guidance when it comes to territories outside of the EU.
Third countries that require a provider of data processing services to transfer non-personal data within the EU must do so within the scope of the act or according to an international agreement. In the absence of an international agreement, transfer will only take place if the competent court or tribunal has authority under the law of that country, to make findings about the legal interests of the provider of the data protected by Union law or national law of the relevant Member State. Third countries can also adopt laws and regulations that are aimed directly at transferring or providing governmental access to non-personal data located outside their borders, including in the EU.
Actions you can take:
- Learn more about the EU Data Act by reading a summary by the European Commission or downloading the full text.
- Learn more about data law and find out how we can help you by reading more about data or information law.
- Comply with access to information or freedom of information laws by joining the Michalsons access to information programme.
- Keep up to date with data protection regulations and decisions by joining the Michalsons data protection programme. You can also book a complimentary programme tour with our programme manager.