In February 2022, the EU Commission has published the Data Act, a regulation proposal to harmonize the rules for access to and use of data by companies, public authorities and individuals themselves. This new piece of regulation would be part of the European wider Data Strategy which aims at creating a single market for data that will ensure Europe’s global competitiveness and data sovereignty (among which, the Common European data spaces and the EU Data Governance Act released in December 2021).
This text aims to address the underutilization of European data (mainly due to lack of clarity regarding who can use and access data generated by connected products and who can create value from it, and to the unbalanced position of strong market players versus SMEs in the data industry), in a context where the IoT ecosystem has never been so flourishing and where there has never been so much data to leverage.
It aims to give individuals and companies greater control over their data, so that the data generated can be easily copied or transferred to them or to third parties, allowing to generate value from it and to benefit from a more competitive data market. It also defines a framework for use of this date by public bodies in specific cases and proposes new rules to make it easier to switch cloud services.
For once, it’s not all about personal data
The proposal covers all types of data generated by physical products (and related software) that obtain, generate or collect, through their components, data relating to their performance, use or environment and that are capable of communicating such data through a publicly available electronic communications service – the “Internet of Things”. We are talking, among others, vehicles, household equipment and consumer goods, medical and healthcare devices, or agricultural and industrial machinery.
Two precisions limit the scope of this definition: first, the information derived or inferred from this data, where lawfully held, should not be considered within scope of this Regulation. Second, data generated by computers, servers, tablets and smartphones, cameras, webcams, sound recording systems and text scanners are not in the scope.
Main objectives
Private sector
The proposed regulation imposes obligations on the data holder – i.e. the product manufacturer – who collects the data generated by its products and has the ability to make some available.
It is worth being noted that (i) SMEs are not considered being data holders pursuant to the Regulation and are exempt from the below obligations, provided, however, that these privileged companies are not economically dependent on larger companies which are not exempt; and (ii) on the contrary, companies providing core platform services that are particularly large and influential (“gatekeepers”, as defined in the proposed Digital Markets Act) are not eligible third parties to receive data on a user’s request.
A data holder (e.g. a car, vocal assistant or home automation product manufacturer) is required to:
- Implement availability by design while manufacturing its products so that the data are easily accessible. This includes an obligation of precontractual information to be provided to the user.
- Share data with the user (e.g. the car owner, the physical customer or the owner of a building) and/or with a third party (e.g. an insurance company; a SME providing maintenance services on vocal assistants; or a startup providing energy data management and reporting services) upon user’s request, including continuously and in real time if required.
- When doing so, conclude fair, clear and non-discriminatory terms: B2B agreement concerning access and use of data which has been unilaterally imposed by a data holder on a SME shall not be binding. The regulation contains a list of unfair terms and standard clauses from the European Commission are expected.
To maintain incentives for manufacturers to continue investing in data generation, the New Data Act will offer the following safeguards:
- Their transfer-related costs shall be – reasonably – covered in data sharing agreement.
- The use, by the user or the third-party recipient, of shared data in direct competition with their product is excluded.
- Protection of intellectual property and trade secrets is safeguarded.
Public bodies
The regulation provides means for public sector bodies to access and use data held by the private sector that is necessary for exceptional circumstances, particularly in case of a public emergency, such as pandemics, floods and wildfires, or to implement a legal mandate if data are not otherwise available.
This could affect private entities such as Mobile Network Operators for mobility data, retailers for consumer statistics, manufacturers for emissions data, companies for employment data, or health tech companies for health data.
Cloud providers
The New Data Act will implement new rules allowing customers to effectively switch between different cloud data-processing services providers, by removing technical and contractual barriers. It includes a right for customers to terminate on 30 days’ notice and puts in place safeguards against unlawful non-personal data transfer and governmental access.
Next steps
The text is now being reviewed by the European Parliament and the Council and can be reasonably expected to be adopted in late 2023 or 2024. Businesses will then have 12 months to implement the new requirements.
The regulation enforcement will be entrusted to the competent national authorities designated by Member states.
Cécile Auvieux




