The Data Governance Act (DGA) is the first legislative output of the European strategy for data. Rather than mandating data sharing (which the Data Act does), the DGA aims to increase trust in voluntary data sharing mechanisms across the EU to foster data-driven innovation.
Reuse of Protected Public Sector Data
The Open Data Directive already mandates the sharing of non-sensitive public sector data. The DGA addresses data held by the public sector that is subject to the rights of others, such as:
- Commercial confidentiality (e.g., trade secrets).
- Statistical confidentiality.
- Intellectual property rights of third parties.
- Personal data (governed by GDPR).
Public bodies are not obliged to allow reuse, but if they do, the DGA imposes strict conditions. The data must be processed in secure, controlled environments (safe rooms) and must be anonymized or aggregated. Exclusive reuse agreements are generally prohibited to prevent monopolies on public data.
Regulation of Data Intermediation Services
The DGA introduces a new regulatory framework for "Data Intermediaries" (data brokers, data marketplaces, data trusts). To ensure trust, these entities must remain strictly neutral.
- Fiduciary Duty: Data intermediaries cannot use the data they facilitate for their own purposes (e.g., they cannot analyze it to sell targeted advertising or build their own competing products).
- Structural Separation: The data intermediation service must be structurally separated from any other value-added services the company provides.
- Notification: Intermediaries must notify the competent national authority and can use a recognized EU label to signal compliance.
Data Altruism Organizations
The DGA establishes a framework for "Data Altruism," allowing individuals and companies to voluntarily donate their data for objectives of general interest (e.g., scientific research, improving healthcare, combating climate change) without seeking reward.
- Organizations managing this data can register as "Recognized Data Altruism Organizations in the Union."
- They must be non-profit, operate independently, and adhere to strict transparency requirements.
- The EU has developed a standardized European data altruism consent form to make it easier for citizens to donate data across borders in compliance with the GDPR.
International Data Transfers
The DGA places safeguards on the transfer of highly sensitive non-personal data to third countries. Public bodies and intermediaries must implement technical, legal, and organizational measures to prevent transfer or access by foreign governments if such access would conflict with EU or national law, creating a framework somewhat analogous to GDPR's rules for personal data, but applied to industrial data.