The Data Governance Act (Regulation 2022/868)
The Data Governance Act (DGA), formally Regulation (EU) 2022/868, is a horizontal instrument of the European Union’s data strategy aimed at increasing trust in data sharing and strengthening mechanisms for increasing data availability across the EU. Adopted on 30 May 2022 and applicable from 24 September 2023, the DGA establishes a framework for the governance of European data spaces by regulating data intermediation services, facilitating the re-use of public sector data, promoting data altruism, and creating institutional structures for cross-sector data governance. The DGA is the first legislative deliverable of the European Strategy for Data, complemented by the Data Act (Regulation 2023/2854) and sector-specific data legislation.
Re-Use of Public Sector Data
The DGA creates a mechanism for the re-use of public sector data that is protected by the rights of others — including personal data, commercially confidential data, and data protected by intellectual property rights — and that is therefore outside the scope of the Public Sector Information Directive (Directive 2003/98/EC, as amended by Directive 2013/37/EU). Public sector bodies that authorise re-use of such protected data must ensure that appropriate technical and legal safeguards are in place, including anonymisation, pseudonymisation, or processing in a secure processing environment. The DGA imposes transparency obligations on public sector bodies, requiring them to publish the conditions for re-use and to process requests for re-use in a non-discriminatory manner.
The Regulation requires Member States to designate a single point of contact to assist potential re-users and to establish competent bodies to support public sector bodies in authorising re-use. The DGA prohibits exclusive arrangements for re-use of public sector data beyond a defined duration, subject to specified exceptions for public interest projects. Charging for re-use must be transparent, non-discriminatory, and limited to the costs incurred in making the data available.
Data Intermediation Services
The DGA establishes a regulatory framework for data intermediation services (Articles 10–15) — services that aim to establish commercial relationships between data holders and data users for the purposes of data sharing. Data intermediation services include: intermediation between data holders and potential data users (data marketplaces); intermediation between individuals who wish to make their personal data available and data users (personal data spaces); and services of data cooperatives. Providers of data intermediation services must notify their activities to the competent authority and comply with requirements regarding: separation of the intermediation service from other services; transparency of pricing and conditions; non-discriminatory access; and appropriate technical, legal, and organisational measures to prevent unlawful access and ensure security.
Data intermediation service providers may not use the data for which they provide intermediation for their own purposes, including improving their own services. They must operate through a legal person that is separate from their other activities and must ensure that the data intermediation service is functionally separated from their other digital services. Providers established outside the EU must designate a legal representative in the Union.
Data Altruism
The DGA introduces the concept of data altruism — the voluntary sharing of data by individuals or companies for general interest purposes without seeking a reward. The Regulation establishes a framework for registered data altruism organisations, which must comply with transparency and accountability requirements, including maintaining records of data processing, providing clear information about the purposes of data altruism, and ensuring that data subjects can easily withdraw their consent. Organisations registered as data altruism organisations may use a common European logo to signal their compliance.
The DGA provides for the creation of common European data spaces in strategic sectors such as health, environment, energy, agriculture, mobility, finance, manufacturing, public administration, and skills. These data spaces are not directly regulated by the DGA but are facilitated by its governance framework, with the European Data Innovation Board coordinating the development of cross-sector standards and interoperability requirements.
European Data Innovation Board
The European Data Innovation Board (EDIB) (Articles 29–30) is established as an expert group composed of representatives of Member State competent bodies, the European Data Protection Board, the European Commission, and other relevant stakeholders. The EDIB advises the Commission on the consistent application of the DGA, facilitates the development of model contractual clauses for data sharing, promotes the development of data altruism, and supports the development of common European data spaces. The Board issues opinions, recommendations, and guidelines on cross-sector data governance matters.
Competent Authorities and Penalties
Member States must designate one or more competent authorities responsible for the application and enforcement of the DGA. The authorities have powers to investigate compliance, require information, and impose penalties. The Regulation requires Member States to establish rules on penalties for infringements, including for: failure to notify data intermediation services; infringements of the conditions for providing data intermediation services; failure to comply with data altruism requirements; and non-compliance with transparency obligations. Penalties must be effective, proportionate, and dissuasive.