Data Act
The text of the Data Act. The texts have been automatically converted – thank you for pointing out errors. The assignment of the recitals to individual articles is not official and not clear-cut.
The English version is here to find.
(1) In recent years, data-driven technologies have had a transformative effect on all sectors of the economy. In particular, the rapid proliferation of internet-connected products has increased the scope and potential value of data for consumers, businesses and society. High-quality and interoperable data from different sectors increases competitiveness and innovation and ensures sustainable economic growth. The same data can be used and reused indefinitely for different purposes without compromising quality or quantity.(2) However, barriers to data sharing prevent the optimal distribution of data for the benefit of society. These barriers include the lack of incentives for data owners to voluntarily enter into data sharing agreements, uncertainties regarding rights and obligations related to data, the cost of contracting for and setting up technical interfaces, the high fragmentation of information in data silos, poor management of metadata, lack of standards for semantic and technical interoperability, bottlenecks in data access, lack of standardized procedures for data sharing, and the abuse of contractual imbalances regarding data access and use.(3) In sectors with a large number of micro, small and medium-sized enterprises as defined in Article 2 of the Annex to Commission Recommendation 2003/361/ (5) (SMEs), there is often a lack of digital capacity and skills to collect, analyze and use data, and access is often limited because a single actor in the system holds the data or because data or data services are not interoperable per se or across borders.(4) In order to meet the needs of the digital economy and to remove the obstacles to the smooth functioning of the internal market for data, it is necessary to establish a harmonized framework specifying who is entitled to use product data or related service data, under what conditions and on what basis. Therefore, Member States should not adopt or maintain additional national requirements in matters falling within the scope of this Regulation, unless expressly provided for in this Regulation, as this would affect its direct and uniform application. Furthermore, measures taken at Union level should be without prejudice to the obligations and commitments arising from international trade agreements concluded by the Union.(5) This Regulation ensures that users of a connected product or connected service in the Union have timely access to the data generated when using that connected product or connected service and that those users can use the data and also share it with third parties of their choice. It obliges data holders to make the data available to users and third parties of their choice in certain circumstances. It also ensures that data holders provide data to data recipients in the Union on fair, reasonable and non-discriminatory terms and in a transparent manner. Private law rules are crucial in the overall framework for data sharing. Therefore, this Regulation adapts contract law rules and prevents the exploitation of contractual imbalances that hamper fair access to and use of data. This Regulation also ensures that data holders provide public sector bodies and the Commission, the European Central Bank or Union bodies with the data necessary for the performance of a specific task carried out in the public interest in case of exceptional necessity. In addition, this Regulation aims to facilitate switching between data processing services and to improve the interoperability of data and data sharing mechanisms and services in the Union. This Regulation should not be interpreted as conferring on data holders a new right to use data generated when using a connected product or service.(6) Data generation is the result of the actions of at least two actors, in particular the developer or manufacturer of a connected product, which in many cases may also be a provider of connected services, and the user of the connected product or service. Questions of fairness arise in the digital economy, as the data collected by such connected products or connected services is an important asset for after-market services, ancillary services and other services. In order to reap the important economic benefits of data and to encourage businesses in the Union to share data on the basis of voluntary agreements and to develop data-driven value creation, a general approach to the allocation of rights of access to and use of data is preferable to granting exclusive rights of access and use. This Regulation provides for horizontal rules that could be followed by Union or national law taking into account the specific circumstances of the sectors concerned.(119) Since the objectives of this Regulation, namely to ensure a fair distribution of the value of data among actors in the data economy and to promote fair access to and use of data in order to contribute to the creation of a genuine internal market for data, cannot be sufficiently achieved by the Member States but can rather, by reason of the scale and effects of the action and the cross-border use of data, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve those objectives.
(7) The fundamental right to the protection of personal data is safeguarded in particular by Regulations (EU) 2016/679 (6) and (EU) 2018/1725 (7) of the European Parliament and of the Council. Directive 2002/58/ of the European Parliament and of the Council (8) also protects the privacy and confidentiality of communications, including through conditions for the storage of and access to personal and non-personal data on terminal equipment. These Union legislative acts form the basis for sustainable and responsible data processing, even when data sets contain a mixture of personal and non-personal data. This Regulation complements and is without prejudice to Union law on the protection of personal data and privacy, in particular Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive 2002/58/. Nothing in this Regulation should be applied or interpreted in such a way as to weaken or restrict the right to the protection of personal data or the right to privacy and confidentiality of communications. Any processing of personal data under this Regulation should comply with Union data protection law, including the requirement of a valid legal basis for processing pursuant to Article 6 of Regulation (EU) 2016/679 and, where applicable, the conditions laid down in Article 9 of that Regulation and Article 5(3) of Directive 2002/58/. This Regulation does not constitute a legal basis for the collection or generation of personal data by the data controller. This Regulation obliges data controllers to provide users with personal data to third parties of their choice or at the request of a user. Such access should be granted in the case of personal data processed by the data controller on the basis of one of the legal bases referred to in Article 6 of Regulation (EU) 2016/679. Where the user is not the data subject, this Regulation does not provide a legal basis for granting access to personal data or for making it available to third parties and should not be understood as conferring a new right on the data controller to use personal data generated in the use of a connected product or connected service. In these cases, it could be in the interest of the user to enable compliance with the requirements of Article 6 of Regulation (EU) 2016/679. Since this Regulation should not affect the data protection rights of data subjects, the data controller may comply with data access requests in these cases, inter alia, by anonymizing personal data or, if readily available data contain personal data of several data subjects, by transmitting only personal data of the user.
(10) This Regulation shall be without prejudice to Union legislation on data sharing, access to and use of data for the purposes of prevention, investigation, detection or prosecution of criminal offenses or the execution of criminal penalties, or for customs and tax purposes, irrespective of the legal basis under the Treaty on the Functioning of the European Union (TFEU) on which such Union legislation was adopted, or to legislation on international cooperation in this area, in particular on the basis of the Council of Europe Convention on Cybercrime (ETS No. 185), which was signed in Budapest on November 23, 2001. That legislation includes Regulations (EU) 2021/784 (12), (EU) 2022/2065 (13) and (EU) 2023/1543 (14) of the European Parliament and of the Council and Directive (EU) 2023/1544 of the European Parliament and of the Council (15). This Regulation shall not apply to the collection or sharing of, or access to or use of, data pursuant to Regulation (EU) 2015/847 of the European Parliament and of the Council (16) and Directive (EU) 2015/849 of the European Parliament and of the Council (17). This Regulation shall not apply to areas not covered by Union law and shall not affect the competences of Member States in relation to public security, defense or national security, customs and tax administration or the health and safety of citizens, irrespective of the type of entity entrusted by Member States with the performance of tasks relating to those competences.
(13) This Regulation is without prejudice to legal acts of the Union and of the Member States relating to the protection of intellectual property rights, including Directives 2001/29/ (19), 2004/48/ (20) and (EU) 2019/790 (21) of the European Parliament and of the Council.
(11) Unless expressly provided for in this Regulation, this Regulation should be without prejudice to Union legislation laying down physical design and data requirements for devices to be placed on the Union market.(28) Union consumer law, in particular Directives 93/13/EEC and 2005/29/, applies to contracts between a data controller and a consumer as a user of a connected product or service that generates data, in order to ensure that a consumer is not subject to unfair contract terms. For the purposes of this Regulation, unfair contract terms unilaterally imposed on an undertaking should not be binding on that undertaking.(10) This Regulation shall not prevent the conclusion of voluntary lawful data-sharing contracts, including contracts concluded on the basis of reciprocity, which meet the requirements of this Regulation.(9) Unless otherwise provided for in this Regulation, it shall be without prejudice to national contract law, including rules on the formation of contracts, their validity or their legal consequences or on the effects of the termination of a contract. This Regulation complements and is without prejudice to Union law promoting the interests of consumers and ensuring a high level of consumer protection and protecting their health, safety and economic interests, in particular Council Directive 93/13/EEC (9) and Directives 2005/29/ (10) and 2011/83/EU (11) of the European Parliament and of the Council.(115) This Regulation should be without prejudice to rules that take into account specific needs of individual sectors or areas of public interest. Such rules may include additional requirements on the technical aspects of data access, such as interfaces for data access, or on the way in which data access could be granted, for example directly through the product or through data intermediary services. Similarly, such rules may concern restrictions on the rights of data holders to access or use user data or other aspects that go beyond data access and use, such as governance aspects or security requirements, including cybersecurity requirements. This Regulation should also be without prejudice to more specific rules related to the development of common European data spaces or, subject to the exceptions laid down in this Regulation, Union or national law on making data accessible and authorizing their use for the purposes of scientific research.(116) This Regulation should be without prejudice to the application of competition rules, in particular Articles 101 and 102 TFEU. The rules provided for in this Regulation should not be used to restrict competition contrary to the rules of the TFEU.
(14) Connected devices that obtain, generate or collect data about their performance, use or environment through their components or operating systems and that can transmit such data via an electronic communications service, physical connection or on-device access – often referred to as the Internet of Things – should fall within the scope of this Regulation, with the exception of prototypes. Examples of such electronic communications services include, in particular, terrestrial telephone networks, cable television networks, satellite networks and near-field communication networks. Connected products are found in all sectors of the economy and society, including in private, civil or commercial infrastructures, vehicles, medical equipment, lifestyle equipment, ships, aircraft, household appliances and consumer goods, medical and healthcare products or agricultural and industrial machinery and equipment. Manufacturers’ design choices and, where applicable, Union or national law addressing sector-specific needs and objectives or relevant decisions of competition authorities should determine what data can be provided by a connected product.(22) The networked products may be designed to make certain data accessible directly from a data store on the device or from a remote server to which the data is transmitted. Access to data storage on the device may be enabled via wired or wireless local radio networks connected to a publicly available electronic communications service or cellular network. The server may be the manufacturer’s own local server capacity or that of a third party or cloud service provider. Processors within the meaning of Article 4(8) of Regulation (EU) 2016/679 are not considered data controllers. However, they may be expressly commissioned by the controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 to provide data. Connected products may be designed in such a way that the user or a third party can process the data on the connected product, on a computer instance of the manufacturer or in an information and communication technology (ICT) environment selected by the user or third party.(23) Virtual assistants are playing an increasingly important role in the digitalization of the consumer and professional environment, serving as a user-friendly interface for playing content, obtaining information or activating products that are connected to the internet. For example, virtual assistants can serve as a central gateway in a smart home environment and collect significant amounts of relevant data about how users interact with products connected to the Internet, including those manufactured by third parties, and can replace the use of manufacturer-provided interfaces such as touchscreens or smartphone apps. The user may wish to provide this data to third party manufacturers to enable novel smart services. Virtual assistants should be covered by the right of access to data provided for in this Regulation. Data generated when a user interacts with a connected product through a virtual assistant provided by an entity other than the manufacturer of the connected product should also be covered by the right of access to data provided for in this Regulation. However, only data resulting from the interaction between the user and a connected product or connected service via the virtual assistant should be covered by this Regulation. Data generated by the virtual assistant that is not related to the use of a connected product or connected service is not covered by this Regulation.(16) This Regulation enables users of connected products to use after-market services, ancillary services and other services based on data collected by sensors embedded in those products, where the collection of such data is of potential use for improving the performance of the connected products. It is important to distinguish between the markets for the provision of such sensor-enabled connected products and related services, on the one hand, and the markets for unrelated software and content, such as text, audio or audiovisual content, which is often subject to intellectual property rights, on the other. Therefore, data generated by such sensor-equipped connected products when their users record, transmit, display or play content, including for use by an online service, as well as the content itself, which is often subject to intellectual property rights, should not be covered by this Regulation. This Regulation should also not apply to data obtained or generated by the connected product for the purposes of storage or processing on behalf of other parties that are not users, or accessed through or transmitted to the connected product, such as may be the case for servers or cloud infrastructures operated by their owners exclusively on behalf of third parties, including for use by an online service.
(17) It is necessary to lay down rules for products which, at the time of purchase, rental or leasing, are connected to a connected service in such a way that the connected product could not perform one or more of its functions without that service, or which is subsequently connected to the product by the manufacturer or by a third party in order to complement or adapt the functions of the connected product. Such connected services involve the exchange of data between the connected product and the service provider, i.e. they should be understood as services explicitly linked to the operation of the functions of the connected product, as in the case of services that may transmit commands to the connected product, which in turn may affect its activity or behavior. Services that do not affect the operation of the connected product and that do not transmit data or commands from the service provider to the connected product should not be considered as connected services. Such services could include, for example, additional advisory, analytical or financial services or regular repair and maintenance services. Connected services may be offered as part of a purchase, rental or leasing contract. Connected services could also be provided for products of the same type and users should reasonably expect them to be provided, taking into account the nature of the connected product and public statements made by the seller or on behalf of the seller, lessor, landlord or other persons upstream in the contractual chain, including the manufacturer, prior to the conclusion of the contract. Those connected services may themselves generate data of value to the user, irrespective of the data collection capabilities of the connected product to which they are connected. This Regulation should also apply to connected services that are not provided by the seller, lessor or landlord itself, but by a third party. In case of doubt as to whether the provision of the service is part of the purchase, rental or leasing contract, this Regulation should apply. Neither the supply of electricity nor the provision of connectivity should be construed as related services under this Regulation.
(80) Computing services should include services that enable location-independent and on-demand network access to a configurable, scalable and elastic shared pool of distributed resources. These computing resources include resources such as networks, servers or other virtual or physical infrastructures, software – including software development tools – storage, applications and services. The fact that customers of data processing services can allocate computing resources such as server time or network storage space themselves, without interaction with the provider of data processing services, could be described as minimal administrative effort and minimal interaction between provider and customer. The term „location-independent“ is used to describe the provision of and access to computing capacity over the network via mechanisms that encourage the use of heterogeneous thin or thick client platforms (from web browsers to mobile devices and workstations). The term „scalable“ refers to computing resources that are flexibly allocated by the provider of data processing services, regardless of their geographical location, in order to compensate for fluctuations in demand. The term „elastic“ is used to describe computing resources that are provided and released according to demand in order to be able to quickly increase or decrease available resources depending on the workload. The term „shared pool“ is used to describe the computing resources provided to multiple users who access the service via a shared access point, but where processing is performed separately for each user, even though the service is provided via the same electronic equipment. The term „distributed“ is used to describe computing resources that are located on different networked computers or devices and that communicate and coordinate with each other by exchanging messages. The term „highly distributed“ is used to describe data processing services where data is processed closer to where it is generated or collected, e.g. in a networked computing device. Edge computing, a form of this highly distributed data processing, is likely to give rise to new business models and cloud services that should be open and interoperable from the outset.(81) The generic term „data processing services“ covers a considerable number of services with a very wide range of different purposes, functions and technical structures. According to the general understanding of providers and users and in line with widely used standards, data processing services fall under one or more of the following three models for the provision of data processing services, namely „Infrastructure-as-a-Service“ (IaaS), „Platform-as-a-Service“ (PaaS) and „Software-as-a-Service“ (SaaS). These service delivery models are a specific, ready-made combination of ICT resources offered by a provider of data processing services. These three basic delivery models for data processing services are further complemented by new variations, each with a very specific combination of ICT resources, such as „Storage-as-a-Service“ and „Database-as-a-Service“. Data processing services can be categorized in more detail and subdivided into a non-exhaustive list of data processing services that have the same main objective and functions and the same type of data processing models that are not related to the operational characteristics of the service (same service type). Services belonging to the same service type may have the same model for the provision of data processing services, but while two databases may appear to have the same main objective, they could fall into a more detailed sub-category of comparable services after taking into account their data processing model, their distribution model and the use cases they are targeted at. Services of the same service type may have different and competing characteristics such as performance, security, robustness and quality of service.
(18) The user of a connected product should be understood as a natural or legal person, such as a business, a consumer or a public sector body, who owns a connected product or, for example through a rental or leasing contract, holds certain temporary rights of access to or use of data from the connected product or uses connected services for the connected product. These access rights should in no way alter or interfere with the rights of data subjects who may interact with a connected product or connected service in relation to the personal data generated by the connected product or during the provision of connected services. The user bears the risks and enjoys the benefits of using the connected product and should also have access to the data generated by it. He should therefore be entitled to benefit from the data generated by that connected product and any connected services. An owner, tenant or lessee should also be considered a user, including in cases where multiple entities can be considered users. In the case of multiple users, each individual user may contribute to data generation in different ways and have an interest in different forms of use; examples include fleet management for a leasing company or mobility solutions for individuals using a car-sharing service.(21) Where multiple persons or entities are considered to be users, for example in the case of joint ownership or where an owner, tenant or lessee has joint rights to access or use data, the design of the connected product or connected service or interface should allow each user to access the data generated by them. The use of connected products that generate data usually requires a user account to be set up. Such an account enables the user to be identified by the data owner, who may be the manufacturer. It can also be used as a means of communication and for submitting and processing data access requests. If several manufacturers or providers of connected services have jointly sold, rented or leased connected products to or provided integrated services for the same user, the user should contact each of the parties with whom he has concluded a contract. Manufacturers or developers of a connected product that is typically used by several persons should put in place the necessary mechanisms to allow, where appropriate, the creation of separate user accounts for individual persons or the use of the same user account by several persons. Account-based solutions should allow users to delete their accounts and the associated data and could provide for the possibility for users to terminate or request the termination of data access, use or sharing, in particular in cases where the ownership of the product is transferred to other persons or where other persons use the connected product. Access should be granted to the user on the basis of simple request procedures that allow for automatic execution and do not require verification or approval by the manufacturer or data owner. This means that the data should only be provided when the user actually requests access. If automatic execution of the data access request, for example via a user account or the mobile application provided with the connected product or service, is not possible, the manufacturer should inform the user how the data can be accessed.
(8) The principles of data minimization and data protection by design and by default are essential where the processing involves significant risks to the fundamental rights of individuals. Taking into account the state of the art, all parties involved in data sharing, including data sharing within the scope of this Regulation, should implement technical and organizational measures to protect those rights. These measures include not only pseudonymization and encryption, but also the use of increasingly available technology that allows algorithms to be used directly at the point of data generation and valuable insights to be gained without transferring the data between the parties or unnecessarily copying the raw or structured data itself.
(15) The data represent digitized user actions and processes and should therefore be accessible to the user. The rules on access to and use of data from connected products and connected services under this Regulation cover both product data and connected service data. Product data means data generated by the use of a connected product and designed by the manufacturer to be retrievable from the connected product by a user, data owner or third party, including, where applicable, the manufacturer. Connected service data means data that also represents the digitization of user actions or operations in connection with the connected product and is generated during the provision of a connected service by the provider. Data generated during the use of a connected product or connected service should be understood as intentionally recorded data or data generated indirectly through user actions, such as data about the environment or interactions of the connected product. Such data should include data on the use of a connected product generated by a user interface or through a connected service and should not be limited to information that a product or service has been used, but should include all data generated by the connected product as a result of such use, such as data automatically generated by sensors and data recorded by embedded applications, including applications indicating hardware status and malfunctions. Such data should also include data generated by the connected product or connected service while the user is inactive, such as when the user decides not to use a connected product for a certain period of time but to leave it in standby mode or even switch it off, as the status of a connected product or its components, such as its batteries, may change when the connected product is in standby mode or switched off. Data that is not substantially altered, i.e. data in raw form, also referred to as source or primary data, which refers to data points that are automatically generated without any further form of processing, as well as data that has been prepared prior to further processing and analysis to make it understandable and usable, falls within the scope of this Regulation. This includes data collected by a single sensor or a group of interconnected sensors in order to make the collected data understandable for more diverse use cases by determining a physical quantity or property or the change of a physical quantity, such as temperature, pressure, flow rate, sound, pH, liquid level, position, acceleration or velocity. The term „prepared data“ should not be interpreted as requiring the data owner to make a significant investment in cleaning and transforming the data. The data to be provided should include the relevant metadata, including its basic context and timestamp, to make the data usable in combination with other data, e.g. data that has been sorted and classified with other data points associated with it or reformatted into a common format. Such data is potentially valuable to the user and supports innovation and the development of digital and other services to protect the environment, health and the circular economy, including by facilitating the maintenance and repair of the connected products concerned. By contrast, information inferred or derived from such data that is the result of additional investment in attributing value or insights from the data (in particular by means of complex proprietary algorithms, including those that are part of proprietary software) should not fall within the scope of this Regulation, and therefore data holders should not be obliged to provide such data to a user or data recipient, unless otherwise agreed between the user and the data holder. Such data could include, in particular, information obtained through sensor fusion, where data is derived or inferred from multiple sensors collected in the connected product using complex proprietary algorithms and may be subject to intellectual property rights.
(20) In practice, not all data generated by connected products or connected services are easily accessible to their users, and there are often limited possibilities in terms of portability of data generated by internet-connected products. Users are therefore unable to obtain the data required to access repair and other services, and companies are unable to offer innovative, convenient and more efficient services. In many sectors, because manufacturers have control over the technical design of connected products or connected services, they can determine what data is generated and how it can be accessed, even though they have no legal right to this data. It is therefore necessary to ensure that connected products are designed and manufactured and connected services are designed and provided in such a way that the product data and connected service data, including the corresponding metadata necessary to interpret and use that data, including to retrieve, use or share the data, are always easily and securely accessible to a user, free of charge, in a comprehensive, structured, commonly used and machine-readable format. Product data and connected service data that a data controller lawfully obtains or can obtain from the connected product or connected service, for example due to the design of the connected product, the data controller’s contract with the user for the provision of connected services and its technical means for accessing the data without disproportionate effort, are referred to as „readily available data“. Readily available data excludes data generated during product use, unless the connected product is designed to store or transmit such data outside the component in which it is generated or the connected product as a whole. This Regulation should therefore not be interpreted as imposing an obligation to store data on the central processing unit of a connected product. The absence of such an obligation should not prevent the manufacturer or data controller from agreeing such adaptations with the user on a voluntary basis. The design obligations under this Regulation are also without prejudice to the principle of data minimization under Article 5(1)(c) of Regulation (EU) 2016/679 and should not be understood as requiring connected products and connected services to be designed in such a way as to store or otherwise process personal data other than those necessary for the purposes of their processing. Union or national law could be introduced to lay down further specificities, such as the product data that should be accessible through connected products or connected services, as such data may be essential for the efficient operation, repair or maintenance of those connected products or connected services. Where subsequent updates or changes to a connected product or connected service by the manufacturer or another party result in additional accessible data or a restriction of initially accessible data, those changes should be communicated to the user as part of the update or change.
(83) Digital assets refer to elements in digital form for which the customer has the right of use, including applications and metadata related to the configuration of settings, security and the management of access and control rights, as well as other elements such as representations of virtualization technologies, including virtual machines and containers. Digital assets may be transferred provided the customer has a right of use that is independent of the contractual relationship with the data processing service they wish to change. The other elements mentioned above are the prerequisite for the customer to be able to effectively use its data and applications in the environment of the acquiring provider of data processing services.
(85) Switching is a process that originates from the customer and consists of several steps – including data extraction – which means downloading the data from the ecosystem of the original provider of data processing services, transforming the data if it is structured in such a way that it does not fit into the schema of the target location, and uploading the data to a new target location. In certain situations described in this Regulation, it should also be considered as switching when a particular service is removed from the contract and moved to another provider. The switch is sometimes carried out by a third party on behalf of the customer. Accordingly, all the rights and obligations of the customer set out in this Regulation, including the obligation to cooperate in good faith, should be understood to apply to the third party concerned in those circumstances. Data processing service providers and customers bear different degrees of responsibility depending on the step in the process. For example, the original data processing service provider is responsible for extracting the data into a machine-readable format, while the customer and the acquiring data processing service provider must upload the data to the new environment, unless a special professional transition service is used. A customer who intends to exercise the rights provided for in this Regulation in connection with the switch should inform the original data processing services provider of the decision to either switch to another data processing services provider or to an ICT infrastructure on its own premises or to delete the customer’s assets and exportable data.
(88) Switching fees are fees that providers of data processing services charge their customers for completing the switch. These fees are usually intended to pass on the costs that the original provider of data processing services may incur as a result of the switch to the customer requesting the switch. Common examples of switching fees are costs associated with the transfer of data from one provider of data processing services to another or from one provider to an ICT infrastructure on its own premises („data extraction fees“) or costs incurred through specific support activities during the execution of the switch. Unreasonably high data extraction charges and other unjustified charges that are unrelated to the actual costs of switching hinder switching by the customer, restrict the free flow of data, may restrict competition and lead to dependency of the customer on a particular service by reducing incentives to choose another or further service providers. Therefore, switching fees should be abolished after three years from the date of entry into force of this Regulation. Providers of data processing services should be able to charge reduced switching fees until that date.
(86) Functional equivalence means that after a switch, a minimum functional scope based on the customer’s exportable data and digital assets is re-established in the environment of the new data processing service of the same service type, with the acquiring data processing service providing a substantially comparable result for shared functions provided to the customer under the contract. Providers of data processing services can only be expected to enable functional equivalence in relation to the functions offered independently by both the original and the acquiring data processing service. Providers of data processing services are only required to facilitate functional equivalence under this Regulation if they offer services under the IaaS delivery model.
(24) Before entering into a purchase, rental or leasing contract for a connected product, the seller, lessor or lender – which may also be the manufacturer – should provide the user with information on the product data that the connected product may generate, including the type, format and estimated amount of data, in a clear and comprehensible manner. This could include, where available, information on data structures, data formats, vocabularies, classification systems, taxonomies and code lists, as well as clear and sufficient information relevant to the exercise of user rights and how the data can be stored, retrieved or accessed, including the terms of use and quality of service of application programming interfaces or the provision of software development kits, where applicable. This obligation ensures transparency with regard to the generated product data and simplifies access for the user. The information obligation could be met, for example, by maintaining a stable URL address on the Internet that can be distributed as a web link or QR code and leads to the relevant information that the seller, lessor or lessor – which may also be the manufacturer – could provide to the user before concluding a purchase, rental or leasing contract for a connected product. In any case, the user must be able to store the information in such a way that it can subsequently be viewed and the unaltered reproduction of the stored information is possible. While the data controller cannot be expected to store the data indefinitely in view of the needs of the user of the connected product, it should apply an appropriate regime in relation to the duration of data storage, where appropriate in accordance with the principle of storage limitation under Article 5(1)(e) of Regulation (EU) 2016/679, which allows for the effective application of data access rights under that Regulation. The obligation to provide information does not affect the obligation of the controller to provide information to the data subject in accordance with Articles 12, 13 and 14 of Regulation (EU) 2016/679. The obligation to provide the relevant information prior to the conclusion of a contract for the provision of a connected service should lie with the potential data controller, regardless of whether the data controller concludes a purchase, rental or leasing contract for a connected product. If the information changes during the lifetime of the connected product or the duration of the contract for the connected service, including if the purpose for which this data is to be used changes from that originally intended, information on this should also be provided to the user.
(27) In concentrated sectors where end-users are supplied with connected products by a small number of manufacturers, users may have limited options for data access, use and sharing. In these circumstances, contractual agreements may not be sufficient to achieve the goal of user empowerment, making it difficult for users to derive value from the data generated by the connected products they purchase, rent or lease. As a result, the potential for innovative smaller companies to offer data-driven solutions in a competitive manner and for a diverse data economy in the Union is limited. This Regulation should therefore build on recent developments in certain sectors, such as the code of conduct for the sharing of agricultural data by means of a contract. Union or national law may be adopted to address sector-specific needs and objectives. In addition, data holders should not use readily available data that is non-personal data to gain insights into the economic situation, assets or production methods of the user or into the use by the user in any other way that could undermine the commercial position of that user in the markets in which it operates. This could include using knowledge of the overall performance of a company or farm to its detriment in contractual negotiations with the user for the potential purchase of the user’s product or farm produce, or entering such information into larger aggregated databases on specific markets, such as databases on crop yields for the coming harvest season, as such use could have an indirect negative impact on the user. The user should be provided with the technical interface necessary to manage the permissions, preferably with fine-grained permission options (e.g. „allow access once“ or „allow access only while using the app or service“), including the possibility to revoke such permissions.
(29) Data controllers may request appropriate user identification in order to verify a user’s authorization to access the data. In the case of personal data processed by a processor on behalf of the controller, data controllers should ensure that the request for access is received and processed by the processor.
(31) Directive (EU) 2016/943 of the European Parliament and of the Council (23) provides that the acquisition, use or disclosure of a trade secret is to be considered lawful, inter alia, where such acquisition, use or disclosure is required or permitted by Union or national law. While this Regulation requires data holders to disclose certain data to users or third parties selected by the user, even if such data is covered by trade secret protection, this should be interpreted in a way that respects the protection of trade secrets in accordance with Directive (EU) 2016/943. In this context, data controllers should be able to require the user or third parties selected by the user to respect the confidentiality of data that are considered trade secrets. Therefore, data holders should identify the trade secrets prior to their disclosure and have the possibility to agree with users or user-selected third parties on necessary measures to preserve their confidentiality, including through the use of model contractual clauses, confidentiality agreements, strict access protocols, technical standards and the application of codes of conduct. In addition to the use of model contractual clauses to be developed and recommended by the Commission, the establishment of codes of conduct and technical standards relating to the protection of trade secrets in the processing of data could also contribute to achieving the objective of this Regulation and should therefore be promoted. Where there is no agreement on the necessary measures or where a user or a third party selected by the user does not implement those agreed measures or breaches the confidentiality of trade secrets, it should be possible for the data controller to refuse or suspend the disclosure of the data classified as trade secrets. In such cases, the data holder should immediately notify the user or the third party in writing of its decision and inform the national competent authority of the Member State where the data holder is established that it has refused or suspended the disclosure of data, indicating which measures have not been agreed or implemented and, where relevant, which trade secrets have been breached. In principle, data holders cannot refuse a data access request under this Regulation on the sole ground that certain data are considered to be trade secrets, as this would undermine the intended effect of this Regulation. However, in exceptional cases, a data holder holding a trade secret should be able to refuse a data access request for the specific data concerned on a case-by-case basis if it can demonstrate to the user or the third party that the disclosure of that trade secret is likely to result in serious economic damage despite technical and organizational measures taken by the user or the third party. Serious economic damage is associated with serious irreparable economic losses. The data controller should duly justify its refusal to the user or the third party in writing without undue delay and inform the competent authority thereof. Such justification should be based on objective facts showing that the disclosure of certain data is likely to result in a concrete risk of serious economic damage and why the measures taken to protect the requested data are considered insufficient. In this context, any negative impact on cybersecurity may be taken into account. Without prejudice to the right to appeal before a court of a Member State, the user or the third party who wishes to contest the decision of the data controller to refuse, refuse or suspend the transfer of data may lodge a complaint with the competent authority, which should then decide without delay whether and under which conditions the transfer of the data should start or resume, or the user or the third party may agree with the data controller to refer the matter to a dispute settlement body. The exceptions to data access rights provided for in this Regulation should in no way limit the rights of data subjects to access and data portability under Regulation (EU) 2016/679.
(57) Data controllers may apply appropriate technical protection measures to prevent the unlawful disclosure of or access to data. However, these measures should not discriminate between data recipients or impair access to and use of data by users or data recipients. In the event of abusive practices by a data recipient, such as misleading the data owner by providing false information with the intention of using the data for unlawful purposes, including the development of a competing networked product based on the data, the data owner and, where appropriate, if not the same person, the trade secret holder or the user may request the third party or data recipient to take immediate corrective or remedial action. Such requests, in particular requests to cease the production, offering or marketing of goods, derived data or services and requests to cease the import, export and storage of infringing goods or to destroy them, should be assessed in terms of whether they are proportionate to the interests of the data controller, the trade secret holder or the user.
(32) The objective of this Regulation is not only to stimulate the development of new, innovative connected products or connected services and to drive innovation in downstream markets, but also to stimulate the development of entirely new types of services using the data concerned, including on the basis of data from a variety of connected products or connected services. At the same time, this Regulation seeks to prevent the loss of incentives to invest in the type of connected products from which the data is obtained, for example where data is used to develop a competing connected product that is considered interchangeable or substitutable by users, in particular on the basis of its characteristics, price and intended use. This Regulation does not provide for a prohibition on the development of a connected service using data obtained under this Regulation, as this would have an undesirable chilling effect on innovation. The innovation efforts of data holders are protected by the prohibition to use data accessed under this Regulation for the development of a competing connected product. Whether a connected product is in competition with the connected product from which the data originates depends on whether the two connected products compete on the same product market. This has to be decided on the basis of well-established principles of Union competition law to determine the relevant product market. However, a legitimate purpose for the use of the data, to the extent that the requirements of this Regulation, Union or national law are met, could include reverse engineering. This may be for the purposes of repairing or extending the life of a connected product or providing after-market services for connected products.
(34) When using a networked product or connected service, especially if the user is a natural person, data may be generated that relates to a data subject. The processing of such data is subject to the provisions of Regulation (EU) 2016/679, even if personal and non-personal data are inextricably linked in a data set. The data subject may be the user or another natural person. Access to personal data may only be requested by a controller or a data subject. The user, who is the data subject, is entitled to access the personal data relating to that user under certain circumstances in accordance with Regulation (EU) 2016/679; these rights are not affected by this Regulation. Under this Regulation, a user who is a natural person also has the right to access all data generated by the use of a connected product, whether personal or non-personal. Where the user is not the data subject but a company, including a sole trader, and the product is not used jointly in a household, the user is considered to be the controller. Accordingly, a user who intends to request access to personal data generated during the use of a connected product or connected service as a controller requires a legal basis for processing the data in accordance with Article 6(1) of Regulation (EU) 2016/679, such as the consent of the data subject or the performance of a contract to which the data subject is party. This user should ensure that the data subject is adequately informed about the specific, explicit and legitimate purposes of the processing of these data and how the data subject can effectively exercise his or her rights. Where the data controller and the user are joint controllers within the meaning of Article 26 of Regulation (EU) 2016/679, they must specify in a transparent manner in an agreement which of them fulfills the relevant obligations to comply with that Regulation. It should be understood that once data has been provided, such a user may in turn become a data controller if that user fulfills the criteria of this Regulation and thus may in turn be subject to the obligations to provide data under this Regulation.
(36) Access to data stored on terminal equipment or accessible via terminal equipment is subject to Directive 2002/58/ and requires the consent of the subscriber or user within the meaning of that Directive, unless access to the data is strictly necessary for the provision of an information society service explicitly requested by the user or subscriber or for the sole purpose of transmitting a communication. Directive 2002/58/ protects the integrity of a user’s terminal equipment with regard to the use of processing and storage functions and the collection of information. Internet of Things devices are considered to be terminal equipment if they are directly or indirectly connected to a public communications network.
(25) This Regulation should not be understood as conferring a new right on data holders to use product data or connected service data. Where the manufacturer of a connected product is the data controller, a contract between the manufacturer and the user should form the basis for the use of non-personal data by the manufacturer. Such a contract could be part of an agreement for the provision of the connected service, which may be concluded together with the purchase, rental or leasing contract for the connected product. Any contractual clause allowing the data controller to use the product data or connected service data should be transparent to the user, including in relation to the purposes for which the data controller intends to use the data. Such uses could include improving the functioning of the connected product or connected services, developing new products or services, or aggregating data with the aim of providing the resulting derived data to third parties, provided that such derived data does not enable the identification of individual data transmitted by the connected product to the data controller and does not enable third parties to retrieve such data from the data set. Any change to the contract should require the informed consent of the user. This Regulation does not prevent the parties from agreeing contractual clauses which have the effect of excluding or restricting the use of non-personal data or certain categories of non-personal data by a data controller. Nor does it prevent the parties from agreeing that product data or related service data may be provided directly or indirectly to third parties, including, where relevant, through another data controller. Furthermore, this Regulation does not preclude sector-specific regulatory requirements under Union law or national law in conformity with Union law which would exclude or restrict the use of certain data by the data holder on well-defined public policy grounds. Furthermore, this Regulation does not prevent users from providing data to third parties or data holders in the case of business-to-business relationships under any lawful contractual clauses, including by agreeing to limit or restrict re-disclosure of such data or by providing users with adequate consideration, for example, for waiving their right to use or disclose such data. Although the term „data controller“ does not generally include public sector bodies, it may include public sector companies.
(26) To promote the emergence of liquid, fair and efficient markets for non-personal data, users of networked products should be able to share data with minimal legal and technical effort, including for commercial purposes. It is currently often difficult for companies to justify the labor or IT costs involved in preparing non-personal datasets or data products and offering them to potential counterparties through data intermediation services, including data marketplaces. A major obstacle to the sharing of non-personal data by businesses therefore arises from the lack of predictability of the economic return on investment in the preparation and provision of datasets or data products. In order for liquid, fair and efficient markets for non-personal data to emerge in the Union, it is necessary to clarify which party has the right to offer such data on a market. Users should therefore have the right to share non-personal data with data recipients for commercial and non-commercial purposes. Such disclosure could be made directly by the user, at the request of the user through a data controller or through data intermediary services. Data intermediary services within the meaning of Regulation (EU) 2022/868 of the European Parliament and of the Council (22) could serve the data economy by establishing business relationships between users, data recipients and third parties and assisting users in exercising their right to use data, for example by ensuring the anonymization of personal data or the aggregation of access to data from a large number of individual users. Where data are exempted from a data controller’s obligation to provide them to users or third parties, the scope of such data could be specified in the contract concluded between the user and the data controller for the provision of a related service, so that users can easily identify which data are available to them for sharing with data recipients or third parties. Data holders should not provide non-personal product data to third parties for either commercial or non-commercial purposes, except for the performance of their contract with the user; this should be without prejudice to the legal requirements under Union or national law for a data holder to provide data. Where appropriate, data controllers should contractually oblige third parties not to re-disclose the data they have received.(30) The user should be free to use the data for any lawful purpose. This includes providing the data obtained by the user in the exercise of his rights under this Regulation to a third party offering a after-market service that may be in competition with a service provided by a data controller, or instructing the data controller to do so. The request for access should be made by the user or by an authorized third party acting on behalf of a user, including by a provider of a data intermediary service. Data holders should ensure that the data provided to a third party is as accurate, complete, reliable, relevant and up-to-date as the data generated by the use of the connected product or service that the data holder can or is authorized to access. Intellectual property rights should be respected when processing the data. It is important that there continue to be incentives to invest in products whose functions are based on the use of data from sensors built into these products.(35) Product data or related service data should only be provided to third parties at the request of the user. Accordingly, this Regulation supplements the right of a data subject under Article 20 of Regulation (EU) 2016/679 to receive the personal data concerning him or her in a structured, commonly used, machine-readable and interoperable format and to transmit those data to another controller, where the personal data are processed by automated means on the basis of Article 6(1)(a) or Article 9(2)(a) or a contract pursuant to Article 6(1)(b) of that Regulation. Data subjects also have the right to have the personal data transmitted directly from one controller to another, but only if this is technically feasible. Article 20 of Regulation (EU) 2016/679 specifies that this concerns data provided by the data subject, without specifying whether this requires active behavior by the data subject or whether this also applies in cases where a connected product or service, by its design, passively collects the behavior of a data subject or other information relating to a data subject. The rights contained in this Regulation supplement the right to receive and transmit personal data in accordance with Article 20 of Regulation (EU) 2016/679 in various ways. This Regulation grants users the right to access and provide any product data or related service data to a third party, regardless of whether it is personal data, regardless of the distinction between actively provided or passively collected data and regardless of the legal basis for the processing. In contrast to Article 20 of Regulation (EU) 2016/679, this Regulation requires and ensures the technical feasibility of third party access to all types of data within its scope, whether personal or non-personal, thus ensuring that technical barriers no longer hinder or prevent access to such data. It also allows data holders to set a fair compensation for costs incurred in providing direct access to the data generated by the user’s connected product, which is to be borne by third parties but not by the user. Where a data controller and a third party are unable to agree on terms for such direct access, the data subject should in no way be prevented from exercising the rights laid down in Regulation (EU) 2016/679, including the right to data portability, by seeking redress in accordance with that Regulation. In this context, in accordance with Regulation (EU) 2016/679, a contract may not authorize the processing of special categories of personal data by the data controller or the third party.
(33) A third party to whom data is provided may be a natural or legal person, such as a consumer, a business, a research organization, a non-profit organization or an entity acting in a professional capacity. If a data controller provides the data to the third party, it should not abuse its position to gain a competitive advantage in markets where the data controller and the third party may be in direct competition. The data controller should therefore not use readily available data to gain insight into the economic situation, assets or production methods of the third party or use by the third party in any other way that could undermine the commercial position of the third party in the markets in which it operates. The user should be able to disclose non-personal data to third parties for commercial purposes. With the user’s consent and subject to the provisions of this Regulation, third parties should be able to transfer the data access rights granted by the user to other third parties, including for a fee. Business-to-business data intermediaries and personal information management systems (PIMS), referred to as data intermediation services in Regulation (EU) 2022/868, may assist users or third parties in establishing business relationships with an unspecified number of potential counterparties for any lawful purpose falling within the scope of this Regulation. They could play a crucial role in aggregating access to data so that big data analytics or machine learning can be facilitated, provided that users retain full control over whether they make their data available for such aggregation and under which commercial conditions their data is to be used.
(37) In order to prevent users from being exploited, third parties to whom the data has been provided at the user’s request should only process this data for the purposes agreed with the user and only pass it on to other third parties if the user has given their consent to this data transfer.
(38) In accordance with the principle of data minimization, third parties should only access information that is necessary for the provision of the service requested by the user. Once the third party has gained access to the data, it should process it for the purposes agreed with the user without interference from the data controller. It should be as easy for the user to deny or terminate third party access to the data as it is for the user to allow access to the data. Neither third parties nor data holders should unduly impede the exercise of users„ choices or rights, including by offering them choices in a non-neutral way, or by coercing, deceiving or manipulating the user, or by undermining or interfering with the user’s autonomy, decision-making capacity or freedom of choice, including through a digital user interface or part thereof. In this context, third parties or data owners should not use so-called “dark patterns„ when designing their digital interfaces. “Dark patterns„ are design techniques that are used to mislead or deceive consumers into making decisions that have negative consequences for them. These manipulative techniques may be used to induce and deceive users, particularly vulnerable consumers, into undesirable behavior by encouraging them to make decisions about data disclosure, and to disproportionately influence the decision-making of users of the service in a way that undermines or impairs their autonomy, decision-making ability or choice. Usual and lawful commercial practices that comply with Union law should not in themselves be considered as “dark patterns’. Third parties and data controllers should comply with their obligations under relevant Union law, in particular the requirements of Directives 98/6/ (24) and 2000/31/ (25) of the European Parliament and of the Council and Directives 2005/29/ and 2011/83/EU.
(39) Third parties should also refrain from using data falling within the scope of this Regulation for profiling of an individual, unless such processing activities are strictly necessary to provide the service requested by the user, including in the context of automated decision-making. The requirement to erase data when it is no longer necessary for the purpose agreed with the user, unless otherwise agreed in relation to non-personal data, supplements the data subject’s right to erasure under Article 17 of Regulation (EU) 2016/679. Where a third party is a provider of a data intermediation service, the safeguards provided for in Regulation (EU) 2022/868 apply to the data subject. The third party may use the data for the development of a new and innovative connected product or connected service, but not for the development of a competing connected product.
(40) Start-ups, small enterprises and enterprises that qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/, as well as enterprises from traditional sectors with less developed digital capabilities, face difficulties in gaining access to relevant data. The aim of this Regulation is to facilitate access to data for these entities while ensuring that the obligations are as proportionate as possible to avoid overreaching. The accumulation and aggregation of vast amounts of data and the technological infrastructure for its monetization has simultaneously created a small number of very large companies with considerable economic power in the digital economy. These very large companies include operators of core platform services that control entire platform ecosystems in the digital economy, making it impossible for existing or new market players to challenge their position or compete with them. Regulation (EU) 2022/1925 of the European Parliament and of the Council (26) aims to address these inefficiencies and imbalances by allowing the Commission to designate a company as a „gatekeeper“ and imposing a number of obligations on these gatekeepers, including the prohibition to merge certain data without consent and the obligation to ensure effective data portability rights under Article 20 of Regulation (EU) 2016/679. In accordance with Regulation (EU) 2022/1925 and given the unique ability of these companies to acquire data, it is not necessary to achieve the objective of this Regulation and therefore disproportionate in relation to the data controllers subject to the relevant obligations to grant such gatekeepers a right of access to data. Their inclusion is also likely to limit the benefits that this Regulation can bring to SMEs in relation to the fair distribution of data value creation among market participants. This means that a company designated as a gatekeeper operating core platform services cannot, on the basis of this Regulation, request or obtain access to user data generated when using a connected product or service or a virtual assistant. In addition, third parties to whom data is provided at the request of the user may not provide the data to a gatekeeper. For example, the third party may not engage a gatekeeper to provide the service. However, this does not prevent third parties from using data processing services offered by a gatekeeper. Nor does it prevent those companies from obtaining and using the same data by other lawful means. Access rights under this Regulation contribute to a wider choice of services for consumers. As voluntary agreements between gatekeepers and data holders remain unaffected, restricting the granting of access to gatekeepers would not exclude them from the market or prevent them from offering their services.(41) Given the current state of the art, it would be too burdensome to impose further design obligations on microenterprises and small enterprises for connected products that they manufacture or design or connected services that they provide. However, this is not the case where a microenterprise or small enterprise has a partner enterprise or an associated enterprise within the meaning of Article 3 of the Annex to Recommendation 2003/361/ which is not considered to be a microenterprise or small enterprise and which is entrusted with the manufacture or design of a connected product or the provision of a connected service. In such cases, the undertaking that has awarded the manufacturing or design contract to a microenterprise or small enterprise shall be able to compensate the contractor appropriately. However, a microenterprise or small enterprise may be subject to the requirements of this Regulation as a data controller if it is not the manufacturer of the connected product or a provider of connected services. A transitional period should apply to a company that has been classified as a medium-sized enterprise for less than one year and to connected products placed on the market by a medium-sized enterprise less than one year ago. That one-year period allows a medium-sized enterprise to adapt and prepare before being exposed to competition on the services market for the connected products it manufactures on the basis of access rights under this Regulation. That transitional period shall not apply where such a medium-sized enterprise has a partner undertaking or an associated undertaking which is not a microenterprise or a small enterprise, or where such a medium-sized enterprise has been entrusted with the manufacture or design of a connected product or the provision of a connected service.
(42) Taking into account the variety of connected products that generate different types, volumes and frequencies of data, which present different data and cybersecurity risks and economic opportunities of different value, and in order to ensure consistency of data-sharing practices in the internal market, including across sectors, and to promote and advance fair data sharing practices even in those areas where such a right of access to data is not provided for, this Regulation lays down horizontal rules on the organization of access to data in all cases where a data controller is obliged to provide data to a data recipient under Union law or national law adopted in accordance with Union law. Such access should be based on fair, reasonable, non-discriminatory and transparent conditions. These general access rules do not apply to data provision obligations under Regulation (EU) 2016/679. Voluntary data sharing remains unaffected by these rules. The non-binding model contractual clauses for data sharing between companies, which the Commission will develop and recommend, can help the parties to conclude contracts that contain fair, reasonable and non-discriminatory conditions and are to be implemented in a transparent manner. The conclusion of contracts that may include the non-binding model contractual clauses should not imply that the right to transfer data to third parties is in any way linked to the existence of such a contract. Should the parties – even with the assistance of dispute resolution bodies – not be able to conclude a contract on the transfer of data, the right to transfer data to third parties is enforceable before national courts.(45) Agreements for the provision of data concluded in the context of business-to-business relationships should not distinguish between similar categories of data recipients, whether they are large companies or SMEs. To compensate for the lack of information on the conditions contained in different contracts, which makes it difficult for the data recipient to assess whether the conditions for the provision of the data are non-discriminatory, it should be the responsibility of data holders to prove that a contractual term is non-discriminatory. There is no unlawful discrimination if the data controller provides for different contractual clauses for the provision of data, provided that those differences are justified on objective grounds. These obligations apply without prejudice to Regulation (EU) 2016/679.
(46) In order to encourage further investment in the generation and provision of valuable data, including investment in relevant technical tools, while avoiding disproportionate burdens on access to and use of data, which would render data sharing economically unviable, this Regulation lays down the principle that data holders may request adequate compensation where they are obliged under Union law or national law adopted in accordance with Union law to provide data to a data recipient in the context of business-to-business relationships. This consideration should not be understood as payment for the data itself. The Commission should adopt guidelines on the basis of which an appropriate consideration in the data economy can be calculated.(47) First, fair compensation for complying with the obligation under Union or national law adopted in accordance with Union law to comply with a data access request may include compensation for the costs associated with providing the data. These may be technical costs, such as costs necessary for the reproduction, electronic dissemination and storage of data, but not the costs of data collection or production. Technical costs could also include the costs of processing required in advance of making the data available, including the costs associated with formatting the data. Costs associated with providing the data may also include the costs of facilitating specific data sharing requests. Depending on the amount of data and the agreements made for the provision of the data, these costs may also vary. Long-term agreements between data owners and data recipients, e.g. via a subscription model or the use of smart contracts, may result in lower costs in the context of regular or repeated transactions in a business relationship. Costs related to the provision of data either relate to a specific request or cover multiple requests. In the latter case, the costs of providing the data should not be borne in full by a single data recipient. Secondly, the appropriate consideration may also include a margin, except in relation to SMEs and non-profit research organizations. The margin may vary depending on factors related to the data itself, such as the amount, format or type of data. It may take into account the cost of collecting the data. Therefore, the margin may be lower if the data owner has collected the data for its own business without making significant investments, or it may be higher if a significant investment is required to collect the data for the purposes of the data owner’s business. In cases where the use of the data by the data recipient does not affect the data controller’s own activities, the margin may be limited or even excluded. In addition, where the data is co-generated by a connected product owned, rented or leased by the user, the consideration could be comparatively lower than in other cases where the data is generated by the data owner, for example in the provision of a connected service.(48) Intervention is not required if data is shared between large companies or if the data owner is a small or medium-sized enterprise and the data recipient is a large company. In these cases, it is assumed that the companies are able to negotiate a consideration within reasonable and non-discriminatory limits.
(49) In order to protect SMEs from excessive economic burdens that would make it excessively difficult for them to develop and operate innovative business models, the appropriate consideration to be borne by them for the provision of data should not exceed the costs directly associated with the provision of the data. Costs directly related to the provision are those costs that are attributable to the individual data access requests, taking into account that the data owner has to set up the necessary technical interfaces or the necessary software and network connection on a permanent basis. The same rule should apply to non-profit research institutions.
(51) Transparency is an important principle to ensure that the consideration requested from a data holder is reasonable or, where the data recipient is an SME or a non-profit research organization, that the consideration does not exceed the costs directly related to the provision of the data to the data recipient and attributable to the individual request. In order to enable data recipients to assess and verify whether the consideration complies with the requirements of this Regulation, the data holder should provide the data recipient with sufficiently detailed information for the calculation of the consideration.
(52) Alternative means of resolving domestic and cross-border disputes related to the provision of data should be available to data holders and data recipients alike, so that trust in data sharing is strengthened. If the parties cannot agree on fair, reasonable and non-discriminatory terms for the provision of data, dispute settlement bodies should offer the parties a simple, quick and inexpensive solution. While this Regulation only lays down the conditions that dispute resolution entities must meet in order to be certified, Member States are free to adopt specific rules on the certification procedure, including the expiry or withdrawal of certification. The provisions on dispute resolution contained in this Regulation should not oblige Member States to set up dispute resolution entities.(55) In order to ensure the uniform application of this Regulation, dispute settlement bodies should take into account the non-binding standard contractual clauses to be developed and recommended by the Commission, as well as Union or national law establishing data-sharing obligations or guidance from the relevant specialized authorities on the application of that law.
(53) The dispute resolution procedure under this Regulation is a voluntary procedure that allows users, data controllers and data recipients to agree to refer their disputes to dispute resolution bodies. Therefore, the parties should be free to turn to a dispute resolution body of their choice, whether inside or outside the Member States where those parties are established.
(54) In order to avoid the need to refer the same dispute to two or more dispute resolution entities, in particular in a cross-border situation, it should be possible for a request for dispute resolution to be rejected by a dispute resolution entity if it has already been submitted to another dispute resolution entity or to a court of a Member State.
(56) The parties to a dispute settlement procedure should not be prevented from exercising their fundamental rights to an effective remedy and to a fair trial. Therefore, the decision to refer a dispute to a dispute resolution entity should not deprive those parties of the right to appeal to a court of a Member State. The dispute settlement bodies should make annual activity reports publicly available.
(28) Union consumer law, in particular Directives 93/13/EEC and 2005/29/, applies to contracts between a data controller and a consumer as a user of a connected product or service that generates data, in order to ensure that a consumer is not subject to unfair contract terms. For the purposes of this Regulation, unfair contract terms unilaterally imposed on an undertaking should not be binding on that undertaking.(43) On the basis of the principle of contractual freedom, the parties should be free to negotiate the precise conditions for the provision of data in their contracts within the framework of the general access rules for the provision of data. The terms of such contracts could also cover technical and organizational measures, including in relation to data security.(44) In order to ensure that the conditions for mandatory data access are fair for both parties, the general rules on data access rights should refer to the rule on the avoidance of unfair contract terms.(58) If one party is in a stronger negotiating position, there is a risk that it could exploit this position to the detriment of the other party when negotiating access to data, with the result that access to data is less commercially viable and sometimes unsustainable. Such contractual imbalances are detrimental to all companies who are not really in a position to negotiate the terms of access to data and who may have no choice but to accept non-negotiable contractual terms. Therefore, unfair contract terms relating to data access and use or liability and remedies for breach or termination of data-related obligations should not be binding on companies where these terms have been unilaterally imposed on those companies.
(59) The rules on contractual terms should take into account the principle of contractual freedom as an essential concept in business relationships between companies. Therefore, not all contract terms should be subject to an unfairness test, but only those terms that are unilaterally imposed. This concerns situations where there is no room for negotiation, where one party introduces a certain contractual term and the other company cannot influence the content of this term despite attempts to negotiate. Contractual clauses that are merely introduced by one party and accepted by the other company, or clauses that are negotiated between the parties and subsequently agreed in a modified form, should not be considered unilaterally imposed.(60) In addition, the rules on unfair contract terms should only apply to those parts of a contract that relate to the provision of data, namely contractual terms on data access and use and liability or remedies for breach and termination of data-related obligations. Other parts of the same contract which are not related to the provision of data should not be subject to the unfairness test set out in this Regulation.(61) Criteria for identifying unfair contract terms should only be applied to overbroad contract terms where a stronger bargaining position has been abused. The vast majority of contract terms which are economically more favorable to one party than to the other, including those which are common in contracts between undertakings, are a normal expression of the principle of freedom of contract and continue to apply. For the purposes of this Regulation, a gross deviation from good commercial practice would mean, inter alia, that the party on whom the condition has been unilaterally imposed is objectively prejudiced in its ability to protect its legitimate commercial interest in the data concerned.(2) If contractual clauses comply with mandatory provisions of Union law or, in the absence of contractual clauses governing the matter, with applicable provisions of Union law, they shall not be considered unfair.
(62) In order to ensure legal certainty, this Regulation establishes a list of terms which are always presumed to be unfair and a list of terms which are presumed to be unfair. In the latter case, the company imposing the contract term should be able to rebut the presumption of unfairness by proving that a contract term listed in this Regulation is not unfair in the specific case. Where a contractual term is not included in the list of terms which are always presumed to be unfair or which are presumed to be unfair, the general provision on unfairness applies. In this context, the contract terms listed as unfair in this Regulation should serve as a benchmark for the interpretation of the general unfairness provision. Finally, non-binding standard contractual clauses drawn up and recommended by the Commission for contracts on the transfer of data between undertakings may also be helpful for commercial undertakings when negotiating contracts. If a contractual term is declared unfair, the contract in question should continue to apply without that term, unless the unfair term is not severable from the other contractual terms.
(63) In cases of exceptional necessity, it may be necessary for public authorities, the Commission, the European Central Bank or Union bodies to use existing data, including, where appropriate, attached metadata, held by an undertaking in the performance of their statutory duties in the public interest in order to respond to public emergencies or other exceptional situations. Exceptional need means circumstances that are unforeseeable and temporary, as opposed to other circumstances that may be planned or scheduled or occur regularly or frequently. While the term „data controller“ does not generally include public bodies, it may include public undertakings. Research institutions and research funding bodies could also be established as public bodies or bodies governed by public law. In order to limit the burden on businesses, microenterprises and small enterprises should only be required to provide data to public sector bodies, the Commission, the European Central Bank or Union bodies where such data are necessary in cases of exceptional need to respond to a public emergency and where public sector bodies, the Commission, the European Central Bank or Union bodies cannot otherwise obtain such data in a timely and effective manner under equivalent conditions.
(64) In the case of public emergencies such as public health emergencies, emergencies caused by natural disasters, including those exacerbated by climate change and environmental degradation, and man-made major disasters such as major cybersecurity incidents, the public interest in the use of the data will outweigh the interest of the data holders to freely dispose of the data they hold. In such a case, data holders should be obliged to provide the data to public authorities, the Commission, the European Central Bank or Union bodies at their request. The existence of a public emergency should be established or declared in accordance with Union or national law and on the basis of the relevant procedures, including those of the relevant international organizations. In such cases, the public sector body should demonstrate that the data subject to the request could not be obtained otherwise in a timely and effective manner and under equivalent conditions, for example through the voluntary provision of data by another entity or searches of a public database.
(65) An exceptional necessity may also arise from situations which do not constitute an emergency. In such cases, a public sector body, the Commission, the European Central Bank or a Union body should only be allowed to request non-personal data. The public sector body should demonstrate that the data are necessary to perform a specific task in the public interest explicitly provided for by law, such as the production of official statistics or the mitigation or resolution of a public emergency. In addition, such a request may only be made where the public sector body, the Commission, the European Central Bank or a Union body has identified specific data which it could not otherwise obtain in a timely and effective manner and under equivalent conditions, and only where it has exhausted all other available means, to obtain such data, such as obtaining the data through voluntary agreements, including acquiring non-personal data on the market, bidding the prevailing market rate, or by relying on existing obligations to provide data or adopting new legislation that could ensure the timely availability of the data. Furthermore, the conditions and principles for requests should apply, for example in relation to purpose limitation, proportionality, transparency and time limitation. Where data necessary for the production of official statistics are requested, the requesting public sector body should also demonstrate whether it is authorized under national law to acquire non-personal data on the market.
(66) This Regulation should neither apply to nor pre-empt voluntary data-sharing agreements between private and public entities, including the provision of data by SMEs, and is without prejudice to Union acts providing for binding requests for information from public entities to private entities. This Regulation should be without prejudice to obligations imposed on data holders to provide data that are not based on exceptional necessity, in particular where the data basis and the data holders are known or the data can be used on a regular basis, as in the case of reporting obligations and obligations arising from the internal market. Data access requirements for the purpose of verifying compliance with applicable rules should also be unaffected by this Regulation, including in cases where public sector bodies delegate the task of verifying compliance to other than public sector bodies.
(68) In carrying out their tasks in the areas of prevention, investigation, detection or prosecution of criminal or administrative offenses or the execution of criminal or administrative penalties, as well as the collection of data for tax or customs purposes, public authorities, the Commission, the European Central Bank or Union bodies should rely on their powers under Union or national law. This Regulation is therefore without prejudice to legislative acts on data sharing, data access and data use in those areas.
(72) In case of exceptional necessity in the context of a public emergency, public authorities should use non-personal data whenever possible. In the case of requests based on an exceptional necessity not related to a public emergency, no personal data can be requested. If personal data is the subject of the request, the data controller should always anonymize the data. If it is strictly necessary to provide personal data with the data to a public authority, the Commission, the European Central Bank or a Union body, or if anonymization proves impossible, the authority requesting the data should demonstrate the strict necessity and the specific and limited purposes of the processing. The applicable rules on the protection of personal data should be complied with. The provision of the data and their subsequent use should be accompanied by safeguards for the rights and interests of the data subjects.
(69) In accordance with Article 6(1) and (3) of Regulation (EU) 2016/679, a proportionate, limited and predictable framework at Union level is necessary when choosing the legal basis for the provision of data by data holders to public sector bodies, the Commission, the European Central Bank and Union bodies in cases of exceptional necessity, both to ensure legal certainty and to minimize the administrative burden on businesses. To this end, requests for data from public sector bodies, the Commission, the European Central Bank or Union bodies to data holders should be specific, transparent and proportionate in terms of their scope and level of detail. The purpose of the request and the intended use of the requested data should be specifically and clearly explained, while allowing the requesting body appropriate flexibility in the performance of its tasks in the public interest. The request should also take into account the legitimate interests of the data controller to whom it is addressed. The burden on data holders should be minimized by requiring the requesting authorities to respect the principle of uniqueness, which prevents the same data from being requested several times or by several public sector bodies, the Commission, the European Central Bank or Union bodies. In order to ensure transparency, requests for data made by the Commission, the European Central Bank or Union bodies should be published without delay by the body requesting the data. The European Central Bank and the Union bodies should inform the Commission of their requests. Where the request for data has been made by a public sector body, that body should also inform the data coordinator of the Member State in which the public sector body is established. It should be ensured that all requests are publicly available online. Following such notification of a data request, the competent authority may decide to assess the lawfulness of the request and carry out its tasks in relation to the enforcement and application of this Regulation. The data coordinator should ensure that all requests made by public sector bodies are publicly available online.
(70) The purpose of the obligation to provide data is to ensure that public authorities, the Commission, the European Central Bank or institutions of the Union have the necessary knowledge to manage or prevent public emergencies or to overcome them or to maintain the capacity to perform certain tasks expressly provided for by law. The data obtained by those bodies may constitute business secrets. Therefore, neither Regulation (EU) 2022/868 nor Directive (EU) 2019/1024 of the European Parliament and of the Council (28) should apply to data provided under this Regulation and such data should not be considered as open data available for re-use by third parties. However, this should be without prejudice to the applicability of Directive (EU) 2019/1024 to the re-use of official statistics for the production of which data obtained under this Regulation have been used, provided that the re-use does not extend to the underlying data. Furthermore, this should be without prejudice to the possibility of onward dissemination of the data for research purposes or for the development, production and dissemination of official statistics, provided that the conditions laid down in this Regulation are met. Public sector bodies should also be allowed to exchange data obtained under this Regulation with other public sector bodies, the Commission, the European Central Bank or Union bodies in order to meet the exceptional need for which they were requested.
(71) Data holders should have the possibility to either refuse or request an amendment to the request of a public sector body, the Commission, the European Central Bank or a Union body without undue delay and in any event within five or 30 working days at the latest, depending on the nature of the exceptional necessity invoked in the request. Where applicable, the data holder should have this opportunity if it has no control over the requested data, i.e. if it does not have direct access to the data and cannot determine its availability. It should be possible to justify the non-provision of the data if it can be demonstrated that the request is comparable to a request previously submitted by another public sector body or by the Commission, the European Central Bank or a Union body for the same purpose and the data holder has not been informed of the erasure of the data in accordance with this Regulation. If a data holder refuses the request or requests its amendment, it should justify the refusal to the public sector body, the Commission, the European Central Bank or the Union body that made the request. Where sui generis database rights under Directive 96/9/ of the European Parliament and of the Council (29) apply in respect of the requested data sets, data holders should exercise their rights in a way that does not prevent the public sector body, the Commission, the European Central Bank or the Union body from obtaining or disclosing the data in accordance with this Regulation.
(73) Data provided to public authorities, the Commission, the European Central Bank or Union bodies on grounds of exceptional necessity should only be used for the purposes of the data request, unless the data controller who provided the data has explicitly agreed to the data being used for other purposes. Unless otherwise agreed, the data should be deleted as soon as it is no longer necessary for the purpose stated in the request and the data controller should be informed thereof. This Regulation builds on existing Union and national access regimes and does not change national law on public access to documents related to transparency obligations. Data should be deleted as soon as they are no longer needed to comply with those transparency obligations.
(74) When re-using data provided by data holders, public sector bodies, the Commission, the European Central Bank or Union bodies should comply with both applicable Union or national law and the contractual obligations of the data holder. They should refrain both from developing or improving a connected product or service that competes with the connected product or service of the data controller and from sharing the data with third parties for these purposes. They should also publicly acknowledge a data controller at its request and be responsible for ensuring the security of the data received. Where disclosure of the data holder’s business secrets to public authorities, the Commission, the European Central Bank or Union bodies is strictly necessary to fulfill the purpose for which the data were requested, the data holder should be assured of the confidentiality of those data prior to their disclosure.
(75) When it comes to the protection of an important public good, such as the management of public emergencies, the public sector body, the Commission, the European Central Bank or the Union body concerned should not be expected to provide any consideration to undertakings for the data obtained. Public emergencies are rare events and not all such emergencies require the use of data held by undertakings. At the same time, the obligation to provide data could be a significant burden for micro and small enterprises. These businesses should therefore be able to request consideration even in the context of public emergency measures. It is not likely that the business activities of data holders will be affected by the use of this Regulation by public authorities, the Commission, the European Central Bank or Union bodies. However, as cases of exceptional necessity, other than the management of a public emergency, may be more frequent, data holders should be entitled in such cases to adequate compensation, which should not exceed the technical and organizational costs associated with fulfilling the request, and to the reasonable margin necessary to provide the data to the public sector body, the Commission, the European Central Bank or the Union body. The consideration should not be understood as payment for the data itself and should not be mandatory. Data holders should not be able to request consideration where national statistical institutes or other national authorities responsible for the production of statistics are not allowed by national law to provide data holders with consideration for the provision of data. The public sector body, the Commission, the European Central Bank or the Union body concerned should be able to challenge the amount of the consideration requested by the data holder by bringing the matter before the competent authority of the Member State in which the data holder is established.
(76) The public sector body, the Commission, the European Central Bank or a Union body should be authorized to disclose the data it has obtained on the basis of the request to other bodies or persons where this is necessary for carrying out scientific or analytical activities which it cannot carry out itself, provided that such activities are compatible with the purpose of the data request. It should inform the data controller in good time of any such disclosure. The data may also be shared with national statistical authorities and Eurostat for the development, production and dissemination of official statistics under the same circumstances. However, the research activities concerned should be compatible with the purpose of the data request and the data holder should be informed of the disclosure of the data he has provided. Individuals conducting research or research organizations to which such data may be disclosed should be either non-profit or acting in the public interest on behalf of the government. Organizations should not be considered research organizations for the purposes of this Regulation if they are subject to a significant degree of influence by commercial entities which, by virtue of their structure, could exercise control and thereby obtain privileged access to the results of the research.
(77) In order to address a cross-border public emergency or other exceptional need, requests for data may be addressed to data holders in Member States other than that of the requesting public sector body. In this case, the requesting public sector body should inform the competent authority of the Member State where the data holder is established so that it can assess the request on the basis of the criteria set out in this Regulation. This should also apply to requests from the Commission, the European Central Bank or a Union body. If personal data are requested, the public sector body should inform the supervisory authority responsible for monitoring the application of Regulation (EU) 2016/679 in the Member State where the public sector body is established. The competent authority concerned should be empowered to inform the public sector body, the Commission, the European Central Bank or the Union body that it must cooperate with the public sector bodies of the Member State where the data holder is established in order to minimize the administrative burden on the data holder. If the competent authority has valid objections as to the compatibility of the request with this Regulation, it should refuse the request of the public sector body, the Commission, the European Central Bank or the Union body, which in turn should take those objections into account before taking further action, including resubmitting the request.
(78) The ability of customers of data processing services, including cloud and edge services, to switch from one data processing service to another while maintaining a minimum set of service functionalities and without experiencing downtime, or to use services from multiple providers without undue hardship and data transfer costs, is essential for a more competitive market with lower barriers to entry for new providers of data processing services and for ensuring better resilience of users of those services. Customers benefiting from free offers should also benefit from the switching provisions laid down in this Regulation so that those offers do not create a situation of dependency for customers.(79) Regulation (EU) 2018/1807 of the European Parliament and of the Council (30) requires providers of data processing services to develop and effectively implement self-regulatory codes of conduct that include best practices, including to facilitate the switching of data processing service providers and the transfer of data. Given the limited uptake of self-regulatory frameworks developed in response and the general lack of open standards and interfaces, a set of minimum regulatory obligations needs to be established for data processing service providers in order to remove those pre-commercial, commercial, technical, contractual and organizational barriers that not only lead to reduced data transfer speeds in the event of a customer switching providers, but also prevent the effective implementation of switching between data processing services.(82) If the original data processing service provider impedes the extraction of exportable data belonging to the customer, this may hinder the restoration of the service functions in the infrastructure of the acquiring data processing service provider. In order to facilitate the customer’s exit strategy, avoid unnecessary and burdensome tasks and ensure that the customer does not lose any of its data by completing the switch, the initial data processing services provider should inform the customer in advance of the scope of data that can be exported once that customer decides to switch to another service offered by another data processing services provider or to an ICT infrastructure on its own premises. The term „exportable data“ should include at least the input and output data – including metadata – generated or co-generated directly or indirectly by the customer’s use of the data processing service, excluding assets or data from the data processing service provider or from a third party. Assets or data from the data processing service provider or from a third party that are protected by intellectual property rights or constitute trade secrets of that provider or third party, or data related to the integrity and security of the service, where the data processing service provider is exposed to cybersecurity risks in case of export, should be excluded from the exportable data. These exemptions should not hinder or delay the implementation of the change.(84) The objective of this Regulation is to facilitate switching between data processing services, including the conditions and measures necessary for a customer to be able to terminate a contract for a data processing service, to conclude one or more new contracts with different data processing service providers, to transfer its exportable data and digital assets and to benefit from functional equivalence where applicable.(91) Where providers of data processing services are themselves customers of data processing services provided by a third party, they may themselves benefit from the more effective implementation of the switch, while remaining bound by the obligations under this Regulation in relation to their own service offerings.(92) Providers of data processing services should be obliged to provide, within their capabilities and proportionate to their respective obligations, all assistance and support necessary to make the switch to the service of another provider of data processing services successful, effective and secure. This Regulation does not oblige data processing service providers to develop new categories of data processing services, including within or on the basis of the ICT infrastructure of different data processing service providers, in order to ensure functional equivalence in an environment other than their own. The original provider of data processing services has neither access to nor insight into the environment of the acquiring provider of data processing services. Functional equivalence should therefore not be understood as obliging the original provider of data processing services to recreate the service in question within the infrastructure of the acquiring provider of data processing services. Rather, the original provider of data processing services should take all reasonable measures within its powers to enable the realization of functional equivalence by providing capacity, adequate information, documentation, technical support and, where appropriate, the necessary tools.(93) Providers of data processing services should also be required to remove existing barriers and not create new ones, including in relation to customers who wish to switch to an ICT infrastructure on their own premises. Barriers may be of a pre-commercial, commercial, technical, contractual or organizational nature, among others. Providers of data processing services should also be required to remove obstacles to the separation of a particular individual service from other data processing services provided under a contract and to allow switching for the service concerned, where there are no major demonstrable technical obstacles to such separation.
(96) In order to facilitate interoperability and switching between data processing services, users and providers of data processing services should consider the use of implementation and compliance tools, in particular those published by the Commission in the form of an EU Cloud Rulebook and a Guide to public procurement for data processing services. In particular, standard contractual clauses are appropriate as they increase trust in data processing services, create a more balanced relationship between users and providers of data processing services and increase legal certainty as regards the conditions for switching to other data processing services. In this context, users and providers of data processing services should consider using the standard contractual clauses or other self-regulatory compliance tools, provided that they meet the requirements of this Regulation, developed by relevant bodies or expert groups established under Union law.
(87) Data processing services are used in different areas and differ in terms of their complexity and type of service. This must be taken into account in particular with regard to the transfer process and the corresponding time frame. However, it should only be possible to claim an extension of the transitional period if the switch cannot be completed within the envisaged time for technical reasons in duly justified cases. The burden of proof in this respect should lie entirely with the provider of the data processing service concerned. This is without prejudice to the customer’s exclusive right to extend the transition period once for a period that it deems more appropriate for its own purposes. The customer may invoke this right of extension before or during the transition period, taking into account that the contract will continue to apply during the transition period.
(95) The information that data processing service providers must provide to customers could support customers’ exit strategy. The information should include the following: Procedures for initiating the switch from the data processing service, the machine-readable data formats to which the user data can be exported, the tools for data export – including open interfaces – and information on compatibility with harmonized standards or common specifications based on open interoperability specifications, information on known technical limitations and constraints that could affect the completion of the switch, and the estimated time required to complete the switch.
(97) In order to facilitate the switching between data processing services, all parties involved, including the initial and the acquiring data processing service provider, should cooperate in good faith to make the switch effective and to enable the secure and timely transfer of the necessary data in a commonly used, machine-readable format via an open interface, while maintaining service continuity.
(89) The initial provider of data processing services should be able to outsource certain tasks and to compensate third parties for the performance of the obligations laid down in this Regulation. The costs of the outsourcing of services decided by the initial provider of data processing services during the execution of the migration should not be borne by the customer and those costs should be considered unjustified, unless they cover services provided by the provider of data processing services at the request of the customer for additional assistance in the migration that go beyond the obligations of the provider in the migration explicitly laid down in this Regulation. This Regulation does not prevent customers from providing consideration to third parties for assistance in the migration process or prevent parties from entering into fixed-term contracts for data processing services, including proportionate penalties for early termination of those contracts, in accordance with Union or national law. In order to promote competition, the phasing out of charges related to the switching of data processing services should in particular include the abolition of data extraction charges levied by a provider of data processing services on the customer. Standard service charges for the provision of the data processing services themselves are not switching charges. These standard service charges shall not be revocable and shall apply until the contract for the provision of the service concerned ceases to apply. Customers may request the provision of additional services under this Regulation which go beyond the provider’s obligations under this Regulation when switching. These additional services may be provided and invoiced by the provider if they are provided at the customer’s request and the customer agrees to the price of these services in advance.
(94) A high level of security should be maintained throughout the implementation of the change. This means that the original provider of data processing services should extend the level of security it has committed to in relation to the service to all technical modalities – such as network connections or physical devices – for which it is responsible during the implementation of the switch. Existing rights related to the termination of contracts, including those introduced by Regulation (EU) 2016/679 and Directive (EU) 2019/770 of the European Parliament and of the Council (31), should remain unaffected. This Regulation should not be understood as preventing a provider of data processing services from offering new and improved services, features and functionalities to customers or from competing with other providers of data processing services on that basis.
(90) An ambitious and innovation-promoting regulatory approach to interoperability is needed to prevent lock-in to specific providers to the detriment of competition and the development of new services. Interoperability between data processing services requires several interfaces and infrastructure levels as well as software and is rarely limited to the simple question of whether it can be achieved or not. Rather, establishing the necessary interoperability depends on a cost-benefit analysis to determine whether it makes sense to strive for the reasonably foreseeable results. The ISO/IEC 19941:2017 standard is an important international standard that provides an important reference point for achieving the objectives of this Regulation, as it includes technical considerations to clarify the complexity of such a process.
(98) Data processing services for services where most of the main features are specifically tailored to the specific requirements of a single customer or where all components have been developed for the purposes of a single customer should be exempted from some of the obligations applicable to switching between data processing services. Services offered by the provider of data processing services through its catalog of services on a large commercial scale should not be included. It is one of the obligations of the provider of data processing services to duly inform potential customers of such services of those obligations laid down in this Regulation which do not apply to the services concerned before the conclusion of a contract. The provider of data processing services is not prevented from eventually launching such services on a large scale, in which case it would, however, have to comply with all obligations for switching laid down in this Regulation.
(101) Third countries may adopt laws, regulations and other legal acts aimed at ensuring that non-personal data stored outside their borders, including in the Union, can be transferred or that public authorities have direct access to such data. Court judgments or decisions issued in third countries by other judicial or administrative authorities, including law enforcement authorities, requesting such transfer of or access to non-personal data should be enforceable if they are based on an international agreement, such as a mutual legal assistance treaty, existing between the requesting third country and the Union or a Member State. It may also sometimes be the case that the obligation to transfer or grant access to non-personal data arising from the law of a third country conflicts with an obligation to protect such data under Union law or the national law of the Member State concerned, in particular as regards the protection of individuals’ fundamental rights, such as the right to security and the right to an effective remedy, or the fundamental interests of a Member State relating to national security or defense, as well as the protection of sensitive commercial data, including the protection of trade secrets, and the protection of intellectual property rights, including contractual confidentiality obligations under such law. In the absence of an international agreement regulating these issues, the transfer of or access to non-personal data should only be allowed if it has been verified that the legal system of the third country concerned provides for the justification and proportionality and the sufficient precision of the judicial order or decision and allows the addressee to submit its reasoned objection for review by the competent court of the third country, which is empowered to take due account of the relevant legal interests of the provider of the data. Where possible, the provider of data processing services should be able to inform the customer whose data are requested in the context of the data access request of the third-country authority before granting access to those data in order to verify whether such access may be in breach of Union or national law, such as that on the protection of sensitive commercial data, including the protection of trade secrets and intellectual property rights and contractual confidentiality obligations.(102) In order to further strengthen trust in data, it is important that safeguards to ensure that Union citizens, public authorities and businesses have control over their data are implemented as far as possible. In addition, Union law, values and standards should be upheld, including in relation to security, data protection, privacy and consumer protection. In order to prevent unlawful government access to non-personal data by the authorities of third countries, providers of data processing services subject to this Regulation, such as cloud and edge services, should take all reasonable measures to prevent access to systems where non-personal data is stored, including, where appropriate, by encrypting data, conducting frequent audits, verifying compliance with relevant security certification schemes and amending company policies.
(103) Standardization and semantic interoperability should play an important role in providing technical solutions to ensure interoperability within and between European common data spaces, which are purpose- or sector-specific or cross-sectoral interoperable frameworks for common standards and procedures for the sharing or joint processing of data, including for the development of new products and services, scientific research or civil society initiatives. This Regulation should lay down certain essential interoperability requirements. Participants in data spaces that offer data or data services to other participants and that are entities that facilitate or are involved in the sharing of data within common European data spaces, including data holders, should comply with those requirements insofar as they concern elements under their control. Compliance with those requirements may be ensured by compliance with the essential requirements laid down in this Regulation or presumed on the basis of compliance with harmonized standards or common specifications in the context of a presumption of conformity. In order to facilitate compliance with the interoperability requirements, it is necessary to provide for a presumption of conformity for interoperability solutions that comply in whole or in part with the harmonized standards referred to in Regulation (EU) No 1025/2012, which constitutes the standard framework for the development of the standards according to which such presumptions of conformity are provided. The Commission should assess the barriers to interoperability and prioritize the standardization needs so that, on that basis, it can mandate one or more European standardization bodies in accordance with Regulation (EU) No 1025/2012 to develop draft harmonized standards that meet the essential requirements laid down in this Regulation. Where such mandates do not result in harmonized standards or where such harmonized standards are not sufficient to ensure conformity with the essential requirements laid down in this Regulation, the Commission should be able to adopt common specifications in those areas, provided that it duly respects the role and functions of the standardization organisations. Common specifications should only be adopted as an exceptional fallback solution to facilitate compliance with the essential requirements of this Regulation, or where the standardization process is blocked, or in the event of delays in the adoption of appropriate harmonized standards. Where a delay is due to the technical complexity of the standard concerned, the Commission should take this into account before considering the adoption of common specifications. Common specifications should be developed in an open and inclusive manner, taking into account, where appropriate, the advice of the European Data Innovation Board (EDIB) established under Regulation (EU) 2022/868. In addition, common specifications could also be adopted in the different sectors, based on their specific needs, in accordance with Union or national law. In addition, the Commission should be enabled to mandate the development of harmonized standards for the interoperability of data processing services.
(99) In line with the minimum requirement to enable switching of providers of data processing services, this Regulation also aims to improve interoperability for the parallel use of multiple data processing services through complementary functionalities. This concerns situations where customers do not terminate a contract with a view to switching to another provider of data processing services, but where several services from different providers are used in parallel and interoperably in order to be able to use the complementary functionalities of the different services in the customer’s system configuration. However, in contrast to the one-off extraction required when completing a switch, data extraction from one data processing service provider to another with the aim of facilitating the parallel use of services can, as is well known, be an ongoing process. Providers of data processing services should therefore be able to continue to charge data extraction fees for data extraction for the purposes of parallel use after three years from the date of entry into force of this Regulation, provided that those fees do not exceed the costs incurred. Among other things, this is important for the successful introduction of multi-cloud strategies, which enable customers to implement future-proof IT strategies and reduce dependence on individual providers of data processing services. Facilitating a multi-cloud approach for customers of data processing services can also help to strengthen the operational resilience of customers’ digital systems, as stated in Regulation (EU) 2022/2554 of the European Parliament and of the Council (32) in relation to providers of financial services.
(100) Open interoperability specifications and standards developed in accordance with Annex II to Regulation (EU) No 1025/2012 of the European Parliament and of the Council (33) in the area of interoperability and portability are expected to enable a multi-vendor cloud environment, which is an essential prerequisite for open innovation in the European data economy. As the uptake of defined standards in the market under the Cloud Standardization Coordination (CSC) initiative completed in 2016 has been subdued, the Commission must also rely on market participants to develop relevant open interoperability specifications to keep pace with the rapid technological progress in this industry. Such open interoperability specifications can then be adopted by the Commission in the form of common specifications. Furthermore, where it has not been demonstrated that common specifications or standards facilitating effective cloud interoperability of the processing of data at PaaS and SaaS level can be established through market-driven processes, the Commission should be able, on the basis of this Regulation and in accordance with Regulation (EU) No 1025/2012, to mandate European standardization bodies to develop such standards for specific types of services for which such standards do not yet exist. In addition, the Commission will encourage market players to develop relevant open interoperability specifications. Following a stakeholder consultation, the Commission should be able, by means of implementing acts, to require the use of harmonized interoperability standards or common interoperability specifications for certain types of services by means of a reference in a central Union database of interoperability standards for data processing services. Providers of data processing services should ensure compatibility with those harmonized standards and common specifications on the basis of open interoperability specifications which should not compromise the security or integrity of the data. Harmonized standards for interoperability of data processing services and common specifications based on open interoperability specifications are only referred to if they comply with the criteria set out in this Regulation, which have the same importance as the requirements set out in Annex II to Regulation (EU) No 1025/2012 and the interoperability aspects defined in the international standard ISO/IEC 19941:2017. In addition, the needs of SMEs should be taken into account in the standardization process.
(104) In order to promote the interoperability of tools for the automated implementation of data-sharing agreements, it is necessary to lay down essential requirements for smart contracts that professionals create for others or integrate into applications that support the implementation of data-sharing agreements. In order to facilitate the compliance of such smart contracts with these essential requirements, it is necessary to provide for a presumption of conformity for the smart contracts that comply in whole or in part with the harmonized standards under Regulation (EU) No 1025/2012. The term „smart contract“ in this Regulation is technology-neutral. Smart contracts can, for example, be linked to an electronic register of transactions. The essential requirements should only apply to providers of smart contracts, but not when they draw up smart contracts internally for internal use only. The essential requirement to ensure that smart contracts can be suspended and terminated presupposes the mutual consent of the parties to the data sharing agreement. The applicability of the relevant provisions of civil, contract and consumer protection law to data sharing agreements remains or should remain unaffected by the use of smart contracts for the automated execution of such agreements.(105) In order to demonstrate compliance with the essential requirements of this Regulation, the provider of a smart contract – or, failing that, the person whose trade, business or profession involves the implementation of smart contracts for others in connection with the implementation of an agreement or parts thereof for the provision of data in the context of this Regulation – should carry out a conformity assessment and draw up an EU declaration of conformity. That conformity assessment should be subject to the general principles laid down in Regulation () No 765/2008 of the European Parliament and of the Council (34) and Decision () No 768/2008 of the European Parliament and of the Council (35).(106) In addition to requiring professional developers of smart contracts to comply with essential requirements, it is also important to encourage those participants in data spaces that offer data or data-based services to other participants within and through common European data spaces to support the interoperability of data sharing tools, including smart contracts.
(107) In order to ensure the application and enforcement of this Regulation, Member States should designate one or more competent authorities. Where a Member State designates more than one competent authority, it should also designate a data coordinator among them. Competent authorities should cooperate with each other. By exercising their investigatory powers in accordance with applicable national procedures, competent authorities should be able to seek and obtain information, in particular in relation to the activities of entities under their jurisdiction and, including in the context of joint investigations, taking due account of the fact that supervisory and enforcement measures in relation to entities under the jurisdiction of another Member State should be adopted by the competent authority of that other Member State, where appropriate in accordance with the procedures for cross-border cooperation. Competent authorities should assist each other in a timely manner, in particular where a competent authority in one Member State has or can gather relevant information for an investigation carried out by competent authorities in other Member States to which the competent authorities in the Member State where the entity is established do not have access. Competent authorities and data coordinators should be listed in a public register kept by the Commission. The data coordinator could provide additional assistance in facilitating cooperation in cross-border situations, for example where a competent authority in a particular Member State does not know which authority it should contact in the Member State of the data coordinator, for example where the case involves more than one competent authority or more than one sector. The data coordinator should act as a single point of contact for all questions related to the application of this Regulation. Where no data coordinator has been designated, the competent authority should assume the tasks assigned to the data coordinator under this Regulation. The competent authorities responsible for monitoring compliance with data protection law and the competent authorities designated under Union or national law should be responsible for the application of this Regulation in their areas of competence. In order to avoid conflicts of interest, the authorities responsible for the application and enforcement of this Regulation in the area of provision of data following a request based on exceptional necessity should not have the right to make such a request.
(19) The term „data literacy“ refers to the skills, knowledge and understanding that enable users, consumers and businesses, in particular SMEs falling within the scope of this Regulation, to become aware of the potential value of the data they generate, produce and share, and motivate them to offer and provide access to their data in accordance with the relevant legislation. Data literacy should go beyond the acquisition of knowledge about tools and technologies and aim to enable and empower citizens and businesses to benefit from an inclusive and fair data market. The dissemination of data literacy measures and the introduction of appropriate follow-up measures could help to improve working conditions and ultimately support the consolidation and innovation pathway of the data economy in the Union. Competent authorities should promote tools and take measures to improve the data literacy of users and entities falling within the scope of this Regulation and make them aware of their rights and obligations under this Regulation.
(108) In order to enforce their rights under this Regulation, natural and legal persons should have the right to lodge a complaint in the event of a breach of their rights under this Regulation. The data coordinator should provide natural and legal persons, on request, with all necessary information to enable them to lodge a complaint with the competent authority concerned. Those authorities should be obliged to cooperate with each other so that the complaint can be dealt with appropriately and resolved effectively and expeditiously. In order to make use of the mechanism of the Consumer Protection Cooperation Network and to enable representative actions, this Regulation amends the Annexes to Regulation (EU) 2017/2394 of the European Parliament and of the Council (36) and to Directive (EU) 2020/1828 of the European Parliament and of the Council (37).
(109) Competent authorities should ensure that sanctions apply to breaches of the obligations laid down in this Regulation. Such penalties could include financial penalties, warnings, reprimands or orders to bring business practices into compliance with the obligations laid down in this Regulation. The sanctions determined by the Member States should be effective, proportionate and dissuasive and should take into account the recommendations of the EDIB, thus contributing to the highest level of consistency in the determination and application of sanctions. Competent authorities should, where appropriate, take interim measures to limit the impact of a suspected infringement while the investigation of that infringement is ongoing. In doing so, they should take into account, inter alia, the nature, gravity, extent and duration of the breach in relation to the public interest concerned, the scale and nature of the activities carried out and the economic capacity of the breaching party. They should also take into account whether the infringer systematically or repeatedly fails to comply with its obligations under this Regulation. In order to ensure compliance with the ne bis in idem principle, and in particular to avoid that the same breach of the obligations under this Regulation is sanctioned more than once, a Member State intending to exercise its jurisdiction over an infringing party that is not established in the Union and has not designated a representative in the Union should inform all data coordinators and the Commission without undue delay.
(111) In order to assist companies in drafting and negotiating contracts, the Commission should draw up and recommend non-binding standard contractual clauses for data-sharing contracts between companies, taking into account, where necessary, the conditions in certain sectors and existing practices with voluntary data-sharing mechanisms. These model contract clauses should primarily provide a practical tool to facilitate the conclusion of a contract, in particular for SMEs. If the model contract provisions are used comprehensively and consistently, they should also have a positive impact on the design of data access and data use contracts and thus lead to fairer contractual relationships for data access and data sharing overall.
(110) The EDIB should advise and assist the Commission in coordinating national procedures and policies on the issues covered by this Regulation and in achieving its objectives in relation to technical standardization to improve interoperability. It should also play a key role in initiating comprehensive discussions between the competent authorities on the application and enforcement of this Regulation. This exchange of information should improve effective access to justice, enforcement and judicial cooperation across the Union. Among other tasks, competent authorities should use the EDIB as a platform for the assessment, coordination and adoption of recommendations for the establishment of sanctions for infringements of this Regulation. It should enable competent authorities, with the support of the Commission, to agree on an optimal approach to the determination and imposition of such penalties. This approach avoids fragmentation while providing flexibility to Member States and should lead to effective recommendations that support the uniform application of this Regulation. The EDIB should also have an advisory role in the standardization procedures and the adoption of common specifications by means of implementing acts and in the adoption of delegated acts to establish a monitoring mechanism for the switching fees charged by providers of data processing services and to further specify the essential requirements for data interoperability, data sharing mechanisms and services and for the common European data spaces. It should also advise and assist the Commission in the adoption of the guidelines defining interoperability specifications for the functioning of the common European data spaces.
(112) In order to avoid the risk that the holders of data obtained or generated by physical components such as sensors of a connected product and service or other machine-generated data in databases may invoke the sui generis right under Article 7 of Directive 96/9/ and thereby hinder, in particular, the effective exercise of the right of users to access and use data and the right to disclose data to third parties under this Regulation, it should be clarified that the sui generis right does not apply to such databases. This is without prejudice to the possible application of the sui generis right under Article 7 of Directive 96/9/ to databases containing data which do not fall within the scope of this Regulation, provided that the protection requirements laid down in paragraph 1 of that Article are fulfilled.
(113) In order to take account of the technical aspects of data processing services, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission in respect of supplementing this Regulation by introducing a monitoring mechanism of the switching fees charged by providers of data processing services on the market and by further specifying the essential requirements regarding interoperability for data space participants offering data or data services to other data space participants. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (38). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.(114) In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission in respect of the adoption of common specifications for ensuring the interoperability of data, data sharing mechanisms and services and common European data spaces, common specifications for the interoperability of data processing services and common specifications for the interoperability of smart contracts. Implementing powers should also be conferred on the Commission in respect of the publication of references to harmonized standards and common specifications for the interoperability of data processing services in the central Union database of standards for the interoperability of data processing services. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council (39).
(117) In order to allow participants falling within the scope of this Regulation to adapt to the new provisions of this Regulation and to take the necessary technical precautions, those provisions should only apply from September 12, 2025.
(118) The European Data Protection Supervisor and the European Data Protection Board were consulted in accordance with Article 42(1) and (2) of Regulation (EU) 2018/1725 and delivered their opinions on May 4, 2022.