fold out | fold

Chap­ter I Gene­ral provisions

(1) In recent years, data-dri­ven tech­no­lo­gies have had a trans­for­ma­ti­ve effect on all sec­tors of the eco­no­my. In par­ti­cu­lar, the rapid pro­li­fe­ra­ti­on of inter­net-con­nec­ted pro­ducts has increa­sed the scope and poten­ti­al value of data for con­su­mers, busi­nesses and socie­ty. High-qua­li­ty and inter­ope­ra­ble data from dif­fe­rent sec­tors increa­ses com­pe­ti­ti­ve­ness and inno­va­ti­on and ensu­res sus­tainable eco­no­mic growth. The same data can be used and reu­sed inde­fi­ni­te­ly for dif­fe­rent pur­po­ses wit­hout com­pro­mi­sing qua­li­ty or quantity.
(2) Howe­ver, bar­riers to data sha­ring pre­vent the opti­mal dis­tri­bu­ti­on of data for the bene­fit of socie­ty. The­se bar­riers include the lack of incen­ti­ves for data owners to vol­un­t­a­ri­ly enter into data sha­ring agree­ments, uncer­tain­ties regar­ding rights and obli­ga­ti­ons rela­ted to data, the cost of con­trac­ting for and set­ting up tech­ni­cal inter­faces, the high frag­men­ta­ti­on of infor­ma­ti­on in data silos, poor manage­ment of meta­da­ta, lack of stan­dards for seman­tic and tech­ni­cal inter­ope­ra­bi­li­ty, bot­t­len­ecks in data access, lack of stan­dar­di­zed pro­ce­du­res for data sha­ring, and the abu­se of con­trac­tu­al imba­lan­ces regar­ding data access and use.
(3) In sec­tors with a lar­ge num­ber of micro, small and medi­um-sized enter­pri­ses as defi­ned in Artic­le 2 of the Annex to Com­mis­si­on Recom­men­da­ti­on 2003/361/ (5) (SMEs), the­re is often a lack of digi­tal capa­ci­ty and skills to coll­ect, ana­ly­ze and use data, and access is often limi­t­ed becau­se a sin­gle actor in the system holds the data or becau­se data or data ser­vices are not inter­ope­ra­ble per se or across borders.
(4) In order to meet the needs of the digi­tal eco­no­my and to remo­ve the obs­ta­cles to the smooth func­tio­ning of the inter­nal mar­ket for data, it is neces­sa­ry to estab­lish a har­mo­ni­zed frame­work spe­ci­fy­ing who is entit­led to use pro­duct data or rela­ted ser­vice data, under what con­di­ti­ons and on what basis. The­r­e­fo­re, Mem­ber Sta­tes should not adopt or main­tain addi­tio­nal natio­nal requi­re­ments in mat­ters fal­ling within the scope of this Regu­la­ti­on, unless express­ly pro­vi­ded for in this Regu­la­ti­on, as this would affect its direct and uni­form appli­ca­ti­on. Fur­ther­mo­re, mea­su­res taken at Uni­on level should be wit­hout pre­ju­di­ce to the obli­ga­ti­ons and com­mit­ments ari­sing from inter­na­tio­nal trade agree­ments con­clu­ded by the Union.
(5) This Regu­la­ti­on ensu­res that users of a con­nec­ted pro­duct or con­nec­ted ser­vice in the Uni­on have time­ly access to the data gene­ra­ted when using that con­nec­ted pro­duct or con­nec­ted ser­vice and that tho­se users can use the data and also share it with third par­ties of their choice. It obli­ges data hol­ders to make the data available to users and third par­ties of their choice in cer­tain cir­cum­stances. It also ensu­res that data hol­ders pro­vi­de data to data reci­pi­en­ts in the Uni­on on fair, rea­sonable and non-dis­cri­mi­na­to­ry terms and in a trans­pa­rent man­ner. Pri­va­te law rules are cru­cial in the over­all frame­work for data sha­ring. The­r­e­fo­re, this Regu­la­ti­on adapts con­tract law rules and pre­vents the explo­ita­ti­on of con­trac­tu­al imba­lan­ces that ham­per fair access to and use of data. This Regu­la­ti­on also ensu­res that data hol­ders pro­vi­de public sec­tor bodies and the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies with the data neces­sa­ry for the per­for­mance of a spe­ci­fic task car­ri­ed out in the public inte­rest in case of excep­tio­nal neces­si­ty. In addi­ti­on, this Regu­la­ti­on aims to faci­li­ta­te swit­ching bet­ween data pro­ce­s­sing ser­vices and to impro­ve the inter­ope­ra­bi­li­ty of data and data sha­ring mecha­nisms and ser­vices in the Uni­on. This Regu­la­ti­on should not be inter­pre­ted as con­fer­ring on data hol­ders a new right to use data gene­ra­ted when using a con­nec­ted pro­duct or service.
(6) Data gene­ra­ti­on is the result of the actions of at least two actors, in par­ti­cu­lar the deve­lo­per or manu­fac­tu­rer of a con­nec­ted pro­duct, which in many cases may also be a pro­vi­der of con­nec­ted ser­vices, and the user of the con­nec­ted pro­duct or ser­vice. Que­sti­ons of fair­ness ari­se in the digi­tal eco­no­my, as the data coll­ec­ted by such con­nec­ted pro­ducts or con­nec­ted ser­vices is an important asset for after-mar­ket ser­vices, ancil­la­ry ser­vices and other ser­vices. In order to reap the important eco­no­mic bene­fits of data and to encou­ra­ge busi­nesses in the Uni­on to share data on the basis of vol­un­t­a­ry agree­ments and to deve­lop data-dri­ven value crea­ti­on, a gene­ral approach to the allo­ca­ti­on of rights of access to and use of data is pre­fera­ble to gran­ting exclu­si­ve rights of access and use. This Regu­la­ti­on pro­vi­des for hori­zon­tal rules that could be fol­lo­wed by Uni­on or natio­nal law taking into account the spe­ci­fic cir­cum­stances of the sec­tors concerned.
(119) Sin­ce the objec­ti­ves of this Regu­la­ti­on, name­ly to ensu­re a fair dis­tri­bu­ti­on of the value of data among actors in the data eco­no­my and to pro­mo­te fair access to and use of data in order to con­tri­bu­te to the crea­ti­on of a genui­ne inter­nal mar­ket for data, can­not be suf­fi­ci­ent­ly achie­ved by the Mem­ber Sta­tes but can rather, by rea­son of the sca­le and effects of the action and the cross-bor­der use of data, be bet­ter achie­ved at Uni­on level, the Uni­on may adopt mea­su­res, in accordance with the prin­ci­ple of sub­si­dia­ri­ty as set out in Artic­le 5 of the Trea­ty on Euro­pean Uni­on. In accordance with the prin­ci­ple of pro­por­tio­na­li­ty, as set out in that Artic­le, this Regu­la­ti­on does not go bey­ond what is neces­sa­ry in order to achie­ve tho­se objectives.
Artic­le 1 Sub­ject mat­ter and scope
(1) This Regu­la­ti­on con­ta­ins har­mo­ni­zed pro­vi­si­ons on, inter alia
a) the pro­vi­si­on of pro­duct data and con­nec­ted ser­vice data to the user of the con­nec­ted pro­duct or con­nec­ted service,
b) the pro­vi­si­on of data by data con­trol­lers to data recipients,
c) the pro­vi­si­on of data by data con­trol­lers to public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies whe­re the­re is an excep­tio­nal need to use such data for the per­for­mance of a spe­ci­fic task car­ri­ed out in the public interest,
d) the faci­li­ta­ti­on of swit­ching bet­ween data pro­ce­s­sing services,
e) the intro­duc­tion of pro­tec­ti­ve mea­su­res against unlawful access by third par­ties to non-per­so­nal data and
f) the deve­lo­p­ment of inter­ope­ra­bi­li­ty stan­dards for data to be retrie­ved, trans­mit­ted and used.
(2) This Regu­la­ti­on covers per­so­nal and non-per­so­nal data, inclu­ding the fol­lo­wing types of data, in the fol­lo­wing con­texts:
a) Chap­ter II applies to data, with the excep­ti­on of con­tent rela­ting to the per­for­mance, use and envi­ron­ment of con­nec­ted pro­ducts and con­nec­ted services;
b) Chap­ter III applies to all pri­va­te sec­tor data sub­ject to legal obli­ga­ti­ons regar­ding data sharing;
c) Chap­ter IV applies to all pri­va­te sec­tor data retrie­ved and used on the basis of con­tracts bet­ween companies;
d) Chap­ter V applies to all pri­va­te sec­tor data with a focus on non-per­so­nal data;
e) Chap­ter VI applies to all data and ser­vices pro­ce­s­sed by pro­vi­ders of data pro­ce­s­sing services;
f) Chap­ter VII shall app­ly to all non-per­so­nal data held in the Uni­on by pro­vi­ders of data pro­ce­s­sing services.
(3) This regu­la­ti­on applies to
a) manu­fac­tu­r­ers of con­nec­ted devices pla­ced on the Uni­on mar­ket and pro­vi­ders of con­nec­ted ser­vices, irre­spec­ti­ve of the place of estab­lish­ment of tho­se manu­fac­tu­r­ers or providers;
b) the users of the con­nec­ted pro­ducts or con­nec­ted ser­vices refer­red to in point (a) in the Union;
c) Data hol­ders, regard­less of their place of estab­lish­ment, who pro­vi­de data to data reci­pi­en­ts in the Union;
d) Data reci­pi­en­ts in the Uni­on to whom data is provided;
e) public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies reque­st­ing data con­trol­lers to pro­vi­de data whe­re the­re is an excep­tio­nal need to use such data for the per­for­mance of a spe­ci­fic task car­ri­ed out in the public inte­rest, and data con­trol­lers pro­vi­ding such data in respon­se to such a request;
f) pro­vi­ders of data pro­ce­s­sing ser­vices, whe­re­ver estab­lished, offe­ring such ser­vices to cus­to­mers in the Union;
g) Data room par­ti­ci­pan­ts and appli­ca­ti­on pro­vi­ders using smart con­tracts and per­sons who­se com­mer­cial, busi­ness or pro­fes­sio­nal acti­vi­ties invol­ve the imple­men­ta­ti­on of smart con­tracts for others in con­nec­tion with the per­for­mance of an agreement.
(4) Whe­re refe­rence is made in this Regu­la­ti­on to con­nec­ted pro­ducts or con­nec­ted ser­vices, such refe­ren­ces shall include vir­tu­al assi­stants inso­far as they inter­act with a con­nec­ted pro­duct or con­nec­ted service. 
(5) This Regu­la­ti­on shall app­ly wit­hout pre­ju­di­ce to Uni­on and natio­nal law on the pro­tec­tion of per­so­nal data, pri­va­cy, con­fi­den­tia­li­ty of com­mu­ni­ca­ti­ons and inte­gri­ty of ter­mi­nal equip­ment appli­ca­ble to per­so­nal data pro­ce­s­sed in the con­text of the rights and obli­ga­ti­ons laid down in this Regu­la­ti­on, in par­ti­cu­lar Regu­la­ti­ons (EU) 2016/679 and (EU) 2018/1725 and Direc­ti­ve 2002/58/, inclu­ding the powers and respon­si­bi­li­ties of super­vi­so­ry aut­ho­ri­ties and the rights of data sub­jects. Whe­re users are data sub­jects, the rights set out in Chap­ter II of this Regu­la­ti­on sup­ple­ment the right of access of data sub­jects and the right to data por­ta­bi­li­ty under Artic­le 15 and Artic­le 20 of Regu­la­ti­on (EU) 2016/679 respec­tively. In the event of a con­flict bet­ween this Regu­la­ti­on and Uni­on law on the pro­tec­tion of per­so­nal data or pri­va­cy or natio­nal law adopted in accordance with Uni­on law, Uni­on law or natio­nal law on the pro­tec­tion of per­so­nal data or pri­va­cy shall prevail.
(7) The fun­da­men­tal right to the pro­tec­tion of per­so­nal data is safe­guard­ed in par­ti­cu­lar by Regu­la­ti­ons (EU) 2016/679 (6) and (EU) 2018/1725 (7) of the Euro­pean Par­lia­ment and of the Coun­cil. Direc­ti­ve 2002/58/ of the Euro­pean Par­lia­ment and of the Coun­cil (8) also pro­tects the pri­va­cy and con­fi­den­tia­li­ty of com­mu­ni­ca­ti­ons, inclu­ding through con­di­ti­ons for the sto­rage of and access to per­so­nal and non-per­so­nal data on ter­mi­nal equip­ment. The­se Uni­on legis­la­ti­ve acts form the basis for sus­tainable and respon­si­ble data pro­ce­s­sing, even when data sets con­tain a mix­tu­re of per­so­nal and non-per­so­nal data. This Regu­la­ti­on com­ple­ments and is wit­hout pre­ju­di­ce to Uni­on law on the pro­tec­tion of per­so­nal data and pri­va­cy, in par­ti­cu­lar Regu­la­ti­ons (EU) 2016/679 and (EU) 2018/1725 and Direc­ti­ve 2002/58/. Not­hing in this Regu­la­ti­on should be applied or inter­pre­ted in such a way as to wea­k­en or rest­rict the right to the pro­tec­tion of per­so­nal data or the right to pri­va­cy and con­fi­den­tia­li­ty of com­mu­ni­ca­ti­ons. Any pro­ce­s­sing of per­so­nal data under this Regu­la­ti­on should com­ply with Uni­on data pro­tec­tion law, inclu­ding the requi­re­ment of a valid legal basis for pro­ce­s­sing pur­su­ant to Artic­le 6 of Regu­la­ti­on (EU) 2016/679 and, whe­re appli­ca­ble, the con­di­ti­ons laid down in Artic­le 9 of that Regu­la­ti­on and Artic­le 5(3) of Direc­ti­ve 2002/58/. This Regu­la­ti­on does not con­sti­tu­te a legal basis for the coll­ec­tion or gene­ra­ti­on of per­so­nal data by the data con­trol­ler. This Regu­la­ti­on obli­ges data con­trol­lers to pro­vi­de users with per­so­nal data to third par­ties of their choice or at the request of a user. Such access should be gran­ted in the case of per­so­nal data pro­ce­s­sed by the data con­trol­ler on the basis of one of the legal bases refer­red to in Artic­le 6 of Regu­la­ti­on (EU) 2016/679. Whe­re the user is not the data sub­ject, this Regu­la­ti­on does not pro­vi­de a legal basis for gran­ting access to per­so­nal data or for making it available to third par­ties and should not be under­s­tood as con­fer­ring a new right on the data con­trol­ler to use per­so­nal data gene­ra­ted in the use of a con­nec­ted pro­duct or con­nec­ted ser­vice. In the­se cases, it could be in the inte­rest of the user to enable com­pli­ance with the requi­re­ments of Artic­le 6 of Regu­la­ti­on (EU) 2016/679. Sin­ce this Regu­la­ti­on should not affect the data pro­tec­tion rights of data sub­jects, the data con­trol­ler may com­ply with data access requests in the­se cases, inter alia, by anony­mi­zing per­so­nal data or, if rea­di­ly available data con­tain per­so­nal data of seve­ral data sub­jects, by trans­mit­ting only per­so­nal data of the user.
(6) This Regu­la­ti­on neither applies to, nor pre­jud­ges, vol­un­t­a­ry agree­ments on data exch­an­ge bet­ween pri­va­te and public bodies, in par­ti­cu­lar vol­un­t­a­ry agree­ments on data sha­ring. This Regu­la­ti­on is wit­hout pre­ju­di­ce to Uni­on and natio­nal legal acts on data sha­ring, access to and use of data for the pur­po­ses of pre­ven­ti­on, inve­sti­ga­ti­on, detec­tion or pro­se­cu­ti­on of cri­mi­nal offen­ses or the exe­cu­ti­on of cri­mi­nal pen­al­ties, or for cus­toms and tax pur­po­ses, in par­ti­cu­lar Regu­la­ti­ons (EU) 2021/784, (EU) 2022/2065 and (EU) 2023/1543 and Direc­ti­ve (EU) 2023/1544 or inter­na­tio­nal coope­ra­ti­on in this area. This Regu­la­ti­on shall not app­ly to data coll­ec­tion, data sha­ring, data use or data access pur­su­ant to Regu­la­ti­on (EU) 2015/847 and Direc­ti­ve (EU) 2015/849. This Regu­la­ti­on shall not app­ly in are­as not cover­ed by Uni­on law and shall in no way affect the com­pe­ten­ces of Mem­ber Sta­tes with regard to public secu­ri­ty, defen­se or natio­nal secu­ri­ty, irre­spec­ti­ve of the type of enti­ty ent­ru­sted by Mem­ber Sta­tes with the exer­cise of tasks rela­ted to tho­se com­pe­ten­ces, or their power to safe­guard other essen­ti­al Sta­te func­tions, inclu­ding ensu­ring the ter­ri­to­ri­al inte­gri­ty of the Sta­te and the main­ten­an­ce of public order. This Regu­la­ti­on shall not affect the com­pe­ten­ces of the Mem­ber Sta­tes with regard to cus­toms and tax admi­ni­stra­ti­on or the health and safe­ty of citizens. 
(10) This Regu­la­ti­on shall be wit­hout pre­ju­di­ce to Uni­on legis­la­ti­on on data sha­ring, access to and use of data for the pur­po­ses of pre­ven­ti­on, inve­sti­ga­ti­on, detec­tion or pro­se­cu­ti­on of cri­mi­nal offen­ses or the exe­cu­ti­on of cri­mi­nal pen­al­ties, or for cus­toms and tax pur­po­ses, irre­spec­ti­ve of the legal basis under the Trea­ty on the Func­tio­ning of the Euro­pean Uni­on (TFEU) on which such Uni­on legis­la­ti­on was adopted, or to legis­la­ti­on on inter­na­tio­nal coope­ra­ti­on in this area, in par­ti­cu­lar on the basis of the Coun­cil of Euro­pe Con­ven­ti­on on Cyber­crime (ETS No. 185), which was signed in Buda­pest on Novem­ber 23, 2001. That legis­la­ti­on inclu­des Regu­la­ti­ons (EU) 2021/784 (12), (EU) 2022/2065 (13) and (EU) 2023/1543 (14) of the Euro­pean Par­lia­ment and of the Coun­cil and Direc­ti­ve (EU) 2023/1544 of the Euro­pean Par­lia­ment and of the Coun­cil (15). This Regu­la­ti­on shall not app­ly to the coll­ec­tion or sha­ring of, or access to or use of, data pur­su­ant to Regu­la­ti­on (EU) 2015/847 of the Euro­pean Par­lia­ment and of the Coun­cil (16) and Direc­ti­ve (EU) 2015/849 of the Euro­pean Par­lia­ment and of the Coun­cil (17). This Regu­la­ti­on shall not app­ly to are­as not cover­ed by Uni­on law and shall not affect the com­pe­ten­ces of Mem­ber Sta­tes in rela­ti­on to public secu­ri­ty, defen­se or natio­nal secu­ri­ty, cus­toms and tax admi­ni­stra­ti­on or the health and safe­ty of citi­zens, irre­spec­ti­ve of the type of enti­ty ent­ru­sted by Mem­ber Sta­tes with the per­for­mance of tasks rela­ting to tho­se competences.
(7) This Regu­la­ti­on com­ple­ments the self-regu­la­to­ry approach of Regu­la­ti­on (EU) 2018/1807 by adding gene­ral­ly appli­ca­ble obli­ga­ti­ons in rela­ti­on to cloud switching. 
(8) This Regu­la­ti­on shall be wit­hout pre­ju­di­ce to Uni­on and natio­nal legal acts ensu­ring the pro­tec­tion of intellec­tu­al pro­per­ty rights, in par­ti­cu­lar Direc­ti­ves 2001/29/, 2004/48/ and (EU) 2019/790.
(13) This Regu­la­ti­on is wit­hout pre­ju­di­ce to legal acts of the Uni­on and of the Mem­ber Sta­tes rela­ting to the pro­tec­tion of intellec­tu­al pro­per­ty rights, inclu­ding Direc­ti­ves 2001/29/ (19), 2004/48/ (20) and (EU) 2019/790 (21) of the Euro­pean Par­lia­ment and of the Council.
(9) This Regu­la­ti­on com­ple­ments, and is wit­hout pre­ju­di­ce to, Uni­on law pro­mo­ting the inte­rests of con­su­mers and ensu­ring a high level of con­su­mer pro­tec­tion and pro­tec­ting the health, safe­ty and eco­no­mic inte­rests of con­su­mers, in par­ti­cu­lar Direc­ti­ves 93/13/EEC, 2005/29/ and 2011/83/EU.
(11) Unless express­ly pro­vi­ded for in this Regu­la­ti­on, this Regu­la­ti­on should be wit­hout pre­ju­di­ce to Uni­on legis­la­ti­on lay­ing down phy­si­cal design and data requi­re­ments for devices to be pla­ced on the Uni­on market.
(28) Uni­on con­su­mer law, in par­ti­cu­lar Direc­ti­ves 93/13/EEC and 2005/29/, applies to con­tracts bet­ween a data con­trol­ler and a con­su­mer as a user of a con­nec­ted pro­duct or ser­vice that gene­ra­tes data, in order to ensu­re that a con­su­mer is not sub­ject to unfair con­tract terms. For the pur­po­ses of this Regu­la­ti­on, unfair con­tract terms uni­la­te­ral­ly impo­sed on an under­ta­king should not be bin­ding on that undertaking.
(10) This Regu­la­ti­on shall not pre­vent the con­clu­si­on of vol­un­t­a­ry lawful data-sha­ring con­tracts, inclu­ding con­tracts con­clu­ded on the basis of recipro­ci­ty, which meet the requi­re­ments of this Regulation.
(9) Unless other­wi­se pro­vi­ded for in this Regu­la­ti­on, it shall be wit­hout pre­ju­di­ce to natio­nal con­tract law, inclu­ding rules on the for­ma­ti­on of con­tracts, their vali­di­ty or their legal con­se­quen­ces or on the effects of the ter­mi­na­ti­on of a con­tract. This Regu­la­ti­on com­ple­ments and is wit­hout pre­ju­di­ce to Uni­on law pro­mo­ting the inte­rests of con­su­mers and ensu­ring a high level of con­su­mer pro­tec­tion and pro­tec­ting their health, safe­ty and eco­no­mic inte­rests, in par­ti­cu­lar Coun­cil Direc­ti­ve 93/13/EEC (9) and Direc­ti­ves 2005/29/ (10) and 2011/83/EU (11) of the Euro­pean Par­lia­ment and of the Council.
(115) This Regu­la­ti­on should be wit­hout pre­ju­di­ce to rules that take into account spe­ci­fic needs of indi­vi­du­al sec­tors or are­as of public inte­rest. Such rules may include addi­tio­nal requi­re­ments on the tech­ni­cal aspects of data access, such as inter­faces for data access, or on the way in which data access could be gran­ted, for exam­p­le direct­ly through the pro­duct or through data inter­me­dia­ry ser­vices. Simi­lar­ly, such rules may con­cern rest­ric­tions on the rights of data hol­ders to access or use user data or other aspects that go bey­ond data access and use, such as gover­nan­ce aspects or secu­ri­ty requi­re­ments, inclu­ding cyber­se­cu­ri­ty requi­re­ments. This Regu­la­ti­on should also be wit­hout pre­ju­di­ce to more spe­ci­fic rules rela­ted to the deve­lo­p­ment of com­mon Euro­pean data spaces or, sub­ject to the excep­ti­ons laid down in this Regu­la­ti­on, Uni­on or natio­nal law on making data acce­s­si­ble and aut­ho­ri­zing their use for the pur­po­ses of sci­en­ti­fic research.
(116) This Regu­la­ti­on should be wit­hout pre­ju­di­ce to the appli­ca­ti­on of com­pe­ti­ti­on rules, in par­ti­cu­lar Artic­les 101 and 102 TFEU. The rules pro­vi­ded for in this Regu­la­ti­on should not be used to rest­rict com­pe­ti­ti­on con­tra­ry to the rules of the TFEU.
Artic­le 2 Definitions
For the pur­po­ses of this Regu­la­ti­on, the fol­lo­wing defi­ni­ti­ons shall app­ly
1. „Data“ any digi­tal repre­sen­ta­ti­on of acts, facts or infor­ma­ti­on and any com­pi­la­ti­on of such acts, facts or infor­ma­ti­on, inclu­ding in the form of audio, visu­al or audio­vi­su­al material;
2. „Meta­da­ta“ a struc­tu­red descrip­ti­on of the con­tent or use of data that makes it easier to find or use that data;
3. „per­so­nal data“ per­so­nal data within the mea­ning of Artic­le 4(1) of Regu­la­ti­on (EU) 2016/679;
4. „Non-per­so­nal data„Data that is not per­so­nal data;
5. „net­work­ed pro­duct“ an object that obta­ins, gene­ra­tes or coll­ects data about its use or envi­ron­ment and that can trans­mit pro­duct data via an elec­tro­nic com­mu­ni­ca­ti­ons ser­vice, phy­si­cal con­nec­tion or on-device access and who­se pri­ma­ry func­tion is not the sto­rage, pro­ce­s­sing or trans­mis­si­on of data on behalf of any par­ty other than the user;
(14) Con­nec­ted devices that obtain, gene­ra­te or coll­ect data about their per­for­mance, use or envi­ron­ment through their com­pon­ents or ope­ra­ting systems and that can trans­mit such data via an elec­tro­nic com­mu­ni­ca­ti­ons ser­vice, phy­si­cal con­nec­tion or on-device access – often refer­red to as the Inter­net of Things – should fall within the scope of this Regu­la­ti­on, with the excep­ti­on of pro­to­ty­pes. Examp­les of such elec­tro­nic com­mu­ni­ca­ti­ons ser­vices include, in par­ti­cu­lar, ter­re­stri­al tele­pho­ne net­works, cable tele­vi­si­on net­works, satel­li­te net­works and near-field com­mu­ni­ca­ti­on net­works. Con­nec­ted pro­ducts are found in all sec­tors of the eco­no­my and socie­ty, inclu­ding in pri­va­te, civil or com­mer­cial infras­truc­tures, vehic­les, medi­cal equip­ment, life­style equip­ment, ships, air­craft, hou­se­hold appli­ances and con­su­mer goods, medi­cal and heal­th­ca­re pro­ducts or agri­cul­tu­ral and indu­stri­al machi­nery and equip­ment. Manu­fac­tu­r­ers’ design choices and, whe­re appli­ca­ble, Uni­on or natio­nal law addres­sing sec­tor-spe­ci­fic needs and objec­ti­ves or rele­vant decis­i­ons of com­pe­ti­ti­on aut­ho­ri­ties should deter­mi­ne what data can be pro­vi­ded by a con­nec­ted product.
(22) The net­work­ed pro­ducts may be desi­gned to make cer­tain data acce­s­si­ble direct­ly from a data store on the device or from a remo­te ser­ver to which the data is trans­mit­ted. Access to data sto­rage on the device may be enab­led via wired or wire­less local radio net­works con­nec­ted to a publicly available elec­tro­nic com­mu­ni­ca­ti­ons ser­vice or cel­lu­lar net­work. The ser­ver may be the manufacturer’s own local ser­ver capa­ci­ty or that of a third par­ty or cloud ser­vice pro­vi­der. Pro­ces­sors within the mea­ning of Artic­le 4(8) of Regu­la­ti­on (EU) 2016/679 are not con­side­red data con­trol­lers. Howe­ver, they may be express­ly com­mis­sio­ned by the con­trol­ler within the mea­ning of Artic­le 4(7) of Regu­la­ti­on (EU) 2016/679 to pro­vi­de data. Con­nec­ted pro­ducts may be desi­gned in such a way that the user or a third par­ty can pro­cess the data on the con­nec­ted pro­duct, on a com­pu­ter instance of the manu­fac­tu­rer or in an infor­ma­ti­on and com­mu­ni­ca­ti­on tech­no­lo­gy (ICT) envi­ron­ment sel­ec­ted by the user or third party.
(23) Vir­tu­al assi­stants are play­ing an incre­a­sing­ly important role in the digi­ta­lizati­on of the con­su­mer and pro­fes­sio­nal envi­ron­ment, ser­ving as a user-fri­end­ly inter­face for play­ing con­tent, obtai­ning infor­ma­ti­on or acti­vat­ing pro­ducts that are con­nec­ted to the inter­net. For exam­p­le, vir­tu­al assi­stants can ser­ve as a cen­tral gate­way in a smart home envi­ron­ment and coll­ect signi­fi­cant amounts of rele­vant data about how users inter­act with pro­ducts con­nec­ted to the Inter­net, inclu­ding tho­se manu­fac­tu­red by third par­ties, and can replace the use of manu­fac­tu­rer-pro­vi­ded inter­faces such as touch­screens or smart­phone apps. The user may wish to pro­vi­de this data to third par­ty manu­fac­tu­r­ers to enable novel smart ser­vices. Vir­tu­al assi­stants should be cover­ed by the right of access to data pro­vi­ded for in this Regu­la­ti­on. Data gene­ra­ted when a user inter­acts with a con­nec­ted pro­duct through a vir­tu­al assi­stant pro­vi­ded by an enti­ty other than the manu­fac­tu­rer of the con­nec­ted pro­duct should also be cover­ed by the right of access to data pro­vi­ded for in this Regu­la­ti­on. Howe­ver, only data resul­ting from the inter­ac­tion bet­ween the user and a con­nec­ted pro­duct or con­nec­ted ser­vice via the vir­tu­al assi­stant should be cover­ed by this Regu­la­ti­on. Data gene­ra­ted by the vir­tu­al assi­stant that is not rela­ted to the use of a con­nec­ted pro­duct or con­nec­ted ser­vice is not cover­ed by this Regulation.
(16) This Regu­la­ti­on enables users of con­nec­ted pro­ducts to use after-mar­ket ser­vices, ancil­la­ry ser­vices and other ser­vices based on data coll­ec­ted by sen­sors embedded in tho­se pro­ducts, whe­re the coll­ec­tion of such data is of poten­ti­al use for impro­ving the per­for­mance of the con­nec­ted pro­ducts. It is important to distin­gu­ish bet­ween the mar­kets for the pro­vi­si­on of such sen­sor-enab­led con­nec­ted pro­ducts and rela­ted ser­vices, on the one hand, and the mar­kets for unre­la­ted soft­ware and con­tent, such as text, audio or audio­vi­su­al con­tent, which is often sub­ject to intellec­tu­al pro­per­ty rights, on the other. The­r­e­fo­re, data gene­ra­ted by such sen­sor-equip­ped con­nec­ted pro­ducts when their users record, trans­mit, dis­play or play con­tent, inclu­ding for use by an online ser­vice, as well as the con­tent its­elf, which is often sub­ject to intellec­tu­al pro­per­ty rights, should not be cover­ed by this Regu­la­ti­on. This Regu­la­ti­on should also not app­ly to data obtai­ned or gene­ra­ted by the con­nec­ted pro­duct for the pur­po­ses of sto­rage or pro­ce­s­sing on behalf of other par­ties that are not users, or acce­s­sed through or trans­mit­ted to the con­nec­ted pro­duct, such as may be the case for ser­vers or cloud infras­truc­tures ope­ra­ted by their owners exclu­si­ve­ly on behalf of third par­ties, inclu­ding for use by an online service.
6. „Con­nec­ted ser­vice“ a digi­tal ser­vice, other than an elec­tro­nic com­mu­ni­ca­ti­ons ser­vice, inclu­ding soft­ware, which is con­nec­ted to the pro­duct at the time of purcha­se, ren­tal or lea­se in such a way that the con­nec­ted pro­duct could not per­form one or more of its func­tions wit­hout it, or which is sub­se­quent­ly con­nec­ted to the pro­duct by the manu­fac­tu­rer or a third par­ty in order to sup­ple­ment, update or adapt the func­tions of the con­nec­ted product;
(17) It is neces­sa­ry to lay down rules for pro­ducts which, at the time of purcha­se, ren­tal or lea­sing, are con­nec­ted to a con­nec­ted ser­vice in such a way that the con­nec­ted pro­duct could not per­form one or more of its func­tions wit­hout that ser­vice, or which is sub­se­quent­ly con­nec­ted to the pro­duct by the manu­fac­tu­rer or by a third par­ty in order to com­ple­ment or adapt the func­tions of the con­nec­ted pro­duct. Such con­nec­ted ser­vices invol­ve the exch­an­ge of data bet­ween the con­nec­ted pro­duct and the ser­vice pro­vi­der, i.e. they should be under­s­tood as ser­vices expli­ci­t­ly lin­ked to the ope­ra­ti­on of the func­tions of the con­nec­ted pro­duct, as in the case of ser­vices that may trans­mit com­mands to the con­nec­ted pro­duct, which in turn may affect its acti­vi­ty or beha­vi­or. Ser­vices that do not affect the ope­ra­ti­on of the con­nec­ted pro­duct and that do not trans­mit data or com­mands from the ser­vice pro­vi­der to the con­nec­ted pro­duct should not be con­side­red as con­nec­ted ser­vices. Such ser­vices could include, for exam­p­le, addi­tio­nal advi­so­ry, ana­ly­ti­cal or finan­cial ser­vices or regu­lar repair and main­ten­an­ce ser­vices. Con­nec­ted ser­vices may be offe­red as part of a purcha­se, ren­tal or lea­sing con­tract. Con­nec­ted ser­vices could also be pro­vi­ded for pro­ducts of the same type and users should rea­son­ab­ly expect them to be pro­vi­ded, taking into account the natu­re of the con­nec­ted pro­duct and public state­ments made by the sel­ler or on behalf of the sel­ler, les­sor, land­lord or other per­sons upstream in the con­trac­tu­al chain, inclu­ding the manu­fac­tu­rer, pri­or to the con­clu­si­on of the con­tract. Tho­se con­nec­ted ser­vices may them­sel­ves gene­ra­te data of value to the user, irre­spec­ti­ve of the data coll­ec­tion capa­bi­li­ties of the con­nec­ted pro­duct to which they are con­nec­ted. This Regu­la­ti­on should also app­ly to con­nec­ted ser­vices that are not pro­vi­ded by the sel­ler, les­sor or land­lord its­elf, but by a third par­ty. In case of doubt as to whe­ther the pro­vi­si­on of the ser­vice is part of the purcha­se, ren­tal or lea­sing con­tract, this Regu­la­ti­on should app­ly. Neither the sup­p­ly of elec­tri­ci­ty nor the pro­vi­si­on of con­nec­ti­vi­ty should be con­strued as rela­ted ser­vices under this Regulation.
7. „Pro­ce­s­sing“ any ope­ra­ti­on or set of ope­ra­ti­ons which is per­for­med on data or on sets of data, whe­ther or not by auto­ma­ted means, such as coll­ec­tion, recor­ding, orga­nizati­on, struc­tu­ring, sto­rage, adap­t­ati­on or altera­ti­on, retrie­val, con­sul­ta­ti­on, use, dis­clo­sure by trans­mis­si­on, dis­se­mi­na­ti­on or other­wi­se making available, ali­gnment or com­bi­na­ti­on, rest­ric­tion, era­su­re or destruction;
8. „Data pro­ce­s­sing ser­vice“ a digi­tal ser­vice pro­vi­ded to a cus­to­mer that enables ubi­qui­tous and on-demand net­work access to a shared pool of con­fi­gura­ble, sca­lable and ela­stic com­pu­ting resour­ces of a cen­tra­li­zed, dis­tri­bu­ted or high­ly dis­tri­bu­ted natu­re that can be rapid­ly pro­vi­sio­ned and released with mini­mal manage­ment effort or ser­vice pro­vi­der interaction;
(80) Com­pu­ting ser­vices should include ser­vices that enable loca­ti­on-inde­pen­dent and on-demand net­work access to a con­fi­gura­ble, sca­lable and ela­stic shared pool of dis­tri­bu­ted resour­ces. The­se com­pu­ting resour­ces include resour­ces such as net­works, ser­vers or other vir­tu­al or phy­si­cal infras­truc­tures, soft­ware – inclu­ding soft­ware deve­lo­p­ment tools – sto­rage, appli­ca­ti­ons and ser­vices. The fact that cus­to­mers of data pro­ce­s­sing ser­vices can allo­ca­te com­pu­ting resour­ces such as ser­ver time or net­work sto­rage space them­sel­ves, wit­hout inter­ac­tion with the pro­vi­der of data pro­ce­s­sing ser­vices, could be descri­bed as mini­mal admi­ni­stra­ti­ve effort and mini­mal inter­ac­tion bet­ween pro­vi­der and cus­to­mer. The term „loca­ti­on-inde­pen­dent“ is used to descri­be the pro­vi­si­on of and access to com­pu­ting capa­ci­ty over the net­work via mecha­nisms that encou­ra­ge the use of hete­ro­ge­neous thin or thick cli­ent plat­forms (from web brow­sers to mobi­le devices and work­sta­tions). The term „sca­lable“ refers to com­pu­ting resour­ces that are fle­xi­bly allo­ca­ted by the pro­vi­der of data pro­ce­s­sing ser­vices, regard­less of their geo­gra­phi­cal loca­ti­on, in order to com­pen­sa­te for fluc­tua­tions in demand. The term „ela­stic“ is used to descri­be com­pu­ting resour­ces that are pro­vi­ded and released accor­ding to demand in order to be able to quick­ly increa­se or decrea­se available resour­ces depen­ding on the workload. The term „shared pool“ is used to descri­be the com­pu­ting resour­ces pro­vi­ded to mul­ti­ple users who access the ser­vice via a shared access point, but whe­re pro­ce­s­sing is per­for­med sepa­ra­te­ly for each user, even though the ser­vice is pro­vi­ded via the same elec­tro­nic equip­ment. The term „dis­tri­bu­ted“ is used to descri­be com­pu­ting resour­ces that are loca­ted on dif­fe­rent net­work­ed com­pu­ters or devices and that com­mu­ni­ca­te and coor­di­na­te with each other by exchan­ging mes­sa­ges. The term „high­ly dis­tri­bu­ted“ is used to descri­be data pro­ce­s­sing ser­vices whe­re data is pro­ce­s­sed clo­ser to whe­re it is gene­ra­ted or coll­ec­ted, e.g. in a net­work­ed com­pu­ting device. Edge com­pu­ting, a form of this high­ly dis­tri­bu­ted data pro­ce­s­sing, is likely to give rise to new busi­ness models and cloud ser­vices that should be open and inter­ope­ra­ble from the outset.
(81) The gene­ric term „data pro­ce­s­sing ser­vices“ covers a con­sidera­ble num­ber of ser­vices with a very wide ran­ge of dif­fe­rent pur­po­ses, func­tions and tech­ni­cal struc­tures. Accor­ding to the gene­ral under­stan­ding of pro­vi­ders and users and in line with wide­ly used stan­dards, data pro­ce­s­sing ser­vices fall under one or more of the fol­lo­wing three models for the pro­vi­si­on of data pro­ce­s­sing ser­vices, name­ly „Infras­truc­tu­re-as-a-Ser­vice“ (IaaS), „Plat­form-as-a-Ser­vice“ (PaaS) and „Soft­ware-as-a-Ser­vice“ (SaaS). The­se ser­vice deli­very models are a spe­ci­fic, rea­dy-made com­bi­na­ti­on of ICT resour­ces offe­red by a pro­vi­der of data pro­ce­s­sing ser­vices. The­se three basic deli­very models for data pro­ce­s­sing ser­vices are fur­ther com­ple­men­ted by new varia­ti­ons, each with a very spe­ci­fic com­bi­na­ti­on of ICT resour­ces, such as „Sto­rage-as-a-Ser­vice“ and „Data­ba­se-as-a-Ser­vice“. Data pro­ce­s­sing ser­vices can be cate­go­ri­zed in more detail and sub­di­vi­ded into a non-exhaus­ti­ve list of data pro­ce­s­sing ser­vices that have the same main objec­ti­ve and func­tions and the same type of data pro­ce­s­sing models that are not rela­ted to the ope­ra­tio­nal cha­rac­te­ri­stics of the ser­vice (same ser­vice type). Ser­vices belon­ging to the same ser­vice type may have the same model for the pro­vi­si­on of data pro­ce­s­sing ser­vices, but while two data­ba­ses may appear to have the same main objec­ti­ve, they could fall into a more detail­ed sub-cate­go­ry of com­pa­ra­ble ser­vices after taking into account their data pro­ce­s­sing model, their dis­tri­bu­ti­on model and the use cases they are tar­ge­ted at. Ser­vices of the same ser­vice type may have dif­fe­rent and com­pe­ting cha­rac­te­ri­stics such as per­for­mance, secu­ri­ty, robust­ness and qua­li­ty of service.
9. „same type of ser­vice“ a set of data pro­ce­s­sing ser­vices that have the same main objec­ti­ve and the same ser­vice model for data pro­ce­s­sing as well as the same main functions;
10. „Data swit­ching ser­vice“ a data inter­me­dia­ry ser­vice within the mea­ning of Artic­le 2(11) of Regu­la­ti­on (EU) 2022/868;
11. „Per­son con­cer­ned“ a data sub­ject pur­su­ant to Artic­le 4(1) of Regu­la­ti­on (EU) 2016/679;
12. „Users“ a natu­ral or legal per­son who owns a net­work­ed pro­duct or to whom tem­po­ra­ry rights to use the net­work­ed pro­duct have been con­trac­tual­ly trans­fer­red or who uses the con­nec­ted services;
(18) The user of a con­nec­ted pro­duct should be under­s­tood as a natu­ral or legal per­son, such as a busi­ness, a con­su­mer or a public sec­tor body, who owns a con­nec­ted pro­duct or, for exam­p­le through a ren­tal or lea­sing con­tract, holds cer­tain tem­po­ra­ry rights of access to or use of data from the con­nec­ted pro­duct or uses con­nec­ted ser­vices for the con­nec­ted pro­duct. The­se access rights should in no way alter or inter­fe­re with the rights of data sub­jects who may inter­act with a con­nec­ted pro­duct or con­nec­ted ser­vice in rela­ti­on to the per­so­nal data gene­ra­ted by the con­nec­ted pro­duct or during the pro­vi­si­on of con­nec­ted ser­vices. The user bears the risks and enjoys the bene­fits of using the con­nec­ted pro­duct and should also have access to the data gene­ra­ted by it. He should the­r­e­fo­re be entit­led to bene­fit from the data gene­ra­ted by that con­nec­ted pro­duct and any con­nec­ted ser­vices. An owner, tenant or les­see should also be con­side­red a user, inclu­ding in cases whe­re mul­ti­ple enti­ties can be con­side­red users. In the case of mul­ti­ple users, each indi­vi­du­al user may con­tri­bu­te to data gene­ra­ti­on in dif­fe­rent ways and have an inte­rest in dif­fe­rent forms of use; examp­les include fleet manage­ment for a lea­sing com­pa­ny or mobi­li­ty solu­ti­ons for indi­vi­du­als using a car-sha­ring service.
(21) Whe­re mul­ti­ple per­sons or enti­ties are con­side­red to be users, for exam­p­le in the case of joint owner­ship or whe­re an owner, tenant or les­see has joint rights to access or use data, the design of the con­nec­ted pro­duct or con­nec­ted ser­vice or inter­face should allow each user to access the data gene­ra­ted by them. The use of con­nec­ted pro­ducts that gene­ra­te data usual­ly requi­res a user account to be set up. Such an account enables the user to be iden­ti­fi­ed by the data owner, who may be the manu­fac­tu­rer. It can also be used as a means of com­mu­ni­ca­ti­on and for sub­mit­ting and pro­ce­s­sing data access requests. If seve­ral manu­fac­tu­r­ers or pro­vi­ders of con­nec­ted ser­vices have joint­ly sold, ren­ted or lea­sed con­nec­ted pro­ducts to or pro­vi­ded inte­gra­ted ser­vices for the same user, the user should cont­act each of the par­ties with whom he has con­clu­ded a con­tract. Manu­fac­tu­r­ers or deve­lo­pers of a con­nec­ted pro­duct that is typi­cal­ly used by seve­ral per­sons should put in place the neces­sa­ry mecha­nisms to allow, whe­re appro­pria­te, the crea­ti­on of sepa­ra­te user accounts for indi­vi­du­al per­sons or the use of the same user account by seve­ral per­sons. Account-based solu­ti­ons should allow users to dele­te their accounts and the asso­cia­ted data and could pro­vi­de for the pos­si­bi­li­ty for users to ter­mi­na­te or request the ter­mi­na­ti­on of data access, use or sha­ring, in par­ti­cu­lar in cases whe­re the owner­ship of the pro­duct is trans­fer­red to other per­sons or whe­re other per­sons use the con­nec­ted pro­duct. Access should be gran­ted to the user on the basis of simp­le request pro­ce­du­res that allow for auto­ma­tic exe­cu­ti­on and do not requi­re veri­fi­ca­ti­on or appr­oval by the manu­fac­tu­rer or data owner. This means that the data should only be pro­vi­ded when the user actual­ly requests access. If auto­ma­tic exe­cu­ti­on of the data access request, for exam­p­le via a user account or the mobi­le appli­ca­ti­on pro­vi­ded with the con­nec­ted pro­duct or ser­vice, is not pos­si­ble, the manu­fac­tu­rer should inform the user how the data can be accessed.
13. „Data owner“ a natu­ral or legal per­son who is aut­ho­ri­zed or obli­ged under this Regu­la­ti­on, under appli­ca­ble Uni­on law or under natio­nal law imple­men­ting Uni­on law to use and pro­vi­de data – inclu­ding, whe­re con­trac­tual­ly agreed, pro­duct data or rela­ted ser­vice data – retrie­ved or gene­ra­ted during the pro­vi­si­on of a rela­ted service;
14. „Data reci­pi­ent“ a natu­ral or legal per­son who is acting for pur­po­ses rela­ting to their trade, busi­ness, craft or pro­fes­si­on, wit­hout being a user of a con­nec­ted pro­duct or con­nec­ted ser­vice, and to whom data is pro­vi­ded by the data con­trol­ler, inclu­ding a third par­ty to whom the data con­trol­ler pro­vi­des data at the request of the user or in accordance with a legal obli­ga­ti­on under other Uni­on law or natio­nal law adopted in accordance with Uni­on law;
15. „Pro­duct data“ data gene­ra­ted by the use of a con­nec­ted pro­duct and desi­gned by the manu­fac­tu­rer to be retrie­va­ble by a user, data owner or third par­ty, inclu­ding the manu­fac­tu­rer whe­re appli­ca­ble, via an elec­tro­nic com­mu­ni­ca­ti­on ser­vice, phy­si­cal con­nec­tion or on-device access;
(8) The prin­ci­ples of data mini­mizati­on and data pro­tec­tion by design and by default are essen­ti­al whe­re the pro­ce­s­sing invol­ves signi­fi­cant risks to the fun­da­men­tal rights of indi­vi­du­als. Taking into account the sta­te of the art, all par­ties invol­ved in data sha­ring, inclu­ding data sha­ring within the scope of this Regu­la­ti­on, should imple­ment tech­ni­cal and orga­nizatio­nal mea­su­res to pro­tect tho­se rights. The­se mea­su­res include not only pseud­ony­mizati­on and encryp­ti­on, but also the use of incre­a­sing­ly available tech­no­lo­gy that allo­ws algo­rith­ms to be used direct­ly at the point of data gene­ra­ti­on and valuable insights to be gai­ned wit­hout trans­fer­ring the data bet­ween the par­ties or unneces­s­a­ri­ly copy­ing the raw or struc­tu­red data itself.
16. „con­nec­ted ser­vice data“ Data that repres­ents the digi­tizati­on of user actions or pro­ce­s­ses in con­nec­tion with the con­nec­ted pro­duct and is inten­tio­nal­ly recor­ded by the user or gene­ra­ted as a by-pro­duct of the user’s action during the pro­vi­si­on of a con­nec­ted ser­vice by the provider;
(15) The data repre­sent digi­ti­zed user actions and pro­ce­s­ses and should the­r­e­fo­re be acce­s­si­ble to the user. The rules on access to and use of data from con­nec­ted pro­ducts and con­nec­ted ser­vices under this Regu­la­ti­on cover both pro­duct data and con­nec­ted ser­vice data. Pro­duct data means data gene­ra­ted by the use of a con­nec­ted pro­duct and desi­gned by the manu­fac­tu­rer to be retrie­va­ble from the con­nec­ted pro­duct by a user, data owner or third par­ty, inclu­ding, whe­re appli­ca­ble, the manu­fac­tu­rer. Con­nec­ted ser­vice data means data that also repres­ents the digi­tizati­on of user actions or ope­ra­ti­ons in con­nec­tion with the con­nec­ted pro­duct and is gene­ra­ted during the pro­vi­si­on of a con­nec­ted ser­vice by the pro­vi­der. Data gene­ra­ted during the use of a con­nec­ted pro­duct or con­nec­ted ser­vice should be under­s­tood as inten­tio­nal­ly recor­ded data or data gene­ra­ted indi­rect­ly through user actions, such as data about the envi­ron­ment or inter­ac­tions of the con­nec­ted pro­duct. Such data should include data on the use of a con­nec­ted pro­duct gene­ra­ted by a user inter­face or through a con­nec­ted ser­vice and should not be limi­t­ed to infor­ma­ti­on that a pro­duct or ser­vice has been used, but should include all data gene­ra­ted by the con­nec­ted pro­duct as a result of such use, such as data auto­ma­ti­cal­ly gene­ra­ted by sen­sors and data recor­ded by embedded appli­ca­ti­ons, inclu­ding appli­ca­ti­ons indi­ca­ting hard­ware sta­tus and mal­func­tions. Such data should also include data gene­ra­ted by the con­nec­ted pro­duct or con­nec­ted ser­vice while the user is inac­ti­ve, such as when the user deci­des not to use a con­nec­ted pro­duct for a cer­tain peri­od of time but to lea­ve it in stand­by mode or even switch it off, as the sta­tus of a con­nec­ted pro­duct or its com­pon­ents, such as its bat­te­ries, may chan­ge when the con­nec­ted pro­duct is in stand­by mode or swit­ched off. Data that is not sub­stan­ti­al­ly alte­red, i.e. data in raw form, also refer­red to as source or pri­ma­ry data, which refers to data points that are auto­ma­ti­cal­ly gene­ra­ted wit­hout any fur­ther form of pro­ce­s­sing, as well as data that has been pre­pared pri­or to fur­ther pro­ce­s­sing and ana­ly­sis to make it under­stan­da­ble and usable, falls within the scope of this Regu­la­ti­on. This inclu­des data coll­ec­ted by a sin­gle sen­sor or a group of inter­con­nec­ted sen­sors in order to make the coll­ec­ted data under­stan­da­ble for more diver­se use cases by deter­mi­ning a phy­si­cal quan­ti­ty or pro­per­ty or the chan­ge of a phy­si­cal quan­ti­ty, such as tem­pe­ra­tu­re, pres­su­re, flow rate, sound, pH, liquid level, posi­ti­on, acce­le­ra­ti­on or velo­ci­ty. The term „pre­pared data“ should not be inter­pre­ted as requi­ring the data owner to make a signi­fi­cant invest­ment in clea­ning and trans­forming the data. The data to be pro­vi­ded should include the rele­vant meta­da­ta, inclu­ding its basic con­text and timestamp, to make the data usable in com­bi­na­ti­on with other data, e.g. data that has been sor­ted and clas­si­fi­ed with other data points asso­cia­ted with it or refor­mat­ted into a com­mon for­mat. Such data is poten­ti­al­ly valuable to the user and sup­ports inno­va­ti­on and the deve­lo­p­ment of digi­tal and other ser­vices to pro­tect the envi­ron­ment, health and the cir­cular eco­no­my, inclu­ding by faci­li­ta­ting the main­ten­an­ce and repair of the con­nec­ted pro­ducts con­cer­ned. By con­trast, infor­ma­ti­on infer­red or deri­ved from such data that is the result of addi­tio­nal invest­ment in attri­bu­ting value or insights from the data (in par­ti­cu­lar by means of com­plex pro­prie­ta­ry algo­rith­ms, inclu­ding tho­se that are part of pro­prie­ta­ry soft­ware) should not fall within the scope of this Regu­la­ti­on, and the­r­e­fo­re data hol­ders should not be obli­ged to pro­vi­de such data to a user or data reci­pi­ent, unless other­wi­se agreed bet­ween the user and the data hol­der. Such data could include, in par­ti­cu­lar, infor­ma­ti­on obtai­ned through sen­sor fusi­on, whe­re data is deri­ved or infer­red from mul­ti­ple sen­sors coll­ec­ted in the con­nec­ted pro­duct using com­plex pro­prie­ta­ry algo­rith­ms and may be sub­ject to intellec­tu­al pro­per­ty rights.
17. „rea­di­ly available data“ Pro­duct data and con­nec­ted ser­vice data that a data con­trol­ler lawful­ly obta­ins or can obtain from the con­nec­ted pro­duct or con­nec­ted ser­vice wit­hout dis­pro­por­tio­na­te effort, going bey­ond simp­le processing;
(20) In prac­ti­ce, not all data gene­ra­ted by con­nec­ted pro­ducts or con­nec­ted ser­vices are easi­ly acce­s­si­ble to their users, and the­re are often limi­t­ed pos­si­bi­li­ties in terms of por­ta­bi­li­ty of data gene­ra­ted by inter­net-con­nec­ted pro­ducts. Users are the­r­e­fo­re unable to obtain the data requi­red to access repair and other ser­vices, and com­pa­nies are unable to offer inno­va­ti­ve, con­ve­ni­ent and more effi­ci­ent ser­vices. In many sec­tors, becau­se manu­fac­tu­r­ers have con­trol over the tech­ni­cal design of con­nec­ted pro­ducts or con­nec­ted ser­vices, they can deter­mi­ne what data is gene­ra­ted and how it can be acce­s­sed, even though they have no legal right to this data. It is the­r­e­fo­re neces­sa­ry to ensu­re that con­nec­ted pro­ducts are desi­gned and manu­fac­tu­red and con­nec­ted ser­vices are desi­gned and pro­vi­ded in such a way that the pro­duct data and con­nec­ted ser­vice data, inclu­ding the cor­re­spon­ding meta­da­ta neces­sa­ry to inter­pret and use that data, inclu­ding to retrie­ve, use or share the data, are always easi­ly and secu­re­ly acce­s­si­ble to a user, free of char­ge, in a com­pre­hen­si­ve, struc­tu­red, com­mon­ly used and machi­ne-rea­da­ble for­mat. Pro­duct data and con­nec­ted ser­vice data that a data con­trol­ler lawful­ly obta­ins or can obtain from the con­nec­ted pro­duct or con­nec­ted ser­vice, for exam­p­le due to the design of the con­nec­ted pro­duct, the data controller’s con­tract with the user for the pro­vi­si­on of con­nec­ted ser­vices and its tech­ni­cal means for acce­s­sing the data wit­hout dis­pro­por­tio­na­te effort, are refer­red to as „rea­di­ly available data“. Rea­di­ly available data exclu­des data gene­ra­ted during pro­duct use, unless the con­nec­ted pro­duct is desi­gned to store or trans­mit such data out­side the com­po­nent in which it is gene­ra­ted or the con­nec­ted pro­duct as a who­le. This Regu­la­ti­on should the­r­e­fo­re not be inter­pre­ted as impo­sing an obli­ga­ti­on to store data on the cen­tral pro­ce­s­sing unit of a con­nec­ted pro­duct. The absence of such an obli­ga­ti­on should not pre­vent the manu­fac­tu­rer or data con­trol­ler from agre­e­ing such adap­t­ati­ons with the user on a vol­un­t­a­ry basis. The design obli­ga­ti­ons under this Regu­la­ti­on are also wit­hout pre­ju­di­ce to the prin­ci­ple of data mini­mizati­on under Artic­le 5(1)(c) of Regu­la­ti­on (EU) 2016/679 and should not be under­s­tood as requi­ring con­nec­ted pro­ducts and con­nec­ted ser­vices to be desi­gned in such a way as to store or other­wi­se pro­cess per­so­nal data other than tho­se neces­sa­ry for the pur­po­ses of their pro­ce­s­sing. Uni­on or natio­nal law could be intro­du­ced to lay down fur­ther spe­ci­fi­ci­ties, such as the pro­duct data that should be acce­s­si­ble through con­nec­ted pro­ducts or con­nec­ted ser­vices, as such data may be essen­ti­al for the effi­ci­ent ope­ra­ti­on, repair or main­ten­an­ce of tho­se con­nec­ted pro­ducts or con­nec­ted ser­vices. Whe­re sub­se­quent updates or chan­ges to a con­nec­ted pro­duct or con­nec­ted ser­vice by the manu­fac­tu­rer or ano­ther par­ty result in addi­tio­nal acce­s­si­ble data or a rest­ric­tion of initi­al­ly acce­s­si­ble data, tho­se chan­ges should be com­mu­ni­ca­ted to the user as part of the update or change.
18. „Trade secret“ a trade secret within the mea­ning of Artic­le 2(1) of Direc­ti­ve (EU) 2016/943;
19. „Owner of a trade secret“ the hol­der of a trade secret within the mea­ning of Artic­le 2(2) of Direc­ti­ve (EU) 2016/943;
20. „Pro­fil­ing“ Pro­fil­ing within the mea­ning of Artic­le 4(4) of Regu­la­ti­on (EU) 2016/679;
21. „Pro­vi­si­on on the mar­ket“ any sup­p­ly of a con­nec­ted pro­duct for dis­tri­bu­ti­on, con­sump­ti­on or use on the Uni­on mar­ket in the cour­se of a com­mer­cial acti­vi­ty, whe­ther in return for payment or free of charge;
22. „Pla­cing on the mar­ket“ making a con­nec­ted pro­duct available on the Uni­on mar­ket for the first time;
23. „Con­su­mers“ any natu­ral per­son acting for pur­po­ses which are out­side their trade, busi­ness, craft or profession;
24. „Com­pa­ny“ a natu­ral or legal per­son who, in rela­ti­on to con­tracts and prac­ti­ces cover­ed by this Regu­la­ti­on, is acting for pur­po­ses rela­ting to his trade, busi­ness, craft or profession;
25. „Small busi­ness“ a small enter­pri­se within the mea­ning of Artic­le 2(2) of the Annex to Recom­men­da­ti­on 2003/361/;
26. „Microen­ter­pri­ses“ a microen­ter­pri­se within the mea­ning of Artic­le 2(3) of the Annex to Recom­men­da­ti­on 2003/361/;
27. „Faci­li­ties of the Uni­on“ the bodies, offices and agen­ci­es of the Uni­on estab­lished pur­su­ant to acts adopted on the basis of the Trea­ty on Euro­pean Uni­on, the TFEU or the Trea­ty estab­li­shing the Euro­pean Ato­mic Ener­gy Community;
28. „public body“ the natio­nal, regio­nal and local aut­ho­ri­ties, bodies and insti­tu­ti­ons gover­ned by public law of the Mem­ber Sta­tes or asso­cia­ti­ons con­si­sting of one or more of tho­se aut­ho­ri­ties, bodies or institutions;
29. „public emer­gen­cy“ an excep­tio­nal and tem­po­ra­ry situa­ti­on, such as public health emer­gen­ci­es, emer­gen­ci­es cau­sed by natu­ral dis­asters and major man-made dis­asters, inclu­ding major cyber­se­cu­ri­ty inci­dents, which has a nega­ti­ve impact on the popu­la­ti­on of the Uni­on or of a Mem­ber Sta­te or part the­reof or part the­reof, which poses a risk of serious and lasting con­se­quen­ces for living con­di­ti­ons, eco­no­mic sta­bi­li­ty or finan­cial sta­bi­li­ty or a risk of signi­fi­cant and imme­dia­te dama­ge to eco­no­mic assets in the Uni­on or in the Mem­ber Sta­te con­cer­ned, and which has been declared and offi­ci­al­ly declared in accordance with the rele­vant pro­ce­du­res under Uni­on or natio­nal law;
30. „Cus­to­mer“ a natu­ral or legal per­son who has ente­red into a con­trac­tu­al rela­ti­on­ship with a pro­vi­der of data pro­ce­s­sing ser­vices in order to make use of one or more data pro­ce­s­sing services;
31. „vir­tu­al assi­stants“ Soft­ware that can pro­cess orders, tasks or que­sti­ons, inclu­ding on the basis of input in audio and writ­ten form, with ges­tu­res or move­ments, and that grants access to other ser­vices or con­trols the func­tions of net­work­ed pro­ducts on the basis of the­se orders, tasks or questions;
32. „digi­tal assets“ Ele­ments in digi­tal form – inclu­ding appli­ca­ti­ons – for which the cus­to­mer has a right of use, irre­spec­ti­ve of the con­trac­tu­al rela­ti­on­ship with the data pro­ce­s­sing ser­vice he wis­hes to change;
(83) Digi­tal assets refer to ele­ments in digi­tal form for which the cus­to­mer has the right of use, inclu­ding appli­ca­ti­ons and meta­da­ta rela­ted to the con­fi­gu­ra­ti­on of set­tings, secu­ri­ty and the manage­ment of access and con­trol rights, as well as other ele­ments such as repre­sen­ta­ti­ons of vir­tua­lizati­on tech­no­lo­gies, inclu­ding vir­tu­al machi­nes and con­tai­ners. Digi­tal assets may be trans­fer­red pro­vi­ded the cus­to­mer has a right of use that is inde­pen­dent of the con­trac­tu­al rela­ti­on­ship with the data pro­ce­s­sing ser­vice they wish to chan­ge. The other ele­ments men­tio­ned abo­ve are the pre­re­qui­si­te for the cus­to­mer to be able to effec­tively use its data and appli­ca­ti­ons in the envi­ron­ment of the acqui­ring pro­vi­der of data pro­ce­s­sing services.
33. „ICT infras­truc­tu­re on our own pre­mi­ses“ ICT infras­truc­tu­re and com­pu­ting resour­ces that are owned by the cus­to­mer or ren­ted or lea­sed by the cus­to­mer and that are loca­ted in the customer’s data cen­ter and are ope­ra­ted by the cus­to­mer or a third party;
34. „Chan­ge“ the pro­cess invol­ving a source pro­vi­der of data pro­ce­s­sing ser­vices, a cus­to­mer of a data pro­ce­s­sing ser­vice and, whe­re appli­ca­ble, an acqui­ring pro­vi­der of data pro­ce­s­sing ser­vices, in which the cus­to­mer of a data pro­ce­s­sing ser­vice swit­ches from using a data pro­ce­s­sing ser­vice to using ano­ther data pro­ce­s­sing ser­vice of the same ser­vice type or ano­ther ser­vice offe­red by ano­ther pro­vi­der of data pro­ce­s­sing ser­vices or offe­red to an ICT infras­truc­tu­re on its own pre­mi­ses, inclu­ding by extra­c­ting, trans­forming and uploa­ding the data;
(85) Swit­ching is a pro­cess that ori­gi­na­tes from the cus­to­mer and con­sists of seve­ral steps – inclu­ding data extra­c­tion – which means down­loa­ding the data from the eco­sy­stem of the ori­gi­nal pro­vi­der of data pro­ce­s­sing ser­vices, trans­forming the data if it is struc­tu­red in such a way that it does not fit into the sche­ma of the tar­get loca­ti­on, and uploa­ding the data to a new tar­get loca­ti­on. In cer­tain situa­tions descri­bed in this Regu­la­ti­on, it should also be con­side­red as swit­ching when a par­ti­cu­lar ser­vice is remo­ved from the con­tract and moved to ano­ther pro­vi­der. The switch is some­ti­mes car­ri­ed out by a third par­ty on behalf of the cus­to­mer. Accor­din­gly, all the rights and obli­ga­ti­ons of the cus­to­mer set out in this Regu­la­ti­on, inclu­ding the obli­ga­ti­on to coope­ra­te in good faith, should be under­s­tood to app­ly to the third par­ty con­cer­ned in tho­se cir­cum­stances. Data pro­ce­s­sing ser­vice pro­vi­ders and cus­to­mers bear dif­fe­rent degrees of respon­si­bi­li­ty depen­ding on the step in the pro­cess. For exam­p­le, the ori­gi­nal data pro­ce­s­sing ser­vice pro­vi­der is respon­si­ble for extra­c­ting the data into a machi­ne-rea­da­ble for­mat, while the cus­to­mer and the acqui­ring data pro­ce­s­sing ser­vice pro­vi­der must upload the data to the new envi­ron­ment, unless a spe­cial pro­fes­sio­nal tran­si­ti­on ser­vice is used. A cus­to­mer who intends to exer­cise the rights pro­vi­ded for in this Regu­la­ti­on in con­nec­tion with the switch should inform the ori­gi­nal data pro­ce­s­sing ser­vices pro­vi­der of the decis­i­on to eit­her switch to ano­ther data pro­ce­s­sing ser­vices pro­vi­der or to an ICT infras­truc­tu­re on its own pre­mi­ses or to dele­te the customer’s assets and exporta­ble data.
35. „Data extra­c­tion fees“ Data trans­mis­si­on fees char­ged to cus­to­mers for extra­c­ting their data via the net­work from the ICT infras­truc­tu­re of a pro­vi­der of data pro­ce­s­sing ser­vices to the systems of other pro­vi­ders or to ICT infras­truc­tu­re on their own premises;
36. „Exch­an­ge fees“ char­ges, other than stan­dard ser­vice char­ges or ear­ly ter­mi­na­ti­on pen­al­ties, levied by a pro­vi­der of data pro­ce­s­sing ser­vices on a cus­to­mer for the actions requi­red by this Regu­la­ti­on for swit­ching to ano­ther provider’s systems or ICT infras­truc­tu­re at its own pre­mi­ses, inclu­ding data extra­c­tion charges;
(88) Swit­ching fees are fees that pro­vi­ders of data pro­ce­s­sing ser­vices char­ge their cus­to­mers for com­ple­ting the switch. The­se fees are usual­ly inten­ded to pass on the costs that the ori­gi­nal pro­vi­der of data pro­ce­s­sing ser­vices may incur as a result of the switch to the cus­to­mer reque­st­ing the switch. Com­mon examp­les of swit­ching fees are costs asso­cia­ted with the trans­fer of data from one pro­vi­der of data pro­ce­s­sing ser­vices to ano­ther or from one pro­vi­der to an ICT infras­truc­tu­re on its own pre­mi­ses („data extra­c­tion fees“) or costs incur­red through spe­ci­fic sup­port acti­vi­ties during the exe­cu­ti­on of the switch. Unre­a­son­ab­ly high data extra­c­tion char­ges and other unju­sti­fi­ed char­ges that are unre­la­ted to the actu­al costs of swit­ching hin­der swit­ching by the cus­to­mer, rest­rict the free flow of data, may rest­rict com­pe­ti­ti­on and lead to depen­den­cy of the cus­to­mer on a par­ti­cu­lar ser­vice by redu­cing incen­ti­ves to choo­se ano­ther or fur­ther ser­vice pro­vi­ders. The­r­e­fo­re, swit­ching fees should be abo­lished after three years from the date of ent­ry into force of this Regu­la­ti­on. Pro­vi­ders of data pro­ce­s­sing ser­vices should be able to char­ge redu­ced swit­ching fees until that date.
37. „Func­tion­al equi­va­lence“ the resto­ra­ti­on – on the basis of the Customer’s exporta­ble data and digi­tal assets – of a mini­mum level of func­tion­a­li­ty in the envi­ron­ment of a new data pro­ce­s­sing ser­vice of the same ser­vice type after the switch, if the acqui­ring data pro­ce­s­sing ser­vice pro­vi­des a mate­ri­al­ly com­pa­ra­ble result in respon­se to the same input for com­mon func­tions pro­vi­ded to the Cus­to­mer under the Contract;
(86) Func­tion­al equi­va­lence means that after a switch, a mini­mum func­tion­al scope based on the customer’s exporta­ble data and digi­tal assets is re-estab­lished in the envi­ron­ment of the new data pro­ce­s­sing ser­vice of the same ser­vice type, with the acqui­ring data pro­ce­s­sing ser­vice pro­vi­ding a sub­stan­ti­al­ly com­pa­ra­ble result for shared func­tions pro­vi­ded to the cus­to­mer under the con­tract. Pro­vi­ders of data pro­ce­s­sing ser­vices can only be expec­ted to enable func­tion­al equi­va­lence in rela­ti­on to the func­tions offe­red inde­pendent­ly by both the ori­gi­nal and the acqui­ring data pro­ce­s­sing ser­vice. Pro­vi­ders of data pro­ce­s­sing ser­vices are only requi­red to faci­li­ta­te func­tion­al equi­va­lence under this Regu­la­ti­on if they offer ser­vices under the IaaS deli­very model.
38. „Exporta­ble data“ for the pur­po­ses of Artic­les 23 to 31 and Artic­le 35, input and out­put data, inclu­ding meta­da­ta, gene­ra­ted direct­ly or indi­rect­ly through the use of the data pro­ce­s­sing ser­vice by the cus­to­mer or joint­ly, with the excep­ti­on of assets or data of a data pro­ce­s­sing ser­vice pro­vi­der or third par­ties that are pro­tec­ted by intellec­tu­al pro­per­ty rights or con­sti­tu­te a trade secret;
39. „smart con­tract“ a com­pu­ter pro­gram used for the auto­ma­ted exe­cu­ti­on of an agree­ment or part the­reof, using a sequence of elec­tro­nic records and ensu­ring the inte­gri­ty of the­se records and the cor­rect­ness of their chro­no­lo­gi­cal order;
40. „Inter­ope­ra­bi­li­ty“ the abili­ty of two or more data spaces or com­mu­ni­ca­ti­on net­works, systems, net­work­ed pro­ducts, appli­ca­ti­ons, data pro­ce­s­sing ser­vices or com­pon­ents to exch­an­ge and use data to per­form their functions;
41. „open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons“ a tech­ni­cal spe­ci­fi­ca­ti­on in the field of infor­ma­ti­on and com­mu­ni­ca­ti­on tech­no­lo­gy that is desi­gned to achie­ve inter­ope­ra­bi­li­ty bet­ween data pro­ce­s­sing services;
42. „Com­mon spe­ci­fi­ca­ti­ons“ a docu­ment which is not a stan­dard and which con­ta­ins tech­ni­cal solu­ti­ons enab­ling cer­tain requi­re­ments and obli­ga­ti­ons laid down in this Regu­la­ti­on to be met;
43. „har­mo­ni­zed stan­dard“ a har­mo­ni­zed stan­dard within the mea­ning of Artic­le 2(1)(c) of Regu­la­ti­on (EU) No 1025/2012.

Chap­ter II Data trans­fer from busi­nesses to con­su­mers and bet­ween businesses

Artic­le 3 Obli­ga­ti­on to make pro­duct data and rela­ted ser­vice data available to the user
(1) Con­nec­ted pro­ducts shall be desi­gned and manu­fac­tu­red and con­nec­ted ser­vices shall be desi­gned and pro­vi­ded in such a way that the pro­duct data and con­nec­ted ser­vice data – inclu­ding the rele­vant meta­da­ta neces­sa­ry for the inter­pre­ta­ti­on and use of that data – are easi­ly, secu­re­ly, free­ly acce­s­si­ble to the user by default in a com­pre­hen­si­ve, struc­tu­red, com­mon­ly used and machi­ne-rea­da­ble for­mat and, whe­re rele­vant and tech­ni­cal­ly fea­si­ble, direct­ly accessible.
(2) Befo­re con­clu­ding a purcha­se, ren­tal or lea­sing con­tract for a con­nec­ted pro­duct, the sel­ler, land­lord or les­sor – which may also be the manu­fac­tu­rer – shall pro­vi­de the user with at least the fol­lo­wing infor­ma­ti­on in a clear and com­pre­hen­si­ble man­ner:
a) the type, for­mat and esti­ma­ted volu­me of pro­duct data that the net­work­ed pro­duct can generate;
b) infor­ma­ti­on on whe­ther the net­work­ed pro­duct is able to gene­ra­te data con­ti­nuous­ly and in real time;
c) whe­ther the con­nec­ted pro­duct is capa­ble of sto­ring data on a device or a remo­te ser­ver, inclu­ding the inten­ded reten­ti­on peri­od, if applicable;
d) infor­ma­ti­on on how the user can access, retrie­ve or, if neces­sa­ry, dele­te the data, inclu­ding the tech­ni­cal means to do so, as well as the rele­vant terms of use and qua­li­ty of service.
(24) Befo­re ente­ring into a purcha­se, ren­tal or lea­sing con­tract for a con­nec­ted pro­duct, the sel­ler, les­sor or len­der – which may also be the manu­fac­tu­rer – should pro­vi­de the user with infor­ma­ti­on on the pro­duct data that the con­nec­ted pro­duct may gene­ra­te, inclu­ding the type, for­mat and esti­ma­ted amount of data, in a clear and com­pre­hen­si­ble man­ner. This could include, whe­re available, infor­ma­ti­on on data struc­tures, data for­mats, voca­bu­la­ries, clas­si­fi­ca­ti­on systems, taxo­no­mies and code lists, as well as clear and suf­fi­ci­ent infor­ma­ti­on rele­vant to the exer­cise of user rights and how the data can be stored, retrie­ved or acce­s­sed, inclu­ding the terms of use and qua­li­ty of ser­vice of appli­ca­ti­on pro­gramming inter­faces or the pro­vi­si­on of soft­ware deve­lo­p­ment kits, whe­re appli­ca­ble. This obli­ga­ti­on ensu­res trans­pa­ren­cy with regard to the gene­ra­ted pro­duct data and sim­pli­fi­es access for the user. The infor­ma­ti­on obli­ga­ti­on could be met, for exam­p­le, by main­tai­ning a sta­ble URL address on the Inter­net that can be dis­tri­bu­ted as a web link or QR code and leads to the rele­vant infor­ma­ti­on that the sel­ler, les­sor or les­sor – which may also be the manu­fac­tu­rer – could pro­vi­de to the user befo­re con­clu­ding a purcha­se, ren­tal or lea­sing con­tract for a con­nec­ted pro­duct. In any case, the user must be able to store the infor­ma­ti­on in such a way that it can sub­se­quent­ly be view­ed and the unal­te­red repro­duc­tion of the stored infor­ma­ti­on is pos­si­ble. While the data con­trol­ler can­not be expec­ted to store the data inde­fi­ni­te­ly in view of the needs of the user of the con­nec­ted pro­duct, it should app­ly an appro­pria­te regime in rela­ti­on to the dura­ti­on of data sto­rage, whe­re appro­pria­te in accordance with the prin­ci­ple of sto­rage limi­ta­ti­on under Artic­le 5(1)(e) of Regu­la­ti­on (EU) 2016/679, which allo­ws for the effec­ti­ve appli­ca­ti­on of data access rights under that Regu­la­ti­on. The obli­ga­ti­on to pro­vi­de infor­ma­ti­on does not affect the obli­ga­ti­on of the con­trol­ler to pro­vi­de infor­ma­ti­on to the data sub­ject in accordance with Artic­les 12, 13 and 14 of Regu­la­ti­on (EU) 2016/679. The obli­ga­ti­on to pro­vi­de the rele­vant infor­ma­ti­on pri­or to the con­clu­si­on of a con­tract for the pro­vi­si­on of a con­nec­ted ser­vice should lie with the poten­ti­al data con­trol­ler, regard­less of whe­ther the data con­trol­ler con­clu­des a purcha­se, ren­tal or lea­sing con­tract for a con­nec­ted pro­duct. If the infor­ma­ti­on chan­ges during the life­time of the con­nec­ted pro­duct or the dura­ti­on of the con­tract for the con­nec­ted ser­vice, inclu­ding if the pur­po­se for which this data is to be used chan­ges from that ori­gi­nal­ly inten­ded, infor­ma­ti­on on this should also be pro­vi­ded to the user.
(3) Befo­re con­clu­ding a con­tract for the pro­vi­si­on of a con­nec­ted ser­vice, the pro­vi­der of such a con­nec­ted ser­vice shall pro­vi­de the user with at least the fol­lo­wing infor­ma­ti­on in a clear and com­pre­hen­si­ble man­ner:
a) the natu­re, esti­ma­ted scope and fre­quen­cy of coll­ec­tion of the pro­duct data that the pro­s­pec­ti­ve data con­trol­ler is likely to recei­ve and, whe­re appli­ca­ble, the means by which the user will be able to access or retrie­ve such data, inclu­ding the pro­s­pec­ti­ve data controller’s arran­ge­ments for the sto­rage and reten­ti­on of data;
b) the natu­re and esti­ma­ted scope of the con­nec­ted ser­vice data to be gene­ra­ted and the moda­li­ties by which the user can access or retrie­ve this data, inclu­ding the moda­li­ties of the future data con­trol­ler in rela­ti­on to the sto­rage and the dura­ti­on of the reten­ti­on of data;
c) whe­ther the pro­s­pec­ti­ve data con­trol­ler expects to use rea­di­ly available data its­elf and the pur­po­ses for which the data will be used, and whe­ther it intends to allow one or more third par­ties to use the data for pur­po­ses agreed with the user;
d) the iden­ti­ty of the poten­ti­al data con­trol­ler, e.g. its trade name and the address of the place whe­re it is estab­lished and, whe­re appli­ca­ble, other data pro­ce­s­sing parties;
e) the means of com­mu­ni­ca­ti­on through which the poten­ti­al data owner can be cont­ac­ted quick­ly and com­mu­ni­ca­ted with efficiently;
f) infor­ma­ti­on on how the user can request that the data be pas­sed on to a third par­ty and how he can stop the data trans­fer if necessary;
g) the right of the user to lodge a com­plaint with the com­pe­tent aut­ho­ri­ty refer­red to in Artic­le 37 con­cer­ning a breach of any of the pro­vi­si­ons of this Chapter;
h) whe­ther a pro­s­pec­ti­ve data owner is the owner of trade secrets con­tai­ned in the data acce­s­si­ble through the con­nec­ted pro­duct or gene­ra­ted in the pro­vi­si­on of a con­nec­ted ser­vice and, if the pro­s­pec­ti­ve data owner is not the owner of trade secrets, the iden­ti­ty of the trade secret owner;
i) the dura­ti­on of the con­tract bet­ween the user and the poten­ti­al data con­trol­ler and the arran­ge­ments for the pre­ma­tu­re ter­mi­na­ti­on of such a contract.
Artic­le 4 Rights and obli­ga­ti­ons of users and data hol­ders in rela­ti­on to access to, use and pro­vi­si­on of pro­duct data and rela­ted ser­vice data
(27) In con­cen­tra­ted sec­tors whe­re end-users are sup­plied with con­nec­ted pro­ducts by a small num­ber of manu­fac­tu­r­ers, users may have limi­t­ed opti­ons for data access, use and sha­ring. In the­se cir­cum­stances, con­trac­tu­al agree­ments may not be suf­fi­ci­ent to achie­ve the goal of user empower­ment, making it dif­fi­cult for users to deri­ve value from the data gene­ra­ted by the con­nec­ted pro­ducts they purcha­se, rent or lea­se. As a result, the poten­ti­al for inno­va­ti­ve smal­ler com­pa­nies to offer data-dri­ven solu­ti­ons in a com­pe­ti­ti­ve man­ner and for a diver­se data eco­no­my in the Uni­on is limi­t­ed. This Regu­la­ti­on should the­r­e­fo­re build on recent deve­lo­p­ments in cer­tain sec­tors, such as the code of con­duct for the sha­ring of agri­cul­tu­ral data by means of a con­tract. Uni­on or natio­nal law may be adopted to address sec­tor-spe­ci­fic needs and objec­ti­ves. In addi­ti­on, data hol­ders should not use rea­di­ly available data that is non-per­so­nal data to gain insights into the eco­no­mic situa­ti­on, assets or pro­duc­tion methods of the user or into the use by the user in any other way that could under­mi­ne the com­mer­cial posi­ti­on of that user in the mar­kets in which it ope­ra­tes. This could include using know­ledge of the over­all per­for­mance of a com­pa­ny or farm to its detri­ment in con­trac­tu­al nego­tia­ti­ons with the user for the poten­ti­al purcha­se of the user’s pro­duct or farm pro­du­ce, or ente­ring such infor­ma­ti­on into lar­ger aggre­ga­ted data­ba­ses on spe­ci­fic mar­kets, such as data­ba­ses on crop yields for the coming har­vest sea­son, as such use could have an indi­rect nega­ti­ve impact on the user. The user should be pro­vi­ded with the tech­ni­cal inter­face neces­sa­ry to mana­ge the per­mis­si­ons, pre­fer­a­b­ly with fine-grai­ned per­mis­si­on opti­ons (e.g. „allow access once“ or „allow access only while using the app or ser­vice“), inclu­ding the pos­si­bi­li­ty to revo­ke such permissions.
(1) Inso­far as the user can­not access the data direct­ly from the net­work­ed pro­duct or con­nec­ted ser­vice, the data owners shall pro­vi­de the user with rea­di­ly available data, inclu­ding the meta­da­ta requi­red to inter­pret and use the data, wit­hout undue delay, sim­ply, secu­re­ly, free of char­ge, in a com­pre­hen­si­ve, com­mon­ly used and machi­ne-rea­da­ble for­mat and – if rele­vant and tech­ni­cal­ly fea­si­ble – in the same qua­li­ty as for the data owner, con­ti­nuous­ly and in real time. This shall be done elec­tro­ni­cal­ly upon simp­le request, inso­far as this is tech­ni­cal­ly feasible. 
(2) Users and data hol­ders may con­trac­tual­ly rest­rict access to, use or re-dis­clo­sure of data whe­re such pro­ce­s­sing could com­pro­mi­se the safe­ty requi­re­ments of the con­nec­ted pro­duct as laid down in Uni­on or natio­nal law and thus lead to serious adver­se effects on the health or safe­ty of natu­ral per­sons. The com­pe­tent aut­ho­ri­ties for the sec­tors con­cer­ned may pro­vi­de tech­ni­cal exper­ti­se to users and data hol­ders in this con­text. Whe­re the data hol­der refu­ses to share data in accordance with this Artic­le, it shall noti­fy the com­pe­tent aut­ho­ri­ty desi­gna­ted in accordance with Artic­le 37. 
(3) Wit­hout pre­ju­di­ce to the user’s right to seek a judi­cial reme­dy befo­re a court of a Mem­ber Sta­te at any time, the user may, in the con­text of a dis­pu­te with the data con­trol­ler con­cer­ning the con­trac­tu­al rest­ric­tions or pro­hi­bi­ti­ons refer­red to in para­graph 2 
a) lodge a com­plaint with the com­pe­tent aut­ho­ri­ty in accordance with Artic­le 37(5)(b); or
b) agree with the data con­trol­ler to refer the mat­ter to a dis­pu­te reso­lu­ti­on body in accordance with Artic­le 10(1).
(4) Data con­trol­lers shall not unre­a­son­ab­ly impe­de the exer­cise of choices or rights by the user under this Artic­le, inclu­ding by offe­ring choices to the user in a non-neu­tral way or by under­mi­ning or impai­ring the user’s auto­no­my, free­dom of choice or free­dom of decis­i­on through the struc­tu­re, design, func­tion or ope­ra­ti­on of a digi­tal user inter­face or part thereof. 
(5) In order to veri­fy whe­ther a natu­ral or legal per­son qua­li­fi­es as a user for the pur­po­ses of para­graph 1, the data con­trol­ler shall not request infor­ma­ti­on from that per­son that goes bey­ond what is neces­sa­ry. Data con­trol­lers shall not retain infor­ma­ti­on about the user’s access to the reque­sted data, in par­ti­cu­lar log data, bey­ond what is neces­sa­ry for the pro­per exe­cu­ti­on of the user’s access request and for the secu­ri­ty and main­ten­an­ce of the data infrastructure.
(29) Data con­trol­lers may request appro­pria­te user iden­ti­fi­ca­ti­on in order to veri­fy a user’s aut­ho­rizati­on to access the data. In the case of per­so­nal data pro­ce­s­sed by a pro­ces­sor on behalf of the con­trol­ler, data con­trol­lers should ensu­re that the request for access is recei­ved and pro­ce­s­sed by the processor.
(6) Trade secrets shall be pro­tec­ted and only dis­c­lo­sed if the data con­trol­ler and the user have taken all mea­su­res neces­sa­ry to pro­tect the con­fi­den­tia­li­ty of the trade secrets, in par­ti­cu­lar vis-à-vis third par­ties, pri­or to dis­clo­sure. The data con­trol­ler or, if they are not the same per­son, the trade secret hol­der shall iden­ti­fy the data pro­tec­ted as trade secrets, inclu­ding in the rele­vant meta­da­ta, and agree with the user on appro­pria­te tech­ni­cal and orga­nizatio­nal mea­su­res neces­sa­ry to main­tain the con­fi­den­tia­li­ty of the dis­c­lo­sed data, in par­ti­cu­lar vis-à-vis third par­ties; this applies, for exam­p­le, to model con­tract clau­ses, con­fi­den­tia­li­ty agree­ments, strict access pro­to­cols, tech­ni­cal stan­dards and the appli­ca­ti­on of codes of conduct.
(31) Direc­ti­ve (EU) 2016/943 of the Euro­pean Par­lia­ment and of the Coun­cil (23) pro­vi­des that the acqui­si­ti­on, use or dis­clo­sure of a trade secret is to be con­side­red lawful, inter alia, whe­re such acqui­si­ti­on, use or dis­clo­sure is requi­red or per­mit­ted by Uni­on or natio­nal law. While this Regu­la­ti­on requi­res data hol­ders to dis­c­lo­se cer­tain data to users or third par­ties sel­ec­ted by the user, even if such data is cover­ed by trade secret pro­tec­tion, this should be inter­pre­ted in a way that respects the pro­tec­tion of trade secrets in accordance with Direc­ti­ve (EU) 2016/943. In this con­text, data con­trol­lers should be able to requi­re the user or third par­ties sel­ec­ted by the user to respect the con­fi­den­tia­li­ty of data that are con­side­red trade secrets. The­r­e­fo­re, data hol­ders should iden­ti­fy the trade secrets pri­or to their dis­clo­sure and have the pos­si­bi­li­ty to agree with users or user-sel­ec­ted third par­ties on neces­sa­ry mea­su­res to pre­ser­ve their con­fi­den­tia­li­ty, inclu­ding through the use of model con­trac­tu­al clau­ses, con­fi­den­tia­li­ty agree­ments, strict access pro­to­cols, tech­ni­cal stan­dards and the appli­ca­ti­on of codes of con­duct. In addi­ti­on to the use of model con­trac­tu­al clau­ses to be deve­lo­ped and recom­men­ded by the Com­mis­si­on, the estab­lish­ment of codes of con­duct and tech­ni­cal stan­dards rela­ting to the pro­tec­tion of trade secrets in the pro­ce­s­sing of data could also con­tri­bu­te to achie­ving the objec­ti­ve of this Regu­la­ti­on and should the­r­e­fo­re be pro­mo­ted. Whe­re the­re is no agree­ment on the neces­sa­ry mea­su­res or whe­re a user or a third par­ty sel­ec­ted by the user does not imple­ment tho­se agreed mea­su­res or brea­ches the con­fi­den­tia­li­ty of trade secrets, it should be pos­si­ble for the data con­trol­ler to refu­se or sus­pend the dis­clo­sure of the data clas­si­fi­ed as trade secrets. In such cases, the data hol­der should imme­dia­te­ly noti­fy the user or the third par­ty in wri­ting of its decis­i­on and inform the natio­nal com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te whe­re the data hol­der is estab­lished that it has refu­sed or sus­pen­ded the dis­clo­sure of data, indi­ca­ting which mea­su­res have not been agreed or imple­men­ted and, whe­re rele­vant, which trade secrets have been brea­ched. In prin­ci­ple, data hol­ders can­not refu­se a data access request under this Regu­la­ti­on on the sole ground that cer­tain data are con­side­red to be trade secrets, as this would under­mi­ne the inten­ded effect of this Regu­la­ti­on. Howe­ver, in excep­tio­nal cases, a data hol­der hol­ding a trade secret should be able to refu­se a data access request for the spe­ci­fic data con­cer­ned on a case-by-case basis if it can demon­stra­te to the user or the third par­ty that the dis­clo­sure of that trade secret is likely to result in serious eco­no­mic dama­ge despi­te tech­ni­cal and orga­nizatio­nal mea­su­res taken by the user or the third par­ty. Serious eco­no­mic dama­ge is asso­cia­ted with serious irrepa­ra­ble eco­no­mic los­ses. The data con­trol­ler should duly justi­fy its refu­sal to the user or the third par­ty in wri­ting wit­hout undue delay and inform the com­pe­tent aut­ho­ri­ty the­reof. Such justi­fi­ca­ti­on should be based on objec­ti­ve facts show­ing that the dis­clo­sure of cer­tain data is likely to result in a con­cre­te risk of serious eco­no­mic dama­ge and why the mea­su­res taken to pro­tect the reque­sted data are con­side­red insuf­fi­ci­ent. In this con­text, any nega­ti­ve impact on cyber­se­cu­ri­ty may be taken into account. Wit­hout pre­ju­di­ce to the right to appeal befo­re a court of a Mem­ber Sta­te, the user or the third par­ty who wis­hes to con­test the decis­i­on of the data con­trol­ler to refu­se, refu­se or sus­pend the trans­fer of data may lodge a com­plaint with the com­pe­tent aut­ho­ri­ty, which should then deci­de wit­hout delay whe­ther and under which con­di­ti­ons the trans­fer of the data should start or resu­me, or the user or the third par­ty may agree with the data con­trol­ler to refer the mat­ter to a dis­pu­te sett­le­ment body. The excep­ti­ons to data access rights pro­vi­ded for in this Regu­la­ti­on should in no way limit the rights of data sub­jects to access and data por­ta­bi­li­ty under Regu­la­ti­on (EU) 2016/679.
(7) If no agree­ment is rea­ched on the neces­sa­ry mea­su­res refer­red to in para­graph 6 or if the mea­su­res agreed in accordance with para­graph 6 are not imple­men­ted by the User or if the con­fi­den­tia­li­ty of the trade secrets is brea­ched, the Data Con­trol­ler may refu­se to dis­c­lo­se or, whe­re appro­pria­te, sus­pend the dis­clo­sure of data clas­si­fi­ed as trade secrets. The Data Controller’s decis­i­on shall be duly justi­fi­ed and com­mu­ni­ca­ted to the User in wri­ting wit­hout delay. In such cases, the data hol­der shall noti­fy the com­pe­tent aut­ho­ri­ty desi­gna­ted in accordance with Artic­le 37 that it has refu­sed or sus­pen­ded the dis­clo­sure of data, indi­ca­ting the mea­su­res that have not been agreed or imple­men­ted and the trade secrets for which con­fi­den­tia­li­ty has been undermined. 
(8) Whe­re, in excep­tio­nal cir­cum­stances, the data con­trol­ler which is the hol­der of a trade secret can demon­stra­te that, despi­te the tech­ni­cal and orga­nizatio­nal mea­su­res taken by the user in accordance with para­graph 6 of this Artic­le, it is likely to suf­fer serious eco­no­mic dama­ge as a result of the dis­clo­sure of trade secrets, it may refu­se a data access request for the spe­ci­fic data con­cer­ned on a case-by-case basis. This justi­fi­ca­ti­on must be suf­fi­ci­ent­ly sub­stan­tia­ted on the basis of objec­ti­ve facts, in par­ti­cu­lar the enforcea­bi­li­ty of the pro­tec­tion of trade secrets in third count­ries, the natu­re and degree of con­fi­den­tia­li­ty of the reque­sted data and the uni­que­ness and novel­ty of the net­work­ed pro­duct, and must be sub­mit­ted to the user in wri­ting wit­hout delay. If the data hol­der refu­ses to dis­c­lo­se data in accordance with this para­graph, it shall noti­fy the com­pe­tent aut­ho­ri­ty desi­gna­ted in accordance with Artic­le 37.
(57) Data con­trol­lers may app­ly appro­pria­te tech­ni­cal pro­tec­tion mea­su­res to pre­vent the unlawful dis­clo­sure of or access to data. Howe­ver, the­se mea­su­res should not dis­cri­mi­na­te bet­ween data reci­pi­en­ts or impair access to and use of data by users or data reci­pi­en­ts. In the event of abu­si­ve prac­ti­ces by a data reci­pi­ent, such as mis­lea­ding the data owner by pro­vi­ding fal­se infor­ma­ti­on with the inten­ti­on of using the data for unlawful pur­po­ses, inclu­ding the deve­lo­p­ment of a com­pe­ting net­work­ed pro­duct based on the data, the data owner and, whe­re appro­pria­te, if not the same per­son, the trade secret hol­der or the user may request the third par­ty or data reci­pi­ent to take imme­dia­te cor­rec­ti­ve or reme­di­al action. Such requests, in par­ti­cu­lar requests to cea­se the pro­duc­tion, offe­ring or mar­ke­ting of goods, deri­ved data or ser­vices and requests to cea­se the import, export and sto­rage of inf­rin­ging goods or to destroy them, should be asses­sed in terms of whe­ther they are pro­por­tio­na­te to the inte­rests of the data con­trol­ler, the trade secret hol­der or the user.
(9) Wit­hout pre­ju­di­ce to a user’s right to seek a judi­cial reme­dy befo­re a court of a Mem­ber Sta­te at any time, a data controller’s decis­i­on to refu­se, deny or sus­pend the trans­fer of data pur­su­ant to para­graphs 7 and 8 may be chal­len­ged by a user by
a) lodges a com­plaint with the com­pe­tent aut­ho­ri­ty in accordance with Artic­le 37(5)(b), which shall deci­de wit­hout delay whe­ther and under what con­di­ti­ons the dis­clo­sure of the data shall start or resu­me, or
b) agreed with the data con­trol­ler to refer the mat­ter to a dis­pu­te reso­lu­ti­on body in accordance with Artic­le 10(1).
(10) The user shall not use the data obtai­ned pur­su­ant to a request under para­graph 1 to deve­lop a con­nec­ted pro­duct that is in com­pe­ti­ti­on with the con­nec­ted pro­duct from which the data ori­gi­na­ted, nor shall he dis­c­lo­se or use such data with that inten­ti­on to a third par­ty in order to gain insight into the eco­no­mic situa­ti­on, assets and pro­duc­tion methods of the manu­fac­tu­rer or, whe­re appli­ca­ble, the data owner.
(32) The objec­ti­ve of this Regu­la­ti­on is not only to sti­mu­la­te the deve­lo­p­ment of new, inno­va­ti­ve con­nec­ted pro­ducts or con­nec­ted ser­vices and to dri­ve inno­va­ti­on in down­stream mar­kets, but also to sti­mu­la­te the deve­lo­p­ment of enti­re­ly new types of ser­vices using the data con­cer­ned, inclu­ding on the basis of data from a varie­ty of con­nec­ted pro­ducts or con­nec­ted ser­vices. At the same time, this Regu­la­ti­on seeks to pre­vent the loss of incen­ti­ves to invest in the type of con­nec­ted pro­ducts from which the data is obtai­ned, for exam­p­le whe­re data is used to deve­lop a com­pe­ting con­nec­ted pro­duct that is con­side­red inter­ch­an­geable or sub­sti­tu­ta­ble by users, in par­ti­cu­lar on the basis of its cha­rac­te­ri­stics, pri­ce and inten­ded use. This Regu­la­ti­on does not pro­vi­de for a pro­hi­bi­ti­on on the deve­lo­p­ment of a con­nec­ted ser­vice using data obtai­ned under this Regu­la­ti­on, as this would have an unde­si­ra­ble chil­ling effect on inno­va­ti­on. The inno­va­ti­on efforts of data hol­ders are pro­tec­ted by the pro­hi­bi­ti­on to use data acce­s­sed under this Regu­la­ti­on for the deve­lo­p­ment of a com­pe­ting con­nec­ted pro­duct. Whe­ther a con­nec­ted pro­duct is in com­pe­ti­ti­on with the con­nec­ted pro­duct from which the data ori­gi­na­tes depends on whe­ther the two con­nec­ted pro­ducts com­pe­te on the same pro­duct mar­ket. This has to be deci­ded on the basis of well-estab­lished prin­ci­ples of Uni­on com­pe­ti­ti­on law to deter­mi­ne the rele­vant pro­duct mar­ket. Howe­ver, a legi­ti­ma­te pur­po­se for the use of the data, to the ext­ent that the requi­re­ments of this Regu­la­ti­on, Uni­on or natio­nal law are met, could include rever­se engi­nee­ring. This may be for the pur­po­ses of repai­ring or exten­ding the life of a con­nec­ted pro­duct or pro­vi­ding after-mar­ket ser­vices for con­nec­ted products.
(11) The user may not use any means of coer­ci­on or exploit any gaps in the tech­ni­cal infras­truc­tu­re of a data con­trol­ler that exists to pro­tect the data in order to gain access to data. 
(12) If the user is not the data sub­ject who­se per­so­nal data is reque­sted, the data con­trol­ler may only pro­vi­de per­so­nal data gene­ra­ted during the use of a con­nec­ted pro­duct or con­nec­ted ser­vice to the user if the­re is a valid legal basis for the pro­ce­s­sing in accordance with Artic­le 6 of Regu­la­ti­on (EU) 2016/679 and, whe­re appli­ca­ble, the con­di­ti­ons of Artic­le 9 of that Regu­la­ti­on and Artic­le 5(3) of Direc­ti­ve 2002/58/ are met.
(34) When using a net­work­ed pro­duct or con­nec­ted ser­vice, espe­ci­al­ly if the user is a natu­ral per­son, data may be gene­ra­ted that rela­tes to a data sub­ject. The pro­ce­s­sing of such data is sub­ject to the pro­vi­si­ons of Regu­la­ti­on (EU) 2016/679, even if per­so­nal and non-per­so­nal data are inex­tri­ca­bly lin­ked in a data set. The data sub­ject may be the user or ano­ther natu­ral per­son. Access to per­so­nal data may only be reque­sted by a con­trol­ler or a data sub­ject. The user, who is the data sub­ject, is entit­led to access the per­so­nal data rela­ting to that user under cer­tain cir­cum­stances in accordance with Regu­la­ti­on (EU) 2016/679; the­se rights are not affec­ted by this Regu­la­ti­on. Under this Regu­la­ti­on, a user who is a natu­ral per­son also has the right to access all data gene­ra­ted by the use of a con­nec­ted pro­duct, whe­ther per­so­nal or non-per­so­nal. Whe­re the user is not the data sub­ject but a com­pa­ny, inclu­ding a sole trader, and the pro­duct is not used joint­ly in a hou­se­hold, the user is con­side­red to be the con­trol­ler. Accor­din­gly, a user who intends to request access to per­so­nal data gene­ra­ted during the use of a con­nec­ted pro­duct or con­nec­ted ser­vice as a con­trol­ler requi­res a legal basis for pro­ce­s­sing the data in accordance with Artic­le 6(1) of Regu­la­ti­on (EU) 2016/679, such as the con­sent of the data sub­ject or the per­for­mance of a con­tract to which the data sub­ject is par­ty. This user should ensu­re that the data sub­ject is ade­qua­te­ly infor­med about the spe­ci­fic, expli­cit and legi­ti­ma­te pur­po­ses of the pro­ce­s­sing of the­se data and how the data sub­ject can effec­tively exer­cise his or her rights. Whe­re the data con­trol­ler and the user are joint con­trol­lers within the mea­ning of Artic­le 26 of Regu­la­ti­on (EU) 2016/679, they must spe­ci­fy in a trans­pa­rent man­ner in an agree­ment which of them ful­fills the rele­vant obli­ga­ti­ons to com­ply with that Regu­la­ti­on. It should be under­s­tood that once data has been pro­vi­ded, such a user may in turn beco­me a data con­trol­ler if that user ful­fills the cri­te­ria of this Regu­la­ti­on and thus may in turn be sub­ject to the obli­ga­ti­ons to pro­vi­de data under this Regulation.
(13) The Data Con­trol­ler may only use rea­di­ly available data that is non-per­so­nal data on the basis of a con­tract with the User. The Data Con­trol­ler may not use such data to gain insight into the User’s eco­no­mic situa­ti­on, assets and pro­duc­tion methods or into the User’s use in any other way that could under­mi­ne the User’s com­mer­cial posi­ti­on in mar­kets in which the User operates.
(36) Access to data stored on ter­mi­nal equip­ment or acce­s­si­ble via ter­mi­nal equip­ment is sub­ject to Direc­ti­ve 2002/58/ and requi­res the con­sent of the sub­scri­ber or user within the mea­ning of that Direc­ti­ve, unless access to the data is strict­ly neces­sa­ry for the pro­vi­si­on of an infor­ma­ti­on socie­ty ser­vice expli­ci­t­ly reque­sted by the user or sub­scri­ber or for the sole pur­po­se of trans­mit­ting a com­mu­ni­ca­ti­on. Direc­ti­ve 2002/58/ pro­tects the inte­gri­ty of a user’s ter­mi­nal equip­ment with regard to the use of pro­ce­s­sing and sto­rage func­tions and the coll­ec­tion of infor­ma­ti­on. Inter­net of Things devices are con­side­red to be ter­mi­nal equip­ment if they are direct­ly or indi­rect­ly con­nec­ted to a public com­mu­ni­ca­ti­ons network.
(14) Data owners may not pro­vi­de non-per­so­nal pro­duct data to third par­ties for any com­mer­cial or non-com­mer­cial pur­po­ses other than to ful­fill their con­tract with the user. Whe­re appli­ca­ble, third par­ties may be con­trac­tual­ly obli­ged by data con­trol­lers not to re-dis­c­lo­se the data recei­ved from them.
(25) This Regu­la­ti­on should not be under­s­tood as con­fer­ring a new right on data hol­ders to use pro­duct data or con­nec­ted ser­vice data. Whe­re the manu­fac­tu­rer of a con­nec­ted pro­duct is the data con­trol­ler, a con­tract bet­ween the manu­fac­tu­rer and the user should form the basis for the use of non-per­so­nal data by the manu­fac­tu­rer. Such a con­tract could be part of an agree­ment for the pro­vi­si­on of the con­nec­ted ser­vice, which may be con­clu­ded tog­e­ther with the purcha­se, ren­tal or lea­sing con­tract for the con­nec­ted pro­duct. Any con­trac­tu­al clau­se allo­wing the data con­trol­ler to use the pro­duct data or con­nec­ted ser­vice data should be trans­pa­rent to the user, inclu­ding in rela­ti­on to the pur­po­ses for which the data con­trol­ler intends to use the data. Such uses could include impro­ving the func­tio­ning of the con­nec­ted pro­duct or con­nec­ted ser­vices, deve­lo­ping new pro­ducts or ser­vices, or aggre­ga­ting data with the aim of pro­vi­ding the resul­ting deri­ved data to third par­ties, pro­vi­ded that such deri­ved data does not enable the iden­ti­fi­ca­ti­on of indi­vi­du­al data trans­mit­ted by the con­nec­ted pro­duct to the data con­trol­ler and does not enable third par­ties to retrie­ve such data from the data set. Any chan­ge to the con­tract should requi­re the infor­med con­sent of the user. This Regu­la­ti­on does not pre­vent the par­ties from agre­e­ing con­trac­tu­al clau­ses which have the effect of exclu­ding or rest­ric­ting the use of non-per­so­nal data or cer­tain cate­go­ries of non-per­so­nal data by a data con­trol­ler. Nor does it pre­vent the par­ties from agre­e­ing that pro­duct data or rela­ted ser­vice data may be pro­vi­ded direct­ly or indi­rect­ly to third par­ties, inclu­ding, whe­re rele­vant, through ano­ther data con­trol­ler. Fur­ther­mo­re, this Regu­la­ti­on does not pre­clude sec­tor-spe­ci­fic regu­la­to­ry requi­re­ments under Uni­on law or natio­nal law in con­for­mi­ty with Uni­on law which would exclude or rest­rict the use of cer­tain data by the data hol­der on well-defi­ned public poli­cy grounds. Fur­ther­mo­re, this Regu­la­ti­on does not pre­vent users from pro­vi­ding data to third par­ties or data hol­ders in the case of busi­ness-to-busi­ness rela­ti­on­ships under any lawful con­trac­tu­al clau­ses, inclu­ding by agre­e­ing to limit or rest­rict re-dis­clo­sure of such data or by pro­vi­ding users with ade­qua­te con­side­ra­ti­on, for exam­p­le, for wai­ving their right to use or dis­c­lo­se such data. Alt­hough the term „data con­trol­ler“ does not gene­ral­ly include public sec­tor bodies, it may include public sec­tor companies.
Artic­le 5 Right of the user to trans­fer data to third parties
(26) To pro­mo­te the emer­gence of liquid, fair and effi­ci­ent mar­kets for non-per­so­nal data, users of net­work­ed pro­ducts should be able to share data with mini­mal legal and tech­ni­cal effort, inclu­ding for com­mer­cial pur­po­ses. It is curr­ent­ly often dif­fi­cult for com­pa­nies to justi­fy the labor or IT costs invol­ved in pre­pa­ring non-per­so­nal data­sets or data pro­ducts and offe­ring them to poten­ti­al coun­ter­par­ties through data inter­me­dia­ti­on ser­vices, inclu­ding data mar­ket­places. A major obs­ta­cle to the sha­ring of non-per­so­nal data by busi­nesses the­r­e­fo­re ari­ses from the lack of pre­dic­ta­bi­li­ty of the eco­no­mic return on invest­ment in the pre­pa­ra­ti­on and pro­vi­si­on of data­sets or data pro­ducts. In order for liquid, fair and effi­ci­ent mar­kets for non-per­so­nal data to emer­ge in the Uni­on, it is neces­sa­ry to cla­ri­fy which par­ty has the right to offer such data on a mar­ket. Users should the­r­e­fo­re have the right to share non-per­so­nal data with data reci­pi­en­ts for com­mer­cial and non-com­mer­cial pur­po­ses. Such dis­clo­sure could be made direct­ly by the user, at the request of the user through a data con­trol­ler or through data inter­me­dia­ry ser­vices. Data inter­me­dia­ry ser­vices within the mea­ning of Regu­la­ti­on (EU) 2022/868 of the Euro­pean Par­lia­ment and of the Coun­cil (22) could ser­ve the data eco­no­my by estab­li­shing busi­ness rela­ti­on­ships bet­ween users, data reci­pi­en­ts and third par­ties and assi­sting users in exer­cis­ing their right to use data, for exam­p­le by ensu­ring the anony­mizati­on of per­so­nal data or the aggre­ga­ti­on of access to data from a lar­ge num­ber of indi­vi­du­al users. Whe­re data are exempt­ed from a data controller’s obli­ga­ti­on to pro­vi­de them to users or third par­ties, the scope of such data could be spe­ci­fi­ed in the con­tract con­clu­ded bet­ween the user and the data con­trol­ler for the pro­vi­si­on of a rela­ted ser­vice, so that users can easi­ly iden­ti­fy which data are available to them for sha­ring with data reci­pi­en­ts or third par­ties. Data hol­ders should not pro­vi­de non-per­so­nal pro­duct data to third par­ties for eit­her com­mer­cial or non-com­mer­cial pur­po­ses, except for the per­for­mance of their con­tract with the user; this should be wit­hout pre­ju­di­ce to the legal requi­re­ments under Uni­on or natio­nal law for a data hol­der to pro­vi­de data. Whe­re appro­pria­te, data con­trol­lers should con­trac­tual­ly obli­ge third par­ties not to re-dis­c­lo­se the data they have received.
(30) The user should be free to use the data for any lawful pur­po­se. This inclu­des pro­vi­ding the data obtai­ned by the user in the exer­cise of his rights under this Regu­la­ti­on to a third par­ty offe­ring a after-mar­ket ser­vice that may be in com­pe­ti­ti­on with a ser­vice pro­vi­ded by a data con­trol­ler, or ins­truc­ting the data con­trol­ler to do so. The request for access should be made by the user or by an aut­ho­ri­zed third par­ty acting on behalf of a user, inclu­ding by a pro­vi­der of a data inter­me­dia­ry ser­vice. Data hol­ders should ensu­re that the data pro­vi­ded to a third par­ty is as accu­ra­te, com­ple­te, relia­ble, rele­vant and up-to-date as the data gene­ra­ted by the use of the con­nec­ted pro­duct or ser­vice that the data hol­der can or is aut­ho­ri­zed to access. Intellec­tu­al pro­per­ty rights should be respec­ted when pro­ce­s­sing the data. It is important that the­re con­ti­n­ue to be incen­ti­ves to invest in pro­ducts who­se func­tions are based on the use of data from sen­sors built into the­se products.
(35) Pro­duct data or rela­ted ser­vice data should only be pro­vi­ded to third par­ties at the request of the user. Accor­din­gly, this Regu­la­ti­on sup­ple­ments the right of a data sub­ject under Artic­le 20 of Regu­la­ti­on (EU) 2016/679 to recei­ve the per­so­nal data con­cer­ning him or her in a struc­tu­red, com­mon­ly used, machi­ne-rea­da­ble and inter­ope­ra­ble for­mat and to trans­mit tho­se data to ano­ther con­trol­ler, whe­re the per­so­nal data are pro­ce­s­sed by auto­ma­ted means on the basis of Artic­le 6(1)(a) or Artic­le 9(2)(a) or a con­tract pur­su­ant to Artic­le 6(1)(b) of that Regu­la­ti­on. Data sub­jects also have the right to have the per­so­nal data trans­mit­ted direct­ly from one con­trol­ler to ano­ther, but only if this is tech­ni­cal­ly fea­si­ble. Artic­le 20 of Regu­la­ti­on (EU) 2016/679 spe­ci­fi­es that this con­cerns data pro­vi­ded by the data sub­ject, wit­hout spe­ci­fy­ing whe­ther this requi­res acti­ve beha­vi­or by the data sub­ject or whe­ther this also applies in cases whe­re a con­nec­ted pro­duct or ser­vice, by its design, pas­si­ve­ly coll­ects the beha­vi­or of a data sub­ject or other infor­ma­ti­on rela­ting to a data sub­ject. The rights con­tai­ned in this Regu­la­ti­on sup­ple­ment the right to recei­ve and trans­mit per­so­nal data in accordance with Artic­le 20 of Regu­la­ti­on (EU) 2016/679 in various ways. This Regu­la­ti­on grants users the right to access and pro­vi­de any pro­duct data or rela­ted ser­vice data to a third par­ty, regard­less of whe­ther it is per­so­nal data, regard­less of the distinc­tion bet­ween actively pro­vi­ded or pas­si­ve­ly coll­ec­ted data and regard­less of the legal basis for the pro­ce­s­sing. In con­trast to Artic­le 20 of Regu­la­ti­on (EU) 2016/679, this Regu­la­ti­on requi­res and ensu­res the tech­ni­cal fea­si­bi­li­ty of third par­ty access to all types of data within its scope, whe­ther per­so­nal or non-per­so­nal, thus ensu­ring that tech­ni­cal bar­riers no lon­ger hin­der or pre­vent access to such data. It also allo­ws data hol­ders to set a fair com­pen­sa­ti­on for costs incur­red in pro­vi­ding direct access to the data gene­ra­ted by the user’s con­nec­ted pro­duct, which is to be bor­ne by third par­ties but not by the user. Whe­re a data con­trol­ler and a third par­ty are unable to agree on terms for such direct access, the data sub­ject should in no way be pre­ven­ted from exer­cis­ing the rights laid down in Regu­la­ti­on (EU) 2016/679, inclu­ding the right to data por­ta­bi­li­ty, by see­king redress in accordance with that Regu­la­ti­on. In this con­text, in accordance with Regu­la­ti­on (EU) 2016/679, a con­tract may not aut­ho­ri­ze the pro­ce­s­sing of spe­cial cate­go­ries of per­so­nal data by the data con­trol­ler or the third party.
(1) At the request of a User or a par­ty acting on behalf of a User, the Data Con­trol­ler shall pro­vi­de a third par­ty with rea­di­ly available Data and the meta­da­ta neces­sa­ry for the inter­pre­ta­ti­on and use of such Data wit­hout undue delay, free of char­ge to the User, in the same qua­li­ty as available to the Data Con­trol­ler, easi­ly, secu­re­ly, free of char­ge to the User, in a com­pre­hen­si­ve, struc­tu­red, com­mon­ly used and machi­ne-rea­da­ble for­mat and, whe­re rele­vant and tech­ni­cal­ly fea­si­ble, con­ti­nuous­ly and in real time. The Data Con­trol­ler shall pro­vi­de the Data to the third par­ty in accordance with Artic­les 8 and 9. 
(2) Para­graph 1 shall not app­ly to rea­di­ly available data rela­ted to the test­ing of new net­work­ed pro­ducts, sub­stances or pro­ce­s­ses that are not yet pla­ced on the mar­ket, unless their use by third par­ties is con­trac­tual­ly authorized. 
(3) A com­pa­ny desi­gna­ted as a gate­kee­per in accordance with Artic­le 3 of Regu­la­ti­on (EU) 2022/1925 shall not be con­side­red an aut­ho­ri­zed third par­ty within the mea­ning of this Artic­le and is the­r­e­fo­re not eli­gi­ble,
a) soli­cit or com­mer­ci­al­ly indu­ce in any way, inclu­ding finan­ci­al­ly or other­wi­se, a user to pro­vi­de data obtai­ned from the user in respon­se to a request under Artic­le 4(1) for any of its services;
b) request or com­mer­ci­al­ly incen­ti­vi­ze a user to requi­re the data con­trol­ler to pro­vi­de data for one of its ser­vices in accordance with para­graph 1 of this Article;
c) to obtain from a user data which the user has obtai­ned fol­lo­wing a request pur­su­ant to Artic­le 4(1).
(4) For the pur­po­ses of veri­fy­ing whe­ther a natu­ral or legal per­son is to be clas­si­fi­ed as a user or a third par­ty for the pur­po­ses of para­graph 1, no infor­ma­ti­on bey­ond what is neces­sa­ry shall be reque­sted from the data con­trol­ler or third par­ty. Data con­trol­lers shall not retain infor­ma­ti­on about the third party’s access to the reque­sted data bey­ond what is neces­sa­ry for the pro­per exe­cu­ti­on of the third party’s access request and for the secu­ri­ty and main­ten­an­ce of the data infrastructure. 
(5) The third par­ty may not use any means of coer­ci­on or exploit any gaps in the data controller’s exi­sting tech­ni­cal infras­truc­tu­re to pro­tect the data in order to gain access to data. 
(6) The Data Con­trol­ler shall not use rea­di­ly available data to gain insight into the eco­no­mic situa­ti­on, assets and pro­duc­tion methods of the third par­ty or into the use by the third par­ty in any other way that could under­mi­ne the com­mer­cial posi­ti­on of the third par­ty in the mar­kets in which it ope­ra­tes, unless the third par­ty has aut­ho­ri­zed such use and has the tech­ni­cal pos­si­bi­li­ty to easi­ly revo­ke this aut­ho­rizati­on at any time.
(33) A third par­ty to whom data is pro­vi­ded may be a natu­ral or legal per­son, such as a con­su­mer, a busi­ness, a rese­arch orga­nizati­on, a non-pro­fit orga­nizati­on or an enti­ty acting in a pro­fes­sio­nal capa­ci­ty. If a data con­trol­ler pro­vi­des the data to the third par­ty, it should not abu­se its posi­ti­on to gain a com­pe­ti­ti­ve advan­ta­ge in mar­kets whe­re the data con­trol­ler and the third par­ty may be in direct com­pe­ti­ti­on. The data con­trol­ler should the­r­e­fo­re not use rea­di­ly available data to gain insight into the eco­no­mic situa­ti­on, assets or pro­duc­tion methods of the third par­ty or use by the third par­ty in any other way that could under­mi­ne the com­mer­cial posi­ti­on of the third par­ty in the mar­kets in which it ope­ra­tes. The user should be able to dis­c­lo­se non-per­so­nal data to third par­ties for com­mer­cial pur­po­ses. With the user’s con­sent and sub­ject to the pro­vi­si­ons of this Regu­la­ti­on, third par­ties should be able to trans­fer the data access rights gran­ted by the user to other third par­ties, inclu­ding for a fee. Busi­ness-to-busi­ness data inter­me­dia­ries and per­so­nal infor­ma­ti­on manage­ment systems (PIMS), refer­red to as data inter­me­dia­ti­on ser­vices in Regu­la­ti­on (EU) 2022/868, may assist users or third par­ties in estab­li­shing busi­ness rela­ti­on­ships with an unspe­ci­fi­ed num­ber of poten­ti­al coun­ter­par­ties for any lawful pur­po­se fal­ling within the scope of this Regu­la­ti­on. They could play a cru­cial role in aggre­ga­ting access to data so that big data ana­ly­tics or machi­ne lear­ning can be faci­li­ta­ted, pro­vi­ded that users retain full con­trol over whe­ther they make their data available for such aggre­ga­ti­on and under which com­mer­cial con­di­ti­ons their data is to be used.
(7) If the user is not the data sub­ject who­se per­so­nal data is requi­red, per­so­nal data gene­ra­ted during the use of a con­nec­ted pro­duct or con­nec­ted ser­vice may only be pro­vi­ded by the data con­trol­ler to the third par­ty if the­re is a valid legal basis for the pro­ce­s­sing in accordance with Artic­le 6 of Regu­la­ti­on (EU) 2016/679 and, whe­re appli­ca­ble, the con­di­ti­ons of Artic­le 9 of that Regu­la­ti­on and Artic­le 5(3) of Direc­ti­ve 2002/58/ are met. 
(8) The exer­cise of the data subject’s rights under Regu­la­ti­on (EU) 2016/679, and in par­ti­cu­lar the right to data por­ta­bi­li­ty under Artic­le 20 of that Regu­la­ti­on, shall not be hin­de­red, pre­ven­ted or impai­red by the fail­ure of the data con­trol­ler or the third par­ty to make arran­ge­ments for the trans­fer of the data. 
(9) Trade secrets shall be pro­tec­ted and dis­c­lo­sed to third par­ties only to the ext­ent that such dis­clo­sure is strict­ly neces­sa­ry for the pur­po­se agreed bet­ween the user and the third par­ty. The data con­trol­ler or, if they are not the same per­son, the trade secret hol­der shall iden­ti­fy the data pro­tec­ted as trade secrets, inclu­ding in the rele­vant meta­da­ta, and shall agree with the third par­ty all appro­pria­te tech­ni­cal and orga­nizatio­nal mea­su­res neces­sa­ry to main­tain the con­fi­den­tia­li­ty of the data dis­c­lo­sed, such as model con­tract clau­ses, con­fi­den­tia­li­ty agree­ments, strict access pro­to­cols, tech­ni­cal stan­dards and the appli­ca­ti­on of codes of conduct. 
(10) If no agree­ment is rea­ched on the neces­sa­ry mea­su­res refer­red to in para­graph 9 of this Artic­le or if the third par­ty fails to imple­ment the mea­su­res agreed in accordance with para­graph 9 of this Artic­le or if the con­fi­den­tia­li­ty of the trade secrets is brea­ched, the data con­trol­ler may refu­se to dis­c­lo­se or, whe­re appro­pria­te, sus­pend the dis­clo­sure of data iden­ti­fi­ed as trade secrets. The Data Controller’s decis­i­on shall be duly justi­fi­ed and com­mu­ni­ca­ted to the third par­ty in wri­ting wit­hout delay. In such cases, the data hol­der shall noti­fy the com­pe­tent aut­ho­ri­ty desi­gna­ted pur­su­ant to Artic­le 37 that it has refu­sed or sus­pen­ded the dis­clo­sure of data, indi­ca­ting the mea­su­res that have not been agreed or imple­men­ted and the trade secrets for which con­fi­den­tia­li­ty has been breached. 
(11) Whe­re, in excep­tio­nal cir­cum­stances, the data con­trol­ler which is the hol­der of a trade secret can demon­stra­te that, despi­te the tech­ni­cal and orga­nizatio­nal mea­su­res taken by the third par­ty in accordance with para­graph 9 of this Artic­le, it is likely to suf­fer serious eco­no­mic dama­ge as a result of a dis­clo­sure of trade secrets, it may refu­se the data access request for the spe­ci­fic data con­cer­ned on a case-by-case basis. This justi­fi­ca­ti­on must be suf­fi­ci­ent­ly sub­stan­tia­ted on the basis of objec­ti­ve facts, in par­ti­cu­lar the enforcea­bi­li­ty of the pro­tec­tion of trade secrets in third count­ries, the natu­re and degree of con­fi­den­tia­li­ty of the reque­sted data and the uni­que­ness and novel­ty of the net­work­ed pro­duct, and must be sub­mit­ted to third par­ties in wri­ting wit­hout delay. Whe­re the data hol­der refu­ses to dis­c­lo­se data in accordance with this para­graph, it shall noti­fy the com­pe­tent aut­ho­ri­ty desi­gna­ted in accordance with Artic­le 37. 
(12) Wit­hout pre­ju­di­ce to the right of third par­ties to seek redress befo­re a court of a Mem­ber Sta­te at any time, a third par­ty wis­hing to chall­enge a decis­i­on of the data con­trol­ler to refu­se, refu­se or sus­pend the trans­fer of data pur­su­ant to para­graphs 10 and 11 may do so:
a) lodge a com­plaint pur­su­ant to Artic­le 37(5)(b) with the com­pe­tent aut­ho­ri­ty, which shall deci­de wit­hout delay whe­ther and under what con­di­ti­ons the dis­clo­sure of the data shall start or resu­me; or
b) agree with the data con­trol­ler to refer the mat­ter to a dis­pu­te reso­lu­ti­on body in accordance with Artic­le 10(1).
(13) The right refer­red to in para­graph 1 shall not adver­se­ly affect the rights of data sub­jects under appli­ca­ble Uni­on and natio­nal law on the pro­tec­tion of per­so­nal data.
Artic­le 6 Obli­ga­ti­ons of third par­ties who recei­ve data at the user’s request
(1) A third par­ty shall pro­cess the data pro­vi­ded to it in accordance with Artic­le 5 only for the pur­po­ses and under the con­di­ti­ons agreed with the user and in accordance with appli­ca­ble Uni­on and natio­nal law on the pro­tec­tion of per­so­nal data, inclu­ding the rights of the data sub­ject whe­re per­so­nal data are con­cer­ned. The third par­ty shall dele­te the data as soon as it is no lon­ger requi­red for the agreed pur­po­se, unless other­wi­se agreed with the user with regard to non-per­so­nal data.
(37) In order to pre­vent users from being exploi­ted, third par­ties to whom the data has been pro­vi­ded at the user’s request should only pro­cess this data for the pur­po­ses agreed with the user and only pass it on to other third par­ties if the user has given their con­sent to this data transfer.
(2) The third par­ty is prohibited, 
(38) In accordance with the prin­ci­ple of data mini­mizati­on, third par­ties should only access infor­ma­ti­on that is neces­sa­ry for the pro­vi­si­on of the ser­vice reque­sted by the user. Once the third par­ty has gai­ned access to the data, it should pro­cess it for the pur­po­ses agreed with the user wit­hout inter­fe­rence from the data con­trol­ler. It should be as easy for the user to deny or ter­mi­na­te third par­ty access to the data as it is for the user to allow access to the data. Neither third par­ties nor data hol­ders should undu­ly impe­de the exer­cise of users„ choices or rights, inclu­ding by offe­ring them choices in a non-neu­tral way, or by coer­cing, decei­ving or mani­pu­la­ting the user, or by under­mi­ning or inter­fe­ring with the user’s auto­no­my, decis­i­on-making capa­ci­ty or free­dom of choice, inclu­ding through a digi­tal user inter­face or part the­reof. In this con­text, third par­ties or data owners should not use so-cal­led “dark pat­terns„ when desig­ning their digi­tal inter­faces. “Dark pat­terns„ are design tech­ni­ques that are used to mis­lead or decei­ve con­su­mers into making decis­i­ons that have nega­ti­ve con­se­quen­ces for them. The­se mani­pu­la­ti­ve tech­ni­ques may be used to indu­ce and decei­ve users, par­ti­cu­lar­ly vul­nerable con­su­mers, into unde­si­ra­ble beha­vi­or by encou­ra­ging them to make decis­i­ons about data dis­clo­sure, and to dis­pro­por­tio­na­te­ly influence the decis­i­on-making of users of the ser­vice in a way that under­mi­nes or impairs their auto­no­my, decis­i­on-making abili­ty or choice. Usu­al and lawful com­mer­cial prac­ti­ces that com­ply with Uni­on law should not in them­sel­ves be con­side­red as “dark pat­terns’. Third par­ties and data con­trol­lers should com­ply with their obli­ga­ti­ons under rele­vant Uni­on law, in par­ti­cu­lar the requi­re­ments of Direc­ti­ves 98/6/ (24) and 2000/31/ (25) of the Euro­pean Par­lia­ment and of the Coun­cil and Direc­ti­ves 2005/29/ and 2011/83/EU.
a) make it exce­s­si­ve­ly dif­fi­cult for users to exer­cise their choices or their rights under Artic­le 5 and this Artic­le, inclu­ding by offe­ring users choices in a non-neu­tral way, or in any way coer­cing, decei­ving or mani­pu­la­ting users, or under­mi­ning or impai­ring the user’s auto­no­my, decis­i­on-making abili­ty or choices, inclu­ding through a digi­tal user inter­face or part thereof;
b) wit­hout pre­ju­di­ce to Artic­le 22(2)(a) and (c) of Regu­la­ti­on (EU) 2016/679, to use the data obtai­ned for pro­fil­ing, unless this is neces­sa­ry to pro­vi­de the ser­vice reque­sted by the user;
(39) Third par­ties should also refrain from using data fal­ling within the scope of this Regu­la­ti­on for pro­fil­ing of an indi­vi­du­al, unless such pro­ce­s­sing acti­vi­ties are strict­ly neces­sa­ry to pro­vi­de the ser­vice reque­sted by the user, inclu­ding in the con­text of auto­ma­ted decis­i­on-making. The requi­re­ment to era­se data when it is no lon­ger neces­sa­ry for the pur­po­se agreed with the user, unless other­wi­se agreed in rela­ti­on to non-per­so­nal data, sup­ple­ments the data subject’s right to era­su­re under Artic­le 17 of Regu­la­ti­on (EU) 2016/679. Whe­re a third par­ty is a pro­vi­der of a data inter­me­dia­ti­on ser­vice, the safe­guards pro­vi­ded for in Regu­la­ti­on (EU) 2022/868 app­ly to the data sub­ject. The third par­ty may use the data for the deve­lo­p­ment of a new and inno­va­ti­ve con­nec­ted pro­duct or con­nec­ted ser­vice, but not for the deve­lo­p­ment of a com­pe­ting con­nec­ted product.
c) pro­vi­de the data recei­ved to ano­ther third par­ty, unless the data is pro­vi­ded on the basis of a con­tract with the user, and pro­vi­ded that the other third par­ty takes all mea­su­res agreed bet­ween the data con­trol­ler and the third par­ty that are neces­sa­ry to pro­tect the con­fi­den­tia­li­ty of busi­ness secrets;
d) pro­vi­de the data recei­ved to a com­pa­ny desi­gna­ted as gate­kee­per in accordance with Artic­le 3 of Regu­la­ti­on (EU) 2022/1925;
e) use the data obtai­ned to deve­lop a pro­duct that com­pe­tes with the con­nec­ted pro­duct from which the data ori­gi­na­ted, or to pass the data on to ano­ther third par­ty for this pur­po­se. Third par­ties are also pro­hi­bi­ted from using non-per­so­nal pro­duct data or con­nec­ted ser­vice data pro­vi­ded to them to gain insights into the eco­no­mic situa­ti­on, assets and pro­duc­tion methods of the data owner or the use by the data owner;
f) use the data obtai­ned in a way that adver­se­ly affects the secu­ri­ty of the net­work­ed pro­duct or con­nec­ted service;
g) dis­re­gard the mea­su­res agreed with the data con­trol­ler or trade secret hol­der pur­su­ant to Artic­le 5(9) and under­mi­ne the con­fi­den­tia­li­ty of trade secrets;
h) pre­vent the user, who is a con­su­mer, from pro­vi­ding the data recei­ved to other par­ties, inclu­ding on the basis of a contract.
Artic­le 7 Scope of busi­ness-to-con­su­mer and busi­ness-to-busi­ness data sha­ring obligations
(1) The obli­ga­ti­ons under this Chap­ter shall not app­ly to data gene­ra­ted in the use of con­nec­ted pro­ducts manu­fac­tu­red or desi­gned by a microen­ter­pri­se or a small enter­pri­se or gene­ra­ted in the use of con­nec­ted ser­vices pro­vi­ded by such an enter­pri­se, unless that under­ta­king has a part­ner under­ta­king or an asso­cia­ted under­ta­king within the mea­ning of Artic­le 3 of the Annex to Recom­men­da­ti­on 2003/361/ which is not a microen­ter­pri­se or a small enter­pri­se, and unless the microen­ter­pri­se or small enter­pri­se has been sub­con­trac­ted to manu­fac­tu­re or design a con­nec­ted pro­duct or to pro­vi­de a con­nec­ted service.
The same applies to data gene­ra­ted by the use of con­nec­ted pro­ducts manu­fac­tu­red by an under­ta­king which has been clas­si­fi­ed as a medi­um-sized enter­pri­se within the mea­ning of Artic­le 2 of the Annex to Recom­men­da­ti­on 2003/361/ for less than one year, or to con­nec­ted ser­vices pro­vi­ded by such an under­ta­king, and to con­nec­ted pro­ducts for one year after the date on which they are pla­ced on the mar­ket by a medi­um-sized enterprise.
(40) Start-ups, small enter­pri­ses and enter­pri­ses that qua­li­fy as medi­um-sized enter­pri­ses under Artic­le 2 of the Annex to Recom­men­da­ti­on 2003/361/, as well as enter­pri­ses from tra­di­tio­nal sec­tors with less deve­lo­ped digi­tal capa­bi­li­ties, face dif­fi­cul­ties in gai­ning access to rele­vant data. The aim of this Regu­la­ti­on is to faci­li­ta­te access to data for the­se enti­ties while ensu­ring that the obli­ga­ti­ons are as pro­por­tio­na­te as pos­si­ble to avo­id over­rea­ching. The accu­mu­la­ti­on and aggre­ga­ti­on of vast amounts of data and the tech­no­lo­gi­cal infras­truc­tu­re for its mone­tizati­on has simul­ta­neous­ly crea­ted a small num­ber of very lar­ge com­pa­nies with con­sidera­ble eco­no­mic power in the digi­tal eco­no­my. The­se very lar­ge com­pa­nies include ope­ra­tors of core plat­form ser­vices that con­trol enti­re plat­form eco­sy­stems in the digi­tal eco­no­my, making it impos­si­ble for exi­sting or new mar­ket play­ers to chall­enge their posi­ti­on or com­pe­te with them. Regu­la­ti­on (EU) 2022/1925 of the Euro­pean Par­lia­ment and of the Coun­cil (26) aims to address the­se inef­fi­ci­en­ci­es and imba­lan­ces by allo­wing the Com­mis­si­on to desi­gna­te a com­pa­ny as a „gate­kee­per“ and impo­sing a num­ber of obli­ga­ti­ons on the­se gate­kee­pers, inclu­ding the pro­hi­bi­ti­on to mer­ge cer­tain data wit­hout con­sent and the obli­ga­ti­on to ensu­re effec­ti­ve data por­ta­bi­li­ty rights under Artic­le 20 of Regu­la­ti­on (EU) 2016/679. In accordance with Regu­la­ti­on (EU) 2022/1925 and given the uni­que abili­ty of the­se com­pa­nies to acqui­re data, it is not neces­sa­ry to achie­ve the objec­ti­ve of this Regu­la­ti­on and the­r­e­fo­re dis­pro­por­tio­na­te in rela­ti­on to the data con­trol­lers sub­ject to the rele­vant obli­ga­ti­ons to grant such gate­kee­pers a right of access to data. Their inclu­si­on is also likely to limit the bene­fits that this Regu­la­ti­on can bring to SMEs in rela­ti­on to the fair dis­tri­bu­ti­on of data value crea­ti­on among mar­ket par­ti­ci­pan­ts. This means that a com­pa­ny desi­gna­ted as a gate­kee­per ope­ra­ting core plat­form ser­vices can­not, on the basis of this Regu­la­ti­on, request or obtain access to user data gene­ra­ted when using a con­nec­ted pro­duct or ser­vice or a vir­tu­al assi­stant. In addi­ti­on, third par­ties to whom data is pro­vi­ded at the request of the user may not pro­vi­de the data to a gate­kee­per. For exam­p­le, the third par­ty may not enga­ge a gate­kee­per to pro­vi­de the ser­vice. Howe­ver, this does not pre­vent third par­ties from using data pro­ce­s­sing ser­vices offe­red by a gate­kee­per. Nor does it pre­vent tho­se com­pa­nies from obtai­ning and using the same data by other lawful means. Access rights under this Regu­la­ti­on con­tri­bu­te to a wider choice of ser­vices for con­su­mers. As vol­un­t­a­ry agree­ments bet­ween gate­kee­pers and data hol­ders remain unaf­fec­ted, rest­ric­ting the gran­ting of access to gate­kee­pers would not exclude them from the mar­ket or pre­vent them from offe­ring their services.
(41) Given the cur­rent sta­te of the art, it would be too bur­den­so­me to impo­se fur­ther design obli­ga­ti­ons on microen­ter­pri­ses and small enter­pri­ses for con­nec­ted pro­ducts that they manu­fac­tu­re or design or con­nec­ted ser­vices that they pro­vi­de. Howe­ver, this is not the case whe­re a microen­ter­pri­se or small enter­pri­se has a part­ner enter­pri­se or an asso­cia­ted enter­pri­se within the mea­ning of Artic­le 3 of the Annex to Recom­men­da­ti­on 2003/361/ which is not con­side­red to be a microen­ter­pri­se or small enter­pri­se and which is ent­ru­sted with the manu­fac­tu­re or design of a con­nec­ted pro­duct or the pro­vi­si­on of a con­nec­ted ser­vice. In such cases, the under­ta­king that has award­ed the manu­fac­tu­ring or design con­tract to a microen­ter­pri­se or small enter­pri­se shall be able to com­pen­sa­te the con­trac­tor appro­pria­te­ly. Howe­ver, a microen­ter­pri­se or small enter­pri­se may be sub­ject to the requi­re­ments of this Regu­la­ti­on as a data con­trol­ler if it is not the manu­fac­tu­rer of the con­nec­ted pro­duct or a pro­vi­der of con­nec­ted ser­vices. A tran­si­tio­nal peri­od should app­ly to a com­pa­ny that has been clas­si­fi­ed as a medi­um-sized enter­pri­se for less than one year and to con­nec­ted pro­ducts pla­ced on the mar­ket by a medi­um-sized enter­pri­se less than one year ago. That one-year peri­od allo­ws a medi­um-sized enter­pri­se to adapt and prepa­re befo­re being expo­sed to com­pe­ti­ti­on on the ser­vices mar­ket for the con­nec­ted pro­ducts it manu­fac­tures on the basis of access rights under this Regu­la­ti­on. That tran­si­tio­nal peri­od shall not app­ly whe­re such a medi­um-sized enter­pri­se has a part­ner under­ta­king or an asso­cia­ted under­ta­king which is not a microen­ter­pri­se or a small enter­pri­se, or whe­re such a medi­um-sized enter­pri­se has been ent­ru­sted with the manu­fac­tu­re or design of a con­nec­ted pro­duct or the pro­vi­si­on of a con­nec­ted service.
(2) Con­trac­tu­al clau­ses which, to the detri­ment of the user, exclude the appli­ca­ti­on of the user’s rights under this chap­ter, devia­te from them or modi­fy the effect of the­se rights are not bin­ding on the user.

Chap­ter III Obli­ga­ti­ons of data hol­ders who are obli­ged to pro­vi­de data under Uni­on law

Artic­le 8 Con­di­ti­ons under which data hol­ders pro­vi­de data to data recipients
(1) Whe­re, in the con­text of busi­ness-to-busi­ness rela­ti­on­ships, a data con­trol­ler is obli­ged to pro­vi­de data to a data reci­pi­ent in accordance with Artic­le 5 or other appli­ca­ble Uni­on law or natio­nal law adopted in accordance with Uni­on law, it shall agree with a data reci­pi­ent on the arran­ge­ments for the pro­vi­si­on of the data and shall pro­vi­de them on fair, rea­sonable and non-dis­cri­mi­na­to­ry terms and in a trans­pa­rent man­ner in accordance with this Chap­ter and Chap­ter IV.
(42) Taking into account the varie­ty of con­nec­ted pro­ducts that gene­ra­te dif­fe­rent types, volu­mes and fre­quen­ci­es of data, which pre­sent dif­fe­rent data and cyber­se­cu­ri­ty risks and eco­no­mic oppor­tu­ni­ties of dif­fe­rent value, and in order to ensu­re con­si­sten­cy of data-sha­ring prac­ti­ces in the inter­nal mar­ket, inclu­ding across sec­tors, and to pro­mo­te and advan­ce fair data sha­ring prac­ti­ces even in tho­se are­as whe­re such a right of access to data is not pro­vi­ded for, this Regu­la­ti­on lays down hori­zon­tal rules on the orga­nizati­on of access to data in all cases whe­re a data con­trol­ler is obli­ged to pro­vi­de data to a data reci­pi­ent under Uni­on law or natio­nal law adopted in accordance with Uni­on law. Such access should be based on fair, rea­sonable, non-dis­cri­mi­na­to­ry and trans­pa­rent con­di­ti­ons. The­se gene­ral access rules do not app­ly to data pro­vi­si­on obli­ga­ti­ons under Regu­la­ti­on (EU) 2016/679. Vol­un­t­a­ry data sha­ring remains unaf­fec­ted by the­se rules. The non-bin­ding model con­trac­tu­al clau­ses for data sha­ring bet­ween com­pa­nies, which the Com­mis­si­on will deve­lop and recom­mend, can help the par­ties to con­clude con­tracts that con­tain fair, rea­sonable and non-dis­cri­mi­na­to­ry con­di­ti­ons and are to be imple­men­ted in a trans­pa­rent man­ner. The con­clu­si­on of con­tracts that may include the non-bin­ding model con­trac­tu­al clau­ses should not imply that the right to trans­fer data to third par­ties is in any way lin­ked to the exi­stence of such a con­tract. Should the par­ties – even with the assi­stance of dis­pu­te reso­lu­ti­on bodies – not be able to con­clude a con­tract on the trans­fer of data, the right to trans­fer data to third par­ties is enforceable befo­re natio­nal courts.
(45) Agree­ments for the pro­vi­si­on of data con­clu­ded in the con­text of busi­ness-to-busi­ness rela­ti­on­ships should not distin­gu­ish bet­ween simi­lar cate­go­ries of data reci­pi­en­ts, whe­ther they are lar­ge com­pa­nies or SMEs. To com­pen­sa­te for the lack of infor­ma­ti­on on the con­di­ti­ons con­tai­ned in dif­fe­rent con­tracts, which makes it dif­fi­cult for the data reci­pi­ent to assess whe­ther the con­di­ti­ons for the pro­vi­si­on of the data are non-dis­cri­mi­na­to­ry, it should be the respon­si­bi­li­ty of data hol­ders to pro­ve that a con­trac­tu­al term is non-dis­cri­mi­na­to­ry. The­re is no unlawful dis­cri­mi­na­ti­on if the data con­trol­ler pro­vi­des for dif­fe­rent con­trac­tu­al clau­ses for the pro­vi­si­on of data, pro­vi­ded that tho­se dif­fe­ren­ces are justi­fi­ed on objec­ti­ve grounds. The­se obli­ga­ti­ons app­ly wit­hout pre­ju­di­ce to Regu­la­ti­on (EU) 2016/679.
(2) A con­trac­tu­al term rela­ting to data access and use or to lia­bi­li­ty and reme­dies for breach or ter­mi­na­ti­on of data-rela­ted obli­ga­ti­ons shall not be bin­ding if it con­sti­tu­tes an unfair con­tract term within the mea­ning of Artic­le 13 or if it exclu­des, dero­ga­tes from or modi­fi­es the effect of the exer­cise of the user’s rights under Chap­ter II to the detri­ment of the user. 
(3) A data con­trol­ler shall not dis­cri­mi­na­te bet­ween simi­lar cate­go­ries of data reci­pi­en­ts, inclu­ding part­ner com­pa­nies or affi­lia­tes, with regard to the moda­li­ties of the pro­vi­si­on of data. Whe­re a data reci­pi­ent con­siders that the con­di­ti­ons under which data are pro­vi­ded to it are dis­cri­mi­na­to­ry, the data con­trol­ler shall, upon the data recipient’s rea­so­ned request, prompt­ly pro­vi­de the data reci­pi­ent with infor­ma­ti­on demon­st­ra­ting that the­re is no discrimination. 
(4) Data may only be pro­vi­ded to a data reci­pi­ent by the data con­trol­ler – even exclu­si­ve­ly – if the user has reque­sted this in accordance with Chap­ter II. 
(5) Data con­trol­lers and data reci­pi­en­ts shall not be requi­red to pro­vi­de infor­ma­ti­on bey­ond what is neces­sa­ry to veri­fy com­pli­ance with the model con­trac­tu­al clau­ses agreed for the pro­vi­si­on of data or com­pli­ance with their obli­ga­ti­ons under this Regu­la­ti­on or other appli­ca­ble Uni­on law or natio­nal law adopted in accordance with Uni­on law. 
(6) An obli­ga­ti­on to pro­vi­de data to a data reci­pi­ent does not impo­se an obli­ga­ti­on to dis­c­lo­se trade secrets, unless other­wi­se pro­vi­ded for in Uni­on law, inclu­ding Artic­le 4(6) and Artic­le 5(9) of this Regu­la­ti­on, or in natio­nal law adopted in accordance with Uni­on law.
Artic­le 9 Con­side­ra­ti­on for the pro­vi­si­on of data
(46) In order to encou­ra­ge fur­ther invest­ment in the gene­ra­ti­on and pro­vi­si­on of valuable data, inclu­ding invest­ment in rele­vant tech­ni­cal tools, while avo­i­ding dis­pro­por­tio­na­te bur­dens on access to and use of data, which would ren­der data sha­ring eco­no­mic­al­ly unvia­ble, this Regu­la­ti­on lays down the prin­ci­ple that data hol­ders may request ade­qua­te com­pen­sa­ti­on whe­re they are obli­ged under Uni­on law or natio­nal law adopted in accordance with Uni­on law to pro­vi­de data to a data reci­pi­ent in the con­text of busi­ness-to-busi­ness rela­ti­on­ships. This con­side­ra­ti­on should not be under­s­tood as payment for the data its­elf. The Com­mis­si­on should adopt gui­de­lines on the basis of which an appro­pria­te con­side­ra­ti­on in the data eco­no­my can be calculated.
(47) First, fair com­pen­sa­ti­on for com­ply­ing with the obli­ga­ti­on under Uni­on or natio­nal law adopted in accordance with Uni­on law to com­ply with a data access request may include com­pen­sa­ti­on for the costs asso­cia­ted with pro­vi­ding the data. The­se may be tech­ni­cal costs, such as costs neces­sa­ry for the repro­duc­tion, elec­tro­nic dis­se­mi­na­ti­on and sto­rage of data, but not the costs of data coll­ec­tion or pro­duc­tion. Tech­ni­cal costs could also include the costs of pro­ce­s­sing requi­red in advan­ce of making the data available, inclu­ding the costs asso­cia­ted with for­mat­ting the data. Costs asso­cia­ted with pro­vi­ding the data may also include the costs of faci­li­ta­ting spe­ci­fic data sha­ring requests. Depen­ding on the amount of data and the agree­ments made for the pro­vi­si­on of the data, the­se costs may also vary. Long-term agree­ments bet­ween data owners and data reci­pi­en­ts, e.g. via a sub­scrip­ti­on model or the use of smart con­tracts, may result in lower costs in the con­text of regu­lar or repea­ted tran­sac­tions in a busi­ness rela­ti­on­ship. Costs rela­ted to the pro­vi­si­on of data eit­her rela­te to a spe­ci­fic request or cover mul­ti­ple requests. In the lat­ter case, the costs of pro­vi­ding the data should not be bor­ne in full by a sin­gle data reci­pi­ent. Second­ly, the appro­pria­te con­side­ra­ti­on may also include a mar­gin, except in rela­ti­on to SMEs and non-pro­fit rese­arch orga­nizati­ons. The mar­gin may vary depen­ding on fac­tors rela­ted to the data its­elf, such as the amount, for­mat or type of data. It may take into account the cost of coll­ec­ting the data. The­r­e­fo­re, the mar­gin may be lower if the data owner has coll­ec­ted the data for its own busi­ness wit­hout making signi­fi­cant invest­ments, or it may be hig­her if a signi­fi­cant invest­ment is requi­red to coll­ect the data for the pur­po­ses of the data owner’s busi­ness. In cases whe­re the use of the data by the data reci­pi­ent does not affect the data controller’s own acti­vi­ties, the mar­gin may be limi­t­ed or even exclu­ded. In addi­ti­on, whe­re the data is co-gene­ra­ted by a con­nec­ted pro­duct owned, ren­ted or lea­sed by the user, the con­side­ra­ti­on could be com­pa­ra­tively lower than in other cases whe­re the data is gene­ra­ted by the data owner, for exam­p­le in the pro­vi­si­on of a con­nec­ted service.
(48) Inter­ven­ti­on is not requi­red if data is shared bet­ween lar­ge com­pa­nies or if the data owner is a small or medi­um-sized enter­pri­se and the data reci­pi­ent is a lar­ge com­pa­ny. In the­se cases, it is assu­med that the com­pa­nies are able to nego­tia­te a con­side­ra­ti­on within rea­sonable and non-dis­cri­mi­na­to­ry limits.
(1) Any con­side­ra­ti­on agreed bet­ween a data con­trol­ler and a data reci­pi­ent for the pro­vi­si­on of data in the con­text of busi­ness rela­ti­on­ships bet­ween com­pa­nies must be non-dis­cri­mi­na­to­ry and rea­sonable, and may include a margin. 
(2) When agre­e­ing on a con­side­ra­ti­on, the data con­trol­ler and the data reci­pi­ent shall take into account the fol­lo­wing in par­ti­cu­lar:
a) costs incur­red for the pro­vi­si­on of the data, inclu­ding in par­ti­cu­lar the neces­sa­ry costs for for­mat­ting the data, dis­se­mi­na­ti­on by elec­tro­nic means and storage;
b) whe­re appli­ca­ble, invest­ments in the coll­ec­tion and gene­ra­ti­on of data, taking into account whe­ther other par­ties have con­tri­bu­ted to the pro­cu­re­ment, gene­ra­ti­on or coll­ec­tion of the data concerned.
(3) The con­side­ra­ti­on refer­red to in para­graph 1 may also depend on the scope, for­mat and natu­re of the data. 
(4) Whe­re the data reci­pi­ent is an SME or a non-pro­fit rese­arch orga­nizati­on and the data reci­pi­ent con­cer­ned has no part­ner under­ta­kings or affi­lia­ted under­ta­kings that are not SMEs, any con­side­ra­ti­on shall not exce­ed the costs listed in para­graph 2(a).
(49) In order to pro­tect SMEs from exce­s­si­ve eco­no­mic bur­dens that would make it exce­s­si­ve­ly dif­fi­cult for them to deve­lop and ope­ra­te inno­va­ti­ve busi­ness models, the appro­pria­te con­side­ra­ti­on to be bor­ne by them for the pro­vi­si­on of data should not exce­ed the costs direct­ly asso­cia­ted with the pro­vi­si­on of the data. Costs direct­ly rela­ted to the pro­vi­si­on are tho­se costs that are attri­bu­ta­ble to the indi­vi­du­al data access requests, taking into account that the data owner has to set up the neces­sa­ry tech­ni­cal inter­faces or the neces­sa­ry soft­ware and net­work con­nec­tion on a per­ma­nent basis. The same rule should app­ly to non-pro­fit rese­arch institutions.
(5) The Com­mis­si­on shall adopt gui­de­lines for the cal­cu­la­ti­on of appro­pria­te com­pen­sa­ti­on taking into account the advice of the Euro­pean Data Inno­va­ti­on Board (EDIB) refer­red to in Artic­le 42. 
(6) This Artic­le shall not pre­vent Uni­on law or natio­nal law adopted in accordance with Uni­on law from exclu­ding or pro­vi­ding for a les­ser con­side­ra­ti­on for the pro­vi­si­on of data. 
(7) The data con­trol­ler shall pro­vi­de the data reci­pi­ent with infor­ma­ti­on set­ting out the basis for the cal­cu­la­ti­on of the con­side­ra­ti­on in suf­fi­ci­ent detail to enable the data reci­pi­ent to assess whe­ther the requi­re­ments of para­graphs 1 to 4 are met. 
(51) Trans­pa­ren­cy is an important prin­ci­ple to ensu­re that the con­side­ra­ti­on reque­sted from a data hol­der is rea­sonable or, whe­re the data reci­pi­ent is an SME or a non-pro­fit rese­arch orga­nizati­on, that the con­side­ra­ti­on does not exce­ed the costs direct­ly rela­ted to the pro­vi­si­on of the data to the data reci­pi­ent and attri­bu­ta­ble to the indi­vi­du­al request. In order to enable data reci­pi­en­ts to assess and veri­fy whe­ther the con­side­ra­ti­on com­plies with the requi­re­ments of this Regu­la­ti­on, the data hol­der should pro­vi­de the data reci­pi­ent with suf­fi­ci­ent­ly detail­ed infor­ma­ti­on for the cal­cu­la­ti­on of the consideration.
Artic­le 10 Dis­pu­te resolution
(52) Alter­na­ti­ve means of resol­ving dome­stic and cross-bor­der dis­pu­tes rela­ted to the pro­vi­si­on of data should be available to data hol­ders and data reci­pi­en­ts ali­ke, so that trust in data sha­ring is streng­the­ned. If the par­ties can­not agree on fair, rea­sonable and non-dis­cri­mi­na­to­ry terms for the pro­vi­si­on of data, dis­pu­te sett­le­ment bodies should offer the par­ties a simp­le, quick and inex­pen­si­ve solu­ti­on. While this Regu­la­ti­on only lays down the con­di­ti­ons that dis­pu­te reso­lu­ti­on enti­ties must meet in order to be cer­ti­fi­ed, Mem­ber Sta­tes are free to adopt spe­ci­fic rules on the cer­ti­fi­ca­ti­on pro­ce­du­re, inclu­ding the expiry or with­dra­wal of cer­ti­fi­ca­ti­on. The pro­vi­si­ons on dis­pu­te reso­lu­ti­on con­tai­ned in this Regu­la­ti­on should not obli­ge Mem­ber Sta­tes to set up dis­pu­te reso­lu­ti­on entities.
(55) In order to ensu­re the uni­form appli­ca­ti­on of this Regu­la­ti­on, dis­pu­te sett­le­ment bodies should take into account the non-bin­ding stan­dard con­trac­tu­al clau­ses to be deve­lo­ped and recom­men­ded by the Com­mis­si­on, as well as Uni­on or natio­nal law estab­li­shing data-sha­ring obli­ga­ti­ons or gui­dance from the rele­vant spe­cia­li­zed aut­ho­ri­ties on the appli­ca­ti­on of that law.
(1) Users, data hol­ders and data reci­pi­en­ts shall have access to a dis­pu­te reso­lu­ti­on body cer­ti­fi­ed in accordance with para­graph 5 of this Artic­le for the reso­lu­ti­on of dis­pu­tes refer­red to in Artic­le 4(3) and (9) and Artic­le 5(12) and dis­pu­tes rela­ting to the fair, rea­sonable and non-dis­cri­mi­na­to­ry con­di­ti­ons for the pro­vi­si­on of data and the trans­pa­rent man­ner in which data are pro­vi­ded in accordance with this Chap­ter and Chap­ter IV. 
(53) The dis­pu­te reso­lu­ti­on pro­ce­du­re under this Regu­la­ti­on is a vol­un­t­a­ry pro­ce­du­re that allo­ws users, data con­trol­lers and data reci­pi­en­ts to agree to refer their dis­pu­tes to dis­pu­te reso­lu­ti­on bodies. The­r­e­fo­re, the par­ties should be free to turn to a dis­pu­te reso­lu­ti­on body of their choice, whe­ther insi­de or out­side the Mem­ber Sta­tes whe­re tho­se par­ties are established.
(2) The dis­pu­te reso­lu­ti­on bodies shall inform the par­ties con­cer­ned of the fees or the methods used to deter­mi­ne the fees befo­re the­se par­ties request a decision. 
(3) For dis­pu­tes refer­red to a dis­pu­te reso­lu­ti­on enti­ty pur­su­ant to Artic­le 4(3), whe­re the dis­pu­te reso­lu­ti­on enti­ty resol­ves a dis­pu­te in favor of the user or data reci­pi­ent, the data hol­der shall bear all fees char­ged by the dis­pu­te reso­lu­ti­on enti­ty and reim­bur­se the user or data reci­pi­ent con­cer­ned for any other rea­sonable expen­ses incur­red by the user or data reci­pi­ent in con­nec­tion with the dis­pu­te reso­lu­ti­on. If the dis­pu­te reso­lu­ti­on body deci­des a dis­pu­te in favor of the data con­trol­ler, the user or data reci­pi­ent shall not be obli­ged to reim­bur­se any fees or other costs paid or paya­ble by the data con­trol­ler in con­nec­tion with the dis­pu­te reso­lu­ti­on, unless the dis­pu­te reso­lu­ti­on body deter­mi­nes that the user or data reci­pi­ent has acted in mani­fest bad faith. 
(4) Cus­to­mers and pro­vi­ders of data pro­ce­s­sing ser­vices shall have access to a dis­pu­te reso­lu­ti­on body aut­ho­ri­zed in accordance with para­graph 5 of this Artic­le to resol­ve dis­pu­tes rela­ting to brea­ches of the rights of cus­to­mers and the obli­ga­ti­ons of pro­vi­ders of data pro­ce­s­sing ser­vices in accordance with Artic­les 23 to 31. 
(5) The Mem­ber Sta­te in which the dis­pu­te reso­lu­ti­on enti­ty is estab­lished shall accre­dit that enti­ty at its request after it has demon­stra­ted that it meets all of the fol­lo­wing con­di­ti­ons:
a) It is impar­ti­al and inde­pen­dent and makes its decis­i­ons accor­ding to clear, non-dis­cri­mi­na­to­ry and fair pro­ce­du­ral rules;
b) it has the neces­sa­ry exper­ti­se, in par­ti­cu­lar with regard to fair, rea­sonable and non-dis­cri­mi­na­to­ry terms and con­di­ti­ons, inclu­ding con­side­ra­ti­on, on the trans­pa­rent pro­vi­si­on of data that enables it to set tho­se terms and con­di­ti­ons effectively;
c) it is easi­ly acce­s­si­ble via elec­tro­nic means of communication;
d) it is able to adopt its decis­i­ons quick­ly, effi­ci­ent­ly and cost-effec­tively in at least one offi­ci­al lan­guage of the Union.
(6) Mem­ber Sta­tes shall noti­fy the Com­mis­si­on of the dis­pu­te sett­le­ment bodies appro­ved in accordance with para­graph 5. The Com­mis­si­on shall publish and keep up to date a list of the­se bodies on a dedi­ca­ted website. 
(7) A dis­pu­te reso­lu­ti­on enti­ty shall refu­se to pro­cess a dis­pu­te reso­lu­ti­on request that has alre­a­dy been sub­mit­ted to ano­ther dis­pu­te reso­lu­ti­on enti­ty or to a court of a Mem­ber State. 
(54) In order to avo­id the need to refer the same dis­pu­te to two or more dis­pu­te reso­lu­ti­on enti­ties, in par­ti­cu­lar in a cross-bor­der situa­ti­on, it should be pos­si­ble for a request for dis­pu­te reso­lu­ti­on to be rejec­ted by a dis­pu­te reso­lu­ti­on enti­ty if it has alre­a­dy been sub­mit­ted to ano­ther dis­pu­te reso­lu­ti­on enti­ty or to a court of a Mem­ber State.
(8) A dis­pu­te reso­lu­ti­on body shall offer the par­ties the oppor­tu­ni­ty to com­ment within a rea­sonable peri­od of time on the mat­ters on which the­se par­ties have tur­ned to the body in que­sti­on. In this con­text, each par­ty shall be pro­vi­ded with the writ­ten sub­mis­si­ons of the other par­ty and any state­ments by experts. The par­ties are given the oppor­tu­ni­ty to com­ment on the­se writ­ten sub­mis­si­ons and statements. 
(9) A dis­pu­te reso­lu­ti­on body shall deci­de on a mat­ter refer­red to it no later than 90 days after rece­ipt of a request in accordance with para­graphs 1 to 4. This decis­i­on shall be made in wri­ting or on a dura­ble medi­um and shall be accom­pa­nied by a state­ment of reasons. 
(10) The dis­pu­te reso­lu­ti­on bodies shall draw up and publish annu­al acti­vi­ty reports. The­se annu­al reports must include the fol­lo­wing gene­ral infor­ma­ti­on in par­ti­cu­lar:
a) a com­pi­la­ti­on of the results of disputes;
b) the avera­ge time requi­red to resol­ve disputes;
c) the most com­mon rea­sons for disputes.
(11) In order to faci­li­ta­te the exch­an­ge of infor­ma­ti­on and best prac­ti­ces, a dis­pu­te sett­le­ment enti­ty may deci­de to include in the report refer­red to in para­graph 10 recom­men­da­ti­ons on how to avo­id or reme­dy problems. 
(12) The decis­i­on of a dis­pu­te reso­lu­ti­on body is only bin­ding for the par­ties if the par­ties have express­ly agreed to its bin­ding natu­re befo­re the dis­pu­te reso­lu­ti­on pro­ce­du­re begins. 
(13) This Artic­le shall not affect the right of the par­ties to bring an effec­ti­ve reme­dy befo­re a court of a Mem­ber State. 
(56) The par­ties to a dis­pu­te sett­le­ment pro­ce­du­re should not be pre­ven­ted from exer­cis­ing their fun­da­men­tal rights to an effec­ti­ve reme­dy and to a fair tri­al. The­r­e­fo­re, the decis­i­on to refer a dis­pu­te to a dis­pu­te reso­lu­ti­on enti­ty should not depri­ve tho­se par­ties of the right to appeal to a court of a Mem­ber Sta­te. The dis­pu­te sett­le­ment bodies should make annu­al acti­vi­ty reports publicly available.
Artic­le 11 Tech­ni­cal pro­tec­tion mea­su­res against unaut­ho­ri­zed use or dis­clo­sure of data
(1) A data con­trol­ler may app­ly appro­pria­te tech­ni­cal pro­tec­tion mea­su­res, inclu­ding smart con­tracts and encryp­ti­on, to pre­vent unaut­ho­ri­zed access to data, inclu­ding meta­da­ta, and to ensu­re com­pli­ance with Artic­les 5, 6, 8 and 9 and the model con­trac­tu­al clau­ses agreed for the pro­vi­si­on of data. Such tech­ni­cal pro­tec­tion mea­su­res shall not dis­cri­mi­na­te bet­ween data reci­pi­en­ts or pre­vent users from exer­cis­ing their right to obtain a copy of, retrie­ve, use or access the data or to pro­vi­de data to third par­ties in accordance with Artic­le 5, or pre­vent third par­ties from exer­cis­ing their rights under Uni­on or natio­nal law adopted in accordance with Uni­on law. Users, third par­ties and data reci­pi­en­ts may modi­fy or remo­ve such tech­ni­cal pro­tec­tion mea­su­res only with the con­sent of the data controller. 
(2) In the cir­cum­stances refer­red to in para­graph 3, the third par­ty or the data reci­pi­ent shall com­ply wit­hout undue delay with the requests of the data con­trol­ler and, whe­re appli­ca­ble, the trade secret hol­der – if they are not the same per­son – or the user:
a) dele­te the data pro­vi­ded by the data con­trol­ler and any copies thereof;
b) to cea­se the pro­duc­tion, offe­ring, mar­ke­ting or use of goods, deri­ved data or ser­vices based on the know­ledge obtai­ned with the data or the import, export or sto­rage of inf­rin­ging goods in this sen­se and to destroy all inf­rin­ging goods if the­re is a serious risk that the unlawful use of such data will cau­se sub­stan­ti­al dama­ge to the data con­trol­ler, the trade secret hol­der or the user, or unless such a mea­su­re would be dis­pro­por­tio­na­te to the inte­rests of the data con­trol­ler, the trade secret hol­der or the user;
c) inform the user of the unaut­ho­ri­zed use or dis­clo­sure of the data and of the mea­su­res taken to pre­vent the unaut­ho­ri­zed use or dis­clo­sure of the data;
d) com­pen­sa­te the par­ty that has been har­med by the misu­se or dis­clo­sure of such unlawful­ly acce­s­sed or used data.
(3) Para­graph 2 shall app­ly if a third par­ty or a data reci­pi­ent
a) has given fal­se infor­ma­ti­on to a data owner, used decep­ti­ve or coer­ci­ve means or abu­sed gaps in the tech­ni­cal infras­truc­tu­re in place to pro­tect the data in order to obtain the data,
b) used the data pro­vi­ded for unaut­ho­ri­zed pur­po­ses, inclu­ding the deve­lo­p­ment of a com­pe­ting con­nec­ted pro­duct within the mea­ning of Artic­le 6(2)(e),
c) has unlawful­ly dis­c­lo­sed data to ano­ther party,
d) has not main­tai­ned the tech­ni­cal and orga­nizatio­nal mea­su­res agreed in accordance with Artic­le 5(9), or
e) has modi­fi­ed or remo­ved the tech­ni­cal pro­tec­tion mea­su­res applied by the data con­trol­ler pur­su­ant to para­graph 1 of this Artic­le wit­hout the con­sent of the data controller.
(4) Para­graph 2 shall also app­ly if a user modi­fi­es or remo­ves the tech­ni­cal pro­tec­tion mea­su­res applied by the data con­trol­ler or fails to main­tain the tech­ni­cal and orga­nizatio­nal mea­su­res taken by the user in agree­ment with the data con­trol­ler or, if they are not the same per­son, the trade secret hol­der to pro­tect trade secrets, as well as to any other par­ty recei­ving the data from the user in breach of this Regulation. 
(5) If the data reci­pi­ent has inf­rin­ged Artic­le 6(2)(a) or (b), users shall have the same rights as data con­trol­lers under para­graph 2 of this Article.
Artic­le 12 Scope of the obli­ga­ti­ons of data con­trol­lers requi­red to pro­vi­de data under Uni­on law
(1) This Chap­ter applies whe­re a data con­trol­ler is obli­ged to pro­vi­de data to a data reci­pi­ent in the con­text of busi­ness-to-busi­ness rela­ti­on­ships under Artic­le 5 or under appli­ca­ble Uni­on law or natio­nal law adopted in accordance with Uni­on law. 
(2) Any con­trac­tu­al clau­se in a data trans­fer agree­ment which, to the detri­ment of a par­ty or, whe­re appli­ca­ble, to the detri­ment of the user, exclu­des the appli­ca­ti­on of this chap­ter, devia­tes from it or modi­fi­es its effect shall not be bin­ding on that party.

Chap­ter IV Unfair con­tract terms in rela­ti­on to data access and use bet­ween companies

Artic­le 13 Unfair con­tract terms uni­la­te­ral­ly impo­sed on ano­ther undertaking
(28) Uni­on con­su­mer law, in par­ti­cu­lar Direc­ti­ves 93/13/EEC and 2005/29/, applies to con­tracts bet­ween a data con­trol­ler and a con­su­mer as a user of a con­nec­ted pro­duct or ser­vice that gene­ra­tes data, in order to ensu­re that a con­su­mer is not sub­ject to unfair con­tract terms. For the pur­po­ses of this Regu­la­ti­on, unfair con­tract terms uni­la­te­ral­ly impo­sed on an under­ta­king should not be bin­ding on that undertaking.
(43) On the basis of the prin­ci­ple of con­trac­tu­al free­dom, the par­ties should be free to nego­tia­te the pre­cise con­di­ti­ons for the pro­vi­si­on of data in their con­tracts within the frame­work of the gene­ral access rules for the pro­vi­si­on of data. The terms of such con­tracts could also cover tech­ni­cal and orga­nizatio­nal mea­su­res, inclu­ding in rela­ti­on to data security.
(44) In order to ensu­re that the con­di­ti­ons for man­da­to­ry data access are fair for both par­ties, the gene­ral rules on data access rights should refer to the rule on the avo­id­ance of unfair con­tract terms.
(58) If one par­ty is in a stron­ger nego­tia­ting posi­ti­on, the­re is a risk that it could exploit this posi­ti­on to the detri­ment of the other par­ty when nego­tia­ting access to data, with the result that access to data is less com­mer­ci­al­ly via­ble and some­ti­mes unsu­s­tainable. Such con­trac­tu­al imba­lan­ces are detri­men­tal to all com­pa­nies who are not real­ly in a posi­ti­on to nego­tia­te the terms of access to data and who may have no choice but to accept non-nego­tia­ble con­trac­tu­al terms. The­r­e­fo­re, unfair con­tract terms rela­ting to data access and use or lia­bi­li­ty and reme­dies for breach or ter­mi­na­ti­on of data-rela­ted obli­ga­ti­ons should not be bin­ding on com­pa­nies whe­re the­se terms have been uni­la­te­ral­ly impo­sed on tho­se companies.
(1) Con­trac­tu­al clau­ses rela­ting to data access and use or lia­bi­li­ty and reme­dies for breach or ter­mi­na­ti­on of data-rela­ted obli­ga­ti­ons that one com­pa­ny uni­la­te­ral­ly impo­ses on ano­ther com­pa­ny are not bin­ding on the lat­ter com­pa­ny if they are unfair. 
(59) The rules on con­trac­tu­al terms should take into account the prin­ci­ple of con­trac­tu­al free­dom as an essen­ti­al con­cept in busi­ness rela­ti­on­ships bet­ween com­pa­nies. The­r­e­fo­re, not all con­tract terms should be sub­ject to an unfair­ness test, but only tho­se terms that are uni­la­te­ral­ly impo­sed. This con­cerns situa­tions whe­re the­re is no room for nego­tia­ti­on, whe­re one par­ty intro­du­ces a cer­tain con­trac­tu­al term and the other com­pa­ny can­not influence the con­tent of this term despi­te attempts to nego­tia­te. Con­trac­tu­al clau­ses that are mere­ly intro­du­ced by one par­ty and accept­ed by the other com­pa­ny, or clau­ses that are nego­tia­ted bet­ween the par­ties and sub­se­quent­ly agreed in a modi­fi­ed form, should not be con­side­red uni­la­te­ral­ly imposed.
(60) In addi­ti­on, the rules on unfair con­tract terms should only app­ly to tho­se parts of a con­tract that rela­te to the pro­vi­si­on of data, name­ly con­trac­tu­al terms on data access and use and lia­bi­li­ty or reme­dies for breach and ter­mi­na­ti­on of data-rela­ted obli­ga­ti­ons. Other parts of the same con­tract which are not rela­ted to the pro­vi­si­on of data should not be sub­ject to the unfair­ness test set out in this Regulation.
(61) Cri­te­ria for iden­ti­fy­ing unfair con­tract terms should only be applied to over­broad con­tract terms whe­re a stron­ger bar­gai­ning posi­ti­on has been abu­sed. The vast majo­ri­ty of con­tract terms which are eco­no­mic­al­ly more favorable to one par­ty than to the other, inclu­ding tho­se which are com­mon in con­tracts bet­ween under­ta­kings, are a nor­mal expres­si­on of the prin­ci­ple of free­dom of con­tract and con­ti­n­ue to app­ly. For the pur­po­ses of this Regu­la­ti­on, a gross devia­ti­on from good com­mer­cial prac­ti­ce would mean, inter alia, that the par­ty on whom the con­di­ti­on has been uni­la­te­ral­ly impo­sed is objec­tively pre­ju­di­ced in its abili­ty to pro­tect its legi­ti­ma­te com­mer­cial inte­rest in the data concerned.
(2) If con­trac­tu­al clau­ses com­ply with man­da­to­ry pro­vi­si­ons of Uni­on law or, in the absence of con­trac­tu­al clau­ses gover­ning the mat­ter, with appli­ca­ble pro­vi­si­ons of Uni­on law, they shall not be con­side­red unfair.
(3) Con­trac­tu­al clau­ses are unfair if their appli­ca­ti­on con­sti­tu­tes a gross devia­ti­on from good busi­ness prac­ti­ce in data access and use or vio­la­tes the prin­ci­ple of good faith. 
(4) In par­ti­cu­lar, a con­trac­tu­al term shall be dee­med unfair within the mea­ning of para­graph 3 if it has the fol­lo­wing pur­po­se or effect: 
(62) In order to ensu­re legal cer­tain­ty, this Regu­la­ti­on estab­lishes a list of terms which are always pre­su­med to be unfair and a list of terms which are pre­su­med to be unfair. In the lat­ter case, the com­pa­ny impo­sing the con­tract term should be able to rebut the pre­sump­ti­on of unfair­ness by pro­ving that a con­tract term listed in this Regu­la­ti­on is not unfair in the spe­ci­fic case. Whe­re a con­trac­tu­al term is not inclu­ded in the list of terms which are always pre­su­med to be unfair or which are pre­su­med to be unfair, the gene­ral pro­vi­si­on on unfair­ness applies. In this con­text, the con­tract terms listed as unfair in this Regu­la­ti­on should ser­ve as a bench­mark for the inter­pre­ta­ti­on of the gene­ral unfair­ness pro­vi­si­on. Final­ly, non-bin­ding stan­dard con­trac­tu­al clau­ses drawn up and recom­men­ded by the Com­mis­si­on for con­tracts on the trans­fer of data bet­ween under­ta­kings may also be hel­pful for com­mer­cial under­ta­kings when nego­tia­ting con­tracts. If a con­trac­tu­al term is declared unfair, the con­tract in que­sti­on should con­ti­n­ue to app­ly wit­hout that term, unless the unfair term is not severa­ble from the other con­trac­tu­al terms.
a) the exclu­si­on or limi­ta­ti­on of the lia­bi­li­ty of the par­ty that has uni­la­te­ral­ly impo­sed the clau­se for inten­tio­nal or gross­ly negli­gent acts;
b) the exclu­si­on of the reme­dies available to the par­ty on whom the clau­se has been uni­la­te­ral­ly impo­sed in the event of non-per­for­mance of con­trac­tu­al obli­ga­ti­ons or the exclu­si­on of the lia­bi­li­ty of the par­ty who has uni­la­te­ral­ly impo­sed the clau­se in the event of a breach of tho­se obligations;
c) the exclu­si­ve right of the par­ty that has uni­la­te­ral­ly impo­sed the clau­se to deter­mi­ne whe­ther the data sup­plied is in con­for­mi­ty with the con­tract or to inter­pret con­trac­tu­al clauses.
(5) A con­trac­tu­al term shall be dee­med unfair within the mea­ning of para­graph 3 if it has the fol­lo­wing pur­po­se or effect:
a) an unre­a­sonable limi­ta­ti­on of reme­dies for non-per­for­mance of con­trac­tu­al obli­ga­ti­ons or of lia­bi­li­ty for breach of such obli­ga­ti­ons or an exten­si­on of the lia­bi­li­ty of the com­pa­ny on which the clau­se was uni­la­te­ral­ly imposed;
b) the right of the par­ty that has uni­la­te­ral­ly impo­sed the clau­se to access and use data of the other par­ty in a way that signi­fi­cant­ly harms the legi­ti­ma­te inte­rests of the other par­ty, in par­ti­cu­lar if such data con­ta­ins sen­si­ti­ve com­mer­cial infor­ma­ti­on or is pro­tec­ted by trade secret or intellec­tu­al pro­per­ty rights;
c) the pre­ven­ti­on of the par­ty on which the clau­se was uni­la­te­ral­ly impo­sed from using the data pro­vi­ded or gene­ra­ted by it during the term of the con­tract or a rest­ric­tion on the use of such data to the ext­ent that such par­ty is not entit­led to use, coll­ect, access, con­trol or exploit such data in a rea­sonable manner;
d) pre­ven­ting the par­ty on whom the clau­se was uni­la­te­ral­ly impo­sed from ter­mi­na­ting the agree­ment within a rea­sonable peri­od of time;
e) the pre­ven­ti­on of the par­ty on whom the clau­se was uni­la­te­ral­ly impo­sed from obtai­ning a copy of the data pro­vi­ded or gene­ra­ted by it during the term of the con­tract or within a rea­sonable peri­od after ter­mi­na­ti­on of the contract;
f) the pos­si­bi­li­ty that the par­ty that has uni­la­te­ral­ly impo­sed the clau­se may ter­mi­na­te the con­tract with unre­a­son­ab­ly short noti­ce, taking into account any rea­li­stic pos­si­bi­li­ty for the other par­ty to switch to ano­ther com­pa­ra­ble ser­vice and the finan­cial dis­ad­van­ta­ge cau­sed by the ter­mi­na­ti­on, unless the­re are serious grounds;
g) the pos­si­bi­li­ty that the par­ty that has uni­la­te­ral­ly impo­sed the clau­se sub­stan­ti­al­ly modi­fi­es the con­trac­tual­ly agreed pri­ce or any other mate­ri­al con­di­ti­on rela­ting to the type, for­mat, qua­li­ty or quan­ti­ty of data to be dis­c­lo­sed wit­hout a valid justi­fi­ca­ti­on spe­ci­fi­ed in the con­tract, wit­hout giving the other par­ty the right to ter­mi­na­te the con­tract in the event of such modification.
Point (g) of the first sub­pa­ra­graph shall not affect clau­ses under which the par­ty which has uni­la­te­ral­ly impo­sed the clau­se reser­ves the right to uni­la­te­ral­ly modi­fy the terms of a con­tract of inde­ter­mi­na­te dura­ti­on, pro­vi­ded that the­re is a valid justi­fi­ca­ti­on spe­ci­fi­ed in that con­tract under which the par­ty which has uni­la­te­ral­ly impo­sed the clau­se is obli­ged to noti­fy the other par­ty of such inten­ded modi­fi­ca­ti­on within a rea­sonable time and the other par­ty is free to ter­mi­na­te the con­tract free of char­ge in the event of such modification. 
(6) Con­trac­tu­al clau­ses are dee­med to be uni­la­te­ral­ly impo­sed within the mea­ning of this artic­le if they are intro­du­ced by one con­trac­ting par­ty and the other con­trac­ting par­ty can­not influence their con­tent despi­te attempts to nego­tia­te them. The par­ty that intro­du­ced the con­trac­tu­al clau­se shall bear the bur­den of pro­ving that this clau­se was not uni­la­te­ral­ly impo­sed. The con­trac­ting par­ty that intro­du­ced the dis­pu­ted clau­se can­not cla­im that it is an unfair con­trac­tu­al term. 
(7) If the unfair con­trac­tu­al term is severa­ble from the other terms of the con­tract, the other con­trac­tu­al terms shall remain binding. 
(8) This Artic­le shall not app­ly to con­trac­tu­al clau­ses defi­ning the main sub­ject mat­ter of the con­tract, nor to the ade­qua­cy of the pri­ce of the data pro­vi­ded as consideration. 
(9) The par­ties to a con­tract cover­ed by para­graph 1 may not exclude the appli­ca­ti­on of this Artic­le, dero­ga­te from it or vary its effects.

Chap­ter V Pro­vi­si­on of data to public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies on grounds of excep­tio­nal necessity

(63) In cases of excep­tio­nal neces­si­ty, it may be neces­sa­ry for public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies to use exi­sting data, inclu­ding, whe­re appro­pria­te, atta­ched meta­da­ta, held by an under­ta­king in the per­for­mance of their sta­tu­to­ry duties in the public inte­rest in order to respond to public emer­gen­ci­es or other excep­tio­nal situa­tions. Excep­tio­nal need means cir­cum­stances that are unfo­re­seeable and tem­po­ra­ry, as oppo­sed to other cir­cum­stances that may be plan­ned or sche­du­led or occur regu­lar­ly or fre­quent­ly. While the term „data con­trol­ler“ does not gene­ral­ly include public bodies, it may include public under­ta­kings. Rese­arch insti­tu­ti­ons and rese­arch fun­ding bodies could also be estab­lished as public bodies or bodies gover­ned by public law. In order to limit the bur­den on busi­nesses, microen­ter­pri­ses and small enter­pri­ses should only be requi­red to pro­vi­de data to public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies whe­re such data are neces­sa­ry in cases of excep­tio­nal need to respond to a public emer­gen­cy and whe­re public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies can­not other­wi­se obtain such data in a time­ly and effec­ti­ve man­ner under equi­va­lent conditions.
Artic­le 14 Obli­ga­ti­on to pro­vi­de data due to excep­tio­nal necessity
Whe­re a public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body demon­stra­tes that the­re is an excep­tio­nal need to use cer­tain data, inclu­ding the rele­vant meta­da­ta neces­sa­ry for the inter­pre­ta­ti­on and use of tho­se data, for the per­for­mance of its legal tasks in the public inte­rest in accordance with Artic­le 15, the data hol­ders hol­ding tho­se data, being legal per­sons other than public sec­tor bodies, shall pro­vi­de tho­se data upon duly justi­fi­ed request.
(64) In the case of public emer­gen­ci­es such as public health emer­gen­ci­es, emer­gen­ci­es cau­sed by natu­ral dis­asters, inclu­ding tho­se exa­cer­ba­ted by cli­ma­te chan­ge and envi­ron­men­tal degra­da­ti­on, and man-made major dis­asters such as major cyber­se­cu­ri­ty inci­dents, the public inte­rest in the use of the data will out­weigh the inte­rest of the data hol­ders to free­ly dis­po­se of the data they hold. In such a case, data hol­ders should be obli­ged to pro­vi­de the data to public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies at their request. The exi­stence of a public emer­gen­cy should be estab­lished or declared in accordance with Uni­on or natio­nal law and on the basis of the rele­vant pro­ce­du­res, inclu­ding tho­se of the rele­vant inter­na­tio­nal orga­nizati­ons. In such cases, the public sec­tor body should demon­stra­te that the data sub­ject to the request could not be obtai­ned other­wi­se in a time­ly and effec­ti­ve man­ner and under equi­va­lent con­di­ti­ons, for exam­p­le through the vol­un­t­a­ry pro­vi­si­on of data by ano­ther enti­ty or sear­ches of a public database.
Artic­le 15 Excep­tio­nal need for data use
(65) An excep­tio­nal neces­si­ty may also ari­se from situa­tions which do not con­sti­tu­te an emer­gen­cy. In such cases, a public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body should only be allo­wed to request non-per­so­nal data. The public sec­tor body should demon­stra­te that the data are neces­sa­ry to per­form a spe­ci­fic task in the public inte­rest expli­ci­t­ly pro­vi­ded for by law, such as the pro­duc­tion of offi­ci­al sta­tis­tics or the miti­ga­ti­on or reso­lu­ti­on of a public emer­gen­cy. In addi­ti­on, such a request may only be made whe­re the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body has iden­ti­fi­ed spe­ci­fic data which it could not other­wi­se obtain in a time­ly and effec­ti­ve man­ner and under equi­va­lent con­di­ti­ons, and only whe­re it has exhau­sted all other available means, to obtain such data, such as obtai­ning the data through vol­un­t­a­ry agree­ments, inclu­ding acqui­ring non-per­so­nal data on the mar­ket, bid­ding the pre­vai­ling mar­ket rate, or by rely­ing on exi­sting obli­ga­ti­ons to pro­vi­de data or adop­ting new legis­la­ti­on that could ensu­re the time­ly avai­la­bi­li­ty of the data. Fur­ther­mo­re, the con­di­ti­ons and prin­ci­ples for requests should app­ly, for exam­p­le in rela­ti­on to pur­po­se limi­ta­ti­on, pro­por­tio­na­li­ty, trans­pa­ren­cy and time limi­ta­ti­on. Whe­re data neces­sa­ry for the pro­duc­tion of offi­ci­al sta­tis­tics are reque­sted, the reque­st­ing public sec­tor body should also demon­stra­te whe­ther it is aut­ho­ri­zed under natio­nal law to acqui­re non-per­so­nal data on the market.
(1) The excep­tio­nal need to use cer­tain data within the mea­ning of this chap­ter is limi­t­ed in time and scope and is only dee­med to exist in one of the fol­lo­wing cir­cum­stances if:
a) the reque­sted data are neces­sa­ry to deal with a public emer­gen­cy and the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body can­not other­wi­se obtain tho­se data in a time­ly and effec­ti­ve man­ner under equi­va­lent conditions;
b) cir­cum­stances not cover­ed by point (a) exist, and only inso­far as non-per­so­nal data are con­cer­ned, if
i) a public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body acting on the basis of Uni­on or natio­nal law has iden­ti­fi­ed spe­ci­fic data, the absence of which pre­vents it from per­forming a spe­ci­fic task car­ri­ed out in the public inte­rest and express­ly pro­vi­ded for by law, such as the pro­duc­tion of offi­ci­al sta­tis­tics or the con­tain­ment or reso­lu­ti­on of a public emer­gen­cy, and
ii) the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body has exhau­sted all other means at its dis­po­sal to obtain such data, inclu­ding the acqui­si­ti­on of non-per­so­nal data on the mar­ket by offe­ring mar­ket tariffs or making use of exi­sting obli­ga­ti­ons to pro­vi­de data or adop­ting new legis­la­ti­on that could ensu­re the time­ly avai­la­bi­li­ty of the data.
(2) Para­graph 1(b) of this Artic­le shall not app­ly to microen­ter­pri­ses and small enterprises. 
(3) The obli­ga­ti­on to pro­ve that the public sec­tor body was not able to obtain non-per­so­nal data through acqui­si­ti­on on the mar­ket does not app­ly if the spe­ci­fic task car­ri­ed out in the public inte­rest is the pro­duc­tion of offi­ci­al sta­tis­tics and the acqui­si­ti­on of such data is not per­mit­ted under natio­nal law.
Artic­le 16 Rela­ti­on­ship with other obli­ga­ti­ons to pro­vi­de data for public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies
(1) This Chap­ter shall be wit­hout pre­ju­di­ce to obli­ga­ti­ons laid down in Uni­on or natio­nal law in rela­ti­on to report­ing, com­pli­ance with requests for access to infor­ma­ti­on or pro­of and veri­fi­ca­ti­on of com­pli­ance with legal obligations. 
(66) This Regu­la­ti­on should neither app­ly to nor pre-empt vol­un­t­a­ry data-sha­ring agree­ments bet­ween pri­va­te and public enti­ties, inclu­ding the pro­vi­si­on of data by SMEs, and is wit­hout pre­ju­di­ce to Uni­on acts pro­vi­ding for bin­ding requests for infor­ma­ti­on from public enti­ties to pri­va­te enti­ties. This Regu­la­ti­on should be wit­hout pre­ju­di­ce to obli­ga­ti­ons impo­sed on data hol­ders to pro­vi­de data that are not based on excep­tio­nal neces­si­ty, in par­ti­cu­lar whe­re the data basis and the data hol­ders are known or the data can be used on a regu­lar basis, as in the case of report­ing obli­ga­ti­ons and obli­ga­ti­ons ari­sing from the inter­nal mar­ket. Data access requi­re­ments for the pur­po­se of veri­fy­ing com­pli­ance with appli­ca­ble rules should also be unaf­fec­ted by this Regu­la­ti­on, inclu­ding in cases whe­re public sec­tor bodies dele­ga­te the task of veri­fy­ing com­pli­ance to other than public sec­tor bodies.
(2) This Chap­ter shall not app­ly to public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies car­ry­ing out acti­vi­ties for the pre­ven­ti­on, inve­sti­ga­ti­on, detec­tion or pro­se­cu­ti­on of cri­mi­nal or admi­ni­stra­ti­ve offen­ses or the exe­cu­ti­on of cri­mi­nal pen­al­ties, or to cus­toms or tax admi­ni­stra­ti­ons. This Chap­ter shall be wit­hout pre­ju­di­ce to appli­ca­ble Uni­on law and appli­ca­ble natio­nal law rela­ting to the pre­ven­ti­on, inve­sti­ga­ti­on, detec­tion or pro­se­cu­ti­on of cri­mi­nal or admi­ni­stra­ti­ve offen­ses or the exe­cu­ti­on of cri­mi­nal pen­al­ties or admi­ni­stra­ti­ve sanc­tions, or rela­ting to cus­toms or tax administration. 
(68) In car­ry­ing out their tasks in the are­as of pre­ven­ti­on, inve­sti­ga­ti­on, detec­tion or pro­se­cu­ti­on of cri­mi­nal or admi­ni­stra­ti­ve offen­ses or the exe­cu­ti­on of cri­mi­nal or admi­ni­stra­ti­ve pen­al­ties, as well as the coll­ec­tion of data for tax or cus­toms pur­po­ses, public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies should rely on their powers under Uni­on or natio­nal law. This Regu­la­ti­on is the­r­e­fo­re wit­hout pre­ju­di­ce to legis­la­ti­ve acts on data sha­ring, data access and data use in tho­se areas.
Artic­le 17 Data pro­vi­si­on requests
(1) Public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies shall, in their requests for data pur­su­ant to Artic­le 14
a) spe­ci­fy which data is requi­red, inclu­ding the rele­vant meta­da­ta neces­sa­ry for the inter­pre­ta­ti­on and use of this data;
b) demon­stra­te that the con­di­ti­ons requi­red for the exi­stence of excep­tio­nal neces­si­ty pur­su­ant to Artic­le 15 are met for the pur­po­ses for which the data are required;
c) explain the pur­po­se of the request, the inten­ded use of the reque­sted data, inclu­ding by a third par­ty in accordance with para­graph 4, whe­re appli­ca­ble, and the dura­ti­on of such use and, whe­re appli­ca­ble, the man­ner in which the pro­ce­s­sing of per­so­nal data is inten­ded to meet the excep­tio­nal need;
d) whe­re pos­si­ble, indi­ca­te when the data is expec­ted to be dele­ted by all par­ties who have access to the data;
e) justi­fy the choice of the data con­trol­ler to whom the request is addressed;
f) indi­ca­te any other public aut­ho­ri­ties or the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies and third par­ties to whom the reque­sted data are likely to be disclosed;
g) – if per­so­nal data is requi­red – spe­ci­fy all tech­ni­cal and orga­nizatio­nal mea­su­res neces­sa­ry and pro­por­tio­na­te to imple­ment the data pro­tec­tion prin­ci­ples and neces­sa­ry safe­guards, such as pseud­ony­mizati­on, and whe­ther the data con­trol­ler can car­ry out anony­mizati­on befo­re pro­vi­ding the data;
(72) In case of excep­tio­nal neces­si­ty in the con­text of a public emer­gen­cy, public aut­ho­ri­ties should use non-per­so­nal data when­ever pos­si­ble. In the case of requests based on an excep­tio­nal neces­si­ty not rela­ted to a public emer­gen­cy, no per­so­nal data can be reque­sted. If per­so­nal data is the sub­ject of the request, the data con­trol­ler should always anony­mi­ze the data. If it is strict­ly neces­sa­ry to pro­vi­de per­so­nal data with the data to a public aut­ho­ri­ty, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body, or if anony­mizati­on pro­ves impos­si­ble, the aut­ho­ri­ty reque­st­ing the data should demon­stra­te the strict neces­si­ty and the spe­ci­fic and limi­t­ed pur­po­ses of the pro­ce­s­sing. The appli­ca­ble rules on the pro­tec­tion of per­so­nal data should be com­plied with. The pro­vi­si­on of the data and their sub­se­quent use should be accom­pa­nied by safe­guards for the rights and inte­rests of the data subjects.
h) indi­ca­te the legal pro­vi­si­on ent­ru­sting the reque­st­ing public sec­tor body, the Com­mis­si­on, the Euro­pean Uni­on or the Uni­on body with the spe­ci­fic task car­ri­ed out in the public inte­rest that is rele­vant to the data request;
i) spe­ci­fy the peri­od within which the data must be pro­vi­ded and the peri­od refer­red to in Artic­le 18(2) within which the data hol­der may refu­se the request or request its amendment;
j) use its best efforts to avo­id that the ful­fill­ment of the data request leads to lia­bi­li­ty of the data con­trol­ler for brea­ches of Uni­on or natio­nal law.
(2) A request for data pur­su­ant to para­graph 1 of this Artic­le must
a) be in wri­ting and in clear, con­cise, simp­le lan­guage that is under­stan­da­ble to the data owner,
b) con­tain pre­cise details of the type of data reque­sted and rela­te to the data under the data controller’s con­trol at the time of the request;
c) be pro­por­tio­na­te to the excep­tio­nal need in terms of the level of detail and scope of the data reque­sted and the fre­quen­cy of access to the data reque­sted and be suf­fi­ci­ent­ly justified;
d) respect the legi­ti­ma­te aims of the data con­trol­ler while ensu­ring the pro­tec­tion of com­mer­cial con­fi­den­tia­li­ty in accordance with Artic­le 19(3) and taking into account the cost and effort requi­red to pro­vi­de the data;
e) non-per­so­nal data and only whe­re this pro­ves to be insuf­fi­ci­ent to respond to the excep­tio­nal need to use data in accordance with Artic­le 15(1)(a), requi­re per­so­nal data in pseud­ony­mi­zed form and spe­ci­fy the tech­ni­cal and orga­nizatio­nal mea­su­res taken to pro­tect the data;
f) inform the data sub­ject of the sanc­tions impo­sed in accordance with Artic­le 40 by the com­pe­tent aut­ho­ri­ty desi­gna­ted in accordance with Artic­le 37 if he does not com­ply with the request;
g) whe­re the request is made by a public sec­tor body, to the data coor­di­na­tor refer­red to in Artic­le 37 of the Mem­ber Sta­te in which the reque­st­ing public sec­tor body is estab­lished, who shall make the request publicly available online wit­hout delay, unless the public sec­tor body con­siders that such publi­ca­ti­on would pose a thre­at to public security;
h) pro­vi­ded that the request is made by the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body, be made available online wit­hout delay;
i) – if per­so­nal data are reque­sted – be noti­fi­ed wit­hout delay to the super­vi­so­ry aut­ho­ri­ty respon­si­ble for moni­to­ring the appli­ca­ti­on of Regu­la­ti­on (EU) 2016/679 in the Mem­ber Sta­te in which the public sec­tor body is established.
The Euro­pean Cen­tral Bank and the insti­tu­ti­ons of the Uni­on shall inform the Com­mis­si­on of their requests. 
(69) In accordance with Artic­le 6(1) and (3) of Regu­la­ti­on (EU) 2016/679, a pro­por­tio­na­te, limi­t­ed and pre­dic­ta­ble frame­work at Uni­on level is neces­sa­ry when choo­sing the legal basis for the pro­vi­si­on of data by data hol­ders to public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies in cases of excep­tio­nal neces­si­ty, both to ensu­re legal cer­tain­ty and to mini­mi­ze the admi­ni­stra­ti­ve bur­den on busi­nesses. To this end, requests for data from public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies to data hol­ders should be spe­ci­fic, trans­pa­rent and pro­por­tio­na­te in terms of their scope and level of detail. The pur­po­se of the request and the inten­ded use of the reque­sted data should be spe­ci­fi­cal­ly and cle­ar­ly explai­ned, while allo­wing the reque­st­ing body appro­pria­te fle­xi­bi­li­ty in the per­for­mance of its tasks in the public inte­rest. The request should also take into account the legi­ti­ma­te inte­rests of the data con­trol­ler to whom it is addres­sed. The bur­den on data hol­ders should be mini­mi­zed by requi­ring the reque­st­ing aut­ho­ri­ties to respect the prin­ci­ple of uni­que­ness, which pre­vents the same data from being reque­sted seve­ral times or by seve­ral public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies. In order to ensu­re trans­pa­ren­cy, requests for data made by the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies should be published wit­hout delay by the body reque­st­ing the data. The Euro­pean Cen­tral Bank and the Uni­on bodies should inform the Com­mis­si­on of their requests. Whe­re the request for data has been made by a public sec­tor body, that body should also inform the data coor­di­na­tor of the Mem­ber Sta­te in which the public sec­tor body is estab­lished. It should be ensu­red that all requests are publicly available online. Fol­lo­wing such noti­fi­ca­ti­on of a data request, the com­pe­tent aut­ho­ri­ty may deci­de to assess the lawful­ness of the request and car­ry out its tasks in rela­ti­on to the enforce­ment and appli­ca­ti­on of this Regu­la­ti­on. The data coor­di­na­tor should ensu­re that all requests made by public sec­tor bodies are publicly available online.
(3) A public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body shall not make data obtai­ned under this Chap­ter available for re-use within the mea­ning of point (2) of Artic­le 2 of Regu­la­ti­on (EU) 2022/868 or point (11) of Artic­le 2 of Direc­ti­ve (EU) 2019/1024. Regu­la­ti­on (EU) 2022/868 and Direc­ti­ve (EU) 2019/1024 shall not app­ly to data held by public sec­tor bodies obtai­ned under this Chapter. 
(70) The pur­po­se of the obli­ga­ti­on to pro­vi­de data is to ensu­re that public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank or insti­tu­ti­ons of the Uni­on have the neces­sa­ry know­ledge to mana­ge or pre­vent public emer­gen­ci­es or to over­co­me them or to main­tain the capa­ci­ty to per­form cer­tain tasks express­ly pro­vi­ded for by law. The data obtai­ned by tho­se bodies may con­sti­tu­te busi­ness secrets. The­r­e­fo­re, neither Regu­la­ti­on (EU) 2022/868 nor Direc­ti­ve (EU) 2019/1024 of the Euro­pean Par­lia­ment and of the Coun­cil (28) should app­ly to data pro­vi­ded under this Regu­la­ti­on and such data should not be con­side­red as open data available for re-use by third par­ties. Howe­ver, this should be wit­hout pre­ju­di­ce to the appli­ca­bi­li­ty of Direc­ti­ve (EU) 2019/1024 to the re-use of offi­ci­al sta­tis­tics for the pro­duc­tion of which data obtai­ned under this Regu­la­ti­on have been used, pro­vi­ded that the re-use does not extend to the under­ly­ing data. Fur­ther­mo­re, this should be wit­hout pre­ju­di­ce to the pos­si­bi­li­ty of onward dis­se­mi­na­ti­on of the data for rese­arch pur­po­ses or for the deve­lo­p­ment, pro­duc­tion and dis­se­mi­na­ti­on of offi­ci­al sta­tis­tics, pro­vi­ded that the con­di­ti­ons laid down in this Regu­la­ti­on are met. Public sec­tor bodies should also be allo­wed to exch­an­ge data obtai­ned under this Regu­la­ti­on with other public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies in order to meet the excep­tio­nal need for which they were requested.
(4) Para­graph 3 of this Artic­le shall not pre­vent a public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body from exchan­ging data obtai­ned under this Chap­ter with ano­ther public sec­tor body or with the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body for the pur­po­se of car­ry­ing out the tasks refer­red to in Artic­le 15, as spe­ci­fi­ed in the request refer­red to in point (f) of para­graph 1 of this Artic­le, or from making the data available to a third par­ty whe­re it has dele­ga­ted tech­ni­cal inspec­tions or other tasks to that third par­ty under a publicly available agree­ment. The obli­ga­ti­ons of public sec­tor bodies under Artic­le 19, in par­ti­cu­lar the gua­ran­tees of con­fi­den­tia­li­ty of busi­ness secrets, shall also app­ly to such third par­ties. Whe­re a public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body trans­mits or makes available data pur­su­ant to this para­graph, it shall imme­dia­te­ly inform the data con­trol­ler from whom it recei­ved the data. 
(5) If the data sub­ject con­siders that his or her rights under this Chap­ter have been inf­rin­ged as a result of the trans­fer or making available of data, he or she may lodge a com­plaint with the com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te in which the data sub­ject is estab­lished, desi­gna­ted in accordance with Artic­le 37. 
(6) The Com­mis­si­on shall deve­lop a model request form in accordance with this Article.
Artic­le 18 Ful­fill­ment of data requests
(1) A data hol­der who recei­ves a request for access to data under this Chap­ter shall pro­vi­de the data to the reque­st­ing public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body wit­hout undue delay, taking into account the neces­sa­ry tech­ni­cal, orga­nizatio­nal and legal measures. 
(2) Wit­hout pre­ju­di­ce to spe­ci­fic requi­re­ments regar­ding the avai­la­bi­li­ty of data laid down in Uni­on or natio­nal law, a data hol­der may refu­se or request modi­fi­ca­ti­on of data access requests within the mea­ning of this Chap­ter wit­hout undue delay and in any event within five working days of rece­ipt of the data request in the case of data neces­sa­ry to respond to a public emer­gen­cy, and in other cases of excep­tio­nal neces­si­ty wit­hout undue delay and in any event within 30 working days of rece­ipt of the data request con­cer­ned, on any of the fol­lo­wing grounds: 
(71) Data hol­ders should have the pos­si­bi­li­ty to eit­her refu­se or request an amend­ment to the request of a public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body wit­hout undue delay and in any event within five or 30 working days at the latest, depen­ding on the natu­re of the excep­tio­nal neces­si­ty invo­ked in the request. Whe­re appli­ca­ble, the data hol­der should have this oppor­tu­ni­ty if it has no con­trol over the reque­sted data, i.e. if it does not have direct access to the data and can­not deter­mi­ne its avai­la­bi­li­ty. It should be pos­si­ble to justi­fy the non-pro­vi­si­on of the data if it can be demon­stra­ted that the request is com­pa­ra­ble to a request pre­vious­ly sub­mit­ted by ano­ther public sec­tor body or by the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body for the same pur­po­se and the data hol­der has not been infor­med of the era­su­re of the data in accordance with this Regu­la­ti­on. If a data hol­der refu­ses the request or requests its amend­ment, it should justi­fy the refu­sal to the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body that made the request. Whe­re sui gene­ris data­ba­se rights under Direc­ti­ve 96/9/ of the Euro­pean Par­lia­ment and of the Coun­cil (29) app­ly in respect of the reque­sted data sets, data hol­ders should exer­cise their rights in a way that does not pre­vent the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body from obtai­ning or dis­clo­sing the data in accordance with this Regulation.
a) The data owner has no con­trol over the reque­sted data;
b) a simi­lar request for the same pur­po­se has alre­a­dy been made by ano­ther public sec­tor body or by the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body and the data sub­ject has not been infor­med of the era­su­re of the data in accordance with Artic­le 19(1)(c);
c) the request does not meet the requi­re­ments of Artic­le 17(1) and (2).
(3) If the data sub­ject refu­ses the request refer­red to in point (b) of para­graph 2 or requests its amend­ment, he or she shall iden­ti­fy the public sec­tor body or the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body which pre­vious­ly reque­sted data for the same purpose. 
(4) If the reque­sted data also con­tain per­so­nal data, the­se shall be duly anony­mi­zed by the data con­trol­ler, unless the dis­clo­sure of per­so­nal data is neces­sa­ry to com­ply with a data access request from a public aut­ho­ri­ty, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body. In the­se cases, the data con­trol­ler must pseud­ony­mi­ze the data. 
(5) If the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body intends to object to the refu­sal of a data subject’s request for data or if the data sub­ject intends to object to the request and the mat­ter can­not be resol­ved by amen­ding the request accor­din­gly, the mat­ter shall be refer­red to the com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te whe­re the data sub­ject is estab­lished, desi­gna­ted in accordance with Artic­le 37.
Artic­le 19 Obli­ga­ti­ons of public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies
(1) A public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body which has recei­ved data in respon­se to a request pur­su­ant to Artic­le 14,
a) may not use the data in a way that is incom­pa­ti­ble with the pur­po­se of the data request;
b) must have taken tech­ni­cal and orga­nizatio­nal mea­su­res to ensu­re the con­fi­den­tia­li­ty and inte­gri­ty of the reque­sted data and the secu­ri­ty of the data trans­fers – espe­ci­al­ly in the case of per­so­nal data – and to pro­tect the rights and free­doms of the data subjects;
c) shall dele­te the data as soon as they are no lon­ger neces­sa­ry for the sta­ted pur­po­se and inform the data con­trol­ler and the indi­vi­du­als or orga­nizati­ons that recei­ved the data in accordance with Artic­le 21(1) wit­hout undue delay that the data have been dele­ted, unless the archi­ving of the data is requi­red in accordance with Uni­on or natio­nal law on public access to docu­ments in the con­text of trans­pa­ren­cy obligations.
(73) Data pro­vi­ded to public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies on grounds of excep­tio­nal neces­si­ty should only be used for the pur­po­ses of the data request, unless the data con­trol­ler who pro­vi­ded the data has expli­ci­t­ly agreed to the data being used for other pur­po­ses. Unless other­wi­se agreed, the data should be dele­ted as soon as it is no lon­ger neces­sa­ry for the pur­po­se sta­ted in the request and the data con­trol­ler should be infor­med the­reof. This Regu­la­ti­on builds on exi­sting Uni­on and natio­nal access regimes and does not chan­ge natio­nal law on public access to docu­ments rela­ted to trans­pa­ren­cy obli­ga­ti­ons. Data should be dele­ted as soon as they are no lon­ger nee­ded to com­ply with tho­se trans­pa­ren­cy obligations.
(2) A public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body or third par­ty recei­ving data pur­su­ant to this Chap­ter shall not be aut­ho­ri­zed,
a) use the data or know­ledge about the Data Controller’s eco­no­mic situa­ti­on, assets and pro­duc­tion or ope­ra­ting methods to deve­lop or impro­ve a con­nec­ted pro­duct or ser­vice that com­pe­tes with the Data Controller’s con­nec­ted pro­duct or service;
b) to pass on the data to ano­ther third par­ty for the pur­po­ses men­tio­ned under let­ter a.
(74) When re-using data pro­vi­ded by data hol­ders, public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies should com­ply with both appli­ca­ble Uni­on or natio­nal law and the con­trac­tu­al obli­ga­ti­ons of the data hol­der. They should refrain both from deve­lo­ping or impro­ving a con­nec­ted pro­duct or ser­vice that com­pe­tes with the con­nec­ted pro­duct or ser­vice of the data con­trol­ler and from sha­ring the data with third par­ties for the­se pur­po­ses. They should also publicly ack­now­ledge a data con­trol­ler at its request and be respon­si­ble for ensu­ring the secu­ri­ty of the data recei­ved. Whe­re dis­clo­sure of the data holder’s busi­ness secrets to public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies is strict­ly neces­sa­ry to ful­fill the pur­po­se for which the data were reque­sted, the data hol­der should be assu­red of the con­fi­den­tia­li­ty of tho­se data pri­or to their disclosure.
(3) Dis­clo­sure of trade secrets to a public aut­ho­ri­ty, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body shall be dee­med neces­sa­ry only to the ext­ent that it is indis­pensable for the pur­po­se of a request pur­su­ant to Artic­le 15. In that case, the data con­trol­ler or, if dif­fe­rent, the trade secret hol­der shall iden­ti­fy the data pro­tec­ted as trade secrets, inclu­ding the rele­vant meta­da­ta. The public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body shall take all neces­sa­ry and appro­pria­te tech­ni­cal and orga­nizatio­nal mea­su­res to pre­ser­ve the con­fi­den­tia­li­ty of trade secrets, inclu­ding, whe­re appro­pria­te, the use of model con­trac­tu­al pro­vi­si­ons, tech­ni­cal stan­dards and the appli­ca­ti­on of codes of con­duct, pri­or to the dis­clo­sure of trade secrets. 
(4) A public aut­ho­ri­ty, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body shall be respon­si­ble for the secu­ri­ty of the data received.
Artic­le 20 Com­pen­sa­ti­on in case of excep­tio­nal need
(75) When it comes to the pro­tec­tion of an important public good, such as the manage­ment of public emer­gen­ci­es, the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body con­cer­ned should not be expec­ted to pro­vi­de any con­side­ra­ti­on to under­ta­kings for the data obtai­ned. Public emer­gen­ci­es are rare events and not all such emer­gen­ci­es requi­re the use of data held by under­ta­kings. At the same time, the obli­ga­ti­on to pro­vi­de data could be a signi­fi­cant bur­den for micro and small enter­pri­ses. The­se busi­nesses should the­r­e­fo­re be able to request con­side­ra­ti­on even in the con­text of public emer­gen­cy mea­su­res. It is not likely that the busi­ness acti­vi­ties of data hol­ders will be affec­ted by the use of this Regu­la­ti­on by public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies. Howe­ver, as cases of excep­tio­nal neces­si­ty, other than the manage­ment of a public emer­gen­cy, may be more fre­quent, data hol­ders should be entit­led in such cases to ade­qua­te com­pen­sa­ti­on, which should not exce­ed the tech­ni­cal and orga­nizatio­nal costs asso­cia­ted with ful­fil­ling the request, and to the rea­sonable mar­gin neces­sa­ry to pro­vi­de the data to the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body. The con­side­ra­ti­on should not be under­s­tood as payment for the data its­elf and should not be man­da­to­ry. Data hol­ders should not be able to request con­side­ra­ti­on whe­re natio­nal sta­tis­ti­cal insti­tu­tes or other natio­nal aut­ho­ri­ties respon­si­ble for the pro­duc­tion of sta­tis­tics are not allo­wed by natio­nal law to pro­vi­de data hol­ders with con­side­ra­ti­on for the pro­vi­si­on of data. The public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body con­cer­ned should be able to chall­enge the amount of the con­side­ra­ti­on reque­sted by the data hol­der by brin­ging the mat­ter befo­re the com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te in which the data hol­der is established.
(1) Data hol­ders other than microen­ter­pri­ses and small enter­pri­ses shall pro­vi­de the data neces­sa­ry to address a public emer­gen­cy refer­red to in point (a) of Artic­le 15(1) free of char­ge. The public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body that recei­ved the data shall publicly ack­now­ledge the con­tri­bu­ti­on of the data hol­der upon its request. 
(2) The data con­trol­ler shall be entit­led to fair com­pen­sa­ti­on for the pro­vi­si­on of data in accordance with a request pur­su­ant to Artic­le 15(1)(b). That con­side­ra­ti­on shall cover at least the tech­ni­cal and orga­nizatio­nal costs incur­red in com­ply­ing with the request, inclu­ding, whe­re appro­pria­te, the costs of anony­mizati­on, pseud­ony­mizati­on, aggre­ga­ti­on and tech­ni­cal adap­t­ati­on, and a rea­sonable mar­gin. At the request of the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body, the data con­trol­ler shall pro­vi­de infor­ma­ti­on on the basis of the cost cal­cu­la­ti­on and the appro­pria­te margin. 
(3) Para­graph 2 also applies if micro-enter­pri­ses and small enter­pri­ses cla­im a con­side­ra­ti­on for the pro­vi­si­on of data. 
(4) Data hol­ders shall not have a right to con­side­ra­ti­on for the pro­vi­si­on of data to meet a request under Artic­le 15(1)(b) if the spe­ci­fic task is car­ri­ed out in the public inte­rest in the pro­duc­tion of offi­ci­al sta­tis­tics and the acqui­si­ti­on of data is not per­mit­ted under natio­nal law. Mem­ber Sta­tes shall inform the Com­mis­si­on whe­re the acqui­si­ti­on of data for the pro­duc­tion of offi­ci­al sta­tis­tics is not per­mit­ted under natio­nal law. 
(5) If the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body dis­agrees with the amount of the con­side­ra­ti­on reque­sted from the data hol­der, it may lodge a com­plaint with the com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te whe­re the data hol­der is estab­lished, desi­gna­ted in accordance with Artic­le 37.
Artic­le 21 Dis­clo­sure of data obtai­ned in the con­text of excep­tio­nal needs to rese­arch insti­tu­ti­ons or sta­tis­ti­cal offices
(1) A public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body shall be entit­led to dis­c­lo­se data recei­ved under this Chap­ter
a) to indi­vi­du­als or orga­nizati­ons for the pur­po­se of car­ry­ing out sci­en­ti­fic rese­arch or ana­ly­sis com­pa­ti­ble with the pur­po­se of the data request, or
b) to natio­nal sta­tis­ti­cal offices or to Euro­stat for the com­pi­la­ti­on of offi­ci­al statistics.
(2) Per­sons or orga­nizati­ons recei­ving data under para­graph 1 must be acting in the public inte­rest or in the frame­work of a task of public inte­rest reco­gnized under Uni­on or natio­nal law. This does not include orga­nizati­ons that are sub­ject to signi­fi­cant influence by com­mer­cial enter­pri­ses, which could give them pre­fe­ren­ti­al access to the rese­arch results. 
(3) Indi­vi­du­als or orga­nizati­ons recei­ving data pur­su­ant to para­graph 1 of this Artic­le shall com­ply with the same obli­ga­ti­ons as app­ly to public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on bodies refer­red to in Artic­le 17(3) and Artic­le 19. 
(4) Wit­hout pre­ju­di­ce to point (c) of Artic­le 19(1), indi­vi­du­als or orga­nizati­ons that are reci­pi­en­ts of the data refer­red to in para­graph 1 of this Artic­le may retain the data recei­ved for a peri­od of up to six months after they have been dele­ted by the public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies for the pur­po­ses of the data request. 
(5) Whe­re a public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body intends to trans­mit or make available data pur­su­ant to para­graph 1 of this Artic­le, it shall inform the data con­trol­ler from whom the data have been recei­ved wit­hout undue delay, indi­ca­ting the iden­ti­ty and cont­act details of the orga­nizati­on or indi­vi­du­al recei­ving the data, the pur­po­se of the trans­mis­si­on or making available of the data, the peri­od for which the data are to be used and the tech­ni­cal pro­tec­tion mea­su­res and orga­ni­sa­tio­nal mea­su­res taken, inclu­ding whe­re per­so­nal data or busi­ness secrets are con­cer­ned. If the data sub­ject does not agree with the trans­mis­si­on or making available of data, he or she may lodge a com­plaint with the com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te in which the data sub­ject is estab­lished, desi­gna­ted in accordance with Artic­le 37.
(76) The public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body should be aut­ho­ri­zed to dis­c­lo­se the data it has obtai­ned on the basis of the request to other bodies or per­sons whe­re this is neces­sa­ry for car­ry­ing out sci­en­ti­fic or ana­ly­ti­cal acti­vi­ties which it can­not car­ry out its­elf, pro­vi­ded that such acti­vi­ties are com­pa­ti­ble with the pur­po­se of the data request. It should inform the data con­trol­ler in good time of any such dis­clo­sure. The data may also be shared with natio­nal sta­tis­ti­cal aut­ho­ri­ties and Euro­stat for the deve­lo­p­ment, pro­duc­tion and dis­se­mi­na­ti­on of offi­ci­al sta­tis­tics under the same cir­cum­stances. Howe­ver, the rese­arch acti­vi­ties con­cer­ned should be com­pa­ti­ble with the pur­po­se of the data request and the data hol­der should be infor­med of the dis­clo­sure of the data he has pro­vi­ded. Indi­vi­du­als con­duc­ting rese­arch or rese­arch orga­nizati­ons to which such data may be dis­c­lo­sed should be eit­her non-pro­fit or acting in the public inte­rest on behalf of the govern­ment. Orga­nizati­ons should not be con­side­red rese­arch orga­nizati­ons for the pur­po­ses of this Regu­la­ti­on if they are sub­ject to a signi­fi­cant degree of influence by com­mer­cial enti­ties which, by vir­tue of their struc­tu­re, could exer­cise con­trol and ther­eby obtain pri­vi­le­ged access to the results of the research.
Artic­le 22 Mutu­al assi­stance and cross-bor­der cooperation
(1) Public aut­ho­ri­ties, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies shall coope­ra­te and sup­port each other with a view to the con­si­stent imple­men­ta­ti­on of this Chapter. 
(2) Data that has been exch­an­ged in con­nec­tion with a request for admi­ni­stra­ti­ve assi­stance and admi­ni­stra­ti­ve assi­stance pro­vi­ded in accordance with para­graph 1 may not be used in a man­ner that is incom­pa­ti­ble with the pur­po­se of the data request. 
(3) Whe­re a public sec­tor body intends to request the pro­vi­si­on of data from a data hol­der estab­lished in ano­ther Mem­ber Sta­te, it shall first noti­fy that inten­ti­on to the com­pe­tent aut­ho­ri­ty of that Mem­ber Sta­te desi­gna­ted in accordance with Artic­le 37. This requi­re­ment shall also app­ly to requests for access from the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies. The request shall be exami­ned by the com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te whe­re the data hol­der is established. 
(4) After exami­ning the request in the light of the requi­re­ments laid down in Artic­le 17, the rele­vant com­pe­tent aut­ho­ri­ty shall take one of the fol­lo­wing mea­su­res wit­hout delay:
a) It shall trans­mit the request to the data con­trol­ler and, whe­re appro­pria­te, inform the reque­st­ing public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body that it must coope­ra­te with public sec­tor bodies of the Mem­ber Sta­te in which the data con­trol­ler is estab­lished in order to redu­ce the admi­ni­stra­ti­ve bur­den on the data con­trol­ler in com­ply­ing with the request;
b) it rejects the request for duly justi­fi­ed rea­sons in accordance with this chapter.
The reque­st­ing public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body shall take into account the indi­ca­ti­on of the rele­vant com­pe­tent aut­ho­ri­ty and the rea­sons given by that aut­ho­ri­ty in accordance with the first sub­pa­ra­graph befo­re taking fur­ther action, such as resub­mit­ting the request, whe­re applicable.
(77) In order to address a cross-bor­der public emer­gen­cy or other excep­tio­nal need, requests for data may be addres­sed to data hol­ders in Mem­ber Sta­tes other than that of the reque­st­ing public sec­tor body. In this case, the reque­st­ing public sec­tor body should inform the com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te whe­re the data hol­der is estab­lished so that it can assess the request on the basis of the cri­te­ria set out in this Regu­la­ti­on. This should also app­ly to requests from the Com­mis­si­on, the Euro­pean Cen­tral Bank or a Uni­on body. If per­so­nal data are reque­sted, the public sec­tor body should inform the super­vi­so­ry aut­ho­ri­ty respon­si­ble for moni­to­ring the appli­ca­ti­on of Regu­la­ti­on (EU) 2016/679 in the Mem­ber Sta­te whe­re the public sec­tor body is estab­lished. The com­pe­tent aut­ho­ri­ty con­cer­ned should be empowered to inform the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body that it must coope­ra­te with the public sec­tor bodies of the Mem­ber Sta­te whe­re the data hol­der is estab­lished in order to mini­mi­ze the admi­ni­stra­ti­ve bur­den on the data hol­der. If the com­pe­tent aut­ho­ri­ty has valid objec­tions as to the com­pa­ti­bi­li­ty of the request with this Regu­la­ti­on, it should refu­se the request of the public sec­tor body, the Com­mis­si­on, the Euro­pean Cen­tral Bank or the Uni­on body, which in turn should take tho­se objec­tions into account befo­re taking fur­ther action, inclu­ding resub­mit­ting the request.

Chap­ter VI Swit­ching bet­ween data pro­ce­s­sing services

Artic­le 23 Rem­oval of obs­ta­cles to effec­ti­ve switching
Pro­vi­ders of data pro­ce­s­sing ser­vices shall take the mea­su­res pro­vi­ded for in Artic­les 25, 26, 27, 29 and 30 to enable cus­to­mers to switch to a data pro­ce­s­sing ser­vice cove­ring the same type of ser­vice pro­vi­ded by ano­ther pro­vi­der of data pro­ce­s­sing ser­vices or to ICT infras­truc­tu­re at their own pre­mi­ses or, whe­re appli­ca­ble, to use seve­ral pro­vi­ders of data pro­ce­s­sing ser­vices at the same time. In par­ti­cu­lar, pro­vi­ders of data pro­ce­s­sing ser­vices may not impo­se pre-com­mer­cial, com­mer­cial, tech­ni­cal, con­trac­tu­al and orga­nizatio­nal bar­riers and must remo­ve such bar­riers if they pre­vent cus­to­mers from doing so,
a) ter­mi­na­te the con­tract for the data pro­ce­s­sing ser­vice after the maxi­mum noti­ce peri­od and after the chan­ge has been suc­cessful­ly com­ple­ted in accordance with Artic­le 25;
b) to con­clude new con­tracts with ano­ther pro­vi­der of data pro­ce­s­sing ser­vices for the same type of service;
c) trans­fer exporta­ble data of the cus­to­mer and digi­tal assets to ano­ther pro­vi­der of data pro­ce­s­sing ser­vices or to an ICT infras­truc­tu­re on its own pre­mi­ses, even after taking advan­ta­ge of a free offer;
d) to achie­ve func­tion­al equi­va­lence when using the new data pro­ce­s­sing ser­vice in the ICT envi­ron­ment of ano­ther data pro­ce­s­sing ser­vice pro­vi­der cove­ring the same type of ser­vice, in accordance with Artic­le 24;
e) to sepa­ra­te the data pro­ce­s­sing ser­vices refer­red to in Artic­le 30(1) from other data pro­ce­s­sing ser­vices pro­vi­ded by the data pro­ce­s­sing ser­vice pro­vi­der, whe­re tech­ni­cal­ly feasible.
(78) The abili­ty of cus­to­mers of data pro­ce­s­sing ser­vices, inclu­ding cloud and edge ser­vices, to switch from one data pro­ce­s­sing ser­vice to ano­ther while main­tai­ning a mini­mum set of ser­vice func­tion­a­li­ties and wit­hout expe­ri­en­cing down­ti­me, or to use ser­vices from mul­ti­ple pro­vi­ders wit­hout undue hard­ship and data trans­fer costs, is essen­ti­al for a more com­pe­ti­ti­ve mar­ket with lower bar­riers to ent­ry for new pro­vi­ders of data pro­ce­s­sing ser­vices and for ensu­ring bet­ter resi­li­ence of users of tho­se ser­vices. Cus­to­mers bene­fiting from free offers should also bene­fit from the swit­ching pro­vi­si­ons laid down in this Regu­la­ti­on so that tho­se offers do not crea­te a situa­ti­on of depen­den­cy for customers.
(79) Regu­la­ti­on (EU) 2018/1807 of the Euro­pean Par­lia­ment and of the Coun­cil (30) requi­res pro­vi­ders of data pro­ce­s­sing ser­vices to deve­lop and effec­tively imple­ment self-regu­la­to­ry codes of con­duct that include best prac­ti­ces, inclu­ding to faci­li­ta­te the swit­ching of data pro­ce­s­sing ser­vice pro­vi­ders and the trans­fer of data. Given the limi­t­ed upt­ake of self-regu­la­to­ry frame­works deve­lo­ped in respon­se and the gene­ral lack of open stan­dards and inter­faces, a set of mini­mum regu­la­to­ry obli­ga­ti­ons needs to be estab­lished for data pro­ce­s­sing ser­vice pro­vi­ders in order to remo­ve tho­se pre-com­mer­cial, com­mer­cial, tech­ni­cal, con­trac­tu­al and orga­nizatio­nal bar­riers that not only lead to redu­ced data trans­fer speeds in the event of a cus­to­mer swit­ching pro­vi­ders, but also pre­vent the effec­ti­ve imple­men­ta­ti­on of swit­ching bet­ween data pro­ce­s­sing services.
(82) If the ori­gi­nal data pro­ce­s­sing ser­vice pro­vi­der impe­des the extra­c­tion of exporta­ble data belon­ging to the cus­to­mer, this may hin­der the resto­ra­ti­on of the ser­vice func­tions in the infras­truc­tu­re of the acqui­ring data pro­ce­s­sing ser­vice pro­vi­der. In order to faci­li­ta­te the customer’s exit stra­tegy, avo­id unneces­sa­ry and bur­den­so­me tasks and ensu­re that the cus­to­mer does not lose any of its data by com­ple­ting the switch, the initi­al data pro­ce­s­sing ser­vices pro­vi­der should inform the cus­to­mer in advan­ce of the scope of data that can be expor­ted once that cus­to­mer deci­des to switch to ano­ther ser­vice offe­red by ano­ther data pro­ce­s­sing ser­vices pro­vi­der or to an ICT infras­truc­tu­re on its own pre­mi­ses. The term „exporta­ble data“ should include at least the input and out­put data – inclu­ding meta­da­ta – gene­ra­ted or co-gene­ra­ted direct­ly or indi­rect­ly by the customer’s use of the data pro­ce­s­sing ser­vice, exclu­ding assets or data from the data pro­ce­s­sing ser­vice pro­vi­der or from a third par­ty. Assets or data from the data pro­ce­s­sing ser­vice pro­vi­der or from a third par­ty that are pro­tec­ted by intellec­tu­al pro­per­ty rights or con­sti­tu­te trade secrets of that pro­vi­der or third par­ty, or data rela­ted to the inte­gri­ty and secu­ri­ty of the ser­vice, whe­re the data pro­ce­s­sing ser­vice pro­vi­der is expo­sed to cyber­se­cu­ri­ty risks in case of export, should be exclu­ded from the exporta­ble data. The­se exemp­ti­ons should not hin­der or delay the imple­men­ta­ti­on of the change.
(84) The objec­ti­ve of this Regu­la­ti­on is to faci­li­ta­te swit­ching bet­ween data pro­ce­s­sing ser­vices, inclu­ding the con­di­ti­ons and mea­su­res neces­sa­ry for a cus­to­mer to be able to ter­mi­na­te a con­tract for a data pro­ce­s­sing ser­vice, to con­clude one or more new con­tracts with dif­fe­rent data pro­ce­s­sing ser­vice pro­vi­ders, to trans­fer its exporta­ble data and digi­tal assets and to bene­fit from func­tion­al equi­va­lence whe­re applicable.
(91) Whe­re pro­vi­ders of data pro­ce­s­sing ser­vices are them­sel­ves cus­to­mers of data pro­ce­s­sing ser­vices pro­vi­ded by a third par­ty, they may them­sel­ves bene­fit from the more effec­ti­ve imple­men­ta­ti­on of the switch, while remai­ning bound by the obli­ga­ti­ons under this Regu­la­ti­on in rela­ti­on to their own ser­vice offerings.
(92) Pro­vi­ders of data pro­ce­s­sing ser­vices should be obli­ged to pro­vi­de, within their capa­bi­li­ties and pro­por­tio­na­te to their respec­ti­ve obli­ga­ti­ons, all assi­stance and sup­port neces­sa­ry to make the switch to the ser­vice of ano­ther pro­vi­der of data pro­ce­s­sing ser­vices suc­cessful, effec­ti­ve and secu­re. This Regu­la­ti­on does not obli­ge data pro­ce­s­sing ser­vice pro­vi­ders to deve­lop new cate­go­ries of data pro­ce­s­sing ser­vices, inclu­ding within or on the basis of the ICT infras­truc­tu­re of dif­fe­rent data pro­ce­s­sing ser­vice pro­vi­ders, in order to ensu­re func­tion­al equi­va­lence in an envi­ron­ment other than their own. The ori­gi­nal pro­vi­der of data pro­ce­s­sing ser­vices has neither access to nor insight into the envi­ron­ment of the acqui­ring pro­vi­der of data pro­ce­s­sing ser­vices. Func­tion­al equi­va­lence should the­r­e­fo­re not be under­s­tood as obliging the ori­gi­nal pro­vi­der of data pro­ce­s­sing ser­vices to recrea­te the ser­vice in que­sti­on within the infras­truc­tu­re of the acqui­ring pro­vi­der of data pro­ce­s­sing ser­vices. Rather, the ori­gi­nal pro­vi­der of data pro­ce­s­sing ser­vices should take all rea­sonable mea­su­res within its powers to enable the rea­lizati­on of func­tion­al equi­va­lence by pro­vi­ding capa­ci­ty, ade­qua­te infor­ma­ti­on, docu­men­ta­ti­on, tech­ni­cal sup­port and, whe­re appro­pria­te, the neces­sa­ry tools.
(93) Pro­vi­ders of data pro­ce­s­sing ser­vices should also be requi­red to remo­ve exi­sting bar­riers and not crea­te new ones, inclu­ding in rela­ti­on to cus­to­mers who wish to switch to an ICT infras­truc­tu­re on their own pre­mi­ses. Bar­riers may be of a pre-com­mer­cial, com­mer­cial, tech­ni­cal, con­trac­tu­al or orga­nizatio­nal natu­re, among others. Pro­vi­ders of data pro­ce­s­sing ser­vices should also be requi­red to remo­ve obs­ta­cles to the sepa­ra­ti­on of a par­ti­cu­lar indi­vi­du­al ser­vice from other data pro­ce­s­sing ser­vices pro­vi­ded under a con­tract and to allow swit­ching for the ser­vice con­cer­ned, whe­re the­re are no major demon­stra­ble tech­ni­cal obs­ta­cles to such separation.
Artic­le 24 Scope of tech­ni­cal obligations
The respon­si­bi­li­ty of pro­vi­ders of data pro­ce­s­sing ser­vices under Artic­les 23, 25, 29, 30 and 34 applies only to the ser­vices, con­tracts or busi­ness prac­ti­ces offe­red by the ori­gi­nal pro­vi­der of the data pro­ce­s­sing services.
Artic­le 25 Con­trac­tu­al clau­ses for the exchange
(96) In order to faci­li­ta­te inter­ope­ra­bi­li­ty and swit­ching bet­ween data pro­ce­s­sing ser­vices, users and pro­vi­ders of data pro­ce­s­sing ser­vices should con­sider the use of imple­men­ta­ti­on and com­pli­ance tools, in par­ti­cu­lar tho­se published by the Com­mis­si­on in the form of an EU Cloud Rule­book and a Gui­de to public pro­cu­re­ment for data pro­ce­s­sing ser­vices. In par­ti­cu­lar, stan­dard con­trac­tu­al clau­ses are appro­pria­te as they increa­se trust in data pro­ce­s­sing ser­vices, crea­te a more balan­ced rela­ti­on­ship bet­ween users and pro­vi­ders of data pro­ce­s­sing ser­vices and increa­se legal cer­tain­ty as regards the con­di­ti­ons for swit­ching to other data pro­ce­s­sing ser­vices. In this con­text, users and pro­vi­ders of data pro­ce­s­sing ser­vices should con­sider using the stan­dard con­trac­tu­al clau­ses or other self-regu­la­to­ry com­pli­ance tools, pro­vi­ded that they meet the requi­re­ments of this Regu­la­ti­on, deve­lo­ped by rele­vant bodies or expert groups estab­lished under Uni­on law.
(1) The rights of the cus­to­mer and the obli­ga­ti­ons of the pro­vi­der of data pro­ce­s­sing ser­vices in rela­ti­on to swit­ching bet­ween pro­vi­ders of such ser­vices or, whe­re appli­ca­ble, to an ICT infras­truc­tu­re on its own pre­mi­ses shall be cle­ar­ly set out in a writ­ten con­tract. The pro­vi­der of data pro­ce­s­sing ser­vices shall make this con­tract available to the cus­to­mer befo­re the con­tract is signed in such a way that the cus­to­mer can save and repro­du­ce the contract. 
(2) Wit­hout pre­ju­di­ce to Direc­ti­ve (EU) 2019/770, the con­tract refer­red to in para­graph 1 of this Artic­le shall include at least the fol­lo­wing
a) clau­ses enab­ling the cus­to­mer to switch to a data pro­ce­s­sing ser­vice offe­red by ano­ther data pro­ce­s­sing ser­vice pro­vi­der upon request or to trans­fer all exporta­ble data and digi­tal assets to an ICT infras­truc­tu­re on its own pre­mi­ses wit­hout undue delay and in any event not later than the end of the man­da­to­ry tran­si­ti­on peri­od of no more than 30 calen­dar days from the end of the maxi­mum noti­ce peri­od refer­red to in point (d), during which peri­od the data pro­ce­s­sing ser­vice pro­vi­der shall
i) pro­vi­des the cus­to­mer and third par­ties aut­ho­ri­zed by the cus­to­mer with appro­pria­te sup­port in exe­cu­ting the bill of exchange;
ii) acts with due care to main­tain the con­ti­nui­ty of busi­ness ope­ra­ti­ons and to con­ti­n­ue the pro­vi­si­on of the con­trac­tu­al func­tions or services;
iii) cle­ar­ly infor­med of known risks to the unin­ter­rupt­ed pro­vi­si­on of the func­tions or ser­vices that can be tra­ced back to the ori­gi­nal pro­vi­der of the data pro­ce­s­sing services;
iv) ensu­res a high level of secu­ri­ty during the swit­ching pro­cess, in par­ti­cu­lar the secu­ri­ty of the data during their trans­mis­si­on and the con­ti­nuous secu­ri­ty of the data during the peri­od of access refer­red to in point (g), in accordance with appli­ca­ble Uni­on or natio­nal law;
b) the obli­ga­ti­on of the pro­vi­der of data pro­ce­s­sing ser­vices to sup­port the customer’s exit stra­tegy rele­vant to the con­trac­ted ser­vices, inclu­ding by pro­vi­ding all rele­vant information;
c) a clau­se sta­ting that the con­tract is con­side­red ter­mi­na­ted and the cus­to­mer is infor­med of the ter­mi­na­ti­on in one of the fol­lo­wing cases:
i) if neces­sa­ry, after the chan­ge has been suc­cessful­ly completed;
ii) after expiry of the maxi­mum noti­ce peri­od spe­ci­fi­ed in let­ter d, if the cus­to­mer does not wish to switch but wis­hes to dele­te his exporta­ble data and digi­tal assets after ter­mi­na­ti­on of the service,
d) a maxi­mum noti­ce peri­od for initia­ting the chan­ge, which may not exce­ed two months;
e) an exhaus­ti­ve list of all cate­go­ries of data and digi­tal assets that may be trans­fer­red during the bill exe­cu­ti­on, inclu­ding at least all exporta­ble data;
f) an exhaus­ti­ve list of the cate­go­ries of data spe­ci­fic to the inter­nal func­tio­ning of the provider’s data pro­ce­s­sing ser­vice that are exempt­ed from the exporta­ble data refer­red to in point (e) of this para­graph whe­re the­re is a risk of a breach of the provider’s busi­ness secrets, pro­vi­ded that such exemp­ti­ons do not hin­der or delay the swit­ching refer­red to in point (c) of Artic­le 23;
g) a mini­mum peri­od for data retrie­val of at least 30 calen­dar days start­ing after the end of the tran­si­ti­on peri­od agreed bet­ween the cus­to­mer and the data pro­ce­s­sing ser­vices pro­vi­der in accordance with point (a) of this para­graph and para­graph 4;
h) a clau­se gua­ran­te­e­ing that all exporta­ble data and digi­tal assets gene­ra­ted direct­ly by the cus­to­mer or rela­ting direct­ly to the cus­to­mer will be com­ple­te­ly dele­ted after the expiry of the call peri­od refer­red to in point (g) or after the expiry of an agreed alter­na­ti­ve peri­od at a later date than the expi­ra­ti­on date of the call peri­od refer­red to in point (g), pro­vi­ded that the switch has been suc­cessful­ly completed;
i) swit­ching fees that may be char­ged by pro­vi­ders of data pro­ce­s­sing ser­vices in accordance with Artic­le 29.
(3) The con­tract refer­red to in para­graph 1 shall include clau­ses allo­wing the cus­to­mer to inform the data pro­ce­s­sing ser­vices pro­vi­der of its decis­i­on to take one or more of the fol­lo­wing actions after the expiry of the maxi­mum noti­ce peri­od refer­red to in para­graph 2(d):
a) Chan­ge to ano­ther pro­vi­der of data pro­ce­s­sing ser­vices, in which case the cus­to­mer shall pro­vi­de the neces­sa­ry infor­ma­ti­on about this provider;
b) Switch to an ICT infras­truc­tu­re on your own premises;
c) Dele­ti­on of its exporta­ble data and digi­tal assets.
(4) Whe­re the man­da­to­ry maxi­mum tran­si­ti­on peri­od refer­red to in point (a) of para­graph 2 is not tech­ni­cal­ly fea­si­ble, the pro­vi­der of data pro­ce­s­sing ser­vices shall noti­fy the cus­to­mer within 14 working days of the request for swit­ching, duly justi­fy­ing the tech­ni­cal imprac­ti­ca­bi­li­ty and indi­ca­ting an alter­na­ti­ve tran­si­ti­on peri­od, which shall not exce­ed seven months. In accordance with para­graph 1, con­ti­nui­ty of ser­vice shall be ensu­red during the alter­na­ti­ve tran­si­ti­on peri­od, whe­re applicable. 
(87) Data pro­ce­s­sing ser­vices are used in dif­fe­rent are­as and dif­fer in terms of their com­ple­xi­ty and type of ser­vice. This must be taken into account in par­ti­cu­lar with regard to the trans­fer pro­cess and the cor­re­spon­ding time frame. Howe­ver, it should only be pos­si­ble to cla­im an exten­si­on of the tran­si­tio­nal peri­od if the switch can­not be com­ple­ted within the envi­sa­ged time for tech­ni­cal rea­sons in duly justi­fi­ed cases. The bur­den of pro­of in this respect should lie enti­re­ly with the pro­vi­der of the data pro­ce­s­sing ser­vice con­cer­ned. This is wit­hout pre­ju­di­ce to the customer’s exclu­si­ve right to extend the tran­si­ti­on peri­od once for a peri­od that it deems more appro­pria­te for its own pur­po­ses. The cus­to­mer may invo­ke this right of exten­si­on befo­re or during the tran­si­ti­on peri­od, taking into account that the con­tract will con­ti­n­ue to app­ly during the tran­si­ti­on period.
(5) Wit­hout pre­ju­di­ce to para­graph 4, the con­tract refer­red to in para­graph 1 shall con­tain clau­ses wher­eby the cus­to­mer shall be entit­led to extend the tran­si­tio­nal peri­od once by a peri­od which it con­siders more appro­pria­te for its own purposes.
Artic­le 26 Infor­ma­ti­on obli­ga­ti­on of data pro­ce­s­sing ser­vice providers
The pro­vi­der of data pro­ce­s­sing ser­vices shall pro­vi­de the cus­to­mer with the fol­lo­wing:
a) Infor­ma­ti­on about the available pro­ce­du­res for swit­ching and trans­fer­ring con­tent to the data pro­ce­s­sing ser­vice, inclu­ding infor­ma­ti­on about available swit­ching and trans­fer methods and for­mats, as well as limi­ta­ti­ons and tech­ni­cal rest­ric­tions known to the data pro­ce­s­sing ser­vice provider;
b) a refe­rence to an up-to-date online regi­ster of data pro­ce­s­sing ser­vice pro­vi­ders with details of all data struc­tures and data for­mats as well as the rele­vant stan­dards and open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons in which the exporta­ble data descri­bed in Artic­le 25(2)(e) are available.
(95) The infor­ma­ti­on that data pro­ce­s­sing ser­vice pro­vi­ders must pro­vi­de to cus­to­mers could sup­port cus­to­mers’ exit stra­tegy. The infor­ma­ti­on should include the fol­lo­wing: Pro­ce­du­res for initia­ting the switch from the data pro­ce­s­sing ser­vice, the machi­ne-rea­da­ble data for­mats to which the user data can be expor­ted, the tools for data export – inclu­ding open inter­faces – and infor­ma­ti­on on com­pa­ti­bi­li­ty with har­mo­ni­zed stan­dards or com­mon spe­ci­fi­ca­ti­ons based on open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons, infor­ma­ti­on on known tech­ni­cal limi­ta­ti­ons and cons­traints that could affect the com­ple­ti­on of the switch, and the esti­ma­ted time requi­red to com­ple­te the switch.
Artic­le 27 Obli­ga­ti­on to act in good faith
All par­ties invol­ved, inclu­ding the acqui­ring data pro­ce­s­sing ser­vice pro­vi­ders, shall coope­ra­te in good faith to ensu­re that the chan­ge is car­ri­ed out effec­tively, that data can be trans­fer­red in a time­ly man­ner and that the con­ti­nui­ty of the data pro­ce­s­sing ser­vice is maintained.
(97) In order to faci­li­ta­te the swit­ching bet­ween data pro­ce­s­sing ser­vices, all par­ties invol­ved, inclu­ding the initi­al and the acqui­ring data pro­ce­s­sing ser­vice pro­vi­der, should coope­ra­te in good faith to make the switch effec­ti­ve and to enable the secu­re and time­ly trans­fer of the neces­sa­ry data in a com­mon­ly used, machi­ne-rea­da­ble for­mat via an open inter­face, while main­tai­ning ser­vice continuity.
Artic­le 28 Con­trac­tu­al trans­pa­ren­cy obli­ga­ti­ons regar­ding access and trans­fer in the inter­na­tio­nal environment
(1) Pro­vi­ders of data pro­ce­s­sing ser­vices make the fol­lo­wing infor­ma­ti­on available on their web­sites and keep this infor­ma­ti­on up to date:
a) the juris­dic­tion to which the ICT infras­truc­tu­re set up for the data pro­ce­s­sing of the pro­vi­ders’ indi­vi­du­al ser­vices is subject;
b) a gene­ral descrip­ti­on of the tech­ni­cal, orga­nizatio­nal and con­trac­tu­al mea­su­res taken by the data pro­ce­s­sing ser­vice pro­vi­der to pre­vent inter­na­tio­nal public access to or inter­na­tio­nal public trans­fer of non-per­so­nal data stored in the Uni­on whe­re such access or trans­fer would be con­tra­ry to Uni­on or natio­nal law of the Mem­ber Sta­te concerned.
(2) The web­sites refer­red to in para­graph 1 shall be listed in the con­tract for all data pro­ce­s­sing ser­vices offe­red by pro­vi­ders of data pro­ce­s­sing services.
Artic­le 29 Pro­gres­si­ve aboli­ti­on of exch­an­ge fees
(1) From Janu­ary 12, 2027, pro­vi­ders of data pro­ce­s­sing ser­vices may no lon­ger char­ge swit­ching fees for the com­ple­ti­on of the chan­ge of provider. 
(2) From Janu­ary 11, 2024 to Janu­ary 12, 2027, pro­vi­ders of data pro­ce­s­sing ser­vices may char­ge cus­to­mers redu­ced swit­ching fees for com­ple­ting the switch. 
(3) The redu­ced swit­ching fees refer­red to in para­graph 2 may not exce­ed the costs incur­red by the pro­vi­der of data pro­ce­s­sing ser­vices in direct con­nec­tion with the swit­ching in question. 
(89) The initi­al pro­vi­der of data pro­ce­s­sing ser­vices should be able to out­sour­ce cer­tain tasks and to com­pen­sa­te third par­ties for the per­for­mance of the obli­ga­ti­ons laid down in this Regu­la­ti­on. The costs of the out­sour­cing of ser­vices deci­ded by the initi­al pro­vi­der of data pro­ce­s­sing ser­vices during the exe­cu­ti­on of the migra­ti­on should not be bor­ne by the cus­to­mer and tho­se costs should be con­side­red unju­sti­fi­ed, unless they cover ser­vices pro­vi­ded by the pro­vi­der of data pro­ce­s­sing ser­vices at the request of the cus­to­mer for addi­tio­nal assi­stance in the migra­ti­on that go bey­ond the obli­ga­ti­ons of the pro­vi­der in the migra­ti­on expli­ci­t­ly laid down in this Regu­la­ti­on. This Regu­la­ti­on does not pre­vent cus­to­mers from pro­vi­ding con­side­ra­ti­on to third par­ties for assi­stance in the migra­ti­on pro­cess or pre­vent par­ties from ente­ring into fixed-term con­tracts for data pro­ce­s­sing ser­vices, inclu­ding pro­por­tio­na­te pen­al­ties for ear­ly ter­mi­na­ti­on of tho­se con­tracts, in accordance with Uni­on or natio­nal law. In order to pro­mo­te com­pe­ti­ti­on, the pha­sing out of char­ges rela­ted to the swit­ching of data pro­ce­s­sing ser­vices should in par­ti­cu­lar include the aboli­ti­on of data extra­c­tion char­ges levied by a pro­vi­der of data pro­ce­s­sing ser­vices on the cus­to­mer. Stan­dard ser­vice char­ges for the pro­vi­si­on of the data pro­ce­s­sing ser­vices them­sel­ves are not swit­ching char­ges. The­se stan­dard ser­vice char­ges shall not be revo­ca­ble and shall app­ly until the con­tract for the pro­vi­si­on of the ser­vice con­cer­ned cea­ses to app­ly. Cus­to­mers may request the pro­vi­si­on of addi­tio­nal ser­vices under this Regu­la­ti­on which go bey­ond the provider’s obli­ga­ti­ons under this Regu­la­ti­on when swit­ching. The­se addi­tio­nal ser­vices may be pro­vi­ded and invoi­ced by the pro­vi­der if they are pro­vi­ded at the customer’s request and the cus­to­mer agrees to the pri­ce of the­se ser­vices in advance.
(4) Befo­re ente­ring into a con­tract with a cus­to­mer, pro­vi­ders of data pro­ce­s­sing ser­vices shall cle­ar­ly inform the poten­ti­al cus­to­mer of the stan­dard ser­vice char­ges that may be levied and the pen­al­ties that may be impo­sed for ear­ly ter­mi­na­ti­on, as well as of the redu­ced swit­ching char­ges that may be levied during the time­frame refer­red to in para­graph 2. 
(5) Data pro­ce­s­sing ser­vice pro­vi­ders may pro­vi­de a cus­to­mer with infor­ma­ti­on about data pro­ce­s­sing ser­vices that makes swit­ching very com­pli­ca­ted or cost­ly or impos­si­ble wit­hout signi­fi­cant inter­ven­ti­on in the data, digi­tal assets or ser­vice architecture. 
(6) Pro­vi­ders of data pro­ce­s­sing ser­vices shall publish the infor­ma­ti­on refer­red to in para­graphs 4 and 5 for cus­to­mers on a sepa­ra­te sec­tion of their web­site or in ano­ther easi­ly acce­s­si­ble man­ner, whe­re appropriate. 
(7) The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 45 to sup­ple­ment this Regu­la­ti­on by estab­li­shing a moni­to­ring mecha­nism enab­ling the Com­mis­si­on to moni­tor the swit­ching fees char­ged by pro­vi­ders of data pro­ce­s­sing ser­vices in the mar­ket in order to ensu­re that the swit­ching fees refer­red to in para­graphs 1 and 2 of this Artic­le are abo­lished and redu­ced within the time limits set out in tho­se paragraphs.
Artic­le 30 Tech­ni­cal aspects of the bill of exchange
(94) A high level of secu­ri­ty should be main­tai­ned throug­hout the imple­men­ta­ti­on of the chan­ge. This means that the ori­gi­nal pro­vi­der of data pro­ce­s­sing ser­vices should extend the level of secu­ri­ty it has com­mit­ted to in rela­ti­on to the ser­vice to all tech­ni­cal moda­li­ties – such as net­work con­nec­tions or phy­si­cal devices – for which it is respon­si­ble during the imple­men­ta­ti­on of the switch. Exi­sting rights rela­ted to the ter­mi­na­ti­on of con­tracts, inclu­ding tho­se intro­du­ced by Regu­la­ti­on (EU) 2016/679 and Direc­ti­ve (EU) 2019/770 of the Euro­pean Par­lia­ment and of the Coun­cil (31), should remain unaf­fec­ted. This Regu­la­ti­on should not be under­s­tood as pre­ven­ting a pro­vi­der of data pro­ce­s­sing ser­vices from offe­ring new and impro­ved ser­vices, fea­tures and func­tion­a­li­ties to cus­to­mers or from com­pe­ting with other pro­vi­ders of data pro­ce­s­sing ser­vices on that basis.
(1) As regards data pro­ce­s­sing ser­vices for sca­lable and ela­stic com­pu­ting resour­ces that are limi­t­ed to infras­truc­tu­re ele­ments such as ser­vers, net­works and the vir­tu­al resour­ces neces­sa­ry for the ope­ra­ti­on of the infras­truc­tu­re, but do not pro­vi­de access to the ope­ra­tio­nal ser­vices, soft­ware and appli­ca­ti­ons stored, other­wi­se pro­ce­s­sed or used on tho­se infras­truc­tu­re ele­ments, pro­vi­ders shall take all rea­sonable mea­su­res at their dis­po­sal, in accordance with Artic­le 27, to enable the cus­to­mer to achie­ve func­tion­al equi­va­lence in the use of the acqui­ring data pro­ce­s­sing ser­vice after swit­ching to a ser­vice of the same ser­vice type. The initi­al pro­vi­der of data pro­ce­s­sing ser­vices shall faci­li­ta­te the switch by pro­vi­ding capa­ci­ty, ade­qua­te infor­ma­ti­on, docu­men­ta­ti­on, tech­ni­cal sup­port and, whe­re appro­pria­te, the neces­sa­ry tools. 
(2) Pro­vi­ders of data pro­ce­s­sing ser­vices other than tho­se refer­red to in para­graph 1 shall pro­vi­de open inter­faces free of char­ge to all their cus­to­mers and to the acqui­ring pro­vi­ders of data pro­ce­s­sing ser­vices con­cer­ned in order to enable the switch. Tho­se inter­faces shall con­tain suf­fi­ci­ent infor­ma­ti­on about the ser­vice con­cer­ned to enable the deve­lo­p­ment of the soft­ware neces­sa­ry to com­mu­ni­ca­te with the ser­vices for the pur­po­ses of data por­ta­bi­li­ty and interoperability. 
(90) An ambi­tious and inno­va­ti­on-pro­mo­ting regu­la­to­ry approach to inter­ope­ra­bi­li­ty is nee­ded to pre­vent lock-in to spe­ci­fic pro­vi­ders to the detri­ment of com­pe­ti­ti­on and the deve­lo­p­ment of new ser­vices. Inter­ope­ra­bi­li­ty bet­ween data pro­ce­s­sing ser­vices requi­res seve­ral inter­faces and infras­truc­tu­re levels as well as soft­ware and is rare­ly limi­t­ed to the simp­le que­sti­on of whe­ther it can be achie­ved or not. Rather, estab­li­shing the neces­sa­ry inter­ope­ra­bi­li­ty depends on a cost-bene­fit ana­ly­sis to deter­mi­ne whe­ther it makes sen­se to stri­ve for the rea­son­ab­ly fore­seeable results. The ISO/IEC 19941:2017 stan­dard is an important inter­na­tio­nal stan­dard that pro­vi­des an important refe­rence point for achie­ving the objec­ti­ves of this Regu­la­ti­on, as it inclu­des tech­ni­cal con­side­ra­ti­ons to cla­ri­fy the com­ple­xi­ty of such a process.
(3) For data pro­ce­s­sing ser­vices other than tho­se refer­red to in para­graph 1 of this Artic­le, data pro­ce­s­sing ser­vice pro­vi­ders shall ensu­re com­pa­ti­bi­li­ty with com­mon spe­ci­fi­ca­ti­ons based on open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons or har­mo­ni­zed inter­ope­ra­bi­li­ty stan­dards at least 12 months after the refe­ren­ces to tho­se com­mon inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons or har­mo­ni­zed inter­ope­ra­bi­li­ty stan­dards for data pro­ce­s­sing ser­vices have been published in the cen­tral Uni­on data­ba­se for stan­dards for data pro­ce­s­sing ser­vices in accordance with Artic­le 35(8), fol­lo­wing the publi­ca­ti­on of the under­ly­ing imple­men­ting acts in the Offi­ci­al Jour­nal of the Euro­pean Union. 
(4) Pro­vi­ders of data pro­ce­s­sing ser­vices other than tho­se refer­red to in para­graph 1 of this Artic­le shall update the online regi­ster refer­red to in point (b) of Artic­le 26 in accordance with their obli­ga­ti­ons under para­graph 3 of this Article. 
(5) In the case of swit­ching bet­ween ser­vices of the same type of ser­vice for which no com­mon spe­ci­fi­ca­ti­ons or the har­mo­ni­zed stan­dards for inter­ope­ra­bi­li­ty refer­red to in para­graph 3 of this Artic­le have been published in the cen­tral Uni­on data­ba­se for inter­ope­ra­bi­li­ty of data pro­ce­s­sing ser­vices refer­red to in Artic­le 35(8), the pro­vi­der of the data pro­ce­s­sing ser­vices shall, at the request of the cus­to­mer, export all exporta­ble data in a struc­tu­red, com­mon­ly used and machi­ne-rea­da­ble format. 
(6) Pro­vi­ders of data pro­ce­s­sing ser­vices are not obli­ga­ted to deve­lop new tech­no­lo­gies or ser­vices or to dis­c­lo­se digi­tal assets pro­tec­ted by intellec­tu­al pro­per­ty rights or con­sti­tu­ting a trade secret to a cus­to­mer or ano­ther pro­vi­der of data pro­ce­s­sing ser­vices or to com­pro­mi­se the secu­ri­ty and inte­gri­ty of the cus­to­mer or provider.
Artic­le 31 Spe­ci­fic regime for cer­tain data pro­ce­s­sing services
(1) The obli­ga­ti­ons laid down in Artic­le 23(d), Artic­le 29 and Artic­le 30(1) and (3) shall not app­ly to data pro­ce­s­sing ser­vices whe­re most of the core func­tion­a­li­ties have been tail­o­red to the spe­ci­fic needs of a sin­gle cus­to­mer or whe­re all com­pon­ents have been deve­lo­ped for the pur­po­ses of a sin­gle cus­to­mer and whe­re tho­se data pro­ce­s­sing ser­vices are not offe­red on a wider com­mer­cial sca­le through the ser­vice cata­log of data pro­ce­s­sing ser­vice providers. 
(98) Data pro­ce­s­sing ser­vices for ser­vices whe­re most of the main fea­tures are spe­ci­fi­cal­ly tail­o­red to the spe­ci­fic requi­re­ments of a sin­gle cus­to­mer or whe­re all com­pon­ents have been deve­lo­ped for the pur­po­ses of a sin­gle cus­to­mer should be exempt­ed from some of the obli­ga­ti­ons appli­ca­ble to swit­ching bet­ween data pro­ce­s­sing ser­vices. Ser­vices offe­red by the pro­vi­der of data pro­ce­s­sing ser­vices through its cata­log of ser­vices on a lar­ge com­mer­cial sca­le should not be inclu­ded. It is one of the obli­ga­ti­ons of the pro­vi­der of data pro­ce­s­sing ser­vices to duly inform poten­ti­al cus­to­mers of such ser­vices of tho­se obli­ga­ti­ons laid down in this Regu­la­ti­on which do not app­ly to the ser­vices con­cer­ned befo­re the con­clu­si­on of a con­tract. The pro­vi­der of data pro­ce­s­sing ser­vices is not pre­ven­ted from even­tual­ly laun­ching such ser­vices on a lar­ge sca­le, in which case it would, howe­ver, have to com­ply with all obli­ga­ti­ons for swit­ching laid down in this Regulation.
(2) The obli­ga­ti­ons set out in this chap­ter do not app­ly to data pro­ce­s­sing ser­vices that are not pro­vi­ded as a full ver­si­on, but for test­ing and eva­lua­ti­on pur­po­ses and for a limi­t­ed peri­od of time. 
(3) Befo­re ente­ring into a con­tract for the pro­vi­si­on of the data pro­ce­s­sing ser­vices refer­red to in this Artic­le, the data pro­ce­s­sing ser­vices pro­vi­der shall inform the pro­s­pec­ti­ve cli­ent of the obli­ga­ti­ons under this Chap­ter that do not apply.

Chap­ter VII Unlawful govern­ment access to and unlawful govern­ment trans­fer of non-per­so­nal data in an inter­na­tio­nal context

Artic­le 32 Sta­te access and trans­mis­si­on in an inter­na­tio­nal context
(1) Wit­hout pre­ju­di­ce to para­graphs 2 or 3, data pro­ce­s­sing ser­vice pro­vi­ders shall take all appro­pria­te tech­ni­cal, orga­nizatio­nal and legal mea­su­res, inclu­ding con­tracts, to pre­vent sta­te access to and trans­fer of non-per­so­nal data stored in the Uni­on in the inter­na­tio­nal envi­ron­ment and by third count­ries whe­re this would be con­tra­ry to Uni­on law or the natio­nal law of the Mem­ber Sta­te concerned. 
(2) Any decis­i­on or judgment of a court of a third coun­try and any decis­i­on of an admi­ni­stra­ti­ve aut­ho­ri­ty of a third coun­try requi­ring data pro­ce­s­sing ser­vice pro­vi­ders to trans­fer or grant access to non-per­so­nal data fal­ling within the scope of this Regu­la­ti­on shall, irre­spec­ti­ve of the man­ner in which it is given, be reco­gnized or enforceable only if it is based on a legal­ly bin­ding inter­na­tio­nal agree­ment, such as a mutu­al legal assi­stance agree­ment bet­ween the reque­st­ing third coun­try and the Uni­on or such an agree­ment bet­ween the reque­st­ing third coun­try and a Mem­ber State. 
(3) In the absence of an inter­na­tio­nal agree­ment as refer­red to in para­graph 2, whe­re a data pro­ce­s­sing ser­vice pro­vi­der is sub­ject to a decis­i­on of a court or tri­bu­nal of a third coun­try or a decis­i­on of an admi­ni­stra­ti­ve aut­ho­ri­ty of a third coun­try requi­ring the trans­fer of or access to non-per­so­nal data stored in the Uni­on cover­ed by this Regu­la­ti­on, and the addres­see of such a decis­i­on or judgment would, in the event of sub­se­quent per­for­mance, be in breach of Uni­on or natio­nal law of the Mem­ber Sta­te con­cer­ned, the trans­fer of or access to such data to or for the third coun­try aut­ho­ri­ty con­cer­ned shall take place only if
a) the legal system of the third coun­try requi­res the decis­i­on or judgment to be rea­so­ned and pro­por­tio­na­te and pro­vi­des that the decis­i­on or judgment must be suf­fi­ci­ent­ly spe­ci­fic, for exam­p­le by making suf­fi­ci­ent refe­rence to spe­ci­fic suspec­ted per­sons or infringements,
b) the addressee’s rea­so­ned objec­tion is review­ed by a com­pe­tent court of the third coun­try, and
c) the com­pe­tent court of the third coun­try issuing the decis­i­on or judgment or revie­w­ing the decis­i­on of an admi­ni­stra­ti­ve aut­ho­ri­ty has the power under the law of that third coun­try to take due account of the rele­vant legal inte­rests of the pro­vi­der of the data pro­tec­ted by Uni­on or natio­nal law of the Mem­ber Sta­te concerned.
The addres­see of the decis­i­on or judgment may seek the opi­ni­on of the com­pe­tent natio­nal body or aut­ho­ri­ty respon­si­ble for inter­na­tio­nal coope­ra­ti­on in judi­cial mat­ters to deter­mi­ne whe­ther the con­di­ti­ons laid down in the first sub­pa­ra­graph are met, in par­ti­cu­lar if it con­siders that the decis­i­on may con­cern busi­ness secrets and other sen­si­ti­ve com­mer­cial infor­ma­ti­on and con­tent pro­tec­ted by intellec­tu­al pro­per­ty rights or that the trans­mis­si­on could allow for re-iden­ti­fi­ca­ti­on. The com­pe­tent natio­nal body or aut­ho­ri­ty may con­sult the Com­mis­si­on. If the addres­see con­siders that the decis­i­on or judgment could affect the natio­nal secu­ri­ty or defen­se inte­rests of the Uni­on or its Mem­ber Sta­tes, it shall seek the opi­ni­on of the rele­vant natio­nal body or aut­ho­ri­ty to deter­mi­ne whe­ther the data reque­sted con­cern the natio­nal secu­ri­ty or defen­se inte­rests of the Uni­on or its Mem­ber Sta­tes. If the addres­see has not recei­ved a rep­ly within one month or if such a body or aut­ho­ri­ty con­clu­des in its opi­ni­on that the con­di­ti­ons laid down in the first sub­pa­ra­graph are not met, the addres­see may refu­se the request for the trans­fer of or access to non-per­so­nal data on tho­se grounds.
The EDIB refer­red to in Artic­le 42 shall advi­se and assist the Com­mis­si­on in the deve­lo­p­ment of gui­de­lines for the assess­ment of whe­ther the con­di­ti­ons refer­red to in the first sub­pa­ra­graph of this para­graph are met.
(4) Whe­re the con­di­ti­ons set out in para­graph 2 or 3 are met, the pro­vi­der of data pro­ce­s­sing ser­vices shall pro­vi­de the mini­mum amount of data per­mit­ted in respon­se to the request, based on a rea­sonable inter­pre­ta­ti­on of that request by the pro­vi­der or the rele­vant natio­nal body or aut­ho­ri­ty refer­red to in the second sub­pa­ra­graph of para­graph 3. 
(5) The pro­vi­der of data pro­ce­s­sing ser­vices shall inform the cus­to­mer that a request for access to its data has been made by an aut­ho­ri­ty of a third coun­try befo­re ful­fil­ling the request, except in cases whe­re the request is for law enforce­ment pur­po­ses and is neces­sa­ry to ensu­re the effec­ti­ve­ness of law enforce­ment measures. 
(101) Third count­ries may adopt laws, regu­la­ti­ons and other legal acts aimed at ensu­ring that non-per­so­nal data stored out­side their bor­ders, inclu­ding in the Uni­on, can be trans­fer­red or that public aut­ho­ri­ties have direct access to such data. Court judgments or decis­i­ons issued in third count­ries by other judi­cial or admi­ni­stra­ti­ve aut­ho­ri­ties, inclu­ding law enforce­ment aut­ho­ri­ties, reque­st­ing such trans­fer of or access to non-per­so­nal data should be enforceable if they are based on an inter­na­tio­nal agree­ment, such as a mutu­al legal assi­stance trea­ty, exi­sting bet­ween the reque­st­ing third coun­try and the Uni­on or a Mem­ber Sta­te. It may also some­ti­mes be the case that the obli­ga­ti­on to trans­fer or grant access to non-per­so­nal data ari­sing from the law of a third coun­try con­flicts with an obli­ga­ti­on to pro­tect such data under Uni­on law or the natio­nal law of the Mem­ber Sta­te con­cer­ned, in par­ti­cu­lar as regards the pro­tec­tion of indi­vi­du­als’ fun­da­men­tal rights, such as the right to secu­ri­ty and the right to an effec­ti­ve reme­dy, or the fun­da­men­tal inte­rests of a Mem­ber Sta­te rela­ting to natio­nal secu­ri­ty or defen­se, as well as the pro­tec­tion of sen­si­ti­ve com­mer­cial data, inclu­ding the pro­tec­tion of trade secrets, and the pro­tec­tion of intellec­tu­al pro­per­ty rights, inclu­ding con­trac­tu­al con­fi­den­tia­li­ty obli­ga­ti­ons under such law. In the absence of an inter­na­tio­nal agree­ment regu­la­ting the­se issues, the trans­fer of or access to non-per­so­nal data should only be allo­wed if it has been veri­fi­ed that the legal system of the third coun­try con­cer­ned pro­vi­des for the justi­fi­ca­ti­on and pro­por­tio­na­li­ty and the suf­fi­ci­ent pre­cis­i­on of the judi­cial order or decis­i­on and allo­ws the addres­see to sub­mit its rea­so­ned objec­tion for review by the com­pe­tent court of the third coun­try, which is empowered to take due account of the rele­vant legal inte­rests of the pro­vi­der of the data. Whe­re pos­si­ble, the pro­vi­der of data pro­ce­s­sing ser­vices should be able to inform the cus­to­mer who­se data are reque­sted in the con­text of the data access request of the third-coun­try aut­ho­ri­ty befo­re gran­ting access to tho­se data in order to veri­fy whe­ther such access may be in breach of Uni­on or natio­nal law, such as that on the pro­tec­tion of sen­si­ti­ve com­mer­cial data, inclu­ding the pro­tec­tion of trade secrets and intellec­tu­al pro­per­ty rights and con­trac­tu­al con­fi­den­tia­li­ty obligations.
(102) In order to fur­ther streng­then trust in data, it is important that safe­guards to ensu­re that Uni­on citi­zens, public aut­ho­ri­ties and busi­nesses have con­trol over their data are imple­men­ted as far as pos­si­ble. In addi­ti­on, Uni­on law, values and stan­dards should be upheld, inclu­ding in rela­ti­on to secu­ri­ty, data pro­tec­tion, pri­va­cy and con­su­mer pro­tec­tion. In order to pre­vent unlawful govern­ment access to non-per­so­nal data by the aut­ho­ri­ties of third count­ries, pro­vi­ders of data pro­ce­s­sing ser­vices sub­ject to this Regu­la­ti­on, such as cloud and edge ser­vices, should take all rea­sonable mea­su­res to pre­vent access to systems whe­re non-per­so­nal data is stored, inclu­ding, whe­re appro­pria­te, by encryp­ting data, con­duc­ting fre­quent audits, veri­fy­ing com­pli­ance with rele­vant secu­ri­ty cer­ti­fi­ca­ti­on sche­mes and amen­ding com­pa­ny policies.

Chap­ter VIII Interoperability

Artic­le 33 Essen­ti­al requi­re­ments for inter­ope­ra­bi­li­ty of data, data sha­ring mecha­nisms and ser­vices and com­mon Euro­pean data spaces
(1) Par­ti­ci­pan­ts in data spaces offe­ring data or data ser­vices to other par­ti­ci­pan­ts shall com­ply with the fol­lo­wing essen­ti­al requi­re­ments to faci­li­ta­te the inter­ope­ra­bi­li­ty of data, data sha­ring mecha­nisms and ser­vices, and com­mon Euro­pean data spaces, which are pur­po­se- or sec­tor-spe­ci­fic or cross-sec­tor inter­ope­ra­ble frame­works for com­mon stan­dards and pro­ce­du­res for the sha­ring or joint pro­ce­s­sing of data, inclu­ding for the deve­lo­p­ment of new pro­ducts and ser­vices, sci­en­ti­fic rese­arch or civil socie­ty initia­ti­ves:
a) Data set con­tent, rest­ric­tions on use, licen­ses, data coll­ec­tion methods, data qua­li­ty and uncer­tain­ties are suf­fi­ci­ent­ly descri­bed – in machi­ne-rea­da­ble for­mat whe­re appro­pria­te – to enable the reci­pi­ent to loca­te, access and use the data;
b) the data struc­tures, data for­mats, voca­bu­la­ries, clas­si­fi­ca­ti­on systems, taxo­no­mies and code lists, whe­re available, are descri­bed in a publicly available and stan­dar­di­zed manner;
c) the tech­ni­cal means for data access, such as appli­ca­ti­on pro­gramming inter­faces, as well as their con­di­ti­ons of use and qua­li­ty of ser­vice are suf­fi­ci­ent­ly descri­bed to allow auto­ma­tic data access and trans­mis­si­on bet­ween the par­ties, inclu­ding on a con­ti­nuous basis, in bulk down­load or in real time in a machi­ne-rea­da­ble for­mat, pro­vi­ded that this is tech­ni­cal­ly fea­si­ble and does not inter­fe­re with the pro­per func­tio­ning of the net­work­ed product;
d) whe­re appro­pria­te, pro­vi­de the means to enable the inter­ope­ra­bi­li­ty of tools for the auto­ma­ti­on of the exe­cu­ti­on of data sha­ring con­tracts, such as smart contracts.
The requi­re­ments may be of a gene­ral natu­re or rela­te to spe­ci­fic sec­tors, but must take full account of inter­ac­tions with requi­re­ments under other Uni­on or natio­nal law. 
(2) The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 45 of this Regu­la­ti­on sup­ple­men­ting this Regu­la­ti­on by fur­ther spe­ci­fy­ing the essen­ti­al requi­re­ments laid down in para­graph 1 of this Artic­le, in respect of tho­se requi­re­ments which, by their natu­re, can­not have the inten­ded effect unless they are fur­ther spe­ci­fi­ed in bin­ding Uni­on acts, and with a view to taking due account of tech­no­lo­gi­cal and mar­ket developments.
The Com­mis­si­on shall take into account the advice of the EDIB refer­red to in Artic­le 42(c) when adop­ting dele­ga­ted acts. 
(3) Par­ti­ci­pan­ts in data spaces pro­vi­ding data or data ser­vices to other par­ti­ci­pan­ts in data spaces which com­ply in who­le or in part with har­mo­ni­zed stan­dards the refe­ren­ces of which are published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on shall be pre­su­med to com­ply with the essen­ti­al requi­re­ments set out in para­graph 1 in so far as tho­se requi­re­ments are cover­ed by tho­se har­mo­ni­zed stan­dards or parts of tho­se har­mo­ni­zed standards. 
(4) The Com­mis­si­on shall, in accordance with Artic­le 10 of Regu­la­ti­on (EU) No 1025/2012, man­da­te one or more Euro­pean stan­dar­dizati­on bodies to deve­lop draft har­mo­ni­zed stan­dards that meet the essen­ti­al requi­re­ments set out in para­graph 1 of this Article. 
(5) The Com­mis­si­on may, by means of imple­men­ting acts, adopt com­mon spe­ci­fi­ca­ti­ons cove­ring some or all of the essen­ti­al requi­re­ments set out in para­graph 1, pro­vi­ded that the fol­lo­wing con­di­ti­ons are met:
a) In accordance with Artic­le 10(1) of Regu­la­ti­on (EU) No 1025/2012, the Com­mis­si­on has given a man­da­te to one or more Euro­pean stan­dar­dizati­on bodies to deve­lop a har­mo­ni­zed stan­dard that satis­fies the essen­ti­al requi­re­ments set out in para­graph 1 of this Artic­le; and
i) the order was eit­her not accepted,
ii) the har­mo­ni­zed stan­dards for this con­tract have not been sub­mit­ted within the time limit set in accordance with Artic­le 10(1) of Regu­la­ti­on (EU) No 1025/2012, or
iii) the har­mo­ni­zed stan­dards do not ful­fill the man­da­te, and
b) no refe­rence has been published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on in accordance with Regu­la­ti­on (EU) No 1025/2012 for the har­mo­ni­zed stan­dards cove­ring the rele­vant essen­ti­al requi­re­ments set out in para­graph 1 of this Artic­le, and no such refe­rence is expec­ted to be published within a rea­sonable peri­od of time.
Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 46(2).
(6) Befo­re pre­pa­ring a draft imple­men­ting act refer­red to in para­graph 5 of this Artic­le, the Com­mis­si­on shall inform the Com­mit­tee refer­red to in Artic­le 22 of Regu­la­ti­on (EU) No 1025/2012 that it con­siders that the con­di­ti­ons set out in para­graph 5 of this Artic­le are met. 
(7) When pre­pa­ring the draft imple­men­ting act refer­red to in para­graph 5, the Com­mis­si­on shall take into account the advice of the EDIB and the views of other rele­vant bodies or expert groups and shall duly con­sult all rele­vant stakeholders. 
(8) Par­ti­ci­pan­ts in data spaces that pro­vi­de data or data ser­vices to other par­ti­ci­pan­ts in data spaces that com­ply in who­le or in part with the com­mon spe­ci­fi­ca­ti­ons estab­lished in accordance with the imple­men­ting acts refer­red to in para­graph 5 shall be pre­su­med to com­ply with the essen­ti­al requi­re­ments laid down in para­graph 1 to the ext­ent that tho­se requi­re­ments are cover­ed in who­le or in part by tho­se com­mon specifications. 
(9) Whe­re a har­mo­ni­zed stan­dard is adopted by a Euro­pean stan­dar­dizati­on orga­ni­sa­ti­on and pro­po­sed to the Com­mis­si­on for the pur­po­se of publi­ca­ti­on of its refe­rence in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, the Com­mis­si­on shall assess the har­mo­ni­zed stan­dard in accordance with Regu­la­ti­on (EU) No 1025/2012. Whe­re the refe­rence of a har­mo­ni­zed stan­dard is published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, the imple­men­ting acts refer­red to in para­graph 5 of this Artic­le which cover the same essen­ti­al requi­re­ments as tho­se cover­ed by that har­mo­ni­zed stan­dard shall be repea­led, in who­le or in part, by the Commission. 
(10) Whe­re a Mem­ber Sta­te con­siders that a com­mon spe­ci­fi­ca­ti­on does not enti­re­ly satis­fy the essen­ti­al requi­re­ments laid down in para­graph 1, it shall inform the Com­mis­si­on the­reof by means of a detail­ed expl­ana­ti­on. The Com­mis­si­on shall assess the detail­ed expl­ana­ti­on and may, whe­re appro­pria­te, amend the imple­men­ting act which estab­lished the com­mon spe­ci­fi­ca­ti­on in question. 
(11) The Com­mis­si­on may adopt gui­de­lines taking into account the pro­po­sal of the EDIB in accordance with Artic­le 30(h) of Regu­la­ti­on (EU) 2022/868 lay­ing down inter­ope­ra­ble frame­works for com­mon stan­dards and pro­ce­du­res for the func­tio­ning of com­mon Euro­pean data spaces.
(103) Stan­dar­dizati­on and seman­tic inter­ope­ra­bi­li­ty should play an important role in pro­vi­ding tech­ni­cal solu­ti­ons to ensu­re inter­ope­ra­bi­li­ty within and bet­ween Euro­pean com­mon data spaces, which are pur­po­se- or sec­tor-spe­ci­fic or cross-sec­to­ral inter­ope­ra­ble frame­works for com­mon stan­dards and pro­ce­du­res for the sha­ring or joint pro­ce­s­sing of data, inclu­ding for the deve­lo­p­ment of new pro­ducts and ser­vices, sci­en­ti­fic rese­arch or civil socie­ty initia­ti­ves. This Regu­la­ti­on should lay down cer­tain essen­ti­al inter­ope­ra­bi­li­ty requi­re­ments. Par­ti­ci­pan­ts in data spaces that offer data or data ser­vices to other par­ti­ci­pan­ts and that are enti­ties that faci­li­ta­te or are invol­ved in the sha­ring of data within com­mon Euro­pean data spaces, inclu­ding data hol­ders, should com­ply with tho­se requi­re­ments inso­far as they con­cern ele­ments under their con­trol. Com­pli­ance with tho­se requi­re­ments may be ensu­red by com­pli­ance with the essen­ti­al requi­re­ments laid down in this Regu­la­ti­on or pre­su­med on the basis of com­pli­ance with har­mo­ni­zed stan­dards or com­mon spe­ci­fi­ca­ti­ons in the con­text of a pre­sump­ti­on of con­for­mi­ty. In order to faci­li­ta­te com­pli­ance with the inter­ope­ra­bi­li­ty requi­re­ments, it is neces­sa­ry to pro­vi­de for a pre­sump­ti­on of con­for­mi­ty for inter­ope­ra­bi­li­ty solu­ti­ons that com­ply in who­le or in part with the har­mo­ni­zed stan­dards refer­red to in Regu­la­ti­on (EU) No 1025/2012, which con­sti­tu­tes the stan­dard frame­work for the deve­lo­p­ment of the stan­dards accor­ding to which such pre­sump­ti­ons of con­for­mi­ty are pro­vi­ded. The Com­mis­si­on should assess the bar­riers to inter­ope­ra­bi­li­ty and prio­ri­ti­ze the stan­dar­dizati­on needs so that, on that basis, it can man­da­te one or more Euro­pean stan­dar­dizati­on bodies in accordance with Regu­la­ti­on (EU) No 1025/2012 to deve­lop draft har­mo­ni­zed stan­dards that meet the essen­ti­al requi­re­ments laid down in this Regu­la­ti­on. Whe­re such man­da­tes do not result in har­mo­ni­zed stan­dards or whe­re such har­mo­ni­zed stan­dards are not suf­fi­ci­ent to ensu­re con­for­mi­ty with the essen­ti­al requi­re­ments laid down in this Regu­la­ti­on, the Com­mis­si­on should be able to adopt com­mon spe­ci­fi­ca­ti­ons in tho­se are­as, pro­vi­ded that it duly respects the role and func­tions of the stan­dar­dizati­on orga­ni­sa­ti­ons. Com­mon spe­ci­fi­ca­ti­ons should only be adopted as an excep­tio­nal fall­back solu­ti­on to faci­li­ta­te com­pli­ance with the essen­ti­al requi­re­ments of this Regu­la­ti­on, or whe­re the stan­dar­dizati­on pro­cess is blocked, or in the event of delays in the adop­ti­on of appro­pria­te har­mo­ni­zed stan­dards. Whe­re a delay is due to the tech­ni­cal com­ple­xi­ty of the stan­dard con­cer­ned, the Com­mis­si­on should take this into account befo­re con­side­ring the adop­ti­on of com­mon spe­ci­fi­ca­ti­ons. Com­mon spe­ci­fi­ca­ti­ons should be deve­lo­ped in an open and inclu­si­ve man­ner, taking into account, whe­re appro­pria­te, the advice of the Euro­pean Data Inno­va­ti­on Board (EDIB) estab­lished under Regu­la­ti­on (EU) 2022/868. In addi­ti­on, com­mon spe­ci­fi­ca­ti­ons could also be adopted in the dif­fe­rent sec­tors, based on their spe­ci­fic needs, in accordance with Uni­on or natio­nal law. In addi­ti­on, the Com­mis­si­on should be enab­led to man­da­te the deve­lo­p­ment of har­mo­ni­zed stan­dards for the inter­ope­ra­bi­li­ty of data pro­ce­s­sing services.
Artic­le 34 Inter­ope­ra­bi­li­ty for the pur­po­ses of par­al­lel use of data pro­ce­s­sing services
(1) The requi­re­ments laid down in Artic­le 23, Artic­le 24, Artic­le 25(2)(a)(ii) and (iv) and (e) and (f) and Artic­le 30(2), (3), (4) and (5) shall app­ly muta­tis mut­an­dis to pro­vi­ders of data pro­ce­s­sing ser­vices in order to faci­li­ta­te inter­ope­ra­bi­li­ty for the pur­po­ses of par­al­lel use of data pro­ce­s­sing services. 
(2) If a data pro­ce­s­sing ser­vice is used in par­al­lel with ano­ther data pro­ce­s­sing ser­vice, the pro­vi­ders of data pro­ce­s­sing ser­vices may char­ge data extra­c­tion fees, but only to pass on the extra­c­tion costs incur­red, wit­hout exce­e­ding the­se costs. 
(99) In line with the mini­mum requi­re­ment to enable swit­ching of pro­vi­ders of data pro­ce­s­sing ser­vices, this Regu­la­ti­on also aims to impro­ve inter­ope­ra­bi­li­ty for the par­al­lel use of mul­ti­ple data pro­ce­s­sing ser­vices through com­ple­men­ta­ry func­tion­a­li­ties. This con­cerns situa­tions whe­re cus­to­mers do not ter­mi­na­te a con­tract with a view to swit­ching to ano­ther pro­vi­der of data pro­ce­s­sing ser­vices, but whe­re seve­ral ser­vices from dif­fe­rent pro­vi­ders are used in par­al­lel and inter­ope­ra­b­ly in order to be able to use the com­ple­men­ta­ry func­tion­a­li­ties of the dif­fe­rent ser­vices in the customer’s system con­fi­gu­ra­ti­on. Howe­ver, in con­trast to the one-off extra­c­tion requi­red when com­ple­ting a switch, data extra­c­tion from one data pro­ce­s­sing ser­vice pro­vi­der to ano­ther with the aim of faci­li­ta­ting the par­al­lel use of ser­vices can, as is well known, be an ongo­ing pro­cess. Pro­vi­ders of data pro­ce­s­sing ser­vices should the­r­e­fo­re be able to con­ti­n­ue to char­ge data extra­c­tion fees for data extra­c­tion for the pur­po­ses of par­al­lel use after three years from the date of ent­ry into force of this Regu­la­ti­on, pro­vi­ded that tho­se fees do not exce­ed the costs incur­red. Among other things, this is important for the suc­cessful intro­duc­tion of mul­ti-cloud stra­te­gies, which enable cus­to­mers to imple­ment future-pro­of IT stra­te­gies and redu­ce depen­dence on indi­vi­du­al pro­vi­ders of data pro­ce­s­sing ser­vices. Faci­li­ta­ting a mul­ti-cloud approach for cus­to­mers of data pro­ce­s­sing ser­vices can also help to streng­then the ope­ra­tio­nal resi­li­ence of cus­to­mers’ digi­tal systems, as sta­ted in Regu­la­ti­on (EU) 2022/2554 of the Euro­pean Par­lia­ment and of the Coun­cil (32) in rela­ti­on to pro­vi­ders of finan­cial services.
Artic­le 35 Inter­ope­ra­bi­li­ty of data pro­ce­s­sing services
(1) Open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons and har­mo­ni­zed stan­dards for the inter­ope­ra­bi­li­ty of data pro­ce­s­sing ser­vices
a) ensu­re, as far as tech­ni­cal­ly fea­si­ble, inter­ope­ra­bi­li­ty bet­ween dif­fe­rent data pro­ce­s­sing ser­vices cove­ring the same type of service;
b) impro­ve the por­ta­bi­li­ty of digi­tal assets bet­ween dif­fe­rent data pro­ce­s­sing ser­vices that cover the same type of service;
c) faci­li­ta­te, as far as tech­ni­cal­ly fea­si­ble, func­tion­al equi­va­lence bet­ween the data pro­ce­s­sing ser­vices refer­red to in Artic­le 30(1) cove­ring the same type of service;
d) do not affect the secu­ri­ty and inte­gri­ty of data pro­ce­s­sing ser­vices and data;
e) are desi­gned for the pos­si­bi­li­ty of tech­ni­cal upgrades and the inte­gra­ti­on of new func­tions and inno­va­tions in data pro­ce­s­sing services.
(2) Open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons and har­mo­ni­zed stan­dards for the inter­ope­ra­bi­li­ty of data pro­ce­s­sing ser­vices shall ade­qua­te­ly address the fol­lo­wing:
a) the aspects of cloud inter­ope­ra­bi­li­ty in terms of trans­port inter­ope­ra­bi­li­ty, syn­tac­tic inter­ope­ra­bi­li­ty, seman­tic data inter­ope­ra­bi­li­ty, beha­vi­oral inter­ope­ra­bi­li­ty and the inter­ope­ra­bi­li­ty of rules and specifications;
b) the aspects of cloud data por­ta­bi­li­ty in rela­ti­on to syn­tac­tic data por­ta­bi­li­ty, seman­tic data por­ta­bi­li­ty and the por­ta­bi­li­ty of data rules;
c) the aspects of cloud appli­ca­ti­ons with regard to the syn­tac­tic por­ta­bi­li­ty of appli­ca­ti­ons, the por­ta­bi­li­ty of appli­ca­ti­on com­mands, the por­ta­bi­li­ty of appli­ca­ti­on meta­da­ta, the por­ta­bi­li­ty of appli­ca­ti­on beha­vi­or and the por­ta­bi­li­ty of appli­ca­ti­on rules.
(3) Open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons must com­ply with Annex II of Regu­la­ti­on (EU) No 1025/2012.
(4) After taking into account rele­vant inter­na­tio­nal and Euro­pean stan­dards and self-regu­la­to­ry initia­ti­ves, the Com­mis­si­on may, in accordance with Artic­le 10(1) of Regu­la­ti­on (EU) No 1025/2012, man­da­te one or more Euro­pean stan­dar­dizati­on bodies to deve­lop draft har­mo­ni­zed stan­dards that meet the essen­ti­al requi­re­ments set out in para­graphs 1 and 2 of this Article. 
(5) The Com­mis­si­on may, by means of imple­men­ting acts, adopt com­mon spe­ci­fi­ca­ti­ons based on open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons cove­ring all the essen­ti­al requi­re­ments set out in para­graphs 1 and 2 of this Article. 
(6) When pre­pa­ring the draft imple­men­ting act refer­red to in para­graph 5 of this Artic­le, the Com­mis­si­on shall take into account the views of the rele­vant com­pe­tent aut­ho­ri­ties refer­red to in point (h) of Artic­le 37(5) and other rele­vant bodies or expert groups and shall duly con­sult all rele­vant stakeholders. 
(7) Whe­re a Mem­ber Sta­te con­siders that a com­mon spe­ci­fi­ca­ti­on does not enti­re­ly satis­fy the essen­ti­al requi­re­ments refer­red to in para­graphs 1 and 2, it shall inform the Com­mis­si­on the­reof by means of a detail­ed expl­ana­ti­on. The Com­mis­si­on shall assess the detail­ed expl­ana­ti­on and may, whe­re appro­pria­te, amend the imple­men­ting act which estab­lished the com­mon spe­ci­fi­ca­ti­on concerned. 
(8) For the pur­po­ses of Artic­le 30(3), the Com­mis­si­on shall, by means of imple­men­ting acts, publish the refe­ren­ces of har­mo­ni­zed stan­dards and com­mon spe­ci­fi­ca­ti­ons for inter­ope­ra­bi­li­ty of data pro­ce­s­sing ser­vices in a cen­tral Uni­on data­ba­se of stan­dards for inter­ope­ra­bi­li­ty of data pro­ce­s­sing services. 
(9) The imple­men­ting acts refer­red to in this Artic­le shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 46(2).
(100) Open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons and stan­dards deve­lo­ped in accordance with Annex II to Regu­la­ti­on (EU) No 1025/2012 of the Euro­pean Par­lia­ment and of the Coun­cil (33) in the area of inter­ope­ra­bi­li­ty and por­ta­bi­li­ty are expec­ted to enable a mul­ti-ven­dor cloud envi­ron­ment, which is an essen­ti­al pre­re­qui­si­te for open inno­va­ti­on in the Euro­pean data eco­no­my. As the upt­ake of defi­ned stan­dards in the mar­ket under the Cloud Stan­dar­dizati­on Coor­di­na­ti­on (CSC) initia­ti­ve com­ple­ted in 2016 has been sub­dued, the Com­mis­si­on must also rely on mar­ket par­ti­ci­pan­ts to deve­lop rele­vant open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons to keep pace with the rapid tech­no­lo­gi­cal pro­gress in this indu­stry. Such open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons can then be adopted by the Com­mis­si­on in the form of com­mon spe­ci­fi­ca­ti­ons. Fur­ther­mo­re, whe­re it has not been demon­stra­ted that com­mon spe­ci­fi­ca­ti­ons or stan­dards faci­li­ta­ting effec­ti­ve cloud inter­ope­ra­bi­li­ty of the pro­ce­s­sing of data at PaaS and SaaS level can be estab­lished through mar­ket-dri­ven pro­ce­s­ses, the Com­mis­si­on should be able, on the basis of this Regu­la­ti­on and in accordance with Regu­la­ti­on (EU) No 1025/2012, to man­da­te Euro­pean stan­dar­dizati­on bodies to deve­lop such stan­dards for spe­ci­fic types of ser­vices for which such stan­dards do not yet exist. In addi­ti­on, the Com­mis­si­on will encou­ra­ge mar­ket play­ers to deve­lop rele­vant open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons. Fol­lo­wing a stake­hol­der con­sul­ta­ti­on, the Com­mis­si­on should be able, by means of imple­men­ting acts, to requi­re the use of har­mo­ni­zed inter­ope­ra­bi­li­ty stan­dards or com­mon inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons for cer­tain types of ser­vices by means of a refe­rence in a cen­tral Uni­on data­ba­se of inter­ope­ra­bi­li­ty stan­dards for data pro­ce­s­sing ser­vices. Pro­vi­ders of data pro­ce­s­sing ser­vices should ensu­re com­pa­ti­bi­li­ty with tho­se har­mo­ni­zed stan­dards and com­mon spe­ci­fi­ca­ti­ons on the basis of open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons which should not com­pro­mi­se the secu­ri­ty or inte­gri­ty of the data. Har­mo­ni­zed stan­dards for inter­ope­ra­bi­li­ty of data pro­ce­s­sing ser­vices and com­mon spe­ci­fi­ca­ti­ons based on open inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons are only refer­red to if they com­ply with the cri­te­ria set out in this Regu­la­ti­on, which have the same importance as the requi­re­ments set out in Annex II to Regu­la­ti­on (EU) No 1025/2012 and the inter­ope­ra­bi­li­ty aspects defi­ned in the inter­na­tio­nal stan­dard ISO/IEC 19941:2017. In addi­ti­on, the needs of SMEs should be taken into account in the stan­dar­dizati­on process.
Artic­le 36 Essen­ti­al requi­re­ments for smart con­tracts for the exe­cu­ti­on of data-sha­ring agreements
(1) The pro­vi­der of an appli­ca­ti­on in which smart con­tracts are used or, fai­ling that, the per­son who­se trade, busi­ness or pro­fes­si­on invol­ves the use of smart con­tracts for third par­ties in con­nec­tion with the full or par­ti­al per­for­mance of a data pro­vi­si­on agree­ment, shall ensu­re that tho­se smart con­tracts com­ply with the fol­lo­wing essen­ti­al requi­re­ments:
a) Robust­ness and access con­trol, to ensu­re that the smart con­tract has been desi­gned to pro­vi­de access con­trol mecha­nisms and a very high level of robust­ness to pre­vent mal­func­tions and resist tam­pe­ring by third parties;
b) safe ter­mi­na­ti­on and inter­rup­ti­on, to ensu­re that the­re is a mecha­nism to ter­mi­na­te fur­ther exe­cu­ti­on of tran­sac­tions and that the smart con­tract con­ta­ins inter­nal func­tions to reset the con­tract or issue an ins­truc­tion to ter­mi­na­te or inter­rupt ope­ra­ti­ons, in par­ti­cu­lar to avo­id future unin­ten­ded execution;
c) Data archi­ving and data con­ti­nui­ty, to ensu­re that in situa­tions whe­re a smart con­tract needs to be ter­mi­na­ted or deac­ti­va­ted, it is pos­si­ble to archi­ve the tran­sac­tion data, logic and pro­gram code of the smart con­tract so that the­re is a record of ope­ra­ti­ons (audi­ta­bi­li­ty) that have been per­for­med on the data in the past,
d) Access con­trol, to ensu­re that a smart con­tract is pro­tec­ted by strict access con­trol mecha­nisms at the gover­nan­ce level and the smart con­tract level, and
e) Con­si­sten­cy, to ensu­re com­pli­ance with the terms of the data sha­ring agree­ment imple­men­ted with the smart contract.
(2) The pro­vi­der of a smart con­tract or, fai­ling that, the per­son who­se trade, busi­ness or pro­fes­si­on invol­ves the use of smart con­tracts for third par­ties in con­nec­tion with an imple­men­ta­ti­on of a data sha­ring agree­ment or parts the­reof, shall car­ry out a con­for­mi­ty assess­ment with a view to mee­ting the essen­ti­al requi­re­ments set out in para­graph 1 and, whe­re tho­se requi­re­ments are met, shall draw up an EU decla­ra­ti­on of conformity. 
(3) By issuing the EU decla­ra­ti­on of con­for­mi­ty, the pro­vi­der of an appli­ca­ti­on using smart con­tracts or, fai­ling that, the per­son who­se trade, busi­ness or pro­fes­si­on invol­ves the use of smart con­tracts for third par­ties in con­nec­tion with the per­for­mance of a data pro­vi­si­on agree­ment or parts the­reof, assu­mes respon­si­bi­li­ty for ensu­ring that the essen­ti­al requi­re­ments set out in para­graph 1 are met. 
(4) A smart con­tract which is in con­for­mi­ty with har­mo­ni­zed stan­dards or the rele­vant parts the­reof, the refe­ren­ces of which are published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, shall be pre­su­med to be in con­for­mi­ty with the essen­ti­al requi­re­ments set out in para­graph 1 in so far as tho­se requi­re­ments are cover­ed by tho­se har­mo­ni­zed standards. 
(5) The Com­mis­si­on shall, in accordance with Artic­le 10 of Regu­la­ti­on (EU) No 1025/2012, man­da­te one or more Euro­pean stan­dar­dizati­on bodies to deve­lop draft har­mo­ni­zed stan­dards that meet the essen­ti­al requi­re­ments refer­red to in para­graph 1 of this Article. 
(6) The Com­mis­si­on may, by means of imple­men­ting acts, adopt com­mon spe­ci­fi­ca­ti­ons cove­ring some or all of the essen­ti­al requi­re­ments refer­red to in para­graph 1, pro­vi­ded that the fol­lo­wing con­di­ti­ons are met:
a) In accordance with Artic­le 10(1) of Regu­la­ti­on (EU) No 1025/2012, the Com­mis­si­on has given a man­da­te to one or more Euro­pean stan­dar­dizati­on bodies to deve­lop a har­mo­ni­zed stan­dard that satis­fies the essen­ti­al requi­re­ments set out in para­graph 1 of this Artic­le; and
i) the order was not accepted,
ii) the har­mo­ni­zed stan­dards for this con­tract have not been sub­mit­ted within the time limit set in accordance with Artic­le 10(1) of Regu­la­ti­on (EU) No 1025/2012, or
iii) the har­mo­ni­zed stan­dards do not ful­fill the man­da­te, and
b) no refe­rence has been published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on in accordance with Regu­la­ti­on (EU) No 1025/2012 for the har­mo­ni­zed stan­dards cove­ring the rele­vant essen­ti­al requi­re­ments set out in para­graph 1 of this Artic­le, and no such refe­rence is expec­ted to be published within a rea­sonable peri­od of time.
Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 46(2).
(7) Befo­re pre­pa­ring a draft imple­men­ting act refer­red to in para­graph 6 of this Artic­le, the Com­mis­si­on shall inform the Com­mit­tee refer­red to in Artic­le 22 of Regu­la­ti­on (EU) No 1025/2012 that it con­siders that the con­di­ti­ons set out in para­graph 6 of this Artic­le have been met. 
(8) When pre­pa­ring the draft imple­men­ting act refer­red to in para­graph 6, the Com­mis­si­on shall take into account the advice of the EDIB and the views of other rele­vant bodies or expert groups and shall duly con­sult all rele­vant stakeholders. 
(9) The pro­vi­der of a smart con­tract or, in the absence the­reof, the per­son who­se trade, busi­ness or pro­fes­si­on invol­ves the use of smart con­tracts for third par­ties in con­nec­tion with the per­for­mance of a data sha­ring agree­ment or parts the­reof that com­plies with all or part of the com­mon spe­ci­fi­ca­ti­ons laid down by the imple­men­ting acts refer­red to in para­graph 6, shall be pre­su­med to com­ply with the essen­ti­al requi­re­ments laid down in para­graph 1 to the ext­ent that tho­se requi­re­ments are cover­ed in who­le or in part by tho­se com­mon specifications. 
(10) Whe­re a har­mo­ni­zed stan­dard is adopted by a Euro­pean stan­dar­dizati­on orga­ni­sa­ti­on and pro­po­sed to the Com­mis­si­on for publi­ca­ti­on of its refe­rence in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, the Com­mis­si­on shall assess that har­mo­ni­zed stan­dard in accordance with Regu­la­ti­on (EU) No 1025/2012. Whe­re the refe­rence of a har­mo­ni­zed stan­dard is published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, the imple­men­ting acts refer­red to in para­graph 6 of this Artic­le which cover the same essen­ti­al requi­re­ments as tho­se cover­ed by that har­mo­ni­zed stan­dard shall be repea­led, in who­le or in part, by the Commission. 
(11) Whe­re a Mem­ber Sta­te con­siders that a com­mon spe­ci­fi­ca­ti­on does not enti­re­ly satis­fy the essen­ti­al requi­re­ments refer­red to in para­graph 1, it shall inform the Com­mis­si­on the­reof by pro­vi­ding a detail­ed expl­ana­ti­on. The Com­mis­si­on shall assess the detail­ed expl­ana­ti­on and may, whe­re appro­pria­te, amend the imple­men­ting act which estab­lished the com­mon spe­ci­fi­ca­ti­on concerned.
(104) In order to pro­mo­te the inter­ope­ra­bi­li­ty of tools for the auto­ma­ted imple­men­ta­ti­on of data-sha­ring agree­ments, it is neces­sa­ry to lay down essen­ti­al requi­re­ments for smart con­tracts that pro­fes­sio­nals crea­te for others or inte­gra­te into appli­ca­ti­ons that sup­port the imple­men­ta­ti­on of data-sha­ring agree­ments. In order to faci­li­ta­te the com­pli­ance of such smart con­tracts with the­se essen­ti­al requi­re­ments, it is neces­sa­ry to pro­vi­de for a pre­sump­ti­on of con­for­mi­ty for the smart con­tracts that com­ply in who­le or in part with the har­mo­ni­zed stan­dards under Regu­la­ti­on (EU) No 1025/2012. The term „smart con­tract“ in this Regu­la­ti­on is tech­no­lo­gy-neu­tral. Smart con­tracts can, for exam­p­le, be lin­ked to an elec­tro­nic regi­ster of tran­sac­tions. The essen­ti­al requi­re­ments should only app­ly to pro­vi­ders of smart con­tracts, but not when they draw up smart con­tracts intern­al­ly for inter­nal use only. The essen­ti­al requi­re­ment to ensu­re that smart con­tracts can be sus­pen­ded and ter­mi­na­ted pre­sup­po­ses the mutu­al con­sent of the par­ties to the data sha­ring agree­ment. The appli­ca­bi­li­ty of the rele­vant pro­vi­si­ons of civil, con­tract and con­su­mer pro­tec­tion law to data sha­ring agree­ments remains or should remain unaf­fec­ted by the use of smart con­tracts for the auto­ma­ted exe­cu­ti­on of such agreements.
(105) In order to demon­stra­te com­pli­ance with the essen­ti­al requi­re­ments of this Regu­la­ti­on, the pro­vi­der of a smart con­tract – or, fai­ling that, the per­son who­se trade, busi­ness or pro­fes­si­on invol­ves the imple­men­ta­ti­on of smart con­tracts for others in con­nec­tion with the imple­men­ta­ti­on of an agree­ment or parts the­reof for the pro­vi­si­on of data in the con­text of this Regu­la­ti­on – should car­ry out a con­for­mi­ty assess­ment and draw up an EU decla­ra­ti­on of con­for­mi­ty. That con­for­mi­ty assess­ment should be sub­ject to the gene­ral prin­ci­ples laid down in Regu­la­ti­on () No 765/2008 of the Euro­pean Par­lia­ment and of the Coun­cil (34) and Decis­i­on () No 768/2008 of the Euro­pean Par­lia­ment and of the Coun­cil (35).
(106) In addi­ti­on to requi­ring pro­fes­sio­nal deve­lo­pers of smart con­tracts to com­ply with essen­ti­al requi­re­ments, it is also important to encou­ra­ge tho­se par­ti­ci­pan­ts in data spaces that offer data or data-based ser­vices to other par­ti­ci­pan­ts within and through com­mon Euro­pean data spaces to sup­port the inter­ope­ra­bi­li­ty of data sha­ring tools, inclu­ding smart contracts.

Chap­ter IX Appli­ca­ti­on and enforcement

Artic­le 37 Com­pe­tent aut­ho­ri­ties and data coordinators
(107) In order to ensu­re the appli­ca­ti­on and enforce­ment of this Regu­la­ti­on, Mem­ber Sta­tes should desi­gna­te one or more com­pe­tent aut­ho­ri­ties. Whe­re a Mem­ber Sta­te desi­gna­tes more than one com­pe­tent aut­ho­ri­ty, it should also desi­gna­te a data coor­di­na­tor among them. Com­pe­tent aut­ho­ri­ties should coope­ra­te with each other. By exer­cis­ing their inve­sti­ga­to­ry powers in accordance with appli­ca­ble natio­nal pro­ce­du­res, com­pe­tent aut­ho­ri­ties should be able to seek and obtain infor­ma­ti­on, in par­ti­cu­lar in rela­ti­on to the acti­vi­ties of enti­ties under their juris­dic­tion and, inclu­ding in the con­text of joint inve­sti­ga­ti­ons, taking due account of the fact that super­vi­so­ry and enforce­ment mea­su­res in rela­ti­on to enti­ties under the juris­dic­tion of ano­ther Mem­ber Sta­te should be adopted by the com­pe­tent aut­ho­ri­ty of that other Mem­ber Sta­te, whe­re appro­pria­te in accordance with the pro­ce­du­res for cross-bor­der coope­ra­ti­on. Com­pe­tent aut­ho­ri­ties should assist each other in a time­ly man­ner, in par­ti­cu­lar whe­re a com­pe­tent aut­ho­ri­ty in one Mem­ber Sta­te has or can gather rele­vant infor­ma­ti­on for an inve­sti­ga­ti­on car­ri­ed out by com­pe­tent aut­ho­ri­ties in other Mem­ber Sta­tes to which the com­pe­tent aut­ho­ri­ties in the Mem­ber Sta­te whe­re the enti­ty is estab­lished do not have access. Com­pe­tent aut­ho­ri­ties and data coor­di­na­tors should be listed in a public regi­ster kept by the Com­mis­si­on. The data coor­di­na­tor could pro­vi­de addi­tio­nal assi­stance in faci­li­ta­ting coope­ra­ti­on in cross-bor­der situa­tions, for exam­p­le whe­re a com­pe­tent aut­ho­ri­ty in a par­ti­cu­lar Mem­ber Sta­te does not know which aut­ho­ri­ty it should cont­act in the Mem­ber Sta­te of the data coor­di­na­tor, for exam­p­le whe­re the case invol­ves more than one com­pe­tent aut­ho­ri­ty or more than one sec­tor. The data coor­di­na­tor should act as a sin­gle point of cont­act for all que­sti­ons rela­ted to the appli­ca­ti­on of this Regu­la­ti­on. Whe­re no data coor­di­na­tor has been desi­gna­ted, the com­pe­tent aut­ho­ri­ty should assu­me the tasks assi­gned to the data coor­di­na­tor under this Regu­la­ti­on. The com­pe­tent aut­ho­ri­ties respon­si­ble for moni­to­ring com­pli­ance with data pro­tec­tion law and the com­pe­tent aut­ho­ri­ties desi­gna­ted under Uni­on or natio­nal law should be respon­si­ble for the appli­ca­ti­on of this Regu­la­ti­on in their are­as of com­pe­tence. In order to avo­id con­flicts of inte­rest, the aut­ho­ri­ties respon­si­ble for the appli­ca­ti­on and enforce­ment of this Regu­la­ti­on in the area of pro­vi­si­on of data fol­lo­wing a request based on excep­tio­nal neces­si­ty should not have the right to make such a request.
(1) Each Mem­ber Sta­te shall desi­gna­te one or more com­pe­tent aut­ho­ri­ties respon­si­ble for the appli­ca­ti­on and enforce­ment of this Regu­la­ti­on (her­ein­af­ter „com­pe­tent aut­ho­ri­ties“). Mem­ber Sta­tes may estab­lish one or more new aut­ho­ri­ties or rely on exi­sting authorities. 
(2) Whe­re a Mem­ber Sta­te desi­gna­tes more than one com­pe­tent aut­ho­ri­ty, it shall desi­gna­te a data coor­di­na­tor from among its com­pe­tent aut­ho­ri­ties to faci­li­ta­te coope­ra­ti­on bet­ween the com­pe­tent aut­ho­ri­ties and to assist the enti­ties fal­ling within the scope of this Regu­la­ti­on in all mat­ters rela­ting to its appli­ca­ti­on and enforce­ment. The com­pe­tent aut­ho­ri­ties shall coope­ra­te with each other in the exer­cise of the tasks and powers con­fer­red on them under para­graph 5. 
(3) The super­vi­so­ry aut­ho­ri­ties respon­si­ble for moni­to­ring the appli­ca­ti­on of Regu­la­ti­on (EU) 2016/679 shall also be respon­si­ble for moni­to­ring the appli­ca­ti­on of this Regu­la­ti­on with regard to the pro­tec­tion of per­so­nal data. Chap­ters VI and VII of Regu­la­ti­on (EU) 2016/679 shall app­ly muta­tis mutandis. 
The Euro­pean Data Pro­tec­tion Super­vi­sor shall be respon­si­ble for moni­to­ring the appli­ca­ti­on of this Regu­la­ti­on inso­far as the Com­mis­si­on, the Euro­pean Cen­tral Bank or Uni­on bodies are con­cer­ned. Artic­le 62 of Regu­la­ti­on (EU) 2018/1725 shall app­ly muta­tis mut­an­dis whe­re appropriate. 
The super­vi­so­ry aut­ho­ri­ties refer­red to in this para­graph shall per­form their duties and exer­cise their powers with regard to the pro­ce­s­sing of per­so­nal data. 
(4) Not­wi­th­stan­ding para­graph 1, the fol­lo­wing shall app­ly:
a) For spe­ci­fic sec­to­ral mat­ters of data access and use in con­nec­tion with the appli­ca­ti­on of this Regu­la­ti­on, the com­pe­tence of the sec­to­ral aut­ho­ri­ties shall be preserved;
b) the com­pe­tent aut­ho­ri­ty respon­si­ble for the appli­ca­ti­on and enforce­ment of Artic­les 23 to 31 and Artic­les 34 and 35 shall have expe­ri­ence in the field of data and elec­tro­nic com­mu­ni­ca­ti­ons services.
(5) Mem­ber Sta­tes shall ensu­re that the tasks and powers of the com­pe­tent aut­ho­ri­ties are cle­ar­ly defi­ned and include the fol­lo­wing:
a) Pro­mo­ting data liter­a­cy and rai­sing awa­re­ness of users and enti­ties fal­ling within the scope of this Regu­la­ti­on with regard to the rights and obli­ga­ti­ons ari­sing from this Regulation;
(19) The term „data liter­a­cy“ refers to the skills, know­ledge and under­stan­ding that enable users, con­su­mers and busi­nesses, in par­ti­cu­lar SMEs fal­ling within the scope of this Regu­la­ti­on, to beco­me awa­re of the poten­ti­al value of the data they gene­ra­te, pro­du­ce and share, and moti­va­te them to offer and pro­vi­de access to their data in accordance with the rele­vant legis­la­ti­on. Data liter­a­cy should go bey­ond the acqui­si­ti­on of know­ledge about tools and tech­no­lo­gies and aim to enable and empower citi­zens and busi­nesses to bene­fit from an inclu­si­ve and fair data mar­ket. The dis­se­mi­na­ti­on of data liter­a­cy mea­su­res and the intro­duc­tion of appro­pria­te fol­low-up mea­su­res could help to impro­ve working con­di­ti­ons and ulti­m­ate­ly sup­port the con­so­li­da­ti­on and inno­va­ti­on pathway of the data eco­no­my in the Uni­on. Com­pe­tent aut­ho­ri­ties should pro­mo­te tools and take mea­su­res to impro­ve the data liter­a­cy of users and enti­ties fal­ling within the scope of this Regu­la­ti­on and make them awa­re of their rights and obli­ga­ti­ons under this Regulation.
b) hand­ling of com­plaints about alle­ged inf­rin­ge­ments of this Regu­la­ti­on, inclu­ding in rela­ti­on to busi­ness secrets, and appro­pria­te inve­sti­ga­ti­on of the sub­ject mat­ter of the com­plaint and kee­ping the com­plainant regu­lar­ly infor­med, whe­re appro­pria­te in accordance with natio­nal law, within a rea­sonable peri­od of time, of the pro­gress and out­co­me of the inve­sti­ga­ti­on, in par­ti­cu­lar whe­re fur­ther inve­sti­ga­ti­on or coor­di­na­ti­on with ano­ther com­pe­tent aut­ho­ri­ty is necessary;
c) car­ry­ing out inve­sti­ga­ti­ons into mat­ters rela­ting to the appli­ca­ti­on of this Regu­la­ti­on, inclu­ding on the basis of infor­ma­ti­on pro­vi­ded by ano­ther com­pe­tent aut­ho­ri­ty or other authority;
d) Impo­sing effec­ti­ve, pro­por­tio­na­te and dissua­si­ve finan­cial sanc­tions, which may include peri­odic penal­ty payments and fines with retroac­ti­ve effect, or initia­ting legal pro­ce­e­dings to impo­se fines;
e) Moni­to­ring tech­no­lo­gi­cal and rele­vant eco­no­mic deve­lo­p­ments that are important for the pro­vi­si­on and use of data;
f) coope­ra­te with the com­pe­tent aut­ho­ri­ties of other Mem­ber Sta­tes and, whe­re appro­pria­te, with the Com­mis­si­on or the EDIB to ensu­re the uni­form and effi­ci­ent appli­ca­ti­on of this Regu­la­ti­on, inclu­ding the prompt exch­an­ge of all rele­vant infor­ma­ti­on by elec­tro­nic means, inclu­ding in rela­ti­on to para­graph 10 of this Article;
g) coope­ra­te with the rele­vant com­pe­tent aut­ho­ri­ties respon­si­ble for the appli­ca­ti­on of other Uni­on or natio­nal legal acts, inclu­ding with com­pe­tent aut­ho­ri­ties in the field of data and elec­tro­nic com­mu­ni­ca­ti­ons ser­vices, with the super­vi­so­ry aut­ho­ri­ty respon­si­ble for moni­to­ring the appli­ca­ti­on of Regu­la­ti­on (EU) 2016/679 or with sec­to­ral aut­ho­ri­ties to ensu­re that this Regu­la­ti­on is enforced in accordance with other Uni­on and natio­nal law;
h) coope­ra­te with the rele­vant com­pe­tent aut­ho­ri­ties to ensu­re the enforce­ment of Artic­les 23 to 31 and Artic­les 34 and 35 in accordance with other Uni­on law and self-regu­la­ti­on appli­ca­ble to pro­vi­ders of data pro­ce­s­sing services;
i) Ensu­re the aboli­ti­on of exch­an­ge fees in accordance with Artic­le 29;
j) Exami­na­ti­on of data requests in accordance with Chap­ter V.
Whe­re a data coor­di­na­tor is desi­gna­ted, it shall faci­li­ta­te the coope­ra­ti­on refer­red to in points (f), (g) and (h) of the first sub­pa­ra­graph and assist the com­pe­tent aut­ho­ri­ties at their request.
(6) If such a com­pe­tent aut­ho­ri­ty has been appoin­ted, the data coor­di­na­tor has the fol­lo­wing tasks:
a) It acts as a cen­tral point of cont­act for all que­sti­ons rela­ting to the appli­ca­ti­on of this regulation;
b) It ensu­res the public avai­la­bi­li­ty of data access requests made by public sec­tor bodies in cases of excep­tio­nal neces­si­ty under Chap­ter V and pro­mo­tes vol­un­t­a­ry data sha­ring agree­ments bet­ween public sec­tor bodies and data controllers;
c) shall inform the Com­mis­si­on annu­al­ly of the refu­sals noti­fi­ed in accordance with Artic­le 4(2) and (8) and Artic­le 5(11).
(7) Mem­ber Sta­tes shall noti­fy the Com­mis­si­on of the names of the com­pe­tent aut­ho­ri­ties and their tasks and powers and, whe­re appro­pria­te, the name of the data coor­di­na­tor. The Com­mis­si­on shall keep a public regi­ster of tho­se authorities. 
(8) In exer­cis­ing their duties and powers under this Regu­la­ti­on, the com­pe­tent aut­ho­ri­ties shall act impar­ti­al­ly and shall not be sub­ject to any direct or indi­rect exter­nal influence and shall not seek or recei­ve ins­truc­tions from other aut­ho­ri­ties or from pri­va­te par­ties in indi­vi­du­al cases. 
(9) Mem­ber Sta­tes shall ensu­re that com­pe­tent aut­ho­ri­ties have suf­fi­ci­ent human and tech­ni­cal resour­ces and exper­ti­se to car­ry out their duties effec­tively in accordance with this Regulation. 
(10) Enti­ties fal­ling within the scope of this Regu­la­ti­on shall be sub­ject to the juris­dic­tion of the Mem­ber Sta­te in which the enti­ty is estab­lished. If the enti­ty is estab­lished in more than one Mem­ber Sta­te, it shall be dee­med to fall under the juris­dic­tion of the Mem­ber Sta­te in which it has its main estab­lish­ment, i.e. whe­re the enti­ty has its head office or regi­stered office from which the main finan­cial acti­vi­ties and ope­ra­tio­nal con­trol are exercised. 
(11) Any enti­ty fal­ling within the scope of this Regu­la­ti­on that pro­vi­des net­work­ed pro­ducts or ser­vices in the Uni­on and is not estab­lished in the Uni­on shall desi­gna­te a repre­sen­ta­ti­ve in one of the Mem­ber States. 
(12) In order to ensu­re com­pli­ance with this Regu­la­ti­on, an enti­ty pro­vi­ding net­work­ed pro­ducts or ser­vices in the Uni­on fal­ling within the scope of this Regu­la­ti­on shall appoint a repre­sen­ta­ti­ve to whom the com­pe­tent aut­ho­ri­ties shall have recour­se in addi­ti­on to, or instead of, that enti­ty in all mat­ters rela­ting to that enti­ty. That repre­sen­ta­ti­ve shall coope­ra­te with the com­pe­tent aut­ho­ri­ties and pro­vi­de the com­pe­tent aut­ho­ri­ties, upon request, with full evi­dence of the mea­su­res taken and pro­vi­si­ons estab­lished by the enti­ty pro­vi­ding net­work­ed pro­ducts or ser­vices within the scope of this Regu­la­ti­on to ensu­re com­pli­ance with this Regulation. 
(13) Enti­ties fal­ling within the scope of this Regu­la­ti­on that pro­vi­de con­nec­ted pro­ducts or ser­vices in the Uni­on shall be sub­ject to the juris­dic­tion of the Mem­ber Sta­te in which their repre­sen­ta­ti­ve is estab­lished. The appoint­ment of a repre­sen­ta­ti­ve by that enti­ty shall be wit­hout pre­ju­di­ce to the lia­bi­li­ty of such enti­ty and any legal action that could be taken against such enti­ty. Until an enti­ty appoints a repre­sen­ta­ti­ve in accordance with this Artic­le, it shall fall under the juris­dic­tion of all Mem­ber Sta­tes, as appro­pria­te, for the pur­po­ses of ensu­ring the appli­ca­ti­on and enforce­ment of this Regu­la­ti­on. Each com­pe­tent aut­ho­ri­ty may exer­cise its com­pe­tence, inclu­ding by impo­sing effec­ti­ve, pro­por­tio­na­te and dissua­si­ve pen­al­ties, pro­vi­ded that the enti­ty is not alre­a­dy sub­ject to an enforce­ment pro­ce­du­re under this Regu­la­ti­on initia­ted by ano­ther com­pe­tent aut­ho­ri­ty in the same matter. 
(14) The com­pe­tent aut­ho­ri­ties shall have the power to requi­re users, data hol­ders or data reci­pi­en­ts or their repre­sen­ta­ti­ves fal­ling within the juris­dic­tion of their Mem­ber Sta­te to pro­vi­de any infor­ma­ti­on neces­sa­ry to veri­fy com­pli­ance with this Regu­la­ti­on. Any request for infor­ma­ti­on shall be pro­por­tio­na­te to the per­for­mance of that task and justified. 
(15) Whe­re a com­pe­tent aut­ho­ri­ty in one Mem­ber Sta­te requests the assi­stance or enforce­ment mea­su­res of a com­pe­tent aut­ho­ri­ty in ano­ther Mem­ber Sta­te, it shall make a rea­so­ned request. A com­pe­tent aut­ho­ri­ty shall rep­ly to such a request wit­hout undue delay upon rece­ipt, spe­ci­fy­ing the spe­ci­fic mea­su­res taken or envisaged. 
(16) Com­pe­tent aut­ho­ri­ties shall respect the prin­ci­ple of con­fi­den­tia­li­ty and pro­fes­sio­nal and com­mer­cial sec­re­cy and shall pro­tect per­so­nal data in accordance with Uni­on or natio­nal law. Any infor­ma­ti­on exch­an­ged in the con­text of a request for mutu­al assi­stance and pro­vi­ded in accordance with this Artic­le shall be used only for the pur­po­ses of that request.
Artic­le 38 Right of appeal
(108) In order to enforce their rights under this Regu­la­ti­on, natu­ral and legal per­sons should have the right to lodge a com­plaint in the event of a breach of their rights under this Regu­la­ti­on. The data coor­di­na­tor should pro­vi­de natu­ral and legal per­sons, on request, with all neces­sa­ry infor­ma­ti­on to enable them to lodge a com­plaint with the com­pe­tent aut­ho­ri­ty con­cer­ned. Tho­se aut­ho­ri­ties should be obli­ged to coope­ra­te with each other so that the com­plaint can be dealt with appro­pria­te­ly and resol­ved effec­tively and expe­di­tious­ly. In order to make use of the mecha­nism of the Con­su­mer Pro­tec­tion Coope­ra­ti­on Net­work and to enable repre­sen­ta­ti­ve actions, this Regu­la­ti­on amends the Anne­xes to Regu­la­ti­on (EU) 2017/2394 of the Euro­pean Par­lia­ment and of the Coun­cil (36) and to Direc­ti­ve (EU) 2020/1828 of the Euro­pean Par­lia­ment and of the Coun­cil (37).
(1) Wit­hout pre­ju­di­ce to any other admi­ni­stra­ti­ve or judi­cial reme­dy, natu­ral and legal per­sons shall have the right to lodge a com­plaint indi­vi­du­al­ly or, whe­re appro­pria­te, joint­ly with the com­pe­tent aut­ho­ri­ty of the Mem­ber Sta­te of their habi­tu­al resi­dence, place of work or place of estab­lish­ment, if they con­sider that their rights under this Regu­la­ti­on have been inf­rin­ged. The data coor­di­na­tor shall, on request, pro­vi­de natu­ral and legal per­sons with all neces­sa­ry infor­ma­ti­on to enable them to lodge a com­plaint with the com­pe­tent authority. 
(2) The com­pe­tent aut­ho­ri­ty with which the com­plaint has been lodged shall inform the com­plainant of the pro­gress of the pro­ce­du­re and the decis­i­on taken, in accordance with natio­nal law. 
(3) The com­pe­tent aut­ho­ri­ties shall coope­ra­te in order to hand­le and resol­ve com­plaints effec­tively and in a time­ly man­ner, inclu­ding by exchan­ging all rele­vant infor­ma­ti­on elec­tro­ni­cal­ly wit­hout undue delay. Such coope­ra­ti­on shall be wit­hout pre­ju­di­ce to the coope­ra­ti­on pro­ce­du­re laid down in Chap­ters VI and VII of Regu­la­ti­on (EU) 2016/679 and in Regu­la­ti­on (EU) 2017/2394.
Artic­le 39 Right to an effec­ti­ve judi­cial remedy
(1) Wit­hout pre­ju­di­ce to other admi­ni­stra­ti­ve or ext­ra­ju­di­cial reme­dies, any natu­ral or legal per­son con­cer­ned shall have the right to an effec­ti­ve judi­cial reme­dy against legal­ly bin­ding decis­i­ons of com­pe­tent authorities. 
(2) Whe­re a com­pe­tent aut­ho­ri­ty fails to act on a com­plaint, any natu­ral or legal per­son con­cer­ned shall have the right, in accordance with natio­nal law, eit­her to an effec­ti­ve judi­cial reme­dy or to access to a review by an impar­ti­al body with appro­pria­te expertise. 
(3) Pro­ce­e­dings under this Artic­le shall be brought befo­re the courts of the Mem­ber Sta­te of the com­pe­tent aut­ho­ri­ty against which the appeal, brought by an indi­vi­du­al natu­ral or legal per­son or, whe­re appli­ca­ble, by the repre­sen­ta­ti­ves of one or more natu­ral or legal per­sons, is directed.
Artic­le 40 Sanctions
(109) Com­pe­tent aut­ho­ri­ties should ensu­re that sanc­tions app­ly to brea­ches of the obli­ga­ti­ons laid down in this Regu­la­ti­on. Such pen­al­ties could include finan­cial pen­al­ties, war­nings, repri­man­ds or orders to bring busi­ness prac­ti­ces into com­pli­ance with the obli­ga­ti­ons laid down in this Regu­la­ti­on. The sanc­tions deter­mi­ned by the Mem­ber Sta­tes should be effec­ti­ve, pro­por­tio­na­te and dissua­si­ve and should take into account the recom­men­da­ti­ons of the EDIB, thus con­tri­bu­ting to the hig­hest level of con­si­sten­cy in the deter­mi­na­ti­on and appli­ca­ti­on of sanc­tions. Com­pe­tent aut­ho­ri­ties should, whe­re appro­pria­te, take inte­rim mea­su­res to limit the impact of a suspec­ted inf­rin­ge­ment while the inve­sti­ga­ti­on of that inf­rin­ge­ment is ongo­ing. In doing so, they should take into account, inter alia, the natu­re, gra­vi­ty, ext­ent and dura­ti­on of the breach in rela­ti­on to the public inte­rest con­cer­ned, the sca­le and natu­re of the acti­vi­ties car­ri­ed out and the eco­no­mic capa­ci­ty of the brea­ching par­ty. They should also take into account whe­ther the inf­ring­er syste­ma­ti­cal­ly or repea­ted­ly fails to com­ply with its obli­ga­ti­ons under this Regu­la­ti­on. In order to ensu­re com­pli­ance with the ne bis in idem prin­ci­ple, and in par­ti­cu­lar to avo­id that the same breach of the obli­ga­ti­ons under this Regu­la­ti­on is sanc­tion­ed more than once, a Mem­ber Sta­te inten­ding to exer­cise its juris­dic­tion over an inf­rin­ging par­ty that is not estab­lished in the Uni­on and has not desi­gna­ted a repre­sen­ta­ti­ve in the Uni­on should inform all data coor­di­na­tors and the Com­mis­si­on wit­hout undue delay.
(1) Mem­ber Sta­tes shall lay down the rules on pen­al­ties appli­ca­ble to inf­rin­ge­ments of the pro­vi­si­ons of this Regu­la­ti­on and shall take all mea­su­res neces­sa­ry to ensu­re that they are imple­men­ted. The pen­al­ties pro­vi­ded for must be effec­ti­ve, pro­por­tio­na­te and dissuasive. 
(2) Mem­ber Sta­tes shall noti­fy tho­se rules and mea­su­res to the Com­mis­si­on by Sep­tem­ber 12, 2025 and shall noti­fy it wit­hout delay of any sub­se­quent amend­ment affec­ting them. The Com­mis­si­on shall keep an easi­ly acce­s­si­ble public regi­ster of tho­se mea­su­res and update it regularly. 
(3) When impo­sing pen­al­ties for inf­rin­ge­ments of this Regu­la­ti­on, Mem­ber Sta­tes shall take into account the recom­men­da­ti­ons of the EDIB and the fol­lo­wing non-exhaus­ti­ve cri­te­ria:
a) the natu­re, gra­vi­ty, ext­ent and dura­ti­on of the infringement;
b) Mea­su­res taken by the inf­rin­ging par­ty to miti­ga­te or reme­dy the dama­ge cau­sed by the infringement;
c) pre­vious inf­rin­ge­ments by the inf­rin­ging party;
d) the finan­cial bene­fits gai­ned or los­ses avo­ided by the inf­rin­ging par­ty as a result of the inf­rin­ge­ment, pro­vi­ded that such bene­fits or los­ses can be relia­bly determined;
e) other aggravating or miti­ga­ting cir­cum­stances of the respec­ti­ve case;
f) the inf­rin­ging party’s annu­al tur­no­ver in the Uni­on in the pre­vious finan­cial year.
(4) In the event of inf­rin­ge­ments of the obli­ga­ti­ons laid down in Chap­ters II, III and V of this Regu­la­ti­on, the super­vi­so­ry aut­ho­ri­ties respon­si­ble for moni­to­ring the appli­ca­ti­on of Regu­la­ti­on (EU) 2016/679 may impo­se fines in accordance with Artic­le 83 of Regu­la­ti­on (EU) 2016/679 up to the amount spe­ci­fi­ed in Artic­le 83(5) of that Regu­la­ti­on within their area of competence. 
(5) In the event of inf­rin­ge­ments of the obli­ga­ti­ons laid down in Chap­ter V of this Regu­la­ti­on, the Euro­pean Data Pro­tec­tion Super­vi­sor may impo­se fines in accordance with Artic­le 66 of Regu­la­ti­on (EU) 2018/1725 up to the amount spe­ci­fi­ed in Artic­le 66(3) of that Regu­la­ti­on within its area of competence.
Artic­le 41 Model clau­ses and stan­dard con­trac­tu­al clauses
(111) In order to assist com­pa­nies in draf­ting and nego­tia­ting con­tracts, the Com­mis­si­on should draw up and recom­mend non-bin­ding stan­dard con­trac­tu­al clau­ses for data-sha­ring con­tracts bet­ween com­pa­nies, taking into account, whe­re neces­sa­ry, the con­di­ti­ons in cer­tain sec­tors and exi­sting prac­ti­ces with vol­un­t­a­ry data-sha­ring mecha­nisms. The­se model con­tract clau­ses should pri­ma­ri­ly pro­vi­de a prac­ti­cal tool to faci­li­ta­te the con­clu­si­on of a con­tract, in par­ti­cu­lar for SMEs. If the model con­tract pro­vi­si­ons are used com­pre­hen­si­ve­ly and con­sist­ent­ly, they should also have a posi­ti­ve impact on the design of data access and data use con­tracts and thus lead to fai­rer con­trac­tu­al rela­ti­on­ships for data access and data sha­ring overall.
The Com­mis­si­on shall, befo­re Sep­tem­ber 12, 2025, draft and recom­mend non-bin­ding model con­trac­tu­al clau­ses for data access and use – inclu­ding fair con­side­ra­ti­on and trade secret pro­tec­tion terms and non-bin­ding stan­dard con­trac­tu­al clau­ses for cloud com­pu­ting con­tracts – to assist par­ties in draf­ting and nego­tia­ting con­tracts with fair, rea­sonable and non-dis­cri­mi­na­to­ry con­trac­tu­al rights and obligations.
Artic­le 42 Role of the EDIB
(110) The EDIB should advi­se and assist the Com­mis­si­on in coor­di­na­ting natio­nal pro­ce­du­res and poli­ci­es on the issues cover­ed by this Regu­la­ti­on and in achie­ving its objec­ti­ves in rela­ti­on to tech­ni­cal stan­dar­dizati­on to impro­ve inter­ope­ra­bi­li­ty. It should also play a key role in initia­ting com­pre­hen­si­ve dis­cus­sions bet­ween the com­pe­tent aut­ho­ri­ties on the appli­ca­ti­on and enforce­ment of this Regu­la­ti­on. This exch­an­ge of infor­ma­ti­on should impro­ve effec­ti­ve access to justi­ce, enforce­ment and judi­cial coope­ra­ti­on across the Uni­on. Among other tasks, com­pe­tent aut­ho­ri­ties should use the EDIB as a plat­form for the assess­ment, coor­di­na­ti­on and adop­ti­on of recom­men­da­ti­ons for the estab­lish­ment of sanc­tions for inf­rin­ge­ments of this Regu­la­ti­on. It should enable com­pe­tent aut­ho­ri­ties, with the sup­port of the Com­mis­si­on, to agree on an opti­mal approach to the deter­mi­na­ti­on and impo­si­ti­on of such pen­al­ties. This approach avo­ids frag­men­ta­ti­on while pro­vi­ding fle­xi­bi­li­ty to Mem­ber Sta­tes and should lead to effec­ti­ve recom­men­da­ti­ons that sup­port the uni­form appli­ca­ti­on of this Regu­la­ti­on. The EDIB should also have an advi­so­ry role in the stan­dar­dizati­on pro­ce­du­res and the adop­ti­on of com­mon spe­ci­fi­ca­ti­ons by means of imple­men­ting acts and in the adop­ti­on of dele­ga­ted acts to estab­lish a moni­to­ring mecha­nism for the swit­ching fees char­ged by pro­vi­ders of data pro­ce­s­sing ser­vices and to fur­ther spe­ci­fy the essen­ti­al requi­re­ments for data inter­ope­ra­bi­li­ty, data sha­ring mecha­nisms and ser­vices and for the com­mon Euro­pean data spaces. It should also advi­se and assist the Com­mis­si­on in the adop­ti­on of the gui­de­lines defi­ning inter­ope­ra­bi­li­ty spe­ci­fi­ca­ti­ons for the func­tio­ning of the com­mon Euro­pean data spaces.
The EDIB, set up by the Com­mis­si­on as an expert group in accordance with Artic­le 29 of Regu­la­ti­on (EU) 2022/868, in which the com­pe­tent aut­ho­ri­ties are repre­sen­ted, shall sup­port the uni­form appli­ca­ti­on of this Regu­la­ti­on by
a) Advi­se and assist the Com­mis­si­on on the deve­lo­p­ment of con­si­stent prac­ti­ce by com­pe­tent aut­ho­ri­ties in the enforce­ment of Chap­ters II, III, V and VII,
b) Faci­li­ta­te coope­ra­ti­on bet­ween com­pe­tent aut­ho­ri­ties through capa­ci­ty buil­ding and infor­ma­ti­on exch­an­ge, in par­ti­cu­lar by estab­li­shing methods for the effi­ci­ent exch­an­ge of infor­ma­ti­on on the enforce­ment of rights and obli­ga­ti­ons under Chap­ters II, III and V in cross-bor­der cases, inclu­ding coor­di­na­ti­on in rela­ti­on to the deter­mi­na­ti­on of sanctions,
c) Advi­sing and sup­port­ing the Com­mis­si­on with regard to
i) the ans­wer to the que­sti­on of whe­ther to request the deve­lo­p­ment of har­mo­ni­zed stan­dards in accordance with Artic­les 33(4), 35(4) and 36(5),
ii) the pre­pa­ra­ti­on of the imple­men­ting acts refer­red to in Artic­le 33(5), Artic­le 35(5) and (8) and Artic­le 36(6),
iii) the pre­pa­ra­ti­on of the dele­ga­ted acts refer­red to in Artic­le 29(7) and Artic­le 33(2); and
iv) the adop­ti­on of the gui­de­lines estab­li­shing inter­ope­ra­ble frame­works for com­mon stan­dards and pro­ce­du­res for the func­tio­ning of com­mon Euro­pean data spaces refer­red to in Artic­le 33(11).

Chap­ter X Sui gene­ris right under Direc­ti­ve 96/9/EC

Artic­le 43 Data­ba­ses con­tai­ning cer­tain data
(112) In order to avo­id the risk that the hol­ders of data obtai­ned or gene­ra­ted by phy­si­cal com­pon­ents such as sen­sors of a con­nec­ted pro­duct and ser­vice or other machi­ne-gene­ra­ted data in data­ba­ses may invo­ke the sui gene­ris right under Artic­le 7 of Direc­ti­ve 96/9/ and ther­eby hin­der, in par­ti­cu­lar, the effec­ti­ve exer­cise of the right of users to access and use data and the right to dis­c­lo­se data to third par­ties under this Regu­la­ti­on, it should be cla­ri­fi­ed that the sui gene­ris right does not app­ly to such data­ba­ses. This is wit­hout pre­ju­di­ce to the pos­si­ble appli­ca­ti­on of the sui gene­ris right under Artic­le 7 of Direc­ti­ve 96/9/ to data­ba­ses con­tai­ning data which do not fall within the scope of this Regu­la­ti­on, pro­vi­ded that the pro­tec­tion requi­re­ments laid down in para­graph 1 of that Artic­le are fulfilled.
The sui gene­ris right laid down in Artic­le 7 of Direc­ti­ve 96/9/ shall not app­ly whe­re data have been obtai­ned or gene­ra­ted by means of a con­nec­ted pro­duct or ser­vice fal­ling within the scope of this Regu­la­ti­on, and in par­ti­cu­lar Artic­les 4 and 5 thereof.

Chap­ter XI Final Provisions

Artic­le 44 Other Uni­on legal acts gover­ning rights and obli­ga­ti­ons regar­ding access to and use of data
(1) The spe­cial obli­ga­ti­ons to pro­vi­de data bet­ween com­pa­nies, bet­ween com­pa­nies and con­su­mers and, excep­tio­nal­ly, bet­ween com­pa­nies and public bodies on the basis of Uni­on legis­la­ti­on that has ente­red into force by Janu­ary 11, 2024 and dele­ga­ted or imple­men­ting acts based the­re­on remain unaffected. 
(2) This Regu­la­ti­on shall be wit­hout pre­ju­di­ce to Uni­on law lay­ing down fur­ther requi­re­ments rela­ting to the needs of a sec­tor, a Euro­pean com­mon data space or an area of public inte­rest, in par­ti­cu­lar with regard to
a) tech­ni­cal aspects of data access,
b) Rest­ric­tions on the rights of the data owner to access and use cer­tain data pro­vi­ded by users,
c) Aspects that go bey­ond data access and data use.
(3) This Regu­la­ti­on, with the excep­ti­on of Chap­ter V, shall be wit­hout pre­ju­di­ce to Uni­on and natio­nal law pro­vi­ding for access to and aut­ho­rizati­on of the use of data for the pur­po­ses of sci­en­ti­fic research.
Artic­le 45 Exer­cise of the dele­ga­ti­on of power
(113) In order to take account of the tech­ni­cal aspects of data pro­ce­s­sing ser­vices, the power to adopt acts in accordance with Artic­le 290 TFEU should be dele­ga­ted to the Com­mis­si­on in respect of sup­ple­men­ting this Regu­la­ti­on by intro­du­cing a moni­to­ring mecha­nism of the swit­ching fees char­ged by pro­vi­ders of data pro­ce­s­sing ser­vices on the mar­ket and by fur­ther spe­ci­fy­ing the essen­ti­al requi­re­ments regar­ding inter­ope­ra­bi­li­ty for data space par­ti­ci­pan­ts offe­ring data or data ser­vices to other data space par­ti­ci­pan­ts. It is of par­ti­cu­lar importance that the Com­mis­si­on car­ry out appro­pria­te con­sul­ta­ti­ons during its pre­pa­ra­to­ry work, inclu­ding at expert level, in accordance with the prin­ci­ples laid down in the Inter­in­sti­tu­tio­nal Agree­ment of 13 April 2016 on Bet­ter Law-Making (38). In par­ti­cu­lar, to ensu­re equal par­ti­ci­pa­ti­on in the pre­pa­ra­ti­on of dele­ga­ted acts, the Euro­pean Par­lia­ment and the Coun­cil recei­ve all docu­ments at the same time as Mem­ber Sta­tes’ experts, and their experts syste­ma­ti­cal­ly have access to mee­tings of Com­mis­si­on expert groups deal­ing with the pre­pa­ra­ti­on of dele­ga­ted acts.
(114) In order to ensu­re uni­form con­di­ti­ons for the imple­men­ta­ti­on of this Regu­la­ti­on, imple­men­ting powers should be con­fer­red on the Com­mis­si­on in respect of the adop­ti­on of com­mon spe­ci­fi­ca­ti­ons for ensu­ring the inter­ope­ra­bi­li­ty of data, data sha­ring mecha­nisms and ser­vices and com­mon Euro­pean data spaces, com­mon spe­ci­fi­ca­ti­ons for the inter­ope­ra­bi­li­ty of data pro­ce­s­sing ser­vices and com­mon spe­ci­fi­ca­ti­ons for the inter­ope­ra­bi­li­ty of smart con­tracts. Imple­men­ting powers should also be con­fer­red on the Com­mis­si­on in respect of the publi­ca­ti­on of refe­ren­ces to har­mo­ni­zed stan­dards and com­mon spe­ci­fi­ca­ti­ons for the inter­ope­ra­bi­li­ty of data pro­ce­s­sing ser­vices in the cen­tral Uni­on data­ba­se of stan­dards for the inter­ope­ra­bi­li­ty of data pro­ce­s­sing ser­vices. Tho­se powers should be exer­cis­ed in accordance with Regu­la­ti­on (EU) No 182/2011 of the Euro­pean Par­lia­ment and of the Coun­cil (39).
(1) The power to adopt dele­ga­ted acts is con­fer­red on the Com­mis­si­on sub­ject to the con­di­ti­ons laid down in this Article. 
(2) The power to adopt dele­ga­ted acts refer­red to in Artic­le 29(7) and Artic­le 33(2) shall be con­fer­red on the Com­mis­si­on for an inde­ter­mi­na­te peri­od of time from Janu­ary 11, 2024. 
(3) The dele­ga­ti­on of power refer­red to in Artic­le 29(7) and Artic­le 33(2) may be revo­ked at any time by the Euro­pean Par­lia­ment or by the Coun­cil. A decis­i­on to revo­ke shall put an end to the dele­ga­ti­on of the power spe­ci­fi­ed in that decis­i­on. It shall take effect the day fol­lo­wing the publi­ca­ti­on of the decis­i­on in the Offi­ci­al Jour­nal of the Euro­pean Uni­on or at a later date spe­ci­fi­ed the­r­ein. The decis­i­on of revo­ca­ti­on shall not affect the vali­di­ty of any dele­ga­ted acts alre­a­dy in force. 
(4) Befo­re adop­ting a dele­ga­ted act, the Com­mis­si­on shall con­sult experts desi­gna­ted by each Mem­ber Sta­te in accordance with the prin­ci­ples laid down in the Inter­in­sti­tu­tio­nal Agree­ment of April 13, 2016 on Bet­ter Law-Making. 
(5) As soon as it adopts a dele­ga­ted act, the Com­mis­si­on shall noti­fy it simul­ta­neous­ly to the Euro­pean Par­lia­ment and to the Council. 
(6) A dele­ga­ted act adopted pur­su­ant to Artic­le 29(7) or Artic­le 33(2) shall enter into force only if no objec­tion has been expres­sed eit­her by the Euro­pean Par­lia­ment or the Coun­cil within a peri­od of three months of noti­fi­ca­ti­on of that act to the Euro­pean Par­lia­ment and the Coun­cil or if, befo­re the expiry of that peri­od, the Euro­pean Par­lia­ment and the Coun­cil have both infor­med the Com­mis­si­on that they will not object. That peri­od shall be exten­ded by three months at the initia­ti­ve of the Euro­pean Par­lia­ment or the Council.
Artic­le 46 Com­mit­tee procedure
(1) The Com­mis­si­on shall be assi­sted by the com­mit­tee estab­lished by Regu­la­ti­on (EU) No 2022/868. That com­mit­tee shall be a com­mit­tee within the mea­ning of Regu­la­ti­on (EU) No 182/2011.
(2) Whe­re refe­rence is made to this para­graph, Artic­le 5 of Regu­la­ti­on (EU) No 182/2011 shall apply.
Artic­le 47 Amend­ment to Regu­la­ti­on (EU) 2017/2394
In the Annex to Regu­la­ti­on (EU) 2017/2394, the fol­lo­wing point is added „29 Regu­la­ti­on (EU) 2023/2854 of the Coun­cil and of the Euro­pean Par­lia­ment of 13 Decem­ber 2023 on har­mo­ni­zed rules for fair access to and use of data and amen­ding Regu­la­ti­on (EU) 2017/2394 and Direc­ti­ve (EU) 2020/1828 (Data Regu­la­ti­on) (OJ L, 2023/2854, 22.12.2023, ELI: [http://data.europa.eu/eli/reg/2023/2854/oj).](http://data.europa.eu/eli/reg/2023/2854/oj).“.“
Artic­le 48 Amend­ment to Direc­ti­ve (EU) 2020/1828
In Annex I to Direc­ti­ve (EU) 2020/1828, the fol­lo­wing point is added „68. Regu­la­ti­on (EU) 2023/2854 of the Coun­cil and of the Euro­pean Par­lia­ment of 13 Decem­ber 2023 on har­mo­ni­zed rules for fair access to and use of data and amen­ding Regu­la­ti­on (EU) 2017/2394 and Direc­ti­ve (EU) 2020/1828 (Data Regu­la­ti­on) (OJ L, 2023/2854, 22.12.2023, ELI: [http://data.europa.eu/eli/reg/2023/2854/oj](http://data.europa.eu/eli/reg/2023/2854/oj).).“
Artic­le 49 Assess­ment and verification
(1) By Sep­tem­ber 12, 2028, the Com­mis­si­on shall car­ry out an eva­lua­ti­on of this Regu­la­ti­on and sub­mit a report on its main fin­dings to the Euro­pean Par­lia­ment, the Coun­cil and the Euro­pean Eco­no­mic and Social Com­mit­tee. That eva­lua­ti­on shall assess in par­ti­cu­lar the fol­lo­wing
a) situa­tions con­side­red to be cases of excep­tio­nal neces­si­ty for the pur­po­ses of Artic­le 15 of this Regu­la­ti­on and the prac­ti­cal appli­ca­ti­on of Chap­ter V of this Regu­la­ti­on, in par­ti­cu­lar the expe­ri­ence of the appli­ca­ti­on of Chap­ter V of this Regu­la­ti­on by public sec­tor bodies, the Com­mis­si­on, the Euro­pean Cen­tral Bank and Uni­on bodies; the num­ber and out­co­me of pro­ce­e­dings initia­ted by com­pe­tent aut­ho­ri­ties in accordance with Artic­le 18(5) in rela­ti­on to the appli­ca­ti­on of Chap­ter V of this Regu­la­ti­on; the impact of other obli­ga­ti­ons laid down in Uni­on or natio­nal law for the pur­po­ses of com­ply­ing with requests for access to infor­ma­ti­on; the impact of vol­un­t­a­ry data sha­ring mecha­nisms, such as tho­se estab­lished by data altru­ism orga­nizati­ons reco­gnized under Regu­la­ti­on (EU) 2022/868, on the achie­ve­ment of the objec­ti­ves of Chap­ter V of this Regu­la­ti­on; and the role of per­so­nal data in the con­text of Artic­le 15 of this Regu­la­ti­on, inclu­ding the deve­lo­p­ment of pri­va­cy enhan­cing technologies;
b) the impact of this Regu­la­ti­on on the use of data in the eco­no­my, inclu­ding on data inno­va­ti­on, data mone­tizati­on prac­ti­ces and data bro­kera­ge ser­vices, as well as on the sha­ring of data within the com­mon Euro­pean data spaces;
c) the acce­s­si­bi­li­ty and use of the various cate­go­ries and types of data;
d) the exclu­si­on of cer­tain cate­go­ries of under­ta­kings as bene­fi­ci­a­ries under Artic­le 5,
e) the non-exi­stence of effects on intellec­tu­al pro­per­ty rights;
f) the impact on trade secrets, inclu­ding on the pro­tec­tion against the unlawful acqui­si­ti­on, use and dis­clo­sure of trade secrets, and the impact of the mecha­nism under which the data con­trol­ler may refu­se the user’s request for access to data in accordance with Artic­les 4(8) and 5(11), taking into account, whe­re pos­si­ble, any revi­si­on of Direc­ti­ve (EU) 2016/943;
g) the que­sti­on of whe­ther the list of unfair con­tract terms in Artic­le 13 is still rele­vant in view of new busi­ness prac­ti­ces and the rapid pace of mar­ket innovation;
h) Chan­ges in the con­trac­tu­al prac­ti­ces of data pro­ce­s­sing ser­vice pro­vi­ders and the que­sti­on of whe­ther Artic­le 25 is still suf­fi­ci­ent­ly com­plied with in light of the­se changes;
i) the reduc­tion of fees char­ged by data pro­ce­s­sing ser­vice pro­vi­ders for the exe­cu­ti­on of swit­ching, in line with the pha­sing out of swit­ching fees under Artic­le 29;
j) the inter­ac­tion of this Regu­la­ti­on with other Uni­on acts rele­vant to the data economy;
k) the pre­ven­ti­on of unlawful sta­te access to non-per­so­nal data;
l) the effec­ti­ve­ness of the enforce­ment regime under Artic­le 37;
m) the impact of this Regu­la­ti­on on SMEs in terms of their abili­ty to inno­va­te and the avai­la­bi­li­ty of data pro­ce­s­sing ser­vices to users in the Uni­on and the bur­dens asso­cia­ted with com­pli­ance with the new obligations.
(2) By Sep­tem­ber 12, 2028, the Com­mis­si­on shall car­ry out an eva­lua­ti­on of this Regu­la­ti­on and sub­mit a report on its main fin­dings to the Euro­pean Par­lia­ment and to the Coun­cil and to the Euro­pean Eco­no­mic and Social Com­mit­tee, in addi­ti­on to its report refer­red to in para­graph 1. That eva­lua­ti­on shall assess the impact of Artic­les 23 to 31, Artic­le 34 and Artic­le 35, in par­ti­cu­lar with regard to pri­cing and the diver­si­ty of data pro­ce­s­sing ser­vices offe­red in the Uni­on, with a par­ti­cu­lar focus on SME providers. 
(3) Mem­ber Sta­tes shall pro­vi­de the Com­mis­si­on with all infor­ma­ti­on neces­sa­ry for the pre­pa­ra­ti­on of the reports refer­red to in para­graphs 1 and 2. 
(4) On the basis of the reports refer­red to in para­graphs 1 and 2, the Com­mis­si­on may, if appro­pria­te, sub­mit a legis­la­ti­ve pro­po­sal to the Euro­pean Par­lia­ment and the Coun­cil to amend this Regulation.
Artic­le 50 Ent­ry into force and date of application
(117) In order to allow par­ti­ci­pan­ts fal­ling within the scope of this Regu­la­ti­on to adapt to the new pro­vi­si­ons of this Regu­la­ti­on and to take the neces­sa­ry tech­ni­cal pre­cau­ti­ons, tho­se pro­vi­si­ons should only app­ly from Sep­tem­ber 12, 2025.
This Regu­la­ti­on shall enter into force on the twen­tieth day fol­lo­wing that of its publi­ca­ti­on in the Offi­ci­al Jour­nal of the Euro­pean Union.
It will app­ly from Sep­tem­ber 12, 2025.
The obli­ga­ti­on set out in Artic­le 3(1) shall app­ly to con­nec­ted pro­ducts and their asso­cia­ted ser­vices pla­ced on the mar­ket after Sep­tem­ber 12, 2026.
Chap­ter III shall only app­ly in rela­ti­on to data pro­vi­si­on obli­ga­ti­ons under Uni­on law or natio­nal law adopted in accordance with Uni­on law that enter into force after Sep­tem­ber 12, 2025.
Chap­ter IV applies to con­tracts con­clu­ded after Sep­tem­ber 12, 2025.
Chap­ter IV shall app­ly from Sep­tem­ber 12, 2027 for con­tracts con­clu­ded on or befo­re Sep­tem­ber 12, 2025, pro­vi­ded that
a) they are inde­fi­ni­te or
b) their peri­od of vali­di­ty ends at the ear­liest 10 years after Janu­ary 11, 2024.
This Regu­la­ti­on shall be bin­ding in its enti­re­ty and direct­ly appli­ca­ble in all Mem­ber States.
Done at Strasbourg, Decem­ber 13, 2023.
(118) The Euro­pean Data Pro­tec­tion Super­vi­sor and the Euro­pean Data Pro­tec­tion Board were con­sul­ted in accordance with Artic­le 42(1) and (2) of Regu­la­ti­on (EU) 2018/1725 and deli­ver­ed their opi­ni­ons on May 4, 2022.
(foot­no­tes removed)