Source: OJ L, 2023/2854, 22.12.2023

Current language: EN

Data act regulation

REGULATION (EU) 2023/2854 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

of 13 December 2023

on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)

(Text with EEA relevance)

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Having regard to the proposal from the European Commission,

After transmission of the draft legislative act to the national parliaments,

Having regard to the opinion of the European Central Bank(1),

Having regard to the opinion of the European Economic and Social Committee(2),

Having regard to the opinion of the Committee of the Regions(3),

Acting in accordance with the ordinary legislative procedure(4),

Whereas:

Open full page
Recital 1

In recent years, data-driven technologies have had transformative effects on all sectors of the economy. The proliferation of products connected to the internet in particular has increased the volume and potential value of data for consumers, businesses and society. High-quality and interoperable data from different domains increase competitiveness and innovation and ensure sustainable economic growth. The same data may be used and reused for a variety of purposes and to an unlimited degree, without any loss of quality or quantity.

Recital 2

Barriers to data sharing prevent an optimal allocation of data for the benefit of society. Those barriers include a lack of incentives for data holders to enter voluntarily into data sharing agreements, uncertainty about rights and obligations in relation to data, the costs of contracting and implementing technical interfaces, the high level of fragmentation of information in data silos, poor metadata management, the absence of standards for semantic and technical interoperability, bottlenecks impeding data access, a lack of common data sharing practices and the abuse of contractual imbalances with regard to data access and use.

Recital 3

In sectors characterised by the presence of microenterprises, small enterprises and medium-sized enterprises as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC(5) (SMEs), there is often a lack of digital capacities and skills to collect, analyse and use data, and access is frequently restricted where one actor holds them in the system or due to a lack of interoperability between data, between data services or across borders.

HAVE ADOPTED THIS REGULATION:

  1. Chapter IGeneral provisions
  2. Chapter IIBusiness to consumer and business to business data sharing
  3. Chapter IIIObligations for data holders obliged to make data available pursuant to union law
  4. Chapter IVUnfair contractual terms related to data access and use between enterprises
  5. Chapter VMaking data available to public sector bodies, the commission, the european central bank and union bodies on the basis of an exceptional need
  6. Chapter VISwitching between data processing services
  7. Chapter VIIUnlawful international governmental access and transfer of non-personal data
  8. Chapter VIIIInteroperability
  9. Chapter IXImplementation and enforcement
  10. Chapter XSui generis right under directive 96/9/EC
  11. Chapter XIFinal provisions

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Strasbourg, 13 December 2023.

For the European Parliament

The President

R. METSOLA

For the Council

The President

P. NAVARRO RÍOS

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod