Data Act
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – BUSINESS TO CONSUMER AND BUSINESS TO BUSINESS DATA SHARING
Chapter III – OBLIGATIONS FOR DATA HOLDERS OBLIGED TO MAKE DATA AVAILABLE PURSUANT TO UNION LAW
Chapter IV – UNFAIR CONTRACTUAL TERMS RELATED TO DATA ACCESS AND USE BETWEEN ENTERPRISES
Chapter V – MAKING DATA AVAILABLE TO PUBLIC SECTOR BODIES, THE COMMISSION, THE EUROPEAN CENTRAL BANK AND UNION BODIES ON THE BASIS OF AN EXCEPTIONAL NEED
Chapter VI – SWITCHING BETWEEN DATA PROCESSING SERVICES
Chapter VII – UNLAWFUL INTERNATIONAL GOVERNMENTAL ACCESS AND TRANSFER OF NON-PERSONAL DATA
Chapter VIII – INTEROPERABILITY
Chapter IX – IMPLEMENTATION AND ENFORCEMENT
Chapter X – SUI GENERIS RIGHT UNDER DIRECTIVE 96/9/EC
Chapter XI – FINAL PROVISIONS
Recitals (119)
Recital 35
(35) Product data or related service data should only be made available to a third party at the request of the user. This Regulation complements accordingly the right, provided for in Article 20 of General Data Protection Regulation (GDPR), of data subjects to receive personal data concerning them in a structured, commonly used and machine-readable format, as well as to port those data to another controller, where those data are processed by automated means on the basis of Article 6(1), point (a), or Article 9(2), point (a), or of a contract pursuant to Article 6(1), point (b) of that Regulation. Data subjects also have the right to have the personal data transmitted directly from one controller to another, but only where that is technically feasible. Article 20 of General Data Protection Regulation (GDPR) specifies that it pertains to data provided by the data subject but does not specify whether this necessitates active behaviour on the side of the data subject or whether it also applies to situations where a connected product or related service, by its design, observes the behaviour of a data subject or other information in relation to a data subject in a passive manner. The rights provided for under this Regulation complement the right to receive and port personal data under Article 20 of General Data Protection Regulation (GDPR) in a number of ways. This Regulation grants users the right to access and make available to a third party any product data or related service data, irrespective of their nature as personal data, of the distinction between actively provided or passively observed data, and irrespective of the legal basis of processing. Unlike Article 20 of General Data Protection Regulation (GDPR), this Regulation mandates and ensures the technical feasibility of third party access for all types of data falling within its scope, whether personal or non-personal, thereby ensuring that technical obstacles no longer hinder or prevent access to such data. It also allows data holders to set reasonable compensation to be met by third parties, but not by the user, for costs incurred in providing direct access to the data generated by the user’s connected product. If a data holder and a third party are unable to agree on terms for such direct access, the data subject should in no way be prevented from exercising the rights laid down in General Data Protection Regulation (GDPR), including the right to data portability, by seeking remedies in accordance with that Regulation. It is to be understood in this context that, in accordance with General Data Protection Regulation (GDPR), a contract does not allow for the processing of special categories of personal data by the data holder or the third party.