Data Act
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – BUSINESS TO CONSUMER AND BUSINESS TO BUSINESS DATA SHARING
Chapter III – OBLIGATIONS FOR DATA HOLDERS OBLIGED TO MAKE DATA AVAILABLE PURSUANT TO UNION LAW
Chapter IV – UNFAIR CONTRACTUAL TERMS RELATED TO DATA ACCESS AND USE BETWEEN ENTERPRISES
Chapter V – MAKING DATA AVAILABLE TO PUBLIC SECTOR BODIES, THE COMMISSION, THE EUROPEAN CENTRAL BANK AND UNION BODIES ON THE BASIS OF AN EXCEPTIONAL NEED
Chapter VI – SWITCHING BETWEEN DATA PROCESSING SERVICES
Chapter VII – UNLAWFUL INTERNATIONAL GOVERNMENTAL ACCESS AND TRANSFER OF NON-PERSONAL DATA
Chapter VIII – INTEROPERABILITY
Chapter IX – IMPLEMENTATION AND ENFORCEMENT
Chapter X – SUI GENERIS RIGHT UNDER DIRECTIVE 96/9/EC
Chapter XI – FINAL PROVISIONS
Recitals (119)
Recital 7
(7) The fundamental right to the protection of personal data is safeguarded, in particular, by General Data Protection Regulation (GDPR) ( 6 ) and (EU) 2018/1725 ( 7 ) of the European Parliament and of the Council. ePrivacy Directive (Electronic Communications) of the European Parliament and of the Council ( 8 ) additionally protects private life and the confidentiality of communications, including by way of conditions on any personal and non-personal data storing in, and access from, terminal equipment. Those Union legislative acts provide the basis for sustainable and responsible data processing, including where datasets include a mix of personal and non-personal data. This Regulation complements and is without prejudice to Union law on the protection of personal data and privacy, in particular General Data Protection Regulation (GDPR) and (EU) 2018/1725 and ePrivacy Directive (Electronic Communications). No provision of this Regulation should be applied or interpreted in such a way as to diminish or limit the right to the protection of personal data or the right to privacy and confidentiality of communications. Any processing of personal data pursuant to this Regulation should comply with Union data protection law, including the requirement of a valid legal basis for processing under Article 6 of General Data Protection Regulation (GDPR) and, where relevant, the conditions of Article 9 of that Regulation and of Article 5(3) of ePrivacy Directive (Electronic Communications). This Regulation does not constitute a legal basis for the collection or generation of personal data by the data holder. This Regulation imposes an obligation on data holders to make personal data available to users or third parties of a user’s choice upon that user’s request. Such access should be provided to personal data that are processed by the data holder on the basis of any of the legal bases referred to in Article 6 of General Data Protection Regulation (GDPR). Where the user is not the data subject, this Regulation does not create a legal basis for providing access to personal data or for making personal data available to a third party and should not be understood as conferring any new right on the data holder to use personal data generated by the use of a connected product or related service. In those cases, it could be in the interest of the user to facilitate meeting the requirements of Article 6 of General Data Protection Regulation (GDPR). As this Regulation should not adversely affect the data protection rights of data subjects, the data holder can comply with requests in those cases, inter alia, by anonymising personal data or, where the readily available data contains personal data of several data subjects, transmitting only personal data relating to the user.