Data Governance Act (DGA)
Table of Contents
Chapter I – General provisions
Chapter II – Re-use of certain categories of protected data held by public sector bodies
Chapter III – Requirements applicable to data intermediation services
Chapter IV – Data altruism
Chapter V – Competent authorities and procedural provisions
Chapter VI – European Data Innovation Board
Chapter VII – International access and transfer
Chapter VIII – Delegation and committee procedure
Chapter IX – Final and transitional provisions
Recitals (63)
Recital 50
(50) Recognised data altruism organisations should be able to collect relevant data directly from natural and legal persons or to process data collected by others. Processing of collected data could be done by data altruism organisations for purposes which they establish themselves or, where relevant, they could allow the processing by third parties for those purposes. Where recognised data altruism organisations are data controllers or processors as defined in General Data Protection Regulation (GDPR), they should comply with that Regulation. Typically, data altruism would rely on consent of data subjects within the meaning of Article 6(1), point (a), and Article 9(2), point (a), of General Data Protection Regulation (GDPR) that should be in compliance with requirements for lawful consent in accordance with Articles 7 and 8 of that Regulation. In accordance with General Data Protection Regulation (GDPR), scientific research purposes could be supported by consent to certain areas of scientific research where in keeping with recognised ethical standards for scientific research or only to certain areas of research or parts of research projects. Article 5(1), point (b), of General Data Protection Regulation (GDPR) specifies that further processing for scientific or historical research purposes or statistical purposes should, in accordance with Article 89(1) of General Data Protection Regulation (GDPR), not be considered to be incompatible with the initial purposes. For non-personal data the usage limitations should be found in the permission given by the data holder.