keyboard_tab Data Act 2023/2854 EN
BG CS DA DE EL EN ES ET FI FR GA HR HU IT LV LT MT NL PL PT RO SK SL SV print pdf
- Article 1 Subject matter and scope
- Article 2 Definitions
- Article 3 Obligation to make product data and related service data accessible to the user
- Article 4 The rights and obligations of users and data holders with regard to access, use and making available product data and related service data
- Article 5 Right of the user to share data with third parties
- Article 6 Obligations of third parties receiving data at the request of the user
- Article 7 Scope of business-to-consumer and business-to-business data sharing obligations
- Article 8 Conditions under which data holders make data available to data recipients
- Article 9 Compensation for making data available
- Article 10 Dispute settlement
- Article 11 Technical protection measures on the unauthorised use or disclosure of data
- Article 12 Scope of obligations for data holders obliged pursuant to Union law to make data available
- Article 13 Unfair contractual terms unilaterally imposed on another enterprise
- Article 14 Obligation to make data available on the basis of an exceptional need
- Article 15 Exceptional need to use data
- Article 16 Relationship with other obligations to make data available to public sector bodies, the Commission, the European Central Bank and Union bodies
- Article 17 Requests for data to be made available
- Article 18 Compliance with requests for data
- Article 19 Obligations of public sector bodies, the Commission, the European Central Bank and Union bodies
- Article 20 Compensation in cases of an exceptional need
- Article 21 Sharing of data obtained in the context of an exceptional need with research organisations or statistical bodies
- Article 22 Mutual assistance and cross-border cooperation
- Article 23 Removing obstacles to effective switching
- Article 24 Scope of the technical obligations
- Article 25 Contractual terms concerning switching
- Article 26 Information obligation of providers of data processing services
- Article 27 Obligation of good faith
- Article 28 Contractual transparency obligations on international access and transfer
- Article 29 Gradual withdrawal of switching charges
- Article 30 Technical aspects of switching
- Article 31 Specific regime for certain data processing services
- Article 32 International governmental access and transfer
- Article 33 Essential requirements regarding interoperability of data, of data sharing mechanisms and services, as well as of common European data spaces
- Article 34 Interoperability for the purposes of in-parallel use of data processing services
- Article 35 Interoperability of data processing services
- Article 36 Essential requirements regarding smart contracts for executing data sharing agreements
- Article 37 Competent authorities and data coordinators
- Article 38 Right to lodge a complaint
- Article 39 Right to an effective judicial remedy
- Article 40 Penalties
- Article 41 Model contractual terms and standard contractual clauses
- Article 42 Role of the EDIB
- Article 43 Databases containing certain data
- Article 44 Other Union legal acts governing rights and obligations on data access and use
- Article 45 Exercise of the delegation
- Article 46 Committee procedure
- Article 47 Amendment to Regulation (EU) 2017/2394
- Article 48 Amendment to Directive (EU) 2020/1828
- Article 49 Evaluation and review
- Article 50 Entry into force and application
CHAPTER I
GENERAL PROVISIONS
CHAPTER II
BUSINESS TO CONSUMER AND BUSINESS TO BUSINESS DATA SHARING
CHAPTER III
OBLIGATIONS FOR DATA HOLDERS OBLIGED TO MAKE DATA AVAILABLE PURSUANT TO UNION LAW
CHAPTER IV
UNFAIR CONTRACTUAL TERMS RELATED TO DATA ACCESS AND USE BETWEEN ENTERPRISES
CHAPTER V
MAKING DATA AVAILABLE TO PUBLIC SECTOR BODIES, THE COMMISSION, THE EUROPEAN CENTRAL BANK AND UNION BODIES ON THE BASIS OF AN EXCEPTIONAL NEED
CHAPTER VI
SWITCHING BETWEEN DATA PROCESSING SERVICES
CHAPTER VII
UNLAWFUL INTERNATIONAL GOVERNMENTAL ACCESS AND TRANSFER OF NON-PERSONAL DATA
CHAPTER VIII
INTEROPERABILITY
CHAPTER IX
IMPLEMENTATION AND ENFORCEMENT
CHAPTER X
SUI GENERIS RIGHT UNDER DIRECTIVE 96/9/EC
CHAPTER XI
FINAL PROVISIONS
- data
- metadata
- personal data
- non-personal data
- connected product
- related service
- processing
- data processing service
- same service type
- data intermediation service
- data subject
- user
- data holder
- data recipient
- product data
- related service data
- readily available data
- trade secret
- trade secret holder
- profiling
- making available on the market
- placing on the market
- consumer
- enterprise
- small enterprise
- microenterprise
- Union bodies
- public sector body
- public emergency
- customer
- virtual assistants
- digital assets
- on-premises ICT infrastructure
- switching
- data egress charges
- switching charges
- functional equivalence
- exportable data
- smart contract
- interoperability
- common specifications
- harmonised standard
- data 21
- user 11
- third 9
- party 7
- article 6
- receives 6
- available 6
- agreed 5
- holder 4
- shall 4
- including 4
- trade_secrets 3
- choices 3
- make 3
- necessary 3
- unless 3
- made 3
- parties 3
- pursuant 3
- manner 2
- from 2
- product 2
- under 2
- related_service 2
- non-personal 2
- confidentiality 2
- another 2
- purpose 2
- basis 2
- connected_product 2
- personal 2
- contract 2
- subject 2
- eu / 2
- regulation 2
- rights 2
- measures 2
- prevent 1
- provided 1
- consumer 1
- undertaking 1
- designated 1
- gatekeeper 1
- takes 1
- develop 1
- competes 1
- preserve 1
- between 1
- security 1
- which 1
Article 6
Obligations of third parties receiving data at the request of the user
1. A third party shall process the data made available to it pursuant to Article 5 only for the purposes and under the conditions agreed with the user and subject to Union and national law on the protection of personal data including the rights of the data subject insofar as personal data are concerned. The third party shall erase the data when they are no longer necessary for the agreed purpose, unless otherwise agreed with the user in relation to non-personal data.
2. The third party shall not:
(a) | make the exercise of choices or rights under Article 5 and this Article by the user unduly difficult, including by offering choices to the user in a non-neutral manner, or by coercing, deceiving or manipulating the user, or by subverting or impairing the autonomy, decision-making or choices of the user, including by means of a user digital interface or a part thereof; |
(b) | notwithstanding Article 22(2), points (a) and (c), of Regulation (EU) 2016/679, use the data it receives for the profiling, unless it is necessary to provide the service requested by the user; |
(c) | make the data it receives available to another third party, unless the data is made available on the basis of a contract with the user, and provided that the other third party takes all necessary measures agreed between the data holder and the third party to preserve the confidentiality of trade_secrets; |
(d) | make the data it receives available to an undertaking designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925; |
(e) | use the data it receives to develop a product that competes with the connected_product from which the accessed data originate or share the data with another third party for that purpose; third parties shall also not use any non-personal product data or related_service data made available to them to derive insights about the economic situation, assets and production methods of, or use by, the data holder; |
(f) | use the data it receives in a manner that has an adverse impact on the security of the connected_product or related_service; |
(g) | disregard the specific measures agreed with a data holder or with the trade_secrets holder pursuant to Article 5(9) and undermine the confidentiality of trade_secrets; |
(h) | prevent the user that is a consumer, including on the basis of a contract, from making the data it receives available to other parties. |
whereas