Data Governance Act
The Data Governance Act (Regulation (EU) 2022/868) is the EU framework governing the re-use of protected public sector data, neutral data intermediation services and voluntary data altruism – without lowering the level of protection set by the GDPR.
The Data Governance Act (DGA), formally Regulation (EU) 2022/868 on European data governance, entered into force on 23 June 2022 and has applied directly across all Member States since 24 September 2023. It is one pillar of the European data strategy and pursues a different aim than the GDPR: while the GDPR protects personal data, the DGA builds the structures and trust mechanisms that make data sharing and re-use possible in the first place. The DGA is explicitly not a second layer of data protection law – Article 1(3) DGA makes clear that the GDPR remains unaffected and prevails in the event of a conflict. In particular, the DGA does not create a legal basis of its own for processing personal data.
The regulation rests on three pillars. First, Articles 3 to 9 DGA govern the re-use of protected data held by public sector bodies that fall outside the Open Data Directive because they involve trade secrets, statistical confidentiality, third-party intellectual property rights or personal data; the conditions include non-discriminatory terms, proportionate fees, secure processing environments and anonymisation or pseudonymisation. Second, Articles 10 to 15 DGA subject data intermediation services to a notification regime and a strict neutrality requirement: anyone brokering between data holders and data users must not exploit the intermediated data for their own purposes and must run the service as a legally and commercially separate activity; in return, the provider may use the EU label "data intermediation services provider recognised in the Union". Third, Articles 16 to 25 DGA cover data altruism: organisations that pool data voluntarily and without reward for objectives of general interest such as research, health or climate protection can register as a "data altruism organisation recognised in the Union", subject to transparency, record-keeping and purpose-limitation duties; Article 25 DGA provides for a single European data altruism consent form.
For supervision, Member States designate competent authorities for data intermediation services and data altruism as well as single information points, while the European Data Innovation Board advises at Union level. In Germany the national implementing legislation was substantially delayed; the Federal Network Agency (Bundesnetzagentur) is foreseen as the competent authority, whereas supervision of personal data remains with the data protection authorities. In practice this means a double assessment: alongside the DGA duties, any processing of personal data still needs a legal basis under Article 6 GDPR – and, for special categories, under Article 9 GDPR – plus a clear allocation of roles and safeguards for transfers to third countries. The DGA also operates alongside the Data Act (Regulation (EU) 2023/2854), which creates access and switching rights for connected product data. Note that the European Commission has initiated a streamlining and partial consolidation of EU data law through its digital omnibus proposals; whether and how the DGA will be amended or folded into the Data Act has not yet been finally decided.
Legal Basis
Regulation (EU) 2022/868 (Data Governance Act), in particular Art. 3–9 (re-use of public sector data), Art. 10–15 (data intermediation services), Art. 16–25 (data altruism), Art. 1(3) DGA in conjunction with the GDPR
Practical Example
A mid-sized analytics company plans a platform on which hospitals can make treatment data available to research partners. The data protection officer starts with the classification: because the platform only brokers between data holders and data users and does not analyse the data for its own products, it qualifies as a data intermediation service under Article 10 DGA. That triggers a notification to the competent authority before starting operations, legal and commercial separation of the brokerage business from the remaining analytics business, and a ban on monetising the intermediated data itself. In parallel, the data protection officer documents the GDPR layer: the legal basis for transferring health data (explicit consent under Article 9(2)(a) GDPR or a research provision of national law), the allocation of roles between hospital, platform and research partner, a processing agreement for the technical hosting, a data protection impact assessment and a secure processing environment with pseudonymisation. The result: the DGA governs how the brokering works, while the lawfulness of the processing itself remains a GDPR question.