Data Governance Act

EU

EU Data Governance Act — a sharing infrastructure built on neutrality.

Compliance for data intermediary services, public-sector data re-use, data altruism organisations, and EU data space participants under Regulation (EU) 2022/868.

Overview

Where GDPR governs processing, the DGA governs sharing.

The Data Governance Act — Regulation (EU) 2022/868 — has been in force since 24 September 2023 with no transitional period. It governs how data is shared between organisations, public bodies, and individuals across the EU. Where GDPR regulates how personal data is processed, the DGA regulates how data — both personal and non-personal — is shared and made available.

The regulation creates a new infrastructure for trusted data sharing: rules for public sector data re-use, a registration regime for data intermediary services (data marketplaces, sector data exchanges, personal data spaces, brokers), and a recognition regime for data altruism organisations. The DGA does not override GDPR — where data sharing involves personal data, GDPR continues to apply in full.

Who the DGA applies to

Direct obligations fall on a few specific categories. Indirect impacts are wider.

  • Public sector bodies re-using protected data

    Government bodies and public institutions holding data protected by confidentiality rules — trade secrets, statistical data, third-party IP. Specific Chapter II conditions apply.

  • Data intermediary service providers

    Data marketplaces, sector data exchanges, personal data spaces, brokering services. Must notify the national competent authority before operating.

  • Data altruism organisations

    Non-profits collecting data donated voluntarily for general-interest purposes — research, climate, urban planning. May register as recognised data altruism organisations to gain a trust mark.

  • EU data space participants

    Sector-specific data ecosystems — health (EHDS), mobility, energy, agriculture, manufacturing. Participation increasingly a commercial expectation in those sectors.

  • Indirect: businesses with intermediary or data-altruism customers

    If your clients or partners are subject to the DGA, expect contractual flow-down of neutrality, transparency, and security obligations.

Key chapters

What the DGA actually requires.

  1. 01Ch. II · Arts 3–8

    Re-use of protected public sector data

    Public bodies must comply with specific conditions: appropriate technical and organisational measures, proportionate fees, transparency about re-use conditions.

  2. 02Ch. III · Arts 9–15

    Data intermediary services

    Providers must notify the national competent authority before operating. Cannot use data for their own commercial purposes. Must maintain strict separation between intermediary and other activities. Must implement appropriate technical and security measures.

  3. 03Ch. IV · Arts 16–22

    Data altruism

    Recognised organisations must meet specific governance, transparency, security, and accountability requirements — public register of data uses, restriction to stated altruistic purposes, annual activity reports to the competent authority.

  4. 04Ch. V · Arts 23–29

    European Data Innovation Board

    EDIB coordinates the development of common standards for EU data spaces — sector-specific data ecosystems in health, energy, mobility, agriculture, manufacturing.

Penalties & consequences

National penalties — and operational suspension.

The DGA is enforced by national competent authorities designated by each member state. Penalties for non-compliance are set by national law — the DGA requires them to be effective, proportionate, and dissuasive.

Data intermediary service providers operating without notification, failing to meet neutrality obligations, or misusing data entrusted to them face suspension from operating and, depending on national implementation, significant financial penalties. Designations vary by member state — for example, France has the CNIL for personal-data DGA functions, while other member states (Germany, Italy, Spain, the Netherlands, Belgium) designate their own competent authorities for different DGA functions. Data intermediary service providers operating today without notification are already in violation, regardless of country.

  • Penalty structure

    National

    each member state sets penalties that must be effective, proportionate, and dissuasive.

  • Operational sanction

    Suspension

    data intermediaries operating without notification face suspension.

  • Competent authority

    Per state

    each EU member state designates its own — e.g. CNIL in France for personal-data functions; other authorities elsewhere.

Our approach

DGA scoping, governance design, integrated GDPR coverage.

What we deliver

  • Scoping assessment — confirms whether and how DGA applies to your specific business activities and data flows
  • Notification support for data intermediary service providers — preparation of national authority notification
  • Governance framework for neutrality, transparency, and separation of activities (where intermediary)
  • Recognised data altruism organisation registration support — governance, transparency, accountability requirements
  • Public sector body re-use conditions framework (where applicable)
  • Integrated DGA + GDPR program — sharing infrastructure plus personal data protection in one design
  • EU data space readiness — preparation for participation in sectoral data spaces (EHDS, mobility, etc.)
  • Ongoing compliance under our vCISO service for the security and governance dimensions

Typical timeline

Scope-dependent. Most engagements are a focused governance build.

  1. Weeks 1–2

    Scoping

    Confirm direct vs indirect DGA applicability. Map data flows. Identify chapter-specific obligations.

  2. Weeks 3–8

    Governance build

    Notification preparation, neutrality framework, security and transparency controls, public register design (where altruism).

  3. Ongoing

    Operational compliance

    Annual activity reports (altruism organisations), supervisory authority interactions, GDPR alignment for personal data flows.

FAQ

Common questions.

Does the DGA apply to my business if we are not a data intermediary?
The DGA's direct obligations fall most heavily on data intermediary service providers and data altruism organisations. If your organisation does not provide these services and does not re-use protected public-sector data, the DGA does not impose direct compliance obligations on you. It can still affect you indirectly — if you participate in a sector data space, if your clients or partners are intermediaries or public bodies subject to the DGA, or if you supply connected products whose data may fall under the related Data Act.
What is a data intermediary under the DGA?
A service provider that facilitates the voluntary sharing of data between data holders and data users — acting as a neutral third party. Examples: data marketplaces, sector data exchanges, personal data management services, data brokering platforms. The DGA explicitly excludes cloud providers, data analytics services, and other businesses that process data for their own commercial purposes rather than facilitating sharing between third parties.
How does the DGA interact with GDPR when shared data includes personal data?
When data shared under the DGA includes personal data, GDPR continues to apply in full. The DGA does not create a new lawful basis for processing personal data — it creates a governance infrastructure within which GDPR-compliant data sharing can happen more efficiently. Any data intermediary handling personal data must simultaneously comply with the DGA's neutrality and registration requirements, GDPR's lawful basis, data subject rights, and security obligations, and potentially national data protection law.
What are EU data spaces and how might they affect our business?
EU data spaces are sector-specific ecosystems where organisations within a sector — health, mobility, energy, agriculture, manufacturing, finance — pool and share data under governed, standardised conditions enabled by the DGA. For businesses in affected sectors, participation may become a commercial expectation from clients and partners, a prerequisite for public procurement, or a source of competitive advantage. The European Health Data Space (EHDS), for example, is already creating significant compliance and governance obligations for healthcare and digital-health companies.
What's the difference between the Data Governance Act and the Data Act?
They are complementary but distinct. The DGA establishes the governance infrastructure for voluntary data sharing — registration regimes, frameworks for public-sector data re-use. The Data Act (Regulation (EU) 2023/2854, in force September 2025) gives users of connected products and related services the right to access and share data generated by those products — IoT, smart appliances, industrial machinery. DGA = who can share data and under what conditions. Data Act = who has the right to access data generated by connected products.
Is there a DGA compliance deadline we need to meet?
The DGA has been fully in force since 24 September 2023 — there is no transitional period for entities currently operating data intermediary services that were established before that date. Data intermediary service providers operating *today* without notification to their national competent authority are already in violation. New businesses intending to provide data intermediary services must notify before commencing operations.