EU Data Governance Act — a sharing infrastructure built on neutrality.
Compliance for data intermediary services, public-sector data re-use, data altruism organisations, and EU data space participants under Regulation (EU) 2022/868.
Overview
Where GDPR governs processing, the DGA governs sharing.
The Data Governance Act — Regulation (EU) 2022/868 — has been in force since 24 September 2023 with no transitional period. It governs how data is shared between organisations, public bodies, and individuals across the EU. Where GDPR regulates how personal data is processed, the DGA regulates how data — both personal and non-personal — is shared and made available.
The regulation creates a new infrastructure for trusted data sharing: rules for public sector data re-use, a registration regime for data intermediary services (data marketplaces, sector data exchanges, personal data spaces, brokers), and a recognition regime for data altruism organisations. The DGA does not override GDPR — where data sharing involves personal data, GDPR continues to apply in full.
Who the DGA applies to
Direct obligations fall on a few specific categories. Indirect impacts are wider.
Public sector bodies re-using protected data
Government bodies and public institutions holding data protected by confidentiality rules — trade secrets, statistical data, third-party IP. Specific Chapter II conditions apply.
Data intermediary service providers
Data marketplaces, sector data exchanges, personal data spaces, brokering services. Must notify the national competent authority before operating.
Data altruism organisations
Non-profits collecting data donated voluntarily for general-interest purposes — research, climate, urban planning. May register as recognised data altruism organisations to gain a trust mark.
EU data space participants
Sector-specific data ecosystems — health (EHDS), mobility, energy, agriculture, manufacturing. Participation increasingly a commercial expectation in those sectors.
Indirect: businesses with intermediary or data-altruism customers
If your clients or partners are subject to the DGA, expect contractual flow-down of neutrality, transparency, and security obligations.
Key chapters
What the DGA actually requires.
- 01Ch. II · Arts 3–8
Re-use of protected public sector data
Public bodies must comply with specific conditions: appropriate technical and organisational measures, proportionate fees, transparency about re-use conditions.
- 02Ch. III · Arts 9–15
Data intermediary services
Providers must notify the national competent authority before operating. Cannot use data for their own commercial purposes. Must maintain strict separation between intermediary and other activities. Must implement appropriate technical and security measures.
- 03Ch. IV · Arts 16–22
Data altruism
Recognised organisations must meet specific governance, transparency, security, and accountability requirements — public register of data uses, restriction to stated altruistic purposes, annual activity reports to the competent authority.
- 04Ch. V · Arts 23–29
European Data Innovation Board
EDIB coordinates the development of common standards for EU data spaces — sector-specific data ecosystems in health, energy, mobility, agriculture, manufacturing.
Penalties & consequences
National penalties — and operational suspension.
The DGA is enforced by national competent authorities designated by each member state. Penalties for non-compliance are set by national law — the DGA requires them to be effective, proportionate, and dissuasive.
Data intermediary service providers operating without notification, failing to meet neutrality obligations, or misusing data entrusted to them face suspension from operating and, depending on national implementation, significant financial penalties. Designations vary by member state — for example, France has the CNIL for personal-data DGA functions, while other member states (Germany, Italy, Spain, the Netherlands, Belgium) designate their own competent authorities for different DGA functions. Data intermediary service providers operating today without notification are already in violation, regardless of country.
Penalty structure
National
each member state sets penalties that must be effective, proportionate, and dissuasive.
Operational sanction
Suspension
data intermediaries operating without notification face suspension.
Competent authority
Per state
each EU member state designates its own — e.g. CNIL in France for personal-data functions; other authorities elsewhere.
Our approach
DGA scoping, governance design, integrated GDPR coverage.
What we deliver
- Scoping assessment — confirms whether and how DGA applies to your specific business activities and data flows
- Notification support for data intermediary service providers — preparation of national authority notification
- Governance framework for neutrality, transparency, and separation of activities (where intermediary)
- Recognised data altruism organisation registration support — governance, transparency, accountability requirements
- Public sector body re-use conditions framework (where applicable)
- Integrated DGA + GDPR program — sharing infrastructure plus personal data protection in one design
- EU data space readiness — preparation for participation in sectoral data spaces (EHDS, mobility, etc.)
- Ongoing compliance under our vCISO service for the security and governance dimensions
Typical timeline
Scope-dependent. Most engagements are a focused governance build.
Weeks 1–2
Scoping
Confirm direct vs indirect DGA applicability. Map data flows. Identify chapter-specific obligations.
Weeks 3–8
Governance build
Notification preparation, neutrality framework, security and transparency controls, public register design (where altruism).
Ongoing
Operational compliance
Annual activity reports (altruism organisations), supervisory authority interactions, GDPR alignment for personal data flows.
FAQ