Data sharing law and data spaces
By the end of this module you will be able to:
- State the EU Data Act connected-product access rights and the dates they bite
- Explain fair, reasonable and non-discriminatory business sharing and the cloud switching rights
- Place the Data Governance Act and data altruism in the wider sharing regime
- Describe the common European data spaces and health as the flagship sector
- State the direction of travel for UK smart data schemes
Each Data Act date binds a different set of parties
The EU Data Act arrives on four dates, not one: entry into force binds everyone and changes nothing, while the three later dates bind data holders and users, then product manufacturers, then cloud providers, so what decides your work is which date binds you.
The EU Data Act arrives on four dates, not one, and each date binds a different actor: everyone at entry into force, data holders and users when it becomes applicable, product manufacturers for design, and cloud providers for switching fees. Ask which date binds you before asking what the Act says.
Sectoral data spaces all draw on one interoperability core
A sector data space is sector rules bolted on to one shared interoperability core, which solves identity and trust, vocabularies, access rules and audit once for every sector rather than five times over.
A sector data space is sector rules bolted on to one shared interoperability core, so identity and trust, vocabularies, access rules and audit are solved once rather than five times. Health is the space already in force; the rest inherit the same core when their turn comes.
The farmer bought the tractor. Who bought the yield data it records?
For most of the connected-product era the answer sat in the purchase contract and the terms of the manufacturer portal. A farmer could usually see a dashboard, could rarely export the underlying records in a usable form, and almost never had a way to send the same records to a competing service provider. The commercial effect was that the aftermarket for repair, agronomy advice, insurance pricing and resale valuation ran on whatever the machine maker chose to release.
That is the imbalance the European legislator set out to correct. Rather than regulate one sector at a time, it wrote a horizontal rule that applies to connected products generally, from tractors and wind turbines to washing machines and vehicle telematics units. The user of the product gains a right to the data its use generates, and a right to have that data passed to a third party of their choosing.
The interesting consequence is not the right itself. It is that a design decision taken years before a farmer places an order now has a legal consequence. If the data cannot be extracted, the product does not comply. Access has moved from being a feature of the portal to being a property of the product.
A modern combine harvester records yield, moisture, fuel burn, engine load and field position at metre resolution. The farmer paid for the machine. The manufacturer holds the telemetry. Who may read it, and who may pass it to an independent repair workshop or an agronomy adviser?
Everything earlier in this stage has treated sharing as a choice an organisation makes and then governs. This module deals with the cases where sharing is not a choice. Three instruments now sit behind data sharing in Europe, and a fourth route is being built in the United Kingdom. They differ in what they compel, whom they bind, and when they start to bite, and confusing them is the most common error in this area.
Sharing law does not begin with data. It begins with a bargaining problem: the party that holds the data is usually the party that wrote the contract.
45.1 What data sharing law is trying to fix
Data has an awkward economic property. It costs a great deal to generate the first copy and almost nothing to make the second, so the party holding it has every reason to keep it and very little reason to release it. Where the holder also writes the contract, as a machinery manufacturer or a cloud provider does, the market does not correct the imbalance on its own. Voluntary sharing works well between equals and poorly between a large platform and its customers.
Governance frameworks address the same imbalance from the inside. A well-drafted records the purpose, the parties, the lawful basis each relies on, what is shared and how long it is kept. That is the right instrument when two willing organisations want a defensible record of what they agreed. It is the wrong instrument when one side has no realistic ability to negotiate at all.
Legislation fills that second gap. It does so in three distinct ways, and separating them makes the rest of this module much easier. Some rules create an access right, so a party who previously had no claim on the data acquires one. Some rules constrain terms, so a party who already had to share must now do so on stated conditions rather than conditions of its choosing. Some rules create infrastructure and recognition, so that sharing which was always permitted becomes practically achievable across an entire sector.
Note what none of them do. None of these instruments displaces data protection law. Where the records in question are , a lawful basis, a purpose, a retention position and the rights of the individual all still apply on top. A right to receive data is not a permission to process it for any purpose the recipient fancies, and reading a sharing regulation as though it silently amends the General Data Protection Regulation is a reliable way to build something unlawful.
“effective, efficient, and acceptable use of data”
ISO/IEC 38505-1:2017 - Scope
The standard frames data governance as a governing body duty across three tests. Sharing law makes the third test external rather than internal: acceptability is no longer only what the board is willing to defend, it is what a regulation obliges the organisation to permit.
The first of the three instruments creates an access right, and it is the one with a calendar attached.
45.2 The connected product access right
The , Regulation (EU) 2023/2854, gives the user of a connected product a right of access to the data that the use of that product generates, and a right to require the data holder to make that data available to a third party the user nominates. The user may be a consumer or a business. The third party may be an independent repairer, an insurer, an analytics provider or a competitor of the manufacturer, with one notable exclusion: an undertaking designated as a gatekeeper under the Digital Markets Act is not an eligible recipient under this route.
The Act arrives on four dates rather than one, and the figure above is built around that fact because it is where most compliance mistakes start. It entered into force on 11 January 2024, which created the text but bound nobody to act. It became applicable on 12 September 2025, at which point the access and use duties on data holders and the corresponding rights of users became live. From 12 September 2026 a design obligation attaches to connected products and related services placed on the market after that date. From 12 January 2027 the charging rules for switching a provider of data processing services change again.
The design obligation is the one that reaches engineering rather than legal. It requires that connected products and connected services be designed so that the data they generate is accessible to the user by default, directly where the product allows it, in a structured, commonly used and machine readable form, securely and free of charge. A product that meets the access duty by having a support desk assemble a spreadsheet on request satisfies nobody once that date applies to it.
Ask the date question before the substance question. A vehicle telematics unit placed on the market in 2024 sits under the access duties but not the design duty. A sensor line launched in 2027 sits under both. Two products in the same catalogue can therefore carry different obligations, which is why the compliance record has to be held per product line and per placement date rather than per company.
Common misconception
“The EU Data Act applied from a single date, so if we were compliant in September 2025 we are compliant now.”
The Act arrives on four dates and each binds a different party. Entry into force on 11 January 2024 created the text without binding anyone to act. Applicability on 12 September 2025 started the access and use duties for data holders and users. From 12 September 2026 a design obligation attaches to connected products and related services placed on the market after that date. From 12 January 2027 switching charges for data processing services stop. An organisation that treated September 2025 as the finish line has two later duties still ahead of it, and they land on product engineering and on cloud contracting rather than on the legal function that ran the first exercise.
An access right settles who may ask. It does not settle what the holder may charge or insist upon, which is the second kind of rule.
45.3 Sharing on fair and non-discriminatory terms
Where a data holder is obliged to make data available to a data recipient, the Data Act requires it to do so under terms and conditions that are fair, reasonable and non-discriminatory, and in a transparent manner. The abbreviation FRAND is borrowed from standard-essential patent licensing, where the same problem arises: a party that must license cannot be allowed to price the obligation into irrelevance.
Each word carries weight. Fair excludes terms that would be unconscionable between commercial parties. Reasonable governs the level of any compensation, which may cover the cost of making the data available and, between businesses, a margin. Non-discriminatory prevents a data holder from quoting one price to an independent repair network and a different one to its own subsidiary for materially the same access. Transparent means the basis of the terms has to be capable of being stated rather than left to negotiation in the dark.
The Act also polices the contract itself. Terms about data access and liability that are unilaterally imposed on another enterprise and that depart grossly from good commercial practice can be found unfair and are not binding on the party they were imposed on. Separately, a public sector body may request data held by a business where it demonstrates an exceptional need, such as responding to a public emergency. That is a narrow gateway with its own conditions, not a general power for administrations to help themselves to commercial data.
Two practical consequences follow for anyone building the pipeline behind a sharing obligation. First, the cost of serving a request has to be measurable, because a compensation figure that cannot be explained cannot be shown to be reasonable. Second, the same interface should serve every recipient class, because the cheapest way to prove non-discrimination is to have only one path to discriminate with.
The same Act treats a second lock-in problem with the same logic, except here the asset held hostage is not telemetry. It is the workload itself.
45.4 Switching a provider of data processing services
The Data Act treats as a customer right rather than a commercial favour. A customer of a data processing service, which covers cloud and edge services, must be able to move to another provider or bring the workload back in house, and the provider has duties to make that move possible within a defined process rather than obstruct it.
Charging is handled on a schedule rather than a switch. Between 11 January 2024 and 12 January 2027 a provider may impose reduced switching charges that do not exceed the costs it actually incurs and that are directly linked to the switching process concerned. From 12 January 2027 providers of data processing services must not impose switching charges for the switching process at all. This is why the fourth station on the timeline binds cloud providers rather than manufacturers.
Read the right narrowly and it is disappointing. It does not oblige a competitor to offer the same managed services, and it does not make a proprietary query engine portable. What it does remove is the part of exit cost that was never technical: the egress bill. Once the fee floor is gone, the remaining barrier is the honest one, namely how much service-specific behaviour the architecture absorbed while nobody was measuring.
The operational lesson for a data platform team is to treat exit as a rehearsed procedure. Know which formats leave cleanly, which service behaviours have no equivalent elsewhere, and how long a full extraction of the current estate actually takes. A team that has never measured its own egress time cannot tell the difference between a right it holds and a right it can use.
The Data Act says who may demand data and on what terms. A separate regulation deals with the parties who stand between holders and users, and with data given away rather than traded.
45.5 The Data Governance Act, intermediaries and altruism
Regulation (EU) 2022/868, the Data Governance Act, entered into force on 23 June 2022 and has applied since 24 September 2023. It is the enabling instrument rather than the compelling one, and reading it as a mandate is the single most common error. It sets conditions for the re-use of protected data held by public sector bodies, where that data is commercially confidential, statistically confidential, covered by third party intellectual property rights, or personal. It does not create a right to obtain that data, and it does not require any public body to open anything that national law keeps closed.
Its second strand regulates the . A provider of data intermediation services connects those who hold data with those who want to use it, and under the regulation it must notify its activity, keep the intermediation service structurally separate from any other service it runs, and refrain from using the data it passes on for its own purposes. It charges for the service, not for the data. That structural separation is what distinguishes an intermediary from a data broker, and it is a design constraint rather than a promise in a policy document.
The third strand is : people and organisations making data available voluntarily and without reward for objectives of general interest, such as medical research, environmental monitoring or improving public services. Organisations that collect on this basis may register as recognised data altruism organisations, which requires a not-for-profit character, transparency obligations and entry on a public register. The point of the register is that a public interest purpose becomes checkable rather than merely asserted.
A fourth strand creates the European Data Innovation Board to coordinate practice across member states. Taken together the four strands explain why the Data Governance Act and the Data Act are so often confused and so rarely interchangeable. One builds the plumbing and the trusted roles; the other creates the obligations that make anyone use them.
Common misconception
“The Data Governance Act requires public bodies to release the protected data they hold for re-use.”
It does not. The regulation harmonises the conditions that apply when re-use of protected public sector data is permitted, covering exclusivity, fees, secure processing environments and assistance to re-users. Whether a particular dataset may be re-used at all remains a question for the underlying national law and for data protection law where the records are personal. Treating the Data Governance Act as an access right leads teams to build request pipelines against an obligation that was never created, and to promise applicants an outcome the holding body has no duty to deliver.
Rules and trusted roles still need somewhere to operate. The sector data space is where both are put to work.
45.6 Common European data spaces and health as the flagship
A is a sector-wide arrangement in which organisations share data under common rules, standards and infrastructure, so that participants can reuse one another's data in a trusted setting. The European strategy for data set out common European data spaces across strategic sectors, and the support figure above shows five of them: health, energy, mobility, finance and agriculture.
The geometry of that figure carries the argument. Each sector card draws on one shared interoperability core rather than inventing its own: identity and trust, vocabularies, access rules and audit. A health space and an energy space differ in what they carry and in who is allowed to see it, but they are recognisably the same kind of arrangement because the hard parts are solved once. That is the practical pay-off of the standards work covered in Stage 1. Vocabularies and identifiers stop being a modelling nicety and become the thing that lets a sector agreement scale beyond its founding members.
Health is the sector that has moved from strategy to law. Regulation (EU) 2025/327 on the European Health Data Space was adopted on 11 February 2025, published in the Official Journal on 5 March 2025 and entered into force on 26 March 2025. It separates two purposes that health systems had long muddled together. Primary use is care: a clinician treating a patient, including across a border. Secondary use is research, innovation, policymaking and regulatory activity, carried out through permitted access rather than by handing over copies.
The timetable is long and deliberate. Key parts of the regulation, including the cross-border exchange of the first priority categories of health data such as patient summaries and electronic prescriptions, apply from March 2029, with further phases after that. A sector data space is not a platform that launches; it is a set of obligations that arrive in waves, and the participants who fare best are the ones who treat the interoperability core as work to start now rather than a deadline to meet later.
Secondary use is also where the privacy techniques from Stage 5 earn their keep. A permitted analysis carried out inside a controlled environment, whether described as a or as a secure processing environment, releases the agreed outputs rather than the underlying records. The privacy claim rests on what the environment enforces at the boundary, which is why output controls and audit are the questions worth asking about any such arrangement.
“Data should be discoverable and understandable by humans and machines.”
W3C Data on the Web Best Practices - Abstract
Written for open publishing on the web, but it states the condition a sector data space depends on. Discoverability and shared meaning are what turn a legal right to receive data into data a recipient can actually use, which is why the interoperability core sits underneath every sector in the figure.
The United Kingdom has not copied the horizontal access right. It is building the same effect one sector at a time.
45.7 The UK direction: smart data schemes
The UK route runs through the . The Data (Use and Access) Act 2025, which received Royal Assent in June 2025, gives ministers and the Treasury the power to make regulations requiring a business to pass data about a customer, at that customer's request, to the customer or to a third party the customer has authorised. The Act creates the power; each scheme is then made sector by sector through secondary legislation.
Open Banking is the working example that the rest are measured against. It shows what a scheme needs beyond a duty to share: an authorisation model so the customer can grant and revoke access, a register of authorised third parties, common interfaces so every participant implements the same thing, and a dispute route when a transfer fails. Portability that requires the customer to download a file and forward it is portability on paper. A scheme is what makes the authorised recipient receive the data on request.
The same Act carries changes to data protection law. It amends rather than replaces the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations, with the changes phased in from June 2025. Among them is a list of on which a controller may rely without carrying out the usual balancing test. Most of these changes offer an option rather than impose a new duty, which is a distinction worth holding on to when someone describes the Act as an overhaul.
Public sector data is being approached separately through the , a programme to build the infrastructure that lets public sector data be found and reused safely for public services, research and artificial intelligence. Whatever standards it settles on will shape what publishing to a national audience requires, which is the subject of the next module.
The contrast with the European approach is worth stating plainly, because it changes how an organisation plans. A horizontal access right lands on every connected product at once and is scheduled by date. A scheme-making power lands on nothing until a sector scheme is made, and is scheduled by political priority. A business operating in both jurisdictions therefore tracks two different clocks, and only one of them is published in advance.
A manufacturer placed a connected industrial pump on the EU market in March 2025. In November 2025 a customer asks for the operating data the pump generates and asks that it also be sent to an independent maintenance firm. The manufacturer says its next hardware revision, due in 2027, will add a data export interface, and that until then it can supply a spreadsheet on request. Which obligations apply today?
A government department holds a dataset that contains commercially confidential information supplied by regulated firms. A start-up cites the Data Governance Act and demands access for a new analytics product. What is the correct response?
A UK retail bank and a UK energy supplier are both asked why customers cannot yet move their account data to a rival adviser as easily in energy as in banking. What is the accurate explanation?
Core distinctions
- The EU Data Act, Regulation (EU) 2023/2854, gives users of connected products a right of access to the data their use generates and a right to nominate a third party recipient, excluding undertakings designated as gatekeepers under the Digital Markets Act.
- Four dates matter and each binds a different party: 11 January 2024 entry into force, 12 September 2025 applicability of the access and use duties, 12 September 2026 for the design obligation on products placed on the market after that date, and 12 January 2027 for the end of switching charges.
- Where a data holder must make data available, the terms have to be fair, reasonable and non-discriminatory and transparent, which constrains price, parity between recipients and the ability to leave the basis unexplained.
- The Data Governance Act, Regulation (EU) 2022/868, applicable since 24 September 2023, is an enabling instrument. It conditions re-use of protected public sector data, regulates neutral data intermediaries under structural separation, and recognises data altruism organisations on a public register.
- Common European data spaces put sector rules on one shared interoperability core of identity and trust, vocabularies, access rules and audit. Health is the flagship: Regulation (EU) 2025/327 entered into force on 26 March 2025 with key parts applying from March 2029.
- The UK route is a scheme-making power rather than a horizontal right. The Data (Use and Access) Act 2025 lets ministers create smart data schemes sector by sector, with Open Banking as the working example.
Standards and sources cited in this module
Regulation (EU) 2023/2854 (Data Act)
Chapter II access rights, Chapter III fair terms, Chapter VI switching, Article 50 application dates
Primary text for the connected product access right, the fair, reasonable and non-discriminatory sharing terms, and the four commencement dates used throughout this module.
Policy page, entry into force and application
Commission statement that the Data Act entered into force on 11 January 2024 and came into application on 12 September 2025.
Regulation (EU) 2022/868 (Data Governance Act)
Chapters II to VI
Primary text for re-use of protected public sector data, data intermediation services, data altruism and the European Data Innovation Board.
European Commission: Data Governance Act explained
Data intermediation services and data altruism
Commission explanation of intermediary neutrality, structural separation and the registration of data altruism organisations.
Regulation (EU) 2025/327 (European Health Data Space)
Primary use and secondary use
Primary text for the flagship sector data space, adopted 11 February 2025 and published in the Official Journal on 5 March 2025.
European Commission: European Health Data Space
Timeline of application
Commission page confirming entry into force on 26 March 2025 and the March 2029 application of key provisions including patient summaries and electronic prescriptions.
Data (Use and Access) Act 2025
Part 1, customer data and business data
Primary text for the UK smart data scheme power, under which sector schemes are made by secondary legislation.
ICO: Data Use and Access Act 2025
Summary of the changes
Regulator guidance on how the Act amends rather than replaces UK data protection law, and on the phased commencement of those changes.
ISO/IEC 38505-1:2017, Governance of data
Scope
Governing body duty framed around the effective, efficient and acceptable use of data, which sharing law converts from an internal test into an external one.
W3C Data on the Web Best Practices
Abstract and introduction
Standing requirement that data be discoverable and understandable by humans and machines, which is the condition a sector data space core has to meet.
Module 45 of 52 · Governance and strategy