Data Governance Act

Regulation (EU) 2022/868

Regulation on European data governance

In force since September 24, 2023

Who it applies to

  • Public sector bodies making protected data available for re-use
  • Data intermediation service providers, which must notify and meet neutrality conditions
  • Recognised data altruism organisations

Consumer rights

  • Access / know — not granted
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — grantedReceive your data in a portable, machine-readable form, or have it transmitted onward.
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — not granted

Obligations

Consent model
Opt-in
Universal opt-out signal
Not required
Risk assessments
Not required
Data protection officer
Not required
Records of processing
Not required
Processor contract
Required
Right to cure
None — enforcement may follow immediately
Data broker registration
Required

Breach notification

To individuals
Governed by the GDPR
To the regulator
Not required by this law
What triggers it
See the GDPR

Penalties

Headline
Set by member states
Private right of action
No — enforcement is by the regulator only
Notes
Creates a notification regime for data intermediaries — the closest thing the EU has to the US state data broker registries, though built around neutrality duties rather than deletion rights.

Exemptions

Entities

  • Public undertakings, public service broadcasters and cultural institutions

Sources