Data Governance Act
Regulation (EU) 2022/868Regulation on European data governance
In force since September 24, 2023
Who it applies to
- Public sector bodies making protected data available for re-use
- Data intermediation service providers, which must notify and meet neutrality conditions
- Recognised data altruism organisations
Consumer rights
- Access / know — not granted
- Correction — not granted
- Deletion / erasure — not granted
- Portability — grantedReceive your data in a portable, machine-readable form, or have it transmitted onward.
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — not granted
Obligations
- Consent model
- Opt-in
- Universal opt-out signal
- Not required
- Risk assessments
- Not required
- Data protection officer
- Not required
- Records of processing
- Not required
- Processor contract
- Required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Required
Breach notification
- To individuals
- Governed by the GDPR
- To the regulator
- Not required by this law
- What triggers it
- See the GDPR
Penalties
- Headline
- Set by member states
- Private right of action
- No — enforcement is by the regulator only
- Notes
- Creates a notification regime for data intermediaries — the closest thing the EU has to the US state data broker registries, though built around neutrality duties rather than deletion rights.
Exemptions
Entities
- Public undertakings, public service broadcasters and cultural institutions
Sources
- PrimaryRegulationRegulation (EU) 2022/868 — Data Governance Act text