Data Governance Act: how is it different from the Data Act?
EU Regulation 2022/868 on data intermediaries and public data reuse, applicable since 24 September 2023.
The Data Governance Act is Regulation (EU) 2022/868 of the European Parliament and of the Council on European data governance, which entered into force on 23 June 2022 and became applicable on 24 September 2023, after a 15 month transitional period. It does not create rights over specific datasets, but governs how data can be shared reliably: it regulates the reuse of certain public sector data that cannot be released as open data because it is subject to third party rights, such as health data useful for medical research but protected by intellectual property, privacy or trade secrets; it introduces a notification regime for data intermediation services, which must act as neutral and trustworthy organizers of sharing between those who generate data and those who want to use it; and it creates the framework for data altruism, meaning mechanisms through which citizens and businesses voluntarily make data available for purposes of general interest such as scientific research or public health, including through recognized organizations.
The difference from the Data Act, settled for good
The DGA is constantly confused with the Data Act (Regulation (EU) 2023/2854), applicable since 12 September 2025: they are two distinct texts, with different subjects and objects. The Data Act concerns those who generate or use data and their rights to access, portability and switching, covering topics such as changing cloud provider, the phase out of egress fees and access to IoT data, which this entry does not cover because it is Data Act territory. The Data Governance Act, instead, concerns those who organize data sharing: intermediaries who must notify competent national authorities, and the reuse of protected public data. The applicability date is another way to keep them apart: the DGA applies from 24 September 2023, the Data Act from 12 September 2025, almost two years later. If you deal with data generated by sensors or connected products, or with cloud contracts, the text that concerns you is the Data Act; if you are assessing whether to become, or rely on, a data intermediary, or whether to reuse sensitive public datasets, the text is the DGA.
A concrete enterprise case
A university hospital that wants to make anonymized clinical datasets available to oncology research startups cannot simply publish them as open data: it must check whether a recognized public sector body for data access already exists, or assess whether to register as a data intermediation service under the DGA regime, with the neutrality guarantees this entails. Alternatively, a research consortium can structure the collection as data altruism, involving a recognized organization that gathers individual consent for purposes of general interest. In both cases, the general governance of data sharing, meaning how a company organizes policies, roles and processes for its own datasets, remains a matter of data governance: the DGA adds a regulatory layer on top of that discipline, it does not replace it.
Why it matters for decision makers
For anyone evaluating data sharing partnerships, the DGA sets out the conditions under which an intermediary can call itself trustworthy and neutral, a concrete due diligence criterion when choosing a data intermediation provider. For anyone working with public health or research data, it clarifies the legal perimeter of reuse, avoiding the mistake of treating it as a plain open data matter. And for anyone mixing up the two regulations in contracts or internal policies, telling them apart avoids clauses drafted for the wrong law.
This entry is informational and does not constitute legal advice: for decisions on regulated data, involve your DPO or legal counsel.
Frequently asked questions
Related terms
- Data Act · The EU data regulation, applicable since 12 September 2025: frictionless cloud switching, egress fees being phased out, accessible IoT data.
- Data governance · The rules, roles and processes that make company data reliable, secure and usable: who can do what, on which data, at what quality.
- Digital sovereignty · An organization's effective control over its data, infrastructure and technology: who can access it, who can compel disclosure, who it depends on.
- Data residency · The physical location where data is stored and processed. It says where data resides, not who can be compelled to hand it over: it is not sovereignty.
A term that hits close to home? Let's talk.
CONTACT ME