Six virtues of the Data Act, or, How I Learned to Stop Worrying and Love the Data Act.

Six virtues of the Data Act, or, How I Learned to Stop Worrying and Love the Data Act.


Yet another proposal for an EU digital ‘act’ has just landed and, having worked on it for a year, I cannot be expected to be impartial. So before the world’s brains fully digest its contents, here are seven reasons to believe the Data Act is a Good Thing.

1.??????It empowers consumers – The Data Act builds on right to data portability under Art 20 GDPR, which, for all its innovativeness, is full of with caveats. Note that the Data Act is about economic rights rather than fundamental rights. You have to be an owner of a connected product to have, under the Data Act, the undisputed right to access data your product generated.?But it gives you the right to access and have transferred data from your product, whether it’s personal or not, whatever the legal basis, and it doesn’t depend on the access being ‘technically feasible’ (recital 68 , GDPR). And if, for whatever reason, you can’t port your IoT data under the Data Act, your GDPR Article 20 rights cannot be affected. Safeguards for consumers in the Data Act, like the provisions against profiling and use of dark patterns, are tough and go beyond the basic requirements of the GDPR.

2.??????It empowers SMEs– small and micro companies are exempt from the new obligations, but they do get the access to data from connected products to innovate and compete which they have long campaigned for.?Equally, while the Data Act opens up access to IoT data, it keeps the door shut to big data aggregators – the ‘gatekeepers’ of the Digital Markets Act. Given their ‘unrivalled ability to acquire data’ (recital 36) - they have no need of further encouragement.

3.??????It supports the European Green Deal – connected products have a huge and growing environmental footprint. Making the data available to competing repair and maintenance service providers is essential to reduce waste and for the circularity of products and materials. In this way, the Data Act is of a piece with the forthcoming Digital Product Passport / Sustainable Product Initiative which is close to being unveiled. Also, public bodies combating and trying to adapt to environmental degradation and climate change have not been able to get data they need to prevent and respond to emergencies. The Data Act provides a mechanism for this. It’s a rare act that directly supports both legs of the much vaunted twin green-digital transition.

4.??????It puts data to work for all of society, not just the biggest companies.?Democratic public bodies accessing data from large companies. Public sector access to private data is going to be hotly debated and for good reason. While there are means for data to be moved lawfully from government to business, there isn’t when most data is controlled by a handful of private tech companies. Hence, the call for a lawful and proportionate means in a democracy for data to be accessible in the public interest. The ‘B2G’ section of the Data Act is therefore carefully tied to public emergencies and exceptional needs, with strict safeguards and data minimisation provisions. It also provides for these bodies to give access to genuine (ie not-for-profit or public interest) scientific research.?And again, small and medium are exempt from these data sharing obligations.

5.??????It lets you switch between cloud services. Access to data processing infrastructure is essential for all companies to digitise. But businesses typically get locked into cloud services, and only discover hidden charges when they try to get out.?The Data Act envisages – among other things - the phasing out of charges, like with roaming in telecoms in the past.?

6.??????Minimum red-tape – coherent enforcement. Last, Data Act doesn’t impose yet another regulatory body, but it requires the relevant ones – including data protection authorities - to cooperate.?If you have a complaint, it’s not on you as a consumer or SME to know which authority you should go to – the agencies have to work together to deal with your problem. This directly responds to the call from, notably, the European Data Protection Supervisor (e.g. here, and here) for ‘institutionalised and structured’ cooperation in the digital economy.

So there you have it: fight me.

Stewart Dresner

Founder & Chief Executive, Privacy Laws & Business

3 年

Christian, You have written a concise and clear explanation of the Data Act which provides a valuable public service for all of us. Thank-you, Stewart

God almighty, I misread this and thought you were talking about the AI Act. I was worried that you'd had a stroke or had been kidnapped.

Jerome Deroulez

Avocat - Paris & Bruxelles - DPO externalisé - Fondateur et associé AUMANS AVOCATS - ancien magistrat

3 年

Thanks Christian D'Cunha ! Always interesting to get the point of view of an insider…

回复
Dr. Alexis P.

| #DrPrivacy | FSU Law Grad | Data Privacy Advocate | Global Cybersecurity, Compliance & Risk Management Compliance Leader | Mentor | Educator | Research Fellow | Privacy Expert (GDPR, CCPA, LGPD), HIPAA, CMMC |

3 年

Christian D'Cunha .. great piece, especially like the portability and exclusion of the "gatekeepers". from the data.

Kai Meinke

Co-Founder & Business Lead deltaDAO AG, Lead Gaia-X Open-Source Software Community. Operating Pontus-X, the largest publicly available digital service ecosystem powered by Gaia-X.

3 年

Thanks for sharing, a pleasure to read and to prepare the tech stack for this.

要查看或添加评论,请登录

Christian D'Cunha的更多文章

  • Whose privacy?

    Whose privacy?

    Jaap-Henk Hoepman’s Privacy Is Hard and Seven Other Myths: Achieving Privacy through Careful Design is a compact and…

    1 条评论
  • Sempre ricordato

    Sempre ricordato

    On GDPR Day, 25 May 2018, he was invited to attend a meeting of the directors-general of the European Commission…

  • The age of (trying to regulate) surveillance capitalism

    The age of (trying to regulate) surveillance capitalism

    For a while now the most interesting discussions about tech and privacy have been happening in the United States. In…

    11 条评论
  • The GDPR was the most lobbied law in EU history. DSA: Hold my beer

    The GDPR was the most lobbied law in EU history. DSA: Hold my beer

    Autumn, 2010 We are used to rain on All Saints’ Day. Half the leaves litter the floor and the other half cling to their…

    5 条评论
  • Privacy in a time of corona

    Privacy in a time of corona

    ‘History is bunk’ – so said Henry Ford, allegedly. He was wrong.

    6 条评论
  • Boys who make code which likes boys to be code...

    Boys who make code which likes boys to be code...

    According to a report from the China Academy of Information and Communications Technology and Data Research Center…

  • Un omaggio

    Un omaggio

    I don’t have many photos of me and Giovanni. Just as well, because his svelte poise only threw into ever-starker relief…

    29 条评论
  • Dreaming spires

    Dreaming spires

    Gerrorrf moi laaand! You might hear such an indignant injunction were you to trespass inadvertently upon a field in…

    2 条评论
  • Competition, privacy and red herrings

    Competition, privacy and red herrings

    Not so long ago the interplay between #antitrust and #privacy was dismissed as theoretical hokum, peddled by the…

    3 条评论

社区洞察

其他会员也浏览了