Skip to main content
Category: Privacy Regulations

Data Governance Act

Also known as: DGA, EU Data Governance Act
Simply put

The Data Governance Act is a European Union regulation designed to make it easier and safer to share data across the EU, covering both personal and non-personal data. It sets up rules and structures intended to support data sharing for the benefit of the EU single market, including the reuse of certain data held by public sector bodies. It is a framework for facilitating data sharing rather than a set of penalties or a replacement for existing privacy law.

Formal definition

The Data Governance Act (DGA) is a cross-sectoral EU regulation that establishes a legal framework to facilitate data sharing across sectors, addressing both non-personal and personal data. Per the evidence, it aims to regulate the reuse of protected data held by the public sector, support data-sharing infrastructure, and promote neutral intermediation, in service of the EU single market. The DGA operates alongside the EU GDPR rather than superseding it; where the DGA involves personal data, GDPR obligations continue to apply, and practitioners should map the interplay between the two instruments case by case. This entry defines the instrument's purpose and scope only; it does not cover specific obligations for data intermediation services or data altruism organisations, cross-border transfer mechanics, retention rules, enforcement, or the distinct EU Data Act, none of which are detailed in the evidence provided.

Why it matters

The Data Governance Act matters because data sharing across the EU has historically been constrained by legal uncertainty, fragmented sectoral rules, and a lack of trusted infrastructure for making data available for reuse. The DGA responds by establishing a cross-sectoral framework intended to facilitate the sharing of both non-personal and personal data, including the reuse of certain protected data held by public sector bodies, in service of the EU single market. For organisations, this reframes data sharing from an ad hoc, bilateral activity into an activity supported by defined structures and neutral intermediation.

The practical significance for compliance and governance professionals lies in the interplay between the DGA and existing privacy law. The DGA operates alongside the EU GDPR rather than replacing it; where a data-sharing activity involves personal data, GDPR obligations continue to apply in full. This means that participating in DGA-enabled data sharing does not relieve a controller or processor of its existing accountability, lawful basis, or data subject rights obligations. Practitioners should treat the two instruments as complementary and map their interaction on a case-by-case basis rather than assuming that facilitation under the DGA implies any relaxation of privacy requirements.

It is also important to understand what the DGA is not. It is a framework for facilitating and governing data sharing, not a penalty regime or a substitute for privacy law, and it is distinct from the separate EU Data Act. Misreading the DGA as either a replacement for the GDPR or as an enforcement instrument can lead to gaps in governance, particularly around who bears which obligation when personal data flows through shared infrastructure or intermediaries.

Who it's relevant to

Data protection officers and privacy counsel
DPOs and privacy lawyers need to assess how the DGA interacts with the EU GDPR whenever a data-sharing activity involves personal data. Because the DGA facilitates sharing without displacing GDPR obligations, these roles are responsible for mapping the interplay case by case and confirming that lawful basis, accountability, and data subject rights are addressed independently of any facilitation the DGA provides.
Public sector bodies
The DGA specifically addresses the reuse of certain protected data held by public sector bodies. Governance and legal teams within these organisations are relevant stakeholders because the framework is intended to enable such reuse within defined structures, and this entry does not detail the specific conditions or obligations that apply.
Data governance and information management leads
Those responsible for data ownership, stewardship, cataloguing, and policy are relevant because the DGA establishes a cross-sectoral framework for the governance of data sharing. These roles help determine how shared and reused data is documented, controlled, and made available in a way consistent with the organisation's broader governance obligations.
Organisations participating in EU data-sharing arrangements
Any entity engaging in cross-sectoral data sharing within the EU single market should understand the DGA as the framework governing that activity, distinct from the separate EU Data Act. Such organisations should note that the specific obligations for data intermediation services and data altruism organisations are not covered here and require separate assessment.

Inside DGA

Scope and instrument
The Data Governance Act is an EU regulation intended to facilitate voluntary data sharing and reuse across the internal market. It is a distinct instrument from the EU GDPR and does not replace or amend it; where personal data is involved, GDPR obligations continue to apply in parallel. It is EU-specific and should not be treated as equivalent to UK, US, or other regimes.
Reuse of protected public sector data
It sets conditions for the reuse of certain categories of data held by public sector bodies that are subject to protections (for example, data covered by third-party rights or confidentiality). It generally establishes conditions for such reuse rather than creating a blanket open-data obligation, and it does not itself remove the underlying protections attached to that data.
Data intermediation services
It introduces a framework for entities that act as intermediaries to enable data sharing between data holders and data users. These intermediaries are subject to specific requirements intended to ensure neutrality and trust. This role is separate from the GDPR concepts of controller and processor, and characterisation under the DGA does not by itself determine controller or processor status under data protection law.
Data altruism
It provides a framework for making data available voluntarily for purposes in the general interest, including through recognised data altruism organisations. Where personal data is shared on this basis, a valid GDPR lawful basis is still required; the DGA framework does not, on its own, substitute for or establish that lawful basis.
Governance and oversight bodies
It contemplates competent bodies and coordination structures to support consistent application across Member States. This is a governance-facing framework concerned with how data sharing is organised and supervised, and it is distinct from information security control requirements, though secure handling of shared data remains relevant in practice.

Common questions

Answers to the questions practitioners most commonly ask about DGA.

Does the Data Governance Act replace or override the EU GDPR?
No. The Data Governance Act is a distinct EU instrument that operates alongside the EU GDPR rather than replacing it. Where the two intersect, the Data Governance Act generally defers to data protection law: it does not create new lawful bases for processing personal data, does not alter data subject rights, and does not diminish existing GDPR obligations. In case of conflict involving personal data, GDPR provisions generally continue to apply. Treating the Data Governance Act as a substitute for GDPR compliance is a common mistake; the two must be assessed together. This answer does not cover the detailed interaction mechanics or every scenario of overlap.
Is the Data Governance Act only about opening up personal data for reuse?
No. The Data Governance Act addresses the reuse and sharing of data broadly, which includes both personal and non-personal data, and it is not limited to making personal data available. Conflating its scope with personal-data-only regimes such as the GDPR misstates its purpose. Where personal data is involved, data protection law continues to govern that data, and the Data Governance Act does not by itself make personal data reusable without regard to those rules. This entry does not enumerate the full range of data categories or reuse conditions in scope.
How does the Data Governance Act relate to our existing GDPR compliance program?
In most cases, an organisation subject to both frameworks should treat Data Governance Act obligations as complementary to, not a substitute for, its GDPR program. Existing controls around lawful basis, data subject rights, records of processing, and accountability generally remain necessary where personal data is processed. Organisations typically need to assess how data-sharing or reuse activities under the Data Governance Act interact with their data protection obligations rather than assuming one framework satisfies the other. The specific integration steps depend on the organisation's role, jurisdiction, and the nature of the data involved, which are out of scope here.
Who within an organisation should be accountable for Data Governance Act compliance?
Accountability generally requires clearly assigned roles and demonstrable evidence rather than stated intent alone. In practice, responsibilities may span data governance functions (covering ownership, stewardship, and data cataloguing) and data protection functions (where personal data is in scope). The data protection officer and chief privacy officer are distinct roles and should not be treated as interchangeable when allocating responsibility. This entry does not prescribe a specific organisational structure, which will vary by entity size, sector, and jurisdiction.
What documentation is typically expected to demonstrate compliance?
Under accountability-based frameworks generally, organisations are expected to maintain demonstrable evidence rather than rely on asserted compliance. This typically includes records of the relevant data-sharing or reuse activities and, where personal data is processed, the documentation already required under data protection law. Note that maintaining such records is a governance and accountability obligation and should not be equated with simply deploying a data inventory tool. This entry does not specify the precise documentary requirements, which depend on the applicable provisions and the organisation's activities.
Does the Data Governance Act change how we handle cross-border data transfers?
Cross-border transfer mechanics for personal data generally continue to be governed by data protection law rather than being replaced by the Data Governance Act. Organisations should not assume that reuse or sharing permitted under the Data Governance Act removes the need to satisfy applicable transfer requirements for personal data. The detailed transfer rules, safeguards, and enforcement consequences are out of scope for this entry, and treatment may differ across jurisdictions and regimes.

Common misconceptions

The Data Governance Act replaces or overrides the GDPR for shared data.
The DGA is a separate EU instrument that operates alongside the GDPR. Where personal data is involved, GDPR obligations, including the need for a lawful basis and controller and processor duties, continue to apply and are not displaced by the DGA.
Sharing data through a data intermediation service or as data altruism removes it from data protection rules.
Using a DGA sharing mechanism does not make personal data non-personal, and it does not by itself establish a lawful basis under the GDPR. Personal data shared through these mechanisms remains subject to applicable data protection obligations, which must be satisfied independently.
The DGA gives universal or global rules for data reuse and sharing.
The DGA is an EU-specific instrument. Its provisions should not be assumed to apply in the UK, the US, or other jurisdictions, where data sharing and reuse are governed by different frameworks that must be assessed separately.

Best practices

Assess DGA obligations and GDPR obligations separately, and confirm a valid lawful basis under the GDPR for any personal data being shared or reused rather than assuming a DGA mechanism supplies one.
Where acting as or engaging a data intermediation service, document how DGA-specific requirements are met and separately determine controller and processor roles under data protection law, since the two characterisations do not automatically align.
For reuse of protected public sector data, verify that the underlying third-party rights and confidentiality protections are respected, and retain evidence of the conditions applied rather than assuming reuse is unrestricted.
Treat DGA participation as a governance activity that requires demonstrable evidence, keeping records of the arrangements, safeguards, and decisions rather than relying on stated intent.
Do not extend DGA-based conclusions to non-EU jurisdictions; for cross-border or multi-regime data sharing, obtain a separate legal assessment of applicable frameworks.
Ensure appropriate security controls apply to shared data as a distinct workstream from DGA governance requirements, since the DGA framework does not itself specify a complete set of technical security measures.