Data Governance Act
The Data Governance Act is a European Union regulation designed to make it easier and safer to share data across the EU, covering both personal and non-personal data. It sets up rules and structures intended to support data sharing for the benefit of the EU single market, including the reuse of certain data held by public sector bodies. It is a framework for facilitating data sharing rather than a set of penalties or a replacement for existing privacy law.
The Data Governance Act (DGA) is a cross-sectoral EU regulation that establishes a legal framework to facilitate data sharing across sectors, addressing both non-personal and personal data. Per the evidence, it aims to regulate the reuse of protected data held by the public sector, support data-sharing infrastructure, and promote neutral intermediation, in service of the EU single market. The DGA operates alongside the EU GDPR rather than superseding it; where the DGA involves personal data, GDPR obligations continue to apply, and practitioners should map the interplay between the two instruments case by case. This entry defines the instrument's purpose and scope only; it does not cover specific obligations for data intermediation services or data altruism organisations, cross-border transfer mechanics, retention rules, enforcement, or the distinct EU Data Act, none of which are detailed in the evidence provided.
Why it matters
The Data Governance Act matters because data sharing across the EU has historically been constrained by legal uncertainty, fragmented sectoral rules, and a lack of trusted infrastructure for making data available for reuse. The DGA responds by establishing a cross-sectoral framework intended to facilitate the sharing of both non-personal and personal data, including the reuse of certain protected data held by public sector bodies, in service of the EU single market. For organisations, this reframes data sharing from an ad hoc, bilateral activity into an activity supported by defined structures and neutral intermediation.
The practical significance for compliance and governance professionals lies in the interplay between the DGA and existing privacy law. The DGA operates alongside the EU GDPR rather than replacing it; where a data-sharing activity involves personal data, GDPR obligations continue to apply in full. This means that participating in DGA-enabled data sharing does not relieve a controller or processor of its existing accountability, lawful basis, or data subject rights obligations. Practitioners should treat the two instruments as complementary and map their interaction on a case-by-case basis rather than assuming that facilitation under the DGA implies any relaxation of privacy requirements.
It is also important to understand what the DGA is not. It is a framework for facilitating and governing data sharing, not a penalty regime or a substitute for privacy law, and it is distinct from the separate EU Data Act. Misreading the DGA as either a replacement for the GDPR or as an enforcement instrument can lead to gaps in governance, particularly around who bears which obligation when personal data flows through shared infrastructure or intermediaries.
Who it's relevant to
Inside DGA
Common questions
Answers to the questions practitioners most commonly ask about DGA.