Background
Over the last 12 months, I have been leading workshops with OEMs, IoT product owners and business stakeholders, to discuss the proposed upcoming EU Data Act and how it will impact their organisation and business models.
Over this time, I have become fascinated with the EU Data Act and, whilst it is not without its hurdles, I consider it to be a truly revolutionary move by the EU. I believe it will change how we view data creation, ownership, use and distribution. In fact, considering the colossal implications it is likely to have, it is surprising how infrequently I see it discussed.
As we move into an era of big data, AI and machine learning, democratisation of data is pivotal - all of us generate data through our labour and our everyday actions, but few of us reap the rewards and profits of that data creation.
I view the EU Data Act as an instrument to ensure that the benefits of this data are distributed evenly across society. Whilst it no doubt brings challenges, it creates infinite possibilities for all players - from manufacturers to individuals, businesses and service providers and of course public bodies.
It will require careful consideration from organisation leaders, who will have to, once again, consider data at every stage of their strategy and operations - just like they did for GDPR, but this time for all data, not just personal data. Data protection professionals will certainly be key stakeholders and advisors on this journey and I am excited.
This is the first in a series of articles about the EU Data Act. This initial piece is a very high level overview of the EU Data Act – what it is and where we are at. It will provide the foundation to my future articles, which will be deep dive ‘think pieces’ and analysis about the opportunities, threats and impacts of the proposed legislation. I will consider the Privacy and Data Protection, the Automotive industry, OEMs, Insurers, IoT manufacturers, businesses and consumers.
I should caveat that everything that you read is my interpretation and opinion at the time of writing. The EU Data Act hasn’t yet been finalised and is likely to evolve over time, as will the broader understanding of it. Please feel free to engage and even challenge in the comments for some healthy debate.
What is the EU Data Act?
The EU Data Act is a legislative proposal which aims to lay down consistent rules, specifying who is entitled to access data generated by the use of products or related services. Its goal is to ensure a greater balance in the distribution of the value from data.
Why do we need the EU Data Act?
Data-driven technologies have been transforming and driving all sectors of the economy. Products and services connected to the Internet of Things (IoT) have led to more data being generated than ever before.
This data can be extremely valuable for consumers, businesses, and society, but there are massive barriers to gaining access to and sharing this data, including a lack of incentives for companies holding the data to share it, uncertainty about rights and obligations, high costs, fragmented data, lack of interoperability and data protection issues. These barriers prevent data being shared and used in a way that benefits society and the wider economy, so monopolies reign.
The EU Commission states that 80% of industrial data is never used and believes the introduction of the EU Data Act will unlock the value of the data economy and act as an engine for innovation, competition and economic growth.
What are the specific objectives of the EU Data Act?
Some key points of the EU Data Act are still under negotiation, but the following broad goals are likely to apply:
What is the current status of the EU Data Act?
The EU Data Act proposal has been reviewed by the EU Council and EU Parliament and they have each proposed amendments. EU institutions are now in trilogue discussions – a third scheduled for the 27th June 2023.
The EU Data Act is likely to pass in 2023, some are saying sooner, rather than later.
Does the EU Data Act only apply to EU companies?
No it will be broader - there are still some minor points that will be clarified in EU negotiations, but it is likely to apply to the following:
Are there any exemptions for smaller organisations?
The EU Data Act provides exemptions for micro and small enterprises as follows:
The above applies, as long as these enterprises are not linked or partnered with other enterprises that do not qualify as micro or small.
Depending on how the negotiations proceed, we may see other exemptions for medium enterprises and possibly
tighter exemption qualifying criteria, whereby micro and small enterprises will still be in scope if they are subcontracted to manufacture a product or provide a service.
When will the Data Act be effective?
There is still some debate on the timeline for enforcement – as it stands it looks to be between 18 and 24 months after it enters into force.
Will the EU Data Act apply retroactively?
Maybe – if negotiations align with the EU Parliament’s view, then obligations under Article 4.1 to make the data generated by User’s use of a product or related service, will apply to products and services placed on the market 5 years before the EU Data Act came into force, as long as the provider of a related service is able to remotely deploy mechanisms to ensure the fulfilment of the requirements.
Will organisations have to comply with the EU Data Act?
Yes, there will be fines and penalties for non compliance.
Conclusion
The EU Data Act has far reaching scope and implications and creates endless opportunities and threats. Business leaders should be thinking about the EU Data Act now and considering how it will impact their strategy, roadmap and objectives.
Has your organisation considered the EU Data Act? What opportunities and threats do you see and how are you preparing?
Please follow our LinkedIn Page for future blogs on this topic and if your organisation requires support navigating the proposed EU Data Act, please visit www.dataactconsulting.com
hello@article5consulting.com
article5consulting.com