Your latest edition of Regulating Data: EU Data Act & More has arrived.
Stay in the know with the latest updates and regulatory implementation efforts over the last month.
In this edition, we cover:
- Germany’s new dedicated notification process for those seeking to suspend, restrict or refuse disclosure under the Data Act
- The defined roles of Data Protection Authorities in Germany
- The current state of Data Act implementation across EU member states
1. Germany's new notification procedure for the Data Act's access exceptions
The Data Act grants users and, in certain circumstances, third parties extensive rights to access data generated by connected products and related services. As a general rule, data holders are required to make the relevant data available. The refusal of a data-access request is therefore intended to remain the exception rather than the rule.
1.1 The German process
Germany has introduced a dedicated notification process for data holders seeking to suspend, restrict or refuse disclosure under the Data Act. The Bundesnetzagentur (BNetzA) has published notification forms for cases in which a data holder relies on Articles 4(2), 4(7), 4(8), 5(10) or 5(11) Data Act.
According to the BNetzA, data holders must notify the authority where they:
- Refuse to share data under Article 4(2) Data Act;
- Suspend the disclosure of trade secrets under Articles 4(7) or 5(10) Data Act;
- Refuse the disclosure of trade secrets under Articles 4(7) or 5(10) Data Act; or
- Reject a data access request under Article 4(8) or 5(11) Data Act.
What information must be provided?
The notification form requires data holders to provide, among other things:
- the connected product concerned;
- the data categories affected by the restriction;
- whether the affected party is a user or a third party;
- a justification for the decision; and
- confirmation that the decision and supporting reasons have been communicated to the affected party in writing without undue delay.
The BNetzA also highlights that, where a request is rejected on the basis of Articles 4(8) or 5(11) Data Act, the data holder must provide objective evidence showing that disclosure would be highly likely to result in serious economic damage. According to the authority, this assessment should be based on objective facts, including the enforceability of trade-secret protection in third countries, the nature and confidentiality of the requested data, and the uniqueness and novelty of the connected product concerned.
The Notification Forms: for Article 4 (2), for the other handbreaks.
1.2 Background: Exceptions to the Data Act’s data-access obligations
The Regulation contains a limited number of narrowly defined mechanisms allowing data access to be restricted, suspended or refused. These safeguards are referred to as the Data Act's "handbrakes" on data access.
1.2.1 Security handbrake -- (Art. 4(2) Data Act)
When can it be invoked?
- The disclosure of the requested data would undermine the security requirements of the connected product; and
- that disclosure could result in a serious adverse effect on the health, safety or security of natural persons.
Key conditions:
- The relevant security requirement must be laid down in Union or national law; and
- the restriction must be reflected in the contractual arrangements with the user.
What may the data holder do?
- Restrict or prohibit access to the affected data, provided the relevant conditions under Article 4(2) are met.
- Only the affected data may be restricted; the remainder of the data-access request should continue to be fulfilled.
1.2.2 Trade-secret handbrake – Stage 1 (Art. 4(7) and Art. 5(10) Data Act)
When can it be invoked?
Where the recipient of the data does not comply with the measures necessary to preserve the confidentiality of trade secrets. That is the case if:
- The parties cannot agree on appropriate protective measures to preserve the confidentiality of trade secrets;
- agreed protective measures are not implemented; or
- the recipient undermines the confidentiality of the protected information.
What may the data holder do?
- Suspend or withhold disclosure of the affected trade-secret data.
- Only the affected trade-secret data may be withheld; the remainder of the data-access request must continue to be fulfilled.
1.2.3 Trade-secret handbrake – Stage 2 (Art. 4(8) and Art. 5(11) Data Act)
When can it be invoked?
A data holder may reject a request where, despite agreed and implemented protective measures, disclosure would be highly likely to result in serious economic damage. According to Recital 31 of the Data Act, serious economic damage implies serious and irreparable economic loss.
Threshold
- Objective evidence is required;
- the assessment must be based on the specific circumstances of the individual case; and
- the decision must be properly justified.
Important limitation
- A refusal cannot be justified on a blanket basis for entire categories of data.
- The assessment must be carried out on a case-by-case basis.
1.3 Conclusion
The new notification process established in Germany provides one of the first concrete examples of how Member State authorities intend to supervise the Data Act's safeguards against disclosure of sensitive information. While other Member States have started to publish guidance on the application of the Data Act, Germany appears to be among the first to operationalise these safeguards through a dedicated and publicly available notification process.
It also serves as a reminder that the Data Act's "brakes" on data access are intended to operate as narrowly defined exceptions. Data holders seeking to rely on them face both procedural obligations and a relatively high evidential threshold before data access may be restricted, suspended or refused.
2. Data Act enforcement: Data Protection Authorities are defining their role
The German Data Act Implementation Act (DADG) designates the Bundesnetzagentur (BNetzA) as the central competent authority for the enforcement of the Data Act in Germany. Since the DADG's entry into force on 30 May 2026, however, several data protection authorities have publicly outlined their own role under the German implementation framework.
The Authorities involved
- Federal Commissioner for Data Protection and Freedom of Information (BfDI): since 30 May 2026, competent for supervising the application of the Data Act where personal data is affected, both in relation to businesses and to public bodies of the Federal government (Bund).
- State data protection authorities (Landesdatenschutzbehörden): competent for public-sector bodies at the level of the individual Länder. The Independent State Centre for Data Protection Schleswig-Holstein (ULD) has outlined its competence for public-sector matters in Schleswig-Holstein (see here); the same structure applies analogously in each of the other 15 Länder, with their respective data protection authority.
A noted point of division
According to reporting on the legislative process, the Bundesrat and several Land data protection authorities raised concerns during the DADG's legislative process about the resulting division of competence: for data protection matters outside the Data Act context, the relevant Land data protection authority remains responsible for a given business; for data protection matters arising specifically under the Data Act, competence instead lies with the BfDI. This means businesses may deal with two different data protection authorities depending on whether a given matter falls under the Data Act or under general data protection law.
3. Data Act: State of national implementation across the EU
The Data Act has been in force since 11 January 2024. Nearly a year after it became applicable across the EU, national implementing legislation is still progressing at very different speeds between Member States. While some states have fully implemented the Data Act, others have only published a draft or proposal, and some have not yet published anything at all. The list below sets out a quick overview where each country currently stands.
Status
Implemented
Country
- Denmark,
- Finland,
- Germany,
- Lithuania,
- Malta,
- Netherlands
Partially implemented
Country
- France
Pending
Country
- Austria,
- Belgium,
- Bulgaria,
- Croatia,
- Cyprus,
- Czech Republic,
- Estonia, Greece,
- Hungary,
- Ireland,
- Italy,
- Latvia,
- Luxembourg,
- Poland,
- Portugal,
- Romania,
- Slovakia,
- Slovenia,
- Spain,
- Sweden
Regardless of the status shown above, the Data Act applies directly in every EU Member State. The absence of national implementing legislation does not suspend its substantive obligations; it simply means the national competent authority, data coordinator and penalty framework have not yet been finalised in that Member State.






.jpg?crop=300,495&format=webply&auto=webp)



_11zon.jpg?crop=300,495&format=webply&auto=webp)



_11zon.jpg?crop=300,495&format=webply&auto=webp)


.jpg?crop=300,495&format=webply&auto=webp)
