Regulating data: EU Data Act & more – September 2026 edition

The EU’s digital regulatory landscape is evolving at unprecedented speed, creating both new compliance challenges and strategic opportunities in Europe

05 October 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

The EU’s data and digital regulatory landscape continues to develop on several fronts, with new legislation, national enforcement frameworks and regulatory initiatives moving forward in parallel.

In this edition, we cover:

  • the Irish Presidency’s latest compromise text on the Digital Omnibus and the proposed changes to the Data Act;
  • the small number of Member States that have now designated operational Data Act competent authorities;
  • the new “access by design” requirement that started to apply on 12 September 2026; and
  • the Commission’s new implementing rules for MyHealth@EU under the European Health Data Space.

1. Data Act and Digital Omnibus: Irish Presidency Circulates New Compromise Text

The Irish Presidency has circulated a new compromise text on the Digital Omnibus (document ST 12535/26 of 3 September 2026). The text was prepared for discussion in the Council’s Antici Group (Simplification) on 11 September 2026. The Digital Omnibus would, among other things, amend the Data Act. The document is classified as restricted (LIMITE), but a copy has been published by noyb. It is a Presidency compromise text for discussion, not an agreed Council position.

In brief

  • The main Data Act changes proposed by the Commission in November 2025 remain in the Presidency text: broader trade-secret refusal grounds, a narrower Chapter V focused on public emergencies, deletion of Article 36 and lighter cloud-switching rules for certain legacy contracts.
  • On trade secrets, the September text would also remove the existing “exceptional circumstances” qualifier from Articles 4(8) and 5(11) and provide for Commission guidance on the refusal mechanism.
  • The main new detail in the public-emergency provisions concerns requests aimed at supporting recovery from a public emergency.
  • None of these amendments is final. Until the Digital Omnibus is adopted, the Data Act continues to apply as it stands.

Trade secrets and third-country risks

The Data Act already allows a data holder to refuse an access request where disclosure of trade secrets would, despite the application of all necessary measures, be highly likely to cause serious economic damage. As discussed in our June edition, this mechanism is set out in Articles 4(8) and 5(11).

The September compromise text would broaden this framework in two respects. It would remove the existing reference to “exceptional circumstances” and add a further ground where disclosure would create a high risk that trade secrets are unlawfully acquired, used or disclosed by entities in third countries offering weaker or non-equivalent protection compared with Union law, or by EU-based entities under their direct or indirect control.

The new ground would be voluntary and would have to be assessed on a case-by-case basis. A data holder relying on it would have to provide a written justification without undue delay and notify the competent authority. The user or third party could challenge the refusal before the competent authority, a court or a dispute settlement body.

The amendments would also require the Commission, in consultation with the European Data Innovation Board (EDIB), to issue guidelines on the application of the new provisions.

Data requests by public bodies: public emergencies only

Chapter V of the Data Act currently allows public sector bodies to request data in cases of “exceptional need”. The compromise text would narrow this framework to public emergencies.

Recital 15 defines a public emergency as a well-defined, urgent situation that is unforeseeable and limited in time. It also distinguishes between responding to an ongoing emergency and supporting recovery after the emergency has ended.

The recitals state that “mitigating” should no longer be treated as a separate ground because it is covered by “responding to” a public emergency. The operative text, however, continues to refer to “mitigating” in Article 15a.

For recovery requests, the requesting body would no longer have to exhaust all alternative means of obtaining the data, such as purchasing it on the market. It would nevertheless have to be unable to obtain the data otherwise in a timely and effective manner and under equivalent conditions. Recovery requests could not be made to microenterprises or small enterprises. Micro and small enterprises required to provide data in response to a public emergency would remain entitled to compensation.

The references to situations being “unforeseeable and limited in time” and the revised approach to recovery requests were not included in the Presidency’s May 2026 text.

Article 36: smart contracts

The deletion of Article 36 is not new. The Commission’s November 2025 proposal already provided for its deletion, and the Presidency text maintains it.

Article 36 currently contains requirements for smart contracts used to execute data sharing agreements, including safeguards concerning robustness, manipulation, termination, archiving and access control, as well as a conformity assessment and EU declaration of conformity.

The Commission’s rationale for deleting the provision includes the lack of harmonised standards, uncertainty around key concepts and potentially disproportionate compliance burdens. If the deletion is adopted, these specific requirements would no longer apply.

Until then, Article 36 remains applicable.

Cloud switching exemptions for legacy contracts remain

The compromise text maintains the lighter rules for certain legacy cloud contracts proposed by the Commission in November 2025. (For more on the proposed cloud-switching rules and legacy contracts, see our June edition.)

The compromise text creates a new carve-out for certain “custom-made” data processing services. This is separate from the existing Article 31(1) regime for “custom-built” services. The new carve-out would cover services other than those referred to in Article 30(1), where the majority of the service’s features and functionalities has been adapted by the provider to the customer’s specific needs and the contract was concluded on or before 12 September 2025.

For these contracts, Chapter VI, with the exception of Article 29, and Article 34 would not apply. Providers would not have to renegotiate or amend the contracts before expiry.

A separate carve-out would apply to data processing services other than those referred to in Article 30(1) where the provider is an SME or small mid-cap and the contract was concluded on or before 12 September 2025.

Providers could include proportionate early termination penalties in fixed-term contracts, provided that they do not constitute an obstacle to switching.

Article 29, including the gradual reduction and ultimate removal of switching and egress charges, would remain applicable.

Status

The 3 September text remains a Presidency compromise text and does not constitute an agreed Council position. The Digital Omnibus remains under negotiation, and the amendments discussed above have not yet become law.

2. Data Act: Only a Handful of Member States Have Designated Competent Authorities

Last month we looked at the broader state of national Data Act implementation across the EU. As discussed in that edition, many Member States are still working on broader implementation legislation. This month, we take a closer look at a separate question: which Member States have actually designated an operational competent authority for the Data Act?

Based on our review of publicly available national legislation, draft legislation and information published by national authorities across all 27 Member States, checked in September 2026, we identified six Member States where Data Act competent authorities have been formally designated and are operational:

  • Germany: Bundesnetzagentur, with the BfDI and the Länder authorities covering personal-data matters
  • Netherlands: Authority for Consumers and Markets (ACM), with the Dutch Data Protection Authority (AP) responsible for personal-data matters
  • Denmark: Digitaliseringsstyrelsen
  • Finland: Traficom
  • Malta: Malta Digital Innovation Authority (MDIA), with the Malta Communications Authority (MCA) responsible for Articles 23–31 and 34–35 and the Information and Data Protection Commissioner (IDPC) for personal-data matters
  • Lithuania: Communications Regulatory Authority (RRT)

This leaves 21 Member States where, based on publicly available materials, we could not identify a fully operational Data Act enforcement authority. Some are further along than others:

  • Belgium: the federal coalition agreement provides for the BIPT to take on the Data Act’s supervisory and coordination powers, but the necessary legislation is still pending
  • Czech Republic: draft legislation provides for the Czech Telecommunication Office (ČTÚ) to take on a role under the Data Act
  • Ireland: the CCPC and ComReg have been designated by government decisions, with the CCPC also acting as Data Coordinator, but the legislation giving effect to their powers is still pending
  • Poland: draft legislation provides for the Office of Electronic Communications (UKE) to take on a role under the Data Act
  • France: ARCEP already has responsibilities for data intermediation services and cloud switching under the SREN law, while broader Data Act enforcement powers are still part of the pending DDADUE legislation

A common pattern emerges across several Member States: telecoms regulators are playing a central role. They have been chosen as the main authority in some countries, such as Finland and Lithuania, or are taking responsibility for specific parts of the Data Act, such as cloud switching in Malta and France. Germany has taken a similar approach with the Bundesnetzagentur. The Netherlands is a notable exception, with the ACM and AP sharing responsibility.

Practical implication: in the 21 Member States where we could not identify a fully operational Data Act competent authority, businesses may not yet have a clear national point of contact for complaints under Article 38. This does not affect the substantive obligations under the Data Act, which apply regardless of whether the national enforcement structure is fully in place. Businesses should therefore not assume that the absence of an operational authority means that the Data Act can be disregarded. More than a year after the Regulation became applicable on 12 September 2025, many Member States are still finalising the national structures needed to enforce it.

3. Data Act: What Changed on 12 September, and What Remains Open

On 12 September 2026, the Data Act’s new “access by design” requirement started to apply. Until then, users of connected products and related services already had a right to obtain readily available product data and related service data on request. For products and related services placed on the EU market from 12 September 2026, Article 3(1) now requires data access to be built into the design from the outset, where relevant and technically feasible.

What changes for manufacturers

Since 12 September 2025, users have been able to request product data and related service data under Article 4. Article 3(2) and (3) also require sellers, lessors and providers of related services to give users pre-contractual information about the data a product or service can generate and how those data can be accessed.

Article 3(1) adds a design requirement. Products and related services must be designed and manufactured, or designed and provided, so that the relevant data and necessary metadata are, by default, easily and securely accessible to the user, free of charge and in a structured, commonly used and machine-readable format. Where relevant and technically feasible, the data must also be directly accessible to the user.

The requirement applies to the individual product or related service placed on the market after 12 September 2026. A product placed on the market before that date does not become subject to Article 3(1) simply because it remains available for sale afterwards.

The Regulation also covers virtual assistants where they interact with connected products or related services. In that case, the relevant Data Act obligations concern data arising from that interaction.

What remains open

The main remaining question concerns the scope of the term “connected product”.

Article 2(5) defines a connected product as an item that obtains, generates or collects data concerning its use or environment and is able to communicate product data through an electronic communications service, a physical connection or on-device access. “Product data”, in turn, means data generated by the use of a connected product that the manufacturer has designed to be retrievable.

The definitions are closely linked, which can make borderline cases difficult. This is particularly relevant where data remain on the device and the manufacturer has not designed them to be retrieved. At the same time, the Regulation expressly recognises on-device access as a possible form of access. Local storage alone therefore does not take a product outside the definition.

Standards are still developing

Technical standards supporting the Data Act are also still being developed. CEN, CENELEC and ETSI accepted the Commission’s standardisation request in July 2025. EN 18235-1:2026 was published in March 2026, while further standards covering interoperability remain under development.

This does not delay Article 3(1). The access by design requirement applies from 12 September 2026 regardless of whether the relevant standards have been finalised or cited in the Official Journal.

Practical takeaway

For manufacturers, the position is clear: for products and related services placed on the EU market from 12 September 2026, data access is a design requirement where Article 3(1) applies. The cut-off date therefore needs to be assessed at the level of the individual product or service.

The remaining uncertainty is mainly one of scope. How the definitions of “connected product” and “product data” are applied in borderline cases will determine which products fall within the access by design requirement.

4. EHDS: Commission Adopts Implementing Regulation on MyHealth@EU

Outside the Data Act itself, the Commission has taken a step forward on the European Health Data Space. Implementing Regulation (EU) 2026/2083 was adopted on 18 September 2026 and published in the Official Journal on 21 September 2026. Its legal basis is Article 23(4) and (8) of Regulation (EU) 2025/327, the EHDS Regulation.

The Regulation sets out rules for the operation of MyHealth@EU, the central interoperability platform for the cross-border exchange of personal electronic health data. It builds on the existing eHealth Digital Service Infrastructure, established under Implementing Decision 2019/1765, which has so far allowed Member States to exchange patient summaries, electronic prescriptions and electronic dispensations on a voluntary basis. The new Regulation covers interoperability, security and data protection requirements for the platform going forward.

The Regulation enters into force on 11 October 2026 but will apply from 26 March 2027. This lines up with the EHDS Regulation's own timeline, under which the Commission is required to have adopted the key implementing acts by that date, ahead of the first cross-border exchange obligations for priority data categories from March 2029.

A related implementing act, Regulation (EU) 2026/2098, was adopted alongside it. It sets out the minimum information needed to describe health datasets intended for secondary use, covering what data is available, who holds it, what a given dataset contains and under what conditions it can be accessed. That Regulation applies from 26 March 2029, in line with the EHDS's secondary-use timeline.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.