Data Act Article 33 explained: interoperability requirements for data
Data Act Article 33: Making Data Sharing Work Across Organizations
Article 33 of the EU Data Act sets out practical requirements for organizations that share data within structured environments called data spaces. The core idea is straightforward: if you’re sharing data with others—whether in your supply chain, sector, or across the EU—you need to make sure your data can actually be understood and used by the recipients without unnecessary friction or technical barriers.
This article focuses on interoperability. In plain terms, this means your data systems and the data itself must be designed so that different organizations’ systems can communicate smoothly. Think of it like ensuring all electrical outlets work with the same plugs, or that shipping containers fit on any truck. For companies managing Digital Product Passport information or operating connected products, Article 33 creates a framework to ensure data isn’t locked into proprietary formats that only you can read.
What You Must Document About Your Data
The first requirement under Article 33 is that any dataset you share must come with clear, machine-readable documentation. This isn’t about writing prose descriptions—it’s about structuring information in formats that both humans and software systems can process automatically.
Your documentation must cover several elements:
- Content and scope: What the dataset actually contains and what it doesn’t
- Usage restrictions: Any legal, technical, or commercial limitations on how others can use it
- Licensing terms: What intellectual property rights apply
- Quality metrics: Accuracy, completeness, timeliness, and reliability measures
- Collection methods: How and when the data was gathered
For companies using standards like GS1 or EPCIS 2.0 to manage product data, this documentation requirement aligns well with existing practice—you’re essentially making explicit what was often implicit. The goal is transparency: when another organization receives your data, they know exactly what they’re working with and what they can legally do with it.
Standardizing How Data Is Structured
Beyond describing what’s in your datasets, Article 33 requires that the structure of your data—how it’s organized, formatted, and labeled—must be publicly available and consistently applied. This includes data formats, vocabularies (the terms you use), and classification schemes (how you categorize information).
This requirement addresses a common real-world problem: two organizations might both have data about product durability, but one calls it “service life,” another uses “functional longevity,” and a third labels it “usable lifetime.” Without consistent language and structure, automated systems struggle to match and combine data correctly.
By making these structures public and consistent, Article 33 creates a foundation for the Data Act and portability. When data moves from one system to another, it arrives in a format the receiving system can immediately recognize and process, reducing the need for manual translation or custom integration work.
Technical Access and Automated Data Sharing
Documentation and structure alone aren’t enough. Article 33 also mandates that you provide technical means for others to actually access and receive your data automatically. The primary tool here is application programming interfaces (APIs)—essentially bridges between different software systems.
Your APIs must:
- Enable automatic, direct data transmission between systems
- Support real-time delivery where technically feasible (not just one-off downloads)
- Support bulk downloads where real-time isn’t practical
- Include clear service-level terms (response times, availability, uptime guarantees)
For companies operating connected products that generate or consume continuous data streams, this is particularly important. If you’re managing IoT device information or sustainability metrics that feed into a supply chain, your technical setup must allow other authorized parties to pull that information automatically, on schedule, without requiring manual intervention each time.
Where applicable, the regulation also mentions automated data sharing tools—such as smart contracts or other executable agreements. These must also be interoperable, meaning they should work with the broader ecosystem rather than lock data into a single platform.
The Role of EU Standards and Legal Presumption
Implementing all these interoperability requirements from scratch would be costly and fragmented. That’s why Article 33 gives the European Commission a key role: it will develop and publish harmonised standards and common specifications that companies can follow.
This is important for compliance: if you document your data, structure it, and provide APIs according to standards that the Commission has officially published, you receive a legal presumption of conformity. In other words, you don’t have to prove you’ve met Article 33—following the published standard is itself evidence that you have.
This creates a practical pathway: wait for the Commission to publish the standards in your sector or use case, then align your systems accordingly. Organizations that do so face lower compliance risk. Those that don’t align with published standards, once available, may face scrutiny or enforcement action if they claim to be participating in EU data spaces.
Where These Requirements Apply
Article 33 applies across different types of data spaces:
- Sector-specific spaces: Automotive, construction, or health data spaces with their own community standards
- Cross-sectoral spaces: Broader ecosystems where different industries share data
- Purpose-driven spaces: Data shared for product development, research, or civil society benefit
If you’re a manufacturer with Digital Product Passport obligations, or a logistics company managing product tracking data, or a materials supplier providing environmental performance information to customers, Article 33 likely applies to you if you’re sharing that data within any organized data space.
What This Means for Your Organization
In practical terms, Article 33 is a push toward modernizing how companies manage and share data. Rather than custom integrations and bilateral agreements for each data exchange, the regulation encourages standardized, automated approaches that scale across many partners.
Companies should begin auditing their current data practices: How do you document datasets? Are your data formats publicly specified? Do you have APIs, and are they accessible to authorized parties? Once EU standards are published for your sector, compliance will mean aligning with those standards—there’s no viable alternative if you want to participate in EU data spaces.
Frequently Asked Questions
Do I have to share all my company’s data under Article 33?
No. Article 33 applies only to data you’ve already decided to share within a data space. It doesn’t create new obligations to share data. It does, however, set requirements for how you share data once you’ve committed to doing so.
What happens if I don’t follow the Commission’s published standards?
You lose the legal presumption of conformity. You could still argue you’ve met Article 33’s requirements through other means, but you’d bear the burden of proof. It’s simpler and safer to follow published standards once available.
Are there costs to implementing Article 33 compliance?
Yes, but often these are upfront investments in standardized APIs and documentation practices—not fundamentally different from what many organizations already do. Following published EU standards, once available, should reduce costs compared to custom solutions.
When do these requirements take effect?
Article 33 is in force, but the practical timeline depends on when the Commission publishes harmonised standards for your sector. Until then, compliance is expected based on the general principles outlined in the article.
Official text (Data Act Article 33): “Technical means to access data, such as application programming interfaces, and their terms of use and quality of service shall be sufficiently described” — Regulation (EU) 2023/2854, EUR-Lex
Portable passports, no lock-in
GovGDS distributes DPPs on open standards, aligned with the Data Act on data portability.
Related: The EU Data Act & portability · What is a Digital Product Passport?
