Data Act Article 5 explained: the right to share data with third parties

Data Act Article 5: Right of the user to share data with third parties

Article 5 of the EU Data Act gives users a powerful right to request that companies controlling connected product data hand that information over to third parties—think repair services, sustainability consultants, or alternative software providers. This article fundamentally changes how data flows in the connected economy. Rather than data being locked into silos controlled by product manufacturers, users can now unlock it for legitimate purposes. For businesses, this means preparing robust systems to comply with data-sharing requests while still protecting genuinely sensitive business information.

What Article 5 requires

When a user asks a data holder (typically the manufacturer or platform controlling a connected product) to share data with a third party, the data holder must comply quickly and without charging fees. The data must be delivered in a structured, machine-readable format—not a printout or PDF that a human has to manually re-enter. The quality and completeness of what the third party receives should match what the data holder uses internally. This principle sits at the heart of the Data Act and portability: users own the right to access their data and direct its use, not companies.

The requirement applies to “readily available data”—information the data holder already holds or generates from the connected product’s operation. If you manufacture a smart appliance that logs temperature, usage patterns, energy consumption, and maintenance needs, those datasets must be shareable on demand. The data holder cannot delay or obstruct the request without legitimate grounds, and must establish technical infrastructure to make sharing automatic or near-automatic.

Metadata—information about the data itself, such as timestamps, data quality indicators, or data lineage—must also be shared. This ensures third parties understand the context and reliability of what they receive, which is especially important in supply chain transparency and Digital Product Passport contexts, where data provenance matters.

Who cannot block or incentivize sharing: Gatekeepers

The Data Act singles out designated gatekeepers—the dominant digital platforms identified under EU competition law—and imposes tighter restrictions on them. These gatekeepers cannot use commercial incentives to encourage users to share data with their own services instead of competitors. This addresses a real competitive imbalance: if a large platform offers users a discount or premium feature in exchange for sharing data exclusively with it, that gatekeeper could entrench its market position and exclude rivals.

Gatekeepers also cannot make it easier or more attractive to share data with them than with third parties. All users must face the same terms and friction level when directing their data elsewhere. This rule prevents gatekeepers from using their control over user interfaces and defaults to steer data their way.

Protecting trade secrets while enabling sharing

Article 5 recognizes that some data does touch genuinely sensitive business secrets. A data holder can refuse to share information where disclosure would cause serious economic damage—for example, proprietary algorithms, detailed cost structures, or unreleased product roadmaps embedded in the data. However, this exemption is narrow and defensive. The data holder must justify why disclosure poses serious economic harm, must notify relevant authorities, and cannot use “trade secret” as a blanket excuse to withhold operational data that users have a legitimate interest in accessing.

In practice, many trade secrets can be shared in anonymized or aggregated form, or with contractual protections (such as confidentiality agreements with third parties). Article 5 does not require data holders to hand over raw, unprotected sensitive information; it requires them to find ways to share what users request while genuinely protecting what warrants protection.

Data protection and consent

When shared data includes personal information about individuals—such as usage patterns, location history, or household member details—the share must comply with GDPR. There must be a valid legal basis for passing that personal data to a third party. Often, the user’s explicit consent suffices, but depending on the context, other bases (like legitimate interest or contractual necessity) may apply. Data holders cannot use technical barriers to sharing as a pretext for avoiding GDPR obligations; they must architect solutions that respect both the Data Act’s portability right and GDPR’s privacy safeguards.

Preventing unauthorized access and misuse

Data holders are responsible for ensuring that shared data reaches only the intended third party and that technical infrastructure cannot be exploited to gain unauthorized access. For example, if a user requests their data go to a repair service, the data holder must authenticate that recipient and prevent other parties from intercepting or eavesdropping on the transfer. This is a security and authentication obligation, not a gating mechanism to deny legitimate requests.

Equally important: data holders cannot use shared data to derive commercial insights about third parties without explicit permission. If a manufacturer sees that users are requesting their data be shared with a particular competitor or service provider, it cannot use that pattern to infer market intelligence and act on it. The act of sharing must not become a surveillance tool for the data holder.

Practical implications for connected product businesses

For manufacturers, Article 5 means investing in automated data-sharing infrastructure. Manual processes and custom integrations for every third-party request will not scale. Many organizations are adopting standardized data formats—such as those based on GS1 or EPCIS 2.0 standards—to simplify machine-readable sharing across supply chains and service networks. Building APIs or data interfaces that third parties can securely connect to is now a baseline requirement, not a competitive advantage.

It also means rethinking data governance. You must map which data falls under Article 5’s sharing obligation, which truly warrants trade-secret protection, and which contains personal data requiring GDPR compliance. You need contractual templates for third parties receiving data, audit trails showing who accessed what and when, and incident response plans if unauthorized sharing occurs.

For businesses in regulated industries (automotive, medical devices, industrial equipment), Article 5 intersects with other compliance frameworks. A car manufacturer, for instance, must allow owners to share vehicle data with independent repair shops and insurers; the data must flow in standard, machine-readable formats. This aligns with broader EU policy favoring repairability and competitive aftermarkets.

Frequently asked questions

  • Do we have to share data immediately? No, but “without undue delay” means days, not weeks. Most requests should be fulfilled within days unless there are genuine technical or legal obstacles (e.g., trade-secret redaction requires careful review). Establishing fast, automated processes is the practical standard.
  • Can we charge for sharing infrastructure or compliance costs? No. The user must not be charged, and the cost cannot be passed to third parties receiving the data. Shared data must be delivered at no cost, though third parties may charge end-users for the services they deliver using that data.
  • What if the third party is unknown or potentially malicious? You must authenticate and vet the third party to prevent unauthorized access, but you cannot refuse the share simply because the third party is a competitor or because you disapprove of their business model. Your role is gatekeeper for security and authorization, not arbiter of which uses are “good.”
  • Does Article 5 apply to all data, or only operational data? It applies to “readily available data”—data the product or system generates or the holder possesses. Trade secrets and personal data have specific protections, but these are exceptions, not blanket exclusions.
  • How does this relate to Digital Product Passports? Digital Product Passport frameworks rely on transparent, portable product data. Article 5 enables that portability by ensuring manufacturers cannot lock users into proprietary systems; third parties (including passport platforms) can access product data at user request in standard formats.

Official text (Data Act Article 5): “Data holder shall make available readily available data to a third party without undue delay, free of charge, in machine-readable format” — Regulation (EU) 2023/2854, EUR-Lex

Portable passports, no lock-in

GovGDS distributes DPPs on open standards, aligned with the Data Act on data portability.

Request a demo →

Related: The EU Data Act & portability · What is a Digital Product Passport?

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *