Trade secrets
Protecting trade secrets under the EU Data Act
The Data Act opens up access to product data — but it does not force you to hand over your trade secrets unprotected. This guide explains how to share data while safeguarding confidential information, and the narrow cases where you can withhold it.
Access vs confidentiality
The Data Act deliberately balances two goals: giving users and third parties access to the data a connected product generates, and protecting the trade secrets that data may contain. You cannot use trade secrets as a blanket reason to refuse access — but you are entitled to safeguards before that data leaves your control.
The mechanism runs through Articles 4 (user access) and 5 (third-party sharing): identify what is a trade secret, agree how it will be protected, and only then share.
How the safeguard works
First, you (or the trade-secret holder) must identify which data are protected as trade secrets, including in the relevant metadata. Then you agree proportionate technical and organisational measures with the recipient to preserve confidentiality before disclosure — for example non-disclosure agreements, access controls, secure processing environments or model contractual terms.
Once those measures are in place, the data — trade secrets included — is shared. The protection travels with the data through the contract, rather than by keeping it locked away.
When you can withhold or refuse
If no agreement on measures is reached, or the recipient fails to implement them or undermines confidentiality, you may withhold or suspend sharing of the identified trade-secret data — and you must inform the recipient and notify the competent authority. In exceptional cases, where you can demonstrate you are highly likely to suffer serious economic damage from disclosure despite the measures, you may refuse a specific request on a case-by-case basis.
Practical safeguards
Measures you can agree before sharing
Confidentiality agreements
NDAs or contract clauses limiting how the recipient can use and disclose the data.
Access controls
Strict access protocols, authentication and logging so only authorised people see the data.
Secure environments
Secure data rooms or controlled processing environments rather than raw bulk export.
Standards & templates
Technical standards, codes of conduct or the Commission's model contractual terms.
Getting ready
How to protect trade secrets in practice
Map your trade secrets
Work out which product and service data qualify as trade secrets, and tag them in metadata.
Prepare standard measures
Have NDAs, access controls and clauses ready so you can agree them quickly on request.
Set a request process
Define how you agree measures, and when withholding or suspending is justified.
Document your reasoning
Record why you withheld or refused — you may have to justify it to the competent authority.
Check your exposure
See how well your trade secrets are protected
Answer a few questions to get a free indication of whether your data-sharing safeguards meet the Data Act.