Access vs confidentiality

The Data Act deliberately balances two goals: giving users and third parties access to the data a connected product generates, and protecting the trade secrets that data may contain. You cannot use trade secrets as a blanket reason to refuse access — but you are entitled to safeguards before that data leaves your control.

The mechanism runs through Articles 4 (user access) and 5 (third-party sharing): identify what is a trade secret, agree how it will be protected, and only then share.

How the safeguard works

First, you (or the trade-secret holder) must identify which data are protected as trade secrets, including in the relevant metadata. Then you agree proportionate technical and organisational measures with the recipient to preserve confidentiality before disclosure — for example non-disclosure agreements, access controls, secure processing environments or model contractual terms.

Once those measures are in place, the data — trade secrets included — is shared. The protection travels with the data through the contract, rather than by keeping it locked away.

When you can withhold or refuse

If no agreement on measures is reached, or the recipient fails to implement them or undermines confidentiality, you may withhold or suspend sharing of the identified trade-secret data — and you must inform the recipient and notify the competent authority. In exceptional cases, where you can demonstrate you are highly likely to suffer serious economic damage from disclosure despite the measures, you may refuse a specific request on a case-by-case basis.

Practical safeguards

Measures you can agree before sharing

Confidentiality agreements

NDAs or contract clauses limiting how the recipient can use and disclose the data.

Access controls

Strict access protocols, authentication and logging so only authorised people see the data.

Secure environments

Secure data rooms or controlled processing environments rather than raw bulk export.

Standards & templates

Technical standards, codes of conduct or the Commission's model contractual terms.

Getting ready

How to protect trade secrets in practice

Map your trade secrets

Work out which product and service data qualify as trade secrets, and tag them in metadata.

Prepare standard measures

Have NDAs, access controls and clauses ready so you can agree them quickly on request.

Set a request process

Define how you agree measures, and when withholding or suspending is justified.

Document your reasoning

Record why you withheld or refused — you may have to justify it to the competent authority.

Check your exposure

See how well your trade secrets are protected

Answer a few questions to get a free indication of whether your data-sharing safeguards meet the Data Act.

Start free assessment