Data Act, Article 11 (technical protection measures on access to data)
Regulation (EU) 2023/2854, Art. 11
In force since .
A computer misuse rule binding public and private bodies.
- Obligation class
- Access restriction
As of .
What it requires
- This Regulation is binding in its entirety and directly applicable in all Member States (Article 50). Article 11 sits in Chapter III, which applies where, in business-to-business relations, a data holder is obliged under Article 5 or under applicable Union law or national legislation adopted in accordance with Union law to make data available to a data recipient (Article 12(1)), and Article 11 binds users, third parties and data recipients.
- Do not alter or remove the technical protection measures a data holder applies to prevent unauthorized access to data, including metadata, unless the data holder agrees (Article 11(1)).
- Where you are a third party or data recipient who, for the purposes of obtaining data, provided false information to a data holder, deployed deceptive or coercive means or abused gaps in the technical infrastructure of the data holder designed to protect the data, or who altered or removed the data holder's technical protection measures without its agreement, comply without undue delay with the requests of the data holder (and, where applicable and where they are not the same person, of the trade secret holder or the user) to erase the data made available and any copies, to end the production, offering or placing on the market or use of goods, derivative data or services produced on the basis of knowledge obtained through the data in the cases Article 11(2), point (b), describes, to inform the user of the unauthorized use or disclosure and of the measures taken to end it, and to compensate the party suffering from the misuse or disclosure (Article 11(2) and (3)).
- The same duties apply where a third party or data recipient used the data made available for unauthorized purposes, unlawfully disclosed data to another party or did not maintain the technical and organizational measures agreed under Article 5(9) (Article 11(3), points (b) to (d)), and where a user alters or removes the data holder's technical protection measures (Article 11(4)).
Who enforces it
Enforcement body
The competent authorities each Member State designates under Article 37(1) to be responsible for the application and enforcement of the Regulation.
What this law does
Article 11(1) lets a data holder apply appropriate technical protection measures, including smart contracts and encryption, to prevent unauthorized access to data, including metadata, and to ensure compliance with Articles 4, 5, 6, 8 and 9 and with the agreed contractual terms for making data available.
Those measures must not discriminate between data recipients or hinder a user's right to obtain a copy of, retrieve, use or access data, to provide data to third parties under Article 5 or any right of a third party under Union law or national legislation adopted in accordance with Union law. Article 11(1) provides that users, third parties and data recipients shall not alter or remove such technical protection measures unless agreed by the data holder.
Article 11(3) applies the Article 11(2) remedies where a third party or a data recipient has, for the purposes of obtaining data, provided false information to a data holder, deployed deceptive or coercive means or abused gaps in the technical infrastructure of the data holder designed to protect the data; used the data made available for unauthorized purposes, including the development of a competing connected product within the meaning of Article 6(2), point (e); unlawfully disclosed data to another party; not maintained the technical and organizational measures agreed pursuant to Article 5(9); or altered or removed technical protection measures applied by the data holder pursuant to Article 11(1) without the agreement of the data holder.
Under Article 11(2), in those circumstances the third party or data recipient shall comply without undue delay with the requests of the data holder and, where applicable and where they are not the same person, the trade secret holder or the user, to erase the data made available by the data holder and any copies thereof.
Article 11(2) also requires compliance with requests to end the production, offering or placing on the market or use of goods, derivative data or services produced on the basis of knowledge obtained through the data, or the importation, export or storage of infringing goods for those purposes, and to destroy any infringing goods, where there is a serious risk that the unlawful use of the data will cause significant harm to the data holder, the trade secret holder or the user or where such a measure would not be disproportionate in light of their interests.
Article 11(2) further requires compliance with requests to inform the user of the unauthorized use or disclosure of the data and of the measures taken to put an end to it, and to compensate the party suffering from the misuse or disclosure of such unlawfully accessed or used data.
Article 11(4) applies Article 11(2) also where a user alters or removes technical protection measures applied by the data holder, or does not maintain the technical and organizational measures taken by the user in agreement with the data holder or the trade secrets holder to preserve trade secrets, and in respect of any other party that receives the data from the user by means of an infringement of the Regulation.
Article 12(1) applies Chapter III, in which Article 11 sits, where, in business-to-business relations, a data holder is obliged under Article 5 or under applicable Union law or national legislation adopted in accordance with Union law to make data available to a data recipient. Article 50 applies the Regulation from .
Article 50 also applies Chapter III in relation to obligations to make data available under Union law or national legislation adopted in accordance with Union law that enters into force after .
When LexLint raises it
When your app profile says your app crawls the web.