Law / European Union

Data Act, Essential Requirements for Smart Contracts That Execute Data Sharing Agreements

Regulation (EU) 2023/2854, Art. 36

In force since .

A product security requirements rule binding public and private bodies.

Private right of action
No
Obligation class
Security, Governance

As of .

What it requires

  • It reaches you if you are the vendor of an application using smart contracts or, in the absence of one, the person whose trade, business or profession involves deploying smart contracts for others, in the context of executing an agreement, or part of one, to make data available (Article 36(1); Article 1(3), point (g)). Make those smart contracts robust and access-controlled: design them to offer access control mechanisms and a very high degree of robustness to avoid functional errors and to withstand manipulation by third parties (Article 36(1), point (a)).
  • Build into the smart contract a mechanism to terminate the continued execution of transactions, with internal functions that can reset or instruct the contract to stop or interrupt the operation, in particular to avoid future accidental executions (Article 36(1), point (b)).
  • Provide, for the case in which a smart contract must be terminated or deactivated, a possibility to archive the transactional data, the smart contract logic and the code, to keep the record of operations performed on the data in the past (Article 36(1), point (c)).
  • Protect the smart contract through rigorous access control mechanisms at the governance and smart contract layers, and keep it consistent with the terms of the data sharing agreement that it executes (Article 36(1), points (d) and (e)).
  • Perform a conformity assessment against those essential requirements and, once they are fulfilled, issue an EU declaration of conformity, by which you become responsible for compliance with them (Article 36(2) and (3)).

Who enforces it

Enforcement body

The competent authorities that each Member State designates to be responsible for the application and enforcement of the Regulation (Article 37(1)); an entity falls under the competence of the Member State where it is established (Article 37(10)).

Settledness

As of
Open questions
Will the Commission proposal COM(2025) 837 final, which would delete Article 36 of Regulation (EU) 2023/2854, be adopted, and from what date?

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 36(1) of Regulation (EU) 2023/2854 requires the vendor of an application using smart contracts, or in the absence of one the person whose trade, business or profession involves the deployment of smart contracts for others, to ensure that the smart contracts used to execute an agreement to make data available meet five essential requirements.

The first is robustness and access control: the smart contract must be designed to offer access control mechanisms and a very high degree of robustness to avoid functional errors and to withstand manipulation by third parties.

The second is safe termination and interruption: a mechanism must exist to terminate the continued execution of transactions, and the smart contract must include internal functions which can reset or instruct the contract to stop or interrupt the operation, in particular to avoid future accidental executions.

The third is data archiving and continuity: where a smart contract must be terminated or deactivated, there must be a possibility to archive the transactional data, smart contract logic and code in order to keep the record of operations performed on the data in the past. The fourth is access control: the smart contract must be protected through rigorous access control mechanisms at the governance and smart contract layers.

The fifth is consistency with the terms of the data sharing agreement that the smart contract executes. Article 36(2) requires the vendor of a smart contract, or in the absence of one the person who deploys smart contracts for others, to perform a conformity assessment with a view to fulfilling the essential requirements and, on the fulfilment of those requirements, to issue an EU declaration of conformity.

Article 36(3) makes the party that draws up the EU declaration of conformity responsible for compliance with the essential requirements. Article 36(4) presumes a smart contract that meets harmonised standards whose references are published in the Official Journal to be in conformity with the essential requirements, to the extent that those standards cover them.

Article 1(3), point (g), applies the Regulation to vendors of applications using smart contracts and to persons whose trade, business or profession involves the deployment of smart contracts for others in the context of executing an agreement.

Article 2, point (39), defines a smart contract as a computer program used for the automated execution of an agreement or part thereof, using a sequence of electronic data records and ensuring their integrity and the accuracy of their chronological ordering. Article 37(1) requires each Member State to designate one or more competent authorities to be responsible for the application and enforcement of the Regulation.

Article 40(1) requires Member States to lay down the rules on penalties applicable to infringements of the Regulation, which must be effective, proportionate and dissuasive. Article 50 applies the Regulation from . The Commission proposal COM(2025) 837 final would delete Article 36 of the Regulation.

When LexLint raises it

When your app profile says your app distributes a software product.

Back to the example  ·  Lint your app