On February 23, 2022, the EU Commission published a proposal for a regulation on harmonized rules for access to and use of data as part of its strategy to make the EU a forerunner in the data-driven society. The “Data Law” regulates the access, use and transfer of “industrial data” generated in the EU by connected objects and related services. The law also ensures that this data is shared, stored and processed in accordance with EU regulations, even if the data set contains personal data.
scope
The proposed regulation applies in particular to data from the use of connected objects and related services (e.g. software). Data means any digital representation of any act, fact or information, including in an audio visual or audio visual format. While the regulation applies to data derived from usage and events, it does not apply to information derived or inferred from that data.
Connected devices (ie IoT) include vehicles, household appliances, consumer products, medical and healthcare devices, and agricultural or industrial machines (ie IoT) that generate performance, usage or environmental data. Products designed primarily to display, play, record or transmit content, such as PCs, servers, tablets, smartphones, cameras, webcams, sound recorders and text scanners are not covered by the law.
The Regulation applies to (a) manufacturers of products and providers of related services placed on the Union market, (b) users of such products or services; (b) data holders providing data to data recipients in the Union; (c) data recipients in the Union to whom data are made available; (d) public sector bodies and Union institutions, agencies or bodies requesting data holders to provide data where there is an exceptional need for the performance of a task of public interest and the data holders providing such data in response to such request ; and (e) data processing service providers offering such services to customers in the Union.
Relevant Provisions
-
Manufacturers and designers must enable consumers and businesses to access and use data derived from the use of connected devices that they own, rent or lease, and related services. This is data traditionally collected and stored by the manufacturer or designer, and the device owner’s right to the data is often unclear. According to the law, the device owner can use the data for after-market purposes. For example, a car owner can share usage data with their insurance company, or a business owner can use data from a connected manufacturing device to perform their own maintenance instead of using the manufacturer’s services. To support these efforts, manufacturers and designers must disclose what data can be accessed and design products and services so that the data is easily accessible by default.
-
Data-sharing agreements between parties must avoid contractual clauses that penalize SMEs. The law includes a test to assess the reasonableness of contract terms. The EU Commission plans to develop and publish non-binding model contract clauses to achieve this goal.
-
Cloud service providers must adopt portability measures that allow consumers and businesses to move data and applications to another provider without expense or expense. The law also mandates the implementation of safeguards to protect data stored on cloud infrastructures in the EU.
-
Customers have the right to transfer data from one data processor to another without any commercial, technical, contractual or organizational obstacles.
-
In exceptional situations (e.g. public emergencies), companies must transmit certain data to public authorities under certain conditions.
-
Cloud service providers are subject to certain restrictions on international data exchange or access.
-
The content of certain databases resulting from data generated or retrieved from connected devices is protected.
Next Steps
The proposed regulation aims to boost competition and create opportunities for data-driven innovation as part of the EU’s data strategy. It complements the Data Governance Act, which facilitates the exchange of data between sectors and member states. As the EU continues to strengthen its data strategy, US companies will want to monitor this space and consider first steps toward potential compliance. The regulation applies to US manufacturers and service providers who offer connected objects and related services on the EU market. Compliance requires appropriate policies, procedures and mechanisms to meet the regulation’s requirements for transparency, access, data minimization and safeguards. At a minimum, this includes designing and manufacturing products and services that include standard and standard user access mechanisms and protections.
Jackson Lewis PC © 2022National Law Review, Volume XII, Number 88
Comments are closed.