Sitemap

Decentralizing Data Control: Navigating the EU Data Act and the Future of Data Governance

5 min readFeb 5, 2025

--

Press enter or click to view image in full size

By 2025, the value of the EU data economy is expected to reach €829 billion, up from €301 billion in 2018. This remarkable growth is supported by new regulations, including the Data Act and Data Governance Act, which aim to promote data circulation and reuse across the EU. These regulations are designed to dismantle existing data silos and foster a more open data economy.

The Data Act: Breaking Down Data Silos

The Data Act, effective from September 12, 2025, is a key initiative to promote the circulation of data streams generated by connected devices and related applications. Currently, “manufacturers are able to determine, through their control of the technical design of the connected products or related services, what data are generated and how they can be accessed, despite having no legal right to those data.”[1] The Data Act changes this dynamic by ensuring that “users of a connected product or related service in the Union can access, in a timely manner, the data generated by the use of that connected product or related service and that those users can use the data, including by sharing them with third parties of their choice.”

Data Act Compliance ‘by Design’

By September 12, 2026, all new devices and related applications must be compliant with the Data Act by design. As stipulated, “connected products shall be designed and manufactured, and related services shall be designed and provided, in such a manner that product data and related service data are, by default, easily, securely, free of charge [….] directly accessible to the user.”[1] This means that providers of connected products and applications must ensure that users can directly access and use the data generated by these devices. Additionally, users must be able to share this data with any third party of their choice without any intermediation from the providers.

Practical Impact of the Data Act

To understand the impact of the Data Act, consider the following scenario: You purchase a car equipped with advanced electronics that record your driving data-such as location, speed, and braking behavior-and send it to the car manufacturer. When seeking car insurance, the insurer requests that you install a separate device that collects similar data and sends it directly to them. This results in two devices in your car, both collecting nearly identical data but sending it to different companies.

With the Data Act, you can request the car manufacturer to share this data directly with your insurance company, or any other company you choose, eliminating the need for the second device. This right applies not only to car data but also to data from other devices you own, such as a smartwatch, voice assistant, or smart meter.

The Data Governance Act: Supporting Data Sharing

The Data Governance Act (DGA), which was enforced in September 2023, complements the Data Act by creating a framework that supports data sharing. As described, “The DGA creates a framework to foster a new business model — data intermediation services — that will provide a trusted and secure environment in which companies or individuals can share data.” These data intermediaries “will function as neutral third parties that connect individuals and companies with data users. While they may charge for facilitating the data sharing between the parties, they cannot directly use the data that they intermediate for financial profit.”

Data Act Compliance: A New Business Opportunity

Data Act compliance presents a significant business opportunity for companies. They can create data exchanges by leveraging the services offered by Data Intermediaries, enabling their customers to share data with third parties and potentially monetize this activity.

While the Data Act regulates the fees chargeable to SMEs for data access, it does not intervene in data sharing agreements between large companies or when a large company obtains data from an SME. “In such cases, the enterprises are considered to be capable of negotiating the compensation within the limits of what is reasonable and non-discriminatory. Compensation may also include a margin […]. The margin may vary depending on factors related to the data itself, such as volume, format or nature of the data”1

The Privacy Challenge in Data Sharing

Despite the push for greater data sharing, privacy rules remain unchanged. With multiple data recipients and potentially numerous use cases, “you must explain each data use case separately, giving data subjects an opportunity to consent to each activity individually.” Moreover, “it should be as easy for [data subjects] to withdraw consent as it was for you to obtain consent.” This presents a significant challenge for companies striving to be Data Act compliant, as well as for Data Intermediation Services providers.

The Cost of Centralized Consent Management

In the current centralized approach to consent management, “the data intermediary has to cater for managing consent [& revoke] for data processing for each of the data [owners &] utilisers it serves.”[4] The cost of this approach scales with the number of data owners and recipients. For example, if managing one consent costs €1, a system with 1 million data owners and 10 data recipients would incur a total cost of €10 million.

The Decentralized Consent Management Solution

To address this issue, decentralizing consent management by giving control to Data Owners is the solution. This approach allows data owners to interact directly with each data recipient without any intermediation from the data-sharing service provider. The cost of this decentralized approach depends solely on the number of data owners. Using the previous example, the total cost of consent management would be €1 million, a significant reduction from the centralized approach.

Ecosteer’s Innovative Solutions

Ecosteer has developed technology solutions that provide data owners with unilateral control over data visibility, effectively decentralizing consent management. Their first technology, the Data Visibility Control Overlay (DVCO), allows data owners to control visibility over data streams generated by devices and applications. This technology is based on a globally patented multicast encryption scheme. Ecosteer’s latest innovation allows Data Owners to control visibility over Data Records stored by a Data Intermediary, utilizing a US Patent-pending Record-Level Encryption (RELE) scheme.

Ecosteer’s Data Governance Layer

Ecosteer technologies introduce a third data governance layer-data visibility control-above existing security and privacy measures. Security involves protecting computational resources, while privacy concerns the protection of data exchanged between secured resources. Both are typically managed centrally by the data-sharing services provider. Ecosteer’s solution adds a layer of decentralized control over the visibility of data exchanged within an already secured and private framework.

Understanding the Impact

With the current centralized approach, access to the data-sharing infrastructure is both a necessary and sufficient condition to gain visibility over data. However, Ecosteer’s decentralized approach changes this dynamic. While access remains a necessary condition, it is no longer sufficient to obtain data visibility-this can only be granted by the Data Owner.

In the next article of this series, we will explore the Data Visibility Control Overlay (DVCO) Ecosteer’s technology to decentralize control over data streams generated by connected devices.

Originally published at https://www.linkedin.com.

--

--

Ecosteer
Ecosteer

Written by Ecosteer

Ecosteer empowers data owners with full control, decentralizing consent management, cutting costs & liabilities & driving scalable growth in the digital economy