The EU Data Act creates a framework for business-to-business (B2B) data sharing — governing situations where one company holds data generated by another company's use of connected products or services, and the data-holding company makes that data available commercially. These provisions sit between the user access rights (Chapter II) and the cloud switching rules (Chapter VI), creating a distinct layer of obligations for data holders that operate in B2B markets.
What B2B Data Sharing Covers
B2B data sharing under the Data Act applies when:
- A data holder — a company that holds data generated by another business's use of a connected product or related service
- Makes that data available to a data recipient — another business — under a commercial or contractual arrangement
The typical scenario: an industrial equipment manufacturer collects operational data from machines deployed in a customer's factory. The customer (a business) wants to use that data with a third-party analytics provider or a competing maintenance service. The manufacturer is the data holder; the analytics provider is the data recipient.
Key B2B Data Sharing Obligations
1. Fair, Reasonable, and Non-Discriminatory Terms (FRAND)
Data holders that make data available to business recipients must do so on fair, reasonable, and non-discriminatory terms. This means:
- Pricing for data access must be proportionate and transparent
- Terms offered to one recipient must not be significantly more favourable than terms offered to comparable recipients for comparable data access
- Data holders cannot use data access terms as a tool to disadvantage competitors or protect incumbents
The FRAND standard does not mean data must be provided for free. Data holders can charge a reasonable fee reflecting the cost of making the data available. What they cannot do is set discriminatory pricing, impose unreasonable restrictions, or use access terms strategically to suppress competition.
2. Prohibition on Competing Product Development
A business that receives data from a data holder under a B2B arrangement cannot use that data to develop a competing product. The Data Act is explicit: the data recipient cannot use the received data in a way that directly competes with the data holder's core business.
Example: An automotive manufacturer shares telematics data with an aftermarket maintenance service under a B2B agreement. The maintenance service cannot use that data to develop its own competing vehicle management platform that replicates the manufacturer's product.
3. Purpose Limitation
Data recipients can only use the shared data for the purpose agreed in the data sharing arrangement. They cannot:
- Repurpose the data for analytics outside the agreed scope
- Sell or sub-licence the data to further parties without authorisation
- Use the data for profiling or other processing not covered by the agreement
Purpose limitation under the Data Act mirrors the GDPR principle but applies to non-personal data as well as personal data.
4. Trade Secret Protection
Data holders are not required to share data where doing so would disclose trade secrets. This protection applies where:
- The data itself constitutes a trade secret
- Providing access would reveal proprietary processes, algorithms, or methods
- The data holder can substantiate the trade secret claim
The protection is not absolute. Data holders cannot assert trade secret protection across all data as a blanket strategy to avoid the Data Act. Each trade secret claim must be specific and demonstrable. Where possible, the data holder should provide access to the portions of data that do not involve trade secrets and withhold only the protected elements.
Requirements for Data Sharing Agreements
When B2B data sharing occurs under the Data Act, the agreement between the data holder and the data recipient must address:
Purpose: Precisely defined purpose for which the data is being shared. Generic "analytical use" is insufficient — the purpose should describe the specific service or activity.
Data scope: What data is covered, in what format, with what level of granularity.
Duration: The timeframe for which data sharing is authorised. Open-ended data sharing arrangements create ongoing obligations.
Restrictions on use: Explicit prohibition on competing product development, prohibition on sub-licensing without authorisation, prohibition on purpose extension.
Security obligations: The data recipient must implement appropriate technical and organisational security measures.
Termination: What happens to the data at contract end — deletion, return, or continued use under limited circumstances.
Trade secret provisions: Where the data holder has trade secret concerns, specific provisions restricting further disclosure.
Who Acts as Data Holder in B2B Arrangements
The Data Act defines a data holder as a legal entity or natural person that has the right and technical ability to make available data it has collected or generated. In B2B IoT contexts, the data holder is typically:
- The manufacturer of the connected product
- The provider of the related service (cloud platform, app) that holds the operational data
The data holder is not necessarily the data owner in a property-law sense — the Data Act deliberately avoids creating data ownership. Data holders are custodians of data with obligations, not proprietors with absolute rights.
Horizontal Agreements and Exclusivity
The Data Act addresses concerns about B2B data sharing creating antitrust issues. The FRAND requirements are designed to ensure that data sharing does not become a competitive weapon:
Data exclusivity: Data holders cannot contractually prevent data recipients from seeking similar data from other sources. Exclusive data supply arrangements that foreclose competition are problematic under the Data Act and potentially under EU competition law.
Data monopolisation: Where a data holder has a dominant position (holding unique data that businesses need to compete), the Data Act's FRAND provisions interact with competition law obligations under Article 102 TFEU.
Practical Implications for Data Holders
If you hold B2B product data and operate in the EU:
- Audit your current B2B data sharing arrangements — do they include FRAND pricing, purpose limitations, and trade secret provisions?
- Review existing terms — terms that prevent recipients from accessing or using their own operational data may be void under the Data Act
- Build a data sharing programme — standard terms, an API or structured data export, and a pricing structure
- Document trade secret positions — if you intend to invoke trade secret protection, document the specific data elements and the basis for the claim