EU Data Governance Act (DGA)
Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DGA - Competent Authorities (Ch V)
Article 26 sets the requirements for competent authorities (legal distinctness from operators, sufficient resources, technical expertise, independence). Article 27 grants natural and legal persons the right to lodge a complaint with the competent authority for breaches of the Regulation. Article 28 grants the right to an effective judicial remedy against binding decisions of competent authorities and against decisions of data intermediation service providers / data altruism organisations.
- Identification of the competent authority for each Member State the entity operates in
- Internal complaint-handling procedure
- No mechanism to receive Article 27 complaints
DGA - Data Altruism (Ch IV)
Article 16 permits Member States to have in place organisational or technical arrangements to facilitate data altruism. Article 17 requires each Member State to maintain a public register of recognised data altruism organisations established in its territory, and the Commission to maintain an EU-wide register. Recognised status enables organisations to use the 'recognised data altruism organisation in the Union' label.
- Application records for recognised data altruism organisation status where the entity seeks recognition
- Reliance on the EU-wide register when partnering with a data altruism organisation
Article 18 sets the substantive requirements for a recognised data altruism organisation: (a) legal entity established for general-interest objectives (public health, environment, scientific research, etc.); (b) operates on a not-for-profit basis (any surplus is reinvested); (c) carries out its data-altruism activities through a structure separate from other activities; (d) Article 21 transparency + safeguarding requirements are met. Article 19 sets the registration procedure with the competent authority designated under Article 23.
- Constitutional / by-law evidence of general-interest objective + not-for-profit + structural separation
- Application records under Article 19 procedure
- Mixing data-altruism activities with for-profit operations in the same legal person (Article 18(c) breach)
- Recognised status without ongoing Article 21 transparency
Article 20 requires recognised data altruism organisations to record: (a) all data users using their data; (b) the dates / durations of use; (c) the purpose; (d) any fees paid by data users; (e) the data subjects / data holders' interests safeguarded. Article 21 imposes safeguarding requirements: clear information to data subjects/data holders, mechanisms for consent / permission withdrawal, appropriate technical + organisational measures to protect rights, no use of data for other purposes.
- Article 20 record of all data uses (data user identity, dates, purpose, fees)
- Article 21 information notice + withdrawal mechanism for data subjects + data holders
- Annual transparency report
- Recognised data altruism organisation with no Article 20 record-keeping
- No mechanism for withdrawal of consent / permission per Article 21
Article 22 empowers the Commission to adopt delegated acts establishing a 'rulebook' setting common requirements for recognised data altruism organisations on information security, interoperability, communication strategies for data altruism, and recommended standards for data-altruism consent.
- Adoption of the Article 22 rulebook standards where the entity is a recognised data altruism organisation
Article 23 requires each Member State to designate a competent authority for the registration and supervision of data altruism organisations. Article 24 sets the monitoring tasks. Article 25 requires the Commission to adopt, by way of implementing act, the European data altruism consent form, designed for data subjects to provide informed consent for data-altruism activities and to be modular by sector (health, mobility, environment, etc.).
- Use of the European Data Altruism Consent Form where the entity collects data-altruism consent
- Cooperation records with the Article 23 competent authority
- Bespoke consent text used instead of the European Data Altruism Consent Form where available
DGA - Data Intermediation Services (Ch III)
Article 10 defines the scope of data intermediation services (DIS): (a) intermediation between data holders and data users on a commercial basis; (b) intermediation between data subjects exercising data-subject rights and potential data users; (c) services of data cooperatives. Article 11 imposes a notification regime: providers of DIS must notify the competent authority designated under Article 13 before commencing activities. Article 11 sets the content of the notification (provider identity, services description, governance structure) and provides for a confirmation of completeness within 1 week. DIS that has been notified may use the EU label.
- Article 11 notification submission to the competent authority where the entity provides DIS
- Records of confirmations and any subsequent updates
- Operating a data intermediation service without an Article 11 notification
- Notification missing required content
Article 12 sets the substantive operating conditions for DIS: (a) the DIS provider shall not use the data for purposes other than the intermediation; (b) the DIS provider shall not use derived insights from intermediated data for its own commercial gain; (c) the DIS provider shall provide its services through a separate legal person (structural separation from any other commercial activity); (d) the DIS provider must enable interoperability with other DIS; (e) ICT-security measures appropriate to the risks; (f) fair, transparent and non-discriminatory access; (g) procedures to prevent fraudulent or abusive practices.
- Structural-separation evidence (legal person, governance, accounts) where the entity provides DIS
- ICT-security baseline aligned with Article 12(e) (mapped to NIS2 Art.21(2) baseline measures)
- Conflict-of-interest controls demonstrating no use of intermediated data for own commercial gain
- DIS bundled with other commercial activity in the same legal person
- Use of intermediated data to feed the provider's own products (prohibited by Article 12(b))
- DIS without an ICT-security baseline aligned with NIS2
Article 13 requires each Member State to designate competent authorities for DIS. Article 14 sets the monitoring tasks of the competent authorities (compliance with Articles 10-12, on-site inspections, corrective orders). Article 15 specifies that recognised data altruism organisations or other non-profit entities engaging in similar activities may be exempted from Chapter III if their activities are not commercial.
- Engagement records with the Article 13 DIS competent authority (notifications, inspections, corrective orders)
- DIS provider with no documented engagement with the Article 13 competent authority
DGA - Delegation, Committee, Penalties and Final (Ch VIII-IX)
Article 32 governs the exercise of the delegation of power to the Commission (Article 5 SPE specifications, Article 22 rulebook, Article 25 consent form). Article 33 sets the committee procedure.
- Tracking of Article 5 / Article 22 / Article 25 delegated acts adopted by the Commission
Article 34 requires Member States to lay down penalties applicable to infringements of the obligations on data transfer to third countries (Article 5(14), Article 31), on DIS providers (Articles 10-12) and on data altruism organisations (Articles 18, 20, 21). Penalties must be effective, proportionate and dissuasive. Article 34(3) sets non-exhaustive criteria for the level of penalty (nature, gravity, duration, deliberateness, financial benefit gained, previous infringements).
- Awareness of the applicable national-law penalty regime in each Member State
- Compliance program demonstrating proactive risk management against the Article 34 penalty regime
Article 35 requires the Commission to evaluate the Regulation by 24 September 2025. Article 36 amends Regulation (EU) 2018/1724 (Single Digital Gateway). Article 37 sets transitional arrangements: entities providing DIS prior to 24 September 2023 must comply with Articles 11-12 by 24 September 2025. Article 38 provides that the Regulation entered into force on the twentieth day following its publication in the OJ (23 June 2022) and applied from 24 September 2023.
- Compliance calendar reflecting 23 Jun 2022 entry into force, 24 Sep 2023 general application, 24 Sep 2025 DIS-transition deadline + evaluation
- Pre-2023 DIS provider missing the 24 Sep 2025 Article 12 compliance deadline
DGA - European Data Innovation Board and International (Ch VI-VII)
Article 29 establishes the European Data Innovation Board (EDIB) as a Commission expert group, composed of representatives of national competent authorities for DIS and for data altruism, the European Data Protection Board (EDPB), the Commission and stakeholder representatives. Article 30 lists EDIB's tasks: advise the Commission on cross-sector data interoperability, the deployment of European data spaces, the standards for Article 12 + Article 22 rulebooks, and on Data Governance Act + Data Act enforcement consistency.
- Records of any EDIB consultations, opinions or sub-group memberships involving the entity (industry sub-group, expert input)
Article 31 restricts public sector bodies, data intermediation service providers and recognised data altruism organisations from transferring or granting access to protected non-personal data held in the Union to third-country authorities / parties unless: (a) an international agreement (treaty / MLAT) is in place; (b) safeguards equivalent to those in Article 31(2) are in place; (c) the cumulative conditions of Article 31(3) are met (necessity, proportionality, specificity, judicial authorisation, narrow purpose). The competent authority reviews requests; customers must be informed.
- Internal procedure to receive and assess third-country requests for protected non-personal data
- Records of any refused or partly granted foreign-authority requests
- Customer / data-subject notification procedure
- Transfer of protected non-personal data to a third-country authority without an Article 31 safeguard
- No documented assessment of foreign requests
DGA - General Provisions (Ch I)
Article 1 sets the subject matter: rules on the re-use of certain categories of protected data held by public sector bodies (Chapter II); a notification and supervisory framework for data intermediation services (Chapter III); a voluntary registration framework for entities pursuing data altruism (Chapter IV); the European Data Innovation Board (Chapter VI); rules for international access and transfer (Chapter VII).
- Internal scope analysis identifying which DGA regime(s) apply to the entity (public sector body / DIS provider / data altruism organisation / data re-user / data subject)
- Treating DGA as data-protection legislation - it is governance-focused, distinct from the GDPR; the GDPR continues to apply to any personal-data processing in scope of DGA
Article 2 supplies the definitions used throughout the Regulation, including: 'data', 'data altruism' (sharing of data voluntarily for general-interest objectives such as public health, environment, scientific research), 'data altruism organisation', 'data intermediation services' (services aimed at establishing commercial relationships for the purposes of data sharing between data subjects and data holders, on one hand, and data users, on the other), 'public sector body', 're-use', 'data holder', 'data user', 'consent' (per the GDPR for personal data), 'permission' (for non-personal data).
- Definitions glossary mapping internal terminology to Article 2 (in particular distinguishing 'data intermediation services' under DGA from 'data processing services' under the Data Act)
- Confusing DIS (DGA) with data processing services / cloud (Data Act Chapter VI) - they are distinct regimes
DGA - Re-use of Protected Public Sector Data (Ch II)
Article 3 identifies the categories of data within scope of Chapter II: data held by public sector bodies that is protected on grounds of commercial confidentiality (incl. trade secrets), statistical confidentiality, IP rights of third parties or personal data, but is permitted to be re-used under conditions set in Chapter II. Article 4 prohibits exclusive re-use arrangements (no public sector body may grant a single re-user exclusive rights to such data) except in limited public-interest exceptions (max 12-month renewal limit; transparency).
- Public-sector-body inventory of data within Chapter II scope (where the entity is a PSB)
- Documentation of any exclusive re-use arrangement and its public-interest justification under Article 4
- Exclusive re-use arrangements not registered + justified per Article 4
- Public sector body refusing re-use without a Chapter II ground
Article 5 sets the conditions for re-use: non-discrimination, transparency, no distortion of competition, anonymisation / pseudonymisation / secure-processing-environment requirements for protected categories (in particular personal data). Article 5(9) requires that any re-use of personal data under the Article 5 conditions retains the GDPR as the governing personal-data regime. Article 6 governs fees: re-use is generally free or limited to cost recovery; transparent and non-discriminatory fee structures.
- Anonymisation or pseudonymisation procedures for personal data within Article 5 re-use
- Secure Processing Environment (SPE) controls for protected re-use
- Article 6 fee schedule (cost-based)
- Re-use of personal data without anonymisation / pseudonymisation and without an SPE
- Fees exceeding cost recovery without a public-interest justification
- Confusing Article 5(9) GDPR carve-out (the GDPR continues to apply for the personal-data dimension)
Article 7 requires Member States to designate competent bodies to assist public sector bodies in granting or refusing re-use (e.g., handling the Article 5 anonymisation, SPE provisioning, GDPR compatibility). Article 8 requires single information points (national + EU) listing re-usable Chapter II datasets. Article 9 sets the request procedure (two-month timeline; reasoned decision; appeal route).
- Identification of the relevant Article 7 competent body / Article 8 single information point in each Member State
- Re-use request handling SLA aligned with the Article 9 two-month timeline
- Re-use requests routed informally rather than through the Article 7 competent body / Article 8 single information point
- Re-use decisions without the Article 9 reasoned-decision content
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EU Data Governance Act (DGA) framework page.