Skip to content

Evidence request lists

EU Data Governance Act (DGA)

Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DGA - Competent Authorities (Ch V)

DGA-Art.26_27_28
Competent authority requirements, complaint and judicial remedy (Articles 26-28)

Article 26 sets the requirements for competent authorities (legal distinctness from operators, sufficient resources, technical expertise, independence). Article 27 grants natural and legal persons the right to lodge a complaint with the competent authority for breaches of the Regulation. Article 28 grants the right to an effective judicial remedy against binding decisions of competent authorities and against decisions of data intermediation service providers / data altruism organisations.

Artefacts an auditor will ask for
  • Identification of the competent authority for each Member State the entity operates in
  • Internal complaint-handling procedure
Where this commonly fails
  • No mechanism to receive Article 27 complaints

DGA - Data Altruism (Ch IV)

DGA-Art.16_17
Data altruism national arrangements and public registers (Articles 16-17)

Article 16 permits Member States to have in place organisational or technical arrangements to facilitate data altruism. Article 17 requires each Member State to maintain a public register of recognised data altruism organisations established in its territory, and the Commission to maintain an EU-wide register. Recognised status enables organisations to use the 'recognised data altruism organisation in the Union' label.

Artefacts an auditor will ask for
  • Application records for recognised data altruism organisation status where the entity seeks recognition
  • Reliance on the EU-wide register when partnering with a data altruism organisation
DGA-Art.18_19
Registration requirements and procedure (Articles 18-19)

Article 18 sets the substantive requirements for a recognised data altruism organisation: (a) legal entity established for general-interest objectives (public health, environment, scientific research, etc.); (b) operates on a not-for-profit basis (any surplus is reinvested); (c) carries out its data-altruism activities through a structure separate from other activities; (d) Article 21 transparency + safeguarding requirements are met. Article 19 sets the registration procedure with the competent authority designated under Article 23.

Artefacts an auditor will ask for
  • Constitutional / by-law evidence of general-interest objective + not-for-profit + structural separation
  • Application records under Article 19 procedure
Where this commonly fails
  • Mixing data-altruism activities with for-profit operations in the same legal person (Article 18(c) breach)
  • Recognised status without ongoing Article 21 transparency
DGA-Art.20_21
Transparency and safeguarding requirements (Articles 20-21)

Article 20 requires recognised data altruism organisations to record: (a) all data users using their data; (b) the dates / durations of use; (c) the purpose; (d) any fees paid by data users; (e) the data subjects / data holders' interests safeguarded. Article 21 imposes safeguarding requirements: clear information to data subjects/data holders, mechanisms for consent / permission withdrawal, appropriate technical + organisational measures to protect rights, no use of data for other purposes.

Artefacts an auditor will ask for
  • Article 20 record of all data uses (data user identity, dates, purpose, fees)
  • Article 21 information notice + withdrawal mechanism for data subjects + data holders
  • Annual transparency report
Where this commonly fails
  • Recognised data altruism organisation with no Article 20 record-keeping
  • No mechanism for withdrawal of consent / permission per Article 21
DGA-Art.22
Rulebook (Article 22)

Article 22 empowers the Commission to adopt delegated acts establishing a 'rulebook' setting common requirements for recognised data altruism organisations on information security, interoperability, communication strategies for data altruism, and recommended standards for data-altruism consent.

Artefacts an auditor will ask for
  • Adoption of the Article 22 rulebook standards where the entity is a recognised data altruism organisation
DGA-Art.23_24_25
Competent authority + monitoring + European Data Altruism Consent Form (Articles 23-25)

Article 23 requires each Member State to designate a competent authority for the registration and supervision of data altruism organisations. Article 24 sets the monitoring tasks. Article 25 requires the Commission to adopt, by way of implementing act, the European data altruism consent form, designed for data subjects to provide informed consent for data-altruism activities and to be modular by sector (health, mobility, environment, etc.).

Artefacts an auditor will ask for
  • Use of the European Data Altruism Consent Form where the entity collects data-altruism consent
  • Cooperation records with the Article 23 competent authority
Where this commonly fails
  • Bespoke consent text used instead of the European Data Altruism Consent Form where available

DGA - Data Intermediation Services (Ch III)

DGA-Art.10_11
Data intermediation services and notification (Articles 10-11)

Article 10 defines the scope of data intermediation services (DIS): (a) intermediation between data holders and data users on a commercial basis; (b) intermediation between data subjects exercising data-subject rights and potential data users; (c) services of data cooperatives. Article 11 imposes a notification regime: providers of DIS must notify the competent authority designated under Article 13 before commencing activities. Article 11 sets the content of the notification (provider identity, services description, governance structure) and provides for a confirmation of completeness within 1 week. DIS that has been notified may use the EU label.

Artefacts an auditor will ask for
  • Article 11 notification submission to the competent authority where the entity provides DIS
  • Records of confirmations and any subsequent updates
Where this commonly fails
  • Operating a data intermediation service without an Article 11 notification
  • Notification missing required content
DGA-Art.12
Conditions for providing data intermediation services (Article 12)

Article 12 sets the substantive operating conditions for DIS: (a) the DIS provider shall not use the data for purposes other than the intermediation; (b) the DIS provider shall not use derived insights from intermediated data for its own commercial gain; (c) the DIS provider shall provide its services through a separate legal person (structural separation from any other commercial activity); (d) the DIS provider must enable interoperability with other DIS; (e) ICT-security measures appropriate to the risks; (f) fair, transparent and non-discriminatory access; (g) procedures to prevent fraudulent or abusive practices.

Artefacts an auditor will ask for
  • Structural-separation evidence (legal person, governance, accounts) where the entity provides DIS
  • ICT-security baseline aligned with Article 12(e) (mapped to NIS2 Art.21(2) baseline measures)
  • Conflict-of-interest controls demonstrating no use of intermediated data for own commercial gain
Where this commonly fails
  • DIS bundled with other commercial activity in the same legal person
  • Use of intermediated data to feed the provider's own products (prohibited by Article 12(b))
  • DIS without an ICT-security baseline aligned with NIS2
DGA-Art.13_14_15
Competent authorities, monitoring and exceptions (Articles 13-15)

Article 13 requires each Member State to designate competent authorities for DIS. Article 14 sets the monitoring tasks of the competent authorities (compliance with Articles 10-12, on-site inspections, corrective orders). Article 15 specifies that recognised data altruism organisations or other non-profit entities engaging in similar activities may be exempted from Chapter III if their activities are not commercial.

Artefacts an auditor will ask for
  • Engagement records with the Article 13 DIS competent authority (notifications, inspections, corrective orders)
Where this commonly fails
  • DIS provider with no documented engagement with the Article 13 competent authority

DGA - Delegation, Committee, Penalties and Final (Ch VIII-IX)

DGA-Art.32_33
Delegation and committee procedure (Articles 32-33)

Article 32 governs the exercise of the delegation of power to the Commission (Article 5 SPE specifications, Article 22 rulebook, Article 25 consent form). Article 33 sets the committee procedure.

Artefacts an auditor will ask for
  • Tracking of Article 5 / Article 22 / Article 25 delegated acts adopted by the Commission
DGA-Art.34
Penalties (Article 34)

Article 34 requires Member States to lay down penalties applicable to infringements of the obligations on data transfer to third countries (Article 5(14), Article 31), on DIS providers (Articles 10-12) and on data altruism organisations (Articles 18, 20, 21). Penalties must be effective, proportionate and dissuasive. Article 34(3) sets non-exhaustive criteria for the level of penalty (nature, gravity, duration, deliberateness, financial benefit gained, previous infringements).

Artefacts an auditor will ask for
  • Awareness of the applicable national-law penalty regime in each Member State
  • Compliance program demonstrating proactive risk management against the Article 34 penalty regime
DGA-Art.35_36_37_38
Evaluation, amendment of (EU) 2018/1724, transitional arrangements and entry into force (Articles 35-38)

Article 35 requires the Commission to evaluate the Regulation by 24 September 2025. Article 36 amends Regulation (EU) 2018/1724 (Single Digital Gateway). Article 37 sets transitional arrangements: entities providing DIS prior to 24 September 2023 must comply with Articles 11-12 by 24 September 2025. Article 38 provides that the Regulation entered into force on the twentieth day following its publication in the OJ (23 June 2022) and applied from 24 September 2023.

Artefacts an auditor will ask for
  • Compliance calendar reflecting 23 Jun 2022 entry into force, 24 Sep 2023 general application, 24 Sep 2025 DIS-transition deadline + evaluation
Where this commonly fails
  • Pre-2023 DIS provider missing the 24 Sep 2025 Article 12 compliance deadline

DGA - European Data Innovation Board and International (Ch VI-VII)

DGA-Art.29_30
European Data Innovation Board (Articles 29-30)

Article 29 establishes the European Data Innovation Board (EDIB) as a Commission expert group, composed of representatives of national competent authorities for DIS and for data altruism, the European Data Protection Board (EDPB), the Commission and stakeholder representatives. Article 30 lists EDIB's tasks: advise the Commission on cross-sector data interoperability, the deployment of European data spaces, the standards for Article 12 + Article 22 rulebooks, and on Data Governance Act + Data Act enforcement consistency.

Artefacts an auditor will ask for
  • Records of any EDIB consultations, opinions or sub-group memberships involving the entity (industry sub-group, expert input)
DGA-Art.31
International access and transfer (Article 31)

Article 31 restricts public sector bodies, data intermediation service providers and recognised data altruism organisations from transferring or granting access to protected non-personal data held in the Union to third-country authorities / parties unless: (a) an international agreement (treaty / MLAT) is in place; (b) safeguards equivalent to those in Article 31(2) are in place; (c) the cumulative conditions of Article 31(3) are met (necessity, proportionality, specificity, judicial authorisation, narrow purpose). The competent authority reviews requests; customers must be informed.

Artefacts an auditor will ask for
  • Internal procedure to receive and assess third-country requests for protected non-personal data
  • Records of any refused or partly granted foreign-authority requests
  • Customer / data-subject notification procedure
Where this commonly fails
  • Transfer of protected non-personal data to a third-country authority without an Article 31 safeguard
  • No documented assessment of foreign requests

DGA - General Provisions (Ch I)

DGA-Art.1
Subject matter and scope (Article 1)

Article 1 sets the subject matter: rules on the re-use of certain categories of protected data held by public sector bodies (Chapter II); a notification and supervisory framework for data intermediation services (Chapter III); a voluntary registration framework for entities pursuing data altruism (Chapter IV); the European Data Innovation Board (Chapter VI); rules for international access and transfer (Chapter VII).

Artefacts an auditor will ask for
  • Internal scope analysis identifying which DGA regime(s) apply to the entity (public sector body / DIS provider / data altruism organisation / data re-user / data subject)
Where this commonly fails
  • Treating DGA as data-protection legislation - it is governance-focused, distinct from the GDPR; the GDPR continues to apply to any personal-data processing in scope of DGA
DGA-Art.2
Definitions (Article 2)

Article 2 supplies the definitions used throughout the Regulation, including: 'data', 'data altruism' (sharing of data voluntarily for general-interest objectives such as public health, environment, scientific research), 'data altruism organisation', 'data intermediation services' (services aimed at establishing commercial relationships for the purposes of data sharing between data subjects and data holders, on one hand, and data users, on the other), 'public sector body', 're-use', 'data holder', 'data user', 'consent' (per the GDPR for personal data), 'permission' (for non-personal data).

Artefacts an auditor will ask for
  • Definitions glossary mapping internal terminology to Article 2 (in particular distinguishing 'data intermediation services' under DGA from 'data processing services' under the Data Act)
Where this commonly fails
  • Confusing DIS (DGA) with data processing services / cloud (Data Act Chapter VI) - they are distinct regimes

DGA - Re-use of Protected Public Sector Data (Ch II)

DGA-Art.3_4
Categories of public-sector data and prohibition of exclusive arrangements (Articles 3-4)

Article 3 identifies the categories of data within scope of Chapter II: data held by public sector bodies that is protected on grounds of commercial confidentiality (incl. trade secrets), statistical confidentiality, IP rights of third parties or personal data, but is permitted to be re-used under conditions set in Chapter II. Article 4 prohibits exclusive re-use arrangements (no public sector body may grant a single re-user exclusive rights to such data) except in limited public-interest exceptions (max 12-month renewal limit; transparency).

Artefacts an auditor will ask for
  • Public-sector-body inventory of data within Chapter II scope (where the entity is a PSB)
  • Documentation of any exclusive re-use arrangement and its public-interest justification under Article 4
Where this commonly fails
  • Exclusive re-use arrangements not registered + justified per Article 4
  • Public sector body refusing re-use without a Chapter II ground
DGA-Art.5_6
Conditions for re-use and fees (Articles 5-6)

Article 5 sets the conditions for re-use: non-discrimination, transparency, no distortion of competition, anonymisation / pseudonymisation / secure-processing-environment requirements for protected categories (in particular personal data). Article 5(9) requires that any re-use of personal data under the Article 5 conditions retains the GDPR as the governing personal-data regime. Article 6 governs fees: re-use is generally free or limited to cost recovery; transparent and non-discriminatory fee structures.

Artefacts an auditor will ask for
  • Anonymisation or pseudonymisation procedures for personal data within Article 5 re-use
  • Secure Processing Environment (SPE) controls for protected re-use
  • Article 6 fee schedule (cost-based)
Where this commonly fails
  • Re-use of personal data without anonymisation / pseudonymisation and without an SPE
  • Fees exceeding cost recovery without a public-interest justification
  • Confusing Article 5(9) GDPR carve-out (the GDPR continues to apply for the personal-data dimension)
DGA-Art.7_8_9
Competent bodies, single information points and re-use request procedure (Articles 7-9)

Article 7 requires Member States to designate competent bodies to assist public sector bodies in granting or refusing re-use (e.g., handling the Article 5 anonymisation, SPE provisioning, GDPR compatibility). Article 8 requires single information points (national + EU) listing re-usable Chapter II datasets. Article 9 sets the request procedure (two-month timeline; reasoned decision; appeal route).

Artefacts an auditor will ask for
  • Identification of the relevant Article 7 competent body / Article 8 single information point in each Member State
  • Re-use request handling SLA aligned with the Article 9 two-month timeline
Where this commonly fails
  • Re-use requests routed informally rather than through the Article 7 competent body / Article 8 single information point
  • Re-use decisions without the Article 9 reasoned-decision content
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EU Data Governance Act (DGA) framework page.