Rules & hi-tech

Amid the promises of the Data Act and transatlantic uncertainties, the issue of data portability remains

The difficulties in implementing the new European regulations, which came into full effect in September, and the ruling that threatens the independence of the US Federal Trade Commission (FTC) are once again complicating the landscape of data and cloud services regulation on both sides of the Atlantic

 (Adobe Stock)

3' min read

Translated by AI
Versione italiana

3' min read

Translated by AI
Versione italiana

Data portability was supposed to be the major achievement of the European Data Act, the regulation designed to give businesses back control over the information generated by their connected devices and cloud services. But just a few months before the main provisions come into force, the picture is becoming more complicated: on the one hand, there are operational teething problems in applying the new rules; on the other, a US court ruling that risks undermining the entire framework for data transfers between the European Union and the United States.

The alarm has been raised once again by a decision of the US Supreme Court, which undermines the Federal Trade Commission’s autonomy vis-à-vis the President’s powers. The ruling, which limits the powers of the federal agency responsible for overseeing privacy and unfair commercial practices, could have direct repercussions on the Data Privacy Framework – the agreement that, from 2023, will allow the transfer of personal data from the EU to the US.

Loading...

That framework is, in fact, based on the premise that the US authorities provide adequate protection: if the FTC is weakened, the entire legal structure could collapse, reviving the situation we have already seen with the Schrems I and II judgements, which invalidated the previous Safe Harbour and Privacy Shield agreements.

It is against this backdrop of geopolitical uncertainty that the operational challenges posed by the Data Act arise; the Act came into force at the start of 2024, with its main provisions taking effect in September 2025.

The regulation introduces stringent obligations for manufacturers of connected devices and for cloud service providers: the former must make data generated through the use of their products accessible to users, whilst the latter must facilitate migration to alternative providers by removing the technical and contractual barriers that have hitherto fuelled vendor lock-in.

The timetable provides for a gradual transition. From September 2025, providers must comply with the transparency requirements and switching procedures. From January 2027, it will generally be prohibited to charge fees for switching providers or for data extraction, subject to limited exceptions based on actual costs.

The stated objective is ambitious: according to the European Commission, in 2020 only 8 per cent of SMEs were able to extract value from their data, hampered by proprietary formats, non-interoperable APIs and unfavourable contractual clauses.

The most acute tensions are being felt precisely in relations with US hyperscalers. The Data Act requires data to be provided in structured, commonly used and machine-readable formats, ensuring functional equivalence following migration. However, the lack of shared technical standards for formats and APIs, the complexity of ensuring continuity of cybersecurity during migration, and the emergence of new liability risks represent real obstacles to implementation. Without clear compliance mechanisms, the operational burden could fall disproportionately on smaller providers.

Another key issue concerns data sovereignty. Cloud service providers must implement appropriate technical and organisational measures to prevent non-EU governments from accessing data stored in Europe.

This provision reflects growing concerns about extraterritorial surveillance, but it clashes with the reality of global cloud infrastructures, where encryption keys, management tools and operational expertise often remain in the hands of US entities.

Loading...

On the contractual front, the Data Act prohibits companies from unilaterally imposing unfair terms in B2B relationships relating to access to and use of data. The Commission has drawn up non-binding contractual clauses to guide negotiations, but their practical application remains to be seen.

Producers may refuse to share data identified as trade secrets only in exceptional circumstances, where disclosure would result in serious economic harm despite the technical and organisational measures taken by the user.

For European businesses, the Data Act represents a real opportunity to reduce their dependence on large cloud providers and to capitalise on the data generated by their own production processes. However, the path from regulatory principles to practical implementation is proving to be a bumpy one.

Uncertainty over the future of transatlantic data transfers adds a further layer of complexity, forcing companies to consider data localisation strategies or turning to European providers to reduce their exposure to regulatory risks which, following Schrems I and II, are no longer merely theoretical.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti