Home | Blog |

29. July 2026

Data Spaces and the Data Governance Act: Opportunities for Businesses (Interoperability and Governance)

Kategorien:

With the Data Governance Act (DGA) and the planned Common European Data Spaces, the European Union is establishing a framework that enables data to be shared securely, interoperably, and in a trustworthy manner. This serves as a catalyst for innovation, new business models, and improved access to capital—particularly for start-ups and venture capital-backed companies.

Alongside the Data Act, the DGA is a key pillar of the European Data Strategy. Its objective is to promote the trustworthy exchange of data and to establish harmonised rules across the EU for data spaces, data intermediation services, and data altruism. An important role is also played by the European GAIA-X initiative, which seeks to enable secure and sovereign data sharing between organisations through common standards and a federated data infrastructure. However, GAIA-X is not a statutory requirement under the DGA; rather, it is an independent European initiative that primarily supports the technical implementation of interoperable data spaces.

Businesses that adopt clear governance structures, standardised interfaces, and fair rules for data use at an early stage can gain a sustainable competitive advantage while simultaneously increasing their attractiveness to investors.

Scope of Application

The DGA primarily applies to public sector bodies, data intermediation service providers, and data altruism organisations. In addition, businesses, research institutions, and other market participants benefit indirectly from the framework established by the DGA for secure and trustworthy data sharing.
Importantly, the DGA does not create a general statutory right of access to data. Instead, it establishes the legal and organisational conditions necessary to facilitate the voluntary sharing and reuse of data.

What Does the Data Governance Act Regulate?

The Data Governance Act is an EU Regulation that has applied since September 2023, establishing a harmonised legal framework for data sharing across the European Single Market.

The Regulation provides a uniform legal framework throughout the European Union and focuses in particular on:

  • the re-use of certain categories of protected public sector data;
  • the registration and supervision of data intermediation services; and
  • the promotion of recognised data altruism organisations.

Accordingly, the DGA contains specific rules for public sector bodies, data intermediation service providers, and data altruism organisations.

At the same time, the DGA complements other elements of the European Data Strategy, including the Data Act and the development of sector-specific data spaces, such as those for healthcare, industry, and mobility. These data spaces are intended to be built on common technical and organisational standards. Initiatives such as GAIA-X support this objective by providing interoperable reference architectures and trust mechanisms for secure data exchange.

Data Governance Act vs. Data Act

While the Data Governance Act establishes the legal and organisational framework for the voluntary sharing of data, the Data Act primarily regulates access to and use of certain categories of data, particularly data generated by connected products and related services.
The two legislative acts complement one another and pursue the common objective of fostering a well-functioning European data economy. Businesses should therefore assess on a case-by-case basis which regulatory framework applies, as the DGA and the Data Act govern different subject matters while operating in a complementary manner.

What Are Data Spaces and Why Are They Important?

Common European Data Spaces are sector-specific or thematic environments in which businesses, public sector bodies, and research institutions can exchange and use data in accordance with shared rules and common technical standards. Their purpose is to make data from across the European Union available in a trustworthy manner while ensuring that data holders—both businesses and individuals—retain control over their data.

A defining feature of data spaces is that data generally remains with the respective data holder rather than being stored in a central repository. Instead, data is exchanged on the basis of common technical, organisational, and legal standards. This enables businesses to maintain control over their data and determine the conditions under which it may be accessed and used.

Examples include the Mobility Data Space, data spaces for Industry and the European Green Deal, as well as cloud and research data infrastructures designed to interoperate with one another. GAIA-X contributes to this objective by enabling these different data spaces to communicate through common European standards, allowing businesses to share their data in a secure and sovereign manner.
For start-ups, this opens access to valuable datasets that were previously available primarily to large digital platforms, including industrial sensor data, mobility data, and health data within strictly regulated yet usable environments.

Interoperability: The Technical Foundation for Scalable Business Models

Interoperability means that data, interfaces, and services of different organisations can work together both technically and semantically, enabling their use across organisational and national boundaries.

To achieve this, the DGA promotes the development of common standards, reference architectures, and the work of the European Data Innovation Board (EDIB), which is tasked, among other things, with prioritising cross-sector interoperability standards.
Interoperability is a key prerequisite for effective European data spaces, as it enables secure and standardised data exchange between different companies, platforms, and EU Member States. Likewise, GAIA-X aims to establish common standards for data exchange and improve interoperability between cloud services, platforms, and data services.

For businesses, this means that organisations which adapt their systems early to open interfaces and interoperable data models will find it easier to integrate their services into data spaces and expand into new markets. Venture capital-backed start-ups, in particular, benefit from scalable platform-based business models that allow products and services to be deployed rapidly across multiple data spaces, industries, and countries.

Opportunities for Businesses, Start-ups, and Venture Capital

The DGA establishes the legal framework for secure and trustworthy data sharing. As a result, businesses can benefit from significant commercial opportunities, particularly through improved access to high-quality datasets and the development of data-driven business models.

The framework created by the DGA and European data spaces facilitates the secure exchange of valuable data across organisational and sectoral boundaries, laying the foundation for data-driven innovation and the deployment of artificial intelligence (AI).

Furthermore, standardised access to data enables businesses to reduce transaction costs, simplify collaboration, and scale data-driven business models more efficiently.

Start-ups and venture capital-backed growth companies, in particular, can realise measurable competitive advantages if they view data governance not merely as a compliance obligation but as a strategic business enabler.

The Data Governance Act and Venture Capital: What Start-ups Should Consider

Structured data governance is becoming increasingly important in venture capital transactions. As part of legal and commercial due diligence, investors are placing greater emphasis on whether data usage rights, governance structures, and regulatory compliance requirements are properly documented and implemented.

Key considerations include:

Clear Allocation and Exploitation of Data Rights

Investment agreements should clearly specify ownership of data, identify which parties are entitled to contribute data to data spaces, and define the data usage rights that investors will acquire in the event of an exit.

Compliance Provisions Relating to the DGA, the Data Act, and the GDPR

Investors increasingly expect robust representations and warranties confirming that the company’s data practices comply with the Data Governance Act (DGA), the Data Act, and applicable data protection laws, in particular the General Data Protection Regulation (GDPR). Non-compliance may trigger contractual warranty or indemnification claims and—where agreed—may affect valuation mechanisms, indemnities, or other contractual risk allocation provisions.

Governance Structures as a Value Driver

Well-documented governance processes not only enhance legal certainty but are increasingly regarded as an indicator of quality in venture capital term sheets, influencing company valuation and strengthening a company’s negotiating position.

Practical Implementation Steps for Businesses

To take advantage of the opportunities offered by data spaces and the DGA, businesses should adopt a structured approach and gradually integrate data governance into their organisations. A pragmatic implementation strategy helps ensure compliance while simultaneously unlocking commercial potential. Companies should not view the establishment of a data governance framework solely as a compliance exercise. Rather, early organisational and technical preparation creates the foundation for future participation in European data spaces and for the development of innovative data-driven business models.

Recommended steps include:

1. Conduct a Data Inventory and Define Use Cases

Identify the data already available within the organisation, determine which external datasets are required, and define concrete use cases, such as data-driven services or AI applications.

2. Establish Governance Roles and Processes

Assign responsibilities, define access and approval procedures, and document the rules governing participation in data spaces and the use of data intermediation services.

3. Build an Interoperable Technical Architecture

Implement standardised interfaces, common data models, and recognised security standards to ensure that your systems are compatible with European data spaces.

4. Review and Update Contractual Documentation

Review and update investment agreements, cooperation agreements, and, where applicable, convertible loan agreements to ensure that data usage rights, liability provisions, and compliance obligations are appropriately addressed.

Conclusion and Outlook

With the Data Governance Act, the European Union has established the legal and organisational foundations for a trustworthy European data economy. While the Data Act regulates access to specific categories of data, the DGA creates the conditions necessary for the voluntary sharing and reuse of data within secure data spaces.
Businesses should therefore establish governance structures at an early stage, clearly define data usage rights, and design their technical systems to ensure interoperability. A structured approach to data governance not only enhances legal certainty but also strengthens innovation.

Our Recommendations

  • Assess which data assets are suitable for use within European data spaces.
  • Establish clear data governance structures and assign responsibilities.
  • Review existing contractual documentation to ensure that data usage rights and compliance obligations are adequately addressed.
  • Implement interoperable technical interfaces and recognised security standards to facilitate participation in European data spaces.
  • Monitor the ongoing development of European data spaces and sector-specific standards to identify new business opportunities and regulatory developments at an early stage.

We would be pleased to assist you in leveraging the opportunities offered by the Data Governance Act and European data spaces while ensuring full legal compliance.

Contact us to discuss how our experts can support your business—from developing a legally compliant data governance strategy and drafting data sharing and cooperation agreements to preparing your organisation for participation in European data spaces and compliance with the European Data Strategy.



Frequently Asked Questions about Data Spaces and the Data Governance Act

What is the Data Governance Act (DGA)?

The Data Governance Act (DGA) is an EU Regulation that has applied since September 2023. It establishes the legal framework for the sharing and re-use of data within the European Single Market, particularly through rules governing data intermediation services, data altruism, and the re-use of certain categories of protected public sector data.

What are European data spaces?

European data spaces are sector-specific or thematic ecosystems in which data from different sources can be securely shared and used in accordance with common technical, organisational, and legal standards. Examples include data spaces for industry, mobility, healthcare, energy, and research.

Why is data governance important in venture capital transactions?

A well-structured data governance framework—with clearly defined data usage rights, compliance processes, and contractual safeguards—reduces legal and commercial risks while increasing a company’s attractiveness to venture capital investors. Robust governance can also positively influence investment documentation, including investment agreements, convertible loan agreements, and liquidation preference structures.

Why are data spaces important for businesses?

Data spaces enable businesses to gain access to valuable datasets, foster innovation, and develop new data-driven products and services. Through common standards, businesses can collaborate more efficiently with partners and scale their business models across industries and national borders.

What role does interoperability play?

Interoperability ensures that different IT systems, data formats, and applications can work together seamlessly. Common standards facilitate secure data exchange and allow businesses to participate efficiently in data spaces without developing bespoke interfaces for every individual collaboration.

What is GAIA-X?

GAIA-X is a European initiative aimed at developing a secure, interoperable, and sovereign data infrastructure. Its objective is to establish common standards and trust mechanisms for data exchange, thereby supporting the development of European data spaces. GAIA-X complements the European Data Strategy by facilitating the technical implementation of interoperable data ecosystems.

How does the Data Governance Act differ from the Data Act?

The Data Governance Act establishes the legal and organisational framework for the voluntary sharing and re-use of data and regulates data intermediation services. By contrast, the Data Act primarily governs access to and the use of data, particularly data generated by connected products and related services. The two legislative acts complement one another and together form essential components of the European Data Strategy.

What opportunities do European data spaces create for start-ups and investors?

European data spaces enable start-ups to gain easier access to high-quality datasets, fostering the development of innovative data-driven business models. At the same time, structured data governance, transparent data usage rights, and regulatory compliance increase legal certainty and enhance a company’s attractiveness to investors during financing rounds.

How can businesses prepare for participation in European data spaces?

Businesses should begin by assessing their existing data assets, identifying suitable use cases, and establishing clear data governance structures. They should also implement interoperable IT architectures, standardised interfaces, and clearly defined rules governing data usage rights to facilitate participation in European data spaces.

Questions?

We look forward to hearing from you regarding this and other matters!

Get in touch

More Posts

EviGate

Complete E-Evidence Solution by Rickert.Law and EviGate

Following several years of preparation, Rickert Rechtsanwaltsgesellschaft mbH and nGENn GmbH have launched a joint venture: EviGate GmbH (currently in ... Read more
What is a Legal Representative and who needs one?

EU-E-Evidence: What is a Legal Representative and who needs one?

This is the first post in our series on the EU e-evidence framework, written for the service providers who actually ... Read more
Post Preview: Why you need a designated establishment as an EU service provider

E-Evidence: Based in the EU? Why You Get a Designated Establishment, Not a Legal Representative

This time in our plain English series on the EU e-Evidence framework: What EU-based service providers must do and why ... Read more