Products
© Fiskil 2026. All rights reserved.
GDPR protects privacy. The Data Act opens the data economy. Both apply to personal data—and you must comply with both.
GDPR: Personal data only. Data Act: Personal AND non-personal data.
GDPR: Privacy rights. Data Act: Economic access rights.
Where they overlap: Mixed datasets (e.g., vehicle telemetry, IoT sensors).
In the event of conflict, GDPR prevails. But conflicts are rare—most obligations coexist, creating dual compliance requirements.
Regulatory Context
Article 1(5) Data Act: "Without prejudice to GDPR" - GDPR prevails in conflicts
GDPR applies to personal data processing
Data Act applies to both personal and non-personal data generated by connected products
Where datasets contain both: Both regulations apply simultaneously
Data Act access rights go beyond GDPR: real-time access, non-personal data, third-party sharing
GDPR legal basis still required for personal data processing under Data Act
Implementation
Challenges
Mixed datasets: Vehicle telemetry, smart home sensors, industrial IoT contain both personal and non-personal data
Separating data types: Difficult to isolate personal data from non-personal data in real-time streams
Dual information obligations: Article 3 Data Act + Articles 13-14 GDPR have overlapping disclosure requirements
Different access scopes: GDPR provides snapshot; Data Act may require continuous real-time access
Trade secret protection: Allowed under Data Act, no equivalent exemption under GDPR
Misclassification risk: Unlawful denial under Data Act vs. unlawful disclosure under GDPR
How Fiskil Helps
Dual-Compliant Architecture
Single API infrastructure serves both GDPR Article 15 requests (personal data snapshot) and Data Act Article 4-5 obligations (real-time access, JSON format). Consent management ensures proper authorization for both frameworks.
Data Classification
Structured approach to identifying personal vs. non-personal data in mixed datasets. Apply appropriate regulatory framework to each data element.
Information Disclosures
Pre-contractual disclosures satisfy both Article 3 Data Act and Articles 13-14 GDPR requirements through comprehensive documentation.
Legal Basis Tracking
Platform manages GDPR legal basis requirements (consent, legitimate interest) for personal data shared under Data Act obligations through recipient onboarding workflows.
Trust & Proof
GDPR compliance certified (SOC 2 Type II)
Data protection by design and by default
Built with DPA guidance on Data Act + GDPR interplay
Dual-regulation audit trail
Handles mixed personal/non-personal datasets at scale
Real-time data classification (millions of data points/second)
Deployed across GDPR-regulated industries
Proven dual-compliance architecture
Talk to our team about your EU Data Act compliance needs.