Products
© Fiskil 2026. All rights reserved.
GDPR protects privacy. The Data Act opens the data economy. Both apply to personal data—and you must comply with both.
GDPR: Personal data only. Data Act: Personal AND non-personal data.
GDPR: Privacy rights. Data Act: Economic access rights.
Where they overlap: Mixed datasets (e.g., vehicle telemetry, IoT sensors).
In the event of conflict, GDPR prevails. But conflicts are rare—most obligations coexist, creating dual compliance requirements.
Regulatory Context
Key Obligations
Article 1(5) Data Act: "Without prejudice to GDPR" - GDPR prevails in conflicts
GDPR applies to personal data processing
Data Act applies to both personal and non-personal data generated by connected products
Where datasets contain both: Both regulations apply simultaneously
Data Act access rights go beyond GDPR: real-time access, non-personal data, third-party sharing
GDPR legal basis still required for personal data processing under Data Act
Implementation Reality
Challenges
Mixed datasets: Vehicle telemetry, smart home sensors, industrial IoT contain both personal and non-personal data
Separating data types: Difficult to isolate personal data from non-personal data in real-time streams
Dual information obligations: Article 3 Data Act + Articles 13-14 GDPR have overlapping disclosure requirements
Different access scopes: GDPR provides snapshot; Data Act may require continuous real-time access
Trade secret protection: Allowed under Data Act, no equivalent exemption under GDPR
Misclassification risk: Unlawful denial under Data Act vs. unlawful disclosure under GDPR
Solution
Dual-Compliant Architecture
Single API infrastructure serves both GDPR Article 15 requests (personal data snapshot) and Data Act Article 4-5 obligations (real-time access, JSON format). Consent management ensures proper authorization for both frameworks.
Data Classification
Structured approach to identifying personal vs. non-personal data in mixed datasets. Apply appropriate regulatory framework to each data element.
Information Disclosures
Pre-contractual disclosures satisfy both Article 3 Data Act and Articles 13-14 GDPR requirements through comprehensive documentation.
Legal Basis Tracking
Platform manages GDPR legal basis requirements (consent, legitimate interest) for personal data shared under Data Act obligations through recipient onboarding workflows.
Trust & Proof
GDPR compliance certified (SOC 2 Type II)
Data protection by design and by default
Built with DPA guidance on Data Act + GDPR interplay
Dual-regulation audit trail
Handles mixed personal/non-personal datasets at scale
Real-time data classification (millions of data points/second)
Deployed across GDPR-regulated industries
Proven dual-compliance architecture
Talk to our team about your EU Data Act compliance needs.