Why

Data sovereignty

Data spaces

International standards

We

10 years of IDSA

Become a member

Members

Donate

Board

Head Office

IDSA ambassadors

Contact

Make

Working groups

Task forces

Hubs & competence centers

Open source

Projects

Communities

Offers

Reference Architecture

Dataspace Protocol

IDSA Rulebook

Certification

Data Space Connector Report

Use

Data Space User Group

Data Spaces Radar

Professional qualifications

Training catalog

Knowledge Base

Publications

Most important documents

Papers

Magazine

Legacy

Events

Upcoming events

Calendar

Archive

Event support

News

Blog

Newsroom

Infohub

Newsletter

Regulation

Regulation asks for a mechanism

The obligation is written in the law; the mechanism is not. Data spaces supply the missing part: governed access, purpose-bound usage policies, verified participants and a record of every exchange. This page maps the EU instruments on your critical path to the IDSA asset that answers each one. 

Five instruments on the critical path

Filter by status or obligation. Each card says what the law requires and which IDSA asset answers it.

Status
Obligation
Applies now

Data Act

Regulation (EU) 2023/2854

Users of connected products can require the data holder to share the data those products generate, with third parties of their choosing, on fair terms.

Where IDSA's assets fit

The Dataspace Protocol turns “fair terms” into negotiable contract offers and usage policies, so a request is answered by an agreement a Connector can enforce.

Applies since 12 September 2025.
Applies now

Data Governance Act

Regulation (EU) 2022/868 | repeal proposed

Data intermediation services must notify and meet conditions on transparency, neutrality and conflicts of interest.

Where IDSA's assets fit

The IDSA Rulebook gives governance its own role, the Data Space Governance Authority, separate from the data flow. That separation is the structural answer to the neutrality test.

Applies since September 2023; the Digital Omnibus would move it into the Data Act.
Phasing in

EU AI Act

Regulation (EU) 2024/1689

High-risk AI systems need governed, documented and representative training data, with bias detection and traceability across the data life cycle.

Where IDSA's assets fit

Data spaces supply the governance those rules assume: provenance, traceability, observable transactions and verified participant claims.

General application 2 August 2026; high-risk rules 2027–2028.
Policy frame

European strategy for data

Common European data spaces | DSSC

Not an obligation but the frame around them: a single market for data built on common European data spaces in strategic sectors.

Where IDSA's assets fit

Sectoral blueprints build on IDS-RAM and the IDSA Rulebook. The four layers of interoperability make the strategy measurable.

Set out in February 2020; delivered through sectoral data spaces.
Phasing in

Digital Product Passport

ESPR | product-specific delegated acts

Regulated products must carry a machine-readable record of composition, environmental performance, durability and end-of-life handling.

Where IDSA's assets fit

The data sits with suppliers who will not publish it openly. Usage policies and credential-based access let a manufacturer assemble a passport without exposing its supply chain.

Registry live since 20 July 2026; batteries from 18 February 2027.

Strategy became hard dates

Feb 2020

European strategy for data

The Commission calls for a single market for data, built on common European data spaces.

Sep 2023

Data Governance Act applicable

Notification and neutrality conditions apply to data intermediation services.

Aug 2024

EU AI Act enters into force

CEN/CENELEC is asked to standardize data governance and dataset quality for AI systems.

12 Sep 2025

Data Act applies

Access rights for connected-product data become live law.

19 Nov 2025

Digital Omnibus proposed

A proposal to consolidate the DGA and two other files into the Data Act.

Jul – Aug 2026

DPP Registry live | AI Act general application

The DPP Registry opens on 20 July; the AI Act reaches general application on 2 August.

18 Feb 2027

First mandatory product passports

Batteries first. Other product groups follow by delegated act.

Dec 2027 – Aug 2028

AI Act high-risk obligations

Data governance and quality requirements bite: Annex III systems in 2027, product-embedded in 2028.

Moving target

The Digital Omnibus, proposed on 19 November 2025, would fold the Data Governance Act into the Data Act and has already delayed the AI Act's high-risk rules. Dates here reflect the law as it stands; proposals are marked.

Every obligation needs a mechanism

The requirements that recur across these instruments, and the IDSA asset that specifies a mechanism for each: IDS-RAM for architecture, the IDSA Rulebook for governance, the Dataspace Protocol for the exchange itself.

Fair, purpose-bound access

Contract negotiation and usage policies | DSP

Data Act requests, passport data from suppliers, energy market roles.

Who am I dealing with

Attribute-based trust, claims and credentials | DCP

Verifiable participant attributes, no central member register.

Neutral governance

Data Space Governance Authority | Rulebook

Governance sits apart from the data flow — the structural answer to the DGA's neutrality test.

Data governance and quality

Provenance, traceability and observability | IDS-RAM

Evidence for AI Act requirements on training, validation and test data.

Cross-border, cross-sector

Four layers of interoperability

Technical, semantic, organizational and legal — the checklist a sectoral data space is designed against.

Prove it, don't claim it

Technical Compatibility Kit (TCK)

Conformance testing against the Dataspace Protocol, whatever you buy or build.

Where regulation lands in your data space

Manufacturing

Data Act | Digital Product Passport | AI Act

Machine data sits with the equipment maker, process data with the operator, material data with suppliers. Every obligation crosses a company boundary.

A machine user's access request is answered with a contract offer, not a data dump.

Passport data is pulled from the supplier that holds it, for that use only.

Training data for quality inspection keeps its provenance across the boundary.

Before you ask legal

Any questions? Contact us!

Silvia Castellvi

Your contact person:
Silvia Castellvi
Director Research & Standardization

Become am member

Benefit from all current developments: Become a member of the International Data Spaces Association now!