Regulation
Regulation asks for a mechanism
The obligation is written in the law; the mechanism is not. Data spaces supply the missing part: governed access, purpose-bound usage policies, verified participants and a record of every exchange. This page maps the EU instruments on your critical path to the IDSA asset that answers each one.
Five instruments on the critical path
Filter by status or obligation. Each card says what the law requires and which IDSA asset answers it.
Data Act
Regulation (EU) 2023/2854Users of connected products can require the data holder to share the data those products generate, with third parties of their choosing, on fair terms.
The Dataspace Protocol turns “fair terms” into negotiable contract offers and usage policies, so a request is answered by an agreement a Connector can enforce.
Applies since 12 September 2025.Data Governance Act
Regulation (EU) 2022/868 | repeal proposedData intermediation services must notify and meet conditions on transparency, neutrality and conflicts of interest.
The IDSA Rulebook gives governance its own role, the Data Space Governance Authority, separate from the data flow. That separation is the structural answer to the neutrality test.
Applies since September 2023; the Digital Omnibus would move it into the Data Act.EU AI Act
Regulation (EU) 2024/1689High-risk AI systems need governed, documented and representative training data, with bias detection and traceability across the data life cycle.
Data spaces supply the governance those rules assume: provenance, traceability, observable transactions and verified participant claims.
General application 2 August 2026; high-risk rules 2027–2028.European strategy for data
Common European data spaces | DSSCNot an obligation but the frame around them: a single market for data built on common European data spaces in strategic sectors.
Sectoral blueprints build on IDS-RAM and the IDSA Rulebook. The four layers of interoperability make the strategy measurable.
Set out in February 2020; delivered through sectoral data spaces.Digital Product Passport
ESPR | product-specific delegated actsRegulated products must carry a machine-readable record of composition, environmental performance, durability and end-of-life handling.
The data sits with suppliers who will not publish it openly. Usage policies and credential-based access let a manufacturer assemble a passport without exposing its supply chain.
Registry live since 20 July 2026; batteries from 18 February 2027.Strategy became hard dates
European strategy for data
The Commission calls for a single market for data, built on common European data spaces.
Data Governance Act applicable
Notification and neutrality conditions apply to data intermediation services.
EU AI Act enters into force
CEN/CENELEC is asked to standardize data governance and dataset quality for AI systems.
Data Act applies
Access rights for connected-product data become live law.
Digital Omnibus proposed
A proposal to consolidate the DGA and two other files into the Data Act.
DPP Registry live | AI Act general application
The DPP Registry opens on 20 July; the AI Act reaches general application on 2 August.
First mandatory product passports
Batteries first. Other product groups follow by delegated act.
AI Act high-risk obligations
Data governance and quality requirements bite: Annex III systems in 2027, product-embedded in 2028.
The Digital Omnibus, proposed on 19 November 2025, would fold the Data Governance Act into the Data Act and has already delayed the AI Act's high-risk rules. Dates here reflect the law as it stands; proposals are marked.
Every obligation needs a mechanism
The requirements that recur across these instruments, and the IDSA asset that specifies a mechanism for each: IDS-RAM for architecture, the IDSA Rulebook for governance, the Dataspace Protocol for the exchange itself.
Contract negotiation and usage policies | DSP
Data Act requests, passport data from suppliers, energy market roles.
Attribute-based trust, claims and credentials | DCP
Verifiable participant attributes, no central member register.
Data Space Governance Authority | Rulebook
Governance sits apart from the data flow — the structural answer to the DGA's neutrality test.
Provenance, traceability and observability | IDS-RAM
Evidence for AI Act requirements on training, validation and test data.
Four layers of interoperability
Technical, semantic, organizational and legal — the checklist a sectoral data space is designed against.
Technical Compatibility Kit (TCK)
Conformance testing against the Dataspace Protocol, whatever you buy or build.
Where regulation lands in your data space
Manufacturing
Data Act | Digital Product Passport | AI ActMachine data sits with the equipment maker, process data with the operator, material data with suppliers. Every obligation crosses a company boundary.
A machine user's access request is answered with a contract offer, not a data dump.
Passport data is pulled from the supplier that holds it, for that use only.
Training data for quality inspection keeps its provenance across the boundary.
The analysis behind this page
Written by IDSA members and bodies, free to download. Members shape the next versions.
IDSA Rulebook
Governance, roles and trust requirements for a data space.
Data spaces for the AI Act
What the CEN/CENELEC standardization request asks of data governance.
Reflections on the DGA and data intermediaries
When a data space counts as a data intermediation service.
Standardisation landscape
Who standardizes what, in Europe and internationally.
Data spaces landscape
How the initiatives, blueprints and reference artefacts fit together.
Data spaces and AI
How AI agents can participate in a data space and stay trustworthy.
Before you ask legal
No. Compliance is a legal assessment of your organization. A data space gives you the mechanism these obligations assume you have: governed access, usage policies, verifiable claims and a transaction record. Nothing here is legal advice.
Sometimes. IDSA's impulse paper finds the definition broad enough to need a case-by-case assessment, turning on whether the data space is a closed contractual group or open to all comers. Guidance is still missing.
The IDSA Rulebook for governance, IDS-RAM for architecture, the Dataspace Protocol for the exchange itself. That order to get oriented, the reverse to implement.
No. IDSA is technology-agnostic: open-source and commercial Connectors both exist, and conformance is checked with the Technical Compatibility Kit. The standard is the commitment, the product stays your choice.
The obligations survive the renumbering. Architecture built on governed access and verifiable claims does not care which article a requirement sits in.
Any questions? Contact us!

Your contact person:
Silvia Castellvi
Director Research & Standardization
Become am member
Benefit from all current developments: Become a member of the International Data Spaces Association now!









