Free flow of non-personal data

08 ottobre 2018

New rules aimed at removing obstacles to the free movement of non-personal data within the EU for companies and public authorities were adopted by MEPs. Parliament approves EU’s fifth freedom 

 

This EU law, already provisionally agreed with the Council, will prohibit national rules requiring that data be stored or processed in a specific member state. Non-personal data includes, for instance, machine-generated data or commercial data. Specific examples are aggregated datasets used for big data analytics, data on precision farming that can help to monitor and optimise the use of pesticides and water, or data on maintenance needs for industrial machines. Restrictions on the location of data will only be allowed on grounds of public security, as defined in the Treaties and as interpreted by the EU Court of Justice. Any remaining data localisation requirements will have to be communicated to the European Commission and published online, in order to ensure compliance and transparency. Access to and porting of data The rules ensure that competent authorities will have access to data processed in another member state for regulatory control purposes, such as for inspection and audit. They also foresee the creation of codes of conduct by market players, to make it easier for professional users to switch cloud-service providers and transfer data back to their own IT systems. The Commission will monitor the development and the effective implementation of these codes of conduct within specific deadlines. Data sets composed of both personal and non-personal data In the case of data sets composed of both personal and non-personal data, the free flow regulation will apply to the non-personal data part of the set. Where personal and non-personal data are inextricably linked, this regulation shall not prejudice the application of the new EU data protection rules (GDPR), applicable since 25 May 2018. Thus, the two regulations do not overlap, but will complement each other.

This EU law, already provisionally agreed with the Council, will prohibit national rules requiring that data be stored or processed in a specific member state. Non-personal data includes, for instance, machine-generated data or commercial data. Specific examples are aggregated datasets used for big data analytics, data on precision farming that can help to monitor and optimise the use of pesticides and water, or data on maintenance needs for industrial machines. Restrictions on the location of data will only be allowed on grounds of public security, as defined in the Treaties and as interpreted by the EU Court of Justice. Any remaining data localisation requirements will have to be communicated to the European Commission and published online, in order to ensure compliance and transparency. Access to and porting of data The rules ensure that competent authorities will have access to data processed in another member state for regulatory control purposes, such as for inspection and audit. They also foresee the creation of codes of conduct by market players, to make it easier for professional users to switch cloud-service providers and transfer data back to their own IT systems. The Commission will monitor the development and the effective implementation of these codes of conduct within specific deadlines. Data sets composed of both personal and non-personal data In the case of data sets composed of both personal and non-personal data, the free flow regulation will apply to the non-personal data part of the set. Where personal and non-personal data are inextricably linked, this regulation shall not prejudice the application of the new EU data protection rules (GDPR), applicable since 25 May 2018. Thus, the two regulations do not overlap, but will complement each other.

Archivio news

 

News dello studio

dic23

23/12/2025

ll Garante privacy ha sanzionato Verisure Italia per trattamento illecito di dati personali ai fini di marketing.

  Il provvedimento nasce dal reclamo di un ex cliente, che aveva continuato a ricevere sms promozionali indesiderati, anche dopo essersi opposto al trattamento dei dati, e dalla segnalazione di

dic23

23/12/2025

Definizione della controversia tra Cellnex Italia SpA ed il Comune di Manfredonia (FG) per l’installazione di una rete di comunicazione elettronica ad alta velocità ai sensi del regolamento di cui alla delibera n. 449/16/CONS

Con la delibera n. 42/25/CIR viene definita la controversia tra Cellnex Italia SpA ed il Comune di Manfredonia per l’installazione di una rete di comunicazione elettronica ad alta velocità

dic23

23/12/2025

Delibera 277/25/CONS - Approvazione delle condizioni economiche dei nuovi servizi di accesso su fibra dedicata forniti nelle c.d. aree bianche (Listino "C&D) da Open Fiber S.p.A. beneficiario di aiuti di Stato

Con la delibera n. 277/25/CONS si approvano, ai sensi delle delibere n. 120/16/CONS e n. 171/25/CONS e sulla base dei criteri indicati negli Orientamenti della Commissione europea, nel rispetto di quanto

News Giuridiche

gen7

07/01/2026

La responsabilità dei marketplace online nel trattamento dei dati personali

La Corte di Giustizia UE stabilisce che

gen7

07/01/2026

Rappresentanza organica della società: a chi spetta l'onere della prova?

Quando il potere rappresentativo non deriva

gen7

07/01/2026

Messa alla prova: legittima l’esclusione del delitto di incendio boschivo colposo

<p>La <a href="https://onelegale.wolterskluwer.it/document/10SE0003095711"