A Dutch data intermediary received approval under the European Data Governance Act in July 2026. The decision puts data intermediation under ACM supervision. Companies arranging data exchanges must be able to show who controls the service, which contracts apply and how access is recorded.
Why this matters
Businesses often hold delivery, machine, customer or production data. That does not settle who may send a file to another party. A customer contract, supplier terms, software licence or data source may set the limit. Personal or commercially sensitive records can add duties. A registered intermediary must identify its legal entity, owners, group companies, contacts and service. The Data Governance Act covers that role. The Data Act separately covers connected-product and related-service data.
Example
A logistics company receives a request to send delivery records to a customer’s analyst. The technical team can make the connection, but the contract may limit reuse. Before sending anything, the company checks the customer contract, supplier terms and software licence. It records the dataset, recipient, purpose, approval and end date for access. A broad export setting does not override a restricted contract. The company needs to fix that gap before the records leave its system.
XTROVERSO tips
- Map every data route. List exchanges with customers, suppliers, group companies, platforms and analysts. Record the data holder, recipient and technical provider for each route.
- Check who may approve the transfer. Match every request to a contract, licence or other source of authority. Having a file does not itself permit sharing.
- Test any claim of neutrality. Check revenue terms, reuse rights and group access. The intermediary should not gain rights that conflict with its stated role.
- Keep one decision record. Keep the request, dataset, purpose, contract, approval, recipient and closing date in one file. Name the person responsible for changes and incidents.
- Keep the two EU rules separate. Review intermediary services under the Data Governance Act. Review data from connected products and related services separately under the Data Act.
Need help checking your data-sharing contracts, roles and records before the next request arrives?
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- Besluit databemiddelingsdienst onder de Data Governance Act Stichting Nederlandse Datakluis | ACM
- Autoriteit Consument & Markt - What counts as a data intermediation service
- Autoriteit Consument & Markt - Registration file, ownership visibility and supervisory contact
- Wettenbank - Dutch statutory allocation of supervision and sanctions
- Autoriteit Consument & Markt - Approval and refusal show that registration is a real supervisory gate
- Autoriteit Consument & Markt - Adjacent Data Act pressure on connected-product data and cloud arrangements
- Autoriteit Consument & Markt - Current ACM guidance on the Data Act
- Wettenbank


