Last updated: 11 September 2026
The EU Data Act creates new access and data-sharing rights around connected products. That immediately raises one of the most difficult implementation questions for manufacturers:
What happens when the requested product data contain trade secrets?
The answer is not:
Trade secrets are exempt from the Data Act.
It is also not:
The data holder must disclose everything regardless of confidentiality.
Articles 4 and 5 create a structured safeguard process. Trade secrets should be preserved, identified and protected through proportionate technical and organizational measures. Specific trade-secret data can be withheld or sharing suspended when agreed safeguards are not in place or confidentiality is undermined. In exceptional circumstances, specific data can be refused case by case where the trade-secret holder can demonstrate a high likelihood of serious economic damage despite safeguards.
This guide explains that sequence in operational terms for:
- data holders;
- connected-product manufacturers;
- trade-secret holders;
- users;
- third-party data recipients.
Important: Trade-secret assessments are fact-specific. This guide is informational and does not replace legal advice on Directive (EU) 2016/943, the Data Act or national trade-secret law.
Quick answer: can trade secrets be withheld under the EU Data Act?
Sometimes — but not automatically.
For Article 4 user access and Article 5 third-party sharing, the current Data Act generally requires a staged approach:
- identify the data protected as trade secrets;
- preserve confidentiality;
- agree necessary technical and organizational safeguards before disclosure;
- where safeguards are not agreed/implemented, or confidentiality is undermined, withhold or suspend sharing of the specific trade-secret data under the regulation's conditions;
- in exceptional cases, refuse specific data case by case where the trade-secret holder can objectively demonstrate a high likelihood of serious economic damage despite safeguards;
- give written substantiation and notify the competent authority where required;
- preserve the user's/third party's redress rights.
Primary source:
Regulation (EU) 2023/2854 — Articles 4 and 5
What counts as a “trade secret”?
The Data Act imports the trade-secret concept from Directive (EU) 2016/943.
Article 2 of that Directive defines a trade secret as information that meets all three conditions:
- secret — not generally known or readily accessible among people who normally deal with that type of information;
- commercial value because it is secret;
- subject to reasonable steps to keep it secret by the person lawfully controlling it.
Official source:
Directive (EU) 2016/943 — Trade Secrets Directive
This matters because not every confidential-looking field is legally a trade secret.
Potential examples in connected products
Depending on the facts:
- proprietary calibration parameters;
- detailed control algorithms embodied in retrievable data;
- manufacturing/process parameters;
- confidential diagnostic logic;
- unique device-performance models;
- proprietary engineering mappings;
- commercially sensitive tuning information.
Not automatically a trade secret
- every telemetry field;
- every error code;
- all machine data;
- data that are already public;
- trivial information;
- information not subject to reasonable secrecy measures.
A blanket label:
all data are trade secrets
is weak governance and may be difficult to defend.
Trade-secret holder vs data holder
For more on the data-holder role, see the Data Holder Obligations Guide.
These roles can be different.
Data holder
The party with the Data Act/legal right or obligation to use/make relevant data available.
Trade-secret holder
The person/entity lawfully controlling the trade secret under Directive 2016/943.
Examples:
- product manufacturer is both data holder and trade-secret holder;
- platform provider is data holder while component manufacturer owns the trade secret;
- manufacturer holds product data while a supplier controls secret calibration information embedded in the dataset.
Article 3(3) even requires related-service pre-contractual information about whether the prospective data holder is the trade-secret holder and, if not, the identity of the trade-secret holder.
Operationally, access workflows should therefore have an escalation path to the actual trade-secret owner.
Article 4: trade secrets when sharing with the user
For the request workflow alongside these safeguards, see the Article 4 Data Access Request Template.
Article 4(6) says trade secrets must be preserved and disclosed only where the data holder and user take necessary measures before disclosure to preserve confidentiality, particularly regarding third parties.
The data holder or trade-secret holder should identify:
- which data are protected as trade secrets;
- including identification in relevant metadata where appropriate;
- the necessary technical and organizational safeguards.
Examples of safeguards
Depending on proportionality and risk:
- confidentiality agreement;
- restricted user accounts;
- encrypted transfer;
- access-control lists;
- purpose limitation;
- prohibition on onward disclosure;
- secure environment/data room;
- monitoring/audit commitments;
- deletion/retention controls;
- contractual liability arrangements.
Do not assume every request needs every safeguard.
The measures should be tied to the identified secret and actual risk.
What happens if safeguards cannot be agreed or implemented?
Article 4 provides a middle stage between “share normally” and “refuse completely.”
Where:
- no agreement is reached on necessary measures;
- the user fails to implement agreed measures;
- or the user undermines confidentiality,
the data holder can withhold or suspend sharing of the specific data identified as trade secrets, subject to the regulation's requirements.
The decision must be:
- duly substantiated;
- provided in writing without undue delay;
- accompanied by competent-authority notification as required.
The data holder should identify which safeguards were not agreed/implemented and, where relevant, which trade secrets had confidentiality undermined.
Key operational principle
Continue sharing non-problematic data where possible.
Trade-secret treatment should be granular, not an excuse to stop an entire dataset where only a small subset is sensitive.
Exceptional refusal: serious economic damage
Article 4(8) creates a higher threshold for outright refusal of specific trade-secret data.
In exceptional circumstances, the data holder who is the trade-secret holder may refuse access to specific data where it can demonstrate that, despite the safeguards, disclosure is highly likely to cause serious economic damage.
The demonstration must be:
- case-specific;
- duly substantiated;
- based on objective elements;
- in writing;
- provided without undue delay.
The regulation lists relevant factors including:
- enforceability of trade-secret protection in third countries;
- nature and level of confidentiality;
- uniqueness and novelty of the connected product.
The data holder must also notify the competent authority.
This is intentionally a high bar.
Weak refusal
These data are confidential and commercially sensitive, therefore denied.
Stronger process
- identify exact fields/files;
- explain why they qualify as trade secrets;
- document safeguards considered;
- document why safeguards are insufficient;
- document objective serious-economic-damage risk;
- issue written decision;
- notify authority;
- continue sharing other in-scope data.
User redress under Article 4
A user can challenge withholding/suspension/refusal.
Without limiting court/tribunal rights, Article 4 provides routes including:
- complaint to the competent authority;
- agreed referral to a dispute settlement body under Article 10.
A request portal should communicate these redress options rather than ending with:
Request denied.
Article 5: trade secrets when data go to a third party
For the request workflow alongside these recipient safeguards, see the Article 5 Third-Party Data Sharing Request Template.
Trade-secret risk can increase when data leave the user/data-holder relationship and go to a third-party service provider.
Article 5 therefore contains similar but recipient-focused safeguards.
At a high level:
- trade secrets should be disclosed only to the extent necessary for the purpose agreed between user and third party;
- the data holder/trade-secret holder identifies the trade-secret data;
- proportionate technical and organizational measures are agreed with the third party before disclosure;
- confidentiality must be preserved.
Article 6 then requires the third party to respect those safeguards and prohibits undermining trade-secret confidentiality.
Purpose limitation matters more under Article 5
Article 5 sharing exists because the user chose a third party for an agreed purpose.
Trade-secret disclosure should therefore be scoped to what is necessary for that purpose.
Example:
User hires an independent maintenance provider to diagnose bearing wear.
The recipient may need:
- vibration telemetry;
- temperature readings;
- machine state;
- relevant event codes.
It may not need:
- unrelated proprietary production parameters;
- secret algorithm tuning values;
- product-development datasets.
The data holder should avoid both extremes:
- withholding all data;
- transferring every internal field regardless of purpose.
Article 5 withholding and suspension
Where agreed safeguards are not implemented or confidentiality is undermined, the data holder can withhold/suspend sharing of specific identified trade-secret data under the regulation's conditions.
Again, the decision should be:
- specific;
- substantiated;
- written;
- notified to the competent authority where required.
Other shareable data should continue where possible.
Article 5 exceptional refusal
Article 5(11) provides a serious-economic-damage refusal route similar to Article 4.
Where the data holder who is the trade-secret holder can demonstrate a high likelihood of serious economic damage from disclosure despite the third party's safeguards, it may refuse specific data case by case.
The regulation again references objective considerations such as:
- enforceability in third countries;
- confidentiality level;
- uniqueness/novelty of the connected product.
The decision must be substantiated/written and the competent authority notified.
The third party has challenge/redress routes.
Third-country risk
The regulation specifically points to enforceability of trade-secret protection in third countries as a relevant objective factor in exceptional-refusal analysis.
This does not mean:
non-EU recipient = automatic refusal.
It means cross-border enforceability can be part of the risk assessment.
Possible safeguards can include:
- contractual confidentiality;
- access restrictions;
- controlled hosting;
- EU/EEA processing conditions where appropriate;
- no onward transfer;
- technical segregation.
The correct measures depend on the data and purpose.
Trade-secret metadata and classification
A connected-product company should know which fields are trade secrets before the first request arrives.
A useful internal data inventory can contain:
| Dataset / field | Trade secret? | Holder | Reason | Safeguards | Share status |
|---|---|---|---|---|---|
| Temperature | No | — | — | — | Normal |
| Bearing model coefficient | Yes | Manufacturer | Proprietary model | Restricted access/NDA | Conditional |
| Fault code | Maybe | Manufacturer | Depends on mapping detail | Review | Conditional |
This is far better than deciding request-by-request through email.
Classification discipline
Do not label information “trade secret” merely to avoid access obligations.
Confirm the Directive criteria:
- actually secret;
- commercial value because secret;
- reasonable secrecy measures.
Reasonable steps to keep information secret
The Trade Secrets Directive requires reasonable steps to maintain secrecy.
That makes internal governance relevant.
Potential evidence:
- role-based access controls;
- NDAs/confidentiality terms;
- internal classification;
- restricted repositories;
- logging/security measures;
- vendor confidentiality clauses;
- limited disclosure.
If a manufacturer publishes the same information publicly or shares it freely without confidentiality controls, claiming trade-secret status later may become difficult.
Trade secrets vs intellectual property generally
The Data Act's Article 4/5 safeguard language is specifically structured around trade secrets.
Do not treat every IP concern as the same thing.
Possible overlapping rights include:
- patents;
- copyright;
- database rights;
- confidential know-how;
- trade secrets.
A request may involve more than one legal issue.
The trade-secret workflow in this guide does not automatically resolve all IP questions.
Trade secrets vs personal data
These are different classifications.
A dataset can be:
- non-personal + non-secret;
- non-personal + trade secret;
- personal + non-secret;
- personal + trade secret/confidential business information;
- mixed.
Therefore access review can require both:
- Data Act trade-secret safeguards;
- GDPR lawful basis/data-subject safeguards.
See:
EU Data Act vs GDPR for Connected Products
Trade-secret process for data holders
A practical workflow:
Access/share request
↓
Identify datasets
↓
Trade-secret classification
↓
Identify trade-secret holder
↓
Determine purpose/necessity
↓
Agree safeguards
↓
Share with safeguards
↓
Monitor complianceEscalation:
Safeguards not agreed / breached
↓
Withhold or suspend specific secret data
↓
Written substantiation + authority noticeExceptional escalation:
Safeguards exist BUT serious economic damage highly likely
↓
Case-specific refusal of specific data
↓
Objective substantiation + authority noticeExample: industrial machine analytics request
Fictional example.
A factory asks its machine manufacturer to send operational data to Independent Analytics Ltd under Article 5.
Requested purpose:
predictive maintenance of bearing assemblies.
Requested fields:
- vibration;
- temperature;
- RPM;
- fault events;
- proprietary internal model coefficient.
Step 1 — classify
Vibration/temperature/RPM: normal operational data.
Fault events: potentially shareable, possibly sensitive depending on code mapping.
Model coefficient: manufacturer claims trade-secret status.
Step 2 — necessity
Independent Analytics needs vibration/temperature/RPM/fault events for maintenance.
It may not require the model coefficient.
Step 3 — outcome
Share non-secret operational fields.
Identify the model coefficient as trade secret.
If the coefficient is necessary, negotiate safeguards.
If it is unnecessary to the agreed purpose, it does not need to be part of the requested transfer.
This purpose-based approach reduces conflict before exceptional refusal is even considered.
Example: user Article 4 access
A building owner requests smart-HVAC telemetry.
Most data:
- temperatures;
- setpoints;
- valve states;
- energy readings.
Manufacturer argues one diagnostic model output contains proprietary know-how.
A robust response would not simply deny the entire export.
Instead:
- provide the ordinary data;
- identify the specific trade-secret field;
- determine whether it falls within requested/readily available data;
- agree confidentiality measures if disclosure is needed;
- only use withholding/refusal routes where the regulatory conditions are actually met.
What should a confidentiality agreement cover?
The Data Act does not mandate one single NDA template, but safeguards can address:
- definition of identified trade secrets;
- permitted purpose;
- authorized personnel;
- technical access controls;
- storage location;
- onward-sharing prohibition/conditions;
- security measures;
- retention/deletion;
- incident notification;
- audit/evidence mechanisms;
- liability/remedies where appropriate.
The Commission's non-binding Model Contractual Terms contain practical structures for Data Holder–User and Data Holder–Data Recipient relationships.
Source:
European Commission — Model Contractual Terms
What should a refusal notice contain?
There is no single universal form, but a defensible refusal/withholding notice should be precise.
Possible structure:
Request
- requester;
- product/service;
- requested dataset;
- date.
Specific affected data
- exact field/dataset;
- why identified as trade secret.
Safeguards considered
- proposed measures;
- measures agreed/not agreed;
- implementation failures where relevant.
Decision
- share;
- share with safeguards;
- withhold;
- suspend;
- exceptional refusal.
If exceptional refusal
- objective elements supporting serious-economic-damage likelihood;
- why safeguards do not sufficiently address risk.
Procedure
- written decision date;
- competent-authority notification;
- redress/challenge route.
Avoid broad statements such as:
proprietary data — request rejected.
Common mistakes
1. Calling every dataset a trade secret
Use Directive 2016/943 criteria.
2. Assuming trade-secret status means automatic exemption
Articles 4/5 create safeguards and exceptional-refusal processes.
3. Refusing the entire request because one field is sensitive
Use granular identification.
4. Failing to identify the actual trade-secret holder
It may not be the data holder.
5. No safeguards catalogue
Decide possible technical/organizational measures in advance.
6. Using the serious-economic-damage route casually
It is exceptional and requires objective substantiation.
7. Forgetting competent-authority notification
Withholding/suspension/refusal provisions can trigger notification obligations.
8. Ignoring third-party purpose
Under Article 5, disclose only what is needed for the user-agreed purpose.
9. Mixing confidentiality and GDPR
Trade secrets and personal-data lawful basis are separate analyses.
10. No internal evidence of reasonable secrecy measures
Trade-secret classification relies partly on having taken reasonable steps to preserve secrecy.
Trade-secret readiness checklist
Classification
- Trade-secret criteria documented.
- Secret fields/datasets identified.
- Trade-secret holder identified.
- Reasonable secrecy measures documented.
Article 4
- User access workflow exists.
- Proportionate safeguards available.
- Withhold/suspend workflow exists.
- Exceptional-refusal standard documented.
- Authority-notification process exists.
- Redress information exists.
Article 5
- Recipient purpose documented.
- Necessary trade-secret data identified.
- Recipient confidentiality measures defined.
- Onward-sharing rules defined.
- Recipient security reviewed.
- Serious-economic-damage analysis process exists.
Governance
- Product Compliance/Legal owner defined.
- Engineering/data platform can locate fields.
- Security can implement restrictions.
- Contract templates available.
- Decisions are written/auditable.
Frequently asked questions
Are trade secrets exempt from the EU Data Act?
No blanket exemption exists. Articles 4 and 5 establish confidentiality safeguards, withholding/suspension conditions and an exceptional case-specific refusal mechanism for serious economic damage.
What legally counts as a trade secret?
The Data Act uses the definition from Directive (EU) 2016/943: information must be secret, have commercial value because it is secret, and be subject to reasonable steps to keep it secret.
Who decides whether data are trade secrets?
The data holder/trade-secret holder identifies the relevant data, but the classification and any refusal remain subject to the legal framework and potential challenge/redress.
Can the data holder require an NDA?
Confidentiality agreements can form part of the necessary technical/organizational measures, depending on proportionality and the circumstances.
Can a manufacturer refuse an entire Article 4 request because some fields are secret?
The regulation focuses on identified trade-secret data. Non-problematic data should not automatically be blocked because another field is sensitive.
When can sharing be withheld or suspended?
Where necessary safeguards are not agreed/implemented or confidentiality is undermined, specific identified trade-secret data can be withheld/suspended under the Data Act conditions.
When can access be refused completely for a trade secret?
In exceptional circumstances for specific data, where the trade-secret holder can objectively demonstrate a high likelihood of serious economic damage despite safeguards.
What factors can support serious-economic-damage analysis?
The regulation references factors including enforceability of trade-secret protection in third countries, the nature/level of confidentiality, and the uniqueness/novelty of the connected product.
Must the competent authority be notified?
The relevant Article 4/5 provisions require notification when data are withheld/suspended/refused under the specified trade-secret mechanisms.
Can the user challenge the decision?
Yes. The Data Act preserves court/tribunal rights and provides complaint/dispute-settlement routes in the relevant provisions.
Does Article 5 offer stronger confidentiality controls than Article 4?
Both contain trade-secret safeguards, but Article 5 is specifically structured around disclosure to a third-party recipient and the purpose agreed with the user.
Can a third-party recipient share the secret data onward?
Article 6 restricts further sharing and requires confidentiality measures where trade secrets are involved.
Does GDPR apply to trade-secret data?
If the dataset also contains personal data, GDPR can apply alongside the trade-secret framework. The classifications answer different legal questions.
Should trade-secret fields be documented in metadata?
The Data Act contemplates identifying protected data, including in relevant metadata. Internal field-level classification is operationally useful.
Are Commission Model Contractual Terms mandatory?
No. They are non-binding tools that can help parties structure confidentiality/access relationships.
Primary sources and further reading
- Regulation (EU) 2023/2854 — EU Data Act
- Directive (EU) 2016/943 — Trade Secrets Directive
- European Commission — Data Act FAQ
- European Commission — Data Act explained
- European Commission — Model Contractual Terms
- European Commission — Data Act Legal Helpdesk
RegCatalog provides informational product-data tooling and implementation resources. It does not provide legal advice, trade-secret classification or certification.