The EU Data Act, which entered into force in January 2024 and became applicable in September 2025, reshapes the rules around who can access data generated by connected products and digital services across the European Union. Most commentary focuses on its business-to-business data sharing provisions, but Chapter V introduces a distinct and consequential obligation: the ability of public sector bodies — and, in defined circumstances, EU institutions — to request data directly from private companies. This mechanism, known as business-to-government (B2G) data sharing, creates a legal pathway for governments to access privately held data when they need it to serve a qualifying public interest purpose and no other means of obtaining the data exists.

For US companies operating in the European Union — whether through EU-based subsidiaries, cloud infrastructure serving EU users, or data collected from EU-based connected devices — this chapter represents one of the most operationally significant parts of the Data Act. If your company holds data about energy consumption patterns, mobility behavior, environmental conditions, patient outcomes, or any other dataset that might be relevant to how a European government responds to a crisis or maintains statistical systems, Chapter V creates a legal obligation to provide that data on request. Understanding the structure of this obligation, the procedural protections it includes, and how it differs from other frameworks where governments can demand corporate data is essential for compliance planning.

What Chapter V Actually Creates

Before diving into the details of how B2G requests work, it is worth clarifying what Chapter V does and does not do. This chapter does not create a general government right to access any data a private company holds. It is not a broad surveillance power, and it is explicitly not a law enforcement tool. Instead, it creates a structured, purpose-limited, procedurally constrained mechanism through which a public sector body can request data from a private company when specific conditions are met.

The chapter applies to what the Data Act calls ‘data holders’ — entities that have a legal right or obligation, through contractual or other means, to make certain data available. In practice, this typically means companies that generate, collect, or otherwise control data as part of running a product or service. For US companies, the critical question is whether the data they hold relates to activities, products, services, or users within the EU. If it does, and the company can be considered a data holder under the Act’s definitions, then a qualifying public sector body may submit a B2G request.

The Criteria a Request Must Meet

The Data Act does not give public sector bodies an open-ended right to demand corporate data. A request under Chapter V must satisfy several cumulative criteria before a data holder is obligated to comply. Each criterion is substantive, not merely procedural, and a request that fails to meet any one of them is not a valid request under the Act.

Exceptional Need

The requesting body must demonstrate an exceptional need for the data. This is not a routine data collection authority. The concept of exceptional need implies that the circumstances calling for the data are unusual and that the data is genuinely necessary to address a specific, identified situation. A public body cannot invoke Chapter V to satisfy ordinary administrative curiosity or to build out a general-purpose database of private sector information. The need must be tied to a specific qualifying purpose and must exist at the time of the request.

No Alternative Means

The request must demonstrate that the public sector body cannot obtain the data — or equivalent data — through other means. This is sometimes called a ‘necessity’ or ‘last resort’ requirement. If the requesting body already has access to public datasets, open data, or other sources that would satisfy its need, it cannot invoke Chapter V to obtain private sector data instead. This requirement is designed to prevent the Chapter V mechanism from becoming a shortcut around normal data acquisition processes and to ensure that the burden on private data holders is imposed only when truly necessary.

Proportionality

The scope of data requested must be proportionate to the purpose. This means the requesting body must define what specific data it needs and must not request data beyond what is genuinely required to achieve the stated purpose. Proportionality operates at multiple levels: the categories of data requested must be proportionate, the time period covered must be proportionate, and the granularity of the data requested must be proportionate. If aggregated data would serve the stated purpose, requesting individual-level records would fail the proportionality test. A public body cannot use Chapter V to build a comprehensive data repository when a targeted subset would suffice.

Scope Limitation

The request must be clearly scoped. The requesting body must identify, with specificity, what data is being requested, for what purpose, and for what time period. This requirement for scope limitation is both a protection for data holders — who need to understand what they are being asked to produce — and a constraint on the public body, which cannot submit open-ended requests and then decide later what to do with what it receives.

Qualifying Public Interest Purposes

Not every government data need qualifies under Chapter V. The Data Act identifies specific categories of public interest purposes that can justify a B2G data request. These categories are meaningful constraints, not aspirational language. A request that cannot be placed within one of the qualifying categories is not valid under the Act.

Public Emergencies

A declared public emergency — such as a major disease outbreak, a natural disaster, or a severe public health crisis — is the paradigmatic qualifying purpose under Chapter V. In an emergency, governments often need access to data held by private companies to understand the scope and spread of the emergency, to coordinate a response, and to allocate resources. The COVID-19 pandemic made the practical need for this kind of data access visible: mobility data from telecommunications companies and platform operators, for instance, would have been far more useful to public health authorities if a structured mechanism for requesting it had existed.

Disaster Prevention and Response

Beyond declared emergencies, Chapter V also covers disaster prevention and disaster response. This extends the mechanism to situations where an emergency has not yet been declared but where data access could help prevent a disaster from occurring or limit the damage once one has begun. Flood prediction, wildfire risk assessment, or early warning systems for industrial accidents might all represent contexts where a public sector body could make a compelling argument for accessing privately held environmental or operational data.

Official Statistics

National statistical offices and Eurostat, the EU’s statistical agency, may be eligible to request data for official statistical purposes. This is an important qualifying category for sectors where private companies hold data that would otherwise be difficult to capture through traditional survey methods. Energy consumption data held by smart meter operators, travel pattern data held by mobility service providers, or transaction data held by financial platforms might all be relevant for official statistical purposes. The statistical use case is subject to all the same procedural constraints as other Chapter V requests, and the data must be handled under appropriate statistical confidentiality rules.

Scientific Research

Scientific research in the public interest is another qualifying purpose. Public research institutions, universities, and similar bodies with a mandate to conduct research that serves the public good may be able to invoke Chapter V to access data needed for specific research projects. This category has clear overlap with the research exemptions in the GDPR, and the Data Act’s B2G mechanism for research data is designed to operate within the broader framework of EU data law, not to override it. If the data in question includes personal data, GDPR requirements apply in full alongside the Data Act’s B2G framework.

What Data Holders Must Do When They Receive a Request

When a public sector body submits a valid Chapter V request, the data holder — whether it is a US company or any other private entity — faces a series of obligations. These obligations are not optional, and they must be carried out within the timeframes the Act specifies.

First, the data holder must assess whether the request meets the statutory criteria. This is not simply a matter of checking boxes. A data holder that receives a request which it believes does not meet the requirements — because the stated purpose does not qualify, because the scope is disproportionate, or because the request lacks specificity — has both the right and, in some circumstances, the obligation to push back. Chapter V does not create a regime where private companies must comply with any request bearing an official letterhead. The procedural protections built into the chapter — discussed in more detail in the accompanying article on safeguards and refusal rights — give data holders meaningful tools to challenge deficient requests.

Second, if the data holder determines the request is valid, it must make the data available in the form specified by the requesting body, to the extent that this is technically feasible. The Act anticipates that public sector bodies may need data in specific formats for it to be useful, and it places at least a general obligation on data holders to provide the data in a form that can actually be used.

Third, the data holder must ensure that any personal data included in the response is handled in compliance with GDPR. Chapter V of the Data Act does not create a carve-out from data protection law. If the requested data includes personal data, the data holder must apply GDPR’s data minimization principle, ensure that any transfer to the public sector body has a lawful basis, and satisfy all applicable security requirements.

Fourth, the data holder should document its response to the request — what it provided, when, and in what format. This documentation serves multiple purposes: it provides a basis for claiming compensation, it supports any subsequent dispute about what was shared, and it demonstrates compliance in the event of regulatory scrutiny.

The Right to Compensation

One of the most practically significant aspects of Chapter V is that it provides for compensation when a private company is required to produce data in response to a B2G request. This distinguishes the Data Act mechanism from many regulatory data disclosure obligations, which are simply treated as a cost of doing business without any right to reimbursement.

Under Chapter V, data holders are entitled to receive compensation covering the cost of making the data available. This is not a profit-making provision — the Act specifies that compensation should be at cost, not market value — but it does mean that companies should not absorb the internal costs of identifying, extracting, formatting, and transmitting data in response to government requests. For US companies with EU data assets, this means that responding to a Chapter V request is not simply a matter of finding the data and handing it over. The company should track the internal resources consumed in responding and submit a request for reimbursement based on documented cost.

The compensation framework is adjusted in one important case: where the request arises from a public emergency, the requesting body is not required to pay full cost-based compensation. The rationale is that in a genuine emergency, the cost of imposing reimbursement obligations on public sector bodies should not impede access to data that could save lives or prevent harm. Even in emergency situations, however, the data holder is not required to provide data entirely for free, and the Act preserves some compensation entitlement.

Safeguards Against Secondary Use

A significant concern for any company providing data in response to a government request is the risk that the data will be used for purposes beyond those stated in the request. Chapter V addresses this concern through explicit secondary use restrictions. Data obtained through a Chapter V request may only be used for the specific purpose stated in the request. It may not be used for commercial purposes, it may not be shared with third parties except to the extent strictly necessary to serve the stated purpose, and it may not be retained beyond the time needed to fulfill the stated purpose.

These restrictions are not merely aspirational. The Act imposes obligations on the requesting public sector body — not just on the data holder — and Member States are expected to establish enforcement mechanisms for breaches of secondary use restrictions. For US companies, the practical implication is that a Chapter V response should be accompanied by clear documentation of what is being provided and under what terms, so that there is a clear record if the data subsequently appears to have been used beyond its stated purpose.

The secondary use restrictions also prohibit the requesting body from using the data to make decisions that adversely affect the data holder itself. This prevents a perverse outcome where a company is compelled to hand over data and then discovers that the data was used against it in a regulatory proceeding or a competitive analysis that benefited a state-owned competitor. This protection is one of the more commercially significant aspects of Chapter V, and it is worth understanding in detail — which is why it is explored more fully in the companion article on safeguards and refusal rights.

How Chapter V Differs from Law Enforcement Data Requests

US companies that operate globally are accustomed to receiving data requests from law enforcement agencies under frameworks like mutual legal assistance treaties, court orders, and national security process. It is important to understand that Chapter V of the EU Data Act is a fundamentally different kind of obligation, and the two frameworks should not be conflated.

Law enforcement data requests under EU legal frameworks — including Regulation 2018/1725 for EU institutions, national criminal procedure codes, and the European Investigation Order — are premised on a suspicion of wrongdoing or a specific investigative purpose. They typically involve judicial oversight at the point of authorization. The data holder’s primary obligation is to comply with a lawful order, and the exceptions available to it are largely procedural.

Chapter V requests are fundamentally different. They arise from a stated public interest purpose — an emergency, a statistical need, a research objective — not from a suspicion that the data holder or its customers have done anything wrong. The requesting body is a public sector body performing an administrative or social function, not a law enforcement agency conducting an investigation. The procedural protections available to data holders under Chapter V are substantially more robust than those typically available under law enforcement frameworks, and the secondary use restrictions are stronger and more explicitly stated.

This distinction matters because the appropriate internal response to a Chapter V request is different from the appropriate response to a law enforcement request. Law enforcement requests typically require immediate escalation to legal counsel and, in multinational companies, coordination with a global privacy team. Chapter V requests also warrant legal review, but the analysis centers on whether the request meets the statutory criteria — exceptional need, no alternative means, proportionality, scope limitation, and a qualifying public interest purpose — rather than on whether an order has been validly issued by a competent authority.

Practical Implications for US Companies in Regulated Sectors

The sectors most likely to receive Chapter V requests are those where privately held data has the most direct relevance to public sector functions: health, energy, mobility, and environment. Each of these sectors presents its own compliance considerations.

Health Sector

US health technology companies, pharmaceutical firms, and medical device manufacturers that collect patient-level or population-level health data in the EU are among the most likely recipients of Chapter V requests. In a public health emergency — an outbreak of a novel pathogen, a surge in a particular condition, or a drug safety concern — the data held by private health technology companies may be the most current and granular available. Companies in this sector should anticipate that Chapter V requests are a realistic compliance scenario and should establish procedures for evaluating, responding to, and documenting such requests. They should also be aware that health data is special category data under GDPR, meaning that any Chapter V response involving health information requires an additional lawful basis analysis under Article 9 of the GDPR.

Energy Sector

Energy companies — including US firms operating electricity grids, managing smart meter infrastructure, or providing energy management software — hold data that is directly relevant to public sector functions like grid stability, emergency planning, and energy poverty assessment. An energy shortage or a cascading grid failure could easily trigger a Chapter V request for consumption data, demand forecasting models, or outage records. Energy sector companies should map what data they hold that might be relevant to such scenarios and should understand the relationship between Chapter V and sector-specific data sharing obligations that already exist under EU energy regulation.

Mobility Sector

Ride-hailing platforms, navigation app operators, vehicle manufacturers with connected car platforms, and logistics companies all hold mobility data that governments find valuable for disaster response, infrastructure planning, and statistical purposes. The Mobility Data Space initiative within the EU’s broader data governance framework is specifically designed to facilitate exactly this kind of data sharing, and Chapter V provides a legal backstop for situations where voluntary sharing does not produce the data that a public sector body needs. US mobility companies serving EU markets should understand that their data may be subject to Chapter V requests and should consider whether their data governance policies address this scenario.

Environmental Sector

Companies that collect environmental data — air quality measurements, water quality readings, emissions data from industrial facilities — may receive Chapter V requests in the context of disaster prevention, environmental emergency response, or official statistical compilation. Environmental data is particularly relevant in the context of climate-related disasters, where private sector monitoring networks may provide finer-grained data than public infrastructure. US environmental technology companies operating in Europe should be aware that their data assets may be viewed as a public resource in emergency circumstances.

Building a Chapter V Compliance Program

For US companies that determine they are plausibly data holders under the Data Act, building a compliance program for Chapter V requests does not need to be complex, but it does need to be deliberate. The key elements are: a clear internal understanding of what data the company holds that might be subject to a request; a designated process for receiving, logging, and evaluating requests; a legal review protocol that addresses the criteria a valid request must meet; a documented approach to calculating and claiming compensation; and a policy for managing the confidentiality of commercially sensitive information included in a response.

Companies that are proactive about Chapter V preparation will be better positioned to respond efficiently when a request arrives — and to push back credibly when a request fails to meet the statutory criteria. Given that the Data Act became applicable in September 2025, and that national enforcement authorities are in the process of establishing their supervisory frameworks, now is the right time to build this capacity rather than improvising under pressure when the first request arrives.