The EU Data Act creates powerful obligations on data holders to share data generated by connected products with users and, at a user’s direction, with third parties. But the regulation’s drafters understood that mandating unlimited data sharing could, in some circumstances, destroy the economic value of innovation — particularly where a product’s data reflects proprietary manufacturing methods, algorithmic processes, or technical configurations that a competitor could reverse-engineer from access to raw outputs. To address this tension, the Data Act includes an important but carefully circumscribed exception: data holders may, in some circumstances, refuse to share data on the grounds that doing so would expose trade secrets.

This trade secret exception is not a broad opt-out. It is a high-threshold defense with procedural requirements, oversight mechanisms, and a presumption in favor of sharing that the data holder must overcome. For US manufacturers who have grown accustomed to treating their connected product data as exclusively proprietary, understanding the precise contours of this exception — and what it does not protect — is essential compliance planning.

What Qualifies as a Trade Secret Under EU Law

The Data Act’s trade secret exception draws on the EU Trade Secrets Directive (2016/943), which established a harmonized definition across EU member states. Under that framework, information qualifies as a trade secret if it meets three cumulative conditions: it must be secret (not generally known or readily accessible to persons in the relevant field), it must have commercial value because of its secrecy, and the holder must have taken reasonable steps to keep it secret.

Each of these conditions has real content that must be demonstrated, not merely asserted. Secrecy is not an absolute concept — it means the information is not part of common knowledge in the industry. If the information could be independently derived by a skilled engineer examining publicly available technical literature, it is unlikely to qualify as secret in the relevant sense. The commercial value condition requires that the secrecy itself is the source of value — that competitors would gain a concrete advantage from knowing the information. General know-how accumulated over years of experience may have commercial value, but that value may not depend on secrecy in the way the directive requires. The reasonable steps condition is often where companies fail: informal expectations of confidentiality, without documented policies, access controls, and employee training, will not satisfy this prong.

In the context of connected product data, information that might qualify as a trade secret could include: the specific combination of sensor inputs and thresholds that indicate a particular machine failure mode, if that diagnostic logic is proprietary and not disclosed in product documentation; manufacturing process parameters that can be inferred from production equipment telemetry; or proprietary calibration constants embedded in device outputs. What typically would not qualify includes general usage statistics, standard performance metrics, basic operational logs, and any data category that the manufacturer itself publishes or exposes to third-party analytics services.

The High Threshold: Sufficiently Serious Risk of Serious Economic Harm

Even if information qualifies as a trade secret under the EU Trade Secrets Directive definition, the Data Act sets a further threshold for refusal: the data holder must be able to demonstrate that sharing the data creates a sufficiently serious risk of serious economic harm resulting from the disclosure of trade secrets. This double-seriousness formulation is intentional and demanding.

A vague concern that a competitor might benefit from access to data does not meet this threshold. The risk must be concrete and serious — meaning the data holder must be able to articulate the specific economic harm that would result from disclosure, explain why that harm is serious relative to the scale of the business, and demonstrate that the risk is not merely speculative. Regulators and courts applying this standard will expect evidence, not assertion.

The phrase ‘sufficiently serious risk’ implies a probability assessment: the harm must be likely, not merely conceivable. A data holder who argues that a recipient might theoretically reverse-engineer a manufacturing process from telemetry data, with only a tenuous causal chain between the data and the claimed harm, will struggle to meet this standard. The more direct and quantifiable the connection between disclosure and economic harm, the stronger the refusal claim.

This threshold deliberately creates asymmetry in favor of sharing. The Data Act’s drafters concluded that the value of broad data access — for users, for the secondary service economy, and for innovation generally — outweighs the costs of requiring manufacturers to disclose data that creates only marginal or speculative trade secret risk. Only genuine and serious threats to economically significant proprietary information justify refusal.

How a Data Holder Demonstrates the Risk

Invoking the trade secret exception requires more than a blanket claim. The data holder must provide a specific, reasoned explanation of why the particular data requested qualifies as a trade secret, and why sharing it creates the required level of risk. This means engaging in the analysis at the level of the specific data in question, not at the level of product categories or general business concerns.

In practice, data holders building a credible trade secret claim will need to document several things contemporaneously, not just at the moment of refusal. First, the specific information they assert is a trade secret, described with enough precision that a third party could verify the claim. Second, the steps taken to maintain secrecy — access controls, confidentiality agreements with employees and contractors, policies prohibiting disclosure, physical or logical security measures. Third, the commercial value of the information, with reference to the competitive advantage it provides. Fourth, the causal mechanism by which disclosure would result in serious harm — for example, because a competitor could use the information to replicate a proprietary process without the R&D investment the manufacturer incurred.

Companies that have robust trade secret programs already in place — with documented identification, classification, and protection of trade secrets — will be much better positioned to invoke this exception credibly. Companies that are accustomed to treating data as proprietary by default, without formal trade secret management programs, will need to invest in that infrastructure before the exception will be available to them.

Review and Override by Courts and Authorities

The Data Act does not allow trade secret claims to be self-executing. A data holder who refuses to share data on trade secret grounds does not have the final word. Both the user who requested sharing and the third party they designated have the right to challenge the refusal.

Enforcement of the Data Act falls to the national competent authorities designated by each EU member state. These authorities can investigate complaints, request documentation, and order disclosure where they find that a trade secret claim was not well-founded. They also have the power to impose penalties for unjustified refusals — the Data Act’s penalty regime for violations is substantial, with fines calculated as a percentage of global turnover in the manner familiar from GDPR enforcement.

Courts in EU member states can also review trade secret claims in civil proceedings. A user or third party who believes a refusal was pretextual can seek an injunction compelling disclosure, and courts have tools to evaluate trade secret claims without exposing the claimed secret in open proceedings — including in-camera review, confidentiality orders, and expert assessments. The availability of judicial review means that data holders cannot treat the trade secret exception as a convenient administrative shield against commercially inconvenient sharing obligations.

This oversight framework creates important practical stakes. A data holder who refuses to share data on trade secret grounds and is later found by an authority or court to have made an unfounded claim faces not only an order to share the data but also potential fines, reputational damage, and civil liability to the party that was wrongfully denied access. The exception is a genuine legal defense, but invoking it carries real risk if the underlying claim is not solid.

What Happens When the Parties Disagree

The Data Act contemplates that disputes over trade secret claims will arise and establishes a framework for resolving them. The most immediate pathway is through the data holder providing a more detailed explanation of the specific trade secret concern — essentially, substantiating the claim in a way that allows the requesting party to assess whether the concern is genuine or whether the data can be anonymized, aggregated, or otherwise modified to address the concern without exposing the proprietary element.

Where the disagreement cannot be resolved through dialogue, the requesting party can escalate to the national competent authority or to national courts. Some EU member states may also establish out-of-court dispute resolution mechanisms specifically for Data Act disagreements, as the regulation encourages member states to facilitate accessible dispute resolution options.

In the interim — while a dispute is pending — the data holder is entitled to withhold the contested data. A pending review does not require immediate disclosure. However, if an authority issues a preliminary order or an interim injunction pending full resolution, that order must be complied with promptly.

Trade Secret Protection Agreements as an Alternative to Refusal

The Data Act provides an important middle path that data holders should consider before resorting to outright refusal: sharing with confidentiality safeguards. Under this approach, the data holder does not refuse to share data but instead conditions sharing on the recipient entering into a trade secret protection agreement that imposes binding confidentiality obligations, use restrictions, and security requirements on the receiving party.

This mechanism makes considerable sense in many commercial contexts. The user’s interest in data portability — and the third party’s interest in providing services using that data — can often be satisfied without exposing the data holder to the specific harm they are concerned about, provided appropriate safeguards are in place. A service provider receiving diagnostic telemetry under a confidentiality agreement can use that data to perform maintenance analytics without needing to publish or replicate the data holder’s proprietary diagnostic logic.

The content of trade secret protection agreements under the Data Act should address several specific concerns. First, purpose limitation: the recipient agrees to use the data only for specified purposes and not to attempt to reverse-engineer proprietary processes or configurations from the data. Second, security obligations: the recipient must maintain the data with specified security controls and restrict access to personnel with a need to know. Third, sub-licensing prohibition: the recipient cannot pass the data to further downstream parties without the data holder’s consent. Fourth, audit rights: the data holder should have the right to verify compliance, including through independent audit in sensitive cases.

The Data Act permits data holders to require these agreements before sharing, which provides an important tool for managing trade secret risk without resorting to the high-threshold refusal mechanism. For manufacturers with significant proprietary data concerns, building a standard trade secret protection agreement that can be deployed quickly when sharing requests are received is a practical compliance investment that will also help avoid disputes.

Interaction With the User’s Right of Access

A nuanced point that requires careful attention is the different treatment of the user’s own access right versus the right to direct third-party sharing. The Data Act’s trade secret exception in Article 4(6) allows data holders to take necessary measures to protect trade secrets when making data available, but there is a strong interpretive position that the right of access for the user personally — to access data about their own use of their own device — should be more resistant to trade secret-based limitation than the right to share with third parties.

The logic here parallels data protection law: a person’s fundamental right to know what data exists about them carries significant weight. Applying the trade secret exception to block a user from seeing their own usage data would require extremely strong justification. In practice, the trade secret exception is most defensible when applied to prevent disclosure of how the data holder’s internal systems process or interpret data — the schema, the analytical logic, the derived inferences — rather than to block access to the raw underlying data that the user generated through their own actions.

For US manufacturers, this distinction has a practical design implication: if you can architect your systems so that raw user-generated data and proprietary analytical overlays are stored and accessed separately, you can more credibly grant user access to the former while protecting the latter. A data architecture that conflates raw device data with proprietary processing may create unnecessary friction between your trade secret protection interests and your users’ access rights.

Practical Guidance for US Manufacturers

Build a Trade Secret Inventory

The foundation of any credible trade secret defense is a documented inventory of the specific information you assert as a trade secret, the steps taken to protect it, and the commercial value it represents. This inventory should be maintained as a living document, reviewed regularly, and connected to your data classification policies. Without this documentation, a trade secret claim made at the moment of a sharing request will lack credibility.

Develop a Standard Trade Secret Protection Agreement

Rather than treating every sharing request that implicates sensitive data as a potential refusal, develop a standard trade secret protection agreement that your legal team has pre-approved and that can be offered to requesting parties quickly. This agreement should be calibrated to the actual risk level of different categories of data, not drafted as a maximalist restriction that recipients will resist. A workable agreement that gets signed and allows sharing to proceed is far more protective than an aggressive agreement that generates a dispute.

Implement Data Separation in Your Architecture

Separate raw device data from proprietary analytical overlays at the storage and access layer. This allows you to share raw data freely while maintaining a defensible claim over the analytical logic. It also simplifies GDPR compliance, since it clarifies what data is subject to data subject access requests versus what is internal processing.

Train Your Team on the Standards

Sales, product, and engineering teams need to understand that trade secret protection claims under the Data Act are evaluated against an objective legal standard, not the company’s subjective sense of what is proprietary. Overly aggressive claims made without legal foundation will not hold up to regulatory scrutiny and may expose the company to penalties. Internal training should establish clear protocols for when trade secret claims are appropriate and ensure that product teams are not over-classifying ordinary operational data as proprietary.

Document Refusals Carefully

When a sharing request is refused on trade secret grounds, the refusal should be communicated in writing, with a specific explanation of the basis for the claim (to the extent the explanation itself can be provided without disclosing the secret) and information about the process for challenging the refusal. This documentation protects the data holder if the decision is later reviewed and demonstrates good faith engagement with the regulatory framework.