In the United States, the freedom to negotiate contract terms between businesses is nearly absolute. Courts intervene only in extreme cases of unconscionability, and sophisticated commercial parties are generally presumed capable of protecting their own interests. The EU takes a different approach, particularly when there is a significant disparity in bargaining power between the parties. Chapter IV of the EU Data Act introduces mandatory rules that override contract terms in business-to-business data-sharing agreements where one party is a small or medium-sized enterprise. These rules apply regardless of what the contract says, regardless of the choice of law clause, and regardless of whether the parties negotiated at arm’s length.

For US companies drafting or accepting data-sharing contracts with European SME counterparties, Chapter IV creates a new layer of baseline obligations. Terms that would be enforceable between large commercial parties in a US context may be automatically void or presumptively unfair under EU law when the counterparty qualifies as an SME. Understanding which terms fall into which category — and how to draft agreements that will be enforceable in European proceedings — is essential for any US company doing data business in Europe.

Who Chapter IV Protects

Chapter IV’s protections apply to B2B data-sharing agreements where one party is a micro, small, or medium-sized enterprise as defined under EU law. The EU’s SME definition is based on employee headcount and financial thresholds: a micro-enterprise has fewer than 10 employees and either annual turnover or a balance sheet total not exceeding 2 million euros; a small enterprise has fewer than 50 employees and financial figures not exceeding 10 million euros; and a medium enterprise has fewer than 250 employees and annual turnover not exceeding 50 million euros (or a balance sheet not exceeding 43 million euros).

These thresholds capture a very large proportion of European businesses. The European Commission estimates that SMEs account for over 99 percent of all businesses in the EU and employ approximately two-thirds of the private sector workforce. For US companies building European distribution networks, supplier chains, or partner ecosystems, the overwhelming likelihood is that many of their European counterparties will qualify for SME protection under Chapter IV.

Critically, the protections apply based on the SME status of the counterparty at the time the agreement is made, and they travel with the agreement. A company that qualifies as an SME when it signs a five-year data-sharing agreement does not lose Chapter IV protection if it grows beyond the thresholds during the term of the agreement. The protective rules remain in force for the duration of the contract.

The Structure of Chapter IV: Blacklist and Grey List

Chapter IV’s approach to unfair terms is organized into two tiers, each carrying different consequences. The first tier — commonly called the blacklist — identifies terms that are automatically void under all circumstances. These terms are so fundamentally imbalanced that EU law deems them unenforceable as a matter of public policy, regardless of what the parties agreed. The second tier — the grey list — identifies terms that are presumed unfair but can be rebutted by the party imposing them, if they can demonstrate that the term is justified given the specific circumstances of the agreement.

This structure is familiar in European consumer contract law but its extension to B2B agreements is a significant development. It reflects the EU’s view that smaller businesses, like consumers, often cannot meaningfully negotiate against larger counterparties who control access to data or data-sharing infrastructure. The regulation is therefore willing to override market outcomes in these asymmetric situations.

The Blacklist: Terms That Are Automatically Void

Article 13 of the Data Act identifies several categories of contractual terms that are automatically void and unenforceable when included in a data-sharing agreement with an SME counterparty. The following are the most significant categories.

Exclusions or Limitations of Liability for Gross Negligence or Willful Misconduct

Any term that unilaterally limits or excludes a data holder’s liability for damages caused by its own gross negligence or willful misconduct is automatically void. In US commercial practice, broad limitation of liability clauses are standard boilerplate — it is common to see clauses excluding consequential damages, capping total liability at the contract value, or even excluding all liability for particular categories of claim. Under the Data Act, such clauses cannot be enforced to the extent they shield the data holder from responsibility for its own seriously culpable conduct.

This does not mean limitation of liability clauses are generally prohibited. A data holder can still limit its liability for ordinary negligence, indirect losses, or unforeseeable damages, provided the limitation is not one-sided and does not immunize gross fault. The specific prohibition is on clauses that operate as get-out-of-jail-free provisions when the data holder has acted with serious culpability. Notably, the prohibition refers specifically to unilateral exclusions — a mutual, negotiated limitation applied equally to both parties is less likely to be captured by this provision.

For US companies drafting data-sharing agreements with European SMEs, this means that standard limitation of liability clauses should be reviewed to ensure they do not extend to gross negligence or willful misconduct on the data holder’s part. A clause that says ‘neither party shall be liable for any indirect or consequential losses’ is different from a clause that says ‘the data holder shall not be liable for any claim arising from its performance or non-performance of its data sharing obligations.’ The latter, applied to an SME counterparty, is void.

Exclusion of Remedies for Failure to Deliver Data

A term that purports to exclude or limit the data recipient’s remedies when the data holder fails to perform its data delivery obligations is automatically void. If a data holder commits to providing access to specified data and fails to do so, the data recipient — particularly an SME data recipient — must retain its basic legal remedies: the right to demand specific performance, seek damages, or terminate the agreement.

This provision is aimed at a specific contracting practice that regulators observed in digital markets: data access agreements that create the appearance of a binding commitment to data delivery but hedge that commitment with so many exclusions and carve-outs that the recipient has no practical remedy if delivery fails. Under the Data Act, this kind of provision is void when the recipient is an SME. The SME data recipient can enforce its right to receive the promised data.

In practical terms, this means that agreements must clearly specify what data will be delivered, in what format, on what schedule, and with what quality standards — and must preserve the recipient’s ability to enforce those specifications. Vague delivery commitments hedged with extensive exclusions are both void and a compliance risk.

Unilateral Rights to Change Data Access Terms

A term that allows the data holder to unilaterally change the terms of data access — including what data is provided, the format, the frequency, or the scope of the license — without the data recipient’s consent is automatically void. This prohibition targets change-in-terms provisions that allow one party to rewrite the deal unilaterally after it has been struck.

This is a significant constraint on US-style Terms of Service drafting, where unilateral amendment clauses are common. In a B2B data agreement with an SME counterparty under EU law, you cannot reserve a right to unilaterally reduce the data you provide, change the format, impose new restrictions on use, or modify the recipient’s access rights without the recipient’s agreement. Material changes to the data access terms require bilateral consent.

The Grey List: Terms Presumed Unfair Unless Justified

Article 13 also identifies a set of terms that are presumed to be unfair but can be justified if the party relying on them can demonstrate that they are reasonable given the specific circumstances. The burden of proof is on the party imposing the term to show that it is fair, not on the SME to show that it is unfair. This reversal of the burden is significant: in a dispute, the party defending the term must actively justify it.

Exclusive Value Extraction Rights That Harm the Recipient

A term that gives the data holder an exclusive right to extract value from data in ways that substantially harm the data recipient’s ability to benefit from the data is presumed unfair. This category addresses the situation where a data holder and a data recipient share data under an agreement, but the agreement is structured so that only the holder can monetize or commercially exploit the data while the recipient is locked out from deriving equivalent value.

The paradigmatic example might be an agreement where a manufacturer provides usage data to a service partner but retains exclusive rights to license that data to third parties, to use it for its own competing services, or to restrict the partner’s ability to build derivative products. If the net effect of these terms is that the SME partner receives data but cannot make meaningful commercial use of it, the terms are presumed unfair.

Justifying such terms requires demonstrating a legitimate business rationale that is proportionate to the restriction. A data holder who can show that exclusivity is necessary to protect significant intellectual property investment, and that the SME recipient is receiving adequate compensation for the constraint, has a better chance of rebutting the presumption. But the analysis is specific to the circumstances — boilerplate justifications will not suffice.

Other Presumptively Unfair Terms

The grey list also encompasses terms that allow the data holder to terminate data access on disproportionately short notice without objective justification, terms that require the data recipient to agree to additional obligations that are not related to the data-sharing purpose, and terms that impose asymmetric audit or compliance obligations on the recipient while exempting the holder from equivalent scrutiny. These terms are presumed unfair because they create structural imbalances that systematically benefit the larger party.

Terms relating to data quality guarantees fall into a nuanced area: a data holder who provides data ‘as is’ with no quality warranties may be imposing a grey list term depending on the context. Where the SME recipient is relying on data quality as the foundation of its services — and where the holder could reasonably be expected to maintain quality standards — a blanket no-warranty provision may be presumed unfair.

The Fairness Standard and How It Is Applied

Chapter IV’s prohibition on unfair terms is assessed against an overall standard of fairness, taking into account the nature of the data, the purpose of the sharing arrangement, and the commercial context in which the parties are operating. This is not a mechanical test — it requires an evaluation of whether the terms create a significant imbalance in the parties’ rights and obligations to the detriment of the SME party.

Courts and competent authorities applying this standard will look at the contract as a whole, not at individual provisions in isolation. A term that appears harsh in isolation may be balanced by other provisions that benefit the SME. Conversely, a collection of individually defensible terms that together create a systematically one-sided arrangement may collectively be found unfair.

The assessment is also context-sensitive. Terms that are appropriate in a large-volume data licensing arrangement between sophisticated commercial parties may not be appropriate in a more modest B2B data-sharing agreement with a small supplier. The fairness standard asks whether ordinary businesses in similar circumstances would find the terms acceptable — not whether the specific SME party objected to them at the time of signing.

Enforcement and Consequences

A contract term that falls within the blacklist is void — it has no legal effect, and the rest of the contract remains valid and enforceable unless the void term is so central to the agreement that the parties would not have entered the contract without it. In most cases, voiding a single unfair term leaves the remainder of the agreement intact.

A contract term that falls within the grey list and cannot be justified is also void, with the same consequences. The party seeking to enforce the term bears the burden of demonstrating its justification, and failure to do so results in the term being treated as if it were never in the contract.

Enforcement of Chapter IV is primarily through private action: the SME counterparty can invoke the unfairness provisions in national court proceedings and seek a declaration that a specific term is void. Member states may also designate competent authorities with the power to receive complaints and impose administrative consequences for systematic use of unfair terms.

Practical Implications for US Companies Drafting Data-Sharing Contracts

Audit Your Template Agreements

If your organization uses template data-sharing agreements, data access agreements, or API terms for business customers, conduct a review of those templates against the Chapter IV blacklist and grey list. Identify any provisions that would be automatically void when applied to an SME counterparty, and consider whether to remove those provisions from the templates entirely or to add SME-specific carve-outs.

Do Not Rely on Choice of Law to Avoid Chapter IV

A common instinct is to insert a US governing law clause in agreements with European counterparties and assume that US law will govern any disputes. This approach does not work for Chapter IV. EU mandatory law provisions apply regardless of the choice of law in the agreement, and EU courts — or US courts enforcing judgments obtained in EU proceedings — will apply them. Do not assume that a New York or Delaware governing law clause renders Chapter IV inapplicable.

Qualify Your SME Counterparties

Build a process for identifying whether a European counterparty qualifies as an SME before finalizing data-sharing contract terms. This qualification affects not only Chapter IV but also other parts of the Data Act (such as the FRAND pricing rules discussed elsewhere in this series). A simple self-certification request, backed by a representation and warranty in the contract, is a reasonable starting point.

Draft Liability Limitations Carefully

When limiting liability in contracts with EU SME counterparties, draft with precision. Limit liability for specified categories of loss — consequential damages, lost profits, indirect losses — rather than using broad exclusions that could be read to cover gross negligence or willful misconduct. Consider including an explicit carve-out preserving liability for gross negligence and willful misconduct, which both complies with Chapter IV and demonstrates good faith drafting.

Avoid Unilateral Amendment Clauses for Core Data Access Terms

If you wish to retain flexibility to modify your data product over time, structure that flexibility through defined change processes rather than unilateral amendment rights. For example, you can reserve the right to update the format of data delivery with reasonable notice, while requiring mutual agreement for changes to the categories of data provided or the scope of the recipient’s license. This approach preserves operational flexibility while avoiding the blacklisted unilateral amendment provision.