Dispute Settlement Bodies Under the EU Data Act, and What Happens When Data Sharing Goes Wrong
Article 10 creates certified dispute settlement bodies to resolve fights over data access and compensation without going to court. How the process is expected to work, what it costs, and how to prepare before you ever need it.
The EU Data Act creates a lot of situations where two businesses can disagree: whether data must be shared at all, whether the compensation a data holder asks for is reasonable, whether trade secret protections are being used as a shield or a stall. The Act anticipated this and, in Article 10, built a dedicated off-ramp: certified dispute settlement bodies that can resolve these fights faster and more cheaply than litigation. Since the Act has been applicable from 12 September 2025, this machinery is no longer theoretical, and knowing how it works is part of being ready.
What these bodies are for
Dispute settlement bodies are expected to handle three main families of disagreement. First, disputes about the terms on which a data holder makes data available, including whether conditions are fair, reasonable and non-discriminatory. Second, disputes about compensation, since the Act allows data holders to charge data recipients in business-to-business sharing but constrains how much, with lighter expectations where the recipient is a smaller company. Third, disputes connected to the transparent refusal or restriction of access, for example where trade secrets are invoked.
They are not a general-purpose court for everything Data Act related. A cloud switching disagreement or an unfair contract terms argument under Article 13 would typically go down other routes, and nothing in Article 10 removes your right to go to an ordinary court instead.
How the process is expected to work
Member States certify these bodies against criteria in the Act: they are expected to be impartial, independent, accessible, and staffed with the necessary expertise. A certified body is expected to decide within 90 days of receiving a complaint, which is the headline attraction compared with commercial litigation timelines. Fees are expected to be disclosed up front and to stay reasonable, and there is an expectation that costs can be allocated against the losing side in defined circumstances.
Two design features matter for strategy. The outcome is generally binding only if both sides agreed to be bound by it, so engaging in the process is not automatically a one-way door. And using a dispute settlement body does not strip either party of the right to seek an effective remedy before a national court, so the process sits alongside litigation rather than replacing it.
Who runs this in practice
Certification and the surrounding infrastructure are national. Germany is the clearest early example: its Data Act implementation law, the DADG, has been in force since 30 May 2026 and places enforcement with the Bundesnetzagentur, backed by tiered fines of up to EUR 500,000. Where personal data is involved, GDPR-level fines of up to 4% of worldwide turnover can apply under Article 40(4), though that is specifically the personal-data scenario. Other Member States are building out their equivalents at different speeds, so the practical availability of a certified body near you may vary for a while.
It is also worth tracking the Digital Omnibus discussions in Brussels, which propose softening several Data Act obligations, particularly for smaller companies. Those proposals are not law yet, and until they are, the current dispute framework is the one you should plan around.
Preparing before a dispute exists
The parties most likely to do well in a 90-day process are the ones who arrive with their paperwork already in order. If you are a data holder, that means being able to show how you calculated any compensation you charge, why your terms are reasonable, and, if you restricted access, the specific trade secret or safety grounds you relied on and the safeguards you offered instead of a flat refusal. A refusal documented in real time looks like compliance; one reconstructed after a complaint looks like obstruction.
If you are a data recipient or a user routing data to one, the preparation is symmetrical: keep the request, the stated purpose, and the correspondence. Many disputes under the Act are expected to be arguments about reasonableness, and reasonableness is mostly proven with contemporaneous records rather than advocacy.
Why this matters now rather than later
The volume of potential disputes grows with each deadline. Access-by-design expectations have applied to connected products placed on the market since 12 September 2026, switching charges are expected to be withdrawn from 12 January 2027, and even legacy contracts concluded before the Act are expected to be caught from 12 September 2027. Each milestone creates new obligations that someone can claim you missed, and the dispute settlement route is the cheapest place to lose, or win, those arguments.
If you want to know where your own setup is most exposed before anyone else points it out, our free readiness assessment maps your role and obligations under the Data Act and highlights the areas where disputes most commonly start.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.