When EU Governments Can Demand Your Data: Chapter V, Explained
The Data Act's least-discussed chapter lets public bodies demand data from companies in exceptional circumstances such as floods, fires and public emergencies. Who can ask, what they can ask for, and what to prepare.
Ask a founder what the EU Data Act covers and you will hear about IoT data, cloud switching, maybe unfair contract terms. Almost nobody mentions Chapter V, the part that lets a government body demand data from your company. It is the least-discussed chapter, and the one most likely to arrive as a complete surprise, in the middle of a crisis, with a deadline attached.
What Chapter V actually is
The business-to-government (B2G) provisions give public sector bodies, the European Commission, the European Central Bank and EU agencies the right to request data a company holds when there is an exceptional need to use it for a public-interest task. The paradigm case is a public emergency: floods, wildfires, a pandemic, a major industrial accident, where mobility data, sensor readings or logistics information held by private companies could materially help the response. The regulation has applied since 12 September 2025, and these provisions arrived with it.
What counts as an exceptional need
The bar is meant to be high. A public emergency is the clearest trigger, and in that case the data is generally expected to be provided free of charge. A second, narrower category covers non-emergency situations where a public body cannot obtain the data it needs to fulfil a specific legal task in a timely way by other means, buying it on the market, or getting it through existing reporting obligations. In those non-emergency cases, compensation covering reasonable costs plus a margin is expected to be available. What Chapter V is not: a general-purpose data tap for curious authorities. Requests must be proportionate, specific about the data needed and the purpose, time-limited, and formally justified, and law-enforcement investigation of specific offences is largely outside this framework.
Who is exposed
Any data holder can, in principle, receive a request, though micro and small enterprises benefit from carve-outs for most scenarios. The companies most likely to hear a knock: operators of connected devices and sensor networks (mobility, energy, agriculture, logistics), platforms holding aggregate behavioural or location data, and industrial companies whose telemetry maps onto public infrastructure. Notably, the request goes to whoever holds the data, if you run the cloud backend for somebody's devices, the authority's letter may be addressed to you, not the manufacturer.
Your rights when a request lands
A Chapter V request is not unconditional. The receiving company can expect the request to state its legal basis, purpose, the data sought and the deadline, and can decline or seek modification where the request does not meet the conditions, where the data is not available, or where the request duplicates another. Trade secrets receive procedural protection: they must be disclosed only where strictly necessary, with confidentiality measures agreed. Personal data adds a GDPR layer on top, requests are expected to prefer anonymised or aggregated data wherever that serves the purpose. Deadlines are short in emergencies, which is precisely why improvising your response during one is the failure mode to avoid.
The one document worth preparing
Chapter V compliance is not an engineering project, it is a one-page playbook: who in your company receives and validates such a request, how you check proportionality and legal basis, how trade secrets and personal data are flagged before anything leaves the building, in what format you can actually deliver data quickly, and who signs off. Companies that already built a data inventory and export capability for the Data Act's other chapters discover the marginal cost here is close to zero, the same export path that serves a switching customer serves an emergency request.
Keep it in proportion
For most SaaS companies, Chapter V will never fire. It sits at the bottom of the priority list, after switching terms, contract audits and access duties. But it belongs on the list, because it is the one obligation with no negotiation and no runway when it does arrive. Enforcement of the Data Act generally is national, in Germany via the Bundesnetzagentur under an implementation act in force since May 2026, with fines that can reach GDPR levels where personal data is involved, and an ignored emergency request is not the test case you want to be.
Want to know which Data Act chapters actually apply to your company, including whether B2G requests are a realistic part of your exposure? Our free readiness assessment maps your obligations in about three minutes.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.