photo
23.07.2026

The PL SA in the study visit project under the European Commission’s Technical Support Instrument

Staff of the Personal Data Protection Office took part in study visits organised within the project “Data Governance Act implementation – study visit project”, co‑financed by the European Commission (EC) under the flagship PACE initiative (Public Administration Cooperation Exchange), delivered through the Technical Support Instrument (TSI).

Two such visits were organised as part of the project. The meetings enabled an exchange of experience and perspectives on the implementation of the Data Governance Act (DGA) in the participating countries (Poland, Finland, Hungary). The series of study visits aimed to support cooperation and ensure cross‑border exchange of best practices among the participating states.

The host institutions were the Finnish Transport and Communications Agency Traficom (Liikenne‑ ja viestintävirasto Traficom) and the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH).

Visit to Finland

During the visit to Traficom, Personal Data Protection Office representatives had the opportunity to familiarise themselves with the DGA‑related regulations in Finland and with the organisational structure for data governance, which in Finland is decentralised. The tasks are divided among several institutions that cooperate closely, meet regularly and exchange information on an ongoing basis.

The structure and remit of Traficom differ from those of the Personal Data Protection Office. Above all, Traficom also deals with matters relating to transport in the broad sense, not solely data protection.

It is worth emphasising that Finland was the first country to implement national legislation on data governance through an act covering both the DGA and the Data Act (DA). These regulations entered into force in January 2024.

Under this act, Traficom has the power to issue warnings and reprimands to anyone who breaches the DGA, and subsequently grants time to remedy the infringement. If the issue is not resolved, Traficom may impose financial penalties. These range from EUR 1,000 to EUR 100,000. The relatively low fines reflect the fact that most data intermediation organisations are start‑ups with limited budgets.

Traficom may prioritise its supervisory tasks and may decide not to initiate proceedings in certain cases.

During the visit to Helsinki, the Polish delegation had the opportunity to review the online form used to register organisations wishing to act as data intermediaries.

Traficom experts also discussed in detail their experience in implementing the DGA provisions. They presented practical examples of data intermediation, including a solution whereby, after entering a vehicle’s registration number, an application enables the transfer of technical vehicle data to a car repair workshop.

It was also highlighted that workshops and awareness‑raising activities are organised to increase understanding of data intermediation and data altruism. At the same time, it was noted that limited administrative resources make it challenging to conduct extensive promotional activities in this area. The need for better communication of potential business benefits arising from the use of data made available under the DGA was also emphasised.

During the visit, the Personal Data Protection Office delegation also met representatives of other institutions involved in implementing the DGA in Finland, including the Ministry of Transport and Communications and the Office of the Data Protection Ombudsman.

The Personal Data Protection Office representatives learned about the competences of the Data Protection Ombudsman, which deals exclusively with matters relating to personal data, even though the DGA introduces a broad concept of data, distinguishing between personal and non‑personal data. However, the DGA does not assign supervisory tasks to this authority – its responsibilities derive from the GDPR.

A key element is the cooperation between the Data Protection Ombudsman and Traficom, which involves information exchange within the European Data Innovation Board (EDIB) sub‑group, regular meetings and consultations.

Additionally, the Personal Data Protection Office delegation met the CEO of DataSpace Europe Oy, a data intermediation organisation and the first to be registered in Finland in January 2024. The first non‑EU (British) data intermediation organisation was registered with the Finnish authority in June 2024.

The main role of DataSpace is to facilitate data flows between businesses. The company falls within the “data flows” category and focuses on managing data flows based on consent and appropriate permissions (“permission flows”). The commercial aspect of its activity is secondary, as the key objective is to build standards enabling safe and lawful re‑use of data and to foster trust among market participants.

The visit to Finland demonstrated that Finnish society is highly digitalised, aware of the benefits of making data available for re‑use, and open to data sharing. The data governance market is highly mature and provides favourable conditions for the future functioning of both data intermediation organisations and data altruism organisations. A significant factor contributing to this situation is the high level of public trust in public institutions.

Visit to Hungary

During the meetings in Hungary, the Polish delegation learned about the details of DGA implementation. In Hungary, preparations for implementing the DGA focused on analysing statutory requirements and determining how to organise the registration process so that it would be as straightforward as possible for NAIH while meeting all legal requirements arising from EU legislation

The national provisions – Act CXII of 2011 on the right to informational self‑determination and on the freedom of information – entered into force on 1 March 2024.

In January 2024, a Department for EU Digital Data Strategy was established under the NAIH Vice‑President for International Affairs. It dealt with issues relating to artificial intelligence and new technologies, supervised and registered tasks arising from the DGA, represented NAIH at EDIB meetings, and handled all data‑related tasks not covered by the GDPR. In 2026, the Department was upgraded from its previous status as a division.

The visit to Budapest provided an opportunity to deepen knowledge on data sovereignty and the relationship between data protection and the development of a data‑driven economy. Personal Data Protection Office representatives gained a broader perspective on the links between the DGA and other EU regulations, which is essential for ensuring coherence in national implementation approaches.

The visit also enabled an examination of Hungary’s experience in re‑using public sector data, including the conditions for making such data available and the safeguards applied. Discussions also covered the functioning of new entities introduced by the DGA, including data intermediation service providers and data altruism organisations, along with the challenges associated with their registration and supervision.

The visit also made it possible to identify key organisational challenges related to the implementation of the DGA. It was likewise an opportunity to strengthen competences in international cooperation and the exchange of experience between authorities of EU Member States.

During the visit to Budapest, the delegation of the Personal Data Protection Office also visited the National Data Protection Agency (NAVÜ). NAVÜ acts as a central coordinator which does not assume ownership of data but actively promotes its use. As a result, public bodies receive professional support in making data available, while NAVÜ ensures high‑quality processes. The Agency offers, among other things, anonymisation and pseudonymisation services, enabling the safe sharing of even sensitive data for analytical purposes.

During the meeting, representatives of the Agency discussed their role in the context of the DGA and presented the operational structure and current scope of activities of the institution.

The visit provided insight into the Hungarian model, which is based on two digital pillars: the National Public Data Portal (Nemzeti Közadatportál) and the Data Catalogue (Közadatkataszter). The end user receives a Single Information Point, where standardised forms allow them to submit requests for any public data.

An important element highlighted during the discussions was the establishment of a network of Chief Data Officers (CDOs) within individual public institutions. This helps build professional operational capacity within the administration, ensuring uniform practices, legal compliance and fast, reliable information flows.

At present, there is one data intermediation organisation operating in Hungary. There are, however, no registered data altruism organisations. According to the Hungarian hosts, the limited popularity of such entities stems from restrictive requirements, which make the profitability of this type of activity uncertain.

During the visit, the delegation of the Personal Data Protection Office also visited the University of Pécs, where a representative of the University presented the Smart University Program (SUP), designed to introduce innovative, data‑driven changes. The key components of this project are data management sciences and artificial intelligence, which—combined with cooperation between the academic and private sectors—aim to increase the potential of scientific research and improve the operational efficiency of the University.

In the next part of the meeting at the University, NIDHAS, the first data intermediation organisation in Hungary, shared with representatives of the Personal Data Protection Office both theoretical and practical insights into data intermediation. The theoretical information aligned with previously gathered knowledge and the DGA itself, while the practical insights presented data intermediation from a slightly different perspective.

NIDHAS confirmed the experiences gained in Helsinki: although data intermediation is theoretically a viable business model, from a practical standpoint it is too early for definitive conclusions, as the EU‑based data economy is still at a very early stage of development. Discussions showed that despite the many forms of data intermediation, the services or applications offered often take the form of a “data marketplace”. This brings a key challenge: such platforms can only function if there are entities interested in buying and selling data. The data market is not yet fully developed, which makes it difficult to build a thriving business.

Representatives of the National Authority for Data Protection and Freedom of Information, as well as other Hungarian institutions with whom the delegation of the Personal Data Protection Office met, emphasised that education aimed at increasing citizens’ awareness of the value of data sharing is crucial for effective data governance.

Tripartite cooperation

During each visit, the delegation of the Personal Data Protection Office presented details concerning the functioning of the President of the Personal Data Protection Office, the role and mission of the authority as a supervisory body in the field of personal data protection and privacy. The delegation also discussed the role of the Personal Data Protection Office in implementing the DGA in Poland, the current state of work on national legislation and the activities undertaken so far in preparation for assuming new tasks arising from the DGA.

The outcome of the “Data Governance Act implementation – study visit project” will be jointly prepared reports containing recommendations for the Personal Data Protection Office regarding DGA implementation in Poland. A tripartite meeting between Traficom, the Personal Data Protection Office and the National Authority for Data Protection and Freedom of Information has also been planned to summarise the project. During this meeting, the institutions will be able to exchange information on DGA implementation in their respective countries and discuss prospects for cooperation with the Personal Data Protection Office in future educational initiatives.

What PACE is

PACE is a flagship initiative of the Technical Support Instrument (TSI), an EU programme aimed at supporting Member States in implementing reforms that strengthen resilience and foster economic growth. PACE’s objective is to help build administrative capacity by promoting cooperation and cross‑border exchange between Member States. This is achieved by providing civil servants with opportunities to learn about the working methods of other public administrations across the EU.

Effective cooperation, exchange of experience and best practices can directly contribute to ensuring consistent application of EU law across all Member States.

The institution that supported the Personal Data Protection Office organisationally and substantively during the implementation of the project, on behalf of the European Commission, was Expertise France. The implementation of the PACE project aims to ensure more effective DGA implementation within the Personal Data Protection Office.

Detailed information about the visits can be found in the March and May editions of the Personal Data Protection Office’s Bulletin for Data Protection Officers.