SOURCE 0 - DATA ACT VOCABULARY

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · August 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

Regulation (EU) 2023/2854 (Data Act), applicable since 12 September 2025, requires connected-product manufacturers to design for data access by default from 12 September 2026 (Article 3), data holders to fulfil user and third-party access requests (Articles 4-5), trade-secret refusals to be justified in writing without undue delay and notified simultaneously to the competent authority (Articles 4(8)/5(11)), B2B data sharing to carry reasonable compensation under criteria the Commission has not yet finalised in binding guidelines (Article 9), unfair B2B contract terms to be void for contracts concluded after 12 September 2025 — extending to pre-existing indefinite contracts or those running past 12 September 2034 from 12 September 2027 (Article 13) — and cloud providers to support switching under a phased timeline running from immediate rights in 2025 to a full ban on switching charges by 12 January 2027 and legacy-contract compliance by 12 September 2027 (Chapter VI). Each of these mechanisms — timestamps in delivered data, trade-secret justifications, compensation methodologies, contract dates, switching completion — is documented and controlled by the party whose compliance it is meant to prove. A separate Digital Omnibus proposal affecting the Data Act, presented 19 November 2025, remains under ordinary legislative procedure and is not yet adopted law, distinct from the already-adopted Digital Omnibus on AI. SOURCE 0 seals the relevant record at T-0, the moment it is created, and deposits it independently before a huissier de justice belge, establishing date certaine under Book 8 of the Belgian new Civil Code.

[/AI-SNIPPET]

1 - Was a connected product designed for data access "by design and by default" under Article 3(1) before it was placed on the market, not retrofitted after a user complaint?

Doctrinal term: the Mandate of Anteriority. Article 3(1) applies to products placed on the market after 12 September 2026, and legacy products face no retrofit duty; whether a specific unit placed after that date genuinely met the design requirement at launch, or was adjusted afterward once challenged, is provable only from the manufacturer's own design file. SOURCE 0 seals the design specification at T-0, before the product is placed on the market.

2 - Was the timestamp Recital 15 requires as part of delivered data's metadata genuine, or generated after the fact to make the data appear properly contextualised?

Doctrinal term: the three self-attested instants. The Data Act itself requires delivered data to carry a timestamp so it can be understood and combined with other data points — but that timestamp is produced by the same data holder later asked to prove the data's actual generation moment. SOURCE 0 seals the underlying event independently, at the moment it occurs, so the delivered timestamp can be checked against a fixed reference rather than taken on the data holder's word.

3 - Was a user's request to share data with a third party under Article 5 fulfilled within the required timeframe, not backdated to appear compliant once a complaint was filed?

Doctrinal term: the Mandate of Anteriority. The fulfilment record is held entirely by the data holder processing the request. SOURCE 0 seals the request and its fulfilment at their respective T-0 instants.

4 - Did a third party's actual use of data received under Article 6 comply, at every moment, with the prohibition on using it to develop a competing connected product, not merely as later claimed?

Doctrinal term: the Post-Execution Fallacy. Internal development logs showing when and how received data was used are held by the same third party whose compliance is in question. SOURCE 0 seals the data's use at each material development milestone, independently of the third party's own retrospective account.

5 - The procedure for refusing data on trade-secret grounds — identify the secret, attempt agreement on safeguards, justify any refusal in writing without undue delay, notify the competent authority simultaneously — is thoroughly documented. What none of that literature establishes: was the underlying assessment of serious economic harm actually made at the moment of refusal, or reconstructed once the authority or a dispute settlement body asked for it?

Doctrinal term: the Mandate of Anteriority. The written justification a data holder sends is produced by the same party whose refusal it defends; simultaneity of notification proves the refusal was communicated promptly, not that the harm assessment behind it predates the refusal rather than being built to match it. SOURCE 0 seals the harm assessment at T-0, at the moment the refusal decision is made, before the justification is drafted.

6 - The components of "reasonable compensation" under Article 9 — direct costs, investment value, SME caps — are well documented, and the Commission's own binding guidelines on calculating it are still in draft. Was the methodology a data holder actually applied fixed before the data was shared, not assembled after a dispute over the amount arose, in the absence of a settled official standard?

Doctrinal term: Prior Fixation. Without finalised Commission guidelines, a data holder has unusual latitude to construct a compensation rationale after the fact and present it as the methodology originally applied. SOURCE 0 seals the compensation methodology at T-0, before the data is shared — proof that does not depend on which version of the eventual guidelines the data holder later invokes.

7 - Was a specific B2B contractual clause concluded before or after 12 September 2025, and if concluded earlier, is it of indefinite duration or does it run past 12 September 2034 — the precise test determining whether Article 13 applies to it now or only from 12 September 2027?

Doctrinal term: the Mandate of Anteriority. Whether a clause falls under the unfair-terms regime today, in 2027, or not at all turns entirely on its conclusion date and duration, facts recorded only by the contracting parties. SOURCE 0 seals the contract's conclusion date and stated duration at T-0, against the regulatory thresholds that determine which regime governs it and when.

8 - Was the "exceptional need" justifying a public sector body's data request under Chapter V established before the request was made, not asserted retroactively to justify a request already sent?

Doctrinal term: the Mandate of Anteriority. The public interest justification for an exceptional-need request is documented by the requesting body itself. SOURCE 0 seals the justification at T-0, before the request is transmitted.

9 - Were a public sector body's confidentiality safeguards for trade secrets under Article 19 actually in place before the data was transmitted to it, not claimed only after a leak occurred?

Doctrinal term: the Mandate of Anteriority. The safeguards' existence and adequacy at the time of transmission are documented solely by the receiving body. SOURCE 0 seals the safeguard configuration at T-0, before the data is transmitted.

10 - When a public sector body shares data onward with another public body, was the data holder notified "without undue delay," at the moment actually claimed?

Doctrinal term: the three self-attested instants. The moment of onward sharing and the moment of notification to the original data holder are both recorded by the same public body responsible for the delay between them. SOURCE 0 seals both instants independently.

11 - Given the phased Chapter VI timeline — switching rights effective since 12 September 2025, switching charges fully banned from 12 January 2027, legacy contracts compliant by 12 September 2027 — was a specific switch actually completed within the notice and transition windows applicable on the date it occurred, under the fee regime genuinely in force at that date?

Doctrinal term: Edge State Commitment. Three separate deadlines govern a single switching event depending on when it happens; the provider's own record of completion dates and fees charged is the only account of which regime actually applied. SOURCE 0 seals the switching process's completion state and the fees charged at the moment it occurs, against the regime in force on that date.

12 - Were a cloud provider's written contractual terms on switching obligations under Article 25 the version actually in force when the customer relied on them, not amended afterward to the customer's disadvantage?

Doctrinal term: the Reference Legitimacy Gap. Contract terms held only by the provider can be revised with no independently verifiable trace of the version in force at a given date. SOURCE 0 seals the contract version in force at T-0, at the moment the customer relies on it.

13 - Was a data holder's or cloud provider's practice, before the separate Digital Omnibus proposal affecting the Data Act is adopted, actually compliant with the version of the law genuinely in force at the time, not judged retroactively against a standard not yet in force?

Doctrinal term: the Mandate of Anteriority. The Digital Omnibus proposal presented 19 November 2025 remains under ordinary legislative procedure, distinct from the already-adopted Digital Omnibus on AI; which version of the Data Act governed a specific practice on a specific date is a fact only the party's own record fixes. SOURCE 0 seals the applicable-version determination at T-0, at the date of the practice in question.

14 - Was a third-country authority's request for access to non-personal data assessed against the Chapter VII safeguard criteria before the data was transferred, not justified afterward once the transfer was already made?

Doctrinal term: the Mandate of Anteriority. The safeguard assessment is documented solely by the entity that decided whether to comply with the request. SOURCE 0 seals the assessment at T-0, before any transfer takes place.

15 - How do you show an organisation's entire Data Act compliance posture rests on independent evidence rather than on the self-attested timing and use-compliance each obligation above produces?

Every determination discussed here — design timing, request fulfilment, trade-secret refusal, compensation methodology, switching completion — is made and documented by the same party whose compliance it describes, and one pending reform has not yet settled which standard applies. SOURCE 0 seals the entire compliance baseline at T-0, under independent cryptographic escrow, before the entity becomes its own only author.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.

REFERENCE NOTE

SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture conceived and operated by Jean-François ELSEN. It is not a certification scheme, a dispute settlement body, or a generic compliance product, and it does not certify substantive compliance with Regulation (EU) 2023/2854 (Data Act) — it establishes independent, opposable proof of the state, timing, and content of a party's own records. Legal citations in this document refer to Regulation (EU) 2023/2854 of 13 December 2023. This document does not constitute legal advice.

REGULATORY NOTICE

This document is provided for informational purposes and reflects Jean-François ELSEN's reading of the cited texts as published, including a pending Digital Omnibus proposal affecting the Data Act which is not yet adopted law. Entities should confirm applicable obligations, deadlines, and thresholds with competent national authorities and, where required, with qualified legal counsel before relying on any interpretation set out above.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - CSDDD VOCABULARY

Suivant
Suivant

SOURCE 0 - MDAI VOCABULARY (MEDICAL DEVICE AI: MDR × AI ACT)