European Data Union Strategy: how the EU aims to reshape the data market
More data for AI, less bureaucracy and clear rules for international data flows: with the Data Union Strategy, the EU aims to fundamentally realign its data policy. What exactly is planned, which reforms are coming and what companies should prepare for now.
What is the Data Union Strategy?
The Data Union Strategy is the European Union’s new data strategy. It was published by the European Commission on 19 November 2025 and forms part of the EU’s digital package.
Its objective is clear: data in Europe should become more available, more usable and better protected especially with regard to artificial intelligence.
At its core, the strategy addresses three central challenges:
- lack of high-quality training data for AI
- fragmented and complex data regulation
- geopolitical competition and restricted international access to data
The strategy relies both on regulatory reforms and on the expansion of technical infrastructure.
Newsletter
For your Inbox
Current updates and important information on topics such as data law, information security, technology, artificial intelligence, and much more. (only in German)
More and better data for AI
One of the main problems for European AI development is the availability of high-quality data. The Data Union Strategy aims to address this structurally.
Expansion of Common European Data Spaces
At the centre of the strategy is the expansion of so-called Common European Data Spaces. These are cloud-based data-sharing ecosystems.
Their defining features include:
- clear governance rules
- transparent access and usage rights
- structured data sharing between actors
The objective is, in particular, to expand public-sector data resources and make so-called high-value datasets available, for example in the areas of:
- health
- mobility
- energy
- culture
- language
Data Labs: a bridge between data spaces and AI
In addition, “Data Labs” are to be established. These will act as data service providers and connect data spaces with the AI ecosystem.
Their tasks include:
- pseudonymisation
- data pooling
- data preparation
- generation of synthetic data
This is intended in particular to enable small and medium-sized enterprises to make their own data usable for AI without losing control over them.
Closer integration with so-called AI Factories and European computing infrastructure is also planned.
Simplification and consolidation of data rules
Another key focus is the reduction of regulatory complexity.
At present, there are numerous sets of rules, some of which overlap. This fragmentation creates uncertainty and increases compliance effort.
Consolidation within the Data Act
The plan is to consolidate central legal frameworks, including:
- Data Governance Act, or DGA
- Open Data Directive
- free flow of data rules
These are to be merged into a revised Data Act, following an “omnibus” approach.
The objective is:
- fewer redundancies
- clearer requirements
- lower compliance effort
Reform of cookie rules
Cookie regulation is also to be revised.
The planned changes include:
- integration into the GDPR
- one-click rejection
- browser-based preferences
For companies, this could mean both technical adjustments and a strategic realignment of online marketing.
Amendments to the GDPR
The strategy also provides for targeted clarifications within the GDPR:
- a more precise definition of personal data
- simplified distinction between personal and pseudonymised data
- EU-wide harmonised lists for data protection impact assessments, DPIAs
- notifications to supervisory authorities only where there is a high risk to rights and freedoms
The aim is stronger harmonisation and relief in practical application.
Support for implementation
Accompanying measures are planned to support practical implementation of the Data Act:
- model clauses
- standard cloud clauses
- guidance
- SME helpdesk
The ambition is that legal simplification should not remain merely theoretical, but should be operationally implementable.
International data policy: Europe as a data actor
The Data Union Strategy expressly understands data as a strategic resource.
However, international data flows are often restricted by localisation requirements or restrictive access rules.
Dealing with data localisation
Data localisation refers to requirements under which data may only be processed within a particular country without objective justification.
The strategy provides for:
- a prohibition of unjustified data localisation
- development of a toolbox against discriminatory access rules
Discriminatory rules may, for example, treat companies differently depending on their size or country of establishment.
Protection of sensitive EU non-personal data
While personal data are already comprehensively protected by the GDPR, certain EU non-personal data are also to be more strongly protected in future.
This concerns data that are of strategic importance within the EU for:
- the economy
- security
- public order
Quality standards and synthetic data
A central theme of the strategy is the introduction of European standards for data quality.
In addition, the use of synthetic data is to be specifically promoted.
Synthetic data are artificially generated datasets that imitate real data. They can be used in particular for AI training — with the advantage that data protection risks are reduced.
The establishment of so-called “Synthetic Data Factories” is also being discussed.
In addition, cross-sector data pools are to be created that provide bundled datasets as a complement to decentralised data spaces.
In the long term, “one-click compliance” is also being considered: automated processes are intended to technically map and simplify regulatory requirements.
Initial planned measures
Implementation is to take place gradually.
Planned measures include:
- initial Data Labs
- reforms of cookie rules, GDPR amendments and Data Act support
- expansion of high-value datasets
- measures on international data flows and the protection of sensitive data
Companies should therefore already keep these developments strategically in view.
Conclusion: more data, less complexity but new requirements
The central question is: how can Europe make more high-quality data usable for AI without weakening regulation and data protection?
The Data Union Strategy relies on two levers: the structural expansion of data infrastructure and, at the same time, simplification of the legal framework.
For companies, this creates opportunities through better data access but also a need for adjustment in compliance, data strategy and international positioning.
Our recommendation: assess at an early stage how data spaces, data labs and regulatory adjustments may affect your own business model. Companies that prepare in a structured way now can actively use the new framework conditions instead of merely reacting to them.
Schedule your initial consultation
Describe your situation to us in a no-obligation phone call, and our lawyers will work with you to find the best solution.
Your experts