🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
⚠️ Malware / Trojaner / VirenVorsicht: Android-Malware verschlüsselt Ihre Handys und nimmt heimlich Fotos auf(11.09.2026 um 09:35 Uhr)
🕵️ SicherheitslückenMicrosoft geht endlich eines der nervigsten Probleme von Windows 11 an(11.09.2026 um 11:58 Uhr)
💾 IT Security ToolsSysinternals Suite(11.09.2026 um 12:00 Uhr)
🕵️ SicherheitslückenDefender 0-Day ShieldBreak (CVE-2026-69414) nicht sauber gepatcht - BornCity(11.09.2026 um 12:52 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
⚠️ Malware / Trojaner / VirenVorsicht: Android-Malware verschlüsselt Ihre Handys und nimmt heimlich Fotos auf(11.09.2026 um 09:35 Uhr)
🕵️ SicherheitslückenMicrosoft geht endlich eines der nervigsten Probleme von Windows 11 an(11.09.2026 um 11:58 Uhr)
💾 IT Security ToolsSysinternals Suite(11.09.2026 um 12:00 Uhr)
🕵️ SicherheitslückenDefender 0-Day ShieldBreak (CVE-2026-69414) nicht sauber gepatcht - BornCity(11.09.2026 um 12:52 Uhr)

📰 IT Security Nachrichten 🕛 vor 1 Jahr 10 Min Lesezeit SECURITY-FEED
0

What CIOs are in for with the EU’s Data Act

↗ Quelle (cio.com)
🗣️ Stimme:
📑 Inhaltsübersicht








Over the course of this year, CIOs have spent time studying the Data Act, the European digital regulatory framework composed of a set of laws united by the aim to encourage innovation in European companies, and to open up new markets. It came into force in January and will apply from September 2025 to define who can access and use data generated in the EU in all economic sectors. The measure aims to ensure fair distribution of data value among digital actors, stimulate a competitive data market, open up opportunities for data-driven innovation, and make data more accessible to. In practice, it’s the framework of rules from which a  won’t be a major upheaval either, adds Anselmo. “I’ll have to work, above all, on monitoring data traffic and protecting communications, while isolating some data and regulation of access,” he says.





From cloud to privacy: the law’s highlights





There are some particular articles of the Data Act that would pique the interest of the CIO. Articles 4 to 6, for instance, establish that companies adopt tools and processes to guarantee access to user data directly or through authorized third parties, and support their access requests. These obligations concern manufacturers of connected devices, but also providers of services such as cloud or data analysis. For CIOs, this means they’ll be facilitated in switching from one provider to another.





Also germane is the obligation of interoperability, outlined in articles 28 and 30, or the ability of applications and systems to exchange data securely and automatically beyond geographical and political borders. Therefore, cloud and edge computing service providers must ensure data interoperability, and that it extends to APIs that must be open and standardized.





“The CIO will be able to verify their technology providers comply with these standards and the possibility of migrating between providers, or using multiple providers,” says Degasperi. “This is particularly relevant for cloud providers. The CIO will have to ensure they use compliant platforms that make it easier and less expensive to migrate to another platform.”





And Article 3 is important in reference to GDPR. “If companies share data with each other, they must protect privacy and cybersecurity — another task for the CIO,” he says. “There’s also parts in Articles 14 and 15 about contracts. There must be coordination with the legal team because companies have to ensure contractual clauses with suppliers comply with provisions of the Data Act regarding what data can be collected, who can access the data, how long it can be stored, and so on.”





For Perugini, a relevant point is the burden of accessibility by design. If connected devices must be designed to make access to user data always directly possible, the CIO will have to deal with the technical solutions related to access authorization based on the user’s credentials, and the security of transmission to others. This can concern the CIO regardless of whether the company operates as a manufacturer, seller, supplier, or user of a connected device.





“The CIO must be an active part in creating the rules and solutions for these accesses, and must know the connected product and the Data Act well, and try to design both technical and organizational actions for compliance,” says Perugini. “The CIO must prevent the risk of violation by hackers and unauthorized users.”





There’s also the question of data retention. The CIO must establish, together with other company functions, retention times, which must be scheduled based on the actual use of data collected by connected devices. “Of course, there may be an overlap with GDPR which, on personal data, remains the main reference law,” she says.





Tasks of the CIO





There are many things the CIO will have to perform in light of Data Act provisions. In the meantime, as explained by Perugini, CIOs must do due diligence on the data their companies collect from connected devices and understand where they are in the value chain — whether they are the owners, users, or recipients.





“If the company produces a connected industrial machine and gives it to a customer and then maintains the machine, it finds itself collecting the data as the owner,” she says. “If the company is a customer of the machine, it’s a user and co-generates the data. But if it’s a company that acquires the data of the machine, it’s a recipient because the user or the manufacturer has allowed it to make them available or participates in a data marketplace. CIOs can also see if there’s data generated by others on the market that can be used for internal analysis, and procure it. Any use or exchange of data must be regulated by an agreement between the interested parties with contracts.”





The CIO will also have to evaluate contracts with suppliers, ensuring terms are compliant, and negotiate with suppliers to access data in a direct and interoperable way. Plus, the CIO has to evaluate whether the company’s IT infrastructure is suitable to guarantee interoperability and security of data as per GDPR. And updating teams on regulatory developments and collaborating with colleagues from the legal team or with legal consultants is important. IT action alone isn’t enough. In compliance with the Data Act, organizational and governance aspects are essential, and the CIO will have to collaborate with other functions.





But acquiring skills on the Data Act and the possible use of consultants could increase the costs of compliance, especially for SMEs. But according to Degasperi, there’s a great opportunity to create a more open and collaborative digital ecosystem that avoids data monopolies. “Of course, companies must adopt a conscious and strategic approach, and the CIO will have to rethink data governance,” he says. “The key will be to find a balance between fulfilling regulatory obligations and exploiting opportunities.”





Perugini advises companies to get out of a conservative mindset in order to take advantage of the European law and truly transform into data-driven companies. This will require careful study of the provisions, and an understanding of how to apply them to operations. This will be, in part, a task for the creative CIO because, starting from the tools offered by the Data Act, they’ll have to discover how to use them to spark innovation.


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf cio.com.
↗ Original-Artikel auf cio.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC
1 Quelle
Vorsicht: Android-Malware verschlüsselt Ihre Handys und nimmt heimlich Fotos auf
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten What CIOs are in for with the EU’s Data Act

Thematisch verwandte Begriffe: What, CIOs, with, Data · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...