Data Sharing You Can Trust: The Legal and Trust Framework Behind CircPlastX

Data Sharing You Can Trust: The Legal and Trust Framework Behind CircPlastX

A legal and trust framework for data sharing in the plastics sector

Circularity in the plastics sector depends on data, and on the conditions that make sharing that data safe. Companies across the value chain need reliable information on material composition, recycled content, substances, and lifecycle performance to support compliance, traceability, and sustainable production. That information is commercially sensitive and often legally protected and held by different actors across incompatible systems. The challenge is sharing it in a way that is controlled, purposeful, and legally sound.

The legal and trust framework of CircPlastX is designed to meet that challenge. CircPlastX is a structured environment in which legal, organisational, and technical safeguards work together to make responsible data sharing possible across the plastics value chain. This article explains what that framework looks like, why it is built the way it is, and what it means for organisations considering participation.

What CircPlastX is and how it works

A data space is a controlled environment for business-to-business data exchange in which each participant retains sovereignty over its own data. Participants can make data available under defined conditions, specifying who may access it, for what purpose, and under what restrictions.

CircPlastX is being developed in alignment with the Data Spaces Blueprint published by the Data Spaces Support Centre (DSSC), the EU-funded body responsible for providing reference architecture and guidance for common European data spaces under the Digital Europe Programme. The DSSC defines a data space as an interoperable framework, based on common governance principles, standards, practices and enabling services, that enables trusted data transactions between participants. In the DSSC Blueprint (currently at version 3.0), trust is structurally embedded through governance design, contractual frameworks, and technical controls.

CircPlastX applies this model to the specific needs and regulatory context of the plastics value chain, with data sharing primarily organised around three core services: online testing and certification of recycled content, improving life cycle assessment data quality, and supporting SMEs with substances management and compliance. These services provide structured, purpose-bound entry points that give participants a clear and justified reason to share data, reducing legal and commercial uncertainty from the outset.

The regulatory backdrop

The legal and trust framework of CircPlastX is shaped by a substantial body of EU legislation. Understanding which instruments apply, and how, is essential for any participant. The key horizontal instruments are:

  • The Data Act (Regulation (EU) 2023/2854): sets rules on access to and use of industrial data, requires interoperability in data spaces (Article 33), and will increasingly govern how connected manufacturing and recycling equipment generates shareable data.
  • The Data Governance Act (Regulation (EU) 2022/868): provides the framework for data intermediation services and establishes the conditions for trusted data sharing between sector actors.
  • GDPR (Regulation (EU) 2016/679): even in an industrial B2B context, personal data can surface (user accounts, access logs, mixed datasets), and GDPR obligations follow the data.
  • Trade secrets (Directive (EU) 2016/943): a company’s product formulations, process parameters, and supplier data are often legally protected. CircPlastX governance is designed to keep these protections intact when data is shared, through contractual conditions and controlled access.”
  • Competition law (Arts. 101 and 102 TFEU): multi-party data sharing in a sector-specific space requires attention to information exchange rules.
  • eIDAS 2.0 (Regulation (EU) 2024/1183): provides the EU trust infrastructure for participant identification.

Sector-specific regulation adds further weight: REACH creates data obligations along the supply chain; ESPR and Digital Product Passports will require interoperable data on material and product characteristics; PPWR mandates recycled content traceability.

Interoperability as a legal and governance requirement

Interoperability is often regarded as a technical topic; however, in European data spaces, it is also a legal one. Article 33 of the Data Act sets essential requirements for participants that offer data or data services to others in a data space. Dataset content, use restrictions, licenses, collection methodology, data quality and known limitations need to be described well enough for others to find, understand and reuse the data. The structures, formats, vocabularies and code lists used must be made intelligible. The technical means of access, such as APIs, must be documented, and where tools automate the execution of data sharing agreements, those tools must be interoperable rather than locked to a single vendor.

These requirements are now being made concrete through European standardisation. Under Mandate M/614, formally accepted by CEN and CENELEC in July 2025, the European Standardisation Organisations are developing harmonised standards and technical specifications for a European Trusted Data Framework, including standards on trusted data transactions, a data catalogue implementation framework, and an implementation framework for semantic assets, with delivery scheduled between 2026 and 2027. The incentive to align early is written into the law itself: Article 33(3) of the Data Act grants participants who comply with these harmonised standards a presumption of conformity with the interoperability requirements.

CircPlastX is designed with this trajectory in mind, with catalogue and metadata functionalities allowing providers to describe their datasets, conditions and provenance in a structured way. In a European data space, interoperability is not a design preference; it is a condition for lawful and scalable participation.

The DSSC Blueprint as a design guide

The DSSC Blueprint organises the design of a data space into building blocks covering governance, legal, and technical dimensions. CircPlastX is built in alignment with the Blueprint’s legal building blocks, two of which shape the framework described in this article.

  • The Regulatory Compliance building block addresses a recurring finding in the legal analysis of data spaces: the data space itself is often not the direct addressee of regulatory obligations. Duties under the Data Act, the GDPR or sector-specific legislation typically attach to the participants, in their capacity as data holders, controllers or economic operators. What the data space must do is ensure that its architecture and governance never obstruct, and actively support, participants’ compliance. CircPlastX applies this by mapping the applicable legal instruments, clarifying how responsibilities are allocated between the data space and its participants, and designing its services so that regulatory data flows, from REACH obligations to future Digital Product Passport requirements, can be fulfilled through structured exchange. The data space functions, in short, as an enabling environment for compliance.
  • The Contractual Framework building block translates governance principles into enforceable terms. Participation agreements and standardised data sharing conditions ensure that access and usage rules are consistent across the data space, rather than renegotiated bilaterally for every exchange. Looking ahead, the European Commission is preparing model contractual terms for data access and use under the Data Act. Once finalised, CircPlastX intends to align its contractual templates with them, using a limited set of pre-approved, parameterisable variants that is automated within the data space. This preserves the fairness and legal soundness of the model terms while enabling the standardised, machine-executable contracting that real-time data sharing requires.

The six trust principles of CircPlastX

Drawing on both the DSSC guidance and CircPlastX’s own governance design, the legal and trust framework rests on six principles:

  1. Clear purpose: data is shared for a defined reason; participants know why data is requested and for what it will be used.
  2. Controlled access: access depends on roles, permissions, and conditions; not every participant sees every dataset.
  3. Clear roles: the framework distinguishes data providers, data users, and data right holders, and makes clear that the same organisation can hold more than one role simultaneously.
  4. Traceability: data exchanges are logged and auditable; trust requires the ability to verify what happened.
  5. Interoperability: data must be described clearly enough to be understood and used correctly by others. Article 33 of the Data Act makes this a legal requirement for data space participants.
  6. Accountability: the data space creates the environment; each participant remains responsible for its own conduct.

Accountability and what participants are responsible for

The sixth principle deserves its own section, because it is where the framework meets daily practice. CircPlastX creates the conditions for responsible data sharing, but responsibility for each sharing decision remains with the participant. Before sharing data, every participating organisation should be able to answer a short set of questions.

  • What data are we sharing, and is it sensitive? Product, material, process and environmental data can reveal trade secrets and technical know-how, or details about suppliers, customers and production methods.
  • Are we allowed, or indeed required, to share it? Confidentiality duties, intellectual property and database rights, licences and internal rules may restrict sharing, while the Data Act may oblige a company, as a data holder, to share certain data.
  • Does the dataset include personal data? User accounts, contact details, access logs and mixed datasets can bring the GDPR into play even in an industrial context.
  • For what purpose are we sharing?
  • Who within the organisation is authorised to approve it?
  • What conditions should follow the data once shared, in terms of permitted use, further sharing and restrictions?

None of this requires a legal team on standby for every transaction. The point of the CircPlastX framework is to turn these questions into routine: catalogue descriptions, standardised usage conditions, role-based access and audit trails convert what would otherwise be a bespoke legal exercise into a structured, repeatable process. Responsible participation starts with knowing your data, your rights and your role, and the data space is built to make that knowledge easy to act on.

There is a further reason to address these questions within a structured environment rather than outside it. Under the EU Trade Secrets Directive, information qualifies as a trade secret only if it is secret, has commercial value because it is secret, and has been subject to reasonable steps to preserve that secrecy. The third requirement is particularly relevant here.

Controlled, role-based access, purpose limitations, logged and auditable exchanges, and enforceable conditions of use can help a company demonstrate that it has taken reasonable steps to protect confidential information, even when that information is shared. By contrast, ad hoc disclosures, such as sending a dataset to a counterparty under a broadly drafted confidentiality clause, may make it harder to show that adequate safeguards were in place.

Sharing data through CircPlastX therefore need not compromise confidentiality. Properly managed, it can enable commercially sensitive information to be exchanged while preserving trade secret protection.

Looking ahead: a dynamic regulatory environment

The legal landscape in which CircPlastX is being built will continue to evolve, and the governance framework is designed to remain adaptable.

The Digital Omnibus simplification initiative is under discussion and may affect parts of the data governance framework. Harmonised standards under Article 33 of the Data Act are still being finalised. ESPR implementing acts and Digital Product Passport requirements will progressively define new data obligations for the plastics sector. CircPlastX governance is designed to be adaptable as these instruments take effect.

Conclusion

The plastics value chain is being required to share more data than ever, and there are strong legal and commercial reasons to be careful about how. The CircPlastX legal and trust framework does not resolve that tension by asking participants simply to trust one another more. It resolves it by making trust structural: purpose-bound services that give every exchange a defined reason, contractual terms that make conditions enforceable, controlled access and traceability that keep sensitive information protected, and interoperability aligned with the European standards now taking shape.

For companies in the plastics value chain, the practical message is that the legal complexity surrounding industrial data sharing is real, but it is manageable when the environment is designed for it. Confidentiality and trade secret protection are not obstacles the framework works around; they are conditions it is built to preserve, because without them industrial actors have no basis to participate at all. Data sharing you can trust is not merely an aspiration in CircPlastX; it is a design requirement, and the framework described in this blog post is how it is met.