Chapter 2 — Research and development procurement Proposed — COM(2026) 567

Article 26 — Confidentiality and data protection

In brief

This article protects confidential information exchanged during R&D procurement and requires compliance with EU data-protection rules. Neither public buyers nor economic operators may disclose information the other side has designated as confidential without prior, specific written agreement. It also allows buyers to set data-localisation and access requirements for personal data processed by the contractor.

Key points

  • Buyers must not disclose information designated as confidential by operators (including technical or trade secrets and confidential aspects of tenders), and operators must not disclose information buyers have designated confidential, without prior written agreement.
  • The prior written agreement must be specific to the intended communication, not a general waiver.
  • Buyers must ensure compliance with personal-data rules under Regulation (EU) 2016/679 and Directive 2002/58/EC and applicable national law across market consultation, the call for tenders, contract performance and afterwards.
  • Buyers may specify localisation and access requirements for personal data, such as processing and storage only within the countries referred to in Article 11(1), no external access, no change of processing location without prior written authorisation, and full compliance with transfer rules for any transfer to third countries or international organisations.

What it means in practice

Public buyers must handle sensitive tender and contract information carefully and set clear, specific confidentiality and data-handling terms in the procurement documents. Innovative firms, start-ups and SMEs gain protection for their trade secrets and confidential tender content, while contractors processing personal data may face defined localisation and access restrictions that they must be able to meet.

Anthony Bochon’s analysis

Confidentiality is the trust infrastructure of innovation procurement, and I welcome that the obligation here runs in both directions — protecting the trade secrets and confidential tender content of economic operators, and equally binding operators to information the buyer designates as confidential. The refinement I consider most significant is the rejection of general waivers: consent to disclose must be given with reference to the specific confidential information intended for communication, which is a genuinely protective standard and closer to good trade-secret practice than the loose confidentiality clauses one often sees.

Paragraphs 2 and 3 then layer in GDPR and ePrivacy compliance and, notably, allow the buyer to impose data-localisation and access restrictions tied to the Article 11(1) countries — no processing, storage or access outside that territory, and full compliance for any third-country transfer. In my reading this is where data-protection law meets the Act’s strategic-autonomy agenda, and it will interact closely with the wider EU data framework; addressees handling sensitive R&D data should map their processing, hosting and sub-processor arrangements against these localisation requirements before tendering, because they are contractual conditions rather than mere policy aspirations.

Official text — Article 26 (COM(2026) 567)
1. Without prejudice to the applicable Union and national law, public buyers shall not disclose without prior written agreement information provided to them by economic operators in market consultations, by tenderers during or after the call for tenders, by 47 Directive 2011/7/EU of the European Parliament and of the Council of 16 February 2011 on combating late payment in commercial transactions (recast) (OJ L 48, 23.2.2011, p. 1, ELI: http://data.europa.eu/eli/dir/2011/7/oj). contractors during contract performance or by former contractors after the end of the R&D procurement, which such economic operators have designated as confidential, including technical or trade secrets and the confidential aspects of tenders. Tenderers, contractors or f ormer contactors shall also not disclose without prior written agreement information provided to them by public buyers, which public buyers have designated as confidential. The prior written agreement shall not take the form of a general waiver but shall b e given with reference to the intended communication of the specific confidential information. 2. Public buyers shall ensure compliance with the personal data protection rules laid down in Regulation (EU) 2016/679 and Directive 2002/58/EC, and in applicabl e national law in all exchanges and publication of information during the market consultation, call for tenders, contract performance and after completion of the R&D procurement. 3. Public buyers shall specify in the procurement documents referred to in Ar ticle 10 any requirements on the localisation of and access to the personal data processed by the contractor. Such requirements may include that: (a) the personal data shall only be processed within the territory of those countries referred to in Article 11(1) and shall not be removed from not that territory; (b) the data shall only be held in data centres located with the territory of those countries referred to in Article 11(1); (c) no access shall be given to such data outside of the countries referred to in Article 11(1); (d) the contractor may not change the location of data processing without the prior written authorisation of the public buyer; (e) any transfer of personal data under the R&D procurement contract to third countries or international organisations shall comply fully with the requirements laid down in Regulation (EU) 2016/679.

Source: European Commission, proposal for a Regulation establishing the European Innovation Act, COM(2026) 567 final, 9 September 2026. Read the official proposal (PDF). Text may change during the legislative process.

© 2026 · All rights reserved · Made with by MogaCode