Department
of Excellence
2023 -2027
Who we areLaw BulletinThe Course
Research
Food Law HistoryFood SustainabilityFood InnovationFood (in)EqualityFarm & IP Law
NewsEventsFAQContactsReserved Area
ITA
News

From Field to Cloud: Agriculture 4.0 and the Challenge of the Data Act

by Maria Giulia Corazza

‍

1. Introduction

On the 12thof September 2025, the Data Act became applicable, marking the most recent legislative intervention by the European Union aimed at comprehensively regulating the generation, access, anduse of data produced by a wide range of connected devices and services. As aregulation of general scope, it is expected to affect numerous sectors of the European economy characterized by the increasing use of digital technologies and automated systems. For the first time, the European legislator expressly acknowledges, in a binding legal instrument, the need to protect data generated by agricultural activities as well (Recital 27 of the Regulation). This reference, although seemingly marginal, carries significant weight: it formally recognizes that agriculture—a sector long perceived as distant from the dynamics of digitalization—now generates an ever-increasing volume of technical and operational information as a result of the wide spread adoption of advanced agricultural machinery. Indeed, over the past twenty years, digital transformation has permeated virtually all sectors of the economy, and agriculture has been no exception. The primary sector is now at the centre of profound and tangible changes, an evolution originally described as “Agriculture 4.0” and, by some scholars, even as a genuine “Fourth Industrial Revolution” (D’Avanzo, 2022), concerning the machinery employed within the sector. This inherently heterogeneous phenomenon integrates digital technologies—ranging from the Internet of Things and big data to robotics and blockchain—into agricultural practices, thereby enhancing productivity, sustainability, and traceability throughout the entire agri-food supply chain. Examples include sensors capable of monitoring weather conditions; drones and sophisticated tractors that measure the precise quantities of substances to be applied or seeds to be planted; crop-monitoring systems; robots for selective harvesting; digital solutions for product storage and management; and platforms designed to support animal welfare and the smart management of livestock farming, to mention only a few. In this way, digital innovations in agriculture not only contribute to the objectives established by the European Green Deal and the Farm to Fork Strategy, but also fit within the broader framework of the European Union’s digitalization policies (Digital Strategy), fostering the transition towards a more technological, resilient, and efficient agricultural system—the so-called Twin Transition. From this perspective, digital tools strengthen food security by enabling a rational and data-driven approach. At the same time, blockchain-based solutions provide additional guarantees in terms of transparency and consumer protection, ensuring immutable traceability throughout the entire supply chain (D’Avanzo, 2021). The phenomenon is already experiencing exponential growth. According to current estimates, the number of Agriculture 4.0 devices installed worldwide exceeded 25 million in 2023 and is expected to reach nearly 40 million by 2028. Likewise, the global smart agriculture market is projected to expand from USD 20.6 billion in 2023 to more than USD 60 billion by 2033. However, as is often the case with innovations of a transformative nature, the prospects of the sector, while undoubtedly promising, are not without ambiguity. Although digitalized agriculture appears to outline a future superior to the pre-digital context, it should be remembered—and legal scholars are naturally inclined to emphasize this point—that “innovation” is not, in absolute terms, synonymous with “improvement.” It would be reductive and would expose us to a form of partial blindness, to overlook the potential consequences of the extraordinarily rapid development and diffusion of these technologies. These consequences take the form of unprecedented legal and regulatory challenges that must be addressed in order to ensure the fair and effective implementation of digitalized agriculture. This necessity becomes particularly evident when considering that the adoption of digital tools entails not merely a technical transformation of agricultural practices but also—and above all—a structural reconfiguration ofthe relationships among the actors involved in the supply chain (Ferrari, 2023). The implementation of these technologies marks a clear departure from traditional arrangements, redefining roles, responsibilities, and bargaining positions. Farmers, who historically occupied a central and relatively autonomous role in managing their production processes, are increasingly dependent on digital infrastructures, data analytics services, management platforms, and cloud-based systems. At the same time, new actors have entered the supply chain: Agricultural Technology Providers (ATPs), namely the manufacturers of agricultural machinery themselves. These actors perform crucial functions in the collection, processing, and control of agricultural data, exerting growing influence over the operational and strategic decisions of farming enterprises. This reorganization of existing balances, which affects both the distribution of informational power and access to resources that are essential for production, raises a series of complex legal questions. These range from data protection and intellectual property rights to competition in digital markets, from liability for algorithmic malfunctions to the asymmetrical contractual relationships between farmers and technology providers. It is precisely withinthis largely unexplored terrain that the law is called upon to intervene, ensuring that the digital transition, despite its undeniable benefits, does not give rise to new forms of vulnerability or imbalance.

‍

2.From Machinery to Agricultural Data: The European Regulatory Landscape

 

At this point, it is inevitable to focus on the key protagonists of the agronomic revolution currently underway: agricultural machinery and its innovative output, namely agricultural data. These two elements are embedded within a deeply interconnected system. Put simply, the farmer generates data through the use of machinery; such data are then transmitted through networks, often viacloud-based systems, where they are aggregated, processed, and subsequently used to guide agronomic practices, which are once again carried out through machinery. The cycle is self-reinforcing, operating through a circular dynamic of information generation, processing, and reuse. In the literature, this has been described as a “chicken-and-egg problem,” insofar as “without data, digital services cannot take off, without digital services there is no motivation to share the data” (Brunori et al., 2025, p. 18). The range of machinery involved is highly diverse, both in terms of the technologies employed and the agronomic operations performed; consequently, the categories of agricultural data generated are equally varied (Brunoriet al., 2025). It is precisely this new element—agricultural data—that is assuming an increasingly central role, not only in agronomic practices stricto sensu, but also in the development of new machinery and digital services. Agricultural data have thus become a fundamental component of the agri-food supply chain and, inevitably, have acquired an economic value as well. Given the complexity of the technologies involved and the relationships among the various actors operating within the system, the regulation of machinery use and of the collection and circulation of agricultural data necessarily lies at the intersection of several European legal instruments: Regulation(EU) 2024/1689 (AI Act); Regulation(EU) 2016/679 (GDPR); Regulation(EU) 2018/1807 on the free flow of non-personal data; Regulation(EU) 2022/868 (Data Governance Act); and thevery recent Regulation(EU) 2023/2854 (Data Act). These regulatory initiatives can be more clearly understood when situated within the three macro-segments traditionally used to describe the agri-food supply chain: (i) agriculture, (ii) processing, and (iii) marketing and distribution. Although simplified, this tripartite framework provides the minimum analytical coordinates necessary to map the principal legal instruments currently being applied or implemented at the supranational level to govern digital innovation throughout the agri-foodsector in all its complexity.

Focusing on the first segment—agriculture—it is possible to identify, “downstream,” that is, in the sphere where digital systems directly affect the productive organization of farms and managerial decision-making, the first potential applications of the AI Act. Although the impact of the AI Act on the agri-food sector remains relatively limited at present, it may become relevant whenever farms employ artificial intelligence systems that are subject to risk assessment, transparency, or compliance obligations (Val,2025). It is, however, within the new operational triangle consisting of the farmer, Agriculture 4.0 machinery, and Agricultural Technology Providers (ATPs) that a genuine departure from the traditional relationships characterizing agricultural enterprises emerges. This new arrangement reshapes the value chain by introducing both new actors (ATPs) and new objects (agricultural data), thereby creating the principal area of impact for current European regulatory initiatives. “Upstream” of the use of Agriculture 4.0 machinery lies the regulation of agricultural data as a new element entering the agri-food supply chain, whose nature, ownership, and governance raise unprecedented legal questions. Initially, legal scholarship considered it crucial to define the legal status of agricultural data in order to determine the applicable regulatory framework (Versaci, 2024; Ferrari, 2024;Ferrari, 2023; Guarda,2023; Atik,2021; Ferrari, 2018). However, the mere classification of agricultural data within the traditional categories of personal data (a sdefined under Article 4(1) GDPR) or non-personal data (initially governed by Regulation (EU) 2018/1807) proved not only challenging in many cases (Brunoriet al., 2025; Atik &Martens, 2021), but also inadequate to fully reflect the distinctive characteristics and specific needs associated with agricultural data (Atik,2022). In practice, data sharing occurs primarily through a business-to-business (B2B) exchange between the agricultural enterprise and the ATP, governed by bilateral contracts concluded between the user (i.e., the agricultural enterprise, pursuant to Article 2(12) Data Act) and the data holder (i.e., the ATP, pursuant to Article 2(13) Data Act). These contractual relationships are often characterized by a significant imbalance in bargaining power to the detriment of farming enterprises. The overarching risk is that farmers may progressively lose control over the data generated through their farming activities, with all the distortions that may follow. These includete chnological dependency on the provider due to a lack of interoperability (theso-called digital lock-in; Guarda,2023), as well as a complete loss of trust in the use of new technologies. Such outcomes risk further exacerbating the widespread phenomenon of the digital divide—understood as disparities in access to and use of digital technologies (D’Avanzo, 2022)—and, inevitably, slowing down the digitalization of the agricultural sector.

 

3.Looking Beyond the EU: Soft Law Instruments

 

The debate gradually shifted from the legal nature of agricultural data to the configuration of the rights and prerogatives associated with them. Even before the adoption of the most recent European regulatory instruments, sector-specific soft law initiatives emerged with the aim of governing the circulation of agricultural data irrespective of the distinction between personal and non-personal data. These initiatives developed on a global scale, reflecting a growing interest in establishing data governance rules for the agricultural sector. Within the European context, a key referenceis the EUCode of Conduct on Agricultural Data Sharing by Contractual Agreement. At the international level, noteworthy examples include the Privacy and Security Principles for Farm Data adopted in the United States in 2014 and updated in 2024, as well as other codes of conduct developed outside Europe, such as New Zealand’s FarmData Code of Practice and Australia’s FarmData Code. These initiatives are complemented by broader projects, such as the GlobalOpen Data for Agriculture and Nutrition (GODAN), which promote data-sharing models oriented towards openness and innovation while maintaining an appropriate balance with the protection of privacy, security, and economic interests. From a substantive perspective, the principles underpinning these soft law instruments are largely inspired by the protection model established by the GDPR for personal data. They create a direct link between rights over data and the party generating them, namely the agricultural operator. In this framework, rather than establishing a genuine property rightover data, data ownership is generally understood as the right to determine whomay access and use the data (Ferrari, 2018). The data originator, according to the definition adopted by the European Code of Conduct as well, is the subject entitled to exercise these prerogatives. Nevertheless, it would be inaccurate to speak of ownership in the strict sense, since the Code itself clarifies that data cannot be the object of a property right in the same way as tangible goods. In this respect, there is a partial divergence from the approach adopted in the United States, where a conception more closely aligned with the proprietary paradigm tends to prevail, according to which farmers are considered the owners of the information generated through their productive activities (Versaci, 2024). From an operational standpoint, the various codes of conduct converge in recognizing the central role of B2B contracts as the primary mechanism for regulating relationships between the parties, while assigning farmers a prominent position in determining the conditions governing access to and use of data. More specifically, the codes examined identify a common core of safeguards centred on the transparency of contractual terms, the agricultural operator’s control over data generated during production activities, limitations on third-party use, and the possibility of accessing, retrieving, and reusing collected information. Within this framework, data portability assumes a particularly important function, as it enables the data originator to obtain data concerning them in order to store them or use them within other systems, platforms, or storage infrastructures. Although the wording employed is not always identical, the various codes also display substantial convergence regarding the need to ensure forms of data exchange and reuse capable of preventing technological lock-in and fostering open digital environments. Interoperability, understood as the capacity of the same data to be effectively used for multiple purposes and across different contexts, consequently acquires significance not only from a technical perspective but also from a legal and economic one. It constitutes a necessary condition for ensuring that data circulation can translate into the actual creation of value for all actors involved. It is precisely in this respect, however, that the structural limitation of these voluntary “regulatory” initiatives becomes evident. They lack a sufficiently robust legal foundation capable of providing stable anchoring for the rights they recognize, leaving them vulnerable to divergent interpretations and uneven implementation. This is compounded by thefact that their effectiveness depends entirely on the voluntary adherence of the parties, which may freely choose whether or not to incorporate them contractually. Their soft law nature therefore limits their ability to rebalance market dynamics and address the contractual asymmetries already highlighted, creating the risk that these codes of conduct may ultimately remain little more than programmatic declarations lacking genuine binding force(Atik& Martens, 2021; Ryan etal., 2024). Consequently, there emerges a need for a different regulatory design—one that is sufficiently flexible while simultaneously grounded in law, capable of overcoming these shortcomings and providing a coherent and genuinely effective framework for the governance of agricultural data.

‍

4.The New Frontier of the Data Act: Towards a Common European Agricultural DataSpace, a “Work in Progress” Made in the EU

 

While codes of conduct and other soft law instruments have played a valuable role in bringing the central challenges of agricultural data governance to the forefront, one of the most promising regulatory developments capable of overcoming their limitations is now represented by the European experiment of the Common European Data Spaces. Dedicated to fourteen different economic sectors, these initiatives form part of the broader European Strategy for Data and aim to create a genuine European single market for data, based on the free flow of information, respect for the rules and values of the European Union, and the establishment of fair, transparent, and workable conditions for data access and reuse. Within this framework, European data spaces can be understood as shared infrastructures and common governance frameworks designed to facilitate the pooling, access, and sharing of data in a secure, trustworthy, and non-discriminatory manner, while allowing data holders to retain control over the data they generate and the conditions governing itsreuse. Moreover, their architecture does not rely upon the centralization of data. Rather, it is oriented towards a federated and decentralized model based on interoperability, shared semantics, and common rules governing access and use (Vander Valk & Ryan, 2025). It is within this context that the Common European Agricultural Data Space (CEADS)emerges, having been explicitly announced by the European Commission as a European space dedicated to the trustworthy sharing of agricultural data among private actors and public authorities alike. At least in principle, its purpose is precisely to provide a structural response to the shortcomings already identified in B2B relationships within the sector: reducing informational and contractual asymmetries, strengthening trust in data sharing, preventing lock-in effects, promoting interoperability, and enabling agricultural operators to maintain effective control over the conditions governing access to, use of, and circulation of the data generated through their productive activities. The CEADS is therefore not merely a technical platform. Rather, it is conceived as a regulated environment in which infrastructure, markets, law, and behavioural standards interact to create a data-sharing ecosystem that is both efficientand trustworthy (Vander Valk & Ryan, 2025). The functioning of the CEADS is based on the interaction between the principal regulatory instruments underpinning the European Strategy for Data. The Data Governance Act performs an enabling function, seeking to create the trust conditions and infrastructures necessary for data sharing through the introduction of data intermediation mechanisms and governance models. The Data Act, by contrast, operates at the substantive level by regulating access to and use of data, including in business-to-business relationships, and by contributing to the rebalancing of the contractual asymmetries that characterize the agricultural sector through the imposition of rules deriving from a supranational hard law instrument. For this reason, the Data Act constitutes an essential legal foundation for the development of the European agricultural data space (see Chapter VIII of the Data Act, dedicated to interoperability, and in particular Article 33, entitled “Essential requirements regarding interoperability of data, of data sharing mechanisms and services, as well as of common European data spaces”). At the same time,however, it does not by itself fully address the regulatory needs of the sector(Atik,2023). The specificity of the agricultural context continues to reveal issues requiring further adaptation, both at the definitional level and with regard to the substantive safeguards afforded to farmers (Brunoriet al., 2025). From this perspective, the CEADS still appears to be a project in consolidation rather than a fully accomplished governance framework. The European Commission itself, building upon the outcomes of the preparatory AgriDataSpace project, advocates a gradual and decentralized approach, developed from existing data-sharing initiatives and designed to place farmers’ interests at the centre of the governance of the common data space. The recommendations developed within that framework emphasize, inter alia, the need to introduce usage control mechanisms, safeguards for confidentiality, more flexible consent models, technical interoperability measures, mechanisms to prevent lock-in, coordinating bodies capable of aligning the GDPR, the DataGovernance Act, the Data Act, and sector-specific codes of conduct, as well aspotential certification systems and hybrid governance regimes combining market-based logics with the protection of collective interests (Vander Valk & Ryan, 2025). Ultimately, the CEADS currently represents the most advanced attempt to overcome the existing fragmentation of the regulatory landscape. It marks a transition from a system largely reliant on contractual arrangements and soft law instruments towards a model of multilevel governance, in which horizontal European regulation and the construction of federated data-sharing infrastructures may finally provide the agricultural sector with a more stable, transparent, and interoperable framework. Nevertheless, the decisive question remains whether, in the practical implementation of theCEADS—and therefore, in essence, of the Data Act itself—the European ambition of creating a “fair” data market will genuinely translate, also in the agricultural sector, into a meaningful strengthening of the position of agricultural enterprises and a more balanced distribution of the economic and social value generated by data. From this perspective, the Data Act constitutes a new testing ground for assessing whether sovereignty over agricultural data can find, within the European Union legal order, a form of protection that is not merely proclaimed, but genuinely capable of being exercised in practice.

‍

© 2025 Food For Future. All rights reserved.
Informativa PrivacyCookie PolicyInformativa Mailing List