At a glance
- Article 77(9) set 18 August 2026 as the date for the implementing act.
- The Commission roadmap now indicates Q4 2026 for the Batteries access-rights act.
- The act must specify who has a legitimate interest, which information they can access and the extent to which they may download, share, publish or reuse it.
- Current projects should therefore use configurable policies rather than hard-coded permissions.
What the Regulation already establishes
Article 77 separates public information, information for notified bodies/market surveillance authorities/the Commission, and information available to natural or legal persons with a legitimate interest for the purposes specified by the Regulation.
What the implementing act must clarify
- which persons qualify as having a legitimate interest;
- which Annex XIII information they may access;
- the extent to which they may download, share, publish or reuse that information;
- how commercially sensitive information is limited to the minimum necessary.
A roadmap date is not an automatic legal obligation
Q4 2026 is an indicative Commission timeline and remains subject to adoption and publication procedures. Access rules should therefore remain configurable.
Architecture controls to implement now
| Control | Why it matters |
|---|---|
| Role- and purpose-based access | Separates public, authority, verifier and authorised-party views. |
| Versioned policies | Allows rules to change when the act is adopted. |
| Audit log | Records who viewed, changed or authorised information. |
| Data minimisation | Limits exposure of commercially sensitive information. |
| Separate permissions | Viewing does not automatically imply downloading, sharing or reuse. |
The NexusDpp approach
NexusDpp treats access rights as a policy layer separate from the data. The same field can exist in the passport while visibility and permitted use change by role, purpose and regulatory version, avoiding duplicated data sets.