Back to blog

Textile Traceability Under the EU Data Act: Borrowing a Horizontal Framework

Textile Traceability Under the EU Data Act: Borrowing a Horizontal Framework

The EU Data Act establishes binding rules on who may access, share, and port data generated by connected products and related services. Those rules are horizontal: they apply across sectors, which means textile manufacturers, garment brands, and logistics operators handling IoT-tagged goods are already inside their scope. What does not yet exist is a dedicated EU sectoral data space for textiles. The Commission's programme names fourteen sectors; textiles is not among them. Any claim that a textile data space is 'live' or 'established' comes from research consortia and traceability vendors, not from an adopted Commission framework. This article maps what the Data Act actually requires, explains how the horizontal data-space architecture and GS1's EPCIS standard are being proposed as the connective tissue, and names what remains unresolved.

Key takeaways

  • The EU Data Act grants users of connected products the right to access data generated through their use, and obliges manufacturers to make that access technically possible — obligations that apply to smart textile machinery, RFID-tagged garments, and IoT sensors on production lines.
  • The Commission's Common European Data Spaces programme covers fourteen sectors; textiles is not one of them, and textile-specific data-space proposals remain at the research and pilot stage.
  • GS1's EPCIS standard is the most widely cited interoperability layer for moving traceability events between supply-chain parties, and it maps naturally onto the Data Act's requirement for 'timely and interoperable data access.'
  • The Ellen MacArthur Foundation's work on circular fashion identifies material-level traceability as a prerequisite for circular business models, reinforcing the policy pressure that makes Data Act compliance a strategic question, not merely a legal one.
  • Data architects and compliance leads should treat textile data-space proposals as a design reference, not a regulatory baseline, until the Commission formalises a sectoral programme.

What does the EU Data Act actually require?

The Data Act, adopted by the European Parliament and Council, clarifies rights and obligations around data generated by connected products and related services. Its core mechanism is straightforward: the entity that uses a connected product or service acquires a right to access the data that use generates. The manufacturer or service provider must ensure that right is technically exercisable — through secure, timely, and interoperable means.

For textiles, the practical scope is broader than it first appears. Consider:

  • Smart machinery on the production floor. Cutting tables, knitting machines, and finishing equipment increasingly embed sensors that log output parameters, defect rates, and energy consumption. Under the Data Act, the brand or manufacturer operating that equipment has a right to those logs, and the machine vendor must provide access.
  • RFID and NFC tags on finished goods. A garment carrying a chip that records custody events is a connected product. The retailer scanning that tag at goods-in, and the brand that specified it, both have legitimate claims to the data it holds.
  • IoT monitoring in logistics. Temperature and humidity sensors on shipping containers, or location beacons in warehouses, generate data that the Data Act brings within scope.

The Act also introduces obligations around data portability and third-party sharing: a data holder may be required to share data with a third party designated by the user, under fair, reasonable, and non-discriminatory terms. Model contract clauses developed by the Commission are intended to reduce the transaction cost of negotiating those terms across supply-chain relationships.

What the Act does not do is specify the technical format in which data must be shared, the semantic vocabulary that must be used, or the governance structure of any cross-industry exchange. That is where the data-space architecture and existing standards enter the picture.

What are the Common European Data Spaces, and where do textiles fit?

The Common European Data Spaces programme is the Commission's infrastructure initiative sitting alongside the Data Act. It provides reference architecture, building blocks, semantics, and interoperability specifications that sector-specific data spaces can adopt. The fourteen sectors currently in scope include health, mobility, energy, agriculture, finance, and manufacturing, among others. Textiles is not named.

This distinction matters operationally. A sector with a designated data space benefits from Commission-backed governance models, funded pilot infrastructure, and a shared semantic layer. Participants in those spaces have a clearer path to compliance and interoperability. Textile supply-chain actors do not have that clarity yet. They can draw on the horizontal building blocks — identity management, access control, usage policy enforcement, and connector specifications developed under the IDSA (International Data Spaces Association) and Gaia-X frameworks — but they must assemble those blocks themselves, without a sector-specific governance body to arbitrate disputes or maintain a shared vocabulary.

Research consortia funded under Horizon Europe have proposed textile data-space architectures, and several traceability vendors market solutions described as 'data-space ready.' Those proposals are worth studying as design references. They should not be cited in a compliance audit as evidence of an established regulatory framework, because they are not one.

How does GS1 EPCIS fit into this picture?

GS1's EPCIS standard — the Electronic Product Code Information Services specification — is the most mature interoperability layer available for supply-chain traceability events. It captures the 'what, when, where, why, and how' of products and assets as discrete events: an object event records that a specific item was observed at a specific location; a transformation event records that input materials became an output product; an aggregation event records that items were packed into a container.

EPCIS has several properties that make it a natural candidate for textile traceability under the Data Act:

  1. Standardised semantics. Trading partners share a common vocabulary for describing custody transfers, location changes, and process steps. This directly addresses the interoperability requirement the Data Act places on data holders.
  2. Granularity. Events can be recorded at the item level (a single garment identified by its EPC), the batch level, or the shipment level. A Digital Product Passport that must carry fibre composition, country of origin, and certification data can be anchored to an EPCIS event stream.
  3. Sensor data support. Recent versions of the standard include support for sensor data and process certifications within event messages, which covers IoT-generated data from production equipment.
  4. Existing adoption. EPCIS is already deployed in food, pharmaceutical, and logistics supply chains. Textile manufacturers with existing GS1 infrastructure can extend it rather than build from scratch.

The gap is governance, not technology. EPCIS tells you how to structure a traceability event; it does not tell you who is entitled to query your event repository, under what conditions, or what happens when a supplier refuses to share. Those questions are answered by the Data Act's access-right provisions and, eventually, by the governance layer of whatever data space textile actors construct.

What does the Ellen MacArthur Foundation's circular-fashion work add to this?

The Ellen MacArthur Foundation publishes research and policy recommendations aimed at accelerating the circular economy, with fashion and textiles as one of its three priority areas. Its work on circular fashion consistently identifies material-level traceability as a prerequisite: without reliable data on fibre composition, chemical treatments, and end-of-life options, sorting facilities cannot route garments efficiently, and brands cannot substantiate circular claims.

This reinforces the policy pressure behind the Data Act and the forthcoming Digital Product Passport requirements under the Ecodesign for Sustainable Products Regulation. Traceability data is not only a compliance obligation; it is the information substrate on which circular business models — resale, repair, fibre-to-fibre recycling — depend. A data architect designing a textile traceability system today should treat the Foundation's material-flow analysis as a requirements input, not merely as advocacy literature. The circular-economy case for granular, machine-readable traceability data is structurally aligned with what the Data Act's access and portability provisions make technically mandatory.

What are the unresolved problems?

Several questions remain open and should be named plainly rather than papered over.

Scope at the tier-2 and tier-3 supplier level. The Data Act's obligations attach to manufacturers of connected products. A spinning mill in a third country operating conventional (non-IoT) equipment is not directly in scope. Traceability schemes that require fibre-origin data from that mill must rely on contractual obligations and voluntary disclosure, not on the Data Act's access-right mechanism. The standard is only as strong as its weakest connected link.

Trade-secret carve-outs. The Data Act includes explicit protections for trade secrets. A supplier can resist sharing data that would reveal proprietary process parameters. Textile supply chains involve genuinely sensitive manufacturing know-how — yarn twist rates, finishing chemistry, dye formulations — and the boundary between legitimate trade-secret protection and obstruction of traceability obligations will be contested.

Semantic alignment across tiers. EPCIS provides a structure; it does not mandate the controlled vocabularies that populate that structure. Two suppliers can both claim EPCIS compliance while using incompatible codes for the same fibre type. A textile data space would need to maintain a shared vocabulary — a task that requires ongoing governance investment.

Cross-border enforcement. The Data Act applies to data generated in the EU and to products placed on the EU market. Enforcement against a non-EU manufacturer that refuses to provide access to data generated by its equipment is legally complex. The extraterritorial reach of the Act's provisions is still being tested.

Interaction with GDPR. Where traceability data is linked to identifiable natural persons — artisan producers, individual workers recorded in audit logs — GDPR's lawful-basis requirements apply alongside the Data Act. The two frameworks are not always easy to reconcile in practice, particularly for small producers who are both data subjects and data holders.

A practical checklist for data architects and compliance leads

If you are responsible for a textile brand's or manufacturer's data architecture, the following steps reflect current best practice given the frameworks described above:

  1. Inventory your connected products and IoT endpoints. Identify every device or system that generates data through the use of a connected product or service. That inventory defines your Data Act perimeter.
  2. Map data flows to EPCIS event types. For each data-generating touchpoint, determine whether it produces an object event, a transformation event, or an aggregation event. This mapping is the foundation of an interoperable traceability architecture.
  3. Audit your supplier contracts for data-access clauses. The Data Act's model contract clauses, once published, should be incorporated. In the interim, ensure your supplier agreements do not inadvertently waive access rights the Act grants you.
  4. Identify trade-secret boundaries proactively. Work with legal counsel to define which data elements are legitimately protected and which must be shared. Document that analysis before a dispute arises.
  5. Track the Digital Product Passport rulemaking. The DPP requirements under the Ecodesign for Sustainable Products Regulation will specify minimum data fields for textile products. Align your EPCIS implementation with those fields as they are published in delegated acts.
  6. Monitor the data-space building blocks. The horizontal connectors and access-control specifications being developed under IDSA and Gaia-X are the most likely technical substrate for any future textile data space. Piloting them now reduces integration risk later.
  7. Engage with research consortia. Horizon Europe-funded textile traceability pilots are generating design patterns and governance models that will inform any eventual Commission programme. Participation or close observation is a low-cost way to influence the outcome.

FAQ

Is there an EU data space for textiles? No. The Commission's Common European Data Spaces programme names fourteen sectors; textiles is not among them. Proposals for a textile data space come from research consortia and industry pilots, not from an adopted Commission framework. Treat them as design references, not regulatory baselines.

Does the EU Data Act apply to my garment factory today? It applies if your factory uses connected products — IoT-enabled machinery, RFID infrastructure, sensor-equipped logistics equipment — that generate data through their use. If your production equipment is conventional and non-networked, the Act's direct obligations are limited, though contractual obligations from downstream brands may extend its practical reach.

What is EPCIS and why does it matter for compliance? EPCIS is GS1's standard for capturing and sharing supply-chain traceability events. It provides the structured, interoperable format that the Data Act requires data holders to support. Implementing EPCIS positions you to meet access and portability obligations without building bespoke integrations for each trading partner.

How does the Digital Product Passport relate to the Data Act? The Digital Product Passport, mandated under the Ecodesign for Sustainable Products Regulation, will require specific data fields to be accessible throughout a product's lifecycle. The Data Act's access-right provisions create the legal mechanism for moving that data between parties. The two instruments are complementary: DPP defines what data must exist; the Data Act governs who can access it and on what terms.

Can a supplier refuse to share traceability data by claiming trade secrets? Yes, within limits. The Data Act includes explicit trade-secret protections. A supplier can resist sharing data that reveals proprietary process parameters. However, that protection is not absolute and cannot be used to frustrate the core access rights the Act grants. The boundary will be determined through enforcement and, eventually, case law.

What should I do now if a textile data space does not yet exist? Build on the horizontal building blocks: implement EPCIS for event capture, adopt IDSA connector specifications for data exchange, and align your data model with the Digital Product Passport fields as they are published. A system built on those foundations can be enrolled in a future textile data space without architectural rework.

Further reading

Share this article:

Textile Traceability & EU Data Act: Data Spaces Explained