From Satellites to Data: How the Cyprus Presidency Compromise Redraws the EU Space Act’s Downstream Reach

The EU Space Act has largely been discussed as a regulatory framework for satellites, launches and space infrastructure. The Cyprus Presidency Compromise text, however, places considerably greater emphasis on what those assets ultimately produce: space-based data.

This shift matters well beyond the traditional space sector. Satellite-generated information supports communications, Earth observation, navigation, logistics, agriculture, insurance, energy and an increasing number of data-driven and AI-based services. The compromise text seeks to prevent space operators from avoiding the EU Space Act’s requirements by operating from a third country while continuing to supply the same data to the European downstream economy.

It therefore introduces a targeted system of data provenance and market access. Certain providers may supply space-based data in the Union only if the underlying space activities are entered in the Union Repository of Space Activities (URSA) and carry a valid electronic certificate.

The text remains under negotiation. All Member States maintained scrutiny reservations during the Cyprus Presidency, and questions concerning scope, governance, dual-use activities and the treatment of third-country operators remain open. Nevertheless, the compromise already indicates how the EU Space Act could extend from the regulation of space infrastructure into selected downstream markets.

What “space-based data” means

The compromise text defines space-based data as raw or processed data originally received from a space object in outer space, including data resulting from the interception or transmission of a signal generated by a space object.

The definition is broad enough to cover more than the initial satellite feed. It may include processed Earth observation data and satellite communications data as they move through the value chain. Its outer limits are less clear, however. In particular, the text does not fully resolve when space-derived information that has been combined with substantial non-space inputs or transformed into a distinct analytical product ceases to qualify as space-based data.

This distinction will be relevant for platforms that aggregate satellite imagery, analytics providers that combine Earth observation data with terrestrial sources and AI applications whose outputs are based partly – but not exclusively – on satellite-derived inputs.

From “primary providers” to functional gatekeepers

The Commission’s original proposal focused on “primary providers of space-based data”. This was a technically defined category covering providers initiating the first processing of space-based data that was sufficient to enable its subsequent provision. It included electronic communications providers in relation to communications data and providers carrying out the first processing of observation data.

The Cyprus Presidency compromise takes a different approach. Its operative provisions refer more broadly to a “space-based data provider”: any natural or legal person, including an international organisation and irrespective of whether it is established in the Union or a third country, that provides the service of providing space-based data.

This broader definition does not mean that every company using or passing on satellite-derived information is subject to the new obligations. Article 23a applies only where providing space-based data is the sole service or a decisive part of the service. It does not apply where the data are merely ancillary or one of several sources used to produce another service. Provision for purely research or educational purposes is also excluded.

The recitals illustrate the distinction. Satellite communications services, Earth observation data platforms and maps services incorporating satellite imagery may fall within scope. By contrast, satellite imagery used only for illustrative purposes or a weather service based mainly on non-space data would not.

The compromise therefore replaces the Commission proposal’s technically defined entry point into the downstream chain with a more functional test: does the provider act as a gatekeeper between the space economy and the market for space-derived data?

Article 23a: a market-access rule for space-based data

The central provision is Article 23a. It would permit space-based data providers to supply data within the Union only where the data were generated by a space object whose activities are entered in URSA and carry the relevant e-certificate. Data generated by space activities expressly excluded from the Regulation’s scope would also remain eligible.

The compromise does not comprehensively regulate ownership of satellite data, access rights, licensing models or the allocation of rights in downstream analytical products. Instead, it connects the lawful provision of certain space-based data in the Union to the regulatory status and traceability of the activities through which those data were generated.

The mechanism is intended to close a potential circumvention route. Without it, an operator could avoid the EU Space Act’s safety, resilience and sustainability requirements by operating from outside the Union while continuing to commercialise the resulting data in the internal market. Article 23a makes the provenance of the data a condition for access to that market.

URSA and the e-certificate: compliance follows the data

The compromise also strengthens the data-level function of the e-certificate.

The Commission proposal already linked the certificate to an identifiable space mission and space object and required it to support the tracking of observation data through the first service using those data. It also required providers to possess the certificate when first supplying space-based data or space services in the Union and to annex it to the relevant contracts.

Under the Cyprus Presidency compromise, the European Union Space Programme Agency would issue an e-certificate for each space activity entered in URSA. Together, the URSA entry and the valid certificate would attest compliance of the underlying space activity with the Regulation.

The certificate would identify the mission and space object through which the data were generated. For observation data, it would enable tracking from generation by the space object to incorporation into the service using the data. It would also rely on algorithms to ascertain the compliance of the relevant space activity as the data are incorporated into subsequent services. The recitals further envisage embedding the certificate in the metadata of the space-based data.

At the same time, the blanket requirement in the Commission proposal to annex the e-certificate to each relevant contract no longer appears in the same form. The emphasis shifts towards a machine-readable provenance mechanism intended to accompany the data through the downstream chain.

Many technical questions remain unresolved. The practical operation of the system will depend on standards addressing the certificate’s structure, interoperability, traceability and integration into downstream products. Nevertheless, the direction is clear: compliance would not merely be demonstrated by a credential held by the initial provider. It would become an attribute intended to remain verifiable as the data move through the market.

Third-country reach: two distinct levels of obligation

The compromise has explicit effects outside the European Union. It applies to third-country space operators and space-based data providers where they provide the relevant data or services in the Union. An establishment in the EU is therefore not required.

The consequences must, however, be distinguished at two levels.

First, a third-country space operator whose activities generate data intended to be supplied in the Union must obtain the relevant EUSA registration. Once registered, its space activities are entered in URSA and receive the corresponding e-certificate. Such operators must also appoint one or more legal representatives in the Union with the authority and resources required to cooperate with the Commission and the competent authorities.

Second, a downstream data provider established outside the Union may itself be subject to Article 23a when it supplies space-based data in the Union. A provider that does not operate a satellite or otherwise conduct space activities will not necessarily have activities of its own to register. Its principal obligation is instead to ensure that the data it supplies originate from qualifying space activities entered in URSA and carry the required certificate.

This distinction is particularly relevant for non-European data platforms, distributors and resellers. A US-based Earth observation marketplace, for example, may be directly subject to the market-access rule without itself being the operator responsible for registering the underlying satellite activities.

The precise meaning of providing data “within the Union” remains to be clarified. Offering or supplying the relevant data to customers located in the Union is likely to establish the necessary internal-market connection, but the compromise does not yet set out a detailed targeting test.

An equivalence mechanism may facilitate access for operators established in third countries whose regulatory systems offer comparable protection. Even under such a mechanism, however, the relevant space activities must be linked to the URSA and e-certificate architecture.

Public procurement as a compliance multiplier

Article 23a also contains a provision with potentially significant supply-chain effects.

Central government authorities listed under the EU public procurement framework, as well as Union institutions, bodies and agencies, would have to ensure that space-based data used in the services they procure were generated by space activities entered in URSA and carry an e-certificate.

The formal obligation is addressed to the procuring public bodies. In practice, however, it is likely to be passed down contractually to their suppliers. Providers may be required to document data provenance, maintain certification evidence, impose corresponding obligations on subcontractors and permit contractual audits.

The effects may therefore extend to businesses that do not themselves qualify as space-based data providers. An IT contractor, analytics company or systems integrator supplying a public authority may need to establish where the satellite-derived inputs incorporated into its service originated and whether the underlying activities meet the URSA requirements.

Public procurement could consequently become a major compliance multiplier, carrying the EU Space Act’s provenance rules into second- and third-tier contractual relationships.

Emergency use remains narrowly confined

The compromise contains a limited emergency clause. Where a natural or man-made disaster or a significant incident causes disruption affecting one or more Member States or Union institutions, the affected public bodies may temporarily use data or services deriving from activities not entered in URSA.

The relevant Member State or Union institution must inform the Commission, and the Commission assesses the proportionality and effectiveness of the use and its duration. The provision therefore acts as a narrowly framed public-interest safety valve rather than an alternative route to the EU market.

What this means for companies

The most immediate impact will be felt by Earth observation platforms, satellite communications providers, data distributors and other businesses whose core service consists of supplying satellite-derived information.

They will need to determine whether providing space-based data is the sole or a decisive part of their service. Where it is, they will need processes to verify the identity of the underlying space object, confirm that the relevant activities are entered in URSA and preserve the connection between the data and the corresponding e-certificate.

Businesses whose services combine satellite data with other inputs face a more difficult classification exercise. The decisive questions will include the role of the satellite-derived information in the overall service, whether customers are effectively purchasing the data themselves or a distinct analytical output, and whether the space-based data remain identifiable within the resulting product.

Contracts will also require attention. Data supply and licensing agreements may need warranties regarding provenance and registration, obligations to preserve metadata, notification duties following suspension or withdrawal of certification, audit rights and termination mechanisms where data can no longer lawfully be supplied. Public-sector contracts are likely to require corresponding flow-down provisions throughout the supply chain.

For investors and purchasers, URSA status, certification and data provenance may also become part of regulatory due diligence, particularly where the target’s core products depend on third-country satellite operators or data suppliers.

These obligations would be backed by enforcement powers rather than operating as purely documentary requirements. The compromise provides for corrective measures, public notices and fines. At Commission level, the maximum fine may amount to twice the profits gained or losses avoided through the infringement or, where those amounts cannot be determined, 2 % of worldwide annual turnover.

Abstrakte, diagonale Linien in unterschiedlichen Grüntönen

Conclusion

The Cyprus Compromise does not transform the EU Space Act into a comprehensive law governing the space data economy. Its approach is more targeted. It uses provenance, certification and market-access requirements to connect selected downstream providers to the regulatory compliance of the space activities on which their data depend.

The compromise moves from the technically defined concept of a primary provider to a broader but functionally limited category of space-based data providers. It strengthens the e-certificate as a data-level and potentially machine-readable compliance mechanism. And it establishes a differentiated third-country regime under which both non-EU operators and downstream providers may face obligations when serving the European market.

Companies relying on satellite-derived information should therefore begin mapping their data sources and supply chains. They should assess whether their services fall within Article 23a, whether the underlying activities are capable of being entered in URSA and how certification requirements would affect their contracts, procurement processes and operational resilience.

European space regulation may begin with activities in orbit. Under the Cyprus Presidency compromise, however, it would increasingly follow the data back to Earth.

Companies affected by the emerging framework should begin mapping their data sources, supplier dependencies and contractual relationships. Whether you are a space operator, data provider, technology company, investor or downstream user of satellite-derived information, we advise on scope assessments, compliance strategies, contractual implementation and regulatory due diligence.