EU Data Act — fair access to and use of data.
The EU's new horizontal rules on who can access, share, and switch data generated by connected products, related services, and cloud platforms. Personal and non-personal data alike.
Four sweeping changes to how EU data works.
Connected-product data
Users of connected products (cars, machines, appliances, wearables) and related services get the right to access the data they generate — easily, free of charge, and in machine- readable form. Manufacturers must design products to enable this access.
B2B data sharing
Data holders must share product and service data with third parties at the user's request. Compensation must be non-discriminatory and FRAND (fair, reasonable, non-discriminatory). Unfair contract terms void.
Cloud and edge switching
Cloud providers must enable customers to switch to a competitor or move data on-premises. Switching charges are being phased out: 50% reduction from 2024, full elimination by January 2027. Mandatory contract terms.
B2G data access
Public-sector bodies can request data from private holders in defined exceptional circumstances — public emergencies, statutory tasks. Tight conditions, time-limited use, purpose-bound.
Who needs to act?
Penalties
Member States set their own penalty regimes. Breaches involving personal data attract GDPR-level fines — up to €20M or 4% of global annual turnover. Non-personal-data breaches face effective, proportionate, and dissuasive sanctions at national level. Plus civil liability for unfair contract terms and FRAND violations.
How ComplyOne handles the Data Act.
Data Act — quick answers
When does the Data Act start applying?⌄
The Data Act entered force on 11 January 2024. Most provisions apply from 12 September 2025 — including the connected-product design obligations and the right of users to access their data. Cloud-switching charge reductions phase in: a 50% reduction from January 2024, then full elimination of switching charges from January 2027.
Does the Data Act apply to my company?⌄
If you (a) manufacture connected products (anything from cars and machinery to smart appliances and wearables) sold in the EU, (b) provide related services to those products, (c) act as a data holder under the Regulation, or (d) operate a cloud or edge service, yes. Pure software-only B2C apps with no IoT element are largely out of scope.
How does the Data Act interact with GDPR?⌄
The Data Act applies to all data — personal and non-personal. Where personal data is involved, GDPR continues to apply in full and prevails on conflict. The Data Act is additive: it gives users access rights to non-personal product data that GDPR doesn't reach, and creates B2B-sharing obligations that GDPR doesn't cover.
What are the penalties?⌄
Member States set their own penalty regimes. For breaches involving personal data, GDPR-level penalties apply (up to €20M or 4% of global annual turnover). For non-personal-data breaches, expect effective, proportionate, and dissuasive sanctions at national level — usually similar in scale.
Get your Data Act readiness score.
See where you stand against the connected-product, B2B sharing, cloud-switching, and B2G access rules — in minutes.