Skip to content
Regulation (EU) 2023/2854 · Most provisions applied 12 September 2025

EU Data Act — fair access to and use of data.

The EU's new horizontal rules on who can access, share, and switch data generated by connected products, related services, and cloud platforms. Personal and non-personal data alike.

Four sweeping changes to how EU data works.

Connected-product data

Users of connected products (cars, machines, appliances, wearables) and related services get the right to access the data they generate — easily, free of charge, and in machine- readable form. Manufacturers must design products to enable this access.

B2B data sharing

Data holders must share product and service data with third parties at the user's request. Compensation must be non-discriminatory and FRAND (fair, reasonable, non-discriminatory). Unfair contract terms void.

Cloud and edge switching

Cloud providers must enable customers to switch to a competitor or move data on-premises. Switching charges are being phased out: 50% reduction from 2024, full elimination by January 2027. Mandatory contract terms.

B2G data access

Public-sector bodies can request data from private holders in defined exceptional circumstances — public emergencies, statutory tasks. Tight conditions, time-limited use, purpose-bound.

Who needs to act?

Manufacturers of connected products sold in the EU
Providers of related services to connected products
Data holders under the Regulation (anyone with the right or obligation to use product data)
Cloud, edge, and platform-as-a-service providers
Recipients of data (third parties acting on the user's request)
Public-sector bodies acquiring data under B2G provisions
Designers of smart contracts for data sharing — interoperability rules apply
Non-EU manufacturers selling connected products into the EU

Penalties

Member States set their own penalty regimes. Breaches involving personal data attract GDPR-level fines — up to €20M or 4% of global annual turnover. Non-personal-data breaches face effective, proportionate, and dissuasive sanctions at national level. Plus civil liability for unfair contract terms and FRAND violations.

How ComplyOne handles the Data Act.

Data Act readiness assessment against Articles 3–24 — every requirement scored
Connected-product data inventory and classification (personal vs non-personal)
User-access mechanism review: format, timeliness, no-charge requirements
B2B data-sharing contract review against FRAND and unfair-terms rules
Cloud-switching contract terms audit — fee phase-out, transition assistance, parallel use
B2G data-request handling procedure and emergency-access playbook
Interoperability check for smart-contract data-sharing solutions
Personal-data interface with GDPR — joint controllership and basis tracking

Data Act — quick answers

When does the Data Act start applying?

The Data Act entered force on 11 January 2024. Most provisions apply from 12 September 2025 — including the connected-product design obligations and the right of users to access their data. Cloud-switching charge reductions phase in: a 50% reduction from January 2024, then full elimination of switching charges from January 2027.

Does the Data Act apply to my company?

If you (a) manufacture connected products (anything from cars and machinery to smart appliances and wearables) sold in the EU, (b) provide related services to those products, (c) act as a data holder under the Regulation, or (d) operate a cloud or edge service, yes. Pure software-only B2C apps with no IoT element are largely out of scope.

How does the Data Act interact with GDPR?

The Data Act applies to all data — personal and non-personal. Where personal data is involved, GDPR continues to apply in full and prevails on conflict. The Data Act is additive: it gives users access rights to non-personal product data that GDPR doesn't reach, and creates B2B-sharing obligations that GDPR doesn't cover.

What are the penalties?

Member States set their own penalty regimes. For breaches involving personal data, GDPR-level penalties apply (up to €20M or 4% of global annual turnover). For non-personal-data breaches, expect effective, proportionate, and dissuasive sanctions at national level — usually similar in scale.

Get your Data Act readiness score.

See where you stand against the connected-product, B2B sharing, cloud-switching, and B2G access rules — in minutes.