Skip to content
EU Data Act

How Software Vendors Should Prepare for the EU Data Act

5 min readUpdated 21 October 2026

Software vendors need to understand where they sit in the Data Act's framework before they can assess their obligations. Most software companies are not IoT manufacturers, but many provide software that connects to devices, manages device data, or operates as a cloud platform. Each position in the value chain creates different obligations under the Data Act.


Where Software Vendors Fit in the Data Act Framework

If You Build the Platform Behind a Connected Product

If your software is the cloud backend, management platform, or analytics engine for a connected physical product — and the product would not function or would lose core functionality without your software — you are likely a related service provider.

As a related service provider you must:

  • Enable users to access their product-generated data through your platform
  • Support data sharing with third parties on user instruction
  • Provide data in a machine-readable format
  • Not restrict user data access through contractual terms

If You Provide Cloud Infrastructure

If you operate a SaaS, PaaS, or IaaS platform where customers store significant amounts of data:

  • Cloud switching provisions apply
  • Customers must be able to export data in a standard format
  • Egress fees for switching must be reduced to cost by September 2025 and eliminated by September 2027
  • Contracts must not contain lock-in provisions

If You Are a Data Recipient in a B2B Arrangement

If your software consumes data shared from an IoT manufacturer or data holder under a commercial arrangement:

  • You must use the data only for the agreed purpose
  • You cannot develop competing products using the data
  • You cannot sub-licence or further share the data without authorisation

If You Build Pure SaaS with No Device Connection

If your software has no connection to physical connected products and you are not a significant cloud data holder:

  • The Data Act's IoT provisions do not directly apply
  • Cloud switching provisions may apply if you meet the cloud service provider definition
  • Your customers' Data Act compliance may flow obligations into your contracts (if you hold data for IoT manufacturers, for example)

Contract Review: What to Update

The Data Act renders void certain contractual terms — so a contract review is an immediate practical step for all software vendors.

Terms to remove:

  • Provisions that prevent customers from accessing or sharing their own data
  • Egress fee structures that go beyond cost recovery for data portability/switching
  • Minimum notice periods for termination that are unreasonably long
  • Restrictions on customers operating competing services in parallel

Terms to add or update:

  • Clear data export provisions: what data can be exported, in what format, under what process
  • Switching support obligations: how you support a customer through migration
  • Purpose limitation for B2B data sharing: if you share data with third parties under B2B arrangements, define permitted purposes
  • Trade secret provisions: if you need to protect specific data or algorithms from disclosure, document the basis

Technical Preparation

Data Export Capability

If you do not currently provide a structured data export in a machine-readable format:

  • Build a data export feature (JSON, CSV, or industry-appropriate format)
  • Cover the full dataset — all data the customer has stored in your platform, not just recent records
  • Make it accessible through self-service, not a support request

API for Third-Party Data Sharing

If your platform holds product-generated data that users may want to share with third parties:

  • Build or confirm an API that supports authorised third-party data access
  • Implement an authorisation mechanism — verify that requests are from authorised users before sharing
  • Log all sharing events for audit purposes

Data Format Documentation

If you use proprietary data structures:

  • Document what formats your exports use
  • Provide schema documentation so recipients can interpret the data
  • Assess whether your formats qualify as "commonly used and machine-readable" under the Data Act

B2B Customers in IoT Sectors

If your software customers include IoT manufacturers:

They will flow Data Act obligations into your contract. If your platform holds their customers' product data, your customer (the manufacturer) must ensure you can support their Data Act obligations. Expect:

  • Data Act addenda to existing DPAs
  • Requirements to provide data access interfaces for their end users
  • Audit rights related to Data Act compliance

Start talking to your IoT customers now. Many manufacturers are beginning their Data Act compliance programmes and will need to understand what data their software vendors hold and how it can be accessed.


Interaction with Existing GDPR DPAs

For software vendors who already have GDPR Data Processing Agreements in place with customers:

The Data Act creates parallel obligations that do not sit within the GDPR DPA framework. You may need:

  • A separate Data Act addendum addressing data access, export format, and switching support
  • Updates to your standard DPA to add Data Act provisions where personal data and product data overlap

A combined approach — a single data governance agreement covering GDPR processor obligations and Data Act obligations — is cleaner than separate documents. Your legal team should assess whether to combine or separate.


Checklist for Software Vendors

  • Map where your software sits in the Data Act framework: related service provider, cloud provider, B2B data recipient, or outside scope
  • Audit contracts for void terms (lock-in, egress penalties, data access restrictions)
  • Build or confirm structured data export capability
  • Implement API or self-service data access mechanism where needed
  • Document data formats used in exports
  • Review B2B data sharing terms for FRAND compliance and purpose limitation
  • Talk to IoT manufacturer customers about their Data Act compliance requirements

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →