The EU Data Act and GDPR both govern data rights in the EU, but they address fundamentally different problems, cover different types of data, and create different obligations. Understanding how they interact — and where the gaps are — is essential for compliance planning.
The Core Difference in One Sentence
GDPR governs how organisations process personal data about identified or identifiable individuals.
The Data Act governs access to and sharing of data generated by connected products and cloud services — whether that data is personal or not.
Both can apply to the same dataset simultaneously. A smart health monitor generates personal health data that is also product-generated usage data. GDPR governs the health data as personal data. The Data Act governs access rights to the product-generated data, which may overlap with the same information.
Side-by-Side Comparison
| Dimension | GDPR | EU Data Act |
|---|---|---|
| Data covered | Personal data only | Personal and non-personal data generated by connected products/services |
| Rights holder | Data subject (natural person whose data is processed) | User (any person or business using a connected product) |
| Obligation holder | Data controller/processor | Data holder (manufacturer, related service provider, cloud provider) |
| Core right | Access, rectification, erasure, portability | Access to product-generated data, right to share with third parties |
| Applies to | All organisations processing personal data | IoT manufacturers, related service providers, cloud providers, data holders |
| SME exemption | No | Micro/small enterprises exempt from IoT provisions (not cloud) |
| Enforcement | Data protection authorities (DPAs) | Market surveillance authorities (varies by member state) |
| Date of application | May 2018 | September 2025 |
Where They Overlap
Personal Data Generated by Connected Products
When a connected product generates personal data — a vehicle tracking location, a wearable recording heart rate, a smart meter recording energy consumption linked to an individual household — both GDPR and the Data Act apply simultaneously.
GDPR requires: Lawful basis for processing, privacy notice, data subject rights response, retention limits, data subject access requests.
Data Act requires: Data access by default through the product interface, ability to share product data with third parties on user instruction.
In practice: a user's right to access their data under GDPR (Article 15 subject access) and their right to access their product data under the Data Act are separate but parallel. A single request may engage both.
Data Portability
GDPR Article 20 gives data subjects the right to receive their personal data in a structured, commonly used, machine-readable format and to transmit it to another controller — where the processing is based on consent or contract.
Data Act creates a broader portability right for product-generated data — it covers non-personal data, applies regardless of the lawful basis for processing personal data, and applies to business users as well as individuals.
For IoT companies: a user's request to "give me all my device data" may engage both GDPR portability and Data Act access rights simultaneously.
Where They Diverge
Non-Personal Data
GDPR does not apply to non-personal data — anonymised data, aggregated data, operational data that cannot be linked to an individual. The Data Act explicitly extends data access rights to non-personal data generated by connected product use.
This means an industrial manufacturer's machine performance data (not linked to any individual) is outside GDPR scope but within Data Act scope if it was generated by a business customer's use of a connected product.
Business Users
GDPR rights belong only to natural persons. A company operating a fleet of connected vehicles has no GDPR rights as a corporate entity.
Under the Data Act, business users have data access rights — a manufacturing company operating connected machinery can demand access to the operational data generated by its use of that machinery. This is a genuinely new right with no GDPR equivalent.
Cloud Switching
The Data Act's cloud switching provisions (egress fee elimination, portability, functional equivalence documentation) have no equivalent in GDPR. GDPR Article 20 portability applies to personal data; the Data Act's cloud provisions apply to all customer data held by cloud providers.
Handling Requests That Engage Both Frameworks
When a user submits a data request that engages both GDPR and the Data Act:
- Identify which data elements are personal data — those engage GDPR Article 15 (subject access) and potentially Article 20 (portability)
- Identify which data elements are product-generated usage data — those engage the Data Act
- Personal data that is also product-generated data — both frameworks apply; ensure the response satisfies both
For organisations already running a GDPR data subject rights process: extend the process to handle Data Act requests. The timelines differ (GDPR: 1 month; Data Act: without undue delay, broadly similar), but the underlying data identification and retrieval processes are comparable.
Compliance Programmes: What to Add for the Data Act
If you already have a GDPR compliance programme, the Data Act requires additional elements:
- Data access interface: GDPR does not require products to provide access by default. The Data Act does. You may need to build product functionality.
- Third-party sharing mechanism: GDPR portability allows users to request data for themselves. The Data Act allows users to instruct you to share directly with a third party. This requires a different technical implementation.
- B2B data sharing terms: No GDPR equivalent. Data Act requires FRAND terms for B2B data access arrangements.
- Cloud switching provisions: No GDPR equivalent. Update cloud customer contracts.