The EU Data Act entered into force on 11 January 2024 and will apply from 12 September 2025. It is the EU's most significant legislation on non-personal data — governing who can access, use, and share data generated by connected devices and related services. For IoT manufacturers, cloud providers, and SaaS companies with significant data holdings, the Data Act creates concrete obligations around data access, portability, and switching.
What Problem the Data Act Solves
Most data generated by connected devices — industrial sensors, smart appliances, vehicles, medical devices — is currently locked with the device manufacturer or service provider. The user who generates the data through their activity often cannot access it, share it with other services, or switch providers without losing it.
The Data Act is designed to fix this:
- Users should have the right to access data generated by their use of connected products
- Users should be able to share that data with third parties
- Cloud customers should be able to switch cloud providers without excessive barriers
- Businesses should be able to access data held by cloud providers in exceptional public interest situations
Who Does the Data Act Apply To?
Manufacturers of connected products (IoT):
- Smart appliances (washing machines, thermostats, cameras)
- Industrial equipment with sensors
- Connected vehicles
- Wearable devices
- Any product that collects and processes data about its use
Providers of related services:
- Digital services that accompany connected products (apps that read device data, cloud-connected device management)
Data holders offering data access to data recipients:
- Companies holding data generated by others and sharing it under business-to-business (B2B) arrangements
Cloud service providers:
- Providers of IaaS, PaaS, and SaaS
- Subject to switching and portability requirements
Public sector bodies:
- Rights to access private sector data in exceptional circumstances (Article 15)
Who is exempt:
- Microenterprises and small enterprises (under 50 employees, under €10M turnover) are exempt from most IoT data sharing obligations — but not from cloud switching rules
- B2C services that are not connected products are generally out of scope
Core Rights and Obligations
1. Data Access Rights for Users
Users of connected products have the right to access the data generated by their use of the product. This includes:
- All data generated by the product's operation
- Data transmitted to the manufacturer's cloud services
- Data necessary to use the product's full functionality
Access must be:
- By default (not requiring a special request for each access)
- Easily accessible — through the device interface or an app
- In a commonly used, machine-readable format
2. Right to Share Data with Third Parties
Users can instruct the data holder (typically the manufacturer) to share their data with a third party — another company offering competing or complementary services.
Example: A user of a smart heating system can instruct the manufacturer to share their energy usage data with an energy management service.
The third party can only use the data for the agreed purpose. They cannot sell the data or use it beyond the specified purpose.
3. Business-to-Business Data Sharing
Companies accessing data from manufacturers or other data holders under commercial arrangements must:
- Use the data only for the agreed purposes
- Not use it to develop competing products
- Not share it with further parties without authorisation
- Comply with trade secret protections
4. Cloud Switching Rights
Cloud customers have the right to switch providers without excessive barriers:
- Contractual terms that prevent switching or make it practically impossible are void
- Data portability in a standard format must be supported
- Egress fees for switching must be eliminated by September 2027 (a transition period applies)
Timeline
12 September 2025: Full application of the Data Act
12 September 2027: Egress fee elimination (cloud switching cost removed)
For IoT manufacturers and cloud providers: compliance activities must be completed by September 2025.
Why This Matters Now
The Data Act is receiving less attention than GDPR or the AI Act, but its commercial implications are significant — particularly for IoT manufacturers, cloud providers, and SaaS companies that hold large amounts of customer operational data. The data portability and switching requirements may affect product architecture, pricing, and competitive positioning.
Companies with connected products or cloud-centric business models should begin their Data Act compliance assessment now.