The EU Data Act does not create a single centralised fine regime comparable to GDPR's €20M/4% global turnover cap. Instead, it establishes a framework under which member states set their own penalties — within minimum requirements set out in the Act — and designate competent authorities responsible for enforcement.
How Data Act Enforcement Works
The Data Act requires each EU member state to:
- Designate competent authorities to oversee compliance with different provisions
- Set effective, proportionate, and dissuasive penalties for violations
- Ensure penalties reflect the nature, gravity, duration, and intentional or negligent character of the infringement
Unlike GDPR, the Data Act does not mandate a specific maximum fine amount. Member states have discretion in setting their penalty frameworks — the Act requires only that penalties be effective and dissuasive.
This means:
- Fine exposure will vary by member state
- Enforcement priorities will differ across the EU
- Penalties are not yet fully determined in most jurisdictions (national implementing legislation is still being adopted)
Where the Data Act Does Set Specific Limits
Article 37: Penalties for GPDR-Competent Authorities
Where a Data Act violation also involves personal data, the relevant data protection authority (DPA) has jurisdiction over the personal data aspects. GDPR fines apply to personal data violations — up to €20M or 4% of global annual turnover.
The Data Act and GDPR enforcement overlap when:
- A manufacturer fails to provide a user with access to personal data generated by their device (violates both Data Act user rights and GDPR Article 15)
- A cloud provider prevents a customer from switching and withholds personal data (Data Act cloud switching + GDPR portability)
In these overlap cases, the more stringent framework applies — and GDPR's higher fine ceiling may govern.
Gatekeeper Regulation and Interplay
Where a company subject to the Data Act is also subject to the EU Digital Markets Act (DMA) or EU AI Act, those regulations' enforcement mechanisms sit alongside Data Act penalties.
What Authorities Can Do
While fine amounts vary by member state, the Data Act requires enforcement authorities to have powers to:
- Issue orders requiring compliance — mandatory corrective actions with deadlines
- Suspend data access arrangements that violate Data Act requirements
- Require contract modifications to remove void lock-in terms
- Prohibit data processing arrangements that breach the Act
- Impose periodic penalty payments — ongoing fines for continued non-compliance after an order
The practical enforcement tool in the short term is likely to be corrective orders rather than immediate financial penalties — authorities ordering companies to make data accessible, update contracts, or eliminate egress fees.
Enforcement Priorities to Expect
Based on the Data Act's structure and the regulatory environment:
Cloud switching violations are likely early enforcement targets. The egress fee elimination and contract lock-in provisions are specific, measurable, and commercially significant. A complaint-driven investigation is straightforward — a customer who cannot switch or faces disproportionate exit costs can demonstrate the violation clearly.
B2B data sharing FRAND violations will be investigated where businesses in dependent positions (e.g., aftermarket service providers who need manufacturer data to compete) complain that access is being denied or priced unfairly.
IoT access right violations will generate complaints from users denied access to their device data, particularly in consumer sectors where enforcement agencies have consumer protection mandates.
What the Data Act Explicitly Prohibits (Void Provisions)
Article 42 renders certain contractual terms automatically void. No enforcement action is needed for these to be unenforceable — they are void by operation of law:
- Terms that prevent users from accessing their product-generated data
- Terms imposing disproportionate exit penalties on cloud customers
- Terms containing technically complex notice periods that have no justification
- Terms that prevent customers from operating a parallel service during migration
A company relying on these terms in customer contracts cannot enforce them — and may face regulatory attention for having included them.
GDPR-Type Concerns: Where Large Fines Are More Likely
The highest Data Act-adjacent fine risk comes from the GDPR overlap:
If a connected product manufacturer systematically denies users access to their personal data (violating both Data Act user rights and GDPR Article 15), the GDPR enforcement mechanism applies. This is where the €20M/4% ceiling becomes relevant.
Similarly: a cloud provider that prevents a customer from recovering their personal data during a switch faces GDPR Article 20 portability enforcement, in addition to Data Act cloud switching obligations.
Practical Risk Management
Priority actions to reduce enforcement exposure:
-
Fix contracts now — remove void terms before they become the subject of a complaint. Contracts with lock-in provisions are an immediate and obvious enforcement target.
-
Build data access by default — the most common complaint pattern will be users denied access to their device data. Having a working access mechanism is your primary defence.
-
Document egress fee policy — show that you are on a trajectory to full compliance with the September 2027 deadline.
-
Respond to data access requests promptly — a failure to respond to a specific user request is the most direct path to enforcement.
-
Document your FRAND pricing rationale — if you operate a commercial B2B data sharing programme, document the basis for your pricing and terms so you can demonstrate they are reasonable and non-discriminatory.