The EU Data Act entered into force on 11 January 2024 with a 20-month transition period before full application. Two key compliance deadlines apply — September 2025 and September 2027 — with different obligations attaching to each date.
Timeline at a Glance
| Date | Event | Who Is Affected |
|---|---|---|
| 11 January 2024 | Data Act enters into force | All — start of transition period |
| 12 September 2025 | Full application | All in-scope companies |
| 12 September 2027 | Egress fee elimination | Cloud service providers |
11 January 2024: Entry Into Force
The Data Act was published in the Official Journal of the EU on 22 December 2023 and entered into force on 11 January 2024. This triggered the 20-month transition period before the Act becomes legally binding on in-scope companies.
What this date means practically:
- The 20-month transition period for compliance preparation begins
- Companies should begin scoping exercises, contract reviews, and product design assessments
- Member states begin designating competent authorities and preparing national enforcement frameworks
12 September 2025: Full Application
From 12 September 2025, all Data Act obligations apply to in-scope companies. No grace period; no further transition. Companies that are in scope and not compliant are potentially subject to enforcement from this date.
Obligations active from September 2025:
IoT manufacturers and related service providers:
- Connected products must provide data access by default
- Data must be accessible in a machine-readable format
- Third-party data sharing mechanisms must be operational
- Pre-purchase transparency disclosures must be in place
- Terms restricting user data access must have been removed
Cloud service providers:
- Contracts must not include lock-in provisions (these are void from this date)
- Data portability in standard formats must be supported
- Egress fees must be reduced to cost-of-transmission (not yet eliminated — that comes in 2027)
- Switching support processes must be in place
B2B data holders:
- FRAND terms must apply to commercial data sharing arrangements
- Purpose limitation obligations in B2B data sharing are active
- Trade secret provisions in data sharing agreements must be specific
Which products does this apply to? Products placed on the EU market from September 2025 onwards must comply. For products already in circulation before September 2025, the transition arrangement applies — but the Act's rights provisions for users are immediately applicable.
12 September 2027: Egress Fee Elimination
The most significant deferred obligation is the complete elimination of egress fees for cloud switching.
What changes on this date:
- Cloud service providers cannot charge customers any fee for downloading their data to switch to a competing provider
- This applies specifically to data transfer associated with switching — not to ongoing operational data transfer charges
The transition (September 2025 to September 2027): During this two-year window, cloud providers can still charge egress fees but must:
- Reduce them to the actual cost of data transmission (no profit margin permitted)
- Disclose the fee structure clearly in contracts and customer-facing documentation
- Not use the fee structure to create a practical barrier to switching
What providers should do now:
- Assess the revenue impact of egress fee elimination — some providers generate meaningful revenue from egress; this needs to be accounted for in 2025–2027 pricing strategy
- Update contracts to reflect the transitional fee structure (cost-based only) by September 2025
- Build the operational capability to provide zero-fee data export for switching scenarios before September 2027
Member State Enforcement Timeline
Member states are required to designate competent authorities and establish penalty frameworks. The pace of this varies:
- Some member states (Germany, France, Netherlands) will likely have enforcement frameworks in place close to the September 2025 date
- Others may take longer to complete national implementation
- Cross-border enforcement (where a provider is in one member state but the affected user is in another) follows the country-of-establishment principle for certain provisions
Enforcement is unlikely to be heavily active in the first months after September 2025 — authorities will focus on establishing their programmes and responding to complaints. But the risk is real from day one.
Relationship to Other EU Regulation Timelines
| Regulation | Key Deadline | Interaction with Data Act |
|---|---|---|
| EU AI Act | August 2026 (high-risk) | AI systems in connected products may face both AI Act and Data Act obligations |
| GDPR | Already in force | Personal data generated by connected products: GDPR and Data Act parallel |
| NIS2 | Already in force (October 2024) | Cloud providers subject to NIS2 as digital infrastructure; Data Act cloud rules are separate but complementary |
| CSRD | 2024–2026 phased | No direct interaction, but data centres subject to both EED (under CSRD) and Data Act cloud rules |
Compliance Preparation Schedule
By Q2 2025:
- Complete scope assessment — which provisions apply to your business?
- Product audit — do connected products support data access by default?
- Contract review — identify and remove void lock-in terms
By Q3 2025 (before September 12):
- Data access interfaces operational
- Third-party sharing mechanisms tested
- Updated contracts in place with customers
- Pre-purchase transparency disclosures live on product pages
By Q4 2025:
- First Data Act compliance review completed
- Compliance governance in place (owner, process, documentation)
By 2027:
- Egress fee elimination plan implemented
- Zero-fee data export for switching in production