EU Data Act

What is the EU Data Act?

The EU Data Act is Regulation (EU) 2023/2854, the European rule on who can get at the data that connected products and cloud services produce, and on what terms. It entered into force on 11 January 2024 and has applied since 12 September 2025.

The regulation is about access. Plenty of usable data sits with whoever built the machine or runs the service, and the company that paid for the machine cannot reach it. The Data Act gives that company a right to the data and limits the contract terms it can be made to accept. It binds manufacturers and service providers selling into the EU wherever they are established, the users of those products, and cloud providers with EU customers (Article 1(3)).

Two obligations start later. The design duty in Article 3(1), which says a product must be built so its data is accessible by default, only covers connected products and related services placed on the market on or after 12 September 2026. The unfair contract terms rules in Chapter IV apply to contracts concluded after 12 September 2025, and from 12 September 2027 also to older contracts that run indefinitely or expire at least ten years after 11 January 2024.

The three parts that matter

The regulation has eleven chapters. Three carry the weight for a normal company.

Access to data from connected products (Chapter II). A connected product is an item that collects data about its use or environment and can communicate it, and whose main job is not processing data for somebody else: a machine on your production floor, a company van, a heat pump. Article 4 gives the user a right to the readily available data the product and its related service produce, with the metadata needed to interpret it, free of charge and in a structured, machine-readable format. Article 5 lets the user tell the data holder to send that same data to a third party the user picks, which is how an independent repairer gets the fault codes it needs.

Unfair contract terms in data deals (Chapter IV). Article 13 says a term about access to data, use of data, or liability around data obligations does not bind a company if another company imposed it unilaterally and it is unfair. It is a defence you can raise, not a form you file.

Switching cloud providers (Chapter VI). Providers of data processing services, so IaaS, PaaS and SaaS, have to clear the obstacles that keep a customer from moving to another provider or back on-premises, write switching clauses into the contract, and stop charging for the move.

Cloud switching, in the detail you need

Article 23 tells providers to remove pre-commercial, commercial, technical, contractual and organisational obstacles to switching, including obstacles to running two providers at once and to porting exportable data out.

Article 25 says what belongs in your contract.

  • A notice period to start a switch that runs no longer than two months.

  • A transitional period of 30 calendar days in which the provider helps you move. You can extend it once, and it can run up to seven months where 30 days is technically not feasible.

  • A window of at least 30 days after that in which you can still retrieve your data, followed by erasure.

  • An exhaustive list of which data categories are portable and which ones the provider cannot export.

Article 29 handles the money. Since 12 September 2025 a provider may only charge reduced switching charges that do not exceed the costs it directly incurs for that switch. From 12 January 2027 it may not charge for the switch at all. Article 2(36) names data egress charges inside the definition, so the fee for pulling terabytes out of object storage falls under the ban. Outside it: standard service fees, and early termination penalties the provider told you about before you signed.

Getting the data out of a packaging line

A Flemish food producer runs four packaging machines from two manufacturers. Vibration readings and cycle counts live in each manufacturer's portal as a dashboard and not much else, and the company wants them in its own warehouse.

Under Article 4 the company is the user and can ask for the readily available data through a simple electronic request. Readily available means data the manufacturer lawfully has or can get from the machine without disproportionate effort beyond a simple operation, which is a real limit and the first thing to test. What comes back is free of charge, machine-readable, and carries the metadata needed to read it. Under Article 5 the company can point the same stream at its own maintenance firm instead. The manufacturer may agree compensation with that firm under Article 9, reasonable and non-discriminatory, capped at the cost of making the data available if the firm is an SME. The user pays nothing, the third party may pay something.

Two things can still block it. The manufacturer can hold back specific data as a trade secret, but only under the conditions in Article 4, which means agreeing protective measures rather than simply refusing. And these machines were placed on the market years ago, so nobody had to design them for access by default. If a signal cannot be retrieved without rebuilding the firmware, the answer is no, and that is why the design duty from 12 September 2026 matters for the next machine you buy.

The Data Act and the GDPR are not the same law

The Data Act is not a data protection law and it does not replace the GDPR. They split on two questions.

What kind of data. The GDPR covers personal data, information about an identified or identifiable person, whoever holds it. The Data Act covers data generated by the use of a connected product or related service, and data held by a cloud provider. Most of that is a machine reporting on itself.

Who gets the right. The GDPR gives rights to the person the data is about. The Data Act gives them to the user of the product, and that user is usually a company. A company has no GDPR right of access to its supplier's records, because a company is not a data subject. Under the Data Act it has one.

They overlap when machine data is also about a person, a tracked van and its driver being the obvious case. Article 1(5) settles the tie: where the two conflict, data protection law wins. An Article 5 request to send driver-linked data to a third party still needs a lawful basis under the GDPR.

Where it touches an AI project

A predictive maintenance model needs a history of readings from the machine, and for most companies the reason that project never started is not the model, it is that the readings were locked in a supplier's portal. Article 4 turns "we cannot get the data" into a request with a legal answer, and the Commission's FAQ takes the view that only data generated after 12 September 2025 falls within Chapter II, so the clock on your history started then.

On the cloud side the effect is thinner than it sounds. Ending switching charges makes it cheaper to move the storage and compute under an AI workload, but it does not make a model or a prompt history portable, and whether a managed model API counts as a data processing service under Article 2(8) is not settled. The switching rules remove the exit toll. They say nothing about whether the AI stack itself is portable.

What to do about it, and what is still unsettled

As a buyer of equipment, ask before you sign. Article 3(2) already obliges the seller to tell you, before the sale, which data the product generates, in what format and volume, whether it comes continuously, where it is stored and for how long, and how you access, retrieve and erase it. Ask for that in writing and read it next to the price.

As a cloud customer, know what you are owed. Read your contract against Article 25: notice period, transitional period, retrieval window, and the list of what is portable. If exit fees ever shaped a renewal decision, they are gone from 12 January 2027. Under Article 41 the Commission also put out non-binding model terms for data sharing and standard clauses for cloud contracts, drafted with smaller parties in mind.

Expect the details to keep moving. Member States had to name competent authorities and a data coordinator, and not all managed it on time. In Belgium the federal coalition agreement puts supervision and coordination with the BIPT, with the Data Protection Authority keeping the personal data side. The Commission's Digital Omnibus proposal of November 2025 would also amend the Data Act itself, including exemptions from most of Chapter VI for contracts concluded on or before 12 September 2025, and that file was still in committee in the European Parliament in mid-2026. The dates above are the law today, and the Chapter VI ones are the likeliest to be rewritten.

Last Updated: September 4, 2026 Back to Dictionary
Keywords
eu data act regulation 2023/2854 gdpr data sharing agreement data sovereignty data residency cloud switching connected products ai act digital omnibus eu regulation compliance