What the Data Act is, and why it matters now
The EU Data Act is one of the most significant pieces of digital regulation that most companies have not yet read. It entered into force on 11 January 2024 and became applicable on 12 September 2025, which means its core rules are no longer on the horizon – they are live. Where the GDPR governs personal data, the Data Act governs the much larger world of data generated by connected products and digital services, and it rewrites who gets to access and use that data.
For businesses the change is practical, not abstract. If your company makes or sells connected products, offers a related digital service, or relies on cloud providers, the Data Act affects your contracts, your product design and your commercial model. This article explains what the Act does, who it applies to, where the obligations bite, and how to prepare without overreacting.
Who the Data Act applies to
The Act reaches a broad set of players. It covers manufacturers of connected products and providers of related services that generate data; data holders who control that data; users – whether consumers or businesses – who generate data by using those products; and providers of data processing services, which in practice means cloud and edge providers. Because so many modern products are connected and so many companies run on cloud infrastructure, the great majority of mid-sized and growth companies fall within its scope in one role or another.
Connected products and the user’s right to data
At the heart of the Data Act is a simple but far-reaching idea: the user of a connected product should be able to access the data that product generates, and to share it with third parties of their choice. A connected product can be anything from a vehicle or an industrial machine to a smart appliance or medical device. The data it produces in use can no longer be treated as the manufacturer’s exclusive asset.
In practice this means data should be made available to the user, and on the user’s request to a third party, easily and where relevant in real time. The design obligation that data be accessible by default is being phased in for connected products placed on the market after 12 September 2026, so manufacturers have a window to build access into new products rather than retrofitting it later.
Cloud switching: the end of vendor lock-in
The Data Act also takes direct aim at lock-in among cloud and other data processing providers. Providers must make it genuinely possible for customers to switch to another provider or to an on-premise solution, with mandatory contractual terms supporting the move and obligations to assist the transition. Switching charges are being reduced and are due to be removed entirely from 12 January 2027, after which providers may not bill customers for the switching process itself. For any company evaluating or renegotiating a cloud contract, this materially strengthens the customer’s position.
Fair terms for business-to-business data sharing
Where a data holder is required to share data with another business, the Act sets a fairness standard: the terms must be fair, reasonable and non-discriminatory, and any charge must be reasonable. A data holder may include a margin in what it charges, except where the recipient is a small or medium-sized enterprise or a not-for-profit research organisation, in which case it may recover costs only. The aim is to stop dominant data holders from using price or one-sided terms to block access that the law intends to enable.
The deadlines that still matter
Although the Act has applied since 12 September 2025, two later dates deserve attention. The obligation to design connected products so that data is accessible by default applies to products placed on the market after 12 September 2026. And the ban on cloud switching charges takes full effect from 12 January 2027. Companies that build these timelines into their product roadmaps and procurement cycles now will avoid a scramble later.
Practical example: the manufacturer caught off guard
Consider a company that manufactures connected industrial equipment and has always treated the operational data those machines generate as its own, using it to sell maintenance services exclusively. A business customer, relying on the Data Act, now asks for direct access to that data and wants it shared with an independent maintenance provider it prefers.
Under the old commercial logic the manufacturer would simply refuse. Under the Data Act it generally cannot: the user has a right to the data, and to have it shared with a third party on fair terms. A company that has not adjusted its contracts, its data architecture or its pricing model finds itself both exposed to a legal obligation it did not plan for and at risk of losing a service revenue stream it assumed was protected. The companies that prepare turn the same change into an opportunity, designing new services around data access rather than around withholding it.
Common mistakes companies make
The first mistake is assuming the Data Act is just another data-protection rule and therefore already handled by GDPR compliance. The two regimes overlap but are different; the Data Act is about access to and sharing of data, much of it non-personal, and GDPR work does not cover it.
The second mistake is leaving it to the legal team alone. The Act touches product design, engineering, commercial strategy and procurement, and a purely legal response will miss the operational changes it requires. The third mistake is waiting for the 2026 and 2027 deadlines before acting, when the core obligations already apply and product and contract decisions made now will be hard to unwind later.
Recommended actions
Start by working out which roles your company plays under the Act – manufacturer, data holder, user, cloud provider or several at once – because your obligations follow from that. Map the connected products and services you offer and the data they generate, and review your customer contracts and cloud agreements against the new requirements on access, sharing and switching.
Then plan for the phased deadlines: build data accessibility into the design of products you will place on the market after September 2026, and use the switching rules to your advantage when negotiating cloud contracts ahead of January 2027. Above all, treat the Data Act as a cross-functional project involving legal, product and commercial teams, and document the decisions you take so you can show a considered approach.
Frequently asked questions about the EU Data Act
Is the Data Act the same as the GDPR?
No. The GDPR governs personal data and privacy; the Data Act governs access to and sharing of data generated by connected products and services, much of which is not personal. They can apply to the same dataset, but compliance with one does not mean compliance with the other.
Does it apply to us if we only use connected products and cloud services?
Very likely yes, as a user. The Act gives users rights to the data their connected products generate and strengthens their position when switching cloud providers. Even purely as a customer, the Act works in your favour and is worth understanding.
When did the Data Act start to apply?
The core rules have applied since 12 September 2025. The product-design accessibility obligation applies to connected products placed on the market after 12 September 2026, and the ban on cloud switching charges takes full effect from 12 January 2027.
Can we still charge for sharing our data?
Where you are required to share data with another business, you can charge, but the terms and price must be fair, reasonable and non-discriminatory. If the recipient is an SME or a not-for-profit research organisation, you may generally recover only your costs.
Conclusion
The EU Data Act has quietly become one of the most consequential rules for any company that builds connected products, sells digital services or depends on the cloud. It shifts control over machine-generated data towards users, opens up cloud markets and sets fairness standards for data sharing – and its core obligations are already in force. The companies that treat it as a strategic question rather than a compliance afterthought will not only stay on the right side of the law but find new ways to compete in a more open data economy.
Lawgent helps companies understand where they sit under the EU Data Act, review their product and cloud contracts, and turn the new data-access and switching rules into an advantage rather than a risk. We combine experienced business-law advice with AI-driven efficiency, so you get clear, practical guidance faster and more cost-effectively than at a traditional firm. Want to know how the Data Act affects your products and contracts? Contact Lawgent for a review.