EU Data Act – A New Regulatory Framework for the European Data Economy

On September 12, 2025, Regulation (EU) 2023/2854, better known as EU Data Act, one of the European Union's central digital laws, has come into force. Amidst the attention on the AI Regulation and NIS 2 implementation, this framework threatens to be almost forgotten. Yet, in practice, it is likely to have more far-reaching and immediate consequences for many companies – from mechanical engineers to cloud providers.

The Data Act aims to harmonize data access, data utilization, and interoperability across Europe. It affects not only personal data but also machine-generated and industrial data. Therefore, companies must reconfigure themselves not only in terms of data protection law but also contract law, technology, and strategy.

Starting situation and objectives

Currently, data from connected products (machines, vehicles, sensors, household appliances, medical and health devices, software-based services) often ends up in data silos. Manufacturers retain control, users have difficulty accessing „their“ usage data, and switching cloud providers is expensive or technically difficult (vendor lock-in). This slows down innovation, hinders competition, and prevents the creation of new services that build upon existing data. The Data Act aims to solve this bottleneck: more access, more switching options, clear rules – harmonized across Europe.

Key Content of the Regulation

  1. Access rights for users and authorized third parties

Users of connected products should be able to access the data generated by their use (Art. 4) – and may require the manufacturer („data owner“) to transmit this data to a third party (e.g., a service provider or an analysis platform) (Art. 5). This must happen without undue delay, in principle free of charge, and „where possible“ in real time. Legally important: From September 12, 2026, new products must be designed to enable this access by design (Art. 3).

  • Protection of trade secrets

A lot of usage data reveals something about the „inner workings“ of a product. The Data Act explicitly allows for the protection of trade secrets (cf. Art. 4(6) et seq., Art. 5(9) et seq.), but a blanket refusal of access is only permissible in exceptional cases. Companies must therefore classify in advance which data may potentially require confidentiality and define specific protective measures (access concepts, confidentiality agreements, logging, technical access restrictions, secure environments where applicable). Those who do not prepare anything here will have difficulty invoking the exception later.

  • Contract review

Since September 12, 2025, unfair contractual clauses in B2B data contracts are inadmissible (Art. 13). The regulation works with a „Black List“ (always inadmissible) and a "Grey List" (rebuttably inadmissible). At the same time, conditions must be fair, reasonable, and non-discriminatory ("FRAND"). The crux: reversed burden of proof – the data owner must prove in a dispute that their terms are not discriminatory. This significantly increases litigation risk and requires clean, documented pricing and terms logic. From September 2027, this framework will also apply retroactively in some cases to existing contracts with indefinite terms or very long remaining terms.

  • Cloud Switching and Interoperability

Customers should be able to switch seamlessly to other data processing services. Effective January 2027, the actual migration (data porting, technical switchover) will no longer be subject to pricing; reasonable fees for early termination (e.g., remaining contract term) will still be permitted. Furthermore, the Data Act requires interoperability: providers must meet defined standards so that services can collaborate or data can be used without special bridges – also relevant for Data Spaces and smart contract environments. Practical tip: review formats, APIs, identity/access models, exit procedures, and migration paths.

  • Public access in exceptional situations

In public emergencies (e.g., natural disasters) or when authorities cannot fulfill their duties otherwise, they may request data from the private sector. This must be interpreted narrowly but is operationally demanding: companies need processes to review such requests in a legally secure manner (authority, purpose, scope, relation to GDPR) and to fulfill them in a targeted way.

  • Relationship to GDPR and other laws

Once personal data is involved, the GDPR takes precedence. The Data Act supplements it, but does not replace it. In practice, obligations overlap with NIS-2, DORA, the Data Governance Act, and industry-specific regulations. This makes integrated compliance mandatory: data protection, information security, contract law, IP/trade secret protection, and product development must all be brought to the table.

Enforcement and Sanctions

Each Member State shall designate at least one supervisory authority. Companies with multiple EU establishments are subject to the authority in the location of their main establishment. Violations may be penalized—similar to the GDPR—with fines of up to €20 million or 4% of global annual turnover. Providers without an EU headquarters must appoint an EU representative. Experience shows that authorities will initially focus on providing guidance, but will later take targeted action if industries resist or if standard cases (e.g., missing interfaces, unfair terms and conditions) become frequent.

Legal assessment

From a business perspective, the Data Act is a paradigm shift: it shifts the balance of power away from pure manufacturer privilege towards user-centric data access. This opens up new business models (maintenance, analysis, third-party services) but increases compliance complexity. Legally, three points are particularly tricky:

  1. Interpretation of FRAND obligationsWhat is „fair“ and „non-discriminatory“ depends on the market environment, data types, and intended uses. Without documentation of the pricing and valuation logic, defense will be difficult.
  2. Confidentiality vs. Right of AccessThe exceptional nature of secrecy protection necessitates preventive protection. Those who do not define data classes, protection requirements, and access restrictions in advance will, in case of doubt, lose.
  3. Multilingual standard texts and unclear termsThere are editorial ambiguities between language versions and partly circular definitions. In tricky cases, the English version should also be checked, and Commission guidance should be considered without relying on it solely.

Recommendations for action for practice

Even if your company seems small: Systematically check if products or associated services (apps, portals, analytics, cloud hosting) are included. Then:

  • Gap AnalysisWhat data is generated? Where is it located? Who is the data owner? Who is the user? What third parties could be recipients? Are there already APIs/interfaces?
  • Product and Service DesignPlan for Data-Access-by-Design by September 2026 at the latest. Clarify formats, retrieval channels, authentication, logging, export bandwidths, and error cases.
  • Terms and Conditions/ContractsRevise data clauses along the black/grey list and the FRAND obligation. Define criteria for non-discriminatory pricing/usage terms and document them.
  • Confidentiality programImplement data classification (including non-personal data), define technical/organizational measures (access levels, secure rooms, template NDAs, audit trails), and establish a review process.
  • Cloud Strategy/Exit ReadinessTest portability in practice. Keep exit playbooks ready (data dumps, migration windows, mapping tables, compatibility list), and clarify which costs are permissible from 2027 onwards (early termination only, not the move itself).
  • Government inquiriesEstablish a clear process for quickly and legally soundly reviewing „exceptional need“ requests (authorization, scope, data minimization, GDPR primacy).
  • GovernanceForm an interdisciplinary team (Legal/Privacy, IT Security, Product, Procurement/Sales, IP) and anchor KPIs (Time-to-Data-Export, error rates, throughput, deadlines).

Conclusion

The Data Act marks the beginning of a new phase of European data regulation. While the AI Act primarily addresses ethical and security-related issues, the Data Act directly intervenes in the economic use of data. It shifts the balance between data owners and users – away from the manufacturer and towards the user.

For companies, this means a strategic realignment: those who understand data as a business model will have to live with more transparency, stricter contracts, and increased interoperability in the future.

From a legal perspective, the Data Act brings significant legal uncertainties that will only be clarified through practice and case law. Companies should use the coming months to adapt their processes and contracts – and don't forget: failures can become expensive from autumn 2025.

Get in touch