The application of the EU harmonized rules for a functioning of internal data market (Data Act) has started
On September 12, 2025, the implementation of Regulation (EU) 2023/2854 on harmonized rules on fair access and use of data (Data Act) began. This Regulation, which entered into force on January 11, 2024, aims to maximize the value of data in the economy by ensuring that a wider range of stakeholders gain control over their data, as well as that more data is available for innovative use, while preserving incentives to invest in data generation.
In order to respond to the needs of the digital economy and to remove barriers to a well-functioning internal market for data, the Data Act lays down a harmonised rules, specifying who is entitled to use product data or related service data, under which conditions and on what basis. Concretely, the Data Act lays down harmonised rules, inter alia, on:
(a) the making available of product data and related service data to the user of the connected product or related service;
(b) the making available of data by data holders to data recipients;
(c) the making available of data by data holders to public sector bodies, the Commission, the European Central Bank and Union bodies that request data holders to make data available where there is an exceptional need for those data for the performance of a specific task carried out in the public interest;
(d) facilitating switching between data processing services;
(e) introducing safeguards against unlawful third-party access to non-personal data; and
(f) the development of interoperability standards for data to be accessed, transferred and used.
Defining terms ’data’, ’connected product’ and ’related service’ in the sense of this Regulation
According to the definition from Article 2(1) of the Regulation, ’data’ means any digital representation of acts, facts or information and any compilation of such acts, facts or information, including in the form of sound, visual or audio-visual recording. As explained in the Recital (15), the data represent the digitisation of user actions and events and should accordingly be accessible to the user.
’Connected product’ means an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of any party other than the user (Article 2(5)). As explained in the Recital, connected products that can perform all the listed functions, by means of their components or operating systems, are often referred to as the Internet of Things. They are found in all aspects of the economy and society, including in private, civil or commercial infrastructure, vehicles, health and lifestyle equipment, ships, aircraft, home equipment and consumer goods, medical and health devices or agricultural and industrial machinery.
Which data a connected product is capable of making available is determined not only by manufacturers’ design choices, but also by Union or national law that addresses sector-specific needs and objectives or relevant decisions of competent authorities (Recital 14).
’Related service’ means a digital service, other than an electronic communications service, including software, which is connected with the product at the time of the purchase, rent or lease in such a way that its absence would prevent the connected product from performing one or more of its functions, or which is subsequently connected to the product by the manufacturer or a third party to add to, update or adapt the functions of the connected product (Article 2(6)). Such related services (apps, software) involve the exchange of data between the connected product and the service provider and should be explicitly linked to the connected product’s functions, such as services that transmit commands to the connected product or have some other impact on its action or behavior.
Product data refers to data generated by the use of a connected product that the manufacturer designed to be retrievable, via an electronic communications service, physical connection or on-device access, by a user, data holder or a third party. Related service data means data representing the digitisation of user actions or of events related to the connected product, recorded intentionally by the user or generated as a by-product of the user’s action during the provision of a related service by the provider.
Based on different approaches, data generated by the use of a connected product or related service should be understood to cover:
- data recorded intentionally by the user and data which result indirectly from the user’s action (such as data about the connected product’s environment or interactions) generated automatically by sensors and recorded by embedded applications,
- data generated by a user interface or via a related service,
- data which are not substantially modified, meaning data in raw form, also known as source or primary data which refer to data points that are automatically generated without any further form of processing, as well as data which have been pre-processed for the purpose of making them understandable and useable prior to subsequent processing (Recital 15),
- non-personal and personal data.
By contrast, this Regulation does not cover:
- information inferred or derived from such data, in particular, information derived by means of sensor fusion, which infers or derives data from multiple sensors, collected in the connected product, using proprietary, complex algorithms and which could be subject to intellectual property rights (Recital 15),
- data from unrelated software and content (textual, audio or audiovisual) that connected products generate when the user records, transmits, displays or plays it, often covered by intellectual property rights, inter alia for use by an online service (Recital 16),
- data which was obtained, generated or accessed from the connected product, or which was transmitted to it, for the purpose of storage or other processing operations on behalf of other parties, who are not the user, such as may be the case with regard to servers or cloud infrastructure operated by their owners entirely on behalf of third parties, inter alia for use by an online service.
Who does the Data Act apply to?
This Regulation applies to:
(a) manufacturers of connected products placed on the market in the Union and providers of related services, irrespective of the place of establishment of those manufacturers and providers;
(b) users in the Union of connected products or related services;
(c) data holders, irrespective of their place of establishment, that make data available to data recipients in the Union;
(d) data recipients in the Union to whom data are made available;
(e) public sector bodies, the Commission, the European Central Bank and Union bodies that request data holders to make data available where there is an exceptional need for those data for the performance of a specific task carried out in the public interest and to the data holders that provide those data in response to such request;
(f) providers of data processing services, irrespective of their place of establishment, providing such services to customers in the Union (Cloud and edge providers);
(g) participants in data spaces and vendors of applications using smart contracts and persons whose trade, business or profession involves the deployment of smart contracts for others in the context of executing an agreement.
BUSINESS TO CONSUMER AND BUSINESS TO BUSINESS DATA SHARING
Obligation to make product data and related service data accessible to the user
This Regulation ensures that users of a connected product or related service in the Union can access the data generated by the use of that connected product or related service, as well as that can use that data. According to the definition from Article 2(12) ’user’ means a natural or legal person that owns a connected product or to whom temporary rights to use that connected product have been contractually transferred, or that receives related services.
Therefore, the Data Act imposes the obligation on manufacturers and service providers to make product data and related services data accessible to their users. This means that connected products must be designed and manufactured, and related services shall be designed and provided, in such a manner that product data and related service data (including the relevant metadata necessary to interpret and use those data), are, by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user (Article 3). From a technical aspect, connected products may be designed to make certain data directly accessible from on-device data storage or from a remote server to which the data are communicated. Access to on-device data storage may be enabled via cable-based or wireless local area networks connected to a publicly available electronic communications service or mobile network. The server may be the manufacturer’s own local server capacity or that of a third party or a cloud service provider (Recital 22).
The obligation for manufacturers and service providers shall apply to connected products and the services related to them placed on the market after 12 September 2026.
Furthermore, the Data Act prescribes pre-contractual obligations for the seller, rentor or lessor (which may be the manufacturer) of connected products. Before concluding a contract for the purchase, rent or lease of a connected product, they are required to provide users with information on the data that their connected product is capable of generating, and in addition, information on its capability of generating data continuously and in real-time, storing data on-device or on a remote server, as well as how the user may access, retrieve or, where relevant, erase the data, including the technical means to do so (Article 3(2)).
Providers of related services are subject to more extensive pre-contractual obligations regarding the provision of information, given that they are also the prospective data holders. That information refers, among other things, to the nature, estimated volume and collection frequency of product data that the prospective data holder is expected to obtain and, where relevant, the arrangements for the user to access or retrieve such data, including the prospective data holder’s data storage arrangements and the duration of retention (Article 3(3)).
The rights and obligations of users and data holders with regard to access,
use and making available product data and related service data
This Chapter of the Data Act applies to all raw and pre-processed data generated from the use of a connected product or a related service that is readily available to the data holder.
’Data holder’ means a natural or legal person that has the right or obligation, in accordance with this Regulation, applicable Union law or national legislation, to use and make available data, including, where contractually agreed, product data or related service data which it has retrieved or generated during the provision of a related service (Article 2(13). The data holder is typically the company that manufacture the connected product or that provides a related service. A data holder must conclude a contract with the user defining the rights regarding the access, use and sharing of the data that is generated by the connected product or related service. Such contractual terms could be part of an contract on the provision of the related service, and also the purchase, rent or lease contract relating to the connected product. This Regulation should not be understood to confer any new right on data holders to use product data or related service data. He can only use any readily available data that is non-personal data on the basis of a contract with the user.
‘Readily available data’ means product data and related service data that a data holder lawfully obtains or can lawfully obtain from the connected product or related service, without disproportionate effort going beyond a simple operation (Article 2(17)). Readily available data does not include data generated by the use of a connected product where the design of the connected product does not provide for such data being stored or transmitted outside the component in which they are generated or the connected product as a whole. This Regulation should therefore not be understood to impose an obligation to store data on the central computing unit of a connected product (Recital 20).
As already stated, as a rule, the user should be able to directly access the data. However, where data cannot be directly accessed by the user from the connected product or related service, data holders have an obligation to make readily available data (as well as the relevant metadata necessary to interpret and use those data) accessible to the user without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time (Article 4(1)). The data holder fulfills this obligation on the basis of a simple request through electronic means where technically feasible.
The user must not use the data, obtained pursuant to a request addressed to the data holder, to develop a connected product that competes with the connected product from which the data originate, nor share the data with a third party with that intent and must not use such data to derive insights about the economic situation, assets and production methods of the manufacturer or, where applicable, the data holder.
The right of the user to share data with third parties
The user should be free to use the data for any lawful purpose. To foster the emergence of efficient markets for non-personal data, the Regulation provides for the right of the users of connected products to share data with others, including for commercial purposes, with minimal legal and technical effort. Such data sharing could be performed directly by the user, upon the request of the user via a data holder, or through data intermediation services[1].
Upon request by a user, or by a party acting on behalf of a user, the data holder is obliged to make available readily available data (as well as the relevant metadata necessary to interpret and use those data) to a third party without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge to the user, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time (Article 5).
Data holders are not authorized to make available non-personal product data to third parties for commercial or non-commercial purposes, unless requested to do so by the user for the purpose of fulfilling the contract, or in the case of a request pursuant to Union law or national law (Article 8(4)).
other than the fulfillment of their contract with the user, except in the case of legal requirements pursuant to Union or national law (Article 8(4)).
Where data are excluded from a data holder’s obligation to make them available to users or third parties, the scope of such data could be specified in the contract between the user and the data holder for the provision of a related service so that users can easily determine which data are available to them for sharing with data recipients or third parties.
Where, in business-to-business relations, a data holder is obliged to make data available to a data recipient (as well as under applicable Union law or national legislation), it must agree with a data recipient the arrangement for making the data available and shall do so under fair, reasonable and non-discriminatory terms and conditions and in a transparent manner. Where relevant, data holders should contractually bind third parties not to further share data received from them.
Obligations of third parties receiving data at the request of the user
A ‘third party’ or ‘data recipient’ means a natural or legal person, acting for purposes which are related to that person’s trade, business, craft or profession (other than the user of a connected product or related service) to whom the data holder makes data available, including a third party following a request by the user to the data holder or in accordance with a legal obligation under Union law or national legislation. These are business entities that need access to data from connected products in the EU for their own services, such as repair services, insurance companies, logistics providers, or companies developing and using AI.
A third party is obliged to process the data made available to it upon request by a user only for the purposes and under the conditions agreed with the user and subject to Union and national law on the protection of personal data, including the rights of the data subject insofar as personal data are concerned. The third party must erase the data when they are no longer necessary for the agreed purpose, unless otherwise agreed with the user in relation to non-personal data (Article 6). Upon the agreement with the user, and subject to the provisions of this Regulation, third parties should be able to transfer the data access rights granted by the user to other third parties, including in exchange for compensation (Recital 33).
Protection of personal data and trade secrets
The Data Act covers personal and non-personal data. Any processing of personal data pursuant to this Regulation should comply with Union data protection law. The Data Act imposes an obligation on data holders to make personal data available to users or third parties of a user’s choice upon that user’s request (Articles 4 and 5). Such access can be provided to personal data that are processed by the data holder on the basis of any of the legal bases referred to in Article 6 of Regulation (EU) 2016/679[2]. Where the user is not the data subject whose personal data is requested, any personal data generated by the use of a connected product or related service may be made available by the data holder to the user or to the third party only where there is a valid legal basis for processing under Article 6 of Regulation (EU) 2016/679 and, where relevant, the conditions of Article 9 of that Regulation and of Article 5(3) of Directive 2002/58/EC are fulfilled. In those cases, it could be in the interest of the user to facilitate meeting the requirements of Article 6 of Regulation (EU) 2016/679. As this Regulation must not adversely affect the data protection rights of data subjects, the data holder can comply with requests in those cases, inter alia, by anonymising personal data or, where the readily available data contains personal data of several data subjects, transmitting only personal data relating to the user.
While this Regulation requires data holders to disclose certain data to users, or third parties of a user’s choice (articles 4 and 5), even when such data qualify for protection as trade secrets, it should be interpreted in such a manner as to preserve the protection afforded to trade secrets under Directive (EU) 2016/943. To that end, data holders should identify trade secrets prior to the disclosure, and should agree with users, or third parties of a user’s choice, on proportionate technical and organisational measures necessary to preserve the confidentiality, such as model contractual terms, confidentiality agreements, strict access protocols, technical standards and the application of codes of conduct (articles 4(6) and 5(9)). Where there is no agreement on the necessary measures or where a user, or third parties of the user’s choice, fail to implement agreed measures or undermine the confidentiality of the trade secrets, the data holder may withhold or suspend the sharing of data identified as trade secrets.
OBLIGATIONS FOR DATA HOLDERS TO MAKE DATA AVAILABLE PURSUANT TO UNION LAW
The Regulation also provides for horizontal rules on the arrangements for access to data whenever a data holder is obliged by Union law or national legislation to make data available to a data recipient. Which data a connected product is capable of making available will be determined not only by manufacturers’ design choices, but also, where relevant, Union or national law that addresses sector-specific needs and objectives or relevant decisions of competent authorities. Where, in business-to-business relations, a data holder is obliged to make data available to a data recipient under applicable Union law or national legislation, it must agree with a data recipient the arrangement for making the data available and such access should be based on fair, reasonable, non-discriminatory and transparent terms and conditions (Article 8). Voluntary data sharing remains unaffected by those rules.
In order to ensure that the conditions for mandatory data access are fair for both parties to a contract, the general rule on data access right refers to the rules on avoiding unfair contractual terms (Article 8(2)). Any agreement concluded in business-to-business relations for making data available should be non-discriminatory between comparable categories of data recipients. To help parties to comply with the Data Act and establish fair, secure, and transparent agreements for data sharing and cloud services, the European Commission’s Expert Group published a set of model contractual terms (MCTs) and standard contractual clauses (SCCs).[3]
In order to promote continued investment in generating and making available valuable data, including investments in relevant technical tools, while at the same time avoiding excessive burdens on access to and the use of data which make data sharing no longer commercially viable, this Regulation contains the principle that in business-to-business relations data holders may request reasonable compensation when obliged pursuant to Union law or national legislation to make data available to a data recipient. Such compensation should not be understood to constitute payment for the data itself. When agreeing on any compensation, the data holder and the data recipient shall take into account in particular: costs incurred in making the data available (in particular, the costs necessary for the formatting of data, dissemination via electronic means and storage), as well as investments in the collection and production of data. The European Commission is authorized to adopt guidelines on the calculation of reasonable compensation in the data economy (Article 9).
Should users, data holders and data recipients be unable to conclude a contract on data sharing, they have access to a dispute settlement body (Article 10), cije decision will be binding on the parties only if they have explicitly consented to its binding nature prior to the start of the proceedings. Regardless of this possibility, the right to share data with third parties is enforceable in national courts or tribunals.
A data holder may apply appropriate technical protection measures, including smart contracts and encryption, to prevent unauthorized access to data, including metadata, and to ensure compliance with this Regulation, as well as with the agreed contractual terms for making data available (Article 11).
UNFAIR CONTRACTUAL TERMS RELATED TO DATA ACCESS AND USE BETWEEN ENTERPRISES
Data Act prohibits contractual terms concerning access to and the use of data or liability and remedies for the breach or the termination of data related obligations, which has been unilaterally imposed by an enterprise on another enterprise, if they are unfair. A contractual term is considered unfair if it is of such a nature that its use grossly deviates from good commercial practice in data access and use, contrary to good faith and fair dealing. In order to ensure legal certainty, this Regulation establishes a list of clauses that are always considered unfair and a list of clauses that are presumed to be unfair. In the latter case, the enterprise that imposes the contractual terms is able to rebut the presumption of unfairness by demonstrating that the contractual term listed in this Regulation is not unfair in the specific case in question(Article 13). Finally, non-binding model contractual terms (MCTs) and standard contractual clauses (SCCs) may also be helpful to commercial parties when negotiating contracts.
MAKING DATA AVAILABLE TO PUBLIC SECTOR BODIES, THE COMMISSION, THE EUROPEAN CENTRAL BANK
AND UNION BODIES ON THE BASIS OF AN EXCEPTIONAL NEED
Where a public sector body, the Commission, the European Central Bank or a Union body demonstrates an exceptional need to use certain data to carry out its statutory duties in the public interest (public emergencies, such as public health emergencies, emergencies resulting from natural disasters, as well as human-induced major disasters, such as major cybersecurity incidents), data holders that are legal persons, other than public sectors bodies, is obliged to make them available upon a duly reasoned request (articles 14 to 22).
SWITCHING BETWEEN DATA PROCESSING SERVICES
The ability of customers of data processing services, including cloud and edge services, to switch from one data processing service to another while maintaining a minimum functionality of service and without downtime of services, or to use the services of several providers simultaneously without undue obstacles and data transfer costs, is a key condition for a more competitive market with lower entry barriers for new providers of data processing services, and for ensuring further resilience for the users of those services. Customers benefiting from free-tier offerings should also benefit from the provisions for switching that are laid down in this Regulation, so that those offerings do not result in a lock-in situation for customers (Recital 78).
According to Article 2 (7) ’processing’ means any operation or set of operations which is performed on data or on sets of data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or other means of making them available, alignment or combination, restriction, erasure or destruction. The generic concept ‘data processing services’ covers a substantial number of services with a very broad range of different purposes, functionalities and technical set-ups. According to Article 2 (8) ‘Data processing service’ means a digital service that is provided to a customer and that enables ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources of a centralised, distributed or highly distributed nature that can be rapidly provisioned and released with minimal management effort or service provider interaction. As commonly understood by providers and users and in line with broadly used standards, data processing services fall into one or more of the following three data processing service delivery models, namely Infrastructure as a Service (IaaS), Platform as a service (PaaS) and Software as a Service (SaaS). Those service delivery models represent a specific, pre-packaged combination of ICT resources offered by a provider of data processing service. Those three fundamental data processing delivery models are further complemented by emerging variations, each comprised of a distinct combination of ICT resources, such as Storage as a Service and Database as a Service.
Providers of data processing services are required to take measures to enable customers to switch to a data processing service covering the same service type, which is provided by a different provider of data processing services, or to on-premises ICT infrastructure, or, where relevant, to use several providers of data processing services at the same time. In particular, providers of data processing services may not impose and must remove pre-commercial, commercial, technical, contractual and organizational obstacles, which inhibit customers from terminating and concluding new contracts with a different provider, as well as porting the customer’s exportable data and digital assets to a different provider of data processing services or to an on-premises ICT infrastructure (Article 23).
The Data Act also prescribes the concrete obligations of the source providers of data processing services related to contractual terms concerning switching, provision of information to customers, cooperating in good faith and contractual transparency (Articles 25 to 28). Also, the obligations of the provider of data processing services concerning technical aspects of switching are regulated in detail (Article 30).
From 12 January 2027, providers of data processing services shall not impose any switching charges on the customer for the switching process.
UNLAWFUL INTERNATIONAL GOVERNMENTAL ACCESS AND TRANSFER OF NON-PERSONAL DATA
Providers of data processing services shall take all adequate technical, organisational and legal measures, including contracts, in order to prevent international and third-country governmental access and transfer of non-personal data held in the Union where such transfer or access would create a conflict with Union law or with the national law of the relevant Member State (Article 32).
INTEROPERABILITY
Participants in data spaces that offer data or data services to other participants are recquired to comply with the prescribed essential requirements to facilitate the interoperability of data, of data sharing mechanisms and services, as well as of common European data spaces which are purpose- or sector-specific or cross-sectoral interoperable frameworks for common standards and practices to share or jointly process data for, inter alia, the development of new products and services, scientific research or civil society initiatives (Articles 33 to 36).
IMPLEMENTATION AND ENFORCEMENT
Each Member State must designate at least one competent authority for the enforcement of the Data Act (Article 37). These authorities are expected to coordinate closely with existing sectoral and data protection regulators since the Data Act reinforces but does not replace the GDPR.
Without prejudice to any other administrative or judicial remedy, natural and legal persons shall have the right to lodge a complaint, individually or, where relevant, collectively, with the relevant competent authority in the Member State of their habitual residence, place of work or establishment if they consider that their rights under this Regulation have been infringed.
Notwithstanding any administrative or other non-judicial remedy, any affected natural and legal person shall have the right to an effective judicial remedy with regard to legally binding decisions taken by competent authorities.
Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive (Article 40).