Whether and how does the EU Data Act apply to business entities in Serbia?
Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act) entered into force on 11 January 2024, while most of its provisions started to apply from 12 September 2025. The Data Act aims to maximise the value of data in the economy by ensuring that users (both consumers and businesses) of a connected products (particularly within the Internet-of-Things framework) or related services in the Union can access the data generated by the use of these products or services and that can use the data, including by sharing them with third parties of their choice.
Data act imposes significant new compliance obligations for business entities, which offer connected products, related services or cloud and other data processing services in the European Union (EU). In doing so, provisions of the Data Act apply extraterritorially, and prescribe key obligations for: – manufacturers of connected products placed on the market in the Union and providers of related services,
– data holders,
– providers of data processing services, providing such services to customers in the Union
irrespective of the place of establishment of those manufacturers and providers.
The EU Data Act introduces new rules for any business entity dealing with connected products, related services and data processing services. Therefore, it brings new risks of regulatory fines and lawsuits, but also new opportunities. The aim of this Regulation is not only to foster the development of new, innovative connected products or related services, stimulate innovation on aftermarkets, but also to stimulate the development of entirely novel services making use of the data concerned, including those based on data from a variety of connected products or related services. Considering that the Data Act applies to all sectors and all levels of the economy, determining the rights and obligations of a certain business entity depends on the role it has in the data market, based on its connection with the respective data.
Which business entities are covered by the Data Act application?
- Manufacturers of connected products and providers of related services are subject to the obligation to make product data and related service data directly accessible to the user. (Article 3). This means that connected products must be designed and manufactured, and related services shall be designed and provided, in such a manner that product data and related service data (including the relevant metadata necessary to interpret and use those data), are, by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user.
Product data refers to data generated by the use of a connected product that the manufacturer designed to be retrievable, via an electronic communications service, physical connection or on-device access, by a user, data holder or a third party. Related service data, means data representing the digitisation of user actions or of events related to the connected product, recorded intentionally by the user or generated as a by-product of the user’s action during the provision of a related service by the provider. In terms of this Regulation, connected products are defined as items that obtain, generate or collect, by means of their components or operating systems, data concerning their performance, use or environment and that are able to communicate those data via an electronic communications service, a physical connection, or on-device access, often referred to as the Internet of Things. Connected products are found in all aspects of the economy and society, including in private, civil or commercial infrastructure, vehicles, health and lifestyle equipment, ships, aircraft, home equipment and consumer goods, medical and health devices or agricultural and industrial machinery (Recital 14). From a technical aspect, connected products may be designed to make certain data directly accessible from on-device data storage or from a remote server to which the data are communicated. Access to on-device data storage may be enabled via cable-based or wireless local area networks connected to a publicly available electronic communications service or mobile network. The server may be the manufacturer’s own local server capacity or that of a third party or a cloud service provider (Recital 22). Related service means a digital service, other than an electronic communications service, including software, which is connected with the product at the time of the purchase, rent or lease in such a way that its absence would prevent the connected product from performing one or more of its functions, or which is subsequently connected to the product by the manufacturer or a third party to add to, update or adapt the functions of the connected product (Article 2(6)). Such related services (apps, software) involve the exchange of data between the connected product and the service provider and should be explicitly linked to the operation of the connected product’s functions, such as services that transmit commands to the connected product or have some other impact on its action or behavior. However, the EU Commission acknowledged that the key defining criterion, which is a service’s impact on the ‘functions’ of a connected product, will need further clarification by the courts to help determine which services fall within the scope of the Data Act.
The obligation for manufacturers and service providers shall apply to connected products and the services related to them placed on the market after 12 September 2026.
- Data Act prescribes pre-contractual obligations for seller, rentor or lessor (which may be the manufacturer) of connected products to provide users with information on the data that their connected product is capable of generating (Article 3(2)).
- Providers of related services are subject to more extensive pre-contractual obligations regarding the provision of information, given that they are also the prospective data holders. That information refers, among other things, to the nature, estimated volume and collection frequency of product data that the prospective data holder is expected to obtain and, where relevant, the arrangements for the user to access or retrieve such data, including the prospective data holder’s data storage arrangements and the duration of retention (Article 3(3)).
In accordance with the Data Act this information must be provided in a clear and comprehensible manner, which entails the obligation to prepare or modify appropriate documents on the product and service description that are submitted to the user before concluding contract. The information obligation could be fulfilled, for example by maintaining a stable uniform resource locator (URL) on the web, which can be distributed as a web link or QR code, pointing to the relevant information (Recital 24).
- Where data cannot be directly accessed by the user from the connected product or related service, data holders have an obligation to make readily available data (as well as the relevant metadata necessary to interpret and use those data) accessible to the user without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time (Article 4(1)). The data holder fulfills this obligation on the basis of a simple request through electronic means where technically feasible.
For the purposes of this Regulation, ’data holder’ means a natural or legal person that has the right or obligation, in accordance with this Regulation, applicable Union law or national legislation, to use and make available data, including, where contractually agreed, product data or related service data which it has retrieved or generated during the provision of a related service (Article 2(13). The data holder is typically the company that manufactures the connected product or that provides a related service. A data holder must conclude a contract with the user defining the rights regarding the access, use and sharing of the data that is generated by the connected product or related service. Such contractual terms could be part of a contract on the provision of the related service, and also the purchase, rent or lease contract relating to the connected product.
- The Regulation provides for the right of the users of connected products to share data with others, and such data sharing could be performed directly by the user or upon the request of the user via a data holder. Upon request by a user, the data holder is obliged to make available readily available data (as well as the relevant metadata necessary to interpret and use those data) to a third party without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge to the user, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time (Article 5).
- A third party is obliged to process the data made available to it upon request by a user only for the purposes and under the conditions agreed with the user and subject to Union and national law on the protection of personal data, including the rights of the data subject insofar as personal data are concerned (Article 6).
- The Regulation also provides for horizontal rules on the arrangements for access to data whenever a data holder is obliged by Union law or national legislation to make data available to a data recipient. Which data a connected product is capable of generating, collecting and making accessible to the user will be determined not only by manufacturers’ design choice, but also, where relevant, Union or national law that addresses sector-specific needs and objectives or relevant decisions of competent authorities.
- Providers of data processing services, including cloud and edge services, are required to take the measures to enable customers to switch to a data processing service, covering the same service type, which is provided by a different provider of data processing services, or to on-premises ICT infrastructure, or, where relevant, to use several providers of data processing services at the same time. In particular, providers of data processing services may not impose and must remove pre-commercial, commercial, technical, contractual and organizational obstacles, which inhibit customers from terminating and concluding new contracts with a different provider, as well as porting the customer’s exportable data and digital assets to a different provider of data processing services or to an on-premises ICT infrastructure.
For the purposes of this Regulation, ‘data processing service’ means a digital service that is provided to a customer and that enables ubiquitous and on-demand network access to a shared pool of configurable, scalable and elastic computing resources of a centralised, distributed or highly distributed nature that can be rapidly provisioned and released with minimal management effort or service provider interaction. As commonly understood by providers and users and in line with broadly used standards, data processing services fall into one or more of the following three data processing service delivery models, namely Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS). Those service delivery models represent a specific, pre-packaged combination of ICT resources offered by a provider of data processing services. Those three fundamental data processing delivery models are further complemented by emerging variations, each comprised of a distinct combination of ICT resources, such as Storage as a Service and Database as a Service.
- The Data Act also prescribes the concrete obligations of the source providers of data processing services related to contractual terms concerning switching, provision of information to customers, cooperating in good faith and contractual transparency, as well as obligations concerning technical aspects of switching.
From 12 January 2027, providers of data processing services shall not impose any switching charges on the customer for the switching process. From 11 January 2024 to 12 January 2027, providers of data processing services may impose reduced switching charges, which may not exceed the costs incurred by the provider of data processing services that are directly linked to the switching process concerned.
- In line with the minimum requirements allowing switching between data processing services, providers of data processing services have to comply with the essential requirements regarding interoperability of data, of data sharing mechanisms and services, as well as of common European data spaces.
In order to ensure compliance and use the new opportunities of the EU Data Act, the business entities should undertake more activities.
- Understanding the role the company plays in the Data Act system: the user of a connected product or related service, the manufacturer of a connected product, the provider of related service, the data holder, data recipient, provider of data processing services.
- Identifying the products and services they manufacture, offer or use, which are subject to the Data act application.
- Assessing what type of data is being obtained, generated, collected, stored, processed, transmitted, made available and whether the data will need special protection (personal data, trade secret, intellectual property rights) or contracting to fulfill the obligations of the Data Act.
- Determining where user data rights will require changes to the business.
- Creating a compliance program: identifying and establishing practical processes and measures, technical solutions and procedures for user data access, data separation, and data sharing, ensuring compliance with both the EU Data Act and other relevant laws (such as privacy and trade secrets)
- Establishing clear policies, user notices, access logs, and documentation to defend against enforcement actions or lawsuits, and to demonstrate compliance to partners and regulators
- Revising and updating pre-contractual materials: before concluding a contract, seller, rentor or lessor (which may be the manufacturer) and provider of related services are subject to obligations of providing information to the user regarding the data to be generated. The information must be provided in a clear and comprehensible manner.
- Drafting new contracts or amending existing contracts in order to comply with the Data Act and data user rights:
- the purchase, rent or lease contract relating to the connected product
- contract on the provision of the related service
- A data holder must conclude a contract with the user defining the rights regarding the access, use and sharing of the data that is generated by the connected product or related service. Such contractual terms could be part of a contract on the provision of the related service, and also the purchase, rent or lease contract relating to the connected product.
- Where, in business-to-business relations, a data holder is obliged to make data available to a data recipient, upon request by a user, or under other applicable Union law or national legislation, it must agree with a data recipient the arrangements for making the data available and shall do so under fair, reasonable and non-discriminatory terms and conditions and in a transparent manner.
- Reviewing contracts concerning access to and the use of data or liability and remedies for the breach or the termination of data related obligations, if it has been unilaterally imposed by an enterprise on another enterprise. They are not binding on the latter enterprise if it is unfair. Checking a list of clauses that are always considered unfair and a list of clauses that are presumed to be unfair.
- Using a set of model contractual terms (MCTs) and standard contractual clauses (SCCs), published by the European Commission’s Expert Group on B2B Data Sharing and Cloud Computing Contracts[1]to help parties to comply with the Data Act.
- Clearly setting out in a written contract the rights of the customer and the obligations of the provider of data processing services in relation to switching between providers of such services, including mandatory clauses.
- Updating existing data processing contracts for personal data for the Data Act application
- Taking the measures to enable customers to switch to a data processing service, covering the same service type, which is provided by a different provider of data processing services, or to on-premises ICT infrastructure, or, where relevant, to use several providers of data processing services at the same time.
- Training and monitoring: Provide training for in-house teams and monitor ongoing legal developments in key EU markets, in order to stay ahead of new requirements and risks.
- Considering new business models, such as offering data-driven services, as a strategic opportunity.