AI Guide

EU Data Act: Fair access to connected-product and cloud data in the EU

The EU Data Act (Regulation (EU) 2023/2854) is the EU law that gives users of connected devices the right to access the data those devices generate and requires cloud providers to let customers switch freely. It is a distinct regulation from GDPR and the EU AI Act, focused on data access and portability rather than personal-data rights or AI risk. Learn below what the Data Act actually covers, what it does not, and how German Mittelstand manufacturers need to prepare.

Key Facts
  • Regulation (EU) 2023/2854 entered into force on 11 January 2024; its core data-access and sharing obligations became directly applicable on 12 September 2025.
  • Data-by-design requirements for newly placed connected products apply from 12 September 2026.
  • Cloud and data-processing switching charges must be phased out completely by 12 January 2027 under Article 29.
  • Micro and small enterprises with fewer than 50 employees and turnover or balance sheet under 10 million euros are exempt from the data holder's sharing duties under Article 7 (Bitkom Umsetzungsleitfaden, 2025).
  • Non-compliance can trigger fines of up to 20 million euros or 4% of global annual turnover, enforced in Germany by the Bundesnetzagentur since 2026.

Definition: EU Data Act

The EU Data Act (Regulation (EU) 2023/2854) governs who can access data generated by connected products, sets rules for switching between cloud providers, and requires fair terms in business-to-business data-sharing contracts.

Core characteristics of the EU Data Act

The Data Act applies horizontally across every industry operating connected devices and covers both personal and non-personal data.

  • Gives users of connected products (machines, vehicles, wearables) the right to access data those products generate, in real time where feasible
  • Requires data holders to share that data with third parties the user chooses, on fair, reasonable, and non-discriminatory (FRAND) terms
  • Obliges cloud and SaaS providers to remove switching barriers and phase out exit fees
  • Sets conditions for public authorities to request access to privately held data during emergencies

EU Data Act vs. GDPR and the EU AI Act

Mittelstand teams often conflate the Data Act with GDPR and the EU AI Act, but the three address different problems. GDPR protects individuals’ rights over personal data; the AI Act classifies AI systems by risk. The Data Act regulates neither: it governs who may access machine-generated data from connected products, so a company can be GDPR- and AI-Act-compliant while still failing its duty to share the data a customer’s own machine produces.

Importance of the EU Data Act in enterprise AI

Connected products generate the operational data that increasingly grounds enterprise AI systems, so access control shapes what teams can build, part of the broader AI compliance picture. Gartner estimates that by 2027 over 30% of new industrial IoT contracts in the EU will include explicit Data Act clauses, up from under 5% in 2024.

Methods and procedures for the EU Data Act

Compliance starts with knowing where connected-product data exists and who legally holds it.

Data holder inventory and contract audit

Companies first establish which products generate data, who the data holder is in multi-vendor supply chains, and where contracts fall short of FRAND terms.

  • Map every connected product against the data it produces
  • Review contracts for missing data-sharing clauses
  • Flag pre-2025 contracts needing updated terms

Technical data access design

Data holders build machine-readable export paths, ideally APIs, so users and chosen third parties can pull data directly, separating raw product data from proprietary derived data, which is not automatically subject to the same access duty.

Cloud-switching and data-residency readiness

Cloud providers must be assessed for lock-in, including proprietary formats and exit fees that need to reach zero by January 2027. Where machine data must stay within the EU, this overlaps with data residency planning, since switching a provider can mean moving where the data lives.

Important KPIs for the EU Data Act

Tracking compliance requires both contract-level and technical metrics.

Compliance operations

  • Connected products mapped to a designated data holder: 100%
  • Active B2B data-sharing contracts reviewed for FRAND terms: 100%
  • Cloud switching charges: reduced to 0 euros by 12 January 2027
  • Data access requests fulfilled in machine-readable format: 100%

Strategic exposure

Manufacturers of connected industrial equipment carry the highest exposure: Fraunhofer ISI estimates over 60% of German Mittelstand machinery builders already ship networked sensors without formal data-sharing terms (Fraunhofer, 2025).

Data quality and access reliability

Beyond legal readiness, data governance quality determines whether access requests can actually be fulfilled on time, since poorly labeled telemetry turns a routine request into a multi-week engineering task.

Risk factors and controls for the EU Data Act

Non-compliance risk concentrates in contract gaps and unclear data ownership.

Undefined data holder role

Many Mittelstand supply chains involve multiple parties touching the same connected product, and it is often unclear who legally qualifies as the data holder.

  • Component suppliers and integrators disputing responsibility
  • Legacy contracts silent on data access rights
  • Aftermarket providers requesting data the manufacturer assumed was proprietary

Trade secret and competitive exposure

Sharing raw product data with third parties, including competitors’ service arms, raises legitimate concerns about exposing proprietary design or usage patterns. The Data Act lets data holders withhold specific trade secrets, but only if they can document that the exemption genuinely applies.

Cross-border enforcement fragmentation

Each EU member state designates its own competent authority, so a company operating across borders faces regulators with potentially different interpretations, which makes data sovereignty and clear internal ownership of compliance a practical necessity.

Practical example

A 140-employee manufacturer of connected industrial sensors in Bavaria supplies equipment to automotive and food-processing plants across the EU. Before September 2025, its sales contracts said nothing about who could access the operating data its machines generated, and customers had already asked for raw sensor exports. The company mapped its product line against data flows, updated its terms with FRAND-compliant clauses, and built a self-service export API so customers no longer filed manual requests.

  • Self-service, machine-readable data export for connected products
  • FRAND-compliant sharing clauses in all new and renewed contracts
  • A documented data holder designation for every product line
  • A vendor register tracking cloud switching-fee exposure ahead of 2027

Current developments and effects

The Data Act’s obligations are still phasing in, and enforcement infrastructure is only now taking shape.

National enforcement is standing up

Germany designated the Bundesnetzagentur as its single competent authority through the national Data Act Durchführungsgesetz (DADG), working alongside the federal data protection commissioner where personal data is involved.

  • Bundesnetzagentur is now the central point of contact for German Data Act complaints
  • Bitkom published an implementation guide aimed at Mittelstand manufacturers
  • Sector associations like VDMA issue machinery-specific checklists

The 2026 and 2027 deadlines are the next pressure points

Companies placing new connected products on the market after 12 September 2026 must build data-by-design access into them from launch, raising development cost for smaller manufacturers that had not budgeted for it.

AI vendors are adjusting data-sourcing practices

As enterprises deploy more agents against machine-generated data, AI vendors serving EU manufacturers are increasingly asked to prove their pipelines respect Data Act access rights before a contract is signed.

Conclusion

The EU Data Act is not GDPR and not the AI Act; it is a standalone regulation about who controls access to data generated by connected products and cloud services. For Mittelstand manufacturers, the practical work is concrete: know which products generate data, know who the data holder is, and have FRAND-compliant contracts and export paths ready before the 2026 and 2027 deadlines land. Companies that treat this as routine contract hygiene avoid the fines that fall on those who wait. As connected products and enterprise AI intertwine, Data Act compliance increasingly determines what data an AI system is even allowed to use.

Frequently Asked Questions

What is the EU Data Act in simple terms?

It is an EU regulation giving users of connected devices the right to access the data those devices generate, and requiring cloud providers to let customers switch without lock-in fees. It applies across all industries and covers personal and non-personal data alike.

Is the EU Data Act the same as GDPR?

No. GDPR governs personal data protection, while the Data Act governs access to data generated by connected products and cloud contracts, personal or not. A company can comply with one and still fail the other.

Does the EU Data Act apply to small and medium enterprises?

Micro and small enterprises with fewer than 50 employees and turnover or balance sheet under 10 million euros are exempt from the data holder’s sharing obligations under Article 7, unless linked to a larger enterprise.

What does the EU Data Act mean for AI systems built on IoT data?

The Data Act does not regulate AI systems directly, that is the AI Act’s role, but it determines who is legally entitled to access the connected-product data an AI system might use for training or inference.

What happens if a company ignores its Data Act obligations?

Fines can reach 20 million euros or 4% of global annual turnover. In Germany, the Bundesnetzagentur enforces compliance and can order corrective action before penalties apply.

How long does Data Act readiness typically take for a Mittelstand manufacturer?

Most manufacturers need three to six months to inventory connected products, update contracts, and build a basic export mechanism. Starting with a contract and data-flow audit moves fastest.

Building better software Contact us together