The Data Act governs who has access to the data generated by connected products and related services, and makes switching between data processing service providers easier. It concerns data generally, including non-personal data.
Legal basis
Regulation (EU) 2023/2854 has applied since 12 September 2025. Chapter II gives the user of a connected product a right of access to the data it generates and to share those data with a third party of their choice; manufacturers must design products so that the data are accessible. Chapter IV renders unfair contractual terms about data access between businesses non-binding. Chapter VI requires cloud providers to remove obstacles to switching, with maximum notice periods and with switching charges phased down and eventually abolished. Chapter VII contains safeguards against unlawful access to non-personal data by third-country authorities. The Regulation leaves the GDPR untouched: where personal data are involved, the GDPR continues to apply in full.
How it works in practice
For manufacturers of machinery, vehicles and appliances this means mapping the data flows and informing users in advance about what data are generated and how they can be accessed. For customers of cloud services the Regulation creates room: existing contracts must be brought into line with the new switching rules, which is a good moment to revisit exit provisions as well.
Where it goes wrong
Manufacturers invoke trade secrets to refuse access; that is possible only on the conditions the Regulation sets. A second error is contracts placing data access unilaterally with the supplier, which may fall as unfair terms. Third, the interaction with the GDPR is underestimated where data about drivers or employees sit in the data stream.
Related terms
The Regulation connects to the SaaS agreement, the database right and the data processing agreement.
Do you supply connected products or cloud services? Our IT lawyers test your contracts against the new rules.

