The EU Data Act: New Rules for Data Sharing in Europe

City and data symbolising the EU Data Act and data sharing in Europe

On 11 January 2024, the EU Data Act – Regulation (EU) 2023/2854 – entered into force, twenty days after its publication in the Official Journal of the European Union. The Regulation applies from 12 September 2025. This legislation imposes fundamental new obligations on manufacturers of connected products and providers of related services, affecting a wide range of sectors: from manufacturing and energy to healthcare and the automotive industry. Anyone who generates, processes or uses data in a business context would be well advised to examine the scope of this legislation in good time.

What does the Data Act govern?

The Data Act forms part of the European data strategy, which aims to strengthen Europe’s competitive position in the data economy. The Regulation sets out rules on who has access to data generated by the use of products or services, and under what conditions that data must be shared. This does not concern a general right to all data, but rather a framework of six specific clusters: user access to product and service data, B2B sharing on fair terms, public access in cases of exceptional need, switching between data processing services, protection against international governmental access to non-personal data, and interoperability.

Obligations for businesses: product design

Connected products must be designed and manufactured in such a way that the generated data is, by default, easily, securely, free of charge and in a machine-readable format directly accessible to the user. Users of connected products – think of smart home devices, industrial machinery or vehicles – thereby acquire the right to access the data that their use of that product generates. Manufacturers and service providers may no longer keep that data exclusively for themselves.

Importantly, this obligation has a phased entry into application. Although the Data Act as a whole applies from 12 September 2025, the design and manufacturing obligation for connected products only applies to products placed on the market after 12 September 2026. Existing products are therefore not yet covered.

Fair terms in B2B data sharing

The Regulation contains specific rules on contractual terms in B2B data contracts. A term unilaterally imposed by one undertaking on another does not bind the other party if it is unfair. A term is considered to have been unilaterally imposed where, despite an attempt to negotiate, the other party was unable to influence its content. The burden of proving this rests on the party that included the term.

A term is unfair if its use grossly deviates from good commercial practice and is contrary to good faith and fair dealing. The Regulation gives as examples terms that exclude liability for intent or gross negligence, prevent the other party from using its own data, allow unilateral termination at unreasonably short notice, or permit significant price or other material changes to be made unilaterally. The legal consequence is that the unfair term does not bind the other party, while the remaining contractual provisions remain in force insofar as the term is severable.

Interplay with the GDPR

The Data Act sits alongside the General Data Protection Regulation, but there is an important interplay between them. The Regulation also covers personal data, but does not detach it from data protection law. Where the user is not the data subject whose personal data is requested, that personal data may only be provided where a valid legal basis exists under Article 6 GDPR. The Data Act therefore does not create a standalone exception to the GDPR: data access under the Data Act does not relieve parties of their GDPR obligations, nor does it provide a basis for further retention or reuse of the provided data beyond the purpose for which it was obtained.

Cloud portability and switching

A separate chapter requires providers of data processing services to make switching to another provider easier. They may not impose any pre-commercial, commercial, technical, contractual or organisational obstacles that hinder customers from switching. From 12 January 2027, providers of data processing services may no longer charge customers any switching charges. The actual transfer of data and configurations must take place without undue delay and in no case after a mandatory transitional period of a maximum of thirty days. For organisations heavily dependent on a single cloud provider, this offers new negotiating leverage when renewing or renegotiating contracts.

Public access in cases of exceptional need

The Regulation gives public sector bodies the possibility, under strict conditions, to demand access to private data in cases of exceptional need – such as a public emergency. In that case, data holders other than micro-enterprises and small enterprises are obliged to make the necessary data available free of charge. In other cases of exceptional need, the data holder is entitled to fair compensation. This power is subject to the conditions of proportionality and subsidiarity set out in the Regulation.

Enforcement in the Netherlands

In the Netherlands, enforcement has now been embedded in law through the Data Act Implementation Act (Uitvoeringswet dataverordening). The Netherlands Authority for Consumers and Markets (ACM) is the competent authority for the largest part of the Regulation, including the chapters on product data, B2B sharing, and cloud portability. The Dutch Data Protection Authority (AP) is competent for the privacy-sensitive elements and for the processing of personal data within certain articles and Chapter V. Both authorities may take enforcement action within their own domain by imposing an order subject to a penalty or an administrative fine. The Implementation Act also provides for a cooperation and information-exchange arrangement between the ACM and the AP, so that both supervisors can act in a coordinated manner on overlapping issues.

What does this mean in practice?

Businesses that develop, import or distribute connected products would be wise to review their product design and contractual structure against the Data Act now. For products placed on the market after 12 September 2026, the design and accessibility obligation applies in full. Service providers that process data on behalf of users should take stock of which data-sharing obligations apply to them and whether existing agreements – including unilaterally drafted data clauses – are aligned with them.

Those who wait until enforcement gets under way risk falling behind. Aligning products, services and contracts with the new rules in good time is not only a matter of compliance, but also presents opportunities: those who offer their customers transparency and data access stand out in a market that is increasingly critical of how companies handle data.

Do you have questions about the implications of the EU Data Act for your business or your contracts? The lawyers at Law & More are happy to assist you.

Frequently Asked Questions

Does the Data Act already apply to my existing connected products?

The Regulation applies from 12 September 2025, but the obligation to design connected products so that data is accessible to users only applies to products placed on the market after 12 September 2026. Existing products already on the market before that date are not yet covered. Manufacturers and importers would nevertheless be wise to align their product development with the new requirements now, so that future products are compliant upon market launch.

What should I do if my data contract contains clauses that restrict access to data?

Under the Data Act, contractual terms that are unilaterally imposed and that prevent the other party from using or exploiting its own data may be regarded as unfair and therefore non-binding. It is advisable to have existing data contracts reviewed for such clauses. The burden of proving that a term was not unilaterally imposed rests on the party that included it. Early renegotiation is generally more effective than waiting until the other party invokes the Regulation.

May I share personal data under the Data Act without a GDPR legal basis?

No. The Data Act does not provide a standalone basis for disclosing personal data. Where the user is not the data subject whose personal data is requested, that data may only be provided where a valid legal basis exists under Article 6 GDPR. Moreover, data access under the Data Act provides no basis for further retention or reuse of the disclosed personal data beyond the original purpose. GDPR compliance and Data Act compliance must therefore be ensured simultaneously.

Can I still charge switching fees as a cloud service provider?

From 12 January 2027, providers of data processing services are prohibited from charging customers switching fees. In addition, from 12 September 2025, no technical, contractual or organisational obstacles that hinder switching may be imposed. The actual data transfer upon switching must also take place without undue delay and be completed within a transitional period of thirty days at the latest. Existing contracts containing longer periods or switching charges warrant review.

Which supervisory authority is competent for enforcing the Data Act in the Netherlands?

Enforcement is divided between the Netherlands Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP). The ACM is competent for the largest part of the Regulation, including the provisions on product data, B2B sharing and cloud portability. The AP is competent for the privacy-sensitive elements and the processing of personal data within certain articles and Chapter V. Both authorities may impose an order subject to a penalty or an administrative fine. The usual administrative-law remedies are available against such decisions, including objection, appeal and interim relief.

Does the Data Act also apply to small enterprises?

The Regulation distinguishes by enterprise size on a few points. For example, micro-enterprises and small enterprises are exempt, in cases of public emergency data requests, from the obligation to make data available free of charge; in those cases they are entitled to fair compensation. For the other obligations – including the accessibility obligation for connected products and the fairness test for B2B terms – there is no general exemption for small and medium-sized enterprises. Smaller providers of connected products or cloud services must therefore also align their operations with the Regulation in good time.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

High-risk AI systems are the focal point of the European AI Regulation (Regulation (EU) 2024/1689),

Cyberattacks such as ransomware, phishing, DDoS attacks and computer intrusion rarely affect only the organisation
Cybersecurity is no longer purely a technical matter. It is also a legal and governance

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.