The EU Data Act gives users of connected products and related services the right to access the data they generate, and to have that data shared with third parties. It has applied since 12 September 2025, but the obligation to design products so that data is directly accessible only applies to connected products placed on the market after 12 September 2026.
The Data Act, Regulation (EU) 2023/2854, also sets rules on unfair terms in data contracts between businesses, on switching between cloud providers and on access to data by public bodies in exceptional situations. If your business makes, imports or sells connected products, offers cloud services or uses data under contracts with other businesses, it is likely to be affected. Below we explain the main obligations and how they are enforced in the Netherlands.
What does the Data Act regulate?
The Data Act sets out who may access data generated by the use of products and services, and on what terms that data must be shared. It does not create a general right to all data, but a framework for specific situations.
The Regulation entered into force on 11 January 2024 and forms part of the European data strategy, which aims to make more data available for use in the economy. It covers six main areas: access by users to product and service data, fair terms for data sharing between businesses, access by public bodies in cases of exceptional need, switching between data processing services, safeguards against unlawful governmental access to non-personal data from outside the EU, and interoperability. The full text is available on EUR-Lex.
What must manufacturers of connected products do?
Connected products and related services must be designed so that the data they generate is, by default, easily, securely, free of charge and in a machine-readable format directly accessible to the user, where relevant and technically feasible (Article 3). Think of smart home devices, industrial machines, medical devices or vehicles.
This design obligation applies to connected products and related services placed on the market after 12 September 2026. Products already on the market before that date do not need to be redesigned. Before a contract is concluded, the user must also be informed about the type and volume of data the product generates and how the user can access it.
Where data is not directly accessible, the data holder must make it available to the user on request, without undue delay and free of charge (Article 4). The user can also ask the data holder to share the data with a third party of the user’s choosing (Article 5). Very large online platforms designated as gatekeepers under the Digital Markets Act cannot be such a third party.
Can you protect your trade secrets?
Yes, to a degree. The data holder may require confidentiality measures before disclosing data that contains trade secrets, and may in exceptional cases refuse or suspend sharing if disclosure is highly likely to cause serious economic damage. Such a refusal must be substantiated and notified to the competent authority.
The user may not use the data obtained to develop a product that competes with the connected product from which the data originates. The data holder, for its part, may only use non-personal product data on the basis of a contract with the user.
Which contract terms between businesses are unfair?
A contractual term concerning access to and use of data, or liability and remedies for breach, does not bind the other business if it was unilaterally imposed and is unfair (Article 13). A term is unilaterally imposed if the other party could not influence its content despite an attempt to negotiate it.
The party that introduced the term must prove that it was not unilaterally imposed. A term is unfair if it grossly deviates from good commercial practice in data access and use, contrary to good faith and fair dealing.
The Regulation contains two lists. Terms that are always unfair include those that exclude or limit liability for intentional acts or gross negligence, and those that give the party that imposed the term the exclusive right to interpret the contract. Terms that are presumed unfair include those that inappropriately restrict the other party’s use of data it has contributed, or that allow termination at unreasonably short notice.
An unfair term does not bind the other party, but the rest of the contract remains in force if the term can be separated from it. The rules apply to contracts concluded after 12 September 2025. From 12 September 2027, they also apply to older contracts that run for an indefinite period or expire at least ten years after 11 January 2024.
If a data holder must make data available to another business, it may ask for reasonable compensation (Article 9). For micro, small and medium-sized enterprises and certain research organisations, that compensation may not exceed the costs of making the data available.
How does the Data Act relate to the GDPR?
The Data Act does not replace or override the General Data Protection Regulation (GDPR). It also covers personal data, but where it does, the GDPR continues to apply in full, and in case of conflict the GDPR prevails.
If the user who asks for data is not the data subject whose personal data is involved, that personal data may only be made available if there is a valid legal basis under Article 6 GDPR and, where relevant, Article 9 GDPR. The Data Act does not create such a basis itself.
Data access under the Data Act also does not release the parties from their other GDPR obligations, such as purpose limitation, security and limits on how long data may be stored. Read more about the GDPR risks of sharing data and about how long you may keep customer data.
What changes for cloud providers and their customers?
Providers of data processing services, such as cloud and edge services, must make it easier for customers to switch to another provider or to their own infrastructure. They may not impose commercial, technical, contractual or organisational obstacles that hinder switching.
The contract must allow the customer to switch with a maximum notice period of two months, after which the actual transfer of data and digital assets must be completed within a transitional period of at most thirty days. If that is technically not feasible, the provider must explain why and may extend the period, up to a maximum of seven months.
From 12 January 2027, providers may no longer charge any switching charges at all. Until that date, they may only charge reduced charges that do not exceed the costs directly linked to the switch. For organisations that depend heavily on a single cloud provider, these rules give new leverage when contracts are renewed or renegotiated. Check your existing cloud contracts for longer periods or switching fees.
When can public bodies demand your data?
Public sector bodies may, under strict conditions, require businesses to make data available in cases of exceptional need, such as a public emergency. The request must be specific, proportionate and justified.
In a public emergency, data holders must provide the data free of charge, except micro and small enterprises, which are entitled to compensation. In other cases of exceptional need, for example where the data is needed to carry out a specific task in the public interest and cannot be obtained otherwise, the data holder may claim fair compensation.
Who enforces the Data Act in the Netherlands?
In the Netherlands, supervision is regulated in the Data Act Implementation Act (Uitvoeringswet dataverordening). The Authority for Consumers and Markets (ACM) supervises most of the Regulation, including the rules on product data, data sharing between businesses and cloud switching.
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) is responsible where personal data is involved. Both authorities can impose an order subject to a penalty (last onder dwangsom) or an administrative fine within their own area, and they cooperate and exchange information on overlapping issues.
If an authority takes a decision against your business, you can lodge an objection with that authority and then appeal to the court. Apart from supervision, a business can also enforce its rights under the Regulation in the civil courts, for example if a data holder refuses access to data.
Does the Data Act also apply to small businesses?
Largely, yes. There is no general exemption for small and medium-sized enterprises. The design obligation for connected products and the fairness test for contract terms apply regardless of the size of the business.
There are some exceptions. The obligations on data access and sharing under Chapter II do not apply to data generated by products manufactured or services provided by micro and small enterprises, provided they have no partner or linked enterprise that is larger. In a public emergency, micro and small enterprises are entitled to compensation. Medium-sized enterprises benefit from a limited transitional exemption. Check carefully which category your business falls into.
What should you do now?
Take stock of the products, services and contracts that fall within the scope of the Data Act, and start with those that will be placed on the market after 12 September 2026.
- For connected products: check whether the product design and user information meet Article 3, and set up a process for data access requests.
- For data contracts with other businesses: review standard terms on data use and liability for terms that may be unfair.
- For cloud services: check the notice periods, transfer periods and switching charges in your contracts.
- For personal data: document the legal basis for each data flow and align Data Act and GDPR compliance.
Aligning your products and contracts early is not only a matter of compliance. Offering customers transparency and data access can also be a commercial advantage.
In summary
- The Data Act has applied since 12 September 2025; the design obligation for connected products applies to products placed on the market after 12 September 2026.
- Users can access the data their connected products generate and have it shared with third parties, subject to protection of trade secrets.
- Unilaterally imposed unfair terms on data access, use and liability do not bind the other business.
- Cloud providers must facilitate switching and may no longer charge switching fees from 12 January 2027.
- In the Netherlands, the ACM and the AP supervise compliance and can impose fines.
Frequently asked questions
Does the Data Act already apply to my existing connected products?
The Regulation has applied since 12 September 2025, but the obligation to design connected products so that users can access the data directly only applies to products placed on the market after 12 September 2026. For products already on the market, users can still request access to the data from the data holder.
What should I do if my data contract contains clauses that restrict access to data?
Have the contract reviewed. A unilaterally imposed term that inappropriately restricts the other party’s use of data it has contributed is presumed unfair and then does not bind that party. The party that introduced the term must prove that it was negotiated. Renegotiating early is usually more effective than waiting for a dispute.
May I share personal data under the Data Act without a GDPR legal basis?
No. The Data Act does not provide a legal basis for disclosing personal data. If the user is not the data subject, personal data may only be made available if there is a valid basis under Article 6 GDPR. Data obtained under the Data Act may also not be retained or reused beyond what the GDPR allows.
Can I still charge switching fees as a cloud service provider?
Only until 12 January 2027, and only reduced charges that do not exceed the costs directly linked to the switch. From that date, switching charges are prohibited. The transfer itself must be completed within a transitional period of at most thirty days, unless this is technically not feasible.
Which supervisory authority enforces the Data Act in the Netherlands?
The Authority for Consumers and Markets (ACM) supervises most of the Regulation, including product data, data sharing between businesses and cloud switching. The Dutch Data Protection Authority (AP) is responsible where personal data is involved. Both can impose an order subject to a penalty or a fine, against which objection and appeal are available.
Does the Data Act also apply to small enterprises?
Largely, yes. There is no general exemption for small and medium-sized enterprises. The data access and sharing obligations do not apply to data from products made or services provided by micro and small enterprises without a larger partner or linked enterprise, and in a public emergency they are entitled to compensation.
Law & More advises businesses on data contracts, cloud agreements and compliance with the Data Act and the GDPR. Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.
How Law & More can help you with this is explained on our IT lawyer page.

