EU Data Act: An Overview of Data Access and Obligations

What rights companies can exercise and where the limits lie

Data Act – What Companies Need to Know About Data Access and Moving to the Cloud

What Applies to Connected Products, Data Contracts, and Cloud Services

A machine is purchased, but its operational data remains with the manufacturer. A company wants to switch cloud services, but exporting the data turns into a project of its own. Many companies are familiar with situations like these. The Data Act is intended to ensure that technical dependencies do not automatically become permanent business relationships.

The European Data Regulation has generally been in effect since September 12, 2025. In September 2026, an important requirement regarding the design of connected products will be added. It is therefore crucial for companies to know: What data can they request, what data must they provide, and where do legal limits apply?

Effective as of: September 11, 2026.


Data Act: Data Access Between Connected Machines, Companies, and Cloud Services

What is the Data Act?

The Data Act is the European regulation on fair data access and use. Among other things, it governs how users can access data from connected products and share it with other companies. It is also intended to make it easier to switch between cloud services and to protect companies from certain unfair data contract terms.

This is not about a general right to access all of a company's data. The specific rights and obligations depend on which products, services, and data are involved and what role the company plays.

Which companies are affected?

The Data Act does not apply only to technology providers. A mechanical engineering company may have obligations as a manufacturer and, at the same time, benefit from access rights as a user of third-party production equipment.

The regulation is particularly relevant for manufacturers of connected products, providers of related services, and companies that purchase, rent, or lease such products. These include, for example, connected industrial machinery, vehicles, and smart energy systems. It also applies to providers and customers of data processing services, particularly cloud services.

For micro-enterprises and small businesses, there are exceptions to product-related obligations under certain conditions. However, there is no blanket exemption for small and medium-sized enterprises. Furthermore, these exceptions do not automatically apply to cloud regulations. The key factor is an assessment of the specific business activities and corporate structure.

When did the Data Act take effect?

Three time points are particularly important for operational planning:

  • September 12, 2025: The Data Act is generally applicable. This includes, in particular, the provisions on data access and switching data processing services.
  • After September 12, 2026: For connected products and related services placed on the market after that date, the additional design requirement set forth in Article 3, paragraph 1, applies. The data collected must be made accessible by design.
  • January 12, 2027: Data processing service providers may no longer charge switching fees for processing a change of provider.

The deadline in September 2026 therefore does not mark the general implementation of the Data Act. It pertains to a specific product requirement. Consequently, there is no blanket requirement to retrofit all older devices.

As of the date indicated, the amendments proposed as part of the Digital Omnibus are still undergoing the legislative process. They do not yet constitute a tax relief measure.

What data can companies request?

The focus is on product data and data from related services, such as measurements of temperature, pressure, energy consumption, or operating conditions. Metadata necessary for a meaningful understanding of these values may also be collected.

If the user cannot access the data directly, the data controller must make the collected, readily available data accessible in accordance with the statutory requirements. This access is provided to the user free of charge. In addition, the user may request that the data be made available to a selected third party.

Here's an example: A manufacturing company wants to make the operational data from its connected machine available to an independent maintenance company. The goal is for the maintenance company to detect wear and tear earlier and prevent downtime. The Data Act can provide a way to do this.

However, this does not mean that every additional analysis or forecast developed by the manufacturer must also be disclosed. Similarly, a distinction must be made between free user access and potential compensation for providing data to a commercial recipient.

What do manufacturers and suppliers need to do to prepare?

For affected providers, implementation begins with a seemingly simple question: What data is actually generated, and who can access it?

For products and services subject to the design requirement, the relevant data must, by default, be accessible in a simple, secure, and free manner in a comprehensive, structured, commonly used, and machine-readable format. Direct access is provided, to the extent that it is relevant and technically feasible.

In addition, there are pre-contractual disclosure requirements. For example, users must be informed about what data is generated, where it is stored, and how access works. These disclosure requirements do not begin only on the product effective date of 2026.

In practice, this means that product development, sales, IT, and the legal department should work together on interfaces, product information, and deployment processes. An export button isn’t much help if no one can explain what it exports.

Data Act and GDPR: Access to Data Remains Subject to Restrictions

The Data Act does not replace the GDPR. Personal data remains protected; in the event of a conflict, data protection law takes precedence.

This becomes relevant, for example, in the case of connected company vehicles. Technical vehicle data can also provide insights into employees and their behavior. If the company, as the requesting user, is not itself the data subject, the disclosure of personal data requires an appropriate legal basis under data protection law. The Data Act does not grant blanket authorization for this.

Trade secrets also remain protected. However, they do not automatically justify a complete refusal to grant access to any data. Depending on the case, confidential data must be identified and appropriate protective measures agreed upon, such as access restrictions and confidentiality agreements. Withholding or refusing access is permissible only under the conditions prescribed by law.

Data access and protection requirements should therefore be addressed in the same process, not in two separate email threads.

How does the Data Act affect switching cloud providers?

The Data Act requires registered providers of data processing services to remove certain contractual, technical, and organizational barriers to switching. This may affect infrastructure, platform, and software services. However, not every digital service is automatically covered by the Act; furthermore, there are specific exceptions.

For customers, contracts should clearly specify which data can be exported, how the transition will take place, and what support the provider will offer. These requirements generally apply to existing cloud contracts as well.

Until switching fees are eliminated in January 2027, such fees may not exceed the provider’s costs directly related to the switch. After that, these switching fees will be eliminated. However, this does not make the entire migration project free of charge: one must distinguish between the provider’s own IT expenses, services provided by a new service provider, and fees associated with early contract termination, which must be reviewed separately.

Which contracts should companies review?

In addition to product and cloud contracts, agreements regarding data access and data use deserve attention. Certain unfair terms that one company unilaterally imposes on another are not binding on the disadvantaged company.

This provision initially applies to contracts entered into after September 12, 2025. For certain older long-term contracts, it takes effect in September 2027. Therefore, not every unfavorable clause is automatically invalid. However, it makes sense to conduct a thorough review of usage rights, liability, and data access upon the contract’s expiration.

Implementing the Data Act: Five Practical Next Steps

To get off to a structured start, companies should:

  1. Assess the scope of impact: Which connected products and cloud services are offered or used? What role does the company play in each case?
  2. Mapping Data Sets: What data is generated, where is it stored, and which sets contain personally identifiable information or trade secrets?
  3. Review contracts: Do access rights, intended uses, product information, and transfer provisions meet the requirements?
  4. Establishing Procedures: Who reviews requests, verifies authorizations, and organizes secure deployment?
  5. Testing the technology in practice: Can the data actually be exported and put to good use by the intended recipient?

K11 Consulting helps companies align regulatory requirements with effective operational processes. Particularly when it comes to product data containing personal information, implementation can be integrated with an existing data protection management system.

Conclusion: Data access requires clear lines of responsibility

The Data Act expands companies’ ability to use product data and switch between digital providers. At the same time, it requires the providers in question to provide transparent information, implement appropriate processes, and ensure technical accessibility.

The best way to start, therefore, is not to collect data in general, but to conduct a specific assessment: What rights can we exercise, what obligations must we fulfill, and who is responsible for handling them? Only then can a legal entitlement be transformed into practical, usable access.