Why the Data Act was introduced

The main objective of the Data Act is to break the existing imbalance in access to data generated by connected products and related digital services.
Until now, it has primarily been manufacturers and providers who had full control over this information. Now, the EU legislator clearly emphasizes that data "generated by the user" should also be accessible to them. The new regulations aim to increase competition, for example, in service and repair services, facilitate the interoperability of different systems, and stimulate the development of data-driven innovations. At the same time, the regulations ensure a balance – protecting trade secrets and ensuring the technological security of devices.
The Data Act comes into effect – the end of the transition period and the beginning of new obligations
The Data Act came into effect on January 11, 2024, and its provisions began to be applied as of September 12, 2025. This means that the over 20-month transition period is coming to an end, and entrepreneurs must be ready for full compliance with the new regulations. At this stage, it is no longer about planning, but about actual compliance – implementing mechanisms for handling user requests, adjusting technical systems and contracts, and ensuring that processes comply with the principles of the Data Act and GDPR. Lack of preparation may result in disputes with users, sanctions imposed by supervisory authorities, as well as serious reputational risks.
Who is covered by the Data Act
The scope of the Data Act is very broad and covers practically every sector in which network-connected devices generating data are used. First and foremost, it concerns the household appliances and consumer electronics sector – from smart refrigerators, washing machines, and vacuum robots to smart TVs and smart home systems. Similarly, in the case of mobile electronics – smartphones, tablets, smartwatches, or fitness applications – data on usage patterns, location, or users' health status will also become available to them, and not solely to manufacturers and providers. In this area, it will be particularly important to reconcile the requirements of the Data Act with the strictures of GDPR.
The automotive and energy sectors will also experience significant changes. Modern cars record a vast amount of telemetry data, such as driving style and fuel consumption, location, and the technical condition of the vehicle. From September 2025, drivers will be able to request real-time access to this information. In the energy sector, smart meters for electricity, gas, and water will gain crucial importance. Data on utility consumption will be easily accessible to users and – upon their request – to alternative suppliers, which is intended to support competition and market efficiency.
No less significant will be the consequences for health care, agriculture, and industry. Online medical devices – such as insulin pumps, blood pressure monitors, or patient monitoring systems – generate sensitive data, the processing of which requires a strict alignment of the Data Act with the principles of the GDPR. In agriculture and industry, the new regulations will pave the way for broader use of data generated by agricultural machinery, environmental sensors, or production management systems, giving farmers and industrial entrepreneurs greater control over this resource. Ultimately, the regulation will encompass every sector where data has economic significance – thus not only global manufacturers but also smaller enterprises developing innovative digital solutions.
Which data is subject to sharing
The scope of the Data Act includes data generated both by the product itself and by the service functionally related to it. This primarily concerns information regarding the operation of the device, its usage patterns, readings from sensors, technical events, or metadata. The regulations require that access to this data be provided without unnecessary delay, in a structured format suitable for machine reading. Furthermore, upon the user's request, the data should be transmitted not only to them but also directly to a third party designated by them.
What rights does the user gain – access, portability, and control over the purpose of data use
The Data Act grants the user specific and practical tools: they can access data generated by the device, download it in a structured form, and even request its direct transfer to a chosen third party. These are real rights, not theoretical ones, which is why entrepreneurs must establish efficient procedures for their handling.
In practice, this means the necessity of verifying the identity of the applicant, providing secure transfer channels, ensuring a transparent interface (e.g., a client panel or API), and maintaining records of all submitted requests. Importantly, the user also gains actual control over the purposes for which a third party may use the shared data – without their consent, no other use is permissible.
What about second-hand devices
The Data Act also covers situations where a connected product enters the secondary market and changes ownership. The new user gains the right to use the data generated by the device; however, this must occur with respect for the privacy of the previous owner, the integrity of the system, and the protection of trade secrets. This means that manufacturers and sellers should develop clear procedures for transferring access to data upon change of ownership, such as resetting the device, re-pairing with the application, or mechanisms for migrating permissions. This will ensure that the process is both secure and compliant with the requirements of the Data Act.
What obligations do manufacturers and data holders have
Migrations, clouds, systems.
GDPR in IT.
Particular importance is also attached to the restrictions concerning third parties: they may use the data solely for the agreed purpose, without the right to further disclose or use it for the creation of competitive products. In business relationships, the principles of fairness, reasonableness, transparency, and non-discrimination (FRAND) apply, which additionally protect the interests of micro, small, and medium-sized enterprises. This is complemented by the obligation to implement adequate technical and organizational measures regarding data security and continuous oversight of partners and subcontractors involved in the processing of such data.
Enforcement and Dispute Resolution
The oversight of the application of the Data Act will be the responsibility of authorities designated by the member states. These authorities will be empowered to impose sanctions, which – in accordance with the Data Act – must be effective, proportionate, and sufficiently deterrent. Disputes may arise at various stages: from the refusal to provide data, through the format and quality of interfaces, the timeliness of data provision, or the amount of fees, to the assessment of whether the agreement truly meets the requirements of fairness (FRAND). To minimize risk, entrepreneurs should implement compliance mechanisms that include, among others, maintaining logs of all disclosures, recording user requests, documenting equal treatment of data recipients, and conducting periodic audits of agreements and processes. Such actions will not only facilitate demonstrating compliance in the event of an inspection but will also help reduce the risk of disputes with contractors and users.
How the Data Act Aligns with Other Regulations – Intersection with Competition Law, Cybersecurity, and Sectoral Regulations
The Data Act does not operate in a vacuum but complements existing legal frameworks concerning data. On one hand, it strengthens the principles of fairness, transparency, and non-discrimination in B2B contracts. On the other hand, its practical implementation will often be linked to other obligations, such as cybersecurity requirements arising from the NIS2 directive or sectoral regulations concerning critical infrastructure. However, the relationship with the GDPR is particularly significant, as a substantial portion of the data generated by digital products and services consists of personal data, which must still be processed in accordance with the principles of the General Data Protection Regulation.
Data Act and GDPR – Two Parallel Regimes, One Cohesive Compliance Architecture
The Data Act does not create a new basis for the processing of personal data nor does it modify the GDPR. If the data from a product or service constitutes personal data, the processing must be based on one of the grounds specified in Article 6 of the GDPR (except for special categories of data, for which the basis for processing may be established under one of the conditions specified in Article 9(2) of the GDPR), while adhering to the principles of legality, minimization, and transparency, and fully fulfilling the information obligations.
Key Element of Compliance with the Data Act – Proper Privacy Notice for the User
One of the most important obligations arising from the Data Act is to ensure that the user receives clear and comprehensive information about the data generated by the product before entering into a sales, rental, lease, or leasing agreement for the connected product. The regulation imposes an obligation on the seller, lessor, or leaseholder – regardless of whether they are the manufacturer – to provide the user with understandable information about the type and format of data generated by the product and its estimated quantity.
The provisions also require indicating whether the product generates data continuously and in real-time, or only periodically. An important element is to specify the location and duration of data storage – whether they are stored locally on the device or transferred to an external server, and if so, for how long. The user must also know how they will be able to access, download, or – where possible – delete the data, as well as what technical means have been provided to carry out these operations, e.g., a mobile application, API, or user panel. An additional aspect of the information obligation is to explain whether and to what extent the user will be able to further utilize the data and what quality of supporting services – such as update frequency or system availability – they can expect. Only with a full range of such information can the user consciously assess whether the product meets their needs in the area of data usage.
Similar obligations apply to related service providers, such as applications, cloud services, or service providers. In this case, the entrepreneur is required to inform about the nature and frequency of data collection from the product and about what data they will themselves acquire as the future data holder. It is also necessary to explain what additional data will be generated by the service itself and under what conditions the user will be able to familiarize themselves with, download, or delete it. It is particularly important to indicate the purpose for which the data will be used, as well as whether the data holder plans to share it with third parties and under what conditions. It is also mandatory to disclose one's identity – the company name, registered office address, identification data – and, if necessary, the identity of other data processors acting on their behalf. The provider should ensure effective communication channels that allow the user to contact them quickly, as well as explain how the user can request the sharing of data with a third party and how they can terminate such a process. The privacy notice must also include information about the right to lodge a complaint with the supervisory authority designated under the Data Act, any potential existence of trade secrets in the data and their owner, as well as the duration of the agreement and the terms of its termination.
From a practical perspective, the best solution is to prepare a coherent information card that will accompany the product or service regardless of the sales channel. It can take the form of a paper document in a physical store, a link or QR code in online sales, and also be available in an application associated with the device. It is crucial that manufacturers and providers require their business partners to use uniform content for such a card, which will ensure transparency and compliance with the requirements of the Data Act.
Summary
The Data Act is not just another regulation in EU law, but a true turning point in the approach to data. Instead of treating it solely as "the property of the manufacturer," the new regulations recognize data as a resource that can also be utilized by users and independent service providers. From September 12, 2025, information collected by devices and digital services will no longer be available exclusively to manufacturers – users and external companies should have access to it under clear and transparent conditions.
For entrepreneurs, this poses a real challenge. Those who limit themselves to minimal compliance with the requirements risk conflicts with customers, sanctions from supervisory authorities, and loss of trust. Conversely, companies that treat the Data Act strategically may gain significantly more – a competitive advantage and a reputation as a reliable partner in the data-driven economy.



