Home › Law library › EU Data Act
EU
EU Data Act
Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act)
Sourced. Last verified 9 October 2026
European Union Data sharing
- Status
- In force since 11 Jan 2024; applies from 12 Sep 2025 (design duty 12 Sep 2026; switching fees end 12 Jan 2027).
- Who it applies to
- Makers of connected products and related services sold in the EU, data holders, cloud/data-processing service providers, and businesses using B2B data-sharing contracts, wherever established.
- Size thresholds
- Micro and small enterprises are exempt from the connected-product data-sharing duties (Chapter II), unless linked to a larger firm or subcontracted to make the product.
- Regulator
- National competent authorities designated by each Member State (DPAs for personal data issues)
- Local representative
- Being verified
- Sending data abroad
- Cloud providers must take measures to prevent unlawful non-EU government access to non-personal data held in the EU.
- Maximum penalty
- Set nationally; must be effective, proportionate and dissuasive (e.g. Ireland's draft: up to 4% of EU turnover). GDPR fines apply to personal-data breaches.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Let users access and share data generated by your connected products and services.
- Design new connected products for direct data access (products placed on market from 12 Sep 2026).
- Give pre-contract information on what data a product generates and how to access it.
- Cloud providers: allow switching and remove all switching charges by 12 Jan 2027.
- Remove unfair data-sharing terms imposed on other businesses.
- Share data with public bodies in exceptional need when lawfully requested.
Recent changes
Applied 12 Sep 2025. Digital Omnibus (Nov 2025, pending) would fold in the Data Governance Act and ease trade-secret, B2G and cloud-switching rules; Council presidency aims for deal by end-2026.
Sources
- Primary source: https://digital-strategy.ec.europa.eu/en/policies/data-act
- Second source: https://www.mccannfitzgerald.com/knowledge/data-privacy-and-cyber-risk/data-act-developments-2026-and-beyond
- Regulator: National competent authorities designated by each Member State (DPAs for personal data issues)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].