Skip to content
TECHNOMATON | Docs SAI Certified Trainers

Data Act: Overview

Regulation: EU 2023/2854 Effective: 12 September 2025 (main provisions) Scope: Data access and sharing (IoT, cloud, B2B)


What is the Data Act?

The Data Act is an EU regulation on harmonised rules for fair access to and use of data. It regulates access to data from connected devices (IoT), the rights of cloud service customers to switch between providers, and rules for B2B data sharing.

Main pillars

Who falls under the Data Act?

Directly regulated entities

EntityDescriptionExamples
IoT manufacturersManufacturers of connected productsSmart home, automotive, industrial machines
Service providersRelated services to IoTMobile apps for devices, cloud storage
Data holdersHolders of data from IoTManufacturers, platform operators
Cloud providersIaaS, PaaS, SaaSAWS, Azure, GCP, Salesforce, SaaS companies

Indirectly affected entities (gain rights)

EntityNew rights
IoT usersAccess to data from their devices
Cloud customersRight to switching, data portability
SMEsFRAND conditions for data access
Third partiesAccess to data at the user’s request

Out of scope

  • Products primarily for displaying content (PCs, tablets, smartphones)
  • Purely personal data (primarily GDPR)
  • Financial sector regulated by DORA (lex specialis)

Key obligations

For IoT manufacturers / connected products

ObligationDescriptionDeadline
Data accessEnsure user access to data12.9.2025
TransparencyInformation about data before purchase12.9.2025
Real-time accessData available continuously12.9.2025
Machine-readableStructured, machine-readable format12.9.2025
Data access by designBuilt-in access in new products12.9.2026

For cloud/SaaS providers

ObligationDescriptionDeadline
Switching rightsAllow the customer to switch at any time12.9.2025
Max notice periodMaximum 2 months12.9.2025
Data exportProvide data in a portable format12.9.2025
Technical assistanceAssistance with migration12.9.2025
Prohibition of switching feesNo switching charges12.1.2027

For all B2B contracts

ObligationDescriptionDeadline
Fair termsProhibition of unfair terms12.9.2025 (new contracts)
Existing contractsFairness for existing contracts too12.9.2027

Timeline

Penalties

ProvisionPenalty regimeMaximum penalty
IoT data access (Ch. II)GDPR regimeEUR 20M or 4% of turnover
B2B sharing (Ch. III)National lawPer member state
Unfair terms (Ch. IV)Contractual invalidityN/A (civil disputes)
Cloud switching (Ch. VI)National lawPer member state

Example: An IoT manufacturer violating data access obligations = up to EUR 20M or 4% of global turnover (under the GDPR regime).

Synergies with other regulations


Next steps

  1. Run a Quick Assessment -> Data Act Assessment template
  2. IoT Data Access obligations - for manufacturers of connected products
  3. Cloud Switching requirements - for SaaS/cloud providers and customers
  4. Go through the compliance checklist

Sources