Loading…
Loading…
The Data Act layers five horizontal instruments onto any operator placing connected products, related services, or data-processing services on the EU market.
1. By-design data availability for connected products (Chapter II). Manufacturers of "connected products" (anything from IoT consumer devices to industrial machinery and connected vehicles) and providers of related services must design products so that data generated by their use is, by default, easily, securely, free of charge and where relevant continuously accessible to the user — and shareable with third parties of the user's choosing. This is the structural break with the previous regime: data generated by EU IoT estates is no longer the unilateral property of the manufacturer. Article 3(1) (the data-by-design design obligation) applies to products placed on the market after 12 September 2026.
2. B2B fair-access framework (Chapter III). When manufacturers or data-holders are obliged by other EU or national law to make data available to a recipient, the terms must satisfy the FRAND-style fairness criteria of Articles 8–13 (non-discriminatory, transparent, reasonable compensation tied to costs of making data available rather than to the data's intrinsic value, with SME protections via mandatory model contractual terms).
3. Cloud-switching framework (Chapter VI, Articles 23–31). Data- processing-service providers — including hyperscale cloud (IaaS / PaaS / SaaS) — must enable customer migration to alternative providers via standard contractual rights of switching, functional equivalence requirements, technical-interoperability obligations, and a phased elimination of switching charges. Switching charges must be reduced from 12 September 2025 and abolished entirely from 12 January 2027. Egress fees (network outbound charges) for ordinary data use remain permitted only where they reflect direct costs.
4. B2G emergency data-sharing (Chapter V). EU public-sector bodies may compel private data-holders to share non-personal data in defined "exceptional need" scenarios — public emergencies, responses to natural disasters, or where data is essential to producing official statistics. Compensation is permitted only for the costs of making data available; reimbursement is mandatory in non-emergency exceptional-need cases.
5. Safeguards against international unlawful government access (Article 32). Cloud, edge, and other data-processing providers must take all adequate technical, organisational, and legal measures (including model contractual terms developed by the Commission) to prevent international transfer of non-personal data held in the EU where such transfer would conflict with EU or member-state law. This is the non-personal-data parallel to the Schrems II line for personal data.
The Act also contains an unfair-contract-terms regime for B2B data contracts where one party unilaterally imposes terms on a counterparty (Articles 13 and 13a equivalent), explicitly intended to protect SMEs from take-it-or-leave-it cloud and platform contracts.
directly constrains the architectural lock-in (proprietary APIs, data-egress fee structures, identity-and-access integration) that hyperscalers (AWS, Azure, GCP, Oracle Cloud) rely on to retain enterprise workloads. The 12 January 2027 abolition of switching charges removes a meaningful economic friction; combined with the separately-enforced functional-equivalence requirement, this is the most aggressive cloud-portability regime adopted to date.
user-controlled.** Connected-product makers (Siemens, Bosch, John Deere, ABB, Schindler, Otis, etc.) lose unilateral control over data generated in customer use; aftermarket-services competitors and third-party analytics players gain a statutory access channel.
non-personal-data analogue onto Schrems II logic. US-headquartered cloud providers servicing EU industrial customers must architect to prevent compelled extraterritorial production of non-personal data, reinforcing demand for EU-sovereign cloud / EU-region-only deployment options.
for B2B data-sharing and the unfair-terms test apply across the EU enterprise-software stack. Most major SaaS T&Cs require revision.
framework is likely to anchor partner-jurisdiction copy: the UK, Brazil (LGPD-ecosystem), and several APAC regulators are tracking the cloud-switching architecture for transposition.
(Articles 28–30) depends on standards still being developed via CEN-CENELEC and EU sectoral data-spaces; enforcement bite from 12 Sept 2025 will be uneven across SaaS verticals until harmonised standards land.
establish penalties — the Act does not set a uniform maximum). Convergence with GDPR-style 4%-of-global-turnover fines will depend on national transposing law.
services) and the AI Act (training-data governance) — particularly for AI providers ingesting industrial / IoT data via Article 3 user- rights channels.
conflicting orders (CLOUD Act vs. Data Act): the Commission's promised model contractual terms have not yet been finalised.