Data Act
The Data Act is an EU law designed to improve access to and sharing of data within the EU market for both individuals and businesses. It focuses on who can access and use data generated by connected products and related services, which is a different aim from the EU General Data Protection Regulation's focus on protecting personal data. Note that a separate, unrelated US law also carries the 'DATA Act' name and covers government spending data, so the two should not be confused.
The EU Data Act is a regulation forming part of the European data strategy that came into force on 11 January 2024, with application phased in over time. It establishes rules governing access to, sharing of, and use of data generated within the EU, including obligations on data holders to make certain data available to users and third parties, subject to qualifications such as availability 'where relevant and technically feasible.' Its objective of unlocking value and access across the EU data market is distinct from the EU GDPR, which governs the protection of personal data; the Data Act addresses data access and sharing more broadly (including non-personal data) rather than data protection per se. This entry does not detail the Act's specific article-level obligations, sectoral exemptions, cloud-switching provisions, or enforcement and penalty regimes, and it does not describe how the Data Act interacts with GDPR where personal data is involved. The unrelated US Digital Accountability and Transparency Act (DATA Act, S.994, 113th Congress) is a separate instrument concerning federal spending data and is out of scope for this definition beyond noting the naming overlap.
Why it matters
The EU Data Act reframes a question that data protection professionals often treat as settled: who may access and use data. Where the EU GDPR concentrates on protecting personal data, the Data Act pursues a broader market objective of improving access to and sharing of data generated by connected products and related services, including non-personal data. For organizations that design, sell, or operate connected products, this means data governance can no longer be scoped solely around personal data protection; it must also account for obligations to make certain data available to users and, in some cases, third parties. That shift has practical consequences for how data holders structure their data flows, contracts, and technical architectures.
The practical friction lies in the Act's qualified obligations. It requires data holders to make data available "where relevant and technically feasible," which introduces judgment and design questions rather than a simple binary duty. Organizations will need to be able to demonstrate how they assessed technical feasibility and relevance, consistent with the accountability expectation that governance decisions rest on evidence rather than stated intent. This also creates an interface risk: where the data in question is personal data, the Data Act's access and sharing aims sit alongside the EU GDPR's protection requirements, and the two regimes must be reconciled in practice.
A common and avoidable mistake is confusing the EU Data Act with the unrelated US Digital Accountability and Transparency Act (DATA Act, S.994, 113th Congress), which concerns federal government spending data and has no bearing on connected-product data access in the EU. Professionals reviewing policy documents or vendor materials should verify which instrument is meant before drawing any conclusions, because the two share a name but address entirely different subject matter.
Who it's relevant to
Inside Data Act
Common questions
Answers to the questions practitioners most commonly ask about Data Act.