Skip to main content
Category: Privacy Regulations

Data Act

Also known as: EU Data Act
Simply put

The Data Act is an EU law designed to improve access to and sharing of data within the EU market for both individuals and businesses. It focuses on who can access and use data generated by connected products and related services, which is a different aim from the EU General Data Protection Regulation's focus on protecting personal data. Note that a separate, unrelated US law also carries the 'DATA Act' name and covers government spending data, so the two should not be confused.

Formal definition

The EU Data Act is a regulation forming part of the European data strategy that came into force on 11 January 2024, with application phased in over time. It establishes rules governing access to, sharing of, and use of data generated within the EU, including obligations on data holders to make certain data available to users and third parties, subject to qualifications such as availability 'where relevant and technically feasible.' Its objective of unlocking value and access across the EU data market is distinct from the EU GDPR, which governs the protection of personal data; the Data Act addresses data access and sharing more broadly (including non-personal data) rather than data protection per se. This entry does not detail the Act's specific article-level obligations, sectoral exemptions, cloud-switching provisions, or enforcement and penalty regimes, and it does not describe how the Data Act interacts with GDPR where personal data is involved. The unrelated US Digital Accountability and Transparency Act (DATA Act, S.994, 113th Congress) is a separate instrument concerning federal spending data and is out of scope for this definition beyond noting the naming overlap.

Why it matters

The EU Data Act reframes a question that data protection professionals often treat as settled: who may access and use data. Where the EU GDPR concentrates on protecting personal data, the Data Act pursues a broader market objective of improving access to and sharing of data generated by connected products and related services, including non-personal data. For organizations that design, sell, or operate connected products, this means data governance can no longer be scoped solely around personal data protection; it must also account for obligations to make certain data available to users and, in some cases, third parties. That shift has practical consequences for how data holders structure their data flows, contracts, and technical architectures.

The practical friction lies in the Act's qualified obligations. It requires data holders to make data available "where relevant and technically feasible," which introduces judgment and design questions rather than a simple binary duty. Organizations will need to be able to demonstrate how they assessed technical feasibility and relevance, consistent with the accountability expectation that governance decisions rest on evidence rather than stated intent. This also creates an interface risk: where the data in question is personal data, the Data Act's access and sharing aims sit alongside the EU GDPR's protection requirements, and the two regimes must be reconciled in practice.

A common and avoidable mistake is confusing the EU Data Act with the unrelated US Digital Accountability and Transparency Act (DATA Act, S.994, 113th Congress), which concerns federal government spending data and has no bearing on connected-product data access in the EU. Professionals reviewing policy documents or vendor materials should verify which instrument is meant before drawing any conclusions, because the two share a name but address entirely different subject matter.

Who it's relevant to

Data protection officers and privacy engineers
The Data Act's focus on data access and sharing is distinct from the EU GDPR's focus on protecting personal data, so DPOs and privacy engineers should treat it as a separate obligation set rather than an extension of existing GDPR programs. Where the data involved is personal data, the two regimes intersect, and reconciling access-and-sharing duties with data protection requirements will need dedicated review; this entry does not describe that interaction in detail.
Information governance and data governance leads
Because the Act addresses who can access and use data generated by connected products and related services, governance leads may need to extend ownership, stewardship, and cataloging practices beyond personal data to include non-personal data covered by the Act. The "where relevant and technically feasible" qualification means decisions about making data available should be documented as demonstrable evidence, consistent with accountability expectations, rather than asserted without support.
Legal and compliance teams
Legal and compliance professionals should scope obligations to the EU Data Act itself and note that its aims differ from the EU GDPR. They should also guard against confusing the EU Data Act with the unrelated US DATA Act (S.994, 113th Congress), which concerns federal spending data. This entry does not cover the Act's exemptions, cloud-switching provisions, or enforcement and penalty regimes, which require separate assessment.
Manufacturers and operators of connected products
Organizations that make or operate connected products and related services generating data within the EU are directly in scope as potential data holders, with obligations to make certain data available to users and third parties. Product and architecture decisions will influence what is "technically feasible," so these teams should coordinate early with governance and legal functions.

Inside Data Act

Scope of the Data Act
The EU Data Act is a regulation addressing access to and use of data generated in the Union, with particular focus on data produced by connected products and related services. It sits within the broader EU data strategy alongside instruments such as the GDPR but pursues distinct objectives centred on data access and fairness rather than personal data protection specifically.
Data access and sharing obligations
The instrument establishes rights and obligations concerning who may access data generated through the use of connected products and services, and under what conditions that data may be shared with users and, in certain cases, third parties. The precise mechanics depend on the final text and its implementation.
Relationship to personal data rules
Where data governed by the Data Act constitutes personal data, the EU GDPR continues to apply. The Data Act does not replace or override data protection law; the two operate together, and controllers and processors retain their existing GDPR obligations for any personal data involved.
Governance versus security framing
The Data Act concerns data access, sharing arrangements, and contractual fairness, which are governance and market-regulation matters. It is distinct from information security controls addressing confidentiality, integrity, and availability, although secure data sharing typically requires appropriate security measures alongside the access framework.

Common questions

Answers to the questions practitioners most commonly ask about Data Act.

Is the Data Act the same as the GDPR, or does it replace it?
No. The Data Act and the GDPR are distinct instruments with different objectives. The GDPR governs the processing of personal data and the protection of individuals' rights, while the Data Act focuses on access to and sharing of data generated by connected products and related services, covering both personal and non-personal data. The Data Act does not replace the GDPR; where personal data is involved, GDPR obligations continue to apply in parallel. Organizations should treat compliance with one as insufficient to satisfy the other, and should assess how the two frameworks interact for any given data flow.
Does the Data Act only apply to personal data?
No. Unlike the GDPR, which is scoped to personal data, the Data Act addresses data more broadly, including non-personal and machine-generated data arising from connected products and related services. Because a single dataset can contain both personal and non-personal elements, organizations generally cannot rely on a personal-versus-non-personal distinction to determine which obligations apply. Where personal data is present, the GDPR applies alongside the Data Act. This entry does not detail how mixed datasets are treated in every scenario; that assessment depends on the specific data and context.
Who bears the obligation to make product-generated data available under the Data Act?
Obligations generally fall on the parties that make connected products or related services available and that control access to the data those products generate. Accountability requires demonstrable evidence of how access and sharing are enabled, not merely a stated policy. Organizations should map their role in each data-sharing relationship rather than assuming a single blanket obligation applies uniformly across all their products and services. This entry does not enumerate every category of obligated party or the specific exemptions that may apply.
How does the Data Act interact with our existing GDPR compliance program?
The two frameworks should be treated as complementary rather than interchangeable. Where data-sharing activities under the Data Act involve personal data, existing GDPR requirements, such as identifying a lawful basis, honoring data subject rights, and maintaining appropriate governance evidence, continue to apply. Organizations typically need to coordinate their data governance and privacy functions so that Data Act sharing obligations do not conflict with GDPR protections. This entry does not specify cross-border transfer mechanics or lawful basis selection, which must be assessed for each processing activity.
What governance evidence should we maintain to demonstrate Data Act compliance?
Accountability under data governance frameworks generally requires demonstrable evidence rather than stated intent. In practice, this typically means documenting data ownership and stewardship, data lineage and cataloging for the relevant product-generated data, and the policies and mechanisms enabling access and sharing. These governance activities are distinct from information security controls, though the two overlap where access controls protect shared data. This entry does not prescribe a specific tooling approach or retention schedule, both of which depend on context and jurisdiction.
Does making data available under the Data Act create security or confidentiality concerns we should manage separately?
Yes. Enabling data access and sharing raises information security considerations, confidentiality, integrity, and availability, that are separate from, though related to, the governance question of whether and how data should be shared. Applying security controls such as encryption or tokenization to shared data does not, on its own, change the regulatory character of that data; personal data remains personal data even when protected by such controls. Organizations should generally address security and governance as distinct but coordinated workstreams. This entry does not cover specific technical control requirements.

Common misconceptions

The Data Act replaces or supersedes the GDPR for data generated by connected products.
The Data Act does not displace data protection law. Where the data in question is personal data, the EU GDPR continues to apply in parallel, and the roles and obligations of controllers and processors are unaffected. The two instruments should be read together.
The Data Act is a single global standard for data access that applies the same way everywhere.
The Data Act is an EU regulation and should not be treated as interchangeable with other regimes. Treatment of data access and sharing differs across jurisdictions, and this instrument's provisions are scoped to the EU framework rather than being universal.
The Data Act is primarily a security regulation.
The Data Act is oriented toward data access, sharing, and fairness in data-related arrangements, which are governance and market-regulation concerns. It is not a substitute for an information security programme, though secure sharing generally depends on appropriate security controls.

Best practices

Map data generated by connected products and services and determine, on a case-by-case basis, which portions constitute personal data so that GDPR obligations can be applied alongside Data Act requirements.
Maintain clear separation between Data Act access and sharing obligations and existing GDPR controller and processor responsibilities, documenting how each applies to a given data flow.
Treat data governance work (ownership, stewardship, cataloguing, and sharing arrangements) and information security controls as complementary but distinct, and ensure both are addressed where data is shared.
Use qualified, context-specific analysis rather than assuming the Data Act applies uniformly across jurisdictions, and confirm scope against the applicable EU text before relying on any provision.
Keep demonstrable evidence of how data access, sharing, and any related personal data processing decisions are governed, since accountability requires documentation rather than stated intent.
Consult the definitive legal text and qualified counsel for specifics such as effective timing, precise obligations, and cross-border considerations that are out of scope for this general definition.