News
Understanding the EU data act and its impact on business
Category
Commercial, EU
Date
Riz, Solicitor at Square One Law, outlines the key business take-aways from the EU data act…
The EU Data Act came into effect on 11th January 2024 and is poised to transform data governance across the European Union.
The legislation is designed to promote fairness, stimulate innovation, and enhance accessibility in the data economy.
Important provisions will be coming into effect over the next two years as a result of the legislation, related to data access and sharing.
Despite the UK no longer being part of the EU, the Data Act will have significant implications for UK businesses, particularly those involved in the EU market.
Here is a detailed overview of what you need to know…
What are the key provisions?
- Data accessibility:
- User rights – Users and third parties will have the right to access and use data generated by connected devices. This data must be provided securely, free of charge, and in a commonly used, machine-readable format.
- Data sharing obligations:
- Manufacturers and service providers – Must design products and services to ensure that data is easily accessible to users. They are required to provide information about the data generated, how it can be accessed, retrieved, or erased, prior to contract completion.
- Third-party access – Upon user request, data holders must share data with third parties under fair, reasonable, and non-discriminatory terms. This includes situations where data sharing is mandated by EU or Member State law.
- Protection against unfair practices:
- Contractual Fairness – The Act introduces measures to protect businesses from unfair contractual terms in data-sharing agreements. It prohibits businesses from imposing unfair terms on others concerning data access and usage.
- Trade secrets and data security:
- Trade Secrets – While the Data Act mandates data sharing, it also safeguards trade secrets. Data holders can refuse data sharing in exceptional circumstances if it can be demonstrated that serious economic damage would result from the disclosure.
- Technical Measures – Appropriate technical protection measures, including encryption and smart contracts, must be applied to prevent unauthorised access.
- Public sector access:
- Emergency Situations: Legal entities may be required to share data with public sector bodies during public emergencies where timely access to data is essential.
- Cloud service portability:
- Provider switching – The Data Act requires cloud service providers to facilitate easier switching between services by removing technical, contractual, and commercial barriers. This is aimed at preventing vendor lock-in and promoting a competitive cloud services market.
- Sector-specific rules:
- The Act includes tailored regulations for specific industries like healthcare and automotive, addressing their unique challenges and opportunities in data sharing.
- Transparency:
- Strong transparency obligations are instituted, requiring manufacturers to inform users about the data their products can generate before concluding contracts. This promotes clarity and trust in data handling practices.
- Dispute Resolution and Enforcement:
- The Data Act establishes mechanisms for resolving disputes related to data sharing and sets out enforcement provisions. This includes the designation of competent authorities and the establishment of penalties for non-compliance by EU Member States.
What key dates should I look out for?
The legislation came into effect as of 11th January, but going forward, business leaders may also want to keep an eye on the following…
- 12th September 2025 – Provisions on data access and sharing start to apply.
- 12th September 2026 – Design and manufacturing requirements for simplified data access come into effect for products placed on the market after this date.
- 12th September 2027 – Unfair contractual terms provisions apply to contracts concluded before 12 September 2025.
What are the potential implications for businesses?
- Manufacturers:
- Product redesign – Manufacturers must redesign products to ensure data accessibility, which involves integrating mechanisms that allow users and third parties to easily access and transfer data. This will likely require significant investments in product development and adjustments to current manufacturing processes.
- Compliance with technical measures – Manufacturers must implement robust technical measures to safeguard data, including encryption and the use of smart contracts to automate and secure data-sharing processes.
- Service Providers:
- Data portability – Service providers, especially in the cloud services sector, need to ensure that their systems facilitate data portability. This includes enabling customers to switch between services without encountering significant technical or contractual barriers.
- Interoperability standards – Providers must comply with interoperability standards to ensure seamless data transfer and usage across different platforms, promoting a competitive market environment.
- Small and medium-sized enterprises (SMEs):
- Protections against unfair practices – SMEs benefit from enhanced protections against unfair contractual terms, ensuring they are not exploited by larger entities in data-sharing agreements. This promotes a more equitable data economy where smaller players can compete more effectively.
- Support for Innovation – The Data Act’s provisions on data access and sharing can help SMEs innovate by providing access to valuable data that was previously inaccessible. This can lead to the development of new products and services, fostering growth and competitiveness.
- All businesses:
- Compliance with GDPR – Businesses must ensure that data handling practices under the Data Act are compliant with GDPR requirements, particularly when dealing with personal data. This dual compliance ensures robust data protection and privacy standards.
- Legal and Technical Adjustments – The broad scope of the Data Act means that businesses across various sectors will need to adjust their data handling, storage, and sharing practices. This may involve significant legal and technical adjustments to ensure full compliance with the Act’s requirements.
What else do I need to know?
UK manufacturers of connected products, providers of data processing services, and data holders offering services to EU clients will need to comply with the Data Act.
This extraterritorial reach mirrors the impact of the GDPR, requiring UK businesses to align with EU data standards to continue operating within the EU market.
Furthermore, the Data Act might set a global benchmark, encouraging UK businesses to adopt similar standards domestically to maintain competitiveness and ensure seamless data interoperability with EU counterparts.
Businesses should start preparations now to ensure compliance and leverage the opportunities for innovation and growth that the Data Act aims to foster.










