What Is the EU Data Act?

Also called: Data Act, Regulation (EU) 2023/2854

Related problems: Our cloud provider makes it expensive and slow to leave; Worried a foreign government could demand our business data from our cloud provider; Customers want access to the data our connected products generate; Not sure what our cloud contract must allow when we switch providers

The EU Data Act is a European Union regulation that sets rules on who can access and use data generated by connected products and related services, how cloud and other data processing services must let customers switch providers, and how those providers must guard non-personal data against unlawful access by non-EU governments. The European Commission states it has applied since September 2025, with some parts phasing in later. For IT buyers, its most direct effects are on cloud contracts and exit plans. This entry is an overview for buyers, not legal advice.

At a glance

  • It applies to data from connected products, business-to-business data sharing, public-sector access in exceptional cases, and cloud and data processing services.
  • Cloud customers gain rights to switch providers or move back on-premises, with limits on notice periods, transition time and switching fees.
  • Providers must take measures against non-EU government access to non-personal data held in the EU where it would conflict with EU or national law.
  • It covers non-personal data as well as personal data; GDPR still applies to personal data.
  • Amendments are under discussion, so confirm the current text before relying on specific obligations.

What problem it solves

Two problems drive the Data Act. First, the companies that make connected devices, from industrial machines to vehicles, often controlled the data those devices produced, leaving the businesses and people using them with little access. Second, cloud customers found it hard to leave a provider: long notice periods, high data transfer fees, proprietary formats and unclear exit support created lock-in.

A third concern sits alongside these. GDPR limits foreign orders for personal data, but much business data, such as engineering files, machine telemetry or financial models, is not personal. The Data Act extends a similar safeguard to non-personal data held by cloud providers in the EU, which matters to buyers worried about foreign laws such as the US CLOUD Act.

How it works

Connected-product data. Users of connected products and related services can access the data their use generates and share it with third parties of their choice, subject to protections for trade secrets and security. New products must be designed to make such data accessible.

Fair data-sharing terms. Contract terms on data access and use that one party imposes on another business can be unenforceable if they are unfair, and data-sharing obligations come with rules on compensation and dispute resolution.

Cloud switching. Providers of data processing services, including cloud infrastructure, platform and software services, must remove obstacles to switching. The current text sets a maximum notice period of two months, a transition period of 30 days that can be extended in set circumstances, a period for retrieving data, and deletion afterward. Providers may charge only reduced switching fees until January 2027, after which switching charges are not allowed. Depending on the type of service, providers must work toward functional equivalence, offer open interfaces, or export data in structured, commonly used, machine-readable formats.

Foreign government access. Providers must take adequate technical, organizational and legal measures, including contracts, against non-EU government access to or transfer of non-personal data held in the EU where it would conflict with EU or national law. A foreign order is enforceable mainly when based on an international agreement; without one, disclosure is allowed only under set conditions, the provider must disclose the minimum data permissible, and the customer is to be told first unless secrecy is needed for a law-enforcement investigation.

Obligations by actor

The Data Act has no certification levels; its structure is a set of roles, each with its own obligations.

Actor Who it covers Main obligations or rights What buyers typically see as evidence
Users Businesses and consumers that own, rent or lease a connected product or use a related service Right to access product data and share it with third parties Data access portals and terms in product contracts
Data holders Companies with the right or duty to use and make available data from connected products Make data available to users and authorized third parties on fair terms; protect trade secrets Data-sharing terms, access request processes
Data recipients Third parties receiving data at a user’s request Use data only for agreed purposes; no use to build competing products Data-sharing agreements
Data processing service providers Cloud and other data processing service providers serving EU customers Switching support, limits on switching fees, interoperability, safeguards against unlawful non-EU government access Switching and exit terms, fee schedules, government-access policy
Public sector bodies Public authorities with an exceptional need May request data in specified cases such as public emergencies Formal requests stating purpose and legal basis

When it matters for buyers

  • When negotiating or renewing cloud contracts. Check exit terms, notice periods, data export formats and how switching fees are handled under the current rules.
  • When planning a migration or a multi-cloud strategy. Switching rights can lower the cost of moving, but technical work still takes time.
  • When non-personal business data is sensitive. Ask how the provider responds to non-EU government requests.
  • When you make or buy connected products. Data access rights affect product design and service contracts for IoT deployments.

Our public cloud overview covers how to build exit planning into provider selection.

Questions to ask vendors

  • What are your notice, transition and data retrieval periods if we switch, and how do they match the Data Act?
  • Which switching or data egress charges apply today, and how will they change?
  • In what formats and through which interfaces can we export our data and configurations?
  • What measures do you take against non-EU government requests for our non-personal data, and will you notify us?
  • Where is our data stored, and who can be compelled to disclose it?
  • Which of your services do you treat as custom-built or otherwise exempt from switching rules?

How it differs from GDPR

GDPR is about personal data: lawful use, individuals’ rights and transfers outside Europe. The Data Act is about access to and use of data generally, personal or not, and about competition in cloud services. They overlap where personal data is involved, and GDPR prevails on personal data protection. Both limit foreign government reach in different ways, which is why buyers treat them together under data sovereignty, a separate question from data residency. Related EU measures include the e-Evidence Regulation for criminal investigations the proposed EUCS certification scheme for cloud security, and the proposed Cloud and AI Development Act (CADA), which would set sovereignty levels for public-sector cloud use. A cloud migration plan should account for the switching rules.

Frequently Asked Questions

Does the EU Data Act apply to companies outside the EU?
It can. Its cloud switching rules apply to providers offering data processing services to customers in the EU, and its connected-product rules apply to products placed on the EU market, wherever the company is based. Whether it applies to you depends on the facts, so check with counsel; this is not legal advice.
Does the Data Act make cloud switching free?
Under the current text, providers may charge only reduced switching fees limited to their direct costs until January 2027, after which switching charges are no longer allowed. Some fees, such as charges under fixed-term contracts, are debated, and amendments have been proposed, so check the current text and your contract.
How does the Data Act protect our data from foreign governments?
It requires cloud and other data processing service providers to take adequate technical, legal and organizational measures against non-EU government access to non-personal data held in the EU where that would conflict with EU or national law. Foreign orders are generally honored only on the basis of an international agreement or set conditions, and customers are to be told before disclosure in many cases.
How is the Data Act different from GDPR?
GDPR protects personal data and individuals' rights. The Data Act covers both personal and non-personal data, and focuses on who can access and use data, fair data-sharing terms and switching between cloud providers. Where personal data is involved, GDPR continues to apply alongside it.
Is the Data Act already in force?
Yes. The European Commission states it has applied since September 2025, with some obligations phased in later, such as design rules for new connected products and the end of switching charges. Changes have been proposed as part of a wider EU simplification package, so confirm the current position with counsel.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.