The EU Data Act is a European Union regulation that sets rules on who can access and use data generated by connected products and related services, how cloud and other data processing services must let customers switch providers, and how those providers must guard non-personal data against unlawful access by non-EU governments. The European Commission states it has applied since September 2025, with some parts phasing in later. For IT buyers, its most direct effects are on cloud contracts and exit plans. This entry is an overview for buyers, not legal advice.
At a glance
- It applies to data from connected products, business-to-business data sharing, public-sector access in exceptional cases, and cloud and data processing services.
- Cloud customers gain rights to switch providers or move back on-premises, with limits on notice periods, transition time and switching fees.
- Providers must take measures against non-EU government access to non-personal data held in the EU where it would conflict with EU or national law.
- It covers non-personal data as well as personal data; GDPR still applies to personal data.
- Amendments are under discussion, so confirm the current text before relying on specific obligations.
What problem it solves
Two problems drive the Data Act. First, the companies that make connected devices, from industrial machines to vehicles, often controlled the data those devices produced, leaving the businesses and people using them with little access. Second, cloud customers found it hard to leave a provider: long notice periods, high data transfer fees, proprietary formats and unclear exit support created lock-in.
A third concern sits alongside these. GDPR limits foreign orders for personal data, but much business data, such as engineering files, machine telemetry or financial models, is not personal. The Data Act extends a similar safeguard to non-personal data held by cloud providers in the EU, which matters to buyers worried about foreign laws such as the US CLOUD Act.
How it works
Connected-product data. Users of connected products and related services can access the data their use generates and share it with third parties of their choice, subject to protections for trade secrets and security. New products must be designed to make such data accessible.
Fair data-sharing terms. Contract terms on data access and use that one party imposes on another business can be unenforceable if they are unfair, and data-sharing obligations come with rules on compensation and dispute resolution.
Cloud switching. Providers of data processing services, including cloud infrastructure, platform and software services, must remove obstacles to switching. The current text sets a maximum notice period of two months, a transition period of 30 days that can be extended in set circumstances, a period for retrieving data, and deletion afterward. Providers may charge only reduced switching fees until January 2027, after which switching charges are not allowed. Depending on the type of service, providers must work toward functional equivalence, offer open interfaces, or export data in structured, commonly used, machine-readable formats.
Foreign government access. Providers must take adequate technical, organizational and legal measures, including contracts, against non-EU government access to or transfer of non-personal data held in the EU where it would conflict with EU or national law. A foreign order is enforceable mainly when based on an international agreement; without one, disclosure is allowed only under set conditions, the provider must disclose the minimum data permissible, and the customer is to be told first unless secrecy is needed for a law-enforcement investigation.
Obligations by actor
The Data Act has no certification levels; its structure is a set of roles, each with its own obligations.
| Actor | Who it covers | Main obligations or rights | What buyers typically see as evidence |
|---|---|---|---|
| Users | Businesses and consumers that own, rent or lease a connected product or use a related service | Right to access product data and share it with third parties | Data access portals and terms in product contracts |
| Data holders | Companies with the right or duty to use and make available data from connected products | Make data available to users and authorized third parties on fair terms; protect trade secrets | Data-sharing terms, access request processes |
| Data recipients | Third parties receiving data at a user’s request | Use data only for agreed purposes; no use to build competing products | Data-sharing agreements |
| Data processing service providers | Cloud and other data processing service providers serving EU customers | Switching support, limits on switching fees, interoperability, safeguards against unlawful non-EU government access | Switching and exit terms, fee schedules, government-access policy |
| Public sector bodies | Public authorities with an exceptional need | May request data in specified cases such as public emergencies | Formal requests stating purpose and legal basis |
When it matters for buyers
- When negotiating or renewing cloud contracts. Check exit terms, notice periods, data export formats and how switching fees are handled under the current rules.
- When planning a migration or a multi-cloud strategy. Switching rights can lower the cost of moving, but technical work still takes time.
- When non-personal business data is sensitive. Ask how the provider responds to non-EU government requests.
- When you make or buy connected products. Data access rights affect product design and service contracts for IoT deployments.
Our public cloud overview covers how to build exit planning into provider selection.
Questions to ask vendors
- What are your notice, transition and data retrieval periods if we switch, and how do they match the Data Act?
- Which switching or data egress charges apply today, and how will they change?
- In what formats and through which interfaces can we export our data and configurations?
- What measures do you take against non-EU government requests for our non-personal data, and will you notify us?
- Where is our data stored, and who can be compelled to disclose it?
- Which of your services do you treat as custom-built or otherwise exempt from switching rules?
How it differs from GDPR
GDPR is about personal data: lawful use, individuals’ rights and transfers outside Europe. The Data Act is about access to and use of data generally, personal or not, and about competition in cloud services. They overlap where personal data is involved, and GDPR prevails on personal data protection. Both limit foreign government reach in different ways, which is why buyers treat them together under data sovereignty, a separate question from data residency. Related EU measures include the e-Evidence Regulation for criminal investigations the proposed EUCS certification scheme for cloud security, and the proposed Cloud and AI Development Act (CADA), which would set sovereignty levels for public-sector cloud use. A cloud migration plan should account for the switching rules.
