The European Union’s Data Act, a landmark piece of legislation that came into full effect in September 2025, is fundamentally reshaping the digital economy within the EU and for companies interacting with its market. Spearheaded by the European Commission as a cornerstone of its data strategy, this horizontal regulation aims to democratize access to and use of data generated by connected products and related services, fostering a more equitable distribution of power among manufacturers, users, and service providers. Peter Lando and Stefica Milor of Lando & Anastasi, legal experts specializing in digital regulation, highlight that the Act represents a significant structural shift, impacting intellectual property, privacy, data governance, and competition frameworks.
Chronology and Legislative Background
The journey of the Data Act began with a proposal from the European Commission in February 2022, presented as a crucial step to unlock the economic and societal potential of data in Europe. The Commission envisioned a regulatory framework that would create a level playing field for data-driven innovation while safeguarding fundamental rights. Following extensive deliberations and negotiations within the European Parliament and the Council of the EU, the final text was agreed upon in December 2023. The Act entered into force in January 2024, with most of its provisions becoming applicable from September 12, 2025. A key deadline for new connected products placed on the EU market is September 12, 2026, by which time they must be designed for "access by design."
Key Provisions and Their Impact
At its core, the Data Act grants users—whether consumers or businesses—a statutory right to access the data generated by the connected products and services they use. This encompasses a wide spectrum of data, including raw sensor outputs, pre-processed information, metadata, and machine-generated insights. This broad definition ensures that a comprehensive understanding of a product’s or service’s performance and usage is available to the end-user.
User Access and Control Over Data
The Act mandates that by September 12, 2026, all new connected products entering the EU market must be engineered with "access by design." This means that data generated by these products must be directly, securely, and easily accessible to the user in structured, machine-readable formats. This design principle aims to eliminate technical barriers that have historically hindered user access to their own data. In scenarios where direct access is technically unfeasible, the data holder is obliged to provide the data upon request without undue delay and at no cost to the user.
Furthermore, the Data Act empowers users to instruct data holders to share their generated data with third parties of their choosing. This provision is pivotal for fostering interoperability, enabling multi-vendor maintenance, facilitating independent repair services, and stimulating cross-service innovation. It directly challenges the closed ecosystems that have often characterized the connected product market, where manufacturers have retained exclusive control over product-generated data.
Extraterritorial Reach
A critical aspect of the Data Act is its extraterritorial application. Non-EU companies are brought within its scope whenever EU-based users interact with their products or services. This means that businesses operating globally must ensure their data handling practices align with EU regulations if they have customers within the Union, regardless of their own physical location. This broad reach underscores the EU’s ambition to set global standards for data governance.
Navigating the Intersection of Data Rights, Privacy, and Proprietary Protections
The Data Act operates in conjunction with existing regulations, most notably the General Data Protection Regulation (GDPR). While the Act covers both personal and non-personal data, GDPR remains the governing framework for personal data. In instances where data generated by a connected product also constitutes personal data (e.g., vehicle telemetry linked to a driver), GDPR obligations take precedence. Companies are required to meticulously distinguish between data types, implement data minimization principles, ensure transparency, and verify that user-initiated data sharing does not inadvertently violate data privacy commitments.
One of the most complex challenges presented by the Act lies in the delicate balance between user data rights and the protection of manufacturers’ intellectual property, particularly trade secrets and database rights. Manufacturers often argue that device telemetry and operational data contain proprietary information about their production methods, algorithmic performance, diagnostic logic, and product design.
To address this, the Data Act introduces a "trade secrets handbrake" mechanism. Before disclosing data that may contain trade secrets, a data holder can identify the specific information deemed proprietary. They can then impose proportionate confidentiality obligations and technical safeguards on the recipient. In exceptional circumstances, if adequate protections cannot be agreed upon, the data holder may refuse disclosure. However, this "handbrake" is not an unfettered veto. The Act specifies that companies cannot broadly designate all data as proprietary, and users retain the right to challenge overly expansive claims of trade secrecy.
Moreover, the Act explicitly prohibits the use of certain database rights to obstruct user access to data generated by connected products. This targeted measure is designed to prevent companies from leveraging database protections to create monopolies over machine-generated datasets.
Restrictions on Third-Party Data Use
The Data Act imposes stringent restrictions on how third parties receiving user-authorized data can utilize it. These obligations include:
- Adhering to GDPR principles when handling personal data.
- Prohibiting the use of shared data to develop competing products.
- Limiting data usage solely to the specific purpose agreed upon with the user.
- Acknowledging that misuse of trade secret-protected data will result in legal and commercial consequences.
These measures are intended to ensure that the enhanced data access rights promote innovation and fair competition, rather than enabling unfair competitive practices.
Economic Opportunities and Organizational Readiness
While the Data Act introduces compliance requirements, it also unlocks significant economic potential for businesses that proactively adapt. Companies modernizing their data architectures, enhancing interoperability capabilities, and updating their contractual frameworks are poised to:
- Offer Premium Data-Enabled Services: Develop advanced analytics and value-added services leveraging accessible product data.
- Expand into Aftermarket Services: Break into service markets previously constrained by proprietary data access limitations.
- Build Trust and Brand Reputation: Market themselves as "Data Act ready," signaling a commitment to transparency and user-centricity.
- Enhance Customer Value: Provide greater transparency and control over data, fostering stronger customer relationships.
- Compete Effectively: Thrive in multi-vendor and modular ecosystems where data sharing is a key differentiator.
To capitalize on these opportunities, businesses are advised to undertake several key steps:
- Assess Product Data Flows: Conduct a thorough audit of all data generated, collected, and transmitted by their connected products and related services.
- Update User Materials and Agreements: Revise user manuals, terms of service, and business-to-business (B2B) contracts to clearly outline data access rights, third-party sharing processes, and fair terms of use.
- Prepare Cloud and SaaS Playbooks: Develop detailed guides for migrating data and services in compliance with the Act, particularly regarding migration support.
- Establish Cross-Functional Governance: Create internal governance structures involving legal, privacy, product development, engineering, intellectual property, and security teams to ensure comprehensive implementation of the Act’s obligations.
- Identify and Protect Trade Secrets: Proactively map operational and telemetry data that may constitute trade secrets and define robust disclosure safeguards.
- Incorporate User Access and Sharing Rights into Contracts: Update existing and future contracts to explicitly address user data access and sharing provisions.
- Specify Confidentiality Measures: Clearly define and implement confidentiality measures for sensitive data shared under the Act’s provisions.
Broader Implications and Industry Reactions
The EU Data Act represents a bold move by the European Union to assert greater control over the data economy. Industry reactions have been mixed, with some acknowledging the potential for innovation and others expressing concerns about the complexity of compliance and the potential erosion of competitive advantages derived from proprietary data.
Consumer advocacy groups have largely welcomed the Act, viewing it as a significant step towards empowering individuals and small businesses in their interactions with increasingly sophisticated connected technologies. Technology industry associations have emphasized the need for clear guidance and a phased implementation to allow companies sufficient time to adapt their systems and business models.
Analysis of Impact
The Data Act’s impact is likely to be profound and far-reaching. It signals a shift away from a data-hoarding model towards a more collaborative and accessible data ecosystem. For manufacturers, it necessitates a fundamental re-evaluation of their data strategies, moving from data as a purely internal asset to data as a shared resource. This could lead to increased competition in areas like after-sales services, repair, and data analytics, potentially benefiting consumers through lower prices and greater choice.
However, the success of the Act will hinge on its practical implementation and enforcement. The "trade secrets handbrake" and the detailed restrictions on third-party data use will require careful interpretation and robust oversight to prevent misuse or circumvention. The extraterritorial reach also presents a challenge for global businesses, requiring a harmonized approach to data governance that acknowledges the EU’s stringent requirements.
In conclusion, the EU Data Act is more than just a regulatory update; it is a fundamental redefinition of data ownership and control in the age of connected products. By rebalancing power dynamics and fostering a more open data environment, the Act aims to drive innovation, enhance competition, and ultimately benefit users across the European Union and beyond. Companies that embrace its principles and proactively adapt their operations stand to gain a significant competitive edge in the evolving digital landscape.
