PrivacyCache← All articles
Guides

The EU Data Act: What Privacy and Compliance Teams Need to Know

5 min read
Engineer connecting a rugged tablet to sensor-equipped industrial machinery on a factory floor

Most privacy teams spent 2025 focused on GDPR enforcement and cookie consent. Meanwhile, a different piece of EU law quietly started applying — one that is not a privacy law at all, but lands squarely on the same teams: the EU Data Act.

The Data Act (Regulation (EU) 2023/2854) entered into force in January 2024 and became applicable from 12 September 2025. It governs who can access and share the data generated by connected products and digital services — and although it is a data governance regulation rather than a data protection one, it overlaps with GDPR often enough that compliance teams cannot treat it as someone else's problem.

Here is what it changes and where it touches your existing privacy work.

What the Data Act Actually Regulates

Where GDPR is about personal data, the Data Act is about all the data that connected products and related services generate — personal and non-personal alike. Its core aim is to rebalance who benefits from that data.

Four areas matter most:

None of that reads like a privacy rule. The catch is that a great deal of the data generated by connected products is personal data — and that is where your world and the Data Act's collide.

Where It Overlaps With GDPR

The Data Act is explicit that it does not diminish GDPR. Where the data in question is personal data, the GDPR still applies in full, and it prevails in the event of a conflict.

That creates concrete questions for compliance teams:

The practical takeaway: the Data Act does not loosen anything in GDPR. It adds obligations on top of it.

Who Is In Scope

The Data Act reaches further than "IoT manufacturers." It can apply to makers of connected products and providers of related services, to businesses that receive data at a user's request, to cloud and edge providers, and — through the switching and B2G rules — to a wide range of data-processing services. Many mid-market SaaS and hardware companies that assumed this was an industrial-IoT issue are, in fact, in scope.

If your product generates usage data for customers, or if you rely on a cloud provider you might one day want to leave, the Data Act touches you.

What to Do Now

You do not need a separate "Data Act programme" bolted onto your privacy work. You need to extend what you already have:

  1. Map product-generated data. Add connected-product and service-generated data to your existing data inventory, flagging what is personal, what is non-personal, and what is mixed.
  2. Extend your request intake. Make sure your team can recognise a Data Act access/sharing request and route it correctly, without conflating it with a GDPR DSAR.
  3. Review your data-sharing contracts. Check B2B terms against the Act's fairness rules — the terms that let the stronger party keep all the data rights are exactly what it targets.
  4. Check your cloud exit. Understand your provider's switching support and egress terms; the Act is pushing these toward portability, and your contracts should reflect it.
  5. Keep GDPR as the backstop. For any personal data caught by a Data Act right, run it through your normal GDPR analysis — lawful basis, minimisation, transfer safeguards.

Step 5 is where the two regimes meet in practice. A Data Act request to share product data abroad, for instance, still needs a valid GDPR transfer mechanism — the subject of our guide on international data transfers.

The Bottom Line

The EU Data Act is not a privacy law, but it lands on privacy teams because so much product data is personal data. It adds access rights, data-sharing obligations, and cloud-portability duties — all of which have to be reconciled with a GDPR that still takes precedence wherever personal data is involved.

The organisations that will struggle are the ones treating it as a purely commercial or engineering matter. The ones that will cope have simply extended their existing data map, request intake, and contract review to cover product data too. To see how privacy rules are actually being enforced across the EU, browse our enforcement monitor.

Stay ahead of privacy regulations

Get compliance insights delivered to your inbox — new regulations, enforcement actions, and practical tips.

We respect your privacy. Privacy Policy

Related articles

Cookie banner audit shown on a laptop with compliance checks and tracker signals
Guides6 min read

Is Your Cookie Banner Actually Legal? A 2026 Self-Audit Guide

Most cookie banners set up before 2023 are no longer compliant. Use this 2026 self-audit to check whether your cookie banner is actually legal.

Australia Privacy Act reform workbench with layered compliance controls and reform documents
Guides18 min read

Australia Privacy Act Reform 2026: Small Business Exemption Removal

Australia's 2026 Privacy Act reform: is the small business exemption being removed? Plus the privacy tort, tougher OAIC powers, and how to prepare.

Distributed team compliance network connecting remote work locations across jurisdictions
Guides23 min read

Privacy Compliance for Remote Teams: Navigating Multi-Jurisdiction Challenges

Privacy compliance for remote teams: when foreign laws apply, conflicting rules, DSAR deadlines across regions, and a practical framework.

Track real GDPR enforcement actions

Monitor fines from 30+ European data protection authorities. Understand what violations get penalized and benchmark your risk.

Browse Enforcement Actions