Most privacy teams spent 2025 focused on GDPR enforcement and cookie consent. Meanwhile, a different piece of EU law quietly started applying — one that is not a privacy law at all, but lands squarely on the same teams: the EU Data Act.
The Data Act (Regulation (EU) 2023/2854) entered into force in January 2024 and became applicable from 12 September 2025. It governs who can access and share the data generated by connected products and digital services — and although it is a data governance regulation rather than a data protection one, it overlaps with GDPR often enough that compliance teams cannot treat it as someone else's problem.
Here is what it changes and where it touches your existing privacy work.
What the Data Act Actually Regulates
Where GDPR is about personal data, the Data Act is about all the data that connected products and related services generate — personal and non-personal alike. Its core aim is to rebalance who benefits from that data.
Four areas matter most:
- Access to product data. Users of connected products (think industrial sensors, vehicles, smart devices) get the right to access the data those products generate and to share it with third parties of their choosing.
- Fairer B2B data sharing. The Act polices unfair contractual terms imposed on the party generating or sharing data, so the stronger party cannot simply write itself all the rights.
- Cloud switching. Cloud and other data-processing providers must make it easier for customers to switch providers or move data back in-house, with switching charges phased out over time.
- B2G data sharing. Public bodies can request data from businesses in situations of exceptional need, such as a public emergency.
None of that reads like a privacy rule. The catch is that a great deal of the data generated by connected products is personal data — and that is where your world and the Data Act's collide.
Where It Overlaps With GDPR
The Data Act is explicit that it does not diminish GDPR. Where the data in question is personal data, the GDPR still applies in full, and it prevails in the event of a conflict.
That creates concrete questions for compliance teams:
- A new access right sits next to Article 15. A user's Data Act right to access product data can cover the same records as a GDPR access request — but the two rights have different scopes, triggers, and recipients. Your intake process needs to tell them apart. Our guide to GDPR DSAR response deadlines covers the access-request side; the Data Act adds a second, parallel channel.
- Sharing data with a third party needs a lawful basis. When a user asks you to share product data that includes personal data with another company, the Data Act gives them the right to ask — but GDPR still governs whether and how you may transfer it, and often whose personal data is involved beyond the requester's.
- Non-personal and personal data are frequently mixed. Real datasets rarely split cleanly. When they are inseparable, you have to treat the whole set to the GDPR standard for the personal parts.
The practical takeaway: the Data Act does not loosen anything in GDPR. It adds obligations on top of it.
Who Is In Scope
The Data Act reaches further than "IoT manufacturers." It can apply to makers of connected products and providers of related services, to businesses that receive data at a user's request, to cloud and edge providers, and — through the switching and B2G rules — to a wide range of data-processing services. Many mid-market SaaS and hardware companies that assumed this was an industrial-IoT issue are, in fact, in scope.
If your product generates usage data for customers, or if you rely on a cloud provider you might one day want to leave, the Data Act touches you.
What to Do Now
You do not need a separate "Data Act programme" bolted onto your privacy work. You need to extend what you already have:
- Map product-generated data. Add connected-product and service-generated data to your existing data inventory, flagging what is personal, what is non-personal, and what is mixed.
- Extend your request intake. Make sure your team can recognise a Data Act access/sharing request and route it correctly, without conflating it with a GDPR DSAR.
- Review your data-sharing contracts. Check B2B terms against the Act's fairness rules — the terms that let the stronger party keep all the data rights are exactly what it targets.
- Check your cloud exit. Understand your provider's switching support and egress terms; the Act is pushing these toward portability, and your contracts should reflect it.
- Keep GDPR as the backstop. For any personal data caught by a Data Act right, run it through your normal GDPR analysis — lawful basis, minimisation, transfer safeguards.
Step 5 is where the two regimes meet in practice. A Data Act request to share product data abroad, for instance, still needs a valid GDPR transfer mechanism — the subject of our guide on international data transfers.
The Bottom Line
The EU Data Act is not a privacy law, but it lands on privacy teams because so much product data is personal data. It adds access rights, data-sharing obligations, and cloud-portability duties — all of which have to be reconciled with a GDPR that still takes precedence wherever personal data is involved.
The organisations that will struggle are the ones treating it as a purely commercial or engineering matter. The ones that will cope have simply extended their existing data map, request intake, and contract review to cover product data too. To see how privacy rules are actually being enforced across the EU, browse our enforcement monitor.




