Understanding the EU Data Act: Regulation (EU) 2023/2854 Compliance Guide
The EU Data Act (Regulation (EU) 2023/2854)is one of the European Union's most consequential digital regulations, entering into application on September 12, 2025. Together with the General Data Protection Regulation (GDPR), the Digital Markets Act (DMA), the Digital Services Act (DSA), and the Network and Information Security Directive (NIS2), the Data Act forms the backbone of the EU single market for data.
1. Statutory Scope & Role Classifications
The Data Act applies broadly to any enterprise generating, processing, or sharing data in connection with products placed on the EU market:
- Manufacturers of Connected Products: Any manufacturer of physical items that obtain, generate, or collect data concerning their use or environment and communicate that data (e.g., smart home appliances, medical hardware, industrial robots, connected vehicles, wind turbines).
- Providers of Related Digital Services: Software applications, cloud synchronization tools, or companion mobile apps interconnected with a connected product.
- Data Holders: Entities possessing the legal entitlement or technical ability to control and deploy product telemetry.
- Data Processing Services: Cloud computing, edge infrastructure, and SaaS providers (IaaS, PaaS, SaaS) operating within the Union.
2. The Article 7(1) SME Exemption Framework
To protect European innovation and reduce administrative burden on agile businesses, Article 7(1) exempts microenterprises (fewer than 10 employees, turnover/balance sheet ≤ €2M) and small enterprises (fewer than 50 employees, turnover/balance sheet ≤ €10M) from the onerous obligations of Chapter II (connected product direct access and portability) and Chapter III (B2B data sharing).
However, corporate counsel must be vigilant: under Recommendation 2003/361/EC, if an SME is owned 25% or more by a corporate parent, group headcount and turnover aggregate, nullifying the exemption. Furthermore, if an SME is contracted by a large OEM to manufacture a connected product, the exemption does not shield the product from the Data Act's data-by-design obligations.
3. Connected Product Data Access by Design (Articles 3 to 7)
Under Article 3(1), products must be designed so that generated telemetry is directly accessible to the user by default, securely and free of charge. If direct hardware-level access is technically infeasible, the data holder must provide immediate, real-time access via secure APIs without undue delay (Article 4).
Crucially, under Article 5, users have an enforceable statutory right to port their data to third-party service providers (such as independent repair facilities or aftermarket parts suppliers). However, under Article 5(2), entities designated as "Gatekeepers" under the Digital Markets Act (Regulation (EU) 2022/1925)—including Alphabet, Amazon, Apple, Meta, Microsoft, and ByteDance—are strictly barred from receiving user data under this portability provision, preventing hyperscalers from entrenching market dominance.
4. Article 13 Unfair Contractual Terms: The Blacklist & Greylist
Article 13 introduces an unprecedented contractual fairness standard for B2B data sharing agreements that have been unilaterally imposed on an enterprise.
- The Blacklist (Article 13(4)): Clauses that are per se unfair and void as a matter of law. Any clause excluding liability for intentional misconduct or gross negligence, excluding remedies for non-performance, or giving one party exclusive discretion to judge whether data conforms to the contract is automatically invalid.
- The Greylist (Article 13(5)): Clauses presumed unfair unless the imposing party can prove their reasonableness under the circumstances. These include unilateral contract modification rights, unreasonably short termination notice periods, and provisions blocking legitimate data exploitation.
5. Cloud Switching & Egress Fee Phaseout Timeline (Articles 23 to 29)
One of the Data Act's most disruptive market interventions is the elimination of customer switching barriers in cloud and edge computing:
Transitional Cap (Sept 12, 2025 – Jan 11, 2027)
Under Article 29(1), switching charges and data egress fees are strictly capped to the direct costs incurred by the provider (e.g. basic network transit costs). All profit markups, egress surcharges, and penal administrative fees are illegal.
Zero-Fee Rule (Effective Jan 12, 2027)
Under Article 29(2), providers of data processing services are completely prohibited from imposing switching charges (EUR 0.00). Customers can migrate data or switch providers free of charge.
6. Administrative Penalties & Sanctions (Article 40)
Enforcement of the EU Data Act is coordinated through national competent authorities designated by Member States. For violations of Chapters II, III, and V, penalties mirror the severity of the GDPR under Article 83: supervisory authorities may impose administrative fines up to €20,000,000 or4% of the enterprise's total worldwide annual turnover of the preceding financial year, whichever is higher.