On 12 September 2025, Regulation (EU) 2023/2854—better known as the Data Act—will come into force. This new European regulation marks a turning point in how businesses access, share and reuse data generated by connected products and services.
If your organisation develops technology, provides digital services or manages data, now is the time to act. Summer is just around the corner, but so is the regulatory shift that will redefine Europe’s data economy.
What the Data Act is and why it matters
The Data Act is one of the European Union’s key efforts to build a single market for data, alongside the Data Governance Act (DGA) and the Digital Services Act (DSA). Its aim: to fairly distribute the value created by data and prevent it from being hoarded by dominant players.
The regulation seeks to ensure that data generated by smart devices and connected platforms is made available to those who truly need it—whether businesses, individuals or public institutions. To do so, it establishes a framework of legal, contractual and technical obligations that digital operators must begin implementing now.
This isn’t a theoretical or distant regulation. It affects concrete decisions—how you design a product, write a contract or enable your clients to switch providers.
Who is affected by the Data Act
Despite its technical language, the Data Act has broad applicability. It targets any company involved in connected products or services, such as:
- Manufacturers of smart devices: electric vehicles, connected appliances, home automation systems or industrial machinery.
- Software and platform developers, including IoT services, productivity apps or cloud platforms.
- Data processing providers, such as SaaS, PaaS or IaaS companies.
- Organisations that control generated data, even if they don’t process it directly.
For example, a company that manufactures security cameras with app integration will need to provide customers with access to the data generated—and in some cases, allow that data to be transferred elsewhere.
What type of data is covered
The regulation focuses on data generated through the use of connected products and services, including:
- Sensor readings (e.g. temperature, location, activity).
- Technical logs generated during software operation.
- Data created by users as they interact with a device or app.
It applies to both personal and non-personal data. In case of conflict, GDPR takes precedence.
Excluded from scope:
- Data that has been transformed through advanced analytics.
- Data whose extraction involves disproportionate effort or cost.
This distinction protects intellectual property and avoids requiring companies to share all derived insights.
What the Data Act means for your company
The regulation introduces three main categories of obligations:
1. Access, transparency and portability
You must:
- Clearly inform users about what data is collected and why.
- Provide access to data generated during product or service use.
- Make this data available in standardised, reusable formats.
This will require reviewing your terms of use, data architecture and privacy policies.
2. Interoperability and vendor switching
If you offer cloud-based services:
- Your solutions must be compatible with competing platforms.
- You cannot restrict users from switching providers or charge unjustified fees.
- You must review contracts and eliminate technical or legal barriers.
This will significantly affect companies operating in closed ecosystems.
3. Security and cooperation with public authorities
Additionally, you must:
- Protect data from unauthorised access or leaks.
- Safeguard trade secrets while remaining compliant.
- Provide access to public authorities where required by law and in the general interest.
This requirement is especially relevant in sectors such as health, energy or transport, where data plays a key role in public interest.
Not just another regulation: a strategic opportunity
To some, the Data Act may seem like a compliance burden. But it also offers a chance to gain a competitive edge in a market that values transparency and innovation.
By adapting early, your company can:
- Build trust with customers and partners.
- Improve internal processes with better data governance.
- Unlock new business models based on responsible data sharing.
- Position your brand as an advanced, ethical player in your industry.
Companies that act now will not just avoid fines—they will lead the digital transformation of the European market.
What you can do right now
If your business operates in the digital ecosystem, don’t wait until September. Start by:
- Auditing your data flows: what you generate, how it’s stored, who accesses it.
- Reviewing client and supplier contracts.
- Evaluating system compatibility and portability.
- Designing an action plan that involves legal and technical teams.
- Training your staff to understand the regulation and its impact.
Across Legal can help
At Across Legal, we help digital companies implement the Data Act strategically and efficiently. Our team offers:
- Tailored legal and technical diagnostics.
- Contract review and drafting.
- Custom compliance plans aligned with your business model.
September is approaching fast. Let’s get started—before the clock runs out.
↳ Discover more content in the section Insight.
↳ Do you want to stay up tp day about the sector related news? Follow us on LinkedIn.




