Data Act

Data Act applies to your AI system if it runs on a connected product, holds data generated by one, or is hosted on switchable cloud infrastructure. Most product teams haven’t mapped it.

EU compliance consultancy
EU compliance consultancy

How DSA works for AI products

The Data Act has applied since 12 September 2025, with access-by-design obligations for connected products following from 12 September 2026.

Data Act covers:

  • Manufacturers of connected products and providers of related services placed on the EU market
  • The data holders who control the data those products generate
  • The data recipients who receive it, providers of cloud and edge computing services used in the EU
  • Public sector bodies requesting data under exceptional need.

If your AI system runs on or inside a physical connected product sold into the EU, processes data generated by one, or is hosted on cloud or edge infrastructure offered to EU customers, Data Act reaches you — regardless of whether you are established in the EU and regardless of whether you think of yourself as a hardware company.

Data Act’s core demand is access: the user who generated the data, and in some cases a third party the user names, gets to have it, in a usable format, without the manufacturer or data holder standing in the way.

For AI systems this creates specific obligations around access-by-design in connected products, fair terms when AI training or inference data is shared with third parties, and switching rights for the cloud infrastructure AI workloads run on.

These obligations sit alongside and frequently interact with GDPR, where the data in question is personal, and with the EU AI Act’s own data governance requirements.

Data Act Compliance Assessment for Your AI System

Named lawyer · AI and connected-product specific · Delivered in 5 working days

Data Act and Your AI Product

EU compliance consultancy

Data Act organises its requirements across five areas. Each creates specific obligations for AI systems embedded in, trained on, or hosted alongside connected products and cloud infrastructure.

Access by design
Connected products and related services placed on the EU market from 12 September 2026 must be designed so that the data they generate is, by default, directly accessible to the user in an easy, secure, structured, and machine-readable format, including in real time where technically feasible.

An AI feature embedded in a connected product — a smart appliance, wearable, vehicle, or piece of industrial equipment — does not get a design exemption because the data pipeline runs through a model rather than a simple sensor log.

B2B data sharing and FRAND terms
Where a user requests it, the data holder must make the data generated by a connected product available to a third-party data recipient on fair, reasonable, and non-discriminatory terms.

Where the AI system is the data holder, or where an AI company is the requested third-party recipient, both sides of that exchange carry obligations — one to share without excessive friction, the other not to use the data to build a product that competes with the one it came from.

Unfair contract term protections
Contract terms imposed on SMEs and micro-enterprises that unilaterally restrict, override, or circumvent Data Act data-sharing rights are unenforceable.

Standard-form AI licensing and data-processing agreements written before September 2025 are a common source of now-unenforceable clauses, particularly around exclusivity over generated data.

Business-to-government data sharing
Public sector bodies and Union institutions can request data, including data processed or generated by an AI system, from private data holders in situations of exceptional need — public emergencies or where data is necessary to fulfil a specific legal mandate and cannot reasonably be obtained another way. Requests must be proportionate and the data holder is entitled to compensation in most cases.

Switching between data processing services
Providers of cloud and edge computing services used in the EU must remove technical, contractual, and financial barriers to switching, support standard export formats, and phase out switching charges entirely by January 2027.

Where your AI system’s training or inference infrastructure runs on a third-party cloud, or where you are the cloud provider hosting other companies’ AI workloads, this obligation reaches you directly.

Who Data Act Applies to

Data Act applies directly to manufacturers, data holders, data processing service providers, and — under specific data-sharing obligations — data recipients, regardless of where they are established.

AI companies frequently find themselves in scope of the Data Act through the connected product their AI feature sits inside, or through the cloud infrastructure their models run on, without having identified either as the trigger.

Entity typeIn scope?Key obligation
Manufacturer of an AI-powered connected product (wearable, vehicle, industrial equipment, smart appliance)Yes — as manufacturer/data holderAccess-by-design from 12 September 2026, user data access rights
Provider of a related service to a connected product (companion app, monitoring dashboard)Yes — as related service providerSame access-by-design and data access obligations as the manufacturer
Data holder processing and controlling connected-product data, including via AI analyticsYes — as data holderMust make data available to users and named third parties on FRAND terms
AI company receiving shared connected-product data as a third-party data recipientYes — as data recipientFRAND terms apply; cannot use the data to build a competing connected product
Cloud, edge, or GPU infrastructure provider hosting AI workloads for EU customersYes — as data processing service providerSwitching rights, interoperability, phased elimination of switching charges by January 2027
Public sector body requesting AI-derived data in a declared emergencyYes — under B2G provisionsRequest must be proportionate; compensation ordinarily due to the data holder
SME or micro-enterprise on the receiving end of a restrictive data clause in an AI licensing contractProtected — unfair term provisions applyRestrictive clauses that override Data Act rights are unenforceable
Company running AI purely on internally generated, non-connected-product data with no EU cloud customersNoDocument the determination

FRAND data sharing and the competing-product restriction: what AI companies miss

Data Act’s B2B sharing obligation looks like a straightforward access right until an AI company is the one requesting the data. Article 6(2)(e) prohibits a data recipient from using the data it receives to develop a product that competes with the connected product it came from, and from passing that data to a further third party for that purpose.

Training a model on Data-Act-sourced data without checking whether the output competes with the source product is not a theoretical risk — it is the single most common way AI companies end up on the wrong side of this regime.

Three things AI companies consistently misunderstand:

The competing-product restriction attaches to the data, not to the recipient’s intentions at the time of the request. An AI company that receives connected-product data for one stated purpose and later repurposes it for model training that produces a competing feature is exposed retroactively, not just at the point of misuse.

FRAND terms cut both ways. If your AI system is the data holder — because it processes and structures the data a connected product generates — you cannot use “commercially sensitive” as a blanket reason to refuse or degrade a legitimate third-party access request. The refusal has to survive scrutiny on its own terms.

Cloud switching obligations apply to the infrastructure your AI runs on even if you never touch a physical connected product. An AI company that trains or serves models exclusively on a single cloud provider, with contract terms that make migration commercially impossible, is the customer Data Act’s Chapter VI switching rules were written to protect — and by January 2027, provider-side switching charges disappear regardless of what the contract says.

What Data Act requires from AI products

These are the Data Act requirements that apply most directly to AI products embedded in connected products, trained on shared data, or hosted on EU cloud infrastructure.

Access-by-design assessment — a review of whether your AI-powered connected product or related service makes user-generated data directly, securely, and machine-readably accessible by default, ahead of the 12 September 2026 deadline

Data holder classification — a determination of whether your AI system’s role in processing connected-product data makes you a data holder with sharing obligations, rather than a passive processor

FRAND terms documentation — contractual and pricing terms for third-party data access requests that can withstand a fairness challenge, on both the sharing and receiving side

Competing-product use review — an assessment of whether any model trained on or informed by data received under a Data Act sharing request produces functionality that competes with the source connected product

Unfair contract term audit — a review of existing AI licensing and data-processing agreements with SME and micro-enterprise counterparties for clauses that Data Act now renders unenforceable

B2G request response protocol — a documented process for assessing and responding to public sector data requests under exceptional need, including entitlement to compensation

Cloud switching readiness — confirmation that your AI training and inference infrastructure contracts support data export, interoperability, and the phased removal of switching charges by January 2027

International access safeguards — technical and contractual measures preventing unlawful third-country government access to non-personal data held on your behalf by a cloud or edge provider.

One engagement. Every Data Act obligation mapped for your AI system.

A lawyer-built assessment of your AI system’s Data Act obligations — access-by-design review, data holder and data recipient classification, FRAND terms and competing-product exposure, unfair contract term audit, and cloud switching readiness — and a documented compliance record you and your counterparties can rely on.

When does the EU Data Act apply?

The Data Act, Regulation (EU) 2023/2854, has applied since 12 September 2025. Two further dates matter. The access-by-design obligation in Article 3(1) applies to connected products and related services placed on the market after 12 September 2026. Switching charges between data processing services must fall to zero from 12 January 2027.

What is the Article 3(1) access-by-design obligation?

Article 3(1) requires connected products and related services to be designed and manufactured so that product data and related service data are accessible to the user by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and where relevant and technically feasible, directly. It applies to products placed on the market after 12 September 2026. This is a design obligation rather than a documentation obligation, which means it cannot be satisfied retrospectively with paperwork.

Which roles does the Data Act create?

The Data Act attaches obligations to roles rather than to companies. The principal roles are data holder, user, data recipient, and provider of data processing services. One organisation commonly holds several roles at once across different products — a manufacturer of a connected product is a data holder for the data that product generates and simultaneously a user of the cloud service it runs on. Establishing which roles apply is the first step, because the obligations follow the role.

What is a connected product under the Data Act?

A connected product is an item that obtains, generates or collects data about its use or environment and can communicate that data through an electronic communications service, physical connection or on-device access. This covers vehicles, industrial machinery, medical and health devices, smart home equipment, agricultural machinery and consumer wearables. Products whose primary function is storing, processing or transmitting data on behalf of a party other than the user, such as servers and routers, are excluded.

Does the Data Act apply to software and SaaS?

Partly, and through different chapters. The connected product obligations in Chapters II and III reach related services associated with a physical product. Chapter VI on switching between data processing services reaches cloud and edge providers, including IaaS, PaaS and SaaS. A pure software product with no connected hardware may fall outside the access-by-design obligations while sitting squarely inside the switching regime.

What are the Data Act cloud switching obligations?

Providers of data processing services must remove contractual, commercial, technical and organisational obstacles to customers switching to another provider or to on-premises infrastructure. Switching charges, including egress fees, have been reducing since 12 September 2025 and must reach zero from 12 January 2027. Providers must also support functional equivalence where the service is infrastructure, and provide exit assistance, a maximum 30-day transition period, and open interfaces.

Does the Data Act apply to non-EU companies?

Yes. The Data Act reaches manufacturers of connected products placed on the EU market and providers of related services in the Union regardless of where they are established, and it reaches data processing service providers offering services to customers in the Union. Non-EU manufacturers and providers without an establishment in the Union must designate a legal representative in a Member State where the products or services are offered.

Does the Data Act override trade secret protection?

No, but it constrains how trade secrets can be used to withhold data. Data holders must identify data protected as trade secrets and may require proportionate technical and organisational protective measures before disclosure. Disclosure may be refused, on a case-by-case basis and in exceptional circumstances, where the data holder can demonstrate a high likelihood of serious economic damage. Blanket or systematic refusals do not meet the standard.

What is the “technically feasible” exception in Article 3(1)?

The obligation to provide direct access applies where relevant and technically feasible, which gives manufacturers a genuine but narrow limit. Where direct access is not feasible, data must still be made available on request. The exception is an assessment, not a default, and a market surveillance authority will expect to see the reasoning recorded. Most manufacturers relying on the limit have not documented why.

What information must be given to users before purchase?

Before concluding a contract for a connected product, the seller must provide clear information about the type, format and estimated volume of data the product can generate, whether it generates data continuously and in real time, how the user can access, retrieve or erase that data, and the identity of the data holder. Comparable pre-contractual duties for related services include the nature and volume of the data and the duration of the contract.

How does the Data Act interact with GDPR?

The Data Act applies to personal and non-personal data, and the GDPR continues to apply in full to any personal data involved. Where a user is not the data subject, personal data may only be made available where there is a valid GDPR legal basis. The Data Act does not create a new legal basis for processing personal data, and where the two conflict, the GDPR prevails.

What is the business-to-government data sharing obligation?

Chapter V allows public sector bodies, the Commission, the European Central Bank and Union bodies to request data from data holders where there is an exceptional need, primarily in response to a public emergency. Requests must be proportionate and reasoned, and data holders can decline or seek modification on specified grounds. The Digital Omnibus proposal would narrow this chapter from exceptional need to public emergencies, but that proposal is still in negotiation.

Is the Data Act being amended?

Yes, a proposal is in progress. The Digital Omnibus for data, COM(2025) 837, proposes consolidating the Data Governance Act, the Open Data Directive and the Free Flow of Non-Personal Data Regulation into the Data Act, narrowing the business-to-government chapter, deleting the smart contract requirements in Article 36, and adding relief for custom-made services and smaller providers on legacy contracts. As of the date of this page the proposal is still before the European Parliament and has not been adopted, so the current text remains in force.

What are the penalties under the Data Act?

Member States set their own penalties, which must be effective, proportionate and dissuasive, so the exposure varies by jurisdiction. Where the infringement involves personal data, supervisory authorities under the GDPR may impose GDPR-level fines. The more immediate commercial risk for most companies is contractual: enterprise buyers are beginning to write data access and portability requirements into procurement terms.

What is in the Data Act Compliance Pack?

A role determination worksheet establishing which Data Act roles you hold for each product and on what facts; an Article 3(1) access-by-design assessment including the technical feasibility reasoning; a pre-contractual information template; data sharing terms covering FRAND conditions and third-party access at a user’s request; a trade secret protection record; switching and exit documentation for data processing service providers; and a business-to-government request handling procedure. All in one ready to use template pack.