The EU Data Act: A Guide to Mandatory Data Sharing, IoT Data Access, and the New Rules for Industrial Data
The European Union's sweeping Data Act is now applicable, granting users the legal right to access and share the data generated by their connected devices. The regulation forces manufacturers and cloud providers to dismantle vendor lock-in, eliminate switching fees, and re-architect their products for interoperability.
By Factlen Editorial Team
- Industrial Operators & Consumers
- View the Act as a liberation of their data, enabling them to optimize operations, choose independent repair services, and avoid vendor lock-in.
- Cloud & IoT Providers
- Face significant engineering and compliance burdens to build interoperable systems, while worrying about the tension between mandatory sharing and GDPR privacy rules.
- EU Policymakers
- Argue the Act is necessary to break up data monopolies, foster aftermarket competition, and unlock the economic value of machine-generated data.
What's not represented
- · Independent repair shops and third-party software developers who stand to gain market share from the newly unlocked data.
Why this matters
For decades, the data generated by smart devices and industrial machinery was hoarded by manufacturers, locking customers into proprietary ecosystems. The EU Data Act shatters this model, giving businesses and consumers the legal right to their own data, which will lower cloud computing costs, enable independent repairs, and spark a new wave of third-party analytics tools.
Key points
- The EU Data Act grants users the legal right to access and share data generated by their connected devices.
- Industrial operators can now route machine telemetry to third-party analytics platforms, breaking vendor lock-in.
- Cloud providers must facilitate customer migrations within 30 days and eliminate all switching fees by 2027.
- The regulation applies to any company offering products or services to EU customers, regardless of global headquarters.
- Companies must balance the Data Act's mandatory sharing requirements with the GDPR's strict privacy rules.
For as long as the Internet of Things (IoT) has existed, a quiet monopoly has governed the data it produces. When a smart thermostat adjusted a home's temperature, a connected car tracked its engine health, or a robotic arm assembled parts on a factory floor, the resulting telemetry flowed directly into the manufacturer's proprietary cloud. The user who bought the machine rarely owned the data it generated. Instead, they were often forced to pay for expensive, bundled analytics dashboards just to see their own operational metrics. As of September 12, 2025, the European Union has officially dismantled that paradigm.[1][6]
The EU Data Act, a sweeping regulation designed to unlock the economic value of machine-generated data, is now fully applicable across all 27 member states. It establishes a fundamental new right: the people and businesses that own, rent, or lease connected devices now have the legal authority to access the data those devices generate. Furthermore, they have the right to share that data with third parties of their choosing, free of charge, in a structured and machine-readable format.[1][2]
The scope of the regulation is massive, touching nearly every sector of the digital economy. It covers consumer electronics like smartwatches and connected appliances, but its most profound impact will be felt in the industrial sector. Manufacturers of agricultural equipment, medical devices, and factory machinery can no longer treat product data as their exclusive asset. If a product generates data during use, the user now holds the keys.[2][5]

For industrial operators, this is a liberating shift. Previously, a factory running machines from five different vendors had to navigate five different proprietary data silos, making it nearly impossible to create a unified view of their operations. Under the Data Act, that factory can demand the raw data from all five vendors and route it into a single, third-party analytics platform. This breaks vendor lock-in and allows businesses to optimize their operations using the software of their choice, rather than the software dictated by the hardware manufacturer.[1][6]
Consumers will see immediate benefits in the aftermarket and repair sectors. Historically, automakers and electronics manufacturers restricted access to diagnostic data, forcing consumers to use authorized, often more expensive, repair shops. The Data Act allows a car owner to instantly port their vehicle's diagnostic data to an independent mechanic, fostering competition and driving down maintenance costs.[1]
Beyond connected devices, the Data Act takes direct aim at the cloud computing industry. Chapter VI of the regulation introduces aggressive new rules to facilitate cloud switching, targeting Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) providers. The EU recognized that exorbitant egress fees and technical incompatibilities were trapping businesses in long-term contracts with dominant cloud platforms.[5]
Cloud providers are now legally obligated to remove all pre-commercial, technical, and contractual obstacles that inhibit a customer from migrating to a competitor or moving their data to on-premises infrastructure. When a customer initiates a switch, the provider must complete the transition within a maximum period of 30 days. During this window, the original provider must maintain business continuity and ensure a high level of security.

When a customer initiates a switch, the provider must complete the transition within a maximum period of 30 days.
The financial barriers to cloud migration are also being phased out. While providers can currently charge limited fees to cover the direct costs of a switching request, all such switching charges will be strictly prohibited by January 12, 2027. This effectively mandates that data portability must become a free, frictionless feature of the European cloud market.[5]
To protect smaller players in the ecosystem, the Data Act introduces strict rules against unfair B2B contracts. It invalidates contractual clauses that seek to limit the Act's mandatory data access rights, particularly those imposed on micro, small, and medium-sized enterprises (SMEs) by dominant tech companies. Any term deemed presumptively unfair must be justified by the imposing party, shifting the legal burden away from the smaller business.[1][2]
However, compliance is proving to be a complex engineering challenge, primarily due to the tension between the Data Act and the EU's General Data Protection Regulation (GDPR). The Data Act mandates the broad sharing of data, while the GDPR mandates strict data minimization and purpose limitation. Because IoT data often contains personal identifiers—such as a driver's location history or a smartwatch user's health metrics—companies must navigate a precarious tightrope.[4][6]
Legal experts warn that over-disclosure of personal data to comply with the Data Act could trigger massive GDPR fines, while under-disclosure to protect privacy could result in Data Act enforcement. To resolve this, companies must ensure they have a valid legal basis—such as explicit user consent—before porting any dataset that contains personally identifiable information. The Data Act does not override the GDPR; it operates alongside it.[4]
Manufacturers are also fiercely protective of their intellectual property, raising concerns that mandatory data sharing could expose trade secrets. The regulation addresses this by drawing a line between raw data and derived data. Companies are only required to share the raw, directly observed telemetry generated by the device. They are not required to share insights, complex analytics, or proprietary algorithms that represent their unique secret sauce.[1][2]

The regulatory timeline introduces escalating requirements over the next two years. While the core access rights are now active, a critical deadline looms on September 12, 2026. From that date forward, all new connected products placed on the EU market must feature data-access-by-design. This means compliance can no longer be handled through legal policies alone; it must be hardcoded into the back-end architecture and physical design of the product to ensure data is readily accessible by default.[3][4]
Enforcement of the Data Act will be handled at the national level, with member states designating competent authorities—such as Ireland's Commission for Communications Regulation (ComReg) or Germany's Federal Network Agency. The penalties for non-compliance are severe, mirroring the GDPR's structure with administrative fines that can reach up to 4% of a company's annual global turnover.[3]

Crucially, the Data Act's reach extends far beyond Europe's borders. The regulation applies to any manufacturer or cloud provider that offers connected products or data processing services to customers within the EU, regardless of where the company is headquartered. This extraterritorial scope means that American, Asian, and British tech giants must re-architect their global data pipelines to comply with European standards.[2][6]
By transforming data from a hoarded corporate asset into a liquid, user-controlled resource, the EU Data Act is setting a new global benchmark for the digital economy. It forces hardware manufacturers to compete on the quality of their physical products rather than the exclusivity of their data silos, while giving businesses the freedom to build the exact software ecosystems they need to thrive.[1][6]
How we got here
Jan 2024
The EU Data Act officially entered into force.
Sept 12, 2025
The core provisions of the Data Act became fully applicable across the EU.
Sept 12, 2026
The mandate for data-access-by-design in all new connected products takes effect.
Jan 12, 2027
Cloud providers are prohibited from charging any fees for customer switching requests.
Viewpoints in depth
Industrial Operators & Consumers
Users view the Act as a vital tool to reclaim ownership of their operational data and reduce costs.
For businesses running complex supply chains or factory floors, the Data Act is a major victory against vendor lock-in. Instead of paying multiple manufacturers for fragmented, proprietary analytics dashboards, operators can now demand their raw data and centralize it in a single system. Similarly, consumers gain the ability to take their vehicle or appliance data to independent repair shops, fostering a competitive aftermarket that was previously stifled by data hoarding.
Cloud & IoT Providers
Tech companies face immense engineering challenges to comply with the new interoperability and sharing mandates.
Manufacturers and cloud platforms must fundamentally re-architect their back-end systems to support seamless data portability and data-access-by-design. Beyond the technical hurdles, these providers are deeply concerned about the legal friction between the Data Act and the GDPR. They face the difficult task of building automated systems that freely share machine data while simultaneously filtering out personally identifiable information to avoid massive privacy fines.
EU Policymakers
Regulators argue the Act is essential to democratize the digital economy and spur European innovation.
The European Commission views data as a non-rivalrous resource that has been artificially constrained by a few dominant tech players. By legally mandating data sharing and eliminating cloud switching fees, policymakers aim to level the playing field for startups and SMEs. They believe that unlocking the massive volumes of data generated by the Internet of Things will fuel a new wave of AI development and third-party digital services across the continent.
What we don't know
- How national regulators will practically enforce the boundary between raw data (which must be shared) and derived data (which is protected as a trade secret).
- Whether the elimination of cloud switching fees will lead providers to increase baseline subscription costs to compensate for lost revenue.
- How exactly companies will resolve the conflicting mandates of the Data Act and the GDPR when handling complex datasets that mix machine telemetry with personal behavior.
Key terms
- Data Holder
- The entity, usually the manufacturer or service provider, that has the technical ability to access data generated by a connected product.
- Connected Product
- An Internet of Things (IoT) device that generates data concerning its use or environment and can communicate that data.
- Cloud Switching
- The process of migrating data and digital assets from one cloud service provider to another or to on-premises infrastructure without technical or commercial barriers.
- Data-Access-by-Design
- The requirement that new products be engineered so that users can easily and directly access the data they generate by default.
Frequently asked
Does the EU Data Act apply to personal or non-personal data?
It applies to both. However, when personal data is involved, the GDPR still takes priority, meaning data sharing must have a valid legal basis such as user consent.
Do companies have to share their proprietary algorithms?
No. The Act requires sharing raw or minimally processed data, but explicitly protects derived data, complex analytics, and trade secrets.
Does this law affect companies outside of Europe?
Yes. Any manufacturer or cloud provider offering connected products or data processing services to EU customers must comply, regardless of where they are headquartered.
Can cloud providers still charge egress fees?
Currently, they can charge limited fees to cover direct switching costs, but all switching charges will be strictly prohibited by January 12, 2027.
Sources
[1]European CommissionEU Policymakers
EU Data Act gives users control over data from connected devices
Read on European Commission →[2]White & CaseEU Policymakers
The EU Data Act Becomes Applicable: What Companies Need to Know
Read on White & Case →[3]Simmons & SimmonsEU Policymakers
EU Data Act National Implementation Tracker
Read on Simmons & Simmons →[4]Corporate Compliance InsightsCloud & IoT Providers
The EU Data Act marks a structural shift in the EU data landscape
Read on Corporate Compliance Insights →[5]ScalityCloud & IoT Providers
EU Data Act explained: Cloud switching and interoperability
Read on Scality →[6]Factlen Editorial TeamIndustrial Operators & Consumers
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →
Every angle. Every day.
Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.








