EU Data ActPolicy ExplainerJul 28, 2026, 9:20 PM· 5 min read· #1 of 3 in guides

The EU Data Act: A Guide to the New Rules for Connected Device Data, IoT, and Cloud Switching

The EU's sweeping Data Act mandates that manufacturers share IoT data with users and third parties, while forcing cloud providers to eliminate switching fees by 2027.

By Factlen Editorial Team

EU Policymakers & Regulators 25%Hardware Manufacturers & OEMs 25%Neutral Legal & Policy Analysts 20%Third-Party Service Providers 15%Cloud Infrastructure Providers 15%
EU Policymakers & Regulators
View the Act as essential for breaking monopolies and fostering a competitive data economy.
Hardware Manufacturers & OEMs
Concerned about the exposure of trade secrets and the high cost of re-engineering products.
Neutral Legal & Policy Analysts
Focus on the practical compliance challenges and the sweeping legal implications of the new framework.
Third-Party Service Providers
Champion the law as a lifeline for independent businesses and aftermarket competition.
Cloud Infrastructure Providers
Facing pressure to overhaul business models reliant on customer lock-in and egress fees.

Why this matters

The Data Act fundamentally ends the era of hardware manufacturers hoarding the data generated by the devices you buy. Whether you operate a smart factory, manage a fleet of connected cars, or simply use a smartwatch, you now have the legal right to access that data and move it to competing services.

For the past decade, the data economy has operated on a simple, unspoken rule: whoever builds the hardware keeps the data. A modern connected car generates terabytes of telemetry, a smart factory machine logs every vibration, and a wearable fitness tracker maps every heartbeat. Yet, the businesses and consumers who purchased these devices rarely owned the resulting data. Instead, it was beamed back to the manufacturer's proprietary cloud, locked in a silo, and often monetized or used to force customers into expensive, authorized repair networks.[2]

The European Union's Data Act, which took its first major effect in September 2025, fundamentally rewrites these rules. Described by legal analysts as the most significant overhaul of European data law since the General Data Protection Regulation (GDPR), the Act shifts the balance of power away from hardware manufacturers and cloud giants, placing data access rights directly into the hands of the user.[2]

The core mechanism of the Data Act is a mandated right of access and portability. Under the regulation, users—whether they are individual consumers or large enterprise businesses—have the legal right to access the data generated by their connected products. More importantly, they can demand that the manufacturer share this data in real-time with a third party of the user's choosing.[1]

Under the new rules, users can mandate that manufacturers share device data directly with third-party services.
Under the new rules, users can mandate that manufacturers share device data directly with third-party services.

This sharing mechanism is designed to break up aftermarket monopolies. For example, a logistics company operating a fleet of connected trucks can now route the vehicles' diagnostic data directly to an independent, third-party repair shop, rather than being forced to rely exclusively on the original manufacturer's service network. The manufacturer is legally obligated to facilitate this transfer on fair, reasonable, and non-discriminatory (FRAND) terms.[1]

While the core access rights went live in 2025, the technology industry is currently racing toward the next critical milestone: September 12, 2026. From this date forward, all new connected products placed on the EU market must comply with strict "data-by-design" obligations. Manufacturers can no longer treat data extraction as an afterthought or a cumbersome manual process; devices must be engineered from the ground up to make data easily, securely, and directly accessible to the user by default.

While core provisions are already active, hardware and cloud providers face strict upcoming deadlines in 2026 and 2027.
While core provisions are already active, hardware and cloud providers face strict upcoming deadlines in 2026 and 2027.

The scope of the regulation is vast. It applies to both personal and non-personal data, covering the entire Internet of Things (IoT) ecosystem—from smart home appliances and wearables to industrial robotics and medical devices. Crucially, the Data Act has an extraterritorial reach. Any company offering connected products or data processing services to customers in the EU must comply, regardless of where the company is headquartered. Non-EU companies are required to designate a legal representative within a member state to ensure accountability.

Any company offering connected products or data processing services to customers in the EU must comply, regardless of where the company is headquartered.

Beyond connected hardware, the Data Act takes aggressive aim at the cloud computing sector. For years, enterprise customers have complained of "vendor lock-in," where hyperscale cloud providers make it technically difficult and financially punitive to migrate data and workloads to a competitor. The Data Act introduces mandatory cloud switching requirements for providers of Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and Software-as-a-Service (SaaS).

Under these new rules, cloud providers must allow customers to transition to a rival service within a maximum of 30 days. During this transition, the original provider must maintain functional parallel use and provide open interfaces to ensure technical equivalence at the target destination. The financial barriers to switching are also being dismantled. By January 12, 2027, all cloud switching fees—including data egress charges—will be completely prohibited by EU law.

Cloud providers must now facilitate rapid customer switching and eliminate egress fees by 2027.
Cloud providers must now facilitate rapid customer switching and eliminate egress fees by 2027.

To protect smaller enterprises from being bullied in negotiations, the Data Act introduces a "blacklist" and "greylist" of unfair contractual terms. If a large data holder attempts to force a one-sided data-sharing agreement on a small or medium-sized enterprise (SME), those terms can be deemed legally void. This ensures that the theoretical right to data access isn't undermined by aggressive corporate lawyering.

The regulation also includes provisions for business-to-government (B2G) data sharing. In exceptional circumstances, such as a public health emergency or a major natural disaster, public sector bodies and EU institutions can mandate access to privately held data if it is strictly necessary to respond to the crisis. This ensures that critical telemetry—such as mobility data during a flood—can be utilized for the public good without waiting for commercial negotiations.[2]

Enforcement of the Data Act is decentralized, with individual EU member states responsible for designating competent authorities and levying penalties. However, the financial risks of non-compliance are severe. Mirroring the GDPR's penalty structure, fines for violating the Data Act can reach up to 4% of a company's global annual revenue or EUR 20 million, whichever is higher. This has elevated Data Act compliance from a mid-level IT issue to a board-level priority.

The Data Act mirrors the GDPR's aggressive penalty structure for non-compliance.
The Data Act mirrors the GDPR's aggressive penalty structure for non-compliance.

Despite the law being in effect, significant areas of uncertainty remain, particularly around the definition and protection of "trade secrets." Hardware manufacturers have argued that raw telemetry data is often inextricably linked to proprietary algorithms and intellectual property. While the Data Act allows manufacturers to withhold data if sharing it would cause serious economic damage through the exposure of trade secrets, the threshold for proving this is high, and the European Commission has warned against using trade secrets as a blanket excuse to deny access.[2]

As the September 2026 data-by-design deadline approaches, the engineering burden on IoT companies is immense. Hardware architectures are being redesigned, firmware is being updated to support open APIs, and legal teams are rewriting thousands of B2B contracts. The transition is costly and complex, but it marks a permanent shift in the digital economy: data is no longer a proprietary asset to be hoarded, but a fluid resource that follows the user.[2]

Viewpoints in depth

EU Policymakers & Regulators

View the Act as essential for breaking monopolies and fostering a competitive data economy.

European regulators argue that the vast majority of industrial and consumer data generated in the EU has historically gone unused or been monopolized by a handful of tech giants. By forcing interoperability and mandating data access, policymakers believe the Data Act will unlock billions of euros in economic value, spurring the creation of new AI models, independent repair services, and cross-sector innovations that were previously blocked by proprietary silos.

Hardware Manufacturers & OEMs

Concerned about the exposure of trade secrets and the high cost of re-engineering products.

Original Equipment Manufacturers (OEMs) face the heaviest compliance burden. Many argue that raw machine data is deeply intertwined with proprietary algorithms that constitute core intellectual property. They warn that forcing open access could allow cheap overseas competitors to reverse-engineer European hardware innovations. Furthermore, the requirement to retrofit existing data architectures and design all future products with open APIs represents a massive, uncompensated engineering expense.

Third-Party Service Providers

Champion the law as a lifeline for independent businesses and aftermarket competition.

Independent repair shops, aftermarket software developers, and specialized analytics firms view the Data Act as a massive victory. For years, these businesses have been squeezed out of the market by manufacturers who encrypted diagnostic ports or refused to share telemetry. With guaranteed, FRAND-priced access to device data, third parties can now compete directly with OEMs on service quality and price, rather than being blocked by technical barriers.

Cloud Infrastructure Providers

Facing pressure to overhaul business models reliant on customer lock-in and egress fees.

Hyperscale cloud providers are being forced to dismantle the financial and technical moats that keep enterprise customers tethered to their platforms. The total ban on switching fees by 2027—particularly the lucrative data egress charges—removes a major revenue stream. Providers are now scrambling to ensure their APIs meet the new interoperability standards, knowing that customers can easily migrate workloads to cheaper or more specialized competitors.

What we don't know

  • How national courts will balance the mandate to share data against manufacturers' claims of 'trade secret' protection.
  • Whether the EU will issue further technical standardization guidelines for the required open APIs.
  • How aggressively member states will enforce the 4% revenue fines during the initial rollout phase.

Sources

Source coverage

2 outlets

5 viewpoints surfaced

EU Policymakers & Regulators 25%Hardware Manufacturers & OEMs 25%Neutral Legal & Policy Analysts 20%Third-Party Service Providers 15%Cloud Infrastructure Providers 15%
  1. [1]European CommissionEU Policymakers & Regulators

    The EU Data Act starts to apply, empowering users and unlocking data-driven innovation

    Read on European Commission
  2. [2]Factlen Editorial TeamNeutral Legal & Policy Analysts

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team
Stay informed

Every angle. Every day.

Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.