EU Data Act
The EU Data Act is a European Union regulation that sets rules on who can access and use data generated in the EU, across all economic sectors. It aims to make it easier and fairer to share and use data within the European Economic Area, covering both personal and non-personal data. It is a distinct instrument from the GDPR, though the two can apply together where personal data is involved.
The EU Data Act is Regulation (EU) 2023/2854 of the European Parliament and of the Council on harmonised rules on fair access to and use of data. It establishes horizontal rules applying across economic sectors governing access to and use of data generated by connected products and related services, including obligations affecting data holders' use of readily available non-personal data (which the Commission's guidance indicates is generally prohibited unless contractually agreed). It sits alongside the GDPR rather than replacing it: where data qualifies as personal data of individuals, GDPR obligations continue to apply, and practitioners should assess the interaction of the two frameworks case by case. Precise scope, defined roles (such as data holder and user), applicability dates, and the treatment of specific data categories should be verified against the current official text of Regulation (EU) 2023/2854 and any implementing guidance, as detailed provisions and their application continue to be clarified.
Why it matters
The EU Data Act (Regulation (EU) 2023/2854) matters because it establishes horizontal rules on access to and use of data generated in the EU across all economic sectors, rather than being confined to a single industry. For organisations that manufacture connected products or provide related services, this can reshape existing commercial arrangements around who may access, share, and monetise the data those products generate. Because the Regulation covers both personal and non-personal data, its reach extends beyond the datasets that privacy teams have traditionally focused on under the GDPR.
The Act is significant for compliance programs precisely because it sits alongside the GDPR rather than replacing it. Where data generated by a connected product or service qualifies as personal data of individuals, GDPR obligations continue to apply, and organisations should assess the interaction of the two frameworks on a case-by-case basis. Treating the two instruments as interchangeable, or assuming that compliance with one satisfies the other, would generally be a mistake. According to the Commission's guidance as summarised by DLA Piper, the Act generally prohibits a data holder from using readily available non-personal data unless that use is contractually agreed, which can require organisations to revisit contracts and internal data-use assumptions.
Because detailed provisions, defined roles, and applicability dates continue to be clarified, the practical impact on any given organisation is subject to assessment against the current official text and any implementing guidance. Practitioners should avoid treating an early reading of the Act as settled, and should verify specific obligations and timing against Regulation (EU) 2023/2854 directly.
Who it's relevant to
Inside EU Data Act
Common questions
Answers to the questions practitioners most commonly ask about EU Data Act.