Skip to main content
Category: Legal Framework & Instruments

EU Data Act

Also known as: Data Act, Regulation (EU) 2023/2854
Simply put

The EU Data Act is a European Union regulation that sets rules on who can access and use data generated in the EU, across all economic sectors. It aims to make it easier and fairer to share and use data within the European Economic Area, covering both personal and non-personal data. It is a distinct instrument from the GDPR, though the two can apply together where personal data is involved.

Formal definition

The EU Data Act is Regulation (EU) 2023/2854 of the European Parliament and of the Council on harmonised rules on fair access to and use of data. It establishes horizontal rules applying across economic sectors governing access to and use of data generated by connected products and related services, including obligations affecting data holders' use of readily available non-personal data (which the Commission's guidance indicates is generally prohibited unless contractually agreed). It sits alongside the GDPR rather than replacing it: where data qualifies as personal data of individuals, GDPR obligations continue to apply, and practitioners should assess the interaction of the two frameworks case by case. Precise scope, defined roles (such as data holder and user), applicability dates, and the treatment of specific data categories should be verified against the current official text of Regulation (EU) 2023/2854 and any implementing guidance, as detailed provisions and their application continue to be clarified.

Why it matters

The EU Data Act (Regulation (EU) 2023/2854) matters because it establishes horizontal rules on access to and use of data generated in the EU across all economic sectors, rather than being confined to a single industry. For organisations that manufacture connected products or provide related services, this can reshape existing commercial arrangements around who may access, share, and monetise the data those products generate. Because the Regulation covers both personal and non-personal data, its reach extends beyond the datasets that privacy teams have traditionally focused on under the GDPR.

The Act is significant for compliance programs precisely because it sits alongside the GDPR rather than replacing it. Where data generated by a connected product or service qualifies as personal data of individuals, GDPR obligations continue to apply, and organisations should assess the interaction of the two frameworks on a case-by-case basis. Treating the two instruments as interchangeable, or assuming that compliance with one satisfies the other, would generally be a mistake. According to the Commission's guidance as summarised by DLA Piper, the Act generally prohibits a data holder from using readily available non-personal data unless that use is contractually agreed, which can require organisations to revisit contracts and internal data-use assumptions.

Because detailed provisions, defined roles, and applicability dates continue to be clarified, the practical impact on any given organisation is subject to assessment against the current official text and any implementing guidance. Practitioners should avoid treating an early reading of the Act as settled, and should verify specific obligations and timing against Regulation (EU) 2023/2854 directly.

Who it's relevant to

Manufacturers of connected products and providers of related services
Organisations that make connected products or offer related services are typically most directly affected, as the Act governs access to and use of the data those products and services generate. They should review how the Act's rules interact with their existing data-use and product design practices, subject to verification against the current text.
Data protection officers and privacy compliance leads
DPOs and privacy teams need to assess the interaction between the Data Act and the GDPR, particularly where connected-product data includes personal data of individuals. Because the two instruments can apply together, compliance analysis should treat them as distinct but potentially overlapping frameworks, on a case-by-case basis.
Commercial and technology lawyers negotiating data arrangements
Lawyers advising on contracts should note the Commission's guidance that a data holder is generally prohibited from using readily available non-personal data unless that use is contractually agreed. This can require revisiting contractual terms governing data access, use, and sharing, with the precise obligations confirmed against Regulation (EU) 2023/2854.
Engineers and product teams building connected products
Technical teams designing connected products and related services may need to consider how data is made available to users and other parties, given the Act's rules on access and use. Specific technical obligations and their timing should be checked against the current official text and any implementing guidance, as detailed provisions continue to be clarified.

Inside EU Data Act

Scope of covered data
The EU Data Act addresses access to and sharing of data generated by connected products and related services, including both personal and non-personal data. Where personal data is involved, the GDPR continues to apply in full, and the two frameworks must be read together. The precise interaction between the Data Act and the GDPR is an area where further regulatory guidance may develop, and readers should verify the current position against the official texts.
User access rights to product-generated data
The Data Act is generally intended to enable users of connected products to access data generated by their use of those products and, in many cases, to share it with third parties. This is distinct from GDPR data subject rights such as the right of access and the right to data portability, which concern personal data and derive from the GDPR rather than the Data Act. The two sets of rights may overlap but should not be conflated.
Business-to-business and B2G data sharing provisions
The Data Act contains provisions addressing data sharing between businesses and, in defined circumstances, making data available to public sector bodies. These arrangements are governed by the Data Act's own conditions and are separate from GDPR concepts such as controller-to-processor relationships under Article 28 or the Article 6 legal bases for processing personal data.
Interaction with data protection law
The Data Act does not displace the GDPR. Where personal data is processed under Data Act mechanisms, a valid legal basis under Article 6 (and an additional condition under Article 9 for special category data) is still required, and controller and processor roles must still be correctly identified. The allocation of responsibilities in this overlap is subject to assessment and may be clarified by future guidance.
Relationship to international transfers
Where data sharing under the Data Act involves the transfer of personal data outside the EU, the GDPR transfer regime continues to apply, including the need for an appropriate transfer tool and, where relevant, supplementary measures. Adequacy decisions and transfer mechanisms evolve over time, so any transfer analysis should be verified against the current framework.

Common questions

Answers to the questions practitioners most commonly ask about EU Data Act.

Is the EU Data Act just another version of the GDPR for personal data?
No. The EU Data Act and the GDPR are distinct instruments with different scopes. The GDPR governs the processing of personal data relating to identified or identifiable individuals. The EU Data Act is broader in one sense and narrower in another: it addresses access to and sharing of data generated by connected products and related services, covering both personal and non-personal data. Where the two overlap, the GDPR continues to apply to any personal data, and the EU Data Act does not displace GDPR protections. Treating the EU Data Act as a substitute for, or a mere extension of, the GDPR misstates the relationship. Readers should verify how the specific provisions interact against the current official texts, as the interface between the two regimes is an area where further guidance may develop.
Does the EU Data Act only apply to personal data?
No. Unlike the GDPR, the EU Data Act is not limited to personal data. It concerns data generated by the use of connected products and related services, which can include non-personal data (such as machine-generated or industrial data) as well as personal data. This is a key distinction: a data set can fall within the scope of the EU Data Act without being personal data, and conversely, where personal data is involved, GDPR obligations continue to apply alongside it. Because the mix of personal and non-personal data in a given data set affects which rules apply, an assessment of the specific data involved is generally required.
How should an organization determine whether a given data set falls within the scope of the EU Data Act?
In most cases this requires a scoping assessment of whether the data is generated by the use of a connected product or a related service, and whether the organization's role brings it within the obligations addressed by the instrument. Because the EU Data Act can cover both personal and non-personal data, the assessment should also identify any personal data element, since GDPR obligations continue to apply to that element in parallel. Given that the practical boundaries of scope are an evolving area, organizations should verify their conclusions against the current official text and any regulatory guidance rather than relying on a fixed interpretation.
How does compliance with the EU Data Act interact with existing GDPR obligations?
Where a data set includes personal data, the two regimes apply in parallel, and the GDPR's requirements are not displaced by the EU Data Act. In practice this means an organization typically needs to satisfy the relevant EU Data Act obligations while continuing to meet GDPR requirements such as identifying a lawful basis under Article 6 and, for special category data, an additional condition under Article 9. The precise way obligations are reconciled where they overlap is an area where further guidance may emerge, so organizations should treat the interface cautiously and confirm the position against current authoritative sources.
What internal roles should be involved in an EU Data Act implementation program?
Because the EU Data Act spans both personal and non-personal data and touches on data access, sharing, and contractual arrangements, implementation typically involves a cross-functional group. This commonly includes legal and compliance functions, the data protection officer or privacy team for any personal data elements, and engineering or product teams familiar with the connected products and related services that generate the data. The appropriate allocation of responsibilities depends on the organization's role and the specific data involved, so the composition of the program should follow from the scoping assessment rather than a fixed template.
How should documentation for EU Data Act compliance be approached?
As a general matter, organizations benefit from documenting their scoping assessment, the categories of data involved, and how any personal data element is handled under the GDPR alongside EU Data Act obligations. Where the two regimes overlap, keeping a clear record of how obligations were reconciled supports accountability. Because interpretive guidance in this area may continue to develop, documentation should note the date and source of the interpretation relied upon, and organizations should revisit it against the current official text as the position evolves rather than treating any single snapshot as settled.

Common misconceptions

The EU Data Act replaces or overrides the GDPR for data generated by connected products.
The Data Act does not replace the GDPR. Where personal data is involved, the GDPR continues to apply, and both frameworks must be satisfied. The precise interaction is an area where further guidance may develop and should be verified against the official texts.
The Data Act's user access rights are the same as the GDPR right to data portability.
They are distinct. GDPR data subject rights, such as access and portability, concern personal data and derive from the GDPR. The Data Act's access and sharing rights concern data generated by connected products and can include non-personal data. They may overlap but are separate legal mechanisms.
Sharing data under the Data Act removes the need for a legal basis to process personal data.
Where personal data is processed, an appropriate Article 6 legal basis is still required, and special category data under Article 9 needs an additional condition. Consent is only one of several bases and is not automatically required; the correct basis is determined by context and assessment.

Best practices

Map whether the data in scope is personal, non-personal, or a mixed dataset, and remember that the GDPR applies to any personal data element even where the Data Act also applies.
Where personal data is involved, identify and document an appropriate Article 6 legal basis, and confirm whether an Article 9 condition is also needed for special category data, rather than defaulting to consent.
Correctly identify controller and processor roles for any personal data shared under Data Act mechanisms, and reflect these in the relevant contractual arrangements.
Distinguish Data Act access and sharing rights from GDPR data subject rights in your procedures, so that requests are handled under the correct framework.
Where data sharing may involve transfers of personal data outside the EU, assess the applicable transfer tool and any supplementary measures, and re-verify the position as adequacy decisions and transfer mechanisms evolve.
Monitor emerging regulatory guidance on the interaction between the Data Act and the GDPR, and verify specific obligations, article references, and effective dates against the current official texts before relying on them.