The Data Act in Practice: A Complete Guide for Businesses
If your business sells connected products, holds customer data generated through smart devices, or relies on cloud services to run any part of your operations, you may have heard about the EU Data Act and wondered whether it actually applies to you, and if so, what you are supposed to do about it. It is entirely reasonable to feel uncertain about where your obligations begin and end. This guide walks through what the Data Act means in practice, who it affects, and the practical steps worth taking now.
What Is the Data Act and Why Was It Introduced?
The Data Act is an EU regulation designed to make data generated by connected products, such as smart appliances, connected vehicles, and industrial machinery, more accessible to the people and businesses that generate it. It became applicable on 12th September 2025, and the European Commission's official explainer describes its purpose as clarifying who can use what data and under what conditions, while making the EU's data economy fairer and more competitive.
Historically, manufacturers of connected products have tended to keep exclusive control over the usage data those products generate, even though it is the customer who creates that data simply by using the device. The Data Act changes that balance. It gives users, whether they are individuals or businesses, a right to access data generated by their connected products and to choose to share that data with third parties, including competitors offering repair or maintenance services.
Who Actually Needs to Comply?
If you manufacture or sell connected products in the EU, provide related digital services that work alongside those products, or offer cloud and data processing services to EU customers, the Data Act is likely to apply to you. The Act sets the ground rules for business-to-consumer, business-to-business, and business-to-government data exchange across the EU single market, and national authorities in each member state are responsible for enforcement.
This matters for UK businesses too. If you sell connected products into the EU or provide cloud services to EU customers, you fall within scope regardless of where your company is based. The obligations are not limited to businesses headquartered in the EU.
What Are the Key Deadlines You Need to Know?
The Data Act became applicable for most obligations on 12th September 2025, but several important deadlines are still ahead. From 12th September 2026, a new requirement comes into force under what is sometimes called access by design. Connected products and related services placed on the market after that date must be built so that the data they generate is, by default, easily and securely accessible to users, free of charge, where this is technically feasible. This is a design obligation, meaning it affects product development now, not just compliance paperwork closer to the date.
Cloud and data processing service providers also face a phased timeline. Switching between providers must already be facilitated under fair terms, and from January 2027, charges for switching between data processing services will be banned entirely.
What Does This Mean for Your Contracts?
One of the most practical impacts of the Data Act is on commercial contracts. Businesses that hold data generated by connected products must share that data on terms described in the regulation as fair, reasonable, and non-discriminatory. This means existing data sharing agreements, cloud contracts, and customer terms may need updating to reflect the new statutory rights users now hold.
The European Commission has published non-binding model contractual terms to help businesses negotiate compliant agreements, and these are a useful starting point if you are reviewing your own contracts. The Commission has also opened a Data Act Legal Helpdesk, offering further guidance for businesses working through specific legal questions.
Why Switching Is Harder than the Legal Right to Leave Suggests
Much of the conversation around the Data Act focuses on contracts, but for SaaS and other data driven businesses, the more immediate challenge is often operational rather than legal. A customer may have a clear contractual right to leave a service and take their data with them, yet still find switching genuinely difficult in practice. Integrations may need rebuilding, internal workflows may need redesigning, staff may need retraining, and the functionality they relied on may simply not exist in an equivalent form elsewhere.
This creates a useful question for any business providing software or data services. If customers tend to stay for long periods, is that because the product continues to earn their loyalty, or because leaving would be too disruptive to attempt? The Data Act does not answer that question directly, but it is pushing businesses to examine the distinction more honestly, since the practical barriers that once protected customer retention are gradually being designed out of the market.
Can Your Product Stay Unique While Working Seamlessly with Others?
The Data Act also encourages greater interoperability between services, making it easier for customers to move their data and connect different platforms together. For many SaaS businesses, this sits uneasily alongside years of investment in distinctive functionality, proprietary workflows, and a particular user experience designed to set them apart from competitors.
The practical challenge is finding a workable balance. A product still needs to feel distinctive and worth paying for, while also being accessible, portable, and straightforward to integrate into a customer's wider technology setup. Businesses that treat interoperability purely as a compliance burden risk missing that it can equally become a point of commercial differentiation, particularly as customers increasingly factor ease of integration into their buying decisions.
Retention Strategies Built on Dependency Are Losing Ground
Some businesses have historically benefited from what is often described as stickiness, where a customer becomes so embedded within a platform that moving elsewhere feels impractical even if they are not entirely satisfied. As switching becomes genuinely easier and customers gain stronger rights over their own data, this kind of dependency is harder to rely on as a retention strategy.
The more durable approach is one built around demonstrable value rather than practical difficulty. Businesses that can clearly show why a customer benefits from staying, rather than relying on the friction of leaving, are likely to be better placed as the Data Act continues to reshape customer expectations around portability. This is a subtle shift, but a significant one commercially, and it is worth revisiting your own retention strategy with this distinction in mind.
How Is Compliance Shaping Product Strategy?
Many of the practical questions the Data Act raises, around portability, access rights, and interoperability, cannot be resolved through contracts or policy documents alone. They often require genuine technical solutions, which means product teams, engineers, security specialists, and commercial colleagues all have a role alongside legal teams in getting this right.
In practice, some of the most consequential compliance decisions are made earlier than many businesses expect, during the design and development of a product itself, well before legal teams are typically involved. This is one reason organisations are increasingly treating Data Act readiness as a cross-functional, business-wide exercise rather than something that can be delegated solely to the legal function.
Customers May Be Moving Faster than the Regulator
A further consideration is whether businesses are preparing primarily for regulatory scrutiny or for their customers. While the Data Act creates binding legal obligations, many organisations are already seeing increased questions from customers, procurement teams, and prospective buyers about how their data can be accessed, transferred, and used.
In other words, this is becoming a commercial issue as much as a regulatory one. Increasingly, the question is not simply whether a business can demonstrate compliance with the Data Act if asked, but whether it can show customers, unprompted, that it has already thought these issues through and built them into how its products and services actually operate.
What Practical Steps Should You Be Taking Now?
The most useful starting point is a scoping exercise. Work out which of your products, services, and existing contracts are likely to be affected, and clarify your own role under the Act, since the obligations differ depending on whether you are a manufacturer, a data holder, a cloud provider, or a user. From there, a gap analysis against your current data practices will help identify where technical or contractual changes are needed.
It is also worth reviewing how your organisation currently separates personal data from non-personal data within product usage logs and telemetry. This sounds technical, but it has real legal significance, because the Data Act applies primarily to non-personal data, while the UK GDPR and EU GDPR continue to govern personal data in parallel. Where the two overlap, both regimes apply at once, and getting this wrong creates risk under both frameworks.
Given how much of this work touches product architecture rather than paperwork, it is worth bringing product, engineering, and commercial colleagues into the conversation alongside your legal team from an early stage. Reviewing your contracts is necessary, but it will not on its own answer questions about how easily a customer could actually extract their data and move to a competitor, and that practical reality is increasingly what customers themselves are asking about during procurement.
Finally, keep an eye on the EU's Digital Omnibus proposals. The European Commission has proposed some adjustments to the Data Act, including more flexibility for businesses to refuse data access requests where trade secrets are genuinely at risk. These proposals have not yet been adopted, so the safest approach is to continue building your compliance programme around the Data Act as it currently stands, rather than waiting for changes that may or may not materialise.
Where This Leaves Your Business
The Data Act represents a genuine shift in how data generated by connected products is controlled, and the practical impact reaches well beyond the EU's borders. If your business touches connected products, cloud services, or SaaS platforms in any way, treating this as a one-off legal compliance task is unlikely to be enough. It calls for an ongoing review of product design, contractual terms, and data governance practices as the remaining deadlines approach, and for product, commercial, and legal teams to be working from the same understanding of what genuine portability looks like, rather than the minimum the legislation technically requires.
If you are unsure whether the Data Act applies to your business, or you want help reviewing your contracts and data practices against the new requirements, taking specialist legal advice early will help you avoid costly mistakes later on.
How Can Gerrish Legal Help?
Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property.
We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements.
We are here to help you, get in contact with us today for more information.