If your business makes, sells, or supports any product that connects to the internet – whether that’s a smart fridge, a connected car, or a cloud-based platform – you now have a new set of rules to follow if you’re operating within the EU.
On 12 September 2025, the EU Data Act officially came into play, changing how data from connected products and digital services must be handled, stored, and shared. In short, it gives users far greater control over the data their devices generate, while putting the onus on businesses to provide that access quickly, securely, and fairly.
Even if your company is based outside the EU, you’re not off the hook. If your products or services reach EU customers, you’re likely to be in scope, so in this article, we explore the EU Data Act and what it means for your business, drawing on insights from leading data protection specialists.
The Overview
According to the European Commission, around 80% of industrial data across Europe simply isn’t used, adding up to an enormous amount of untapped potential. The Data Act is designed to provide access to data generated by connected devices and industrial systems so users, companies, and public bodies can use and share more easily. The goal is to drive innovation, efficiency and fair competition through better use and access of data.
For businesses in the UK, this shift brings both challenge and opportunity. Played right, it could create partnerships and innovations that weren’t possible before. The outcome will depend on how quickly your business can adapt.
When handled well, compliance becomes more than a legal burden or box-ticking exercise; it’s a signal of trust. Customers expect transparency around how their data is used, and meeting that expectation can put you ahead of those who treat the law as little more than a requirement.
GDPR Isn’t Enough
You might be thinking, “We’re GDPR compliant – aren’t we already covered?” Not quite.
The GDPR focuses on personal data – information that identifies an individual and how that data is protected and processed. The Data Act, by contrast, governs access to and the use of data generated by connected devices, covering both personal and non-personal information.
Even if your organisation already has a strong compliance framework, the Data Act goes further. While the two laws share the same principles of fairness and accountability, the Data Act introduces new expectations in terms of accessibility, interoperability, and system design.
Who Needs to Comply
If you place connected products or related services on the EU market, the Data Act is likely to apply to your business. This includes manufacturers of connected devices from wearable medical monitors to industrial sensors – as well as software developers, cloud platforms, and service providers that process or enable access to device-generated data.
The Act also extends to organisations based outside the EU that offer such products or services within the single market. These businesses will also need to appoint a legal representative within the EU to manage compliance obligations.
Essentially, if your operations involve connected data in any meaningful way, and you operate across the EU, the Data Act is likely to affect you.
What You’ll Need to Do
The Data Act is built on the principles of transparency and fairness. That means before a customer buys or activates your connected product or service, they must be informed about the type of data it will generate, where that data will be stored, and who will have access to it.
Once the product is in use, customers have the right to access the data they generate – and to share it with third parties, if they wish. Businesses must enable this securely, and without unnecessary delays or restrictions.
Requests can only be refused on legitimate grounds, such as protecting trade secrets, security risks, or maintaining confidentiality.
In some cases, you may also be required to share data with public authorities, particularly during emergencies or for matters of public interest.
For businesses providing cloud or data-processing services, the Act introduces new obligations to allow customers to be able to switch providers without penalty. Portability and interoperability are no longer optional features; they’re legal obligations.
The 2026 Challenge
A second wave of requirements will take effect from September 2026. From that date, new connected products or related services entering the EU market must be designed with data accessibility and user control in mind.
This means designing devices that enable users to access their data directly, securely, and without any barriers or technical hoops to jump through. It represents a major shift in product design, and one that will separate proactive organisations from those that are unprepared.
If your current products lack these capabilities, now is the time to plan for retrofitting or redesign. It’s far easier (and cheaper) to build compliance into your next generation of devices than to bolt it on later.
What It Means for Day-to-Day Operations
Many businesses still don’t have a clear picture of the data their connected products generate, where it flows, how it’s stored, and how easily it can be shared. The first step is to map how data moves through your connected products and systems from creation to use.
You’ll need a comprehensive audit of your connected ecosystem: every device, service, and data stream. Once you understand what’s being generated and where it’s being stored, you can start identifying gaps and risks.
From there, contractual arrangements will need review. Internal governance frameworks will need strengthening. Technical systems may need redesigning to provide real-time, machine-readable data access. And these updates must be completed without compromising security or intellectual property.
It is a demanding process, but also an opportunity to modernise your data strategy and prepare for a future where transparency and interoperability are the norm, not the exception.
Turning Compliance into Competitive Advantage
Compliance isn’t a burden for forward-thinking businesses, and those who see it as an investment will be set apart in the markets.
By giving customers clear, reliable access to their data, you demonstrate openness and accountability, which strengthens trust and loyalty. Great for reputation and even better for retention. By ensuring your systems can integrate seamlessly with others, it could open new possibilities for collaboration. And by embedding transparency into product design, you make your organisation more adaptable to future technologies and regulatory change.
In other words, compliance can be a growth strategy. Companies that view the EU Data Act as a framework for building trust, rather than a bureaucratic hurdle, will be the ones leading the market rather than following it.
The Bigger Picture
The Data Act is more than another piece of regulation – it marks a shift in how the EU envisions the future digital economy. Data can be viewed as a shared asset that fuels innovation, collaboration, and competition.
For businesses operating in the EU, GDPR compliance remains essential for protecting personal data; the Data Act extends those principles to industrial and non-personal data, defining how access and sharing across sectors should work in practice.
The timeline is already unfolding, with obligations being phased in from 2024 to 2026. Prudent organisations will act early and prepare for compliance, setting the pace for a more open and responsible data-driven economy.
Ready to Transform Your B2B Marketing Strategy?
Get a comprehensive SEO audit and discover how to drive more qualified leads to your business.
Get a Free SEO Audit