National competent authoritiesand 1 more — see below
Sanction ceiling
none recorded
General application since 12 September 2025 (Art. 50). The Art. 3(1) design obligation applies to connected products and related services placed on the market after 12 September 2026; the switching-charge ban from 12 January 2027 (Art. 29(1)); Chapter IV's unfair-terms rules to long-running contracts concluded on or before 12 September 2025 from 12 September 2027 (Art. 50). Re-read against the milestones and the Official Journal text (CELEX 32023R2854) on 27 Sep 2026: still partly applicable.
What it does
Fair access to and use of data — predominantly non-personal, industrial and machine-generated — reallocating control over it by default.
How it allocates obligations
Lock-in and contractual imbalance.
Regulated actor
Data holder · Provider of data processing services · Connected-product provider
Protected party
User · Data recipient
Territorial reach
Established in the EU · Outside the EU, serving EU users
Implementation model
Directly applicable
Enforcement mechanism
National competent authorities; penalty levels set by Member States.
Key dates
Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.
13 December 2023AdoptionAdoption
22 December 2023Publication in the Official JournalPublication in the Official Journal
11 January 2024Entry into forceEntry into force
12 September 2025Application dateGeneral application: Chapter III data-access, Chapter IV unfair terms, Chapter VI switching.What it requires: Bring cloud contracts into line with the Art. 25 mandatory switching terms.
12 September 2026Application dateThe Art. 3(1) design obligation applies: connected products must be built so that product and related service data are accessible to the user by default.What it requires: Design and document data-access provision for connected products and related services placed on the market after this date.
12 January 2027Application dateAll cloud switching charges are prohibited outright.What it requires: Remove all switching charges from pricing and contracts.
12 September 2027Application dateChapter IV unfair-terms rules extend to pre-existing long-term B2B contracts concluded on or before 12 September 2025.What it requires: Review and remediate legacy long-term B2B contracts.
4 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.
Yes
actor Provider of data processing servicesactivity Cloud or data processing services
Chapter VI is nine articles (Arts. 23-31) out of fifty and carries most of the Regulation's practical weight for the software industry. Providers of data processing services must remove all pre-commercial, commercial, technical, contractual and organisational obstacles to switching, and Article 25 prescribes the mandatory contractual terms.
Last verified 27 August 2026
Potentially applicable
actor Provider of data processing servicesactivity Cloud or data processing servicesterritory Outside the EU, serving EU users
The Data Act reaches non-EEA providers of data processing services with customers in the Union. Establishment outside the Union is not a way out of the switching regime.
Last verified 27 August 2026
Yes
actor Manufacturer or Connected-product provideractivity Placing connected products on the market
From 12 September 2026 connected products must be designed and manufactured so that product and related service data are, by default, easily, securely and directly accessible to the user. This is a design obligation, not a disclosure one: it bites at the point the product is placed on the market.
Exemptions: Data holders may limit access where data qualifies as a trade secret, but must notify the national competent authority, and the user may challenge before a court. The brief records practitioner doubt about whether the confidentiality measures required of recipients are sufficient.
Last verified 27 August 2026
Potentially applicable
actor SME or Large companyactivity Cloud or data processing services or Placing connected products on the market
The Data Act governs product and service data as such — personal or not, though predominantly non-personal, industrial and machine-generated, with the GDPR prevailing wherever personal data is involved — and reallocates control over it by default. An organisation may be a data holder, a user or a data recipient depending on the arrangement, and the obligations differ in each role.
3 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.
Article
Heading
Binds
Applies
Art. 3(1)load-bearing
Obligation to make connected product data accessible to the userConnected products must be designed and manufactured so that product and related service data are, by default, easily, securely and directly accessible to the user.
Connected-product provider · Manufacturer
Applies from 12 September 2026
Art. 25load-bearing
Contractual terms concerning switchingMandatory contractual content for switching: maximum two-month notice period; 30 calendar day transitional period (or a justified alternative not exceeding seven months where technically unfeasible); at least 30 days data retrieval afterwards; full erasure once retrieval ends.
Provider of data processing services
Applies from 12 September 2025then from 12 January 2027: application date
Art. 8
Conditions under which data holders make data available to data recipientsWhere, in business-to-business relations, a data holder is obliged to make data available to a data recipient, it must agree the arrangements on fair, reasonable and non-discriminatory terms and conditions and in a transparent manner.
Data holder
Applies from 12 September 2027the instrument’s general date; nothing specific to this article is recorded
Enforcement
No enforcement recorded
This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.
Every statement this site makes about Data Act, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.
The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.
3 Primary law2 Official source1 Attributed view5 Interpretation1 Unresolved
Primary lawlaw
The Data Act applies to providers of data processing services, irrespective of their place of establishment, that provide such services to customers in the Union.
Data Act Article 25 prescribes hard-edged switching terms: maximum two-month notice to initiate switching, a 30-calendar-day transitional period (or a justified alternative not exceeding seven months where technically unfeasible), at least 30 days data retrieval afterwards, and full erasure once retrieval ends.
The Data Act Article 3(1) design obligation — connected products must be built so that product and related service data are accessible to the user by default — applies to connected products and related services placed on the market after 12 September 2026.
Ireland published the General Scheme of its Data Bill 2025 on 4 February 2026; it designates the CCPC and ComReg as competent authorities for the Data Act, and the CCPC as Data Coordinator.
Tier 2 · regulatorstates this
General Scheme of the Data Bill 2025 — Government of Ireland — Department of Enterprise, Tourism and Employment 4 February 2026Publication page: 'Published on: 4 February 2026'; the CCPC and ComReg 'are designated as competent authorities for the Data Act. The CCPC is also designated as the Data Coordinator'
Almost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026Part I
The Data Act's trade-secret carve-out may swallow the rule or be swallowed by it: data holders may limit access where data qualifies as a trade secret, but practitioners doubt the required confidentiality measures are sufficient.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026Part VI
Data Act Article 50 phases in Chapter IV for pre-existing contracts but contains no equivalent carve-out for Chapter VI, and practitioner analysis reads the switching right as applying to contracts concluded before 12 September 2025 as well; the Commission's Data Act FAQ (version 1.4, January 2026) does not address the point directly.
Data Act enforcement is national and therefore uneven: each Member State designates its own competent authorities, and Ireland — one of Europe's main data-centre hubs — published the General Scheme of its Data Bill only on 4 February 2026, with no Bill introduced in the Oireachtas by late September 2026.
Tier 1 · primary lawsupports in part
Regulation (EU) 2023/2854 (Data Act) — EUR-Lex 22 December 2023Art. 37(1): 'Each Member State shall designate one or more competent authorities to be responsible for the application and enforcement of this Regulation'
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026Part VI
Sovereignty and interoperability pull in opposite directions: the Data Act was designed to mandate open interoperability and eliminate lock-in, while the proposed Cloud and AI Development Act's sovereignty requirements push toward highly secure, localised environments.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026Part X
Where the GDPR governs personal data, the Data Act governs product and service data as such — personal or not, though predominantly non-personal, industrial and machine-generated, with the GDPR prevailing wherever personal data is involved — and reallocates control over it by default.
1 recorded interaction with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.
The Data Act mandates open interoperability and the elimination of lock-in; the sovereignty requirements of the proposed Cloud and AI Development Act push toward highly secure, localised environments. The two pull in opposite directions.
Carried byData Act Art. 25
What the brief argues
InterpretationSovereignty and interoperability pull in opposite directions: the Data Act was designed to mandate open interoperability and eliminate lock-in, while the proposed Cloud and AI Development Act's sovereignty requirements push toward highly secure, localised environments.
Sources
The European Legal Framework for the Digital World (this brief)Unverified · the brief itself
Recorded as at August 27, 2026
Related
Every one of these is an edge in the data, not a hand-written link list: change the record and this section changes with it.