1. Digital Policy
  2. Instruments
  3. Data Act

Regulation · directly applicable · CELEX 32023R2854

Data Act

Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data

Official text: Regulation (EU) 2023/2854 (Data Act)Tier 1 · primary law

Status
Partly applicable as of 27 September 2026
Competent authority
National competent authoritiesand 1 more — see below
Sanction ceiling
none recorded

General application since 12 September 2025 (Art. 50). The Art. 3(1) design obligation applies to connected products and related services placed on the market after 12 September 2026; the switching-charge ban from 12 January 2027 (Art. 29(1)); Chapter IV's unfair-terms rules to long-running contracts concluded on or before 12 September 2025 from 12 September 2027 (Art. 50). Re-read against the milestones and the Official Journal text (CELEX 32023R2854) on 27 Sep 2026: still partly applicable.

What it does

Fair access to and use of data — predominantly non-personal, industrial and machine-generated — reallocating control over it by default.

How it allocates obligations

Lock-in and contractual imbalance.

Regulated actor
Data holder · Provider of data processing services · Connected-product provider
Protected party
User · Data recipient
Territorial reach
Established in the EU · Outside the EU, serving EU users
Implementation model
Directly applicable
Enforcement mechanism
National competent authorities; penalty levels set by Member States.

Key dates

Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.

  1. 13 December 2023AdoptionAdoption
  2. 22 December 2023Publication in the Official JournalPublication in the Official Journal
  3. 11 January 2024Entry into forceEntry into force
  4. 12 September 2025Application dateGeneral application: Chapter III data-access, Chapter IV unfair terms, Chapter VI switching.What it requires: Bring cloud contracts into line with the Art. 25 mandatory switching terms.
  5. 12 September 2026Application dateThe Art. 3(1) design obligation applies: connected products must be built so that product and related service data are accessible to the user by default.What it requires: Design and document data-access provision for connected products and related services placed on the market after this date.
  6. 12 January 2027Application dateAll cloud switching charges are prohibited outright.What it requires: Remove all switching charges from pricing and contracts.
  7. 12 September 2027Application dateChapter IV unfair-terms rules extend to pre-existing long-term B2B contracts concluded on or before 12 September 2025.What it requires: Review and remediate legacy long-term B2B contracts.

The whole compliance calendar, filterable →

Who it applies to

4 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.

Yes

actor Provider of data processing servicesactivity Cloud or data processing services

Chapter VI is nine articles (Arts. 23-31) out of fifty and carries most of the Regulation's practical weight for the software industry. Providers of data processing services must remove all pre-commercial, commercial, technical, contractual and organisational obstacles to switching, and Article 25 prescribes the mandatory contractual terms.

Last verified 27 August 2026

Potentially applicable

actor Provider of data processing servicesactivity Cloud or data processing servicesterritory Outside the EU, serving EU users

The Data Act reaches non-EEA providers of data processing services with customers in the Union. Establishment outside the Union is not a way out of the switching regime.

Last verified 27 August 2026

Yes

actor Manufacturer or Connected-product provideractivity Placing connected products on the market

From 12 September 2026 connected products must be designed and manufactured so that product and related service data are, by default, easily, securely and directly accessible to the user. This is a design obligation, not a disclosure one: it bites at the point the product is placed on the market.

Exemptions: Data holders may limit access where data qualifies as a trade secret, but must notify the national competent authority, and the user may challenge before a court. The brief records practitioner doubt about whether the confidentiality measures required of recipients are sufficient.

Last verified 27 August 2026

Potentially applicable

actor SME or Large companyactivity Cloud or data processing services or Placing connected products on the market

The Data Act governs product and service data as such — personal or not, though predominantly non-personal, industrial and machine-generated, with the GDPR prevailing wherever personal data is involved — and reallocates control over it by default. An organisation may be a data holder, a user or a data recipient depending on the arrangement, and the obligations differ in each role.

Last verified 27 August 2026

Run these against your situation →

Key provisions

3 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.

ArticleHeadingBindsApplies
Art. 3(1)load-bearingObligation to make connected product data accessible to the userConnected products must be designed and manufactured so that product and related service data are, by default, easily, securely and directly accessible to the user.Connected-product provider · ManufacturerApplies from 12 September 2026
Art. 25load-bearingContractual terms concerning switchingMandatory contractual content for switching: maximum two-month notice period; 30 calendar day transitional period (or a justified alternative not exceeding seven months where technically unfeasible); at least 30 days data retrieval afterwards; full erasure once retrieval ends.Provider of data processing servicesApplies from 12 September 2025then from 12 January 2027: application date
Art. 8Conditions under which data holders make data available to data recipientsWhere, in business-to-business relations, a data holder is obliged to make data available to a data recipient, it must agree the arrangements on fair, reasonable and non-discriminatory terms and conditions and in a transparent manner.Data holderApplies from 12 September 2027the instrument’s general date; nothing specific to this article is recorded

Enforcement

No enforcement recorded

This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.

The whole enforcement observatory →

Evidence and sources

Every statement this site makes about Data Act, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.

The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.

3 Primary law2 Official source1 Attributed view5 Interpretation1 Unresolved
Primary lawlaw

The Data Act applies to providers of data processing services, irrespective of their place of establishment, that provide such services to customers in the Union.

Tier 1 · primary lawstates this

Regulation (EU) 2023/2854 (Data Act) — EUR-Lex 22 December 2023 Art. 1(3)(f)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Data Act Article 25 prescribes hard-edged switching terms: maximum two-month notice to initiate switching, a 30-calendar-day transitional period (or a justified alternative not exceeding seven months where technically unfeasible), at least 30 days data retrieval afterwards, and full erasure once retrieval ends.

Tier 1 · primary lawstates this

Regulation (EU) 2023/2854 (Data Act) — EUR-Lex 22 December 2023 Art. 25(2)(a), (d), (g), (h); Art. 25(4)

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VI

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The Data Act Article 3(1) design obligation — connected products must be built so that product and related service data are accessible to the user by default — applies to connected products and related services placed on the market after 12 September 2026.

Tier 1 · primary lawstates this

Regulation (EU) 2023/2854 (Data Act) — EUR-Lex 22 December 2023 Art. 50, third paragraph

Tier 4 · press / advocacysupports in part

EU Data Act — article index, Article 1 (Subject matter and scope) and Article 50 (Entry into force and application) — eu-data-act.com (unofficial reproduction of the Data Act text) Art. 50

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VI, Annex A

Read it in the brief →Last verified 27 September 2026
Official sourcefact

Ireland published the General Scheme of its Data Bill 2025 on 4 February 2026; it designates the CCPC and ComReg as competent authorities for the Data Act, and the CCPC as Data Coordinator.

Tier 2 · regulatorstates this

General Scheme of the Data Bill 2025 — Government of Ireland — Department of Enterprise, Tourism and Employment 4 February 2026 Publication page: 'Published on: 4 February 2026'; the CCPC and ComReg 'are designated as competent authorities for the Data Act. The CCPC is also designated as the Data Coordinator'

Tier 4 · press / advocacysupports in part

The Data Act Part III: The Irish Enforcement Framework — Matheson 18 May 2026 Section on the General Scheme

Read it in the brief →Last verified 27 September 2026
Official sourcefact

No Data Bill had been introduced in the Oireachtas by 25 September 2026: none appears among the bills of 2025 or of 2026 in its register.

Tier 2 · regulatorstates this

Oireachtas legislation register — bills of 2025 and 2026 (open data API) — Houses of the Oireachtas no Data Bill among the 85 bills of 2025 or the 92 of 2026 (register updated to 25 Sep 2026)

Read it in the brief →Last verified 27 September 2026
Attributed viewattributed

Dublin is one of Europe's main data-centre hubs, alongside Frankfurt, London, Amsterdam and Paris (the 'FLAP-D' markets).

Tier 3 · researchstates this

The value of data centres to Ireland — an independent report prepared by KPMG for the Department of Enterprise, Tourism and Employment (March 2026) — Department of Enterprise, Tourism and Employment (Ireland); report prepared by KPMG 2 June 2026 Executive summary: 'a strategic European data centre hub, alongside Frankfurt, London, Amsterdam, and Paris – collectively known as the FLAP-D markets'

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretationunverified

Almost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I

Read it in the brief →Last verified 27 September 2026
Interpretationcritiqueunverified

The Data Act's trade-secret carve-out may swallow the rule or be swallowed by it: data holders may limit access where data qualifies as a trade secret, but practitioners doubt the required confidentiality measures are sufficient.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VI

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretation

Data Act Article 50 phases in Chapter IV for pre-existing contracts but contains no equivalent carve-out for Chapter VI, and practitioner analysis reads the switching right as applying to contracts concluded before 12 September 2025 as well; the Commission's Data Act FAQ (version 1.4, January 2026) does not address the point directly.

Tier 4 · press / advocacysupports in part

EU Data Act — article index, Article 1 (Subject matter and scope) and Article 50 (Entry into force and application) — eu-data-act.com (unofficial reproduction of the Data Act text) Art. 50

Tier 4 · press / advocacysupports in part

Understanding switching rights under the Data Act — DLA Piper 31 July 2025

Tier 2 · regulatorcontext only

Frequently Asked Questions — Data Act, Version 1.4 — European Commission 22 January 2026 Questions 42b, 52-58b

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VI

Read it in the brief →Last verified 26 September 2026
Interpretationinterpretation

Data Act enforcement is national and therefore uneven: each Member State designates its own competent authorities, and Ireland — one of Europe's main data-centre hubs — published the General Scheme of its Data Bill only on 4 February 2026, with no Bill introduced in the Oireachtas by late September 2026.

Tier 1 · primary lawsupports in part

Regulation (EU) 2023/2854 (Data Act) — EUR-Lex 22 December 2023 Art. 37(1): 'Each Member State shall designate one or more competent authorities to be responsible for the application and enforcement of this Regulation'

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VI

Read it in the brief →Last verified 27 September 2026
Interpretationcritiqueunverified

Sovereignty and interoperability pull in opposite directions: the Data Act was designed to mandate open interoperability and eliminate lock-in, while the proposed Cloud and AI Development Act's sovereignty requirements push toward highly secure, localised environments.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part X

Read it in the brief →Last verified 27 August 2026
Unresolvedlaw

Where the GDPR governs personal data, the Data Act governs product and service data as such — personal or not, though predominantly non-personal, industrial and machine-generated, with the GDPR prevailing wherever personal data is involved — and reallocates control over it by default.

Tier 1 · primary lawsupports in part

Regulation (EU) 2023/2854 (Data Act) — EUR-Lex 22 December 2023 Art. 1(2), 1(5)

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VI

Read it in the brief →Last verified 27 September 2026

The full bibliography and the evidence method →

How it interacts

1 recorded interaction with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.

Cloud and AI Development Act In tension with Data Act

The Data Act mandates open interoperability and the elimination of lock-in; the sovereignty requirements of the proposed Cloud and AI Development Act push toward highly secure, localised environments. The two pull in opposite directions.

Carried byData Act Art. 25
What the brief argues
  • InterpretationSovereignty and interoperability pull in opposite directions: the Data Act was designed to mandate open interoperability and eliminate lock-in, while the proposed Cloud and AI Development Act's sovereignty requirements push toward highly secure, localised environments.
Sources
  • The European Legal Framework for the Digital World (this brief)Unverified · the brief itself

Recorded as at August 27, 2026