The Regulation makes user access to the data generated by connected (IoT) products and related services, and its sharing with a third party of the user's choice, mandatory; voids unfair data terms imposed on SMEs; and introduces switching rules for cloud providers. Turkish manufacturers that sell connected products to the EU market also fall within scope.
Overview
The EU Data Act establishes the contractual order of the data economy, including non-personal data. Its aim is to prevent the data generated by connected products from remaining locked in with the manufacturer alone; to grant users access and sharing rights; and to remove switching barriers in the cloud market.
Who is affected
Manufacturers that place connected products (vehicles, machines, devices) or related digital services on the EU market — even if established in Türkiye — fall within scope. Cloud/SaaS providers are subject to the switching rules; large data holders are subject to exceptional data requests from public sector bodies.
Impact on contracts
Data access and sharing terms are bound to fair, reasonable, and non-discriminatory (FRAND-like) principles; unfair data terms unilaterally imposed on SMEs are not binding. Existing product and service contracts need to be reviewed in respect of their data annexes and confidentiality clauses.
Critical point for the Turkish dimension
The Data Act applies together with trade-secret protection and KVKK/GDPR: the sharing obligation does not eliminate trade-secret protection, but a categorical refusal on grounds of secrecy is not possible either. The contract strikes the balance.
Roadmap
A scope analysis across the product portfolio; a data-flow diagram; a process to handle access requests; revision of the set of contracts (sale, service, cloud); and updating the trade-secret protection strategy — this is the implementation sequence we recommend.
Penalties
The setting of penalties is left to the Member States; they must be effective, proportionate, and dissuasive. For breaches involving personal data, the GDPR penalty framework may come into play; on the B2B side, the principal sanction is the invalidity of unfair terms and contractual disputes.
Related content
For the intersection with personal data, see the GDPR and KVKK records. We detail the product and contract impacts in our Data Act analysis, and the data architecture in our Data focus area.


