Legislation · European Union · EU Directive & Regulation (Regulation (EU) 2023/2854)

EU Data Act

The Data Act “unlocks data” through contract law: it grants users of connected products rights to access and share data, makes switching cloud providers easier, and reviews unfair terms in data contracts.

Recently amendedIn force · 12.09.2025 (application)Source · ABl. L, 22.12.2023Threshold · Providers of connected products/services
In summary

The Regulation makes user access to the data generated by connected (IoT) products and related services, and its sharing with a third party of the user's choice, mandatory; voids unfair data terms imposed on SMEs; and introduces switching rules for cloud providers. Turkish manufacturers that sell connected products to the EU market also fall within scope.

Overview

The EU Data Act establishes the contractual order of the data economy, including non-personal data. Its aim is to prevent the data generated by connected products from remaining locked in with the manufacturer alone; to grant users access and sharing rights; and to remove switching barriers in the cloud market.

Who is affected

Manufacturers that place connected products (vehicles, machines, devices) or related digital services on the EU market — even if established in Türkiye — fall within scope. Cloud/SaaS providers are subject to the switching rules; large data holders are subject to exceptional data requests from public sector bodies.

Impact on contracts

Data access and sharing terms are bound to fair, reasonable, and non-discriminatory (FRAND-like) principles; unfair data terms unilaterally imposed on SMEs are not binding. Existing product and service contracts need to be reviewed in respect of their data annexes and confidentiality clauses.

Critical point for the Turkish dimension

The Data Act applies together with trade-secret protection and KVKK/GDPR: the sharing obligation does not eliminate trade-secret protection, but a categorical refusal on grounds of secrecy is not possible either. The contract strikes the balance.

Roadmap

A scope analysis across the product portfolio; a data-flow diagram; a process to handle access requests; revision of the set of contracts (sale, service, cloud); and updating the trade-secret protection strategy — this is the implementation sequence we recommend.

Penalties

The setting of penalties is left to the Member States; they must be effective, proportionate, and dissuasive. For breaches involving personal data, the GDPR penalty framework may come into play; on the B2B side, the principal sanction is the invalidity of unfair terms and contractual disputes.

Related content

For the intersection with personal data, see the GDPR and KVKK records. We detail the product and contract impacts in our Data Act analysis, and the data architecture in our Data focus area.

This record is provided for general information and monitoring only; it does not constitute legal advice or create an attorney–client relationship. The official text in force is authoritative. Contact our team for a scope and compliance assessment specific to your company.
01

Related Practice Areas

We address this regulation together with our expertise in the following practice areas.

02

Focus & Sector Links

This regulation creates a cross-disciplinary focus with a greater impact on certain sectors.

The most affected sectors
DC
Related Desk · Regional

Data & Cybersecurity Desk

Integrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.

Explore the regional desk
03

Related Services

The services we deploy to support compliance with this regulation.

View all
Legislation · European Union

EU Data Act — obtain the right legal support.

Let us assess the impact of this regulation on your business and establish a practical compliance framework.