Hero background image

EU Data Act: What it means for your data strategy (and how to prepare).

22 June 2026 4 min read Blog Post

The European Union continues to reshape the digital landscape – not only focusing on security (NIS2) and AI (EU AI Act), but also on how data itself is accessed, shared and used. With the EU Data Act, a fundamental shift is underway: organisations can no longer treat data generated by their products and services as exclusively theirs.

The Data Act introduces new rights for users and obligations for organisations, fundamentally changing how data flows across ecosystems. For many, this will have a direct impact on cloud strategy, data architecture and contractual arrangements.

What is the EU Data Act?

The EU Data Act (Regulation (EU) 2023/2854) establishes harmonised rules for fair access to and use of data across the EU economy. Unlike GDPR, which focuses on personal data protection, the Data Act addresses both personal and non-personal data, including machine-generated data from IoT devices.

Implementation timeline at a glance

  • January 2025: Entered into force
  • 12 September 2025: Core obligations apply
  • 12 September 2026: Data-by-design, interoperability obligations
  • 12 January 2027: Ban on switching charges
  • 12 September 2027: Full implementation

Why the EU Data Act matters

A limited number of providers currently control much of the data generated by connected products and digital platforms. This creates structural challenges such as:

  • Vendor lock-in
  • Limited third-party innovation
  • Concentration of market power

The Data Act addresses these challenges by introducing enforceable rights and obligations around data access, sharing and portability. And this positions control over data as a key factor in the ability to keep innovating.

Key Data Act requirements and obligations

The Data Act introduces a user-centric data model with clear obligations across the value chain. It establishes clear roles between ‘data holders’ and ‘data users’, and sets rules for how data is accessed, shared and transferred across the digital ecosystem.

Users can be both consumers and businesses. The goal is to prevent data from being locked within ecosystems and to remove switching barriers. The EU wants to enable open data infrastructures, keep data owners in control, prevent monopolies and foster innovation.

The regulation applies broadly across sectors and introduces new technical, contractual and operational requirements that organisations must embed into product design, service delivery and vendor relationships.

Core requirements

  • Enable user access to data: Users must have access to data generated by their products and services
  • Enable user-controlled data sharing:Users must be able to share their data with third parties
  • Restrict data holder usage:Providers can’t freely use or monetise data generated by their products without a legal basis or explicit user agreement
  • Implement data access by design: Products and services must be designed to make data easily accessible
  • Enable switching between providers: Cloud and SaaS providers must remove switching barriers
  • Ensure data portability and interoperability: Data must be transferable and usable across platforms
  • Eliminate unfair contractual terms:Data-sharing contracts must be fair and transparent
  • Support public sector data access in emergencies:Data may need to be shared in exceptional cases

In essence, data control shifts from data and ecosystem providers to ecosystem users (which directly links to addressing digital sovereignty challenges). And this applies both to businesses and consumers as users.

Who is impacted by the Data Act

The EU Data Act applies broadly across the digital ecosystem and affects any organisation that relies on data from connected products, digital services or cloud platforms.  It sets obligations on how that data is accessed, shared and transferred between parties. Therefore, compliance extends throughout the enire data landscape, directly impacting architecture, vendor strategy, contract management and data governance practices.

  • Organisations using cloud and SaaS: Gain new rights to access and reuse their data
  • Digital product and service providers: Must enable data access and sharing
  • Cloud and platform providers: Must support portability and switching
  • Ecosystem partners: Gain new opportunities to offer data-driven services
  • Public sector bodies: Gain conditional access rights

Note that the Data Act has extraterritorial scope, meaning non-EU providers serving the EU market are also affected.

How should you prepare for EU Data Act compliance?

The Data Act isn’t just a compliance topic – it directly impacts how you design and operate your IT landscape.

Key implications

  • Reduced dependency on single vendors
  • Increased importance of open architectures and APIs
  • Need for stronger data governance and contract management
  • Alignment with broader topics like AI and digital sovereignty

Recommended compliance steps

  1. Understand your data landscape: Know what data you have and generate, who controls it and what dependencies you have
  2. Assess vendor and contract risks: Identify lock-in risks (especially in cloud and SaaS contracts) and review data ownership and access clauses
  3. Enable data access and portability: As the Data Act is enforcing this, know the extent to which obligations apply to your data
  4. Align with broader strategy: Now you know your situation, update your (cloud, data, AI) strategies as foundations for improvements
  5. Structurally embed: Now the direction is clear, start implementing improvements in your vendor landscape, architectures and implementations

From compliance to opportunity

The EU Data Act fundamentally changes how data is accessed and controlled across digital ecosystems. It is therefore both a compliance requirement and an opportunity to reduce lock-in and unlock new value from data.

Navigating Data Act requirements will affect architecture, cloud strategy and data governance. Nordcloud GRC advisors and Security Consultants are here to support your planning and implementation approach.

Want to know more about what the EU Data Act means for your organisation?

Book an informal chat with our compliance experts.

Let’s discuss how we can help with your cloud journey.

Our experts are standing by to talk about your migration, modernisation, development and skills challenges.

Sander combines 20+ years in information security with a focus on practical governance, risk, and compliance. He advises on data, AI, and cloud sovereignty, risk management, and regulations like the AI Act, GDPR, DORA, and NIS2.
Sander Nieuwenhuis LinkedIn
GRC Advisory Global Lead
Scroll to top