EU Data Act – what must companies agree upon regarding data and cloud services?

Short answer: The EU Data Act creates rules regarding access to and use of data from connected products and related services, as well as switching between data processing services. For companies, this means that product terms, data sharing agreements, and cloud/SaaS agreements may need to be adapted.

What is the EU Data Act?

The Data Act is Regulation (EU) 2023/2854. The majority of the rules began to apply on September 12, 2025. The purpose is, among other things, to make data from connected products more accessible and to reduce technical and contractual barriers to switching between data processing services.

Which companies may be affected?

  • manufacturers and providers of connected products
  • providers of related digital services
  • data holders that control relevant product or service data
  • companies that receive data from users or data holders
  • providers of IaaS, PaaS, SaaS, and other data processing services

Data access and data sharing

A central idea is that the user should be able to gain access to certain data generated through the use of a connected product or related service and, in some cases, request that the data be shared with a third party. Agreements therefore need to clearly describe which data is covered, how access is obtained, and what technical and security conditions apply.

Trade secrets and security

The Data Act does not mean that all information must be disclosed without protection. Trade secrets, security risks, and authorizations need to be managed in a structured manner. The agreement should distinguish between access to data and the right to use, forward, or exploit the information.

Cloud switching – changing providers

For data processing services, the regulation contains specific rules intended to reduce commercial, technical, contractual, and organizational barriers when switching to another provider or to local infrastructure. A good agreement therefore needs to regulate export, format, transition periods, cooperation, deletion, and any continued access after migration.

What should companies review in their agreements?

  1. definition of data and roles
  2. access mechanisms and APIs
  3. permitted purposes of use
  4. confidentiality and trade secrets
  5. security requirements and authentication
  6. liability for incorrect or unauthorized use
  7. terms for third-party sharing
  8. switching, export, migration, and deletion
  9. subcontractors and interoperability

Data Act and GDPR are different regulatory frameworks

The Data Act can apply to both personal data and other types of data, but if the material contains personal data, the GDPR must still be followed. The Data Act does not in itself create a general legal basis for the processing of personal data. Roles and rights therefore need to be analyzed in parallel.

See the Template Store's Data Act package for agreements, data sharing, and cloud switching.

FAQ

Is the Data Act the same as the GDPR?

No. The GDPR deals primarily with the protection of personal data, while the Data Act regulates broader issues concerning access to and use of data as well as switching between data processing services.

Are pure SaaS companies affected?

They may be, especially through the rules on data processing services and switching. The exact application depends on the design and role of the service.

Do old agreements need to be reviewed?

Yes, companies should map out agreements that are active while the rules apply and assess which clauses need to be changed or supplemented.

Legal source: Regulation (EU) 2023/2854 on harmonized rules on fair access to and use of data.

The article is general information and does not replace legal advice.

Back to blog