Data Act: What the New European Data Regulation Requires From Your Company
If your company manufactures or sells connected products, offers digital services associated with those products, or simply contracts cloud infrastructure, the Data Act likely already affects your business, whether you know it or not. The European Data Regulation isn't just another personal data protection law like the GDPR — it's a distinct piece of the European data strategy focused on something broader: who can access the data generated by the use of products and services, and under what conditions it can be shared between companies.
Many organizations still treat the Data Act as a purely legal matter, something the legal department will handle by reviewing contracts. That's a mistaken approach. The regulation has direct implications for how connected products are designed, how internal data flows are documented, and which cloud providers a company works with — which also makes it a matter of technology architecture.
In this article, we review the specific obligations the Data Act introduces, how it relates to the Data Governance Act, and why data spaces are the most natural infrastructure for complying with the regulation without turning it into an endless project — and for seizing the business opportunities it also brings.
What the Data Act Is and Who It Affects
The Data Act is the European Data Regulation adopted as part of the European data strategy, aimed at ensuring a fairer distribution of the value generated by data among those who manufacture connected devices, those who use them, and those who offer services based on that data.
It mainly affects three types of actors:
- Manufacturers and providers of connected products: any device that generates data during use and can communicate it, from industrial machinery to climate control equipment or process sensors.
- Providers of related services: companies that offer applications or digital services associated with the operation of those products.
- Providers of cloud and edge data processing services: cloud computing companies, whose provider-switching conditions are regulated by the law.
The core idea is simple to state, though complex to implement: the data generated by the use of a product doesn't belong exclusively to whoever manufactures it, and the user of the product — whether a person or a company — has the right to access that data and decide who to share it with.
The Right to Access Data From Connected Devices
One of the pillars of the Data Act is the right of a connected product's user to access the data that product generates, and to be able to transfer it to a third party of their choosing, including a competitor of the original manufacturer.
Consider an agri-food cooperative in Castile and León that uses connected processing machinery, whose sensors continuously log performance, energy consumption, and maintenance data. Until now, that data typically stayed in the hands of the machinery manufacturer, who used it to improve its own predictive maintenance services, without the cooperative having a straightforward way to access it or hand it over to another data analytics provider.
Under the Data Act, the cooperative has the right to request that data directly or to ask for it to be transferred to a third party — for example, a consultancy offering a maintenance optimization service better suited to its needs. This forces manufacturers to redesign their products and services with data portability in mind from the outset, not just internal exploitation.
For manufacturing companies, this obligation means reviewing very specific aspects:
- Exactly what data each product generates and in what format it's stored.
- What technical mechanisms exist to export it in a readable, structured way.
- Which current contractual clauses might conflict with this right of access.
Fair Conditions for Data Sharing Between Companies
The Data Act also regulates the conditions under which a company must share data with another when required by law or requested by another company under the regulation. The goal is to prevent abusive clauses that, in practice, make it impossible to exercise the right of access even if it exists on paper.
This translates into several principles that companies must build into their data-sharing policies:
- Compensation for sharing data, when applicable, must be reasonable and cannot become a deterrent barrier.
- Contractual conditions for data access cannot be imposed unilaterally and disproportionately on the weaker party in the relationship.
- There must be transparency about what data is shared, for what purpose, and for how long.
For a mid-sized company that until now shared data with clients or suppliers through ad hoc agreements, poorly documented and managed via email or loose files, this represents a shift in approach: a governance framework is needed to record, in a traceable way, what is shared, under what conditions, and with whom.
Switching Cloud Providers Without Friction
Another significant part of the Data Act concerns the ease of switching cloud data processing service providers. The regulation seeks to eliminate the technical, contractual, and economic barriers that currently make it difficult to migrate from one cloud provider to another — a phenomenon known as vendor lock-in.
In practice, this requires cloud providers to facilitate the portability of their customers' data and configurations, to progressively reduce financial penalties for switching providers, and to guarantee a minimum level of interoperability between equivalent services.
For a company that depends on a single cloud provider to store its operational data, this is good news: it strengthens its negotiating position and reduces the risk of being trapped in uncompetitive conditions simply because switching providers would be too costly or technically complex.
Data Act and Data Governance Act: Complementary Pieces
It's worth not confusing the Data Act with the Data Governance Act, even though both are part of the same European data strategy and reinforce each other.
The Data Governance Act focuses on creating trust mechanisms to facilitate data exchange: it regulates concepts such as neutral data intermediaries and data altruism, and establishes principles for public sector bodies to securely reuse certain protected data.
The Data Act, on the other hand, focuses on more specific rights and obligations: access to data from connected products, B2B sharing conditions, and portability between cloud providers.
In other words, the Data Governance Act establishes the framework of trust and the mechanisms that make it possible to share data with guarantees, while the Data Act defines which specific data must be shareable and under what conditions. A company that wants to comply with both regulations coherently needs infrastructure capable of applying granular access policies and keeping verifiable records of every data exchange.
Why a Data Space Is the Natural Infrastructure for Data Act Compliance
Complying with the Data Act through manual processes, loose contracts, and one-off file exports is possible at a small scale, but it becomes unsustainable as soon as a company has several connected products, several clients requesting access to their data, and several partners with whom it shares information on a recurring basis.
A modern data space resolves this complexity because it comes built-in with the elements the Data Act effectively requires:
- A connector with an mTLS gateway that ensures every data transfer is authenticated and encrypted, leaving a record of who accesses what.
- A policy engine based on Open Policy Agent, which allows granular definition of who can access each dataset, under what conditions, and for how long, without having to manage it case by case.
- A transfer module compatible with databases, APIs, files, and real-time streams, which makes it easier to export the data generated by a connected product in a format reusable by third parties.
- A verifiable agreement registry, which keeps a traceable record of the conditions under which each dataset has been shared — especially useful for demonstrating compliance during an audit or a claim.
- A clearing house that certifies the data transactions carried out, providing the traceability the Data Act requires regarding fair sharing conditions.
For a connected equipment manufacturer based in Castile and León, this means being able to respond to a client's request to access data from its machines without building custom development every time: the data space's connector is already set up to authenticate the requester, apply the corresponding access policy, and log the transaction.
From Legal Obligation to Business Opportunity
It's tempting to see the Data Act purely as a compliance burden, but the regulation also opens up real opportunities. Companies that get ahead by building solid data-sharing infrastructure will be able to offer their clients and partners faster, more reliable data access than the competition — turning it into a differentiating sales argument.
What's more, a company participating in a data space doesn't just meet its access obligations — it gains visibility into what data it generates, how it flows, and who uses it, information that often reveals operational improvement opportunities that previously went unnoticed.
Data sovereignty, in this context, doesn't mean closing off access to information, but having real control over the conditions under which it's shared. That's precisely the philosophy underpinning the European data strategy, and it's what makes the Data Act and data spaces fit together almost naturally.
Prepare Your Company for the Data Act
Adapting to the Data Act doesn't require reinventing your company's entire data infrastructure, but it does require a technology foundation capable of managing access, traceability, and sharing conditions in an orderly way. A modern data space offers that infrastructure already in place, with policy governance, secure transfer, and built-in traceability from day one.
If your company produces connected devices or manages data that other organizations might need, look for a technology partner with experience in data spaces who can help you assess how to fit your operations into this regulatory framework without unnecessary friction.