Regulatory Framework
EU Data
Act
Data Access and Sharing Rules
The EU Data Act establishes rules for access to and use of data generated by connected products and related services. Our EU Data Act consulting helps organisations identify applicable obligations and translate them into practical data governance, product and contractual controls.
We assess EU Data Act requirements across data access, data sharing, contracts and technical implementation, helping organisations close operational gaps and maintain ongoing Data Act compliance.
Regulation Overview
Type
EU Regulation – Direct Application
In Force
12 September 2025
Key Application Date
12 September 2025
Market Access
Data access, sharing and contractual obligations
Certificate
No general CE-marking mechanism under the Data Act
Max Penalty
Data access and sharing obligations
EU Data Act Application
The EU Data Act applies from 12 September 2025. Organisations should assess the regulation’s scope, data access processes, contracts and technical controls to determine the requirements applicable to their products and services.
What It Is
Understanding
the EU Data Act
The EU Data Act entered into application on 12 September 2025. It establishes rules designed to make data generated by connected products and related services more accessible and usable, while defining obligations for data holders, users and other parties within its scope.
The regulation addresses data generated by connected products and related services. Organisations should identify what data is generated, who holds it, who can request access, how it can be shared and what technical and contractual controls govern that process.
More About
EU Data Act
The Data Act requires a broader operational assessment than a single certification checklist. Businesses should examine their data architecture, contracts, product interfaces, access procedures and governance model to determine where changes are needed.
A practical EU Data Act compliance programme should begin with scope and role mapping, followed by a review of data flows, user access rights, data-sharing mechanisms, contractual terms, security controls and governance responsibilities.
SUMMARY
Type
EU Regulation – Direct Application
In Force
12 September 2025
Key Application Date
12 September 2025
Market Access Mechanism
Data access, sharing and contractual obligations
Certificate Issued
No general CE-marking mechanism under the Data Act
Max Penalty
Data access and sharing obligations
What the EU Data Act Covers
The regulation addresses data generated by connected products and related services. Organisations should identify what data is generated, who holds it, who can request access, how it can be shared and what technical and contractual controls govern that process.
The Data Act requires a broader operational assessment than a single certification checklist. Businesses should examine their data architecture, contracts, product interfaces, access procedures and governance model to determine where changes are needed.
12 Sep 2025
Full compliance deadline for all manufacturers placing products with digital elements on the EU market.
Data Access
Two categories of critical products with stricter conformity assessment requirements than standard self-certification.
Data Governance
The market access mechanism. Without CE marking your product cannot be legally placed on the EU market.
Who is affected
The EU Data Act can affect different participants depending on their role, including manufacturers of connected products, providers of related services, data holders, users and certain third parties seeking access to data. Scope should therefore be established before controls are designed.
Manufacturer
Connected Product Manufacturers
Manufacturers of connected products should assess which product and service data is generated, how users can access it and whether data-sharing mechanisms satisfy the applicable EU Data Act requirements.
Importer
EU Importers of Connected Products
Organisations importing or distributing connected products should determine whether their role creates obligations under the EU Data Act and ensure relevant contracts and operational processes support applicable data access and sharing requirements.
Distributor
EU Distributors and Resellers
Business partners and service providers should review their contractual and operational responsibilities where they participate in data access, sharing or processing arrangements covered by the regulation.
Core EU Data Act compliance areas
Data Access
User Data Access
Users may have rights to access data generated by connected products or related services. Organisations should establish clear processes for receiving, validating and responding to applicable data access requests.
Data Sharing
Third-Party Data Access
Where the regulation requires or permits data to be made available to third parties, organisations should define secure sharing mechanisms, responsibilities and controls for the relevant data flows.
Contracts & Governance
Contractual Compliance
Contracts, policies and internal governance should reflect applicable EU Data Act obligations, including responsibilities for data access, sharing, confidentiality and handling of protected information.
EU Data Act requirements
EU Data Act requirements can affect data access, data sharing, contractual terms, transparency, technical interfaces, confidentiality and governance. The precise obligations depend on the organisation’s role and the scope of the connected product or related service.
Art.Annex I Part 1
Security by Design Requirements
Products must be delivered without known exploitable vulnerabilities, with a secure default configuration, protection against unauthorised access, data protection, minimal attack surface, and resilience against denial of service attacks.
Mandatory
Art.Annex I Part 1(2)
Confidentiality and Integrity
Products must protect data at rest and in transit. Collected data must be limited to what is necessary for the intended purpose.
Mandatory
Art.Annex I Part 2(1)
Vulnerability Identification and Documentation
Manufacturers must identify and document vulnerabilities and components contained in products, including a software bill of materials in a machine-readable format.
Mandatory
Art.Annex I Part 2(2)
Security Updates for Minimum 5 Years
Manufacturers must address vulnerabilities without delay and provide security updates separately from functionality updates for a minimum of five years or the expected product lifecycle.
Mandatory
Art.13
Technical Documentation
Manufacturers must draw up technical documentation before placing the product on the market. It must enable conformity assessment and be kept for ten years after product placement.
Mandatory
Art.14
Actively Exploited Vulnerability Reporting
Manufacturers must notify ENISA within 24 hours of becoming aware of an actively exploited vulnerability in their product.
24h Reporting
15M EUR
Maximum Penalty – or 2.5% of Global Annual Turnover
The EU Data Act sets maximum penalties of 15 million EUR or 2.5 percent of global annual turnover for violations of the essential requirements. Market surveillance authorities can also require products to be withdrawn from the market or recalled without financial penalty, which for a product-dependent business is often a more significant consequence than the fine.
Conformity assessment and CE marking
Unlike ISO 27001 or IEC 62443, the EU Data Act does not result in a certificate from an accredited body. CE marking is the market access mechanism.
Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market. The pathway for your products depends on their classification: standard, Class I, or Class II.
- Product portfolio scope and classification analysis
- Annex I gap assessment against current product state
- Technical file and Declaration of Conformity preparation
- Support for third-party or notified body engagement
How we deliver EU Data Act engagements
We help manufacturers assess their product portfolio against EU Data Act Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.
Step 1 – Scope
Product Scope and Classification
We identify which of your products fall within EU Data Act scope, classify them as standard, Class I, or Class II products, and determine the applicable conformity assessment route for each.
Output: EU Data Act product scope map with classification and conformity pathway per product
Step 2 – Gap Assessment
Annex I Readiness Assessment
We assess each in-scope product against all Annex I Part 1 and Part 2 requirements and produce a gap report with remediation priorities sequenced by enforcement risk.
Output: EU Data Act Annex I gap report with prioritised finding register per product
Step 3 – Remediate
Technical Remediation and Process Design
We support your engineering and product teams in closing Annex I gaps including secure default configuration, vulnerability management process design, and SBOM implementation.
Output: Closed Annex I gaps with documented evidence and vulnerability handling process
Step 4 – Conform
Declaration of Conformity and Data Governanceing
We prepare the Article 13 technical documentation file and the Declaration of Conformity, enabling your products to carry CE marking and enter the EU market without regulatory challenge.
Output: Technical documentation file and Declaration of Conformity per product
Related
Connected frameworks
and services
Service
EU Digital Regulation programme
Explore →
Regulation
IEC 62443
Explore →
Regulation
NIS2 Directive
Explore →
Start with a 30-minute discovery call
We scope your EU Data Act product obligations and define the fastest path to CE marking. Book a 30-minute discovery call. We help manufacturers assess their product portfolio against EU Data Act Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.
You leave with:
- Your product scope classification
- Your Annex I gap summary
- Your conformity assessment pathway