Regulatory Framework

EU Data
Act

The EU Data Act establishes rules for access to and use of data generated by connected products and related services. Our EU Data Act consulting helps organisations identify applicable obligations and translate them into practical data governance, product and contractual controls.

We assess EU Data Act requirements across data access, data sharing, contracts and technical implementation, helping organisations close operational gaps and maintain ongoing Data Act compliance.

Regulation Overview

Type

EU Regulation – Direct Application

In Force

12 September 2025

Key Application Date

12 September 2025

Market Access

Data access, sharing and contractual obligations

Certificate

No general CE-marking mechanism under the Data Act

Max Penalty

Data access and sharing obligations

EU Data Act Application

The EU Data Act applies from 12 September 2025. Organisations should assess the regulation’s scope, data access processes, contracts and technical controls to determine the requirements applicable to their products and services.

What It Is

Understanding
the EU Data Act

The EU Data Act entered into application on 12 September 2025. It establishes rules designed to make data generated by connected products and related services more accessible and usable, while defining obligations for data holders, users and other parties within its scope.

The regulation addresses data generated by connected products and related services. Organisations should identify what data is generated, who holds it, who can request access, how it can be shared and what technical and contractual controls govern that process.

More About
EU Data Act

The Data Act requires a broader operational assessment than a single certification checklist. Businesses should examine their data architecture, contracts, product interfaces, access procedures and governance model to determine where changes are needed.

A practical EU Data Act compliance programme should begin with scope and role mapping, followed by a review of data flows, user access rights, data-sharing mechanisms, contractual terms, security controls and governance responsibilities.

SUMMARY

Type

EU Regulation – Direct Application

In Force

12 September 2025

Key Application Date

12 September 2025

Market Access Mechanism

Data access, sharing and contractual obligations

Certificate Issued

No general CE-marking mechanism under the Data Act

Max Penalty

Data access and sharing obligations

What the EU Data Act Covers

The regulation addresses data generated by connected products and related services. Organisations should identify what data is generated, who holds it, who can request access, how it can be shared and what technical and contractual controls govern that process.

The Data Act requires a broader operational assessment than a single certification checklist. Businesses should examine their data architecture, contracts, product interfaces, access procedures and governance model to determine where changes are needed.

12 Sep 2025

Full compliance deadline for all manufacturers placing products with digital elements on the EU market.

Data Access

Two categories of critical products with stricter conformity assessment requirements than standard self-certification.

Data Governance

The market access mechanism. Without CE marking your product cannot be legally placed on the EU market.

Who is affected

The EU Data Act can affect different participants depending on their role, including manufacturers of connected products, providers of related services, data holders, users and certain third parties seeking access to data. Scope should therefore be established before controls are designed.

Manufacturer

Connected Product Manufacturers

Manufacturers of connected products should assess which product and service data is generated, how users can access it and whether data-sharing mechanisms satisfy the applicable EU Data Act requirements.

Importer

EU Importers of Connected Products

Organisations importing or distributing connected products should determine whether their role creates obligations under the EU Data Act and ensure relevant contracts and operational processes support applicable data access and sharing requirements.

Distributor

EU Distributors and Resellers

Business partners and service providers should review their contractual and operational responsibilities where they participate in data access, sharing or processing arrangements covered by the regulation.

Core EU Data Act compliance areas

Data Access

User Data Access

Users may have rights to access data generated by connected products or related services. Organisations should establish clear processes for receiving, validating and responding to applicable data access requests.

Data Sharing

Third-Party Data Access

Where the regulation requires or permits data to be made available to third parties, organisations should define secure sharing mechanisms, responsibilities and controls for the relevant data flows.

Contracts & Governance

Contractual Compliance

Contracts, policies and internal governance should reflect applicable EU Data Act obligations, including responsibilities for data access, sharing, confidentiality and handling of protected information.

EU Data Act requirements

EU Data Act requirements can affect data access, data sharing, contractual terms, transparency, technical interfaces, confidentiality and governance. The precise obligations depend on the organisation’s role and the scope of the connected product or related service.

Art.Annex I Part 1

Security by Design Requirements

Products must be delivered without known exploitable vulnerabilities, with a secure default configuration, protection against unauthorised access, data protection, minimal attack surface, and resilience against denial of service attacks.

Mandatory

Art.Annex I Part 1(2)

Confidentiality and Integrity

Products must protect data at rest and in transit. Collected data must be limited to what is necessary for the intended purpose.

Mandatory

Art.Annex I Part 2(1)

Vulnerability Identification and Documentation

Manufacturers must identify and document vulnerabilities and components contained in products, including a software bill of materials in a machine-readable format.

Mandatory

Art.Annex I Part 2(2)

Security Updates for Minimum 5 Years

Manufacturers must address vulnerabilities without delay and provide security updates separately from functionality updates for a minimum of five years or the expected product lifecycle.

Mandatory

Art.13

Technical Documentation

Manufacturers must draw up technical documentation before placing the product on the market. It must enable conformity assessment and be kept for ten years after product placement.

Mandatory

Art.14

Actively Exploited Vulnerability Reporting

Manufacturers must notify ENISA within 24 hours of becoming aware of an actively exploited vulnerability in their product.

24h Reporting

15M EUR

Maximum Penalty – or 2.5% of Global Annual Turnover

The EU Data Act sets maximum penalties of 15 million EUR or 2.5 percent of global annual turnover for violations of the essential requirements. Market surveillance authorities can also require products to be withdrawn from the market or recalled without financial penalty, which for a product-dependent business is often a more significant consequence than the fine.

Conformity assessment and CE marking

Unlike ISO 27001 or IEC 62443, the EU Data Act does not result in a certificate from an accredited body. CE marking is the market access mechanism.

Compliance is demonstrated through a conformity assessment process, after which the manufacturer issues a Declaration of Conformity and affixes CE marking to the product. The CE mark is the market access mechanism. Without it, the product cannot be placed on the EU market. The pathway for your products depends on their classification: standard, Class I, or Class II.

  • Product portfolio scope and classification analysis
  • Annex I gap assessment against current product state
  • Technical file and Declaration of Conformity preparation
  • Support for third-party or notified body engagement

How we deliver EU Data Act engagements

We help manufacturers assess their product portfolio against EU Data Act Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.

Step 1 – Scope

Product Scope and Classification

We identify which of your products fall within EU Data Act scope, classify them as standard, Class I, or Class II products, and determine the applicable conformity assessment route for each.

Output: EU Data Act product scope map with classification and conformity pathway per product

Step 2 – Gap Assessment

Annex I Readiness Assessment

We assess each in-scope product against all Annex I Part 1 and Part 2 requirements and produce a gap report with remediation priorities sequenced by enforcement risk.

Output: EU Data Act Annex I gap report with prioritised finding register per product

Step 3 – Remediate

Technical Remediation and Process Design

We support your engineering and product teams in closing Annex I gaps including secure default configuration, vulnerability management process design, and SBOM implementation.

Output: Closed Annex I gaps with documented evidence and vulnerability handling process

Step 4 – Conform

Declaration of Conformity and Data Governanceing

We prepare the Article 13 technical documentation file and the Declaration of Conformity, enabling your products to carry CE marking and enter the EU market without regulatory challenge.

Output: Technical documentation file and Declaration of Conformity per product

Related

Connected frameworks
and services

Service

EU Digital Regulation programme

Explore →

Regulation

IEC 62443

Explore →

Regulation

NIS2 Directive

Explore →

Start with a 30-minute discovery call

We scope your EU Data Act product obligations and define the fastest path to CE marking. Book a 30-minute discovery call. We help manufacturers assess their product portfolio against EU Data Act Annex I requirements, define the conformity assessment pathway, and prepare the Declaration of Conformity documentation and technical file.

You leave with:

  • Your product scope classification
  • Your Annex I gap summary
  • Your conformity assessment pathway
Scroll to Top