Who should be checking their position?

You should review your EU Data Act exposure if your business is involved in connected products, IoT devices, smart equipment, industrial machinery, vehicle data, cloud services, SaaS platforms, or data-sharing contracts.

The rules are especially relevant where a product or service generates data through use, and where users, business customers or authorised third parties may want access to that data.

Common examples

  • Manufacturers of connected devices, machinery or vehicles.
  • Businesses providing companion apps, monitoring platforms or dashboards.
  • Cloud, hosting, SaaS, PaaS or IaaS providers.
  • Businesses that hold operational, sensor, usage or machine-generated data.
  • Companies using B2B contracts that restrict access to or use of data.
  • SMEs dealing with data-sharing terms imposed by larger commercial partners.

Practical review

Questions to ask internally

These questions can help you decide whether a more detailed review is needed.

Products

Do any of your products connect to the internet or generate data during use?

Services

Do you provide software, dashboards, monitoring tools or digital services linked to a product?

Data access

Could a user or third party request access to product-generated data?

Cloud switching

Could customers need to export, migrate or switch away from your data-processing service?

Contracts

Do your contracts limit data access, data use, portability or onward sharing?

SMEs

Are data-sharing terms being imposed on a smaller business by a stronger commercial party?

Free self-check

Get your free compliance report

Use the Data Act Checker to get an initial indication of whether your business may need a more detailed review.

Start free assessment