Penalties & enforcement
EU Data Act penalties and enforcement
The EU Data Act is enforced by national authorities in each EU country. There is no single EU-wide fine, but penalties must be effective, proportionate and dissuasive — and where personal data is involved, GDPR-level fines can apply on top.
Who enforces the Data Act?
Each EU Member State designates one or more competent authorities to apply and enforce the Data Act (Art. 37). Where a country appoints several, one acts as a "data coordinator" to keep enforcement consistent across sectors.
Data protection authorities remain responsible for the parts of the Data Act that involve personal data. Sectoral regulators — for example in energy, automotive or telecoms — may also be involved within their areas.
What are the penalties?
Unlike the GDPR, the Data Act does not set a single EU-wide fine cap. Instead, each Member State sets its own penalties, which must be effective, proportionate and dissuasive (Art. 40). Member States were required to notify their penalty rules to the European Commission by 12 September 2025, so exact levels vary from country to country.
When setting a penalty, authorities weigh factors such as the nature, gravity, scale and duration of the breach, any steps taken to mitigate harm, previous infringements, the financial benefit gained, and the offender's annual turnover in the EU.
When GDPR fines apply on top
Where an infringement involves personal data, the data protection authorities can apply the GDPR's own fine regime under Article 83 — up to €20 million or 4% of total worldwide annual turnover, whichever is higher. The Data Act does not replace the GDPR, so both regimes can apply to the same activity.
More than fines
Consequences beyond financial penalties
Void contract terms
Unfair contractual terms on data access and use are automatically void and unenforceable (Art. 13) — regardless of any fine.
Complaints
Users and business customers can lodge complaints with the competent authority (Art. 38), which can trigger an investigation.
Orders to comply
Authorities can require you to bring products, services or contracts into compliance — not just impose a fine.
Commercial and reputational risk
Blocked switching, refused data access or unfair terms can damage customer relationships and invite litigation.
Reducing risk
How to lower your enforcement risk
Know your authority
Identify the competent authority — and any data coordinator — in each EU country where you operate.
Fix void clauses
Review B2B contracts for the Art. 13 blacklisted terms and remove them before a counterparty challenges them.
Handle requests properly
Document how you receive, verify and answer data-access and switching requests, so complaints are less likely.
Map the GDPR overlap
Where sharing involves personal data, confirm a GDPR lawful basis to avoid dual exposure to fines.
Check your exposure
See where your compliance gaps are
Answer a few questions to get a free indication of where your business may face Data Act enforcement risk.