Who enforces the Data Act?

Each EU Member State designates one or more competent authorities to apply and enforce the Data Act (Art. 37). Where a country appoints several, one acts as a "data coordinator" to keep enforcement consistent across sectors.

Data protection authorities remain responsible for the parts of the Data Act that involve personal data. Sectoral regulators — for example in energy, automotive or telecoms — may also be involved within their areas.

What are the penalties?

Unlike the GDPR, the Data Act does not set a single EU-wide fine cap. Instead, each Member State sets its own penalties, which must be effective, proportionate and dissuasive (Art. 40). Member States were required to notify their penalty rules to the European Commission by 12 September 2025, so exact levels vary from country to country.

When setting a penalty, authorities weigh factors such as the nature, gravity, scale and duration of the breach, any steps taken to mitigate harm, previous infringements, the financial benefit gained, and the offender's annual turnover in the EU.

When GDPR fines apply on top

Where an infringement involves personal data, the data protection authorities can apply the GDPR's own fine regime under Article 83 — up to €20 million or 4% of total worldwide annual turnover, whichever is higher. The Data Act does not replace the GDPR, so both regimes can apply to the same activity.

More than fines

Consequences beyond financial penalties

Void contract terms

Unfair contractual terms on data access and use are automatically void and unenforceable (Art. 13) — regardless of any fine.

Complaints

Users and business customers can lodge complaints with the competent authority (Art. 38), which can trigger an investigation.

Orders to comply

Authorities can require you to bring products, services or contracts into compliance — not just impose a fine.

Commercial and reputational risk

Blocked switching, refused data access or unfair terms can damage customer relationships and invite litigation.

Reducing risk

How to lower your enforcement risk

Know your authority

Identify the competent authority — and any data coordinator — in each EU country where you operate.

Fix void clauses

Review B2B contracts for the Art. 13 blacklisted terms and remove them before a counterparty challenges them.

Handle requests properly

Document how you receive, verify and answer data-access and switching requests, so complaints are less likely.

Map the GDPR overlap

Where sharing involves personal data, confirm a GDPR lawful basis to avoid dual exposure to fines.

Check your exposure

See where your compliance gaps are

Answer a few questions to get a free indication of where your business may face Data Act enforcement risk.

Start free assessment