Onwyn › Standards › EU Data Act (Regulation (EU) 2023/2854)

Regulation · 2023/2854

EU Data Act (Regulation (EU) 2023/2854)

The Data Act is the EU's horizontal law on who may use the data that connected products, related services and cloud platforms generate. It has applied since 12 September 2025 and it binds companies by role rather than by sector. A connected-product manufacturer or related-service provider is usually the data holder, and must make the data its products generate available to the user, and on the user's instruction to a third party the user names. Any business that unilaterally imposes contract terms about access to or use of data, or about liability for data obligations, is caught by the unfair-terms rules — blacklisted terms are simply not binding. Every provider of a cloud or edge data processing service must let its customers leave: no contractual, commercial, technical or organisational obstacles, a notice period of at most two months, a transition period of 30 calendar days, and from 12 January 2027 no switching charges at all. Two further chapters reach further than most companies expect: public sector bodies can demand data on the basis of an exceptional need, and providers must take active measures against third-country governmental access to non-personal data held in the Union where that access would conflict with Union law. There is no Data Act certification and no certificate to obtain — no notified body signs anything off and no auditor issues a mark. Compliance is demonstrated through contracts, technical capability and documentation: the terms you offer, the access, export and deletion mechanisms you have actually built, and the records showing you can meet the deadlines when a customer or a user invokes them. The Data Act does not override the GDPR; where the two conflict the data protection law prevails, so personal data still needs its own legal basis and the Data Act never supplies one. Enforcement sits with national competent authorities, and for infringements of the data-sharing chapters concerning personal data, fines reach the GDPR Article 83(5) level.

35
Requirements
10
Areas
23
Recommended documents
1
Mapped frameworks
Start EU Data Act free Have us do it instead

What this standard asks for

Every requirement in EU Data Act (Regulation (EU) 2023/2854), grouped the way the standard groups them. In the Semantic Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Scope, roles & application dates

4 requirements

  • Art. 1Determine how the Data Act reaches you, and in which roles
  • Art. 2Map your data against the definitions the Regulation actually uses
  • Art. 50Plan against the staggered application dates
  • Art. 7Test the micro and small enterprise exemption honestly

Connected products: access for the user (Ch. II)

5 requirements

  • Art. 3(1)Design connected products and related services for access by default
  • Art. 3(2)-(3)Give the buyer the required data information before the contract is signed
  • Art. 4(1)-(5)Make readily available data accessible to the user on request
  • Art. 4(6)-(8)Identify and protect trade secrets before you are asked for the data
  • Art. 4(10)-(14)Respect the limits on what each side may do with the data

Sharing with third parties & recipient duties (Ch. II)

3 requirements

  • Art. 5Act on a user's instruction to share data with a third party
  • Art. 6Meet the conditions if you receive data as the third party a user named
  • Art. 11Use technical protection measures without obstructing the rights they sit beside

Data holder obligations: terms & compensation (Ch. III)

2 requirements

  • Art. 8Offer fair, reasonable and non-discriminatory terms, and no exclusivity
  • Art. 9Set compensation you can justify, with the SME cost-only cap

Unfair contractual terms between businesses (Ch. IV)

4 requirements

  • Art. 13(1)-(3)Identify which of your contract terms were unilaterally imposed
  • Art. 13(4)Remove the terms that are always unfair
  • Art. 13(5)Justify or rewrite the terms presumed unfair
  • Art. 41Decide your position on the model contractual terms and standard clauses

Public sector access in exceptional need (Ch. V)

2 requirements

  • Art. 14-15Recognise a valid public sector request based on exceptional need
  • Art. 17-20Answer a public sector request inside the deadlines, or refuse it properly

Cloud and edge switching (Ch. VI)

8 requirements

  • Art. 23Remove every obstacle that stops a customer leaving
  • Art. 24 / Art. 31Determine which of your services the switching duties actually bind
  • Art. 25Put the mandated switching terms into every customer contract
  • Art. 26Publish your switching procedures and a live register of formats
  • Art. 27Cooperate in good faith, including when you are the destination
  • Art. 29Reduce switching charges to cost now, and to zero from 12 January 2027
  • Art. 30Build the technical capability to let a customer leave
  • Art. 34Support in-parallel use, and cap egress charges to cost

International governmental access (Ch. VII)

2 requirements

  • Art. 28Publish your jurisdiction and your safeguards, and reference them in contracts
  • Art. 32Prevent and handle third-country governmental access to non-personal data

Interoperability & standards (Ch. VIII)

2 requirements

  • Art. 33Meet the interoperability essentials if you participate in a data space
  • Art. 35Track harmonised standards and common specifications for cloud interoperability

Enforcement, penalties & the personal-data boundary

3 requirements

  • Art. 37Know your competent authority, and appoint a legal representative if you are outside the EU
  • Art. 40Understand the exposure, including the GDPR-level fines for the data-sharing chapters
  • Art. 1(5)Keep the GDPR boundary explicit — the Data Act does not override it

The documents you will end up with

The recommended document set for EU Data Act (Regulation (EU) 2023/2854) — 23 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

Data Act Role and Scope Register

Per product and per service: whether the Data Act reaches it, and which role you are playing — data holder, connected-product manufacturer, data processing service provider, data recipient, or none of them.

Data Act Readiness Plan

The dated plan against the staggered dates, with an owner against each gap.

Connected Product Data Inventory

What each connected product and related service generates, which of it is readily available data, where it sits, and how it is retrieved.

Pre-Contract Data Information Notice

The information a buyer or a service customer must receive before signing: what data the product generates, where it is kept, how to get it, and how to ask for it to be shared.

User Data Access Procedure

How a user asks for their data, how you verify them, what you send, in what format, and inside what timeframe.

Trade Secret Identification and Protection Record

Which data elements you assert as trade secrets, on what basis, what protective measures you require before disclosing them, and every occasion you withheld, suspended or refused.

Third-Party Data Sharing Procedure

How you handle a user's instruction to share data with a third party they name, including the gatekeeper check and the confidentiality measures you agree first.

Data Recipient Use Commitments

If you receive connected-product data as the third party a user named: what you may and may not do with it, and when you must erase it.

Data Sharing Terms and Compensation Policy

The fair, reasonable and non-discriminatory terms you offer data recipients, and how any compensation is calculated and shown to them.

Technical Protection Measures Note

The technical measures you rely on to stop unauthorised access to shared data, and the record showing they do not obstruct the user's own rights.

Contract Fairness Review

A clause-by-clause pass over your standard terms against the blacklist and the grey list, recording which clauses were unilaterally imposed and what was changed.

Model Contractual Terms Position

Whether you adopt the Commission's model contractual terms and standard contractual clauses, in whole or in part, and where you deviate and why.

Public Sector Data Request Procedure

How you recognise, log, test and answer a request from a public sector body claiming an exceptional need — including how you refuse one that does not qualify.

Switching and Exit Contract Schedule

The contract terms every customer must be offered: the two-month maximum notice, the 30-day transition, the retrieval window, erasure, and the exhaustive list of what is portable.

Switching Scope Determination

Which of your services carry the full switching duties and which fall into the narrow custom-built or non-production carve-out — with the pre-contract notice that goes with it.

Switching Information Page and Format Register

The public page describing your switching and porting procedures, restrictions and limitations, plus the up-to-date online register of data structures, formats and open specifications.

Switching Charges Decision Record

What you charge for switching today, the cost basis behind it, and the dated plan to reach zero by 12 January 2027.

Customer Switching Runbook

The operational procedure your team follows when a customer gives notice, tested at least once against a real dataset rather than described on paper.

International Access Transparency Statement

The published statement of which jurisdiction your infrastructure sits under and what measures you take against conflicting third-country governmental access.

Government Access Request Procedure

What happens when a third-country authority demands customer data: who is told, what is tested, how little is handed over, and when the customer is informed.

Interoperability Standards Watch

How you find out when a harmonised standard or common specification is published, and the 12-month clock it starts.

Data Act Governance Record

Who owns Data Act compliance internally, which competent authority and data coordinator you fall under, and — if you are outside the EU — the legal representative you have designated.

GDPR Interface Note

Where Data Act obligations touch personal data: the legal basis relied on, who the controller is at each step, and what happens when the two regimes pull in different directions.

Work that counts twice

EU Data Act (Regulation (EU) 2023/2854) overlaps with 1 other framework in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start EU Data Act today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.