EU Data Act: Data Access, Fair Cloud Switching, and What Actually Applies from 2025/2026
The EU Data Act has applied directly across the EU since September 12, 2025, and the core obligations around data access and cloud switching are already in force. In Germany, the national implementing act (DADG) has additionally been in effect since May 30, 2026. If you manufacture or sell connected products, offer related services, or operate cloud services, you are in scope. In concrete terms: users get free access to the data their devices generate, you must pass that data on to third parties at the user’s request, and switching cloud providers may no longer be artificially obstructed. These obligations are no longer distant future — they apply today, with further stages kicking in through early and mid-2027.
TL;DR
- The EU Data Act (Regulation (EU) 2023/2854) has applied directly across the EU since September 12, 2025. The data access and cloud switching obligations are already in force.
- Germany’s implementing act, the DADG, entered into force on May 30, 2026 (promulgated May 29, 2026). The competent supervisory authority is the Bundesnetzagentur, Germany’s Federal Network Agency.
- Users of connected products get free, easy, and secure access to the data generated through use — including the right to have it shared with third parties they designate.
- Access by design becomes mandatory for connected products and services placed on the market after September 12, 2026.
- Switching charges for cloud migration (egress fees) are fully banned from January 12, 2027; the fair contract terms test (Art. 13) extends to open-ended legacy contracts from September 12, 2027.
- If you build or sell IoT products or offer cloud services, now is the time to review your data flows, contracts, and architecture. This is an overview, not legal advice.
What is the EU Data Act in the first place?
The EU Data Act is Regulation (EU) 2023/2854. As a regulation, it applies directly in all member states without needing to be transposed into national law first. That has been the case since September 12, 2025: the rules apply immediately.
The goal behind it is stated plainly: the EU wants to make the data economy fairer and more open. Today, the data generated by connected machines, vehicles, or sensors effectively sits with the manufacturer. The Data Act flips that and grants access rights to those who actually use the product. At the same time, switching between cloud providers is meant to become easier, so nobody stays locked into a provider technically or commercially.
Germany’s implementing act, the DADG (Data Act Implementation Act), supplements the regulation with national details, primarily around supervision and enforcement. It entered into force on May 30, 2026 (promulgated the day before, May 29, 2026). The supervisory authority is the Bundesnetzagentur — Germany’s Federal Network Agency, the regulator for networks and digital markets. So if you’re wondering who monitors and enforces the Data Act in Germany: as of now, that’s the Bundesnetzagentur.
Am I affected?
In short: far more likely than most people think. Those affected include in particular:
- Manufacturers and sellers of connected products (IoT). That covers machinery, vehicles, sensors, smart home devices, wearables, and industrial equipment.
- Providers of related services, i.e. the digital services built around these products.
- Data holders who control the data generated through product use.
- Providers of data processing services — in plain terms, cloud providers.
So if your company builds a connected machine, sells a sensor, runs an app for a device, or offers a cloud platform, you fall within scope. Classic mid-market manufacturers that equip their machinery with telemetry or deliver maintenance through connected devices are covered too — not just pure tech corporations.
What obligations are actually coming your way?
The Data Act bundles several obligations. The most important ones at a glance:
| Obligation | What it means |
|---|---|
| Data access for users | Users get free, easy, and secure access to the data generated through use of the product. |
| Data sharing with third parties | At the user’s request, you must pass that data on to third parties they designate. |
| Access by design | Connected products and services must be designed so that data access is possible from the outset (applies to new products from September 12, 2026). |
| Fair contract terms | Abusive contract clauses are prohibited; terms must be fair and transparent. |
| Easier provider switching | Contractual, technical, and commercial switching barriers must be dismantled, especially for cloud switching. |
The most important mindset shift: data from your products is no longer automatically your exclusive asset. The user has a right to it — and gets to decide who else receives it. That touches business models built on the manufacturer’s data monopoly, and it should be thought through early.
Access by design: why September 12, 2026 matters for product teams
One deadline deserves special attention: access by design becomes mandatory for connected products and services placed on the market after September 12, 2026.
This is not a compliance checkbox to tick after the fact — it’s an architecture requirement. Products launched from that date onward must build in data access from the ground up. If you’re planning a new device generation, a new machine series, or a new connected product today, you should anchor data access in your specifications, interfaces, and data model now. Retrofitting is usually more expensive and more error-prone than designing for the requirement from the start.
This is exactly where the Data Act becomes an engineering question: What data is generated, where does it live, how do you make it accessible securely and in a usable format, and how do you manage sharing with third parties in a clean, traceable way? These are topics that belong in product development and software architecture — not in the legal department shortly before launch.
Fair cloud switching: what changes through 2027
The second major block concerns cloud and data processing services. The Data Act wants provider switching to be genuinely possible, without artificial brakes. There’s a clear timeline for it:
- From January 12, 2027, switching charges are fully banned. This concerns so-called cloud switching, or egress fees — the costs that today are sometimes charged when you pull your data out of a cloud. From that date, they may no longer be billed.
- From September 12, 2027, the fair contract terms test (Art. 13) also applies to open-ended legacy contracts. This matters: even existing contracts that run indefinitely will then be measured against the standards of fair contract terms. Anyone counting on old contracts being grandfathered in is mistaken.
For you as a cloud customer, this means lock-in effects that are often taken for granted today are set to be dismantled. For you as a cloud provider, it means your contracts and pricing models need a review well before the deadlines hit.
The deadlines at a glance
To keep things straight, here are the key dates in one place:
| Date | What applies |
|---|---|
| September 12, 2025 | EU Data Act applies directly across the EU; data access and cloud switching obligations are in force. |
| May 30, 2026 | Germany’s implementing act (DADG) in force; supervision by the Bundesnetzagentur. |
| September 12, 2026 | Access by design becomes mandatory for new connected products and services. |
| January 12, 2027 | Full ban on switching charges (cloud switching/egress). |
| September 12, 2027 | Fair contract terms test (Art. 13) extends to open-ended legacy contracts. |
What should you do now?
Even without detailed legal advice, a few sensible first steps follow:
- Inventory your data. What data do your connected products generate, where does it live, who has access today? Without that picture, you can’t serve access rights cleanly.
- Review your product roadmap. Everything placed on the market after September 12, 2026 needs access by design. That belongs in the planning of new products now.
- Go through your cloud contracts. Keep an eye on switching charges, termination clauses, and open-ended legacy contracts before the 2027 deadlines hit.
- Build interfaces and sharing processes. Data access and data sharing with third parties must work in a technically clean, secure, and traceable way.
At Rocket-Monkeys, we see the Data Act primarily for what it is technically: a requirement for architecture, interfaces, and clean data flows. We build connected products and AI integrations so that data access, secure sharing, and a genuine ability to switch providers are designed in from the start — instead of being retrofitted at great expense later. For an overview of other regulatory topics that might affect you, see our Regulatory Radar.
An honest note on the limits: the Data Act is extensive, and many detailed questions — for instance, the scope of individual clauses or the treatment of sensitive data — will only be settled in practice and through interpretation by the supervisory authorities. This article gives you technical and strategic orientation based on the confirmed deadlines and obligations, but it does not replace legal advice. For a legal assessment of your specific case, you should consult qualified counsel.
Up for a quick intro call?
If you want to know what the Data Act means in concrete terms for your connected products or your cloud architecture, talk to us. In a no-obligation intro call, we’ll look at your data flows, your product roadmap, and the upcoming deadlines together, and pinpoint where action is needed. Just drop us a line at info@rocket-monkeys.com. We look forward to hearing from you.