EU Data Act: what it means for your data and AI projects
While almost all the media attention goes to the AI Act, there is another European regulation that is going to directly affect any project working with data: the EU Data Act. In the projects I lead it is starting to come up in conversations about cloud, IoT and artificial intelligence, because it changes the rules on who can access data and under what conditions.
What the EU Data Act is and what it responds to
The EU Data Act is the European regulation that governs fair access to and use of the data generated by connected products and related services. Its aim is to share out the value of data better: to give users and companies more control over the information they generate and to reduce lock-in by large providers.
For anyone leading technology projects, this translates into new design obligations. Connected products must allow the user to access the data they generate and, in many cases, share it with third parties of their choosing.
How the EU Data Act impacts your AI projects
AI feeds on data, so any regulation that changes its governance directly affects artificial intelligence projects. The EU Data Act influences where you can obtain data, how you share it and what clauses you need with providers and clients. A model trained or fed with poorly governed data is a latent legal risk.
That is why I always connect the Data Act with a good data governance base and with EU AI Act compliance: both frameworks reinforce each other and it is wise to treat them together in the project design.
Cloud and portability: the end of provider lock-in
Switching provider without penalties
One of the most relevant parts of the EU Data Act obliges cloud providers to facilitate switching to another provider, removing barriers and reducing exit costs. For infrastructure managers, this is an opportunity to renegotiate and to design less captive architectures.
Interoperability by design
The regulation pushes towards formats and standards that ease portability. Designing with interoperability in mind from the start, as I already recommend in my IT regulations strategy, avoids traumatic migrations later on.
How to prepare without slowing innovation
My recommendation is to map what data your products generate, review the contracts with providers and clients, and adjust the architectures to support access and portability. Done in good time, the EU Data Act does not slow innovation: it orders it and reduces future risks.
EU Data Act and AI Act: how they fit together
A question I am often asked is whether the EU Data Act and the AI Act overlap. They do not compete: they complement each other. The AI Act governs how artificial intelligence systems are built and used, while the Data Act governs the access, sharing and portability of the data that feeds those systems. If you train or fine-tune models with data generated by connected devices, both regulations affect you at once, and it is wise to review them together so as not to document the same thing twice.
In regulated environments, moreover, the Data Act intersects with the obligation to inventory which AI systems you use and with what data. That is why I recommend tackling data portability and the register of AI systems at the same time: the same mapping exercise serves to meet both requirements and avoids duplicating administrative effort.
Common mistakes with data contracts
The first mistake I see is continuing to sign cloud contracts with abusive exit clauses, as if the Data Act did not exist. From the moment it becomes applicable, those clauses cease to be valid, and carrying them over generates unnecessary legal risk. The second mistake is not knowing what data your own operation generates: many companies discover too late that they have valuable assets trapped in a manufacturer’s devices.
My advice is to start with a simple inventory: what data you generate, who controls it today and to whom you should be able to transfer it or claim it from. That map, which takes a few weeks, is the basis for negotiating better contracts and for opening new data-based lines of business that you previously could not move. The Data Act is not only compliance: well used, it is a competitive lever.
A nuance worth keeping in mind: the Data Act does not only open up data, it also distributes responsibilities. Whoever receives access to the information generated by a device takes on obligations regarding its use, its security and the limits of its processing. In the projects I support, I spend time clarifying who is responsible for what in each data flow, because that is where conflicts usually arise. Having those roles defined in writing, before starting to share, avoids friction and demonstrates to the regulator a mature data governance.
Conclusion: data as a first-class citizen
The EU Data Act consolidates an idea I have been defending for years: data is a strategic asset that must be governed with the same seriousness as security or compliance. Those who understand this early will turn this obligation into a competitive advantage.
Frequently asked questions about the EU Data Act
It is the European regulation that governs fair access to and use of the data generated by connected products and related services, giving users and companies more control over their information and reducing lock-in by large providers.
It changes where you can obtain data, how you share it and what clauses you need with providers and clients. A model fed with poorly governed data becomes a legal risk, so it is wise to treat it alongside the EU AI Act.
It obliges cloud providers to facilitate switching to another provider, removing barriers and reducing exit costs, and it drives interoperability through formats and standards that ease portability.
By mapping what data your products generate, reviewing the contracts with providers and clients and adjusting the architectures to support access and portability by design, with enough lead time.
A programme to run with little margin for error? See how I have done it.
See the nine case studies