EU DATA ACT

Consulting and implementation support for the EU Data Act. We help you meet the requirements and turn data access, sharing, and interoperability into a working part of your data governance.

The EU Data Act governs who may access and use data generated by connected products and related services in the EU. It gives users the right to access the data their devices produce, obliges data holders to share it on request, and sets rules for cloud switching and interoperability.

Legal engineering translates regulatory requirements into operational processes and systems. For the EU Data Act, that means data access, sharing, and interoperability designed into products and contracts.

Learn more about Legal Engineering

What the EU Data Act means for your organization

The EU Data Act has applied since 12 September 2025, and the next deadline is approaching: from 12 September 2026, connected products and related services placed on the EU market must be designed so that users can access their data directly, in a structured, machine-readable format. For manufacturers, the Data Act turns from a legal requirement into a product design requirement.

Any company that manufactures or collects data generated by or from a physical device (IoT device) must consider how the Data Act applies to its operations. This includes suppliers of related digital services, data contracts, business-to-government access rules, data processing services (switching between service providers), and interoperability. Enforcement sits with the national authorities of the member states, and the implementation timeline is short.

Meeting these requirements takes a clear view of your data flows and the ability to coordinate legal, technical, and product teams. That is where we come in.

Which EU Data Act deadlines apply now?

 

Since 12 September 2025

The Data Act applies. Users of connected products have data access rights, data holders must make data available on request, and contractual terms must meet the fairness requirements.

 

From 12 September 2026

Connected products and related services newly placed on the EU market must provide direct data access by design, where relevant and technically feasible.

 

From 12 September 2027

The switching charges for data processing services are phased out completely.

 

We provide consulting and implementation support for the EU Data Act

Our steps on a comprehensive EU Data Act Implementation.

Element 1@2x

Applicability assessment

The process begins with an in-depth assessment of your existing products and operations to identify relevant use cases. A thorough evaluation of your product landscape determines whether the Data Act applies and assesses implications for future products and business models ("data access by design").

Element 2@2x

Tailored implementation

Next, a tailored implementation process introduces the necessary modifications and technical capabilities. Technical, legal, and organizational measures come together in one implementation plan.

Element 3@2x

Continuous review

After implementation, iterative reviews and continuous improvement cycles follow. System functionalities are regularly revisited and tested to keep pace with evolving standards and regulatory requirements.

Given the complexity the Data Act brings to data-driven businesses, it’s crucial to work with a partner who can interpret the regulation within your specific context and integrate tailored solutions into your IT systems. Ensuring compliance requires effective implementation, ongoing support, and continuous refinement of your data governance.
Zohar_Photo_Data_Act

Zohar Efroni

principal specialist legal engineering, diconium

Benefit from our multi-disciplinary approach 

Offerings 1

Multidisciplinary expert guidance

Navigating the complexities of the EU Data Act requires specialized knowledge across multiple fields, including in the legal, technical, and operational domains. Our team brings together experts from each of these areas.

Offerings 2

Time and resource efficiency

Implementing the Data Act can be resource-intensive and time-consuming. By partnering with us, you can free up your internal resources and allow your team to focus on core business activities, while we handle the complexities of compliance. 

Offerings 3

Risk mitigation

Offerings 4

Enhanced data practices

Beyond compliance, implementing the Data Act with our support can improve your overall data governance and sharing practices, ultimately leading to better decision-making. 

DICONIUM_120924_AFTERNOON_1913

Why diconium?

We bring hands-on experience in building and running compliance tools that enable smooth, effective implementation. With extensive expertise in legal engineering, IT projects, and regulatory compliance, we have partnered up with industry leaders such as Volkswagen Group entities concerning their Data Act implementation initiatives, successfully translating legal requirements

DICONIUM_120924_AFTERNOON_0959(1) 4a23cae8129e88200b8c66112958d9b6

Ready to update your business?

Your contact at diconium

Zohar Efroni

principal specialist legal engineering

Zohar+Efroni

 

FAQ

What is the EU Data Act and who does it affect? 

The EU Data Act is a regulation designed to improve access to and use of data generated by connected products and services. It primarily affects organizations that collect, process, or share data from IoT devices, platforms, or digital services within the EU. Companies must ensure that data can be accessed, shared, and used in a fair, secure, and transparent way across stakeholders such as users, partners, and public authorities.

Who is a data holder under the EU Data Act?

A data holder is the party that has the right or obligation to make data from a connected product or related service available. In practice this is usually the manufacturer of the connected product or the provider of the related service. The user is the person or company that owns, rents, or leases the product. Determining who holds which role is the first step in any Data Act assessment, because the obligations follow the role, not the industry.

Does the EU Data Act apply to products already on the market?

The access and sharing obligations have applied since 12 September 2025, regardless of when a product was placed on the market. The design requirement for direct data access applies to connected products and related services placed on the market from 12 September 2026. For existing fleets this means access has to be organized even where the product was never designed for it, often through gateways, backends, or platform-side interfaces rather than changes to the device itself.

What does "data access by design" mean in practice?

In practice, data access by design means the product and its backend are built so that users can get to their data without a manual process on the manufacturer's side. That involves documented interfaces, a data model that makes clear which data points exist and what they mean, authentication and permission management so that only entitled parties get access, delivery in a structured, machine-readable format, and access close to real time where the use case requires it. The obligation applies where relevant and technically feasible, which makes the technical assessment part of the compliance work.

What do companies need to do to comply with the EU Data Act?

To comply with the EU Data Act, organizations must identify relevant data use cases, assess how data is generated and shared, and implement mechanisms for data access and portability. This includes aligning technical systems, contractual frameworks, and governance structures. Compliance also requires continuous monitoring to keep pace with evolving requirements and integrate them into existing data governance strategies.

How does the EU Data Act relate to GDPR and the EU AI Act?

The three regulations overlap but answer different questions.

GDPR governs personal data and applies whenever data can be linked to an individual.

The EU Data Act governs access to and sharing of data from connected products, including non-personal data.

The EU AI Act governs how AI systems are developed and used, which matters as soon as product data feeds AI models. Connected products often fall under all three at once, which is why access rights, privacy safeguards, and AI documentation are best designed together rather than in sequence.

What happens in case of non-compliance with the EU Data Act?

Penalties are set by the EU member states and must be effective, proportionate, and dissuasive. Where a violation involves personal data, fines can reach GDPR levels. In practice, the more immediate consequence is commercial: late implementation puts data access rights and the partnerships built on them at risk, and products that cannot deliver data as required become harder to sell into the EU market.

How does Diconium support companies in implementing the EU Data Act?

Diconium supports organizations through a structured end-to-end approach, starting with an in-depth assessment of products, services, and data flows to determine where the EU Data Act applies. Based on this, we design tailored implementation strategies that integrate legal, technical, and organizational measures. Compliance is then not only achieved but embedded into existing IT systems and business processes.