What the EU Data Act means for your organization –
and why you should care
The EU Data Act, effective as of September 2025, presents both challenges and opportunities for businesses operating in the EU. Data-driven enterprises and business models now face a new and complex set of legal obligations regarding data sharing, contractual setups and competition rules.
Any company that manufactures or collects data generated by or from a physical device (IoT device) must consider how the Data Act applies to its operations. This includes suppliers of related digital services, data contracts, business-to-government access rules, data processing services (switching between service providers), and interoperability. Non-compliance with the Data Act might result in significant penalties, and the implementation timeline is demanding. Successfully confronting this challenge requires a thorough understanding of data flows and compliance details, as well as the ability to manage multiple stakeholders effectively.
Businesses affected by this new regulation can greatly benefit from a reliable partner to guide them through the intricate legal, technical, and logistical details of an end-to-end compliance scheme.
We provide consulting and implementation support for the EU Data Act
Our steps on a comprehensive EU Data Act Implementation.
![]()
Applicability assessment
The process begins with an in-depth assessment of your existing products and operations to identify relevant use cases. A thorough evaluation of your products landscape determines whether the Data Act applies and assesses potential implications for the development of future products and business models (“data access by design”).
![]()
Tailored implementation
Next, a tailored implementation process is designed to introduce the necessary modifications and technical capabilities specific to your organization. This comprehensive approach integrates technical, legal, and organizational measures into one implementation plan.
![]()
Continuous review
Post-implementation, an iterative review and continuous improvement cycles follow. System functionalities are regularly revisited and tested to maintain adherence to the latest standards and evolving regulatory requirements.
Given the complexity the Data Act brings to data-driven businesses, it’s crucial to work with a partner who can interpret the regulation within your specific context and integrate tailored solutions into your IT systems. Ensuring compliance requires effective implementation, ongoing support, and continuous refinement of your data governance.
Zohar Efroni
principal specialist legal engineering, diconium
Benefit from our multi-disciplinary approach
Multidisciplinary expert guidance
Navigating the complexities of the EU Data Act requires specialized knowledge across multiple fields, including in the legal, technical, and operational domains. Our team brings together experts from each of these areas.
Time and resource efficiency
Implementing the Data Act can be resource-intensive and time-consuming. By partnering with us, you can free up your internal resources and allow your team to focus on core business activities, while we handle the complexities of compliance.
Risk mitigation
Non-compliance with the Data Act might result in significant penalties and create legal risks. We help you identify and mitigate these risks early and prepare the organization for potential consequences.
Enhanced data practices
Beyond compliance, implementing the Data Act with our support can improve your overall data governance and sharing practices, ultimately leading to better decision-making.
Why diconium?
We bring hands-on experience in building and running compliance tools that enable smooth, effective implementation. With extensive expertise in legal engineering, IT projects, and regulatory compliance, we have partnered up with industry leaders such as Volkswagen Group entities concerning their Data Act implementation initiatives, successfully translating legal requirements
Further insights
Explore more on data driven topics.
Understand EU Data Act
In our blogpost we explained the EU Data Act: rights, obligations and challenges for data holders and manufacturers.
Legal Engineering solutions
Read more about our legal solutions.
Cybersecurity & compliance
Protect your digital assets and data while ensuring regulatory adherence. Discover our offering.
Ready to update your business?
Your contact at diconium
Zohar Efroni
principal specialist legal engineering
FAQ
What is the EU Data Act and who does it affect?
The EU Data Act is a new regulation designed to improve access to and use of data generated by connected products and services. It primarily affects organizations that collect, process, or share data from IoT devices, platforms, or digital services within the EU. Companies must ensure that data can be accessed, shared, and used in a fair, secure, and transparent way across stakeholders such as users, partners, and public authorities.
What do companies need to do to comply with the EU Data Act?
To comply with the EU Data Act, organizations must identify relevant data use cases, assess how data is generated and shared, and implement mechanisms for data access and portability. This includes aligning technical systems, contractual frameworks, and governance structures. Compliance also requires continuous monitoring to keep pace with evolving requirements and integrate them into existing data governance strategies.
How does Diconium support companies in implementing the EU Data Act?
Diconium supports organizations through a structured end-to-end approach, starting with an in-depth assessment of products, services, and data flows to determine where the EU Data Act applies. Based on this, we design tailored implementation strategies that integrate legal, technical, and organizational measures. Compliance is then not only achieved but embedded into existing IT systems and business processes.
Why is the EU Data Act more than just a compliance requirement?
While non-compliance can lead to legal risks and penalties, the EU Data Act also creates opportunities to improve data governance and and open up new business models. Diconium helps organizations use these opportunities by aligning compliance with strategic goals: better data sharing, increased operational efficiency, and more informed decision-making. This turns regulatory requirements into a driver for innovation and long-term business value.
Since when does the EU Data Act apply?
The EU Data Act has applied since 12 September 2025: users of connected products hold data access rights, and data holders must share data on request.
A second deadline follows on 12 September 2026. Connected products and related services placed on the market from that date must be designed so that product data is accessible to users by default, in a structured, machine-readable format ("access by design").
For manufacturers, that turns the Data Act from a legal requirement into a product design requirement.
What happens in case of non-compliance with the Data Act?
Penalties are set by the EU member states and must be effective, proportionate, and dissuasive; for violations involving personal data, fines can reach GDPR levels.
Beyond penalties, late implementation risks losing data access rights and partnerships built on them.
