EU Data Act now directly applicable law: New obligations, but also rights for European companies

The EU's European Data Strategy is a project aimed at regulating the digital economy. The goal is to create a secure, people-centered digital ecosystem in which citizens are empowered and businesses benefit from digital potential.

A central element of the Data Act (DA) is the obligation to make data generated when using networked products, e.g., household appliances or cars, or so-called connected services, accessible to users, ideally through direct access. For example, the DA should enable users to switch between cloud providers without any problems. The DA applies to data generated when using connected products or connected services, regardless of whether it is personally identifiable. In this respect, the scope of the DA is broader than that of the GDPR.

The DA is relevant for companies not only because they, as potential addressees, may have to comply with the resulting obligations, but also as potentially entitled users if networked products or connected services are used.

The DA came into force on January 11, 2024, and will be directly applicable throughout the EU from September 12, 2025. It is therefore important for companies to familiarize themselves with the new obligations, if they have not already done so.

Help in this context can be provided by, among other things, the "GDD Practical Guide: European Data Strategy: AI Regulation, Data Act, etc." can provide assistance in this context. The GDD practical guide provides an overview of the most important legal acts that have been planned or already adopted as part of the European data strategy and classifies them according to their implications for data protection law. Particular attention is also paid to the position and tasks of the data protection officer, who is faced with new tasks in relation to the legal acts in question.

The responsibilities for supervising the Data Act in Germany still need to be defined in binding terms. The draft bill for a national Data Act implementation law dated February 5, 2025, stipulates that the Federal Network Agency (BNetzA) is the competent authority for the application and enforcement of the DA. The draft law provides for a special responsibility of the Federal Commissioner for Data Protection and Freedom of Information (BfDI) for monitoring the GDPR “within the framework” of the DA. The BfDI is to support the BNetzA in data protection matters and cooperate with it in a spirit of trust and cooperation. However, the special responsibility of the BfDI is controversial, and it is also conceivable that responsibility could be assigned to the state authorities otherwise responsible for monitoring data protection in the private sector

In any case, as long as no special jurisdiction is regulated by law, it can be assumed on the basis of the provision in Art. 37 (3) DA that the state data protection authorities are also responsible for monitoring data protection in connection with the DA.

The European Data Act is also a topic
at the GDD's Data Protection Conference (DAFTA).

DAFTA-Program (DE)