Home/Consulting/Data Act
EU Data Act · Data economy

Sharing data—without losing your business model.

The Data Act opens up data from connected products to users and third parties—and changes who controls the data generated by your machines. We update your contracts, interfaces and processes in good time.

What the Data Act regulates

Fair rules for a connected economy

The Data Act (Regulation (EU) 2023/2854) defines who may access data from connected products and related services, and the conditions under which data must be shared. Its aim is to unlock the economic potential of industrial and IoT data and break down data silos.

Applicable from

12 September 2025

The core obligations apply from this date. ‘By design’ accessibility requirements for newly placed connected products take effect later, so product development and contracts must be adapted beforehand.

Infringements may result in substantial penalties to be determined by the Member States. Early adaptation costs less than subsequent correction.

Scope

Three data-sharing scenarios

The Data Act addresses different relationships—each with its own rights and obligations.

01

B2C—Users & manufacturers

Users of connected products—both individuals and businesses—have the right to access the data they generate through use, easily, securely and free of charge, and wherever possible directly from the product.

02

B2B—Sharing data with third parties

At the user's request, data holders must make the data available to designated third parties on fair, reasonable and non-discriminatory terms. Unfair contractual terms are not binding.

03

B2G—Data for public authorities

In exceptional cases, such as public emergencies, authorities may request access to company data, subject to narrowly defined conditions and safeguards.

Your obligations

What you need to address now

From product design to cloud contracts, the Data Act affects many areas at once.

  • Data accessibility ‘by design’ for connected products and related services.
  • Pre-contractual information for users on the type and volume of data generated and how it can be accessed.
  • Data provision processes to give users and designated third parties access to data.
  • Fair contractual terms —reviewing and adapting existing contracts.
  • Protection of trade secrets when sharing data.
  • Easier cloud switching —removing switching barriers and fees.
  • Protection against unlawful third-country access to data stored in the EU.
Cloud switching

Breaking free from vendor lock-in

The Data Act requires providers of data processing services to facilitate switching to another provider through clear termination periods, migration support and the gradual removal of switching fees. It is an opportunity for customers—and an obligation for providers to redesign contracts and interfaces.

We assess your cloud contracts from both perspectives—as a provider that needs to become compliant, or as a customer seeking to exercise its right to switch.

Implementation with Nuviax

Data Act compliance in four steps

Step 01

Data & scope analysis

We identify which connected products and related services you offer or use, which data they generate and the role in which the Data Act applies to you.

Step 02

Contract & clause review

We review data licensing, usage and cloud contracts for prohibited terms, adapt them and draft fair, enforceable terms—while protecting your trade secrets.

Step 03

Technical data access solution

Our IT team builds the interfaces and processes through which users and third parties can access data securely, with logging and appropriate controls—including authentication and an audit trail.

Step 04

Documentation & support

We prepare the pre-contractual information, document data flows in an audit-proof manner and keep you informed as the regulation evolves.

Reviewing and processing business documents
Data Act compliance in four steps
Data Act

Data Act: services for your competitive advantage

We combine compliance with commercial use to enable sustainable business models, secure data value creation and enforceable switching rights.

01

Future-proof business models

Products and services are aligned with the Data Act, DMA and AI Act—with a focus on commercial viability and market opportunities.

02

Protecting your assets

Trade secrets, IP and proprietary models are safeguarded in the context of expanded data access rights.

03

Data value creation and access rights

Offensive and defensive data strategies, contract drafting, licences and fair remuneration models based on FRAND principles.

04

IoT, cloud and XaaS

Access by design, interoperability and switching rights for connected products, cloud and service models.

05

Cloud and edge switching

Reduce vendor lock-in, safeguard business continuity and prepare switching rights before fee phase-out deadlines.

06

AI integration

Legally secure integration of AI into business processes and product development under data law, taking the AI Act into account.

DORA

DORA services for ICT service providers

For ICT service providers in the financial sector, we supplement our Data Act consulting with the specific requirements of DORA.

01

DORA relevance analysis

Determining which requirements actually apply to you and where you are affected only indirectly.

02

Scope of services

Obligations are clearly allocated between financial entities and ICT service providers so that responsibility is not shifted unilaterally.

03

Appropriate measures

Advice on commercially sensible safeguards proportionate to the risk and size of the company.

04

Third-party risk and contracts

Minimum contractual provisions under Art. 30 DORA, risk reduction, and fair, clear terms.

05

Negotiation and implementation

Nuviax supports you with contract drafting, operational implementation and collaborative coordination with financial-sector customers.

FAQ

Frequently asked questions about the Data Act

This means products that record, generate or collect data about their use or environment and can communicate that data—from industrial machinery, vehicles and agricultural technology to building systems and smart household appliances. If your product generates and transmits sensor data, the Data Act is very likely relevant.
No. The Data Act expressly protects trade secrets. You may require and agree appropriate safeguards before disclosure; in narrowly defined cases, disclosure may be refused or suspended. The key is sound contractual and technical implementation—which is exactly what we set up for you.
The GDPR remains fully applicable. Where shared data is personal data, the GDPR also applies and takes precedence with regard to its protection. We integrate both regulatory frameworks so that Data Act access rights and GDPR data protection obligations do not conflict.
You gain rights: easier provider switching, clearer deadlines, migration support and, in time, the removal of switching fees. We review your contracts for restrictive clauses and provide technical and legal support for a planned provider switch.

Share data—on your terms

In 30 minutes, clarify how the Data Act affects you and which contracts and interfaces should take priority. Consulting and technical implementation from a single source.