The deadline has arrived – so what now?
Since 12 September 2025, the EU Data Act has been directly applicable law throughout the European Union. The 20-month transition period has expired. What seemed like a distant deadline for months has now become a reality – and presents many businesses with significant challenges.
What the EU Data Act really changes
The key message is clear: data sovereignty has shifted fundamentally. Owners of connected products – from wind turbines and industrial machinery to smart home devices – now have the legally enshrined right to access the data generated by their devices and to share it with third parties.
1. Data access is no longer an option – it is an obligation
Manufacturers of connected products face a fundamental reorientation of their business models. Exclusive access to device data, which was previously often used as a competitive advantage, is no longer tenable. Companies must now:
- Provide technical interfaces that enable users to access data in real time
- Ensure machine-readable formats so that data can be processed directly
- Ensure free access for users
A practical example: the operator of a wind turbine can now transmit maintenance data directly to an independent service provider without needing the manufacturer as an intermediary. What used to be a matter for negotiation is now a legal right.
2. Switching cloud providers becomes easier
For cloud providers, the Data Act brings about far-reaching changes. ‘Vendor lock-in’ – that is, technical and economic dependence on a specific provider – is being actively combated:
- Customers have the right to switch to another provider within a maximum of 30 days
- The switching process must be technically straightforward and cost-effective
3. Protection of trade secrets remains in place
The Data Act is not a free pass for unlimited access to data. Companies can continue to protect trade secrets and are not required to disclose them. However, the burden of proof shifts: anyone wishing to deny access to data must provide substantiated evidence as to why this is necessary to protect trade secrets.
Initial practical experience: where are the sticking points?
The first few weeks since the Act came into force clearly show that the Data Act is not only a legal challenge but, above all, an operational and technical one.
Technical implementation hurdles
The greatest difficulties are evident in:
Interface development: Manufacturers must provide standardised APIs to enable users to access data directly. Many companies underestimated the effort required for technical implementation. Legacy systems, which were never designed for external data access, must be retrofitted – often without interrupting operations.
Data quality and format: Providing data ‘in a machine-readable format’ often requires fundamental adjustments to existing systems.
Security architectures: The balancing act between data access and the protection of trade secrets calls for new security concepts.
Contractual adjustments
Existing licence, service and partnership agreements must be reviewed and amended to ensure compliance with the Data Act. This applies in particular to:
- Unfair contract terms that unilaterally disadvantage one party – these are now invalid
- Pricing models, which must take into account free data access for users
- Liability provisions that reflect the new data access rights
The challenge: Many companies are unsure which of their existing clauses might be classified as ‘unfair’. Without clear regulatory guidance, they must carry out their own legal assessments.
Supervision and support: The gap is being filled
A key issue: whilst EU Member States were required to notify their national sanction frameworks, Germany had yet to formally designate its supervisory authority by the deadline.
The German solution
A draft Data Act Implementation Act (DA-DG) designates the Federal Network Agency (BNetzA) as the central supervisory authority. This would be a clear solution that would provide companies with legal certainty – unlike with data protection, there would be only one national point of contact for the Data Act. However, the law had not yet been formally adopted by the deadline.
Practical guidance from the business community
On 12 September 2025, the digital industry association Bitkom published a practical guide providing answers to the most important questions regarding the Data Act. Materna also contributed its expertise to the development of this guide. This initiative demonstrates that where the public sector has yet to provide sufficient support, associations and experienced consultancy firms step in to help businesses with implementation.
Sanctions: The consequences of non-compliance
Enforcement of the Data Act takes place at national level. Unlike the GDPR, which provides for a uniform framework of fines across the EU, under the Data Act individual Member States develop their own rules on sanctions. However, these must comply with EU requirements: they must be effective, proportionate and dissuasive.
Special considerations regarding personal data
As soon as personal data is involved, the strict GDPR penalties also apply – up to 20 million euros or 4 per cent of global annual turnover.