Data Act and data sharing: who must share what and when?

The Data Act came into effect on 12 September 2025. The core of the first part of the law is the data sharing framework. This framework determines who gets access to which data, under which conditions and for which purpose. Important: these obligations do not only affect organisations that generate data, such as is the case with Internet of Things products.

Depending on the chapter of the Data Act, data holders, data recipients (third parties) and public authorities may fall under specific rules and obligations. Users, on the other hand, primarily obtain rights, such as access to data and the right to have data transferred to third parties. In this blog we explain who these organisations are and what they need to take into account about the data sharing framework of the Data Act.

Why the Data Act exists

Data was too often locked up at a handful of powerful players. This slows innovation, increases lock-in and leads to unfair contracts. The Data Act aims to break through these patterns with two clear goals: fair distribution of the value of data and fair access to and use of data.

The structure of the Data Act

The Data Act consists of different chapters, each regulating a different part of the data landscape (see also article 1(2) of the Data Act).

Chapters II to V together constitute the data-sharing framework: they set out the rights and obligations relating to data generated by connected products and services (Chapter II), the rules for data sharing between businesses and fair contract terms (Chapters III and IV), and the possibility for public authorities to access data in exceptional circumstances (Chapter V). The later chapters (VI to VIII) cover data processing services, protection against unlawful access by foreign governments, and interoperability. In this way, the Data Act establishes a broad framework covering the technical, economic, and legal aspects of data use. In this blog, we will not discuss the final section on data processing services.

Chapter II: connected products and related services

The Data Act introduces transparency rights and obligations for 'connected products' and 'related services' (more on these terms later). As a user, you have the right to access the data generated by your use and the right to share that data with a third party of your choice. In addition, the Data Act introduces obligations for parties that market such products and services.

Initially, most people limited the scope of the Data Act to Internet of Things devices, but a connected product can be more than just a smart refrigerator. A connected product is an object capable of collecting or generating data regarding its use, performance, or environment, and communicating that data. Examples include connected refrigerators or running watches, but bicycles and cars can also qualify as connected products if they generate and communicate data. A related service is a digital service linked to the use of a connected product that affects the product's functionality (such as an app that controls light brightness or refrigerator temperature).

Rights and obligations

With the exception of micro or small enterprises, the seller, lessor or leaseholder of a connected product or the provider of a related service, must comply with information obligations. Before concluding an agreement, it must be clear which data is being collected, where it is stored, how a user can access the data and what the purposes of the use of data by a (potential other) data holder are.

Furthermore, in connected products and related services, the new principle of access by design must be embedded. This means that the user should preferably have direct access via the product or service. If that is truly not possible, the data holder must make the data available actively and (where feasible) in real time (for example, via a website where data can be downloaded).

The data holder

But who is the data holder and why is this relevant? The data holder is the party that has the right or the obligation to use and make data available, such as the manufacturer of a connected product or the provider of the related service.

The Data Act imposes obligations on the data holder with regard to data sharing and rights on the user. Users may request data from the data holder, and have the right to request the data holder to forward that data to a third party. For example, I can ask Garmin to forward data about the use of my running watch to my physiotherapist.

Please note: in practice, there may be multiple data holders. If Betty rents a connected car whilst on holiday from rental company Shiny Wheels, which obtained the car from car company Yotoya, the relationship is as follows. Betty is the user, and both Shiny Wheels and Yotoya are data holders. If Betty requests data from Shiny Wheels, Shiny Wheels in turn requests Betty's data from Yotoya, for example via a direct platform offered by Yotoya or through a formal request.

Please also note: be aware that a user can also be a legal entity. The users who have the right to request data can therefore also be business parties.

Conditions for data sharing

Such data sharing is subject to certain conditions for both the third party and the data holder. Among other things, the third party is limited in their use based on the purposes set by the user, the third party may not be a gatekeeper and the third party may not use the data for profiling.

There must therefore be a three-party contract between the data holder(s), data recipients and the user to set out these arrangements. The European Commission has drawn up non-binding model contract terms (MCTs) for data sharing agreements to help companies draft appropriate terms concerning, for example, reasonable compensation and the protection of trade secrets.

Figure 1: illustration from the European Commission of the triangular contract in 'Final Report of the Expert Group on B2B data sharing and cloud computing contracts' of 2 April 2025.

Please note: this chapter concerns data generated through the use of a product or service. But the Data Act does not end there.

Chapters III & IV: mandatory data sharing between undertakings (B2B)

This chapter introduces a data sharing framework for cases where a party is obliged to share data with another party (both being undertakings). This can occur under the Data Act upon a request from a user, but also on the basis of other national or European rules. Sharing takes place (among other things) under the rules set out in the Data Act, such as:

  • Data sharing must be fair, reasonable and non-discriminatory ("FRAND" conditions).
  • Compensation may be requested; for SMEs/NGOs, compensation should cover all costs.
  • The data holder may implement appropriate technical protection measures, which the data recipient may not modify.
  • Unfair terms may not be used. The Data Act contains blacklist provisions (always invalid) and greylist provisions (presumed unfair) designed to counter "take-it-or-leave-it" contracts.

In practice, this means that parties that do not themselves 'measure' or 'generate' anything will also be affected by the Data Act: as a recipient (with strict limits on use) or as a holder that must share data on the basis of an obligation other than the Data Act.

Chapter V: sharing data with public authorities in cases of exceptional need (B2G)

The public sector may request data in cases of “exceptional need” and must motivate such a request and demonstrate proportionality. In other words: the authority must not be able to obtain the (personal) data itself through another, equivalent, means.

Situations of exceptional need include both general emergencies (such as major natural or man-made disasters, pandemics and cybersecurity incidents) and non-emergency situations (for example, aggregated and anonymised data from GPS systems of drivers which can be used to optimise traffic flows).

In the event of a general emergency, European and national entities may request both personal data and non-personal data. In the absence of a general emergency, authorities may, in certain situations (for example when fulfilling a specific task in the public interest, such as the compilation of official statistics), request non-personal data.

What you need to arrange now

Do you offer a connected product or a related service? If so, there are various obligations on transparency you must comply with and you should prepare for triangular contracts with third parties and your users. It is also relevant to consider the interplay with personal data protection (including the General Data Protection Regulation (GDPR)): what data are you permitted to share and on what basis? Consider the following:

  • Access-by-design: organise direct access or a robust mechanism for timely provision of data.
  • Have insight into your data: know which data is stored where, which data you should be able to supply and how you can retrieve this data.
  • Draw up your terms for data sharing (FRAND): consider standard terms, a pricing model (breaking down cost drivers), arrangements regarding trade secrets, security and audit clauses and clear usage purposes for recipients. Pay attention to the blacklist and greylist terms.
  • Prepare an analysis of lawfulness: what is the legal basis for data sharing and which safeguards are in place?

Not offering a connected product or related service? Then examine which B2B and B2G sharing scenarios (Chapter III) may be relevant for your organisation, how you will respond to data requests and which data you are willing and able to share or receive under which conditions (such as trade secrets and security policies).

  • Create a B2G request procedure: who assesses, how do you substantiate, what do you log, how do you anonymise?
  • Prepare yourself as a data recipient: if a user makes a request for data from a data holder and your organisation must process that data for purpose X, how will you handle this?

In summary

The Data Act is about fair sharing and not only by organisations who make smart products, but equally by organisations who must share data or may receive data under clear rules. If you offer a connected product or related service, you must already be complying with these obligations. Other organisations would be wise to prepare for data requests. This is also important in the context of the EU's broader ambition to better regulate the framework for the free movement of data.

Set up your processes, contracts and technology in such a way that you know per chapter: am I a holder, user, recipient or public authority partner, and what do I need to do?

Need help with this? Do not hesitate to reach out!

Contact us

Back to overview