The Data Act came into effect on 12 September 2025. The core of the first part of the law is the data sharing framework. This framework determines who gets access to which data, under which conditions and for which purpose. Important: these obligations do not only affect organisations that generate data, such as is the case with Internet of Things products.
Depending on the chapter of the Data Act, data holders, data recipients (third parties) and public authorities may fall under specific rules and obligations. Users, on the other hand, primarily obtain rights, such as access to data and the right to have data transferred to third parties. In this blog we explain who these organisations are and what they need to take into account about the data sharing framework of the Data Act.
Data was too often locked up at a handful of powerful players. This slows innovation, increases lock-in and leads to unfair contracts. The Data Act aims to break through these patterns with two clear goals: fair distribution of the value of data and fair access to and use of data.
The Data Act consists of different chapters, each regulating a different part of the data landscape (see also article 1(2) of the Data Act).
Chapters II to V together constitute the data-sharing framework: they set out the rights and obligations relating to data generated by connected products and services (Chapter II), the rules for data sharing between businesses and fair contract terms (Chapters III and IV), and the possibility for public authorities to access data in exceptional circumstances (Chapter V). The later chapters (VI to VIII) cover data processing services, protection against unlawful access by foreign governments, and interoperability. In this way, the Data Act establishes a broad framework covering the technical, economic, and legal aspects of data use. In this blog, we will not discuss the final section on data processing services.
The Data Act introduces transparency rights and obligations for 'connected products' and 'related services' (more on these terms later). As a user, you have the right to access the data generated by your use and the right to share that data with a third party of your choice. In addition, the Data Act introduces obligations for parties that market such products and services.
Initially, most people limited the scope of the Data Act to Internet of Things devices, but a connected product can be more than just a smart refrigerator. A connected product is an object capable of collecting or generating data regarding its use, performance, or environment, and communicating that data. Examples include connected refrigerators or running watches, but bicycles and cars can also qualify as connected products if they generate and communicate data. A related service is a digital service linked to the use of a connected product that affects the product's functionality (such as an app that controls light brightness or refrigerator temperature).
With the exception of micro or small enterprises, the seller, lessor or leaseholder of a connected product or the provider of a related service, must comply with information obligations. Before concluding an agreement, it must be clear which data is being collected, where it is stored, how a user can access the data and what the purposes of the use of data by a (potential other) data holder are.
Furthermore, in connected products and related services, the new principle of access by design must be embedded. This means that the user should preferably have direct access via the product or service. If that is truly not possible, the data holder must make the data available actively and (where feasible) in real time (for example, via a website where data can be downloaded).
But who is the data holder and why is this relevant? The data holder is the party that has the right or the obligation to use and make data available, such as the manufacturer of a connected product or the provider of the related service.
The Data Act imposes obligations on the data holder with regard to data sharing and rights on the user. Users may request data from the data holder, and have the right to request the data holder to forward that data to a third party. For example, I can ask Garmin to forward data about the use of my running watch to my physiotherapist.
Please note: in practice, there may be multiple data holders. If Betty rents a connected car whilst on holiday from rental company Shiny Wheels, which obtained the car from car company Yotoya, the relationship is as follows. Betty is the user, and both Shiny Wheels and Yotoya are data holders. If Betty requests data from Shiny Wheels, Shiny Wheels in turn requests Betty's data from Yotoya, for example via a direct platform offered by Yotoya or through a formal request.
Please also note: be aware that a user can also be a legal entity. The users who have the right to request data can therefore also be business parties.
Such data sharing is subject to certain conditions for both the third party and the data holder. Among other things, the third party is limited in their use based on the purposes set by the user, the third party may not be a gatekeeper and the third party may not use the data for profiling.
There must therefore be a three-party contract between the data holder(s), data recipients and the user to set out these arrangements. The European Commission has drawn up non-binding model contract terms (MCTs) for data sharing agreements to help companies draft appropriate terms concerning, for example, reasonable compensation and the protection of trade secrets.

Figure 1: illustration from the European Commission of the triangular contract in 'Final Report of the Expert Group on B2B data sharing and cloud computing contracts' of 2 April 2025.
Please note: this chapter concerns data generated through the use of a product or service. But the Data Act does not end there.
This chapter introduces a data sharing framework for cases where a party is obliged to share data with another party (both being undertakings). This can occur under the Data Act upon a request from a user, but also on the basis of other national or European rules. Sharing takes place (among other things) under the rules set out in the Data Act, such as:
In practice, this means that parties that do not themselves 'measure' or 'generate' anything will also be affected by the Data Act: as a recipient (with strict limits on use) or as a holder that must share data on the basis of an obligation other than the Data Act.
The public sector may request data in cases of “exceptional need” and must motivate such a request and demonstrate proportionality. In other words: the authority must not be able to obtain the (personal) data itself through another, equivalent, means.
Situations of exceptional need include both general emergencies (such as major natural or man-made disasters, pandemics and cybersecurity incidents) and non-emergency situations (for example, aggregated and anonymised data from GPS systems of drivers which can be used to optimise traffic flows).
In the event of a general emergency, European and national entities may request both personal data and non-personal data. In the absence of a general emergency, authorities may, in certain situations (for example when fulfilling a specific task in the public interest, such as the compilation of official statistics), request non-personal data.
Do you offer a connected product or a related service? If so, there are various obligations on transparency you must comply with and you should prepare for triangular contracts with third parties and your users. It is also relevant to consider the interplay with personal data protection (including the General Data Protection Regulation (GDPR)): what data are you permitted to share and on what basis? Consider the following:
Not offering a connected product or related service? Then examine which B2B and B2G sharing scenarios (Chapter III) may be relevant for your organisation, how you will respond to data requests and which data you are willing and able to share or receive under which conditions (such as trade secrets and security policies).
The Data Act is about fair sharing and not only by organisations who make smart products, but equally by organisations who must share data or may receive data under clear rules. If you offer a connected product or related service, you must already be complying with these obligations. Other organisations would be wise to prepare for data requests. This is also important in the context of the EU's broader ambition to better regulate the framework for the free movement of data.
Set up your processes, contracts and technology in such a way that you know per chapter: am I a holder, user, recipient or public authority partner, and what do I need to do?
Need help with this? Do not hesitate to reach out!