EU Data Act Compliance Timeline & FAQ
The Data Act gives users of connected products a right to the data those products generate, sets fairness rules for business-to-business data sharing, lets public bodies request data in exceptional need and enshrines the right to switch cloud services. Most of it has applied since 12 September 2025; the remaining obligations arrive between September 2026 and September 2027, and national enforcement is taking shape, in Germany since 30 May 2026.
Last updated
On this page
- At a glance
- Key dates
- The timeline in detail: 2023 to 2024 · 2025 · 2026 · 2027 · 2028
- Where the Data Act meets other EU digital laws
- Frequently asked
- How to keep this straight
- Sources
At a glance
- The Data Act entered into force on 11 January 2024 and has applied in general since 12 September 2025 (Art 50).
- Users of connected products and related services can access the data they generate and have it shared with third parties (Articles 4 and 5); data holders may use non-personal product data only on the basis of a contract with the user.
- From 12 September 2026, connected products and related services placed on the market must be designed for access by default (Article 3(1)).
- Cloud switching is now a mandatory right for cloud customers, requires certain contract clauses and charges, including egress, must already be limited to cost and disappear entirely on 12 January 2027 (Article 29).
- The unfair-terms test for data-sharing contracts reaches pre-existing long-term contracts on 12 September 2027 (Article 13, Article 50).
- Enforcement is national: Member States designate competent authorities and set penalties (Art 37, Art 40); for personal data, GDPR-level fines apply through the data protection authorities. In Germany the implementing law (DADG) has been in force since 30 May 2026, with the Bundesnetzagentur as competent authority.
- Guidance is accumulating: the Commission's FAQ (v1.4, January 2026), the vehicle-data guidance (September 2025), the model contractual terms and cloud standard contractual clauses (November 2025) and draft guidelines on reasonable compensation (February 2026 draft).
Beyond the dates in the timeline, the Data Act contains delegated and implementing powers (Art 45, Art 46) and the Commission's standardisation and interoperability work (Arts 33 to 36); they shape how the regime evolves but rarely drive day-to-day compliance, so we keep them out of the main timeline.
Key dates
- 2023-12-22Published in the Official JournalRegulation (EU) 2023/2854 is published; every later deadline counts from here.Key provisionsArt 50
- 2024-01-11Entry into force; reduced switching charges beginTwenty days after publication. From this date providers of data processing services must limit switching charges, including data egress, to the costs they actually incur.
- 2025-09-12General applicationUser access and sharing rights, B2B fairness rules, the unfair-terms test for new contracts, B2G requests, cloud switching, international safeguards and interoperability apply. The Commission publishes FAQ v1.3 and the vehicle-data guidance C(2025) 6119 the same day.
- 2025-11-19Model contractual terms and cloud SCCs adoptedCommission Recommendation C(2025) 7750: non-binding model contractual terms for data sharing and standard contractual clauses for cloud computing contracts.Key provisionsArt 41
- 2026-01-22Commission FAQ updated to v1.4Living document, non-binding; in practice the reference point national authorities work from.
- 2026-02-20Compensation-guidelines consultation closesThe Commission's draft guidelines on reasonable compensation, published in February 2026; adoption expected later in 2026 after EDIB consultation.Key provisionsArt 9(5)
- 2026-05-30Germany: DADG enters into forceThe German Data Act implementation law takes effect. The Bundesnetzagentur becomes the competent authority and single point of contact, licenses dispute settlement bodies and supervises cloud switching; the BfDI stays responsible for personal data.
- 2026-09-12Access by designConnected products and related services placed on the market from this date must make their data accessible to the user by default; the one remaining product-design obligation.
- 2027-01-12Switching charges abolishedProviders of data processing services may no longer charge for switching at all, data egress included. Costs of parallel (multi-cloud) use may still be billed.Key provisionsArt 29(1)
- 2027-09-12Unfair-terms control reaches legacy contractsThe Art 13 test extends to data-sharing contracts concluded on or before 12 September 2025 that are indefinite or run at least ten years from 11 January 2024.
- 2028-09-12Commission evaluationThe Commission must evaluate the Data Act and report to the European Parliament and the Council.Key provisionsArt 49
The timeline in detail
2023 to 2024 — Adoption and entry into force
The Data Act is the EU's horizontal rulebook for data generated by connected products and related services, for business-to-business data sharing and for switching between data processing services. It was published on 22 December 2023 and entered into force on 11 January 2024 (Article 50). One provision started to bite immediately: from that date, providers of data processing services had to limit any switching charges, including data egress, to the costs they actually incur (Article 29(2)).
2025 — Application begins
Since 12 September 2025 the core of the regulation applies. Users of connected products and related services can access readily available product and related-service data without undue delay, free of charge and, where relevant and technically feasible, continuously and in real time (Article 4), and can have that data shared with a third party of their choice (Article 5). Data holders that share data under a legal obligation must do so on fair, reasonable and non-discriminatory terms (Article 8) for reasonable compensation (Article 9); unilaterally imposed unfair terms in data-sharing contracts between enterprises are void (Article 13); public bodies can request data in cases of exceptional need (Articles 14 to 22); cloud customers gain switching rights (Articles 23 to 31); and providers must protect non-personal data against unlawful third-country government access (Article 32).
The Commission accompanied the application date with two documents: version 1.3 of its FAQ and a dedicated guidance on vehicle data (C(2025) 6119 final), the first sector-specific reading of Chapter II. Both are non-binding, and the FAQ states expressly that it does not represent the Commission's official position; in practice they are the reference points national authorities work from.
On 19 November 2025 the Commission adopted the Recommendation required by Article 41: model contractual terms for the three mandatory data-sharing relationships (data holder to user, user to data recipient, data holder to data recipient) plus a template for voluntary sharing, and six standard contractual clauses for cloud computing contracts covering switching and exit, termination, security and business continuity, non-dispersion, non-amendment and liability (C(2025) 7750). They are voluntary and can be amended, but they are the Commission's own translation of Chapter VI into contract language and the natural starting point for the contract review that Article 25 requires.
2026 — Access by design, national enforcement, and the compensation guidelines
The FAQ moved to version 1.4 on 22 January 2026. In February 2026 the Commission published draft guidelines on calculating reasonable compensation under Article 9 and consulted on them until 20 February; adoption, after consultation of the European Data Innovation Board, is expected in the course of 2026. The draft confines chargeable amounts to incremental, necessary costs of making data available, allows an optional margin tied to investment in data generation, and excludes overhead, sunk costs and ordinary business expenses. For SMEs and not-for-profit research organisations, compensation may not exceed the costs directly attributable to the request (Article 9(4)).
National enforcement is also arriving. In Germany the Datenverordnung-Anwendungs-und-Durchsetzungs-Gesetz (DADG) entered into force on 30 May 2026. It makes the Bundesnetzagentur the competent authority and single point of contact under Article 37: it cooperates with the Federal Commissioner for Data Protection (BfDI) on personal data, with the Commission and with the European Data Innovation Board, licenses dispute settlement bodies, monitors compliance with the cloud switching rules and runs an information programme for market participants (Bundesnetzagentur press release of 30 May 2026; Bundesnetzagentur Data Act hub). Penalties under Article 40 are set in the national law; for personal data the GDPR fine framework applies through the data protection authorities. Other Member States are at different stages, so the applicable national law should be checked for each jurisdiction.
The year's hard deadline is 12 September 2026. From that date, Article 3(1) applies to connected products and related services placed on the market: they must be designed and manufactured so that product data and related service data, including the metadata needed to interpret them, are by default easily, securely and free of charge accessible to the user, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, directly. Products placed on the market before that date remain subject to the access rights of Articles 4 and 5, but not to the design obligation. Manufacturers therefore decide product by product whether to build direct on-device access or to provide indirect access through the data holder, a choice the Commission treats as legitimate under either route.
2027 — Switching charges end, legacy contracts are caught
Two deadlines fall in 2027. On 12 January 2027 the transitional regime for cloud switching ends: providers of data processing services may no longer charge for switching at all, egress included (Article 29(1)). Where a customer does not switch but uses services in parallel, for example in a multi-cloud deployment, the costs of the resulting data egress may still be billed. The contractual mechanics of a switch, with the notice, transitional and retrieval periods of Article 25, have applied since 12 September 2025 and are set out in the FAQ below.
On 12 September 2027 the unfair-terms control in Article 13 extends to data-sharing contracts concluded on or before 12 September 2025, provided they are of indefinite duration or due to expire at least ten years after 11 January 2024 (Article 50). Enterprises with long-running supplier or platform agreements should review them against the blacklist and greylist of unfair terms before that date.
2028 — Review
By 12 September 2028 the Commission must evaluate the Data Act and report to the European Parliament and the Council (Article 49). Separately, the Digital Omnibus proposed in November 2025 includes targeted amendments to the Data Act; their final shape depends on the ongoing legislative process.
Where the Data Act meets other EU digital laws
- GDPR: the General Data Protection Regulation (GDPR) prevails whenever personal data are involved (Article 1(5)); the Data Act creates no new legal basis for processing, and where the user is not the data subject a GDPR basis is still required. The EDPB and EDPS flagged exactly this in their Joint Opinion 2/2022, together with concerns about sensitive data from health and wearable devices and about public-sector access.
- Data Governance Act: the Data Governance Act (DGA) sets the framework for data intermediaries and data altruism; the Data Act supplies the substantive access rights those intermediaries can help exercise.
- Digital Markets Act: undertakings designated as gatekeepers under the Digital Markets Act (DMA) are not eligible third parties and cannot receive user data under Article 5 (Article 5(3)).
- Cyber Resilience Act: the same connected products that must open their data under the Data Act must be secure by design under the Cyber Resilience Act (CRA); access interfaces built for Article 3(1) fall within the CRA's essential requirements. See the CRA compliance timeline and FAQ.
- Digital Omnibus: the November 2025 package proposes targeted amendments to the Data Act alongside the GDPR and ePrivacy changes; see the Digital Omnibus explainer.
Frequently asked
- Which products and services does the Data Act cover?
- Three groups. Connected products: items that obtain, generate or collect data on their use or environment and can communicate it, provided their primary function is not storing or processing data for others (Article 2(5)). Related services: digital services connected with the product at purchase or added later, whose absence would prevent the product from performing one of its functions (Article 2(6)). Data processing services: cloud and edge services such as IaaS, PaaS and many SaaS offerings (Article 2(8)). Chapter II covers the first two; Chapter VI covers the third.
- Is a smartphone or laptop a “connected product”?
- Contested. The definition excludes items whose primary function is storing, processing or transmitting data on behalf of others (Article 2(5)), and the recitals point to IoT devices from smart appliances to industrial machinery (Recital 14). Data protection and consumer bodies have argued against sweeping personal devices into scope; the Commission has not issued a specific clarification. Manufacturers should assess each product against the definition and document the reasoning.
- Does the Data Act apply to companies and users outside the EU?
- Manufacturers and data holders are covered irrespective of their place of establishment once a connected product is placed on the EU market or a related service is offered there (Article 1(3)). Data generated by such a product while it is used abroad still falls under the access rights. Users outside the EU do not benefit from the rights; the decisive factor for mobile products such as vehicles, ships or aircraft is whether they were placed on the EU market, for which registration in a Member State is an indicator.
- Which data are in scope: raw, pre-processed or derived?
- Raw and pre-processed data generated by the use of a connected product or related service, including the metadata needed to interpret them. Data resulting from substantial investment in cleaning, transformation or proprietary algorithms are inferred or derived and fall outside the access rights (Recital 15). Content, meaning textual, audio or audiovisual material created for human consumption and typically protected by intellectual property, is excluded (Recital 16); sensor imagery from a vehicle camera is not content in that sense. Applying pseudonymisation or other privacy-enhancing techniques does not by itself turn data into derived data.
- Does the Data Act apply to connected products sold before 12 September 2025?
- Yes for the access rights: users of products already on the market can request their data under Articles 4 and 5, and data holders need a contract with the user before using non-personal product data themselves (Article 4(13)). Where a data holder cannot identify the user despite reasonable efforts, the Commission accepts continued use of the data. The design obligation of Article 3(1) is different: it applies only to products and related services placed on the market from 12 September 2026.
- What is the EU Data Act?
- A horizontal EU regulation (2023/2854) on fair access to and use of data. It gives users of connected products and related services rights to the data they generate, sets fairness and compensation rules for business-to-business data sharing, allows public bodies to request data in exceptional need, and imposes switching, interoperability and safeguard duties on cloud and other data processing services.
- Who is the “data holder”?
- The natural or legal person that has the right or obligation to use and make available data, including product or related-service data it has retrieved or generated (Article 2(13)). Control over access decides, not who built the hardware or software: a manufacturer is not automatically the data holder, the role can be contracted to another entity, and where only the user can access the data there may be no data holder at all. A company cannot be user and data holder for the same data at the same time.
- Who is the “user”?
- Whoever owns a connected product or has been granted temporary rights to use it under a contract, or receives a related service: consumers as well as businesses (Article 2(12)). A single product can have several users, for instance a leased vehicle, in which case each user holds the access rights for the data generated during its use.
- What is a “related service”?
- A digital service, including software, that is connected with the product at purchase, rent or lease in such a way that its absence would prevent the product from performing a function, or that is later connected to add to, update or adapt functions (Article 2(6)). The Commission points to replaceability, user expectations and the marketing accompanying the product as indicators, while acknowledging that the decisive criterion, impact on the product's functions, will need clarification by the courts.
- What does “readily available data” mean?
- Product and related-service data that a data holder lawfully obtains or can lawfully obtain from the product or service without disproportionate effort going beyond a simple operation (Article 2(17)). Data a manufacturer chooses not to retrieve or store on its servers are not readily available; only data designed to be retrievable must be made available.
- When does the Data Act apply?
- In stages: it entered into force on 11 January 2024 and applies in general since 12 September 2025. The access-by-design obligation of Article 3(1) applies to products and related services placed on the market from 12 September 2026. The unfair-terms test applies to contracts concluded after 12 September 2025, and from 12 September 2027 to older indefinite or long-term contracts (Article 50).
- What changed on 12 September 2026?
- Connected products and related services placed on the market from that date must be designed so that their data, with the metadata needed to interpret them, are accessible to the user by default: easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, directly (Article 3(1)). Direct on-device access is not mandatory in every case; manufacturers may provide indirect access through the data holder where direct access is not relevant or feasible, taking account of cost, trade secrets and product security.
- When do cloud switching charges end?
- Since 11 January 2024 providers of data processing services may charge only the costs they actually incur for a switching operation, including egress. From 12 January 2027 no switching charges may be levied at all (Article 29). Costs of data egress caused by parallel use of several providers, as in a multi-cloud set-up, are not switching charges and may still be billed after that date.
- When does the unfair-terms test reach existing contracts?
- Article 13 applies to data-sharing contracts between enterprises concluded after 12 September 2025. From 12 September 2027 it also applies to contracts concluded on or before 12 September 2025 that are of indefinite duration or due to expire at least ten years after 11 January 2024. Contracts concluded before 11 January 2024 and expiring earlier remain unaffected.
- What must a data holder do when a user requests data?
- Make readily available product and related-service data, with the metadata needed to interpret them, available without undue delay, easily, securely, free of charge to the user, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real time (Article 4(1)). The data holder may verify that the requester is a user through proportionate means and may agree on protections for trade secrets, but may not make access unduly difficult. Its own use of non-personal product data requires a contract with the user, and it may not use the data to derive insights into the user's economic situation, assets or production methods (Article 4(13)).
- How must data access be provided: directly or indirectly, by push or by pull?
- The regulation leaves the technical route to the manufacturer and data holder but fixes the outcome. Access is direct where the user can retrieve, stream or download the data without any intervention by the data holder, for example through an on-device interface or an API to the manufacturer's server; the storage location does not matter (Article 3(1), Recital 22). Access is indirect where the product or service is designed so that the user must ask the data holder, typically through a portal or request process, and the data holder then makes the data available without undue delay (Article 4(1)). Mixed configurations are allowed: part of the data can be direct, the rest indirect, and the user must be told which route applies before contracting (Article 3(2), Article 3(3)). Direct access is only required where relevant and technically feasible, so the manufacturer may weigh the cost of redesign, trade secret and security exposure and the usefulness of direct access for the product in question, and may attach contractual conditions to direct access. In delivery terms, both routes can be served by pull or by push. Pull means the user or the third party retrieves the data on demand, through an API call, a download or a self-service portal; push means the data holder transmits the data as it is generated, through streaming or event-driven architectures that trigger updates. The Commission's FAQ expects APIs for automated retrieval and event-driven designs wherever low latency matters, as in IoT systems, connected mobility and industrial monitoring, because the data must be available continuously and in real time where relevant and technically feasible, in a comprehensive, structured, commonly used and machine-readable format such as JSON, XML or CSV, of the same quality as the data holder uses itself, easily and securely (Article 4(1), Article 5(1), Recital 30, Recital 35). Which mix fits depends on the product architecture, on whether the data are readily available on the device or only on the back-end, on industry latency needs and on the security and trade secret exposure of each route; feasibility is assessed objectively against industry standards. For vehicles the Commission treats remote back-end access, on-board access and data intermediation services as equally legitimate means.
- Must data be shared with third parties, and can gatekeepers receive it?
- On the user's request, the data holder must make readily available data available to a third party of the user's choice, on the same terms as to the user (Article 5). Undertakings designated as gatekeepers under the Digital Markets Act are not eligible third parties and cannot request or receive the data, nor may they solicit users to share it (Article 5(3)). Recipients in third countries can receive data, subject to the safeguards of Chapter VII and to the GDPR for personal data. Recipients may not use the data to develop a competing connected product or to profile individuals beyond what the requested service needs (Article 6).
- Can a data holder refuse for trade secrets or safety reasons?
- Trade secrets are protected but not a general ground for refusal: the holder identifies the secrets, agrees proportionate protective measures with the user or third party and may withhold or suspend sharing only where it can demonstrate, on a case-by-case basis, that it is highly likely to suffer serious economic damage despite those measures, notifying the competent authority (Article 4(6)–(8), Article 5(9)–(11)). Access may also be restricted where it would undermine security requirements laid down in EU or national law, again with notification of the authority (Article 4(2)).
- How much can a data holder charge for making data available?
- Between businesses, compensation must be non-discriminatory and reasonable and may include a margin (Article 9). The Commission's draft guidelines of February 2026 limit chargeable amounts to incremental, necessary costs directly linked to the request, such as specific formatting, sub-set selection, anonymisation or confidentiality measures, and exclude overhead, sunk costs and ordinary business expenses; any margin must reflect investment in generating the data. SMEs and not-for-profit research organisations may be charged only the costs directly attributable to their request, with no margin (Article 9(4)). On request, the data holder must explain the basis of its calculation in sufficient detail (Article 9(7)). Data must be provided to the user free of charge.
- What must a business do when a public body requests data?
- Public sector bodies and EU institutions may request data only in cases of exceptional need: a public emergency, or a specific public-interest task they cannot fulfil without the data after exhausting other means, including purchase (Articles 14 and 15). The request must be written, specific and justified (Article 17). The data holder must comply without undue delay but may refuse or seek modification within 30 working days, or five working days in a public emergency, if it does not control the data, has already supplied it to another body, or the request is deficient (Article 18). Personal data may be requested only in a public emergency and only where non-personal data would not suffice. Law-enforcement requests remain outside Chapter V.
- What do vehicle manufacturers specifically have to do?
- The Commission's vehicle-data guidance applies the general rules to cars: OEMs and other data holders must give users and, on request, third parties such as independent repairers or insurers access to readily available vehicle data of the same quality as they use themselves, either directly from the vehicle or indirectly through a back-end interface. Article 3(1) does not force direct on-board access; making data available through the OBD-II port or an API are both legitimate routes. Only data designed to be retrievable are in scope, so data points an OEM chooses not to retrieve or store are not readily available. The guidance also encourages sector standards and dialogue between OEMs, aftermarket operators and authorities.
- What must cloud and other data processing services do?
- Providers of data processing services (IaaS, PaaS, SaaS and other cloud and edge services) must remove commercial, technical, contractual and organisational obstacles to switching (Article 23), set the switching rights and obligations out in a written contract with the minimum content of Article 25, inform customers about switching procedures, formats and known limitations and keep an online register of data structures and formats (Article 26), cooperate in good faith with the customer and the destination provider (Article 27), publish the jurisdiction their infrastructure is subject to (Article 28), limit and from 12 January 2027 abolish switching charges (Article 29), and meet the technical requirements of Article 30: functional equivalence for IaaS, open interfaces and interoperability specifications for PaaS and SaaS, and data export in a structured, commonly used, machine-readable format. Parallel use of several providers is treated separately (Article 34). Under Chapter VII they must also take technical, organisational and legal measures against unlawful third-country government access to non-personal data (Article 32). All of this has applied since 12 September 2025; unlike the unfair-terms rules of Chapter IV, Chapter VI has no transitional period for existing contracts (Article 50).
- Do existing cloud contracts have to be changed, and are there standard clauses?
- Yes. Article 25(1) requires the customer's switching rights and the provider's obligations to be clearly set out in a written contract made available before signature, and Article 25(2) prescribes the minimum content: the switching and porting clause with the 30-day transitional period, support for the customer's exit strategy, the termination clause, the maximum notice period of two months, an exhaustive list of portable data and digital assets, any trade secret exemptions, the retrieval period, the erasure clause and the switching charges. Because Chapter VI applies to all contracts since 12 September 2025, contracts concluded before that date must be brought into line as well; the Commission's FAQ lists bringing service contracts in line with Article 25 as the first compliance step for any in-scope provider. For the drafting, Article 41 tasked the Commission with non-binding standard contractual clauses, adopted on 19 November 2025 (Recommendation C(2025) 7750): SCC Switching & Exit, SCC Termination and SCC Security & Business Continuity translate Chapter VI into contract text, and SCC Non-Dispersion, SCC Non-Amendment and SCC Liability address the contractual imbalances that could undermine those rights. Their use is voluntary and they may be adapted, but a provider that deviates from them should be able to show that its own wording still meets Article 25.
- What happens after a customer exercises the switching right, and which periods apply?
- The sequence is fixed by Article 25. The customer notifies the provider of its decision to switch to another provider, to move to on-premises infrastructure or to erase its data (Article 25(3)). A notice period then runs which the contract may not set longer than two months (Article 25(2)(d)); the service contract remains in force throughout. After the notice period, the transitional period starts, in which the provider must complete the switch without undue delay and at the latest within 30 calendar days, assist the customer and its authorised third parties, maintain business continuity, flag known continuity risks and keep the data secure during transfer (Article 25(2)(a)). If 30 days are technically unfeasible, the provider must say so within 14 working days of the request, justify it and propose an alternative period of at most seven months, with service continuity guaranteed throughout (Article 25(4)); the customer may also extend the transitional period once for a period it considers appropriate (Article 25(5)). After the transitional period the customer has a retrieval period of at least 30 calendar days to fetch remaining data (Article 25(2)(g)); once it expires, or a later agreed date passes, the provider must fully erase the customer's exportable data and digital assets (Article 25(2)(h)). The contract terminates on successful completion of the switch, or at the end of the notice period where the customer only wants erasure (Article 25(2)(c)). Charges during the process follow Article 29: limited to cost now, none from 12 January 2027; the provider must also state in advance what the switching will involve and in which formats (Article 26).
- Who enforces the Data Act, and what are the penalties?
- Each Member State designates one or more competent authorities and, where there are several, a data coordinator as single point of contact (Article 37). Penalties are set nationally and must be effective, proportionate and dissuasive (Article 40); for infringements involving personal data, the data protection authorities can impose GDPR-level fines of up to EUR 20 million or 4% of worldwide annual turnover. Non-EU data holders and providers offering services in the EU must designate a legal representative in a Member State. National penalty frameworks differ between Member States and are still being completed in some; the applicable national law should be checked. In Germany the DADG has been in force since 30 May 2026 and designates the Bundesnetzagentur as competent authority and single point of contact, with the BfDI responsible for personal data.
- Are there model contracts for Data Act compliance?
- Yes. By Recommendation C(2025) 7750 of 19 November 2025 the Commission published non-binding model contractual terms for data access and use, covering the relationships between data holders, users and data recipients plus a template for voluntary data sharing, and six standard contractual clauses for cloud computing contracts covering switching and exit, termination, security and business continuity, non-dispersion, non-amendment and liability (Article 41). Both can be adapted to the parties' needs and are meant to support fair, reasonable and non-discriminatory terms; in practice they require tailoring to the specific service. Translations into all EU languages were announced to follow.
How to keep this straight
Work the Data Act like a Pro. Every article referenced above links straight into the consolidated text: read the Data Act on Lawbster with linked cross-references, one-click language switching and the official guidance documents collected on the act's page. For the wider regulatory wave, see the EU AI Act compliance timeline & FAQ, the EU Cyber Resilience Act timeline & FAQ, the EU Digital Services Act timeline & FAQ and the Lawbster manifesto.
Sources
- Regulation (EU) 2023/2854 (Data Act), consolidated text on Lawbster; official text on EUR-Lex.
- European Commission, Frequently Asked Questions about the Data Act, v1.4 (22 January 2026); non-binding.
- European Commission, Guidance on vehicle data accompanying the Data Act, C(2025) 6119 final (12 September 2025); non-binding.
- European Commission, Recommendation on model contractual terms and standard contractual clauses for cloud computing contracts, C(2025) 7750 (19 November 2025); non-binding.
- European Commission, draft guidelines on reasonable compensation under Article 9 (February 2026; consultation closed 20 February 2026).
- Bundesnetzagentur, press release of 30 May 2026 on the DADG and the Bundesnetzagentur Data Act hub.
- EDPB-EDPS Joint Opinion 2/2022 on the Data Act proposal (4 May 2022).