The New European Data Act – What UK Businesses Need to Know

30th September 2025

The EU Data Act (Regulation (EU) 2023/2854) came into force in January 2024 and will take full effect from September 2025. It represents one of the most significant shifts in European digital regulation, alongside the EU AI Act and the Data Governance Act, as part of a broader digital strategy. But what is this new act and how will it affect UK organisations?

What is the EU Data Act?

The EU Data Act is a new regulation that sets standards for the use and sharing of personal data within the EU. It aims to create a fairer, more competitive European data economy by ensuring businesses and consumers alike can unlock value from the data they generate. Unlike the EU Data Governance Act, which focuses on voluntary data sharing and trusted intermediaries, the Data Act establishes rights and obligations. It ensures that users can access the data generated by their products and that this data can be shared with third parties under fair, reasonable, and non-discriminatory (FRAND) conditions.

Data generated by connected devices, from industrial machinery to consumer IoT products, has traditionally been locked within the systems of manufacturers or service providers. The Data Act changes this dynamic by granting rights to businesses and consumers. The Act states that data holders must share data with third parties, subject to FRAND terms. It also prevents unfair contractual terms imposed by larger players and allows public sector access to private data in emergency cases (e.g., natural disasters).

The Aims of the EU Data Act

The EU Data Act aims to create a fairer data economy within the EU by unlocking access to the vast amounts of personal and non-personal information generated by connected products, services, and industrial devices. At its core, the regulation is designed to reduce imbalances between powerful data holders, such as manufacturers or large service providers, and the individuals or businesses that generate the data in the first place. By giving users clear rights to access and share their data, requiring that third parties be granted access on fair, reasonable, and non-discriminatory (FRAND) terms, and preventing unfair contractual practices, the Act promotes competition and innovation. It also seeks to strengthen resilience and public interest, allowing governments to request data during emergencies. 

Until now, a lot of the data generated by connected devices and digital services has been locked away by manufacturers and service providers, leaving users and smaller businesses with little control or ability to benefit from it. This imbalance creates barriers to innovation, reinforces the dominance of larger players, and limits competition across the digital economy. By introducing rules for fair access and use of data, the Act helps to level the playing field.

Key Provisions of the EU Data Act

The regulation introduces several core provisions that businesses need to be aware of. It applies broadly to data generated in the EU, covering both personal data (alongside existing GDPR obligations) and non-personal data. Here is a brief summary of the main provisions of the Act:

Scope and Coverage

  • Applies to data generated in the EU by connected products, services, and industrial devices.
  • Covers both non-personal and certain personal data (where GDPR also applies).

User Rights

  • Individuals and businesses gain the right to access and use the data generated by their own devices.
  • Data must be made available in a transparent, accessible, and secure way.

Third-Party Access

  • Data holders must share data with third parties under fair, reasonable, and non-discriminatory (FRAND) conditions.
  • Prevents larger players from imposing unfair contract terms.

Cloud and Portability

  • Strengthens data portability rights, reducing vendor lock-in.
  • Requires cloud service providers to enable easy switching between services.

Public Sector Use

  • Allows public bodies to request access to private-sector data in cases of public emergencies (e.g. natural disasters, pandemics).

International Safeguards

  • Places restrictions on sensitive data transfers outside the EU to protect competitiveness and security.

Enforcement and Penalties

  • Enforced by national regulators across member states.
  • Non-compliance can result in GDPR-level fines (up to 4% of global turnover).

How Does It Compare to UK Law?

There is currently no equivalent of the EU Data Act in UK law at the moment, although proposals are being considered. The Department for Science, Innovation and Technology ran a consultation into Smart Data schemes that could help foster innovation and competition. Any upcoming new regulations as a result of this will likely rely on powers granted by the Data (Use and Access) Act 2025, as well as other existing UK data legislation.

What UK Businesses Should Do

If your business operates within the EU, then your activities could fall within the scope of the EU Data Act, especially if you handle connected products, IoT services or cloud infrastructure. Here are some steps you can take to reduce any disruptions or compliance risks.

  • Map your data flows to identify which products, services or operations generate data within the EU, and determine what types of data you hold and how they are currently accessed or shared. 
  • Audit any existing customer or supplier contracts to ensure they comply with the Act’s requirements for fair, reasonable, and non-discriminatory (FRAND) terms.
  • Update agreements to ensure users can access their data and share it with third parties.
  • Enable portability and interoperability that will allow users to easily port their data between providers and work with IT teams or vendors to prepare for cloud switching obligations.
  • Establish processes for handling requests from EU public authorities in emergencies, ensuring data sharing mechanisms are secure, transparent, and compliant with other UK and EU laws.
  • If you transfer data outside of the EU, review whether these transfers could be restricted under the Act and put safeguards in place where necessary.
  • Train staff on new obligations and integrate Data Act compliance into your wider data governance framework alongside GDPR.

By acting early, UK businesses can reduce compliance risks, avoid disruption when the Act is enforced from September 2025, and position themselves competitively in a more open and innovative European data market.

The EU Data Act marks a major change in how data is accessed, shared, and governed across Europe, and businesses that prepare now will be best placed to stay compliant and competitive. If you’re unsure how the new rules affect your organisation or need support reviewing your contracts, data flows, or compliance processes, our team can help. Get in touch with us here at Griffin House Consultancy today for tailored guidance and practical steps to make sure your business is ready.

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Sources:

Legislation

Lewis Silkin

Bird & Bird

European Commission

Eversheds Sutherland

UK Government 

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details