How the EU Data Act applies to smart building equipment such as HVAC systems, elevators, access control and energy management platforms, and what the key deadlines mean in practice.
How users can send connected product data to repair shops, insurers and analytics providers under Article 5, and what data holders must do when such a request arrives.
How the EU Data Act applies to smart meters, EV charging stations, heat pumps and solar inverters, and what energy companies and installers can now demand.
Product data, related service data, metadata, and what falls outside: a plain-English guide to which data the EU Data Act's access and sharing rules reach.
User, data holder, data recipient, third party: what each role means under the EU Data Act, how to work out which one you are, and what obligations follow.
How the EU Data Act applies to tractors, harvesters and precision farming equipment, what data farmers can now request, and what manufacturers need to prepare.
What the EU Data Act means for smartwatches, fitness bands and other wearables, which data users can request, and how the rules interact with the GDPR.
Connected glucose monitors, CPAP machines, hearing aids and fitness wearables generate valuable data. Here is what the EU Data Act expects from their makers.
Article 36 of the EU Data Act sets essential requirements for smart contracts used in data sharing, including a kill switch, access controls and robustness.
When data must be free, when you can charge, and what counts as reasonable compensation under the EU Data Act, explained for founders without legalese.
A plain-English playbook for handling an EU Data Act access or sharing request, from verifying the requester and the deadlines to trade secrets and what not to say.
The EU's Digital Omnibus package proposes real changes to the Data Act: legacy contract exemptions, early termination penalties, SME relief and stronger trade secret defences. None of it is law yet, and the 12 January 2027 egress ban is untouched.
Germany's Data Act Implementation Act (DADG) is in force since 30 May 2026. Here is who enforces, what the real fine amounts are, and why the 4% figure only applies in one lane.
Modern cars generate torrents of data, and the EU Data Act hands drivers, fleets and repair shops new rights to it. What carmakers, fleet operators and automotive software companies need to know.
The European Commission has been rolling out non-binding model contractual terms for data access and standard clauses for cloud switching. What these templates are, what they are not, and how to use them.
The Data Act phases out charges for switching cloud providers, including egress fees in a switching context, by 12 January 2027. What the ban covers, what it probably does not, and how to prepare.
The Data Act's least-discussed chapter lets public bodies demand data from companies in exceptional circumstances such as floods, fires and public emergencies. Who can ask, what they can ask for, and what to prepare.
The Data Act's unfair-terms rules have applied to new contracts since September 2025. From 12 September 2027 they are set to reach long-term contracts signed years earlier. What survives, what does not, and how to audit before the date.
Micro and small enterprises get a real carve-out from the Data Act's data-sharing chapter, but not from cloud switching. Where the exemption applies, where it quietly ends, and the traps inside it.
From 12 September 2026, connected products placed on the EU market must make product data directly and easily accessible to users by default. What that means in engineering terms.
Maximum two months' notice, a 30-day transition, machine-readable export, and switching fees on the way out. What Chapter VI of the Data Act demands from SaaS and cloud contracts.
The Data Act lets users demand product data even when trade secrets are involved. Blanket refusals are non-compliant, the law requires identification, protection measures, and narrow exceptions.
Most SaaS founders assume the EU Data Act is an IoT law. In many cases it reaches SaaS too, through cloud switching rules, unfair contract terms and related services.
Data Act compliance for a typical SaaS or device company condenses into five concrete deliverables. Here is the checklist, in build order, with what each document must contain.
The Data Act did not arrive on one date. Applicable since 12 September 2025, access-by-design from 12 September 2026, egress fees banned January 2027, legacy contracts caught in September 2027.
Data Act penalties are set nationally. Germany's implementation act gives the Bundesnetzagentur tiered fines of up to EUR 500,000, and personal-data infringements can reach GDPR levels. Here is how the enforcement map is forming.
Connected-product makers carry the heaviest Data Act load: access by design, user data-sharing rights, third-party sharing, transparency duties. A practical map for hardware teams.
The Data Act follows the product and the customer, not the vendor's incorporation. What US and other non-EU companies actually need to do, and what they can skip.
GDPR protects people's personal data. The Data Act governs product and service data as an economic asset. Different scope, different regulator, different fines, and you need both.
The Data Act makes certain unilaterally imposed data terms unenforceable against smaller businesses. The blacklist, the grey list, and why pre-2024 MSAs deserve an audit.
The Data Act's scope turns on two definitions. Vehicles, machines and wearables are in; your phone's apps mostly are not; and 'related service' is broader than developers expect.
Not sure which rules apply to you?
Run the free 3-minute readiness assessment and get a scored gap report for your specific product.