DataAct Ready

EU Data Act guides ·

Data Act Fines and Enforcement: Who Can Punish You, and How Hard?

Data Act penalties are set nationally. Germany's implementation act gives the Bundesnetzagentur tiered fines of up to EUR 500,000, and personal-data infringements can reach GDPR levels. Here is how the enforcement map is forming.

The Data Act does not have one EU-wide fine schedule the way people imagine. It delegates enforcement to the member states, which makes the picture messier, and in some countries sharper, than GDPR's.

The structure

Each member state designates one or more competent authorities and lays down penalty rules, which must be effective, proportionate and dissuasive. Where personal data is involved, data protection authorities can also apply GDPR-level fines, up to 4% of global annual turnover, for infringements of the Data Act's data-sharing provisions in their lane.

Germany moved first and loudest

Germany's Data Act Implementation Act (DADG) entered into force on 30 May 2026, making the Bundesnetzagentur (Federal Network Agency) the central Data Act authority. The final law sets tiered fines of up to EUR 500,000, lower than the percent-of-turnover figures floated in earlier drafts, but a fine can exceed that cap to claw back economic benefits gained from a violation, and the GDPR-level exposure above still applies where personal data is involved. Other member states are at various stages of designating authorities and setting penalties; the pattern so far rhymes with how GDPR enforcement built up, slowly, then suddenly.

Enforcement is not only fines

Three quieter mechanisms will likely bite earlier than headline penalties:

  • Private enforcement: Article 13 voids unfair contract terms directly, your customer's lawyer invokes it in a dispute, no regulator needed.
  • Customer rights requests: a user demanding their product data, or a business customer invoking switching rights, creates an immediate compliance test with a paper trail.
  • Procurement and due diligence: enterprise buyers and investors have started asking Data Act questions in security reviews, the way they ask about GDPR and SOC 2.

"We didn't know" as a strategy

The regulation has been applicable since 12 September 2025 and the access-by-design duty since 12 September 2026. Regulators historically show little patience for unawareness after a law's second year, and none after they publish guidance. The cheap window is now, while enforcement teams are still staffing up and voluntary compliance reads as good faith.

The proportionate response

Nobody is suggesting a small SaaS needs a GDPR-scale programme. The Data Act deliverables are finite: scoping, a switching addendum, an access policy, export documentation, a contract audit, and for device makers an access-by-design review. Run our free three-minute assessment to see which of those apply to you, and you will know the actual size of your exposure instead of the imagined one.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.