DataAct Ready

EU Data Act guides ·

Interoperability Requirements Under the EU Data Act, Explained in Plain English

Articles 33 to 36 quietly turn interoperability from a nice-to-have into a legal expectation, for data space participants and cloud providers alike. What the requirements actually say, who they catch, and what to do about them now.

Most coverage of the EU Data Act focuses on the headline items: users getting access to device data, cloud customers getting exit rights. The interoperability chapter gets far less attention, partly because it reads like plumbing. But if you sell data, participate in a data space, or run a cloud or SaaS product for EU customers, the plumbing is aimed at you, and the deadlines attached to the rest of the Act are already pulling it into force.

Where the interoperability duties come from

The Data Act has been applicable since 12 September 2025, and its interoperability provisions sit mainly in Articles 33 to 36. They fall into two broad groups. The first targets participants in so-called common European data spaces and, more generally, anyone making data available under the Act: data has to be described well enough that a recipient can actually find it and use it. The second targets providers of data processing services, meaning cloud and SaaS, and links directly to the switching regime: a customer's data and, where feasible, their workloads are expected to move to another provider or to on-premise systems without being trapped by proprietary formats.

What data holders are expected to do

For data holders, the core expectation is machine-readability plus documentation. The dataset's content, structure, format, licensing conditions and access methods are expected to be described sufficiently so that a recipient can identify what the data is and work with it. In practice that points to documented schemas, data dictionaries, and APIs with published descriptions rather than ad hoc CSV exports explained over email. None of this requires exotic technology. It requires the kind of documentation discipline that many engineering teams already aspire to and few maintain.

This matters more than it first appears because of how it interacts with the access rights. Since 12 September 2026, connected products placed on the EU market are expected to meet access-by-design expectations, with product data accessible to users easily and, where relevant and technically feasible, directly. An access right that delivers an undocumented binary blob arguably defeats the purpose, so the interoperability expectations are best read as the quality bar for the access rights, not a separate project.

What cloud and SaaS providers are expected to do

For data processing services, interoperability is the technical half of the switching regime. Providers are expected to make exportable data available in a structured, commonly used and machine-readable format, and open interfaces are expected to be available to support switching and, for some service types, in-parallel use of multiple providers. The commercial half is on its own clock: switching charges are expected to be withdrawn from 12 January 2027, which removes the pricing lever some providers might otherwise use to make a technically possible exit economically unattractive.

The European Commission can also request harmonised standards for interoperability and, where standards are missing, adopt common specifications. The practical consequence is that "our format is proprietary, sorry" is expected to become steadily harder to defend over time, because a reference standard you declined to follow is a worse position than no standard existing at all.

Who enforces this, and with what

Enforcement is national. Germany moved early: its implementation act, the DADG, has been in force since 30 May 2026, with the Bundesnetzagentur as the lead authority and tiered fines of up to EUR 500,000 for Data Act violations. Where personal data is involved, GDPR-level fines of up to 4% of worldwide annual turnover can come into play under Article 40(4), but that is the personal-data lane, not the general rule. Other Member States are at varying stages, so exposure depends on where your customers and supervisors sit.

One caveat worth knowing: the Commission's Digital Omnibus package proposes softening parts of the Data Act, including relief for smaller companies. Those proposals are not law yet, and interoperability has not been the focus of the softening in any case, so building against the current text remains the sensible baseline.

A realistic to-do list

Treat interoperability as documentation work first and engineering work second. Inventory the data you hold or expose, write down its formats and schemas, and check whether a competent outsider could consume it from your docs alone. If you run SaaS, test your own export: take the output and try to reconstruct a working dataset somewhere else. If your own team cannot do it in an afternoon, a switching customer cannot do it in the 30-day transition window the Act contemplates, and that gap is now a legal problem rather than a quality complaint.

If you are unsure which of these duties apply to your product at all, our free readiness assessment walks through your role under the Data Act and shows which obligations, including the interoperability expectations, actually land on you.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.