DataAct Ready

EU Data Act guides ·

Smart Contract Requirements Under the EU Data Act Explained

Article 36 of the EU Data Act sets essential requirements for smart contracts used in data sharing, including a kill switch, access controls and robustness.

Buried near the end of the EU Data Act is a provision that caused more debate in the blockchain world than almost anything else in the regulation: Article 36 on smart contracts. If your company uses automated, code-based agreements to execute data sharing, this article sets essential requirements those programs are expected to meet. The Data Act has been applicable since 12 September 2025, so these rules are not on the horizon. They are already here.

What the Data Act means by a smart contract

The Data Act defines a smart contract as a computer program used for the automated execution of an agreement, or part of one, using a sequence of electronic data records and ensuring their integrity and the accuracy of their chronological ordering. That definition is technology-neutral on its face, but it clearly captures blockchain-based contracts as well as some other forms of automated agreement logic.

Importantly, the scope is narrower than many early commentaries suggested. Article 36 applies to smart contracts used to execute data sharing agreements within the scope of the Data Act, such as making data available to a user or a third party. A DeFi protocol or an NFT marketplace that has nothing to do with Data Act data sharing is generally not expected to be caught, although the exact boundaries are still being worked out in practice.

The essential requirements

Vendors of smart contract applications for data sharing, or those who deploy them in the course of a commercial activity, are expected to ensure the contract meets several essential requirements.

Robustness and access control come first. The smart contract should be designed to avoid functional errors and to withstand manipulation by third parties, with rigorous access control mechanisms at both the governance and the smart contract layer.

The most discussed requirement is safe termination and interruption, often called the kill switch. There must be a mechanism to terminate the continued execution of transactions, through internal functions that can reset the contract or instruct it to stop. This sits uneasily with the immutability that many blockchain designs treat as a core feature, and it is the main reason Article 36 attracted criticism from the sector.

Data archiving and auditability are also required. If a smart contract must be terminated or deactivated, there should be a way to archive the transactional data and the contract's logic and code, so what happened can be audited later. Finally, the access control mechanisms themselves should be protected consistently.

Who is responsible, and what conformity looks like

The obligations fall on the vendor of the smart contract application or, where no vendor exists in the picture, on the person deploying the smart contract for a data sharing agreement in a commercial context. The vendor performs a conformity assessment against the essential requirements and issues an EU declaration of conformity, taking responsibility for compliance. Harmonised standards are expected to be developed to make this assessment more concrete, and following them will create a presumption of conformity.

Enforcement and penalties

As with the rest of the Data Act, enforcement is handled by national authorities. Germany's implementation act, the DADG, has been in force since 30 May 2026, with the Bundesnetzagentur as the enforcing authority and tiered fines of up to EUR 500,000. Where personal data flows through the arrangement, GDPR-level fines of up to 4 percent of annual worldwide turnover can apply under Article 40(4). Other member states have their own regimes at varying stages of readiness, so the practical enforcement risk depends on where you operate.

It is also worth knowing that the Digital Omnibus package proposes to soften several parts of the Data Act. Those proposals are not law yet, and none of the published drafts would remove the smart contract requirements outright, so building against Article 36 as it stands remains the prudent course.

Practical steps for teams using smart contracts

If automated agreements execute any part of your data sharing, start with an inventory: which contracts touch data covered by the Data Act? For those that do, check whether a termination mechanism exists, whether access controls are documented at both governance and contract level, and whether you can archive state and code if a contract is shut down. If you buy smart contract tooling from a vendor, ask for their EU declaration of conformity.

Smart contracts are only one corner of the Data Act, and most companies have bigger gaps elsewhere, from access request handling to contract terms. Our free readiness assessment covers the full set of obligations and shows you, in a few minutes, which ones apply to your business and where to focus first.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.