DataAct Ready

EU Data Act guides ·

US Company, EU Customers: Yes, the Data Act Reaches You

The Data Act follows the product and the customer, not the vendor's incorporation. What US and other non-EU companies actually need to do, and what they can skip.

"We're a Delaware company, EU regulations are Europe's problem" did not survive contact with the GDPR, and it does not survive the Data Act either.

Why the law reaches across the Atlantic

The Data Act applies to manufacturers of connected products placed on the market in the EU and to providers of related services and data processing services offered to customers in the EU, wherever the provider is established. The trigger is the market, not the headquarters. One paying customer in Berlin puts the relevant chapter on your desk. Non-EU manufacturers and providers in scope are also expected to appoint a legal representative in the EU, mirroring the GDPR Article 27 pattern.

What is in scope for a typical US SaaS

  • The cloud-switching chapter: your EU customers get the mandatory exit rights, two months' maximum notice, 30-day transition, machine-readable export, switching charges falling away by January 2027. Your standard MSA almost certainly needs an EU-facing addendum.
  • Article 13 unfair terms: standard-form data clauses unilaterally imposed on smaller EU business customers can be void. US-drafted liability and data-use boilerplate is a frequent offender.
  • If you touch devices, a companion app, telemetry from customer hardware, an IoT platform, the connected-product and related-service duties come in on top.

What you can usually skip

If you sell no hardware and act purely as a cloud/SaaS provider, the access-by-design engineering duty is not your chapter, that one binds product manufacturers. Scoping first stops you from over-complying: a real portion of panicked Data Act spending is companies doing work the law never asked of them.

The pragmatic US playbook

  1. Confirm scope honestly: list EU revenue, EU users, device touchpoints.
  2. Fix the contract: an EU switching addendum plus an Article 13 screen of your standard terms.
  3. Build or document the export path for customer data.
  4. Decide on an EU representative if you are in scope for that duty.
  5. Write it down, regulators and enterprise buyers both respond well to a documented position, even one with dated remediation plans in it.

Our free assessment was built exactly for this scoping step: three minutes of questions, a readiness score, and a list of which obligations apply to your specific setup, before you spend a dollar on counsel.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.