DataAct Ready

EU Data Act guides ·

EU Data Act vs Data Governance Act: What Is the Difference?

The Data Act and the Data Governance Act sound similar but do very different jobs. Here is which one applies to you, in plain English.

The EU now has two major data laws with confusingly similar names: the Data Act and the Data Governance Act (DGA). Companies regularly mix them up, and it matters, because they impose very different obligations on very different actors. The short version: the Data Act tells you what you must do with the data your connected products and cloud services generate, while the DGA mostly regulates a narrower group of players, such as data intermediaries and organisations reusing public sector data. Most companies are squarely in scope of the Data Act and only lightly touched, if at all, by the DGA.

Two laws, two jobs

The Data Governance Act came first. It has applied since 24 September 2023 and is best understood as plumbing for data sharing: it sets conditions for reusing certain protected public sector data, creates a regulatory regime for "data intermediation services" (neutral marketplaces and brokers that connect data holders with data users), and establishes a framework for "data altruism", where individuals and companies donate data for the common good.

The Data Act is the broader, heavier instrument. It has applied since 12 September 2025 and creates direct rights and obligations around the data generated by connected products and related services: users can access that data and share it with third parties, cloud providers must make switching easier, unfair data clauses in contracts can be void, and public bodies can demand data in emergencies. Since 12 September 2026 it has also required that new connected products be designed for direct data access, the so-called access by design obligation.

Who each law actually touches

If you manufacture connected devices, run a related service or app for such devices, or offer cloud or edge services in the EU, the Data Act applies to you. Its obligations run on a timeline that is still unfolding: switching charges for cloud services are expected to be withdrawn entirely by 12 January 2027, and from 12 September 2027 the core access and sharing rules are expected to reach certain legacy contracts for products placed on the market before September 2025.

The DGA, by contrast, mostly matters if you are one of three things. First, a public sector body holding protected data that others want to reuse. Second, a data intermediation provider, which must notify the competent national authority and follow strict neutrality rules, including not using the data it brokers for its own purposes. Third, a data altruism organisation seeking registration. An ordinary SaaS company or device maker is typically none of these.

Where the two laws meet

The laws are designed to work together. When a user exercises their Data Act right to share device data with a third party, a DGA-regulated data intermediary may be the vehicle that makes the sharing workable at scale. The European Commission has also promoted common European data spaces, where DGA governance structures and Data Act access rights are expected to reinforce each other. In practice, the Data Act supplies the rights to data, and the DGA supplies trusted middlemen and reuse rules.

Neither law overrides the GDPR. Where the data involved is personal data, GDPR obligations apply on top of both, and that has enforcement consequences described below.

Enforcement looks very different

DGA enforcement has so far been quiet, focused on registration and notification of intermediaries. Data Act enforcement is becoming concrete. Each member state designates its own competent authority and sets its own penalties. Germany is the most developed example: its implementation act, the DADG, has been in force since 30 May 2026 and hands enforcement to the Bundesnetzagentur, with tiered fines of up to EUR 500,000 depending on the violation. Where personal data is involved, Article 40(4) of the Data Act points to GDPR-level fines of up to 4 percent of global annual turnover. In other words, the 4 percent exposure is not the default Data Act fine, it is the ceiling where the personal data dimension is engaged.

Does the Digital Omnibus change any of this?

The European Commission's Digital Omnibus proposals would soften parts of the Data Act, including possible exemptions for legacy contracts, changes to early termination penalties and additional relief for SMEs. These are proposals, not law. Until the legislative process concludes, the Data Act's current text and deadlines remain the ones to plan against, and the DGA is not expected to change materially either way.

Which one should be on your compliance roadmap?

For most companies the practical answer is simple: the Data Act. Unless you operate a data marketplace, run a data altruism scheme or manage public sector data, the DGA imposes little on you directly, while the Data Act likely already applies to your products, contracts and cloud arrangements today. If you want a quick, structured read on where you stand, the free readiness assessment at [dataactready.org](https://www.dataactready.org) walks you through the questions that matter, from access by design to contract clauses, and shows you where the gaps are in a few minutes.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.