DataAct Ready

EU Data Act guides ·

EU Data Act vs GDPR: What Is Actually Different?

GDPR protects people's personal data. The Data Act governs product and service data as an economic asset. Different scope, different regulator, different fines, and you need both.

Founders keep asking whether Data Act compliance is covered by the GDPR work they already did. It is not: the two laws answer different questions.

What each law is about

GDPR answers: how must personal data about people be handled? It is a fundamental-rights law about privacy.

The Data Act answers: who gets to use and share the data that products and services generate, and on what commercial terms? It is a market-power law about access, portability and fair contracts. Most of the data it covers, machine telemetry, sensor readings, usage logs, may not be personal data at all.

Where they overlap

Connected-product data is often mixed: a vehicle's location trace is both product data (Data Act) and personal data (GDPR). The Data Act explicitly leaves the GDPR intact: where data is personal, GDPR rules still apply on top. In practice that means a data-access request under the Data Act may also need a GDPR lawful basis before you hand data to a third party.

Key differences at a glance

  • Subject matter: GDPR, personal data; Data Act, product, related-service and cloud data, personal or not.
  • Beneficiaries: GDPR protects natural persons; the Data Act gives rights to users, including businesses.
  • Portability: GDPR Article 20 is a limited right for individuals; the Data Act makes access and sharing a design requirement and a contractual duty, including business-to-business.
  • Contracts: GDPR barely touches commercial terms; the Data Act voids unfair unilaterally imposed data clauses and caps cloud-switching terms.
  • Regulators: GDPR, data protection authorities; Data Act, separately designated national authorities (in Germany, the Bundesnetzagentur).
  • Fines: GDPR, up to 4% of global turnover; Data Act, set nationally (Germany: tiered fines of up to EUR 500,000), though personal-data infringements can draw GDPR-level fines through data protection authorities.

Why "our DPO handles it" is risky

GDPR programmes are built around privacy: minimisation, lawful bases, DPIAs. Data Act obligations are built around availability: export formats, switching timelines, access-by-design engineering, contract clauses. A company can be exemplary on GDPR and have literally none of the Data Act deliverables in place, no switching addendum, no export documentation, no access policy.

The efficient way to run both

Treat GDPR as your privacy layer and the Data Act as your data-commerce layer. Reuse your data inventory (you mapped data flows for GDPR anyway), then run a Data-Act-specific gap check on contracts, export capability and product design. Our free assessment does that second part in about three minutes.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.