How to Respond to an EU Data Act Data Access Request
A plain-English playbook for handling an EU Data Act access or sharing request, from verifying the requester and the deadlines to trade secrets and what not to say.
Sooner or later it lands in your inbox: a customer, or a vendor acting on a customer's behalf, quoting the EU Data Act and asking for "all readily available data" your product generated for them. The rights behind that email have been applicable since 12 September 2025, so the request is probably not a bluff. What matters now is responding in a way that keeps you compliant without giving away more than the law requires.
Here is a practical walkthrough of what to do in the first days after a request arrives.
Step 1: Work out which right is being invoked
Not every "give us the data" email is the same request. The Data Act contains several distinct rights, and your obligations differ depending on which one applies.
A request under Article 4 comes from the user of a connected product or related service and asks for the data the product generated for them. A request under Article 5 also comes from the user, but asks you to share that data with a third party of their choice, which can include your competitor. A request under the cloud switching chapter, often citing Article 25, comes from a customer who wants to move to another provider and expects your cooperation with the transition, including an export of their exportable data.
Read the email carefully and identify which situation you are in. If the request does not say, it is legitimate to ask the requester to clarify what they want and in what capacity they are asking.
Step 2: Verify the requester
You are expected to hand data to the user or to a third party the user has actually authorised, not to anyone who emails your support address. Confirming that the requester is your customer, or holds a mandate from your customer, is a reasonable and prudent step. What you should not do is turn verification into a delay tactic. A proportionate identity check is fine; a six-week "security review" before you even acknowledge the request is likely to look like obstruction.
Step 3: Respect the clock
The Data Act does not give you a comfortable statutory quarter to think it over. Access under Articles 4 and 5 is expected to happen without undue delay, and where the product was placed on the EU market from 12 September 2026 the data should increasingly be accessible directly, by design, without a request at all. For switching, the timelines are concrete: notice periods for the customer are capped at a maximum of two months, and the transition itself is built around a 30 day window. If a new vendor is quoting Article 25 at you, assume the clock is already running.
Step 4: Handle trade secrets properly
Trade secrets are the most misunderstood defence in this area. The Data Act does not let you refuse a request with a blanket "that data is proprietary". If you believe specific data points would reveal a trade secret, you are expected to identify the specific secrets concerned and agree proportionate protection measures with the requester, such as confidentiality commitments or technical safeguards. Refusal is reserved for exceptional situations, and even then it needs to be reasoned and documented. A one-line rejection is the response most likely to end up in front of a regulator.
Step 5: Deliver in a usable format, and keep receipts
Data handed over under the Data Act is expected to be comprehensive, machine-readable and, where relevant, of the same quality you enjoy yourself. A PDF screenshot of a dashboard rarely meets that bar; a structured export usually does. Whatever you provide, document it: the request, your verification, what you delivered, when, and in what format. Enforcement in this area is national, and the authorities are no longer hypothetical. Germany's implementation act, the DADG, has been in force since 30 May 2026, with the Bundesnetzagentur able to impose tiered fines of up to EUR 500,000, and GDPR-level fines of up to 4% of turnover remain possible where personal data is involved.
What not to do
Do not ignore the email. Do not answer with your standard "we take data seriously" template. Do not charge the user for their own data under Article 4, and do not quietly point the requester at a paid API tier as the only route. And do not assume the pending Digital Omnibus proposals will rescue you: the ideas being discussed in Brussels, such as legacy contract exemptions and SME relief, are not law yet, and the rights described above apply today.
Get ahead of the next request
The easiest access request is the one your product already answers by design: an export endpoint, documented formats, and contract terms that anticipate switching. If you want to know how ready you are before the next email arrives, the free readiness assessment at [dataactready.org](https://www.dataactready.org) takes about three minutes, runs entirely in your browser, and maps your gaps to the exact articles a requester is likely to quote at you.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.