Article 13: When Your Contract's Data Clauses Are Simply Void
The Data Act makes certain unilaterally imposed data terms unenforceable against smaller businesses. The blacklist, the grey list, and why pre-2024 MSAs deserve an audit.
Article 13 of the Data Act is the provision most likely to surprise a SaaS founder in a dispute: it does not fine you for an unfair data clause: it deletes the clause.
The mechanism
Where a contract term about data access, use, liability or remedies is unilaterally imposed by one enterprise on another (classically: a standard-form MSA presented take-it-or-leave-it to a smaller customer), and the term is unfair within the meaning of Article 13, the term is not binding. The rest of the contract survives; the offending clause is treated as if it were not there. A court or arbitrator applies this directly.
The blacklist (always unfair)
Terms are unfair per se if, for example, they:
- exclude or limit your liability for intentional acts or gross negligence,
- exclude the other party's remedies for your non-performance,
- give you the exclusive right to determine whether the data supplied conforms to the contract, or to interpret any term of the contract.
The grey list (presumed unfair)
Terms are presumed unfair if, among others, they:
- inappropriately limit remedies for non-performance or liability for breach,
- allow you to access and use the other party's data in a way significantly detrimental to their legitimate interests,
- prevent the other party from using data they contributed or generated during the contract,
- prevent termination on reasonable notice, or
- allow you to change essential terms unilaterally without a valid reason and notice.
If your standard terms were drafted before 2024 and touch data, at least one grey-list pattern is very often present.
Timing
The regime has applied to new contracts since 12 September 2025, and from 12 September 2027 it is set to reach certain older long-term contracts too. Legacy paper does not stay safe indefinitely.
What to do about it
- Pull your standard MSA and DPA.
- Screen every data-related clause against the blacklist and grey list.
- Redraft the failures, usually toward mutuality: shared data-use rights, balanced liability, reasonable termination.
This is a bounded, checklist-driven exercise, not an open-ended legal project. The compliance pack includes an unfair-terms audit checklist mapped to Article 13 that a founder can run against their own contract in an afternoon, before spending counsel hours on the redraft. The free assessment will tell you first whether Article 13 is even in scope for you.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.