Who Is a Data Holder Under the EU Data Act? Roles Explained
User, data holder, data recipient, third party: what each role means under the EU Data Act, how to work out which one you are, and what obligations follow.
Most of the EU Data Act's obligations attach to a single label: the data holder. If that label fits your company, you owe users data access, you must answer sharing requests, and your contracts have to say so. If it does not fit, much of the law simply is not addressed to you. Yet many founders reading about the Data Act skip past the definitions and jump straight to the deadlines, then discover halfway through a compliance project that they never checked which role they actually play. This guide walks through the cast of characters in plain English.
The four roles in one paragraph
The Data Act, applicable since 12 September 2025, is built around four roles. The user is whoever owns, rents or leases a connected product, or receives a related service; it can be a person or a company. The data holder is the party entitled or obliged to make product or related service data available, in practice usually the manufacturer or the service provider that controls the data. The data recipient is a party, acting for professional purposes, that receives data at the user's request. A third party is anyone the user tells the data holder to send data to, such as a repair shop, an insurer or a competitor's platform. One company can wear different hats in different relationships, sometimes on the same day.
How to tell if you are a data holder
Ask two questions. First, does your product or service generate data through its use, and do you have the practical ability to access that data? Second, are you the one who decides what happens to it? If you manufacture a connected device that phones home to your cloud, you are almost certainly a data holder for that device's data. If you run a related service, such as the companion app that a device needs to function, the same is expected to apply. Being a data holder is not about company size or where you are established: a US manufacturer selling connected products into the EU can be a data holder for its EU users' data, and small and micro enterprises benefit from certain exemptions in Chapter II but should verify them rather than assume them.
Importantly, you can be a data holder without ever having thought of yourself as a data company. A maker of coffee machines, forklifts or HVAC systems that added connectivity for diagnostics now holds product data within the meaning of the Act.
What the data holder role obliges you to do
The core duty is making data available. Since September 2025, users can request readily available product and related service data, free of charge, in a comprehensive, structured, commonly used and machine-readable format. Where a user asks, the data holder must also make that data available to a third party of the user's choosing, on fair, reasonable and non-discriminatory terms. For products placed on the EU market since 12 September 2026, the access-by-design obligation applies on top: new units are expected to ship so that users can reach their data directly where technically feasible, without begging support for an export.
Data holders also carry contract duties. Agreements about data access cannot quietly undo the user's rights, and unilaterally imposed unfair terms in B2B data contracts can be void under Article 13. From 12 September 2027 those fairness rules are expected to reach older contracts still in force, so legacy paperwork is not grandfathered forever.
Data recipients and third parties have rules too
Receiving data is not a free-for-all. A third party that gets data at the user's request may only use it for the agreed purpose, must delete it when that purpose is fulfilled, and cannot use it to profile people or to develop a competing connected product. Data recipients that break these rules can face enforcement in their own right. If your growth plan involves pulling competitor device data via user requests, the Act both enables the request and fences in what you may do with the result.
Why the label matters for enforcement
Enforcement runs through national authorities, and the role you play determines which duties they measure you against. Germany's implementation act, the DADG, has been in force since 30 May 2026, with the Bundesnetzagentur enforcing through tiered fines of up to EUR 500,000 per violation category; where personal data is involved, fines can reach GDPR levels of up to 4% of worldwide turnover, but only in those cases. Other member states are expected to follow their own schemes. Arguing about whether you were really the data holder is a poor position to be in after a complaint lands.
One caveat: Brussels is currently debating the Digital Omnibus, a package that proposes softening parts of the Data Act, including relief for smaller companies. Those proposals are not law yet, so the roles and duties described here remain the ones that apply today.
Work out your role in three minutes
The fastest way to know which hat you wear, and which obligations follow, is to run our free readiness assessment at [dataactready.org](https://www.dataactready.org). It asks a handful of plain-English scope questions, tells you whether you look like a data holder, a recipient or both, and maps your gaps to the exact articles that apply. No signup, and everything runs in your browser.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.