As the EU Data Act becomes applicable in September 2025, understanding its enforcement structure and penalties mechanism is critical for compliance planning. Unlike centralised regimes like the GDPR, the Data Act delegates primary enforcement to individual EU member states.
Each member state must designate a competent authority (or several) to oversee implementation, and, if more than one is appointed, additionally assign a data coordinator to facilitate cross-agency collaboration. For personal data matters, existing national data protection authorities will remain active, alongside EU-level bodies such as the European Data Protection Supervisor (EDPS) and the European Data Innovation Board (EDIB).
One innovative feature of the legislation is the introduction of dispute settlement bodies (Article 10), designed to resolve B2B data sharing disputes, particularly around FRAND terms, trade secrets, or refusal to share data. These out-of-court bodies must resolve disputes within 90 days and publish publicly available annual reports (in line with the promotion of transparency). Notably, if a user or data recipient wins a dispute, the data holder must cover all costs and reimburse reasonable expenses. The reverse does not apply, unless bad faith is proven.
The Act also incorporates extraterritorial enforcement. Non-EU entities, including UK businesses, offering products or services to EU users or sharing data with EU-based recipients must appoint a legal representative in a member state. This echoes similar requirements under the GDPR and reflects the EU’s expanding digital regulatory reach.
Penalties are set at national level but must be effective, proportionate, and dissuasive (Article 40). There’s no uniform cap (like in GDPR) but instead, member states will need to develop their own rules in alignment with Commission guidelines and EDIB recommendations.
With the Act’s deadline looming, companies handling connected product and related service data, whether as manufacturers, service providers, or data recipients, should be assessing their risk exposure under the new enforcement model and preparing internal processes for potential regulatory oversight or disputes.
___
We covered this topic in detail in our recent webinar, “Enter the EU Data Act – The New Rulebook for B2B Data Sharing”. If you’re interested in viewing the recording of this webinar please do get in touch.