The EU Data Act reached a major milestone on 12 September 2025, when the majority of the rules came into effect. This included both the rules relating to connected products and related services, and the cloud switching obligations for data processing service providers.
However, implementation is not fully complete. There are further dates that businesses need to keep on their radar. At the end of 2026, manufacturers face obligations under Article 3(1), requiring their products and services to enable users to directly access data. In January 2027, the full ban on switching charges comes into effect. At the end of 2027, the rules on unfair contractual terms will extend to existing B2B contracts that predated the 12 September 2025 milestone.
For businesses trying to understand their obligations, the European Commission’s FAQs are an important resource. The FAQs provide clarification on the application of the rules and on key definitions, many of which remain broad and difficult to apply in practice. For example, they look at the definition of data processing services, which include SaaS, PaaS and IaaS, and provide guidance for businesses carrying out scoping assessments.
There is also sector-specific guidance, including for the automotive sector in relation to data access and sharing in the context of vehicle data and telematics. Draft guidance on reasonable compensation under Article 9 also provides useful indicators on pricing models for mandatory data sharing.
Enforcement remains an area of uncertainty. Because the Data Act is a Regulation, it applies directly in all member states. However, enforcement is decentralised. Member states must designate competent authorities and establish their own penalty frameworks, including maximum fine amounts.
Progress across member states has been varied. Some have already passed national implementing laws, designated competent authorities and established penalty frameworks. Others are still developing, and many have made little or no progress.
Unlike GDPR, the Data Act does not set an EU-wide maximum cap on penalties. Instead, the Data Act requires penalties to be effective, proportionate and dissuasive. This means enforcement approaches may vary between member states, based on different on different interpretations and national frameworks.
In the shorter term, the absence of fully developed enforcement frameworks does not mean there is no risk. Given the new user rights under the Act, early enforcement may in fact be user-led, including in the form complaints and private enforcement.
This article was compiled using insights from our recent webinar: EU Data Act 2026: The Year Compliance Gets Real. If you’d like to view the recording of this webinar, please do get in touch.