Comparison GuideEUData Act

Data Act vs GDPR

Compare the EU Data Act's connected-product and related-service data access rules with GDPR duties for personal data, data subjects, controllers, processors, and lawful basis.

Separate access obligations from privacy limits before sharing raw or pre-processed product data with users or third parties.

Author
Sorena AI
Published
May 6, 2026
Updated
Jul 26, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 6, 2026
Updated Jul 26, 2026
Overview

The EU Data Act can require access to product data and related service data for connected products placed on the Union market and related services provided in the Union, including personal and non-. still governs every processing operation involving personal data within its own material and territorial scope. First decide whether the data and request fall within Data Act Chapter II. Then identify the data subject, controller, processor, recipient, purpose, Article 6 lawful basis, any Article 9 condition for special-category data, and any ePrivacy rule. A Data Act duty does not supply the GDPR lawful basis or override a data subject's rights.

Side-by-side comparison

EU Data Act vs GDPR for connected-product data

This matrix helps separate Data Act access duties from personal-data duties when a connected-product or related-service data request may include .

Review all sources
First framework
EU Data Act

The Data Act column asks whether connected-product or related-service data must be made accessible, usable, or shareable.

Second framework
GDPR

The column asks whether any personal-data processing in that access, use, or sharing is lawful and properly controlled.

Comparison row 1

Scope boundary

EU Data Act

The Data Act creates harmonised rules for fair access to and use of data, including Chapter II rights for users of connected products and related services.

GDPR

remains the controlling law for personal-data processing, data subject rights, controller and processor duties, and supervisory authority powers.

Operational implication

Start with the Data Act only for the access question. If is involved, Article 1(5) makes the privacy-law boundary explicit: and related privacy law prevail in a conflict.

Comparison row 2

Covered actors

EU Data Act

Data Act roles include the user, , data recipient, third party, manufacturer, related-service provider, and public-sector requester depending on the chapter and request type.

GDPR

roles include data subject, controller, processor, joint controller, recipient, data protection authority, and European Data Protection Supervisor where EU institutions are involved.

Operational implication

Do not translate roles mechanically. A Data Act user can be a data subject in one flow, a controller in another flow, and neither in a request involving another person's .

Comparison row 3

Trigger

EU Data Act

Chapter II focuses on raw and pre-processed product data and related service data that is readily available to the , plus metadata needed to interpret and use it. Inferred or derived data and content are outside that Chapter II scope.

GDPR

applies to in the export, including pseudonymised data and personal-data fields inside mixed datasets. Properly anonymised information falls outside GDPR only when the person is not or is no longer identifiable, taking account of means reasonably likely to be used.

Operational implication

Build exports at field level. Separate raw or pre-processed data from inferred, derived, and content fields; then mark personal, non-personal, mixed, pseudonymised, anonymous, and trade-secret material before deciding what can be sent.

Comparison row 4

Core obligations

EU Data Act

The Data Act gives users access to product data and related service data generated by their use of a connected product or related service, regardless of whether the data is personal or non-personal, when the data is in scope.

GDPR

Article 15 gives a data subject access to undergoing processing and related information. Article 20 portability is narrower: it covers personal data the data subject provided to the controller, when processing is automated and based on consent or contract. Both rights protect the rights and freedoms of others.

Operational implication

If the requester is the data subject, assess Data Act access, access, and GDPR portability separately. A failed Data Act scope test does not decide a GDPR request, and Article 15 access does not automatically meet Article 20 portability conditions.

Comparison row 5

Evidence record

EU Data Act

The Data Act can oblige a to make available to the user or a third party at the user's request, but it does not create a legal basis to collect or generate personal data.

GDPR

requires a valid Article 6 basis for each personal-data processing purpose. Special-category data also needs an Article 9(2) condition. Transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability still apply.

Operational implication

Record who the data subject is, who will receive the data, the requested purpose, the Article 6 basis, any Article 9 condition, the fields needed for that purpose, the retention rule, and the information given to affected people.

Comparison row 6

Timing and deadlines

EU Data Act

The Data Act has applied generally since 12 September 2025. Article 3(1)'s access-by-design duty applies to connected products and related services placed on the market after 12 September 2026. Chapter II has enterprise-size exclusions in Article 7, subject to its linked-enterprise and subcontracting conditions.

GDPR

has applied since 25 May 2018. Data subject requests are generally answered without undue delay and within one month, with a possible two-month extension where necessary because of complexity or number. That GDPR deadline is not the response period for every Data Act request.

Operational implication

Record the legal route, product placement date, enterprise-size facts, request date, requester identity, and deadline. When one request invokes both laws, track the duties separately and coordinate the response.

Comparison row 7

Enforcement

EU Data Act

Member States designate competent authorities for Data Act enforcement and set penalties that must be effective, proportionate, and dissuasive. Users can challenge certain withholding, suspension, refusal, and access disputes through competent authorities, courts, or dispute settlement routes.

GDPR

Data protection authorities remain responsible for Data Act application insofar as personal-data protection is concerned, and enforcement paths continue for GDPR infringements.

Operational implication

Escalate to the right authority path. A Data Act access dispute, a trade-secret refusal, and a unlawful-disclosure complaint may involve different competence even when they arise from the same export.

Comparison row 8

Overlap and reuse

EU Data Act

The Data Act requires trade secrets to be preserved through agreed technical and organisational measures. Withholding, suspension, or refusal must be justified and tied to the Data Act conditions.

GDPR

requires data minimisation and appropriate security. Anonymisation may remove data from GDPR only if people are no longer identifiable; pseudonymisation is a safeguard but the data remains .

Operational implication

Run separate reviews for trade-secret confidentiality and serious economic damage, and for personal-data lawfulness, minimisation, and security. Neither label is a generic refusal reason.

Comparison row 9

Practical decision rule

EU Data Act

Beyond Chapter II, the Data Act also covers B2G exceptional-need requests, switching between data processing services, and safeguards against unlawful third-country government access to non-.

GDPR

For B2G requests involving , the Data Act requires privacy safeguards and does not lower personal-data protection. International transfers of personal data remain governed by rather than the Data Act's non-personal-data third-country access rules.

Operational implication

Do not apply the connected-product access analysis to every Data Act chapter. B2G and cloud matters need their own scope check, and still moves back to .

Practical decision rule

Practical decision rule

  • Scope the product data, related service data, metadata, readily available data, exclusions, recipient, and Article 7 enterprise conditions under the Data Act.
  • Map personal-data fields, data subjects, roles, Article 6 bases, Article 9 conditions, transparency, retention, security, and transfer rules.
  • Document separate conclusions where Data Act access and disclosure point in different directions; personal-data law prevails in a conflict.
Section 1

An access duty does not override privacy law

Article 1(5) of the Data Act says the regulation is without prejudice to EU and national law on , privacy, confidentiality of communications, and terminal-equipment integrity. It also says that, if there is a conflict, the personal-data or privacy law prevails.

Product and related-service data can contain personal and non- in the same export. A Data Act request can start the access analysis, but it does not create a lawful basis for disclosing another person's personal data or collecting personal data that was not already lawfully processed.

  • Use the Data Act to decide whether product data or related service data must be made accessible.
  • Use to decide whether the personal-data processing in that access, use, or sharing is lawful.
  • If the user is also the data subject, assess the Data Act request and the separate rights of access and portability. GDPR portability applies only when its own conditions are met.
  • If the user is not the data subject, check Article 6 and, where relevant, Article 9 and ePrivacy conditions before disclosure.
  • If one request invokes both laws, log two legal routes and deadlines; answering one route does not close the other.
Section 2

Classify the data field by field

For Data Act Chapter II access, the Commission explains the scope as raw and pre-processed data generated from use of a connected product or related service that is readily available to the , including relevant metadata. Inferred or derived data and content are outside that Chapter II scope.

does not use the Data Act's product-data boundary. It applies to the personal-data fields in a mixed dataset. Pseudonymised data remains when it can be attributed to a person with additional information; only data rendered anonymous so that a person is no longer identifiable falls outside GDPR. The same export can therefore contain Data Act in-scope non-personal data, Data Act in-scope personal data, and material outside Chapter II such as inferred or derived information and content.

  • List raw sensor or event fields separately from enriched scores, analytics, recommendations, and audiovisual content.
  • Mark each field as personal, non-personal, mixed, outside Chapter II, redacted, anonymised, or pseudonymised before disclosure.
  • Include metadata needed to interpret the export, such as timestamps, units, sensor identifiers, quality limits, and collection context.
  • Do not use privacy-preserving transformations alone as a reason to treat otherwise in-scope raw or pre-processed data as derived data.
Section 3

Assign GDPR roles and lawful basis

The Data Act has users, data holders, data recipients, third parties, manufacturers, related-service providers, and public-sector requesters. asks a different question: who determines the purposes and means of personal-data processing, who processes for someone else, and who is the data subject?

When the user is not the data subject, Articles 4(12) and 5(7) of the Data Act allow the to disclose only if there is a valid Article 6 basis and, where relevant, the conditions in GDPR Article 9 and ePrivacy Directive Article 5(3) are met. A business user that determines why and how it will use the received personal data may be a controller for that processing; the role depends on the facts, not the Data Act label.

  • Identify whether the requester is the Data Act user, the data subject, both, or neither.
  • Identify the and any third-party recipient under the Data Act.
  • Identify the controller, processor, joint-controller, and recipient positions under for the same flow; do not assign them by contract label alone.
  • Record the specific Article 6 basis before sending to a user that is not the data subject or to a third party chosen by that user.
  • For health, biometric identification, genetic, or other Article 9 data, record both an Article 6 basis and an Article 9(2) condition. Check national law where the selected condition permits or requires it.
Recommended next step

Review a Data Act and GDPR overlap

Use the comparison to prepare a field-level export map, role analysis, lawful-basis note, recipient review, and trade-secret safeguard record for a connected-product data request.

Section 4

Control third-party sharing and refusal grounds

The Data Act lets a user ask the to make in-scope data available to an eligible third party in the Union, but the route is not unlimited. A Digital Markets Act gatekeeper is not eligible under Article 5. The third party must use the data only for the purposes and on the conditions agreed with the user, comply with personal-data law, and follow the additional restrictions in Article 6.

Trade secrets are not a blanket refusal ground. The Data Act requires confidentiality measures first, allows withholding or suspension where agreed measures are missing or undermined, and allows refusal only in exceptional circumstances where serious economic damage is highly likely despite safeguards.

  • Check whether the chosen third party is eligible under the Data Act and not a prohibited recipient for the requested route.
  • Limit third-party personal-data disclosure to the user's requested purpose and the lawful basis.
  • Document trade-secret identification, confidentiality measures, technical controls, and any written withholding, suspension, or refusal reason.
  • Escalate refusals or suspensions to the competent-authority and dispute paths described in the Data Act instead of relying on informal denials.
Section 5

Check dates and Chapter II exclusions before building the response

The Data Act has applied generally since 12 September 2025. The Article 3(1) duty to design covered products and related services so that data is readily accessible applies to connected products and related services placed on the market after 12 September 2026. That later date does not postpone every Chapter II access duty.

Chapter II does not apply to data generated through connected products manufactured or designed, or related services provided, by qualifying microenterprises and small enterprises, subject to the partner, linked-enterprise, and subcontracting conditions in Article 7. A limited one-year rule also covers certain enterprises that have newly become medium-sized. These exclusions do not remove duties from personal-data processing.

  • Record the product and related-service provider, enterprise size and relationships, subcontracting facts, and product placement date.
  • Separate the Article 3(1) access-by-design question from an Article 4 user request for readily available data.
  • Apply to even if a Data Act Chapter II duty or route is unavailable.
Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Supports the broader Data Act chapter structure for B2G requests, cloud switching, and non-personal-data government-access safeguards.
ec.europa.eu
Referenced sections
  • Supports the Commission's explanation that Chapter V cannot lower protection for personal data or trade secrets and that GDPR governs international personal-data transfers.
eur-lex.europa.eu
Referenced sections
  • Articles 4, 5 and 32 and recital 26 support pseudonymisation, anonymisation, minimisation, and security distinctions.
Related guides

Explore more topics

Data Act and Common European Data Spaces
How Data Act Article 33 connects data-space participation with metadata, vocabularies, APIs, access terms, data quality, governance, and standards monitoring.
Data Act and Data Governance Act Overlap FAQ
FAQ explaining where the EU Data Act and Data Governance Act overlap, how they differ, and how to route product, cloud, public-sector reuse, intermediary, and data altruism workflows.
Data Act Audit Evidence and Request Logs FAQ
FAQ for Data Act request logs covering user and third-party access, B2G exceptional need requests, cloud switching records, contract terms, trade secrets, and GDPR boundaries.
Data Act B2B Data-Sharing Contract Clauses
Clause guide for EU Data Act B2B data sharing: FRAND terms, compensation, trade secret safeguards, recipient limits, termination, logs, and GDPR boundaries.
Data Act B2B Data-Sharing Contract Template
A usable EU Data Act B2B data-sharing template outline covering access requests, data schedules, permitted use, trade secrets, security, compensation, GDPR boundaries, audit records, and termination.
Data Act B2G Exceptional-Need Requests
An official source guide to EU Data Act Chapter V requests from public bodies: exceptional need, public emergencies, request contents, limits, safeguards, costs, and records.
Data Act Cloud Switching Compliance Checklist
A cited EU Data Act checklist for cloud and data processing service providers covering switching clauses, notices, export formats, charges, interoperability, and evidence.
Data Act Cloud Switching Contract Terms FAQ
FAQ on EU Data Act cloud switching contract terms: Article 25 clauses, assistance, notice, transition, charges, export, termination, interoperability, and records.
Data Act Cloud Switching Fees and Deadlines FAQ
FAQ on EU Data Act cloud switching charges, 2027 fee removal, notice periods, transition windows, data retrieval, contract terms, and evidence records.
Data Act Complaints and Dispute Settlement FAQ
FAQ on EU Data Act complaints, competent authorities, dispute settlement bodies, B2B data-sharing disputes, B2G requests, cloud switching disputes, and evidence records.
Data Act Exportable Data and Metadata FAQ
FAQ explaining which product, related service, metadata, and cloud switching data must be exportable under the EU Data Act, and which data can be excluded.
Data Act FAQ for Aftermarket Repair and Mobility Services
FAQ on EU Data Act vehicle-data access for repairers, independent service providers, fleets, insurers, and mobility services.
Data Act Smart Contracts for Data Sharing
Data Act Article 36 smart contract guide for data-sharing agreements: scope, robustness, access control, termination, interruption, archiving, standards status, and conformity evidence.
Data Act SME Exceptions and Startups FAQ
FAQ on where the EU Data Act gives micro, small, medium-sized, startup, and SME actors narrower treatment for access duties, compensation, and B2B terms.
Data Act Trade Secret Technical Protection Measures FAQ
FAQ on how EU Data Act data holders can protect trade secrets with confidentiality safeguards, technical measures, limited withholding, suspension, refusal, and evidence.
Data Act Trade Secrets and Protection Measures
Data Act guide for protecting trade secrets during access and sharing: classification, safeguards, refusal thresholds, notices, evidence records, and reviews.
Data Act Unfair Contractual Terms | Article 13 B2B Contract Review
Review B2B data-sharing clauses under EU Data Act Article 13: unilateral terms, always unfair examples, presumed unfair terms, model clauses, evidence, and remediation.
Data Act Vehicle Data Guidance
Commission-cited guide to Data Act vehicle data access: connected vehicles, vehicle-related services, raw and pre-processed data, aftermarket use cases, access routes, safeguards, and GDPR boundaries.
EU Data Act and Common European Data Spaces FAQ
FAQ on how EU Data Act interoperability duties, Data Governance Act rules, and sector data-space governance fit together without treating participation as a general obligation.
EU Data Act and GDPR: Personal Data Overlap FAQ
FAQ on how the EU Data Act works when connected-product or related-service data includes personal data, mixed datasets, GDPR roles, lawful basis, trade secrets, and third-party sharing.
EU Data Act Applicability Test
Check whether a product, related service, data holder, cloud service, data-space role, smart contract, or B2G request is in scope of the EU Data Act.
EU Data Act Application Dates and Transition FAQ
FAQ on when the EU Data Act applies, which obligations are delayed, and what product, contract, cloud, and evidence records teams should maintain.
EU Data Act Article 3 Pre-Contract Information
What Article 3 of the EU Data Act requires before connected-product purchase, rent, lease, or related-service contracting: data categories, access, data holder identity, third-party sharing, complaints, and evidence.
EU Data Act Article 32: Foreign Government Access FAQ
FAQ on EU Data Act safeguards for non-EU government access to non-personal data held in the Union by data processing service providers.
EU Data Act Article 36 Smart Contract Controls FAQ
FAQ explaining when EU Data Act Article 36 applies to smart contracts for data-sharing agreements and what controls, conformity evidence, and limits it requires.
EU Data Act B2B Data Sharing Compensation FAQ
FAQ on when Data Act data holders may charge B2B data recipients, what reasonable compensation can include, SME limits, unfair terms, disputes, and trade secret safeguards.
EU Data Act B2G Compensation and Costs FAQ
FAQ on when Data Act B2G exceptional-need requests are free, when fair compensation may be claimed, which costs can be included, and what records to keep.
EU Data Act B2G Exceptional Need FAQ
When public-sector bodies can request business-held data under the EU Data Act, what a valid request must contain, and how data holders handle limits, trade secrets, compensation, and evidence.
EU Data Act Checklist for Product, Cloud, and Contract Teams
A cited EU Data Act checklist for connected-product data access, third-party sharing, B2G requests, cloud switching, unfair terms, smart contracts, personal data boundaries, evidence, and owners.
EU Data Act Cloud Switching and Exit Plans
A cited EU Data Act guide for data processing service exit plans: switching contracts, exportable data, assistance, charges, interoperability, retrieval, erasure, and records.
EU Data Act Cloud Switching Procurement FAQ
Procurement checklist FAQ for EU Data Act cloud switching: contract terms, exit support, exportable data, switching charges, interoperability, termination, and supplier evidence.
EU Data Act Compliance Program
Build a Data Act compliance program for connected-product data access, contracts, B2G requests, cloud switching, smart contracts, GDPR boundaries, records, and ownership.
EU Data Act Connected Product Scope and Data Types
Classify EU Data Act connected products, related services, product data, related-service data, readily available data, metadata, and excluded derived outputs.
EU Data Act Connected Product Scope FAQ
FAQ explaining when connected products, related services, generated data, EU market placement, and SME exceptions fall within EU Data Act scope.
EU Data Act Data Processing Service Switching
A cited EU Data Act guide for provider and customer switching duties: exit assistance, exportable data, contract clauses, charges, interoperability, retrieval, and erasure.
EU Data Act data spaces interoperability FAQ
FAQ explaining Article 33 Data Act interoperability requirements for data-space participants, common European data spaces, standards, APIs, metadata, and architecture evidence.
EU Data Act deadlines and compliance calendar
A cited calendar for EU Data Act application dates, product design timing, contract remediation, cloud switching charges, response periods, standards work, and evidence records.
EU Data Act Direct Access by Design FAQ
FAQ for product and legal teams designing user access to connected-product and related-service data under the EU Data Act.
EU Data Act Enforcement and Competent Authorities FAQ
FAQ on who enforces the EU Data Act, how complaints work, how Member States set penalties, when dispute settlement can be used, and when GDPR authorities remain responsible.
EU Data Act FAQ: scope, access rights, B2G, cloud switching, GDPR, and dates
EU Data Act FAQ index covering connected-product access, third-party sharing, B2G exceptional need, cloud switching, smart contracts, GDPR boundaries, unfair terms, and application dates.
EU Data Act Functional Equivalence: IaaS Switching FAQ
FAQ on Data Act functional equivalence for cloud switching: IaaS scope, customer outcomes, export support, interoperability duties, limits, and evidence.
EU Data Act Indirect Access Request Workflow FAQ
FAQ for Data Act teams handling user and third-party data requests when direct connected-product access is unavailable, incomplete, or limited.
EU Data Act Interoperability Standards: Articles 33-36
FAQ on EU Data Act interoperability standards for data spaces, cloud switching, smart contracts, harmonised standards, common specifications, and M/614.
EU Data Act Model Terms and Cloud Clauses FAQ
FAQ on the EU Data Act non-binding model contractual terms for data access and use, cloud switching clauses, B2B use, unfair terms, and evidence.
EU Data Act Non-Emergency Public-Sector Request FAQ
FAQ on EU Data Act requests where a public body claims exceptional need outside a public emergency, including scope, request contents, limits, compensation, confidentiality, and evidence.
EU Data Act Penalties and Enforcement
Official source guide to Data Act penalties under Article 40, Member State enforcement, penalty factors, complaints, judicial remedies, and the GDPR enforcement boundary.
EU Data Act Pre-Contractual Information FAQ
FAQ on EU Data Act Article 3 pre-contract information for connected products and related services, including data categories, access methods, data holder identity, third-party sharing, and GDPR boundaries.
EU Data Act Product Data vs Related-Service Data
FAQ explaining how the EU Data Act separates connected product data, related service data, readily available raw and pre-processed data, metadata, and inferred or derived outputs.
EU Data Act Public Emergency Request FAQ
FAQ on EU Data Act public emergency requests: exceptional need, request content, timing, data holder response, compensation, confidentiality, and records.
EU Data Act Readily Available Data FAQ
FAQ on what counts as readily available data under the EU Data Act, including product data, related service data, metadata, inferred data, and access mechanics.
EU Data Act Related Services FAQ
FAQ explaining when software is a Data Act related service, how it links to connected products, which product and service data are in scope, and what exclusions apply.
EU Data Act Requirements by Workstream
EU Data Act requirements for connected-product access, B2B terms, B2G exceptional need, cloud switching, smart contracts, interoperability, GDPR boundaries, and records.
EU Data Act Smart Contracts for Data Sharing FAQ
Answers on Article 36 Data Act smart-contract requirements for data sharing: scope, robustness, access control, termination, archiving, conformity assessment, contract terms, and standards status.
EU Data Act Third-Party Data Sharing FAQ
FAQ on user-directed third-party data sharing under the EU Data Act, covering data holder duties, recipient limits, trade secrets, security, GDPR, and gatekeepers.
EU Data Act Trade Secret Safeguards FAQ
FAQ on protecting trade secrets when handling EU Data Act user and third-party data access requests, including safeguards, withholding, suspension, refusal, notices, and records.
EU Data Act Unfair Contractual Terms FAQ
FAQ on Article 13 of the EU Data Act: B2B unfair contract terms, unilateral take-it-or-leave-it clauses, always-unfair terms, presumed-unfair terms, SMEs, model terms, and review evidence.
EU Data Act User Access and Portability Rights
Practical guide to EU Data Act user access, connected-product data portability, third-party sharing, trade secret safeguards, and the GDPR boundary.
EU Data Act Users, Data Holders, and Recipients FAQ
FAQ explaining Data Act users, data holders, data recipients, connected products, related services, user access, third-party limits, and GDPR boundaries.
EU Data Act Vehicle Data Guidance FAQ
FAQ on EU Data Act vehicle data guidance for connected vehicles, aftermarket repair, mobility services, third-party access, trade secrets, security, and GDPR boundaries.
EU Data Act vs Data Governance Act
Compare the EU Data Act with the Data Governance Act: connected-product access, cloud switching, B2B/B2G duties, protected public-sector reuse, intermediaries, altruism, governance, and enforcement.
EU Data Act: Non-Personal Data and Mixed Datasets
FAQ on how the EU Data Act treats non-personal data, mixed datasets, GDPR precedence, user and third-party access, trade-secret limits, and evidence records.