Does the Data Act override the GDPR when requested data includes personal data?
No. Article 1(5) is the boundary rule: the Data Act complements EU data-protection and privacy law, and rules prevail where personal-data protection conflicts with a Data Act access or sharing step. The Data Act is therefore not a shortcut around GDPR purpose limitation, , special-category conditions, transparency, minimisation, security, or data-subject rights.
Split the request into two decisions: which product or related-service data falls within the Data Act, and which condition permits each personal-data operation or disclosure. The Data Act has applied since 12 September 2025, but that application date did not alter the GDPR test. Non- can often proceed while personal data is separated, anonymised, narrowed, or withheld.
- Treat the Data Act as the access-and-sharing regime for connected-product and related-service data, not as a .
- Escalate any personal-data element to the privacy owner before disclosure to a user, third party, or public body.
- Document the split between non-, personal data relating to the requesting user, and personal data relating to other people.
Article 1(5) and Recital 7 establish that EU personal-data and privacy law remain controlling when personal data is processed under the Data Act.
The Commission FAQ states that the GDPR is fully applicable to personal-data processing under the Data Act.