| Scope boundary | Covers processing of personal data, including information relating to an identified or identifiable natural person. | Covers data broadly, including connected-product and related-service data, and can apply to personal and non-personal data. Other chapters govern specified data-sharing, contract, public-sector, switching, and interoperability situations. | Run Data Act scope on the product, service, data, and relationship. Run GDPR scope on every personal-data operation within it. |
|---|
| Covered actors | Requires role allocation for controllers, joint controllers, processors, representatives where relevant, DPO tasks where applicable, processor contracts, RoPA, security, breach, DPIA, and accountability records. | Relevant Data Act actors include users of connected products or related services, data holders, third-party data recipients, enterprises receiving contractual terms, public-sector bodies making exceptional-need requests, and providers and customers of data-processing services. | Record Data Act and GDPR roles separately. A Data Act user may also be a GDPR data subject, controller, or neither, depending on the facts. |
|---|
| Trigger | Requires a lawful basis for each processing purpose and accountability evidence for lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity, and confidentiality. | A Data Act right or duty to make data available does not erase GDPR conditions for personal-data processing. The Data Act preserves data-protection law and makes it prevail where the rules conflict. | Document both the Data Act access basis and the GDPR lawful basis before personal data is disclosed or reused. |
|---|
| Core obligations | Requires transparent information and data-subject rights handling, including access, rectification, erasure, restriction, portability, objection, and automated-decision safeguards where applicable. | Chapter II gives users rights to access data generated by connected products and related services and to have data made available to third parties, subject to conditions including limits on recipient use and trade-secret safeguards. | A single portal may accept both requests, but it must distinguish a GDPR data-subject request from a Data Act user or third-party access request. |
|---|
| Evidence record | Requires a Chapter V transfer basis or safeguard when personal data is transferred to a third country or international organisation. | The Data Act has safeguards against unlawful third-country government access to non-personal data held in the Union. Those safeguards are distinct from GDPR Chapter V mechanisms for personal data. | Classify the data first. Use GDPR transfer tools for personal data and the Data Act's non-personal-data safeguard where its conditions apply. |
|---|
| Timing and deadlines | GDPR duties follow the processing lifecycle: lawful basis and notice before processing, DPIA before likely high-risk processing, rights clocks on request, and breach assessment after awareness. | The Data Act generally applies from 12 September 2025. Article 3(1) design duties apply to covered products and related services placed on the market after 12 September 2026; other chapters have their own contract and switching transitions. | Track GDPR event-based clocks and Data Act application or transition dates in separate fields. |
|---|
| Enforcement | The GDPR gives supervisory authorities powers to monitor application, handle complaints, investigate, and impose corrective measures, including suspension of data flows or administrative fines where needed. | Member States designate one or more competent authorities for the Data Act and lay down penalties. Data-protection authorities remain responsible for monitoring personal-data protection where the Data Act involves personal data. | Route the privacy issue to the competent data-protection authority and the Data Act issue to the designated Data Act authority; coordinate when both are engaged. |
|---|
| Overlap and reuse | The GDPR analysis can still run even when another EU data regime is also relevant, and the same factual workflow may need a separate lawfulness, transfer, or security review. | The Data Act can add a user access or sharing right to the same data while restricting how a third-party recipient may use it. | Reuse shared facts, not legal conclusions. The Data Act access result and GDPR disclosure or reuse result must both permit the planned action. |
|---|
| Practical decision rule | Start with GDPR if any personal data is present, and determine scope, lawful basis, rights, transfers, security, and accountability for the planned processing. | If a connected-product, data-sharing, contract, public-sector request, cloud-switching, interoperability, or smart-contract fact pattern is present, identify the applicable Data Act chapter, role, duty, safeguard, and date. | Proceed only when both results allow the action: the Data Act result for access or use and the GDPR result for any personal-data processing. |
|---|