Since September 12, 2025, the EU Data Act has been in force. Data holders of data originating from the use of connected products and related services must, in principle, make these data available to users.
However, there are exceptions, even if defined very narrowly: for example, in cases of serious risks to safety or health, or to protect trade secrets.
For personal data, the GDPR remains fully applicable: if datasets contain personal data, a valid legal basis is still required.
SMEs may also benefit from certain exemptions that can provide relief.
The Data Act is very far-reaching and has set out clear mechanisms to make circumvention of disclosure obligations more difficult.
A “disclosure at any price” is not intended. Instead, data holders must carefully assess whether they or the data they manage fall under one of the narrowly defined exemption provisions.