Back to Publications
Regulatory Brief · EU compliance

EU Data Act 2025: Key B2B Obligations for Product Manufacturers and Cloud Providers

23 May 2026By NexCyber Editorial EU compliance

The EU Data Act, which entered into force in September 2023 and will apply from September 2025, introduces significant changes for businesses across various sectors. It aims to facilitate data sharing, enhance competition, and empower users with greater control over data generated by connected devices. This article provides a comprehensive overview of the key obligations for product manufacturers and cloud providers under the new regulation.

The EU Data Act, which entered into force in September 2023 and will apply from September 2025, introduces significant changes for businesses across various sectors. It aims to facilitate data sharing, enhance competition, and empower users with greater control over data generated by connected devices. This article provides a comprehensive overview of the key obligations for product manufacturers and cloud providers under the new regulation.

Understanding the Scope of the EU Data Act

The EU Data Act has a broad scope, impacting a wide range of entities, including IoT manufacturers, digital platforms, cloud service providers, and the public sector. Its primary goal is to create a harmonized framework for data sharing and usage across the EU.

Impact on IoT Manufacturers

IoT manufacturers are significantly affected by the Data Act, as they are required to provide users with access to data generated by their devices. This provision aims to empower users and enable them to make informed decisions about their data usage.

Role of Cloud Providers

Cloud service providers are also under scrutiny, as the Data Act mandates easier switching between service providers and prohibits excessive switching costs. This is intended to foster competition and prevent vendor lock-in, ensuring a more dynamic cloud services market.

Public Sector Involvement

The public sector is encouraged to leverage data more effectively to improve public services. The Data Act facilitates data access for public authorities, especially in cases of exceptional need, such as emergencies or public interest scenarios.

Data Sharing Obligations: Users' Right to Access Product-Generated Data

One of the core tenets of the EU Data Act is the user's right to access data generated by products they own or use. This provision is designed to enhance transparency and user empowerment.

Empowering Users

Product manufacturers must ensure that users can easily access data generated by their devices. This includes providing clear instructions and tools for data retrieval, thereby enabling users to utilize their data for personal or commercial purposes.

Technical and Organizational Measures

Manufacturers are required to implement appropriate technical and organizational measures to facilitate data access. This may include developing user-friendly interfaces and ensuring data portability in commonly used formats.

B2B Data Sharing: Fair Access and Non-Discriminatory Terms

The Data Act promotes fair and non-discriminatory data sharing practices between businesses, aiming to create a level playing field and stimulate innovation.

Fair Access to Data

Businesses must provide fair access to data under reasonable and non-discriminatory terms. This is particularly relevant for companies that rely on data from other entities to develop new products or services.

Contractual Adjustments

To comply with the Data Act, companies may need to review and adjust their B2B contracts to ensure they align with the principles of fairness and non-discrimination. This includes revising terms related to data access, usage rights, and pricing.

Cloud Switching: Porting Requirements and Switching Costs Ban

The Data Act introduces specific provisions to facilitate easier switching between cloud service providers, addressing common challenges faced by businesses.

Porting Requirements

Cloud providers must ensure that users can port their data and applications to another provider without undue delay or technical barriers. This involves offering standardized interfaces and ensuring data interoperability.

Prohibition of Switching Costs

To prevent vendor lock-in, the Data Act prohibits excessive switching costs. Cloud providers must eliminate or significantly reduce fees associated with data porting and service termination, enabling users to switch providers with minimal financial burden.

International Data Transfer Restrictions Under the Data Act

The Data Act also addresses international data transfers, imposing restrictions to safeguard EU data sovereignty and security.

Compliance with EU Standards

Entities transferring data outside the EU must ensure compliance with EU data protection standards. This includes adhering to adequacy decisions or implementing appropriate safeguards, such as standard contractual clauses.

Impact on Global Operations

Businesses with global operations may need to reassess their data transfer mechanisms to ensure compliance with the Data Act. This could involve renegotiating contracts with international partners or investing in additional compliance measures.

Overlap with GDPR and Data Governance Act

The EU Data Act intersects with existing regulations like the GDPR and the Data Governance Act, creating a comprehensive data governance framework.

GDPR Synergies

While the GDPR focuses on personal data protection, the Data Act addresses broader data access and sharing issues. Businesses must navigate these overlapping regulations to ensure comprehensive compliance.

Data Governance Act Alignment

The Data Act complements the Data Governance Act by enhancing data availability and fostering data-driven innovation. Companies should consider both regulations when developing data governance strategies.

Action List for Product Manufacturers and Cloud Providers Before September 2025

To ensure compliance with the EU Data Act by September 2025, product manufacturers and cloud providers should take proactive steps.

Conduct a Compliance Audit

Businesses should conduct a thorough audit of their data practices to identify potential areas of non-compliance. This includes reviewing data access mechanisms, contractual terms, and data transfer processes.

Update Contracts and Policies

Companies must update their B2B contracts and internal policies to align with the Data Act's requirements. This may involve renegotiating terms with partners and revising user agreements.

Invest in Technical Solutions

Investing in technical solutions to facilitate data access, portability, and interoperability is crucial. This includes developing APIs, enhancing data security measures, and ensuring compliance with international data transfer standards.

Train Staff and Raise Awareness

Training staff on the requirements of the Data Act and raising awareness about data sharing obligations is essential. This will help ensure that all employees understand their roles in achieving compliance.

Next Step with NexCyber

As the EU Data Act's application date approaches, it's crucial for businesses to assess their readiness and implement necessary changes. NexCyber offers comprehensive compliance solutions tailored to the specific needs of product manufacturers and cloud providers. Visit [NexCyber](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=eu-data-act-2025-b2b-obligations) to learn how we can support your journey towards compliance with the EU Data Act.