Editorial explainer · official sources (EUR-Lex, European Commission)medium
The Data Act: who can read your devices' data, and why it's a security matter
Not an attack, but a law that redraws who can access the data generated by connected objects. The Data Act — Regulation (EU) 2023/2854 — has been in force since 11 January 2024 and applicable since 12 September 2025. It gives users the right to access the data their devices produce and to share it with third parties, requires providers to make cloud switching easier, and introduces safeguards against unlawful access to data by non-EU governments. More parties touching the same data means more surface to protect: an explainer on what changes and why security is part of it, not a footnote.
The object that generates data, and the question of whose it is
A connected car, a farming machine, a thermostat, an industrial device: each of these objects continuously produces data about how it works. For years the answer to "whose data is that" was effectively just one: the manufacturer's, who collects it and decides who may see it. The Data Act, Regulation (EU) 2023/2854, rewrites that answer. It has been in force since 11 January 2024 and is applicable since 12 September 2025: not a proposal, but law in force.
The principle is simple to state and broad in its consequences: the user of a connected product — the one who uses it, not only the one who built it — has the right to access the data that product generates and to share it with third parties of their choice. A farmer can take their tractor's data to an independent repair shop; the owner of a machine can give it to an alternative maintenance provider. Data stops being the manufacturer's fenced yard and becomes a resource the user can move.
The regulation's three levers
The Data Act rests on a few main levers, and each has a security angle.
- 01Data access and sharingthe user accesses device data and gives it to third parties
- 02Cloud provider switchingan obligation to remove barriers to moving
- 03Non-personal data safeguardsbarriers to unlawful access by non-EU governments
The first is the data access just described. The second concerns the cloud: the regulation requires data-processing service providers to make switching to another provider easier, removing contractual, economic and technical obstacles to switching. The aim is to reduce lock-in, the situation where changing provider is so costly it becomes impractical. The third is protecting non-personal data held in the EU against unlawful access or transfer by third-country authorities — a theme that completes, for non-personal data, what other rules provide for personal data.
Why security isn't a separate chapter
It is easy to read the Data Act as a matter of competition and markets. It is, but not only. Each lever shifts something on the security plane. Opening a device's data to third parties means multiplying the points where that data travels and is stored: more recipients, more channels, more surface to protect. The regulation is aware of this and provides that sharing happen with adequate measures, and that making data available not compromise trade secrets and security — a delicate balance, because refusing to share "for security" must not become the shortcut to dodge the obligation.
Cloud switching, likewise, is good news for resilience — being able to leave a provider is part of a continuity strategy — but the data migration is itself a moment of risk: it must be moved encrypted, verified, with no orphan copies left behind. And the safeguard against non-EU government access is, in essence, a question of data sovereignty with direct implications for where and how information is stored.
What to take, even beyond the obligation's borders
The Data Act interlocks with the rest of the European data rulebook. It does not replace the GDPR: where there is personal data, the GDPR prevails and its protections stand. It sits instead alongside the security rules — NIS2, the Cyber Resilience Act — composing a picture in which connected products must be at once secure, interoperable and "open" toward the user.
For anyone who makes or sells connected objects and software in the EU, the practical message is that data accessibility must be designed, not improvised: interfaces that allow access securely, contracts that do not use security as a pretext to deny it, switching procedures that leave no data exposed. This is an explainer, not the attack of the day; but it is the frame within which, more and more, device data will move. The dates and content that matter are verifiable at the official sources at the top of the page: the text on EUR-Lex and the European Commission's explanations.