EU Data Act: who has a right to your product's data
Since 12 September 2025, users can demand the raw data your product generates - for free. From 12 September 2026, that access has to be built into the hardware itself.
If your product has a sensor and your service collects telemetry, someone else already has a legal right to demand that data. Not a regulator, not a competitor - your own customer. And you have to hand it over for free.
Regulation (EU) 2023/2854 - the Data Act - entered into force on 11 January 2024, and the bulk of its rules have applied since 12 September 2025. Its logic runs opposite to the GDPR's: the GDPR limits who may use data, while the Data Act mandates who must share it.
For a Bulgarian startup this is not an abstract Brussels topic. If you build IoT hardware, connected SaaS, an appliance with a companion app, fleet telematics, or a medical device with a cloud dashboard, you are a "data holder" under the regulation. And the next hard deadline is weeks away.
The timeline: where we are and what's next
| Date | What kicks in | Who it hits |
|---|---|---|
| 11.01.2024 | Entry into force (Art. 50) | Everyone - transition periods start |
| 02.04.2025 | Commission publishes model contractual terms (MCTs) and cloud SCCs | Anyone negotiating B2B data terms |
| 12.09.2025 | General application: access rights under Arts. 4 and 5 | Data holders, users |
| 12.09.2025 | Cloud egress fees capped at direct costs (Art. 29) | IaaS/PaaS/SaaS providers |
| 12.09.2026 | "Access by design" for new products (Art. 3(1)) | Hardware manufacturers |
| 12.09.2027 | Art. 13 extends to pre-existing B2B contracts | Parties to pre-2025 contracts |
| 12.09.2028 | Switching charges abolished entirely (EUR 0) | Cloud service providers |
Two of those dates have already passed. The next one - access by design - is less than two months out, and it's the only one that demands a change to the product itself rather than to a contract or a terms page.
Who is in scope
The regulation works with four concepts defined in Article 2, and it's worth checking which of them describe you:
- Connected product (Art. 2(5)) - any item that obtains, generates or collects data about its own use or its environment and transmits it over a network, a physical connection, or on-device access. The air quality sensor, the Wi-Fi coffee machine, the e-scooter, the industrial pump.
- Related service (Art. 2(6)) - a digital service, software included, without which the product could not perform its functions, or which is added later to extend them. The companion mobile app, the cloud dashboard, the analytics subscription.
- Data holder (Art. 2(13)) - the party with the right or obligation to use and make that data available, based on factual and technical control over it. In a typical startup that's you, even when the data physically sits in AWS.
- User (Art. 2(12)) - the natural or legal person who owns, rents or leases the product, or receives the related service. That is your customer, not necessarily the person physically operating the device.
Territorial scope is broad: under Article 1(3) the regulation covers anyone offering connected products or services to users in the EU, regardless of where the company is incorporated or where its servers sit. A Delaware entity does not put you outside it.
Prototypes are explicitly excluded - preliminary models of new products that have not been placed on the market and are used solely for testing or R&D. Your pilot device sitting with three beta customers will struggle to qualify as a prototype, though, if you've already invoiced for it.
The small-enterprise exemption - and where it stops
Article 7 exempts micro and small enterprises - under 50 employees and under EUR 10 million in turnover or balance sheet total - from the data-sharing obligations in Articles 3, 4 and 5. For a large share of Bulgarian startups that is genuine relief, and it means the September 2026 access-by-design deadline is not your urgent problem.
Watch where the exemption ends, though. It does not cover:
- Article 13 and the void clauses in your B2B contracts;
- the cloud-switching rules, if you are the SaaS provider;
- your obligations as a recipient of someone else's data, if you're building on third-party data.
Most importantly: the exemption disappears the day you cross the thresholds. A company that grows from 40 to 60 people in a year wakes up owing a product interface it never designed.
Which data you owe - and which you don't
This is the dividing line every conversation with customers and lawyers will circle back to.
You owe the raw data. Automatically recorded sensor readings, operating parameters and the associated metadata - this is the material the regulation wants pulled out of closed ecosystems.
You do not owe derivative data. The outputs of your proprietary algorithms, sensor fusion, computed indices and predictions are the product of your investment rather than of the device, and they are not subject to mandatory disclosure under Chapter II.
The boundary is not clean, though. In a complex IoT or SaaS platform, where the "raw stream" ends and the "processed result" begins is a technical judgment, and there is no Court of Justice case law on it yet. The practical takeaway: draw that line yourself, document it in your architecture, and be ready to defend it. A startup that doesn't know today which of its fields are raw will be negotiating from a much weaker position tomorrow.
One defensive reflex also disappears. Article 35 amends Directive 96/9/EC so that the sui generis database right does not apply to databases containing data generated by connected products and services. You cannot block access to raw machine data by arguing that you invested in the database.
What exactly the customer can ask for
Access by the user (Article 4). Data is provided free of charge, without undue delay, and at the same quality that is available to you. There is no "export premium plan."
Transfer to a third party (Article 5). At the customer's request you must send the data to a recipient of their choosing - including a service competitor of yours - on fair, reasonable and non-discriminatory (FRAND) terms. You cannot charge the customer anything; you may negotiate compensation with the third party under Article 9, but where the recipient is an SME that compensation is capped at the direct costs of making the data available.
Two limits work in your favour:
- No competing product. Article 4(4) and Article 6(2)(e) expressly bar the user and the third party from using the data to develop a connected product that directly competes with yours.
- No gatekeepers. Under Article 6(2)(d), data may not be routed to companies designated as gatekeepers under Regulation (EU) 2022/1925 (the DMA) when the request comes through Article 5.
"Access by design": the deadline that needs engineering
For connected products placed on the market after 12 September 2026, Article 3(1) requires data to be accessible to the user by default - easily, securely, free of charge, and in a structured, machine-readable format. In practice: the export interface belongs in the product spec, not in a backlog item labelled "on request."
Separately, Article 3(2) requires pre-contractual transparency - before signing, the customer must know what kind of data the product will generate, in what volume, at what frequency, and how they will access it. That information belongs in your terms and your product documentation.
A trade secret is not an emergency brake
The most common misconception: "our data is know-how, so we're not handing it over." The regulation does not accept that as a general ground. The mechanism runs in three steps:
- Identify in advance. You specify which concrete elements are trade secrets - before the request arrives, not after.
- Protective measures. You are entitled to impose conditions: an NDA, encryption, restricted access, technical and organisational measures. If the other side refuses to agree to them, your refusal to share is lawful.
- Full refusal - by exception. Article 4(8) permits withholding access only if you can demonstrate a high likelihood of serious and irreparable economic damage despite the measures applied.
What exactly clears the bar for "serious and irreparable damage" is still unknown - there is no CJEU case law. So the only sensible posture is procedural: a written risk assessment, documented reasoning, and a paper trail of the confidentiality measures you offered. A refusal with no file behind it is a refusal that will not survive scrutiny.
Data Act vs GDPR: the four collision points
Article 1(5) sets the hierarchy: the Data Act applies without prejudice to the GDPR and Directive 2002/58/EC. Where they conflict, data protection wins.
| Issue | The Data Act wants | The GDPR requires | What you do |
|---|---|---|---|
| Legal basis | You to hand the data over | A basis under Art. 6 | The Data Act is not itself a basis - demand proof before transferring |
| Mixed datasets | The whole data stream | Protection of the personal part only | Separate architecturally and anonymise |
| Volume | "All generated data" | Minimisation (Art. 5(1)(c)) | Granular export by category, not one large dump |
| Purpose | Reuse and innovation | Purpose limitation (Art. 5(1)(b)) | Contractually fix the recipient's purposes |
The most dangerous real-world scenario: the user requesting the data is not the data subject. The classic case - an employer asking for telematics from a company car driven by an employee. The Data Act obliges you to provide the data, but it does not give you an Article 6 GDPR basis to disclose the personal part of it. You need a separate basis, such as the employee's explicit consent.
Remember the pseudonymisation/anonymisation distinction too. Pseudonymised data remains personal data under Article 4(5) GDPR and needs a legal basis. Only full, irreversible anonymisation takes it out of scope.
Article 13: the clauses that become void
If you sell B2B, this is the section with the highest and most underestimated risk. Article 13 renders unilaterally imposed terms on data access and use unenforceable.
Blacklist (Art. 13(4)) - void outright:
- excluding or limiting liability for intent or gross negligence;
- fully excluding the other party's legal remedies.
Greylist (Art. 13(5)) - presumed unfair:
- restricting the other party's rights to use data it generated itself;
- unreasonably short termination notice periods.
The sanction isn't a fine - it's worse: the clause simply doesn't exist. The liability cap your whole pricing model rests on evaporates at the precise moment you need it.
From 12 September 2027 the rule extends to contracts signed before 2025. So your legacy long-term enterprise agreements need review too, not just the new ones.
On 2 April 2025 the European Commission published model contractual terms (MCTs) for data sharing and standard contractual clauses (SCCs) for cloud contracts. They are non-binding and not a safe harbour - using them doesn't guarantee compliance, but they give you a solid starting point in negotiation and a useful argument when the other side's counsel pushes for something plainly outside the frame.
Cloud: the end of the lock-in fee
If you offer IaaS, PaaS or SaaS, Chapter VI obliges you to remove the commercial and technical barriers to a customer leaving. The practical schedule:
- from 12 September 2025 - egress fees may only cover the direct costs actually incurred;
- from 12 September 2028 - any switching charge disappears entirely (EUR 0).
If you're on the other side of that - a buyer of cloud services - it's renewal-negotiation leverage you didn't have before.
One detail for blockchain teams: Article 36 imposes technical requirements on smart contracts, including a termination mechanism. In the Digital Omnibus package (staff working document SWD(2025) 836) the Commission proposed deleting Article 36 entirely, on the grounds that a "kill switch" requirement is incompatible with decentralised networks. Until the reform is adopted its status remains formally pending - don't build architecture around it, but don't write it off either.
If you're building AI on other people's data
The Data Act opens access to raw machine data, which is good news for anyone training models - including with an eye on the data-quality requirements of the AI Act.
The boundaries are clear:
- Shareable: the raw sensor data.
- Not shareable: model weights, internal parameters and derivative models - those are yours.
- Permitted: training a model on data you received, provided the end product is not a connected product that directly competes with the original within the meaning of Art. 4(4).
- Mandatory: a valid GDPR basis for all personal data in the training set. The Data Act does not supply one.
The public sector: when the state can demand data
Chapter V lets public sector bodies request data on a demonstrated "exceptional need." The scope is narrow, and worth knowing so that not every letter from an institution reads as an obligation:
- in a public emergency (disaster, pandemic), data is provided free of charge;
- for other tasks in the public interest you are entitled to compensation - costs plus a margin;
- under Article 18 you may object within 5 working days in an emergency and 15 working days otherwise, if you don't hold the data or the request is incomplete.
Penalties and risk priority
The penalty framework has two layers. For breaches of Chapter II (Articles 3-14), Article 40 refers to the GDPR authorities and the Article 83 GDPR thresholds - up to EUR 20 million or 4% of global annual turnover. Everything else is penalised under national law.
| Risk | Area | Who it hits | Timing |
|---|---|---|---|
| High | GDPR breach when sharing mixed datasets | Everyone | Immediate |
| High | Void Art. 13 clauses in B2B contracts | All B2B | Live since 12.09.2025 |
| Medium | No mechanism to export raw data | IoT and related services | Live since 12.09.2025 |
| Medium | Non-compliance with access by design | Hardware manufacturers | 12.09.2026 |
| Low | Charging for a cloud switch | SaaS and cloud providers | 12.09.2028 |
Bulgaria: the rules exist, the authority doesn't yet
The regulation applies directly and needs no national law to bind you. But the domestic enforcement framework is still unfinished.
A public consultation on preparing implementing legislation ran on the public consultations portal (document ID 10803-K). A dedicated Bulgarian act implementing the Data Act, or corresponding amendments to the Electronic Communications Act, have not yet been adopted and published in the State Gazette.
Nor has a national data coordinator been designated. Discussions continue on how to split powers between the data protection commission (CPDP), the communications regulator (CRC) and the Ministry of e-Government. All institutional appointments and the specific administrative penalty procedures remain pending until the national law is promulgated.
The practical read: the absence of a designated authority slows down inspections but does not suspend your obligations - all the more so because Chapter II penalties route through the CPDP's already functioning structure.
Checklist by startup type
I build IoT or connected hardware
- Inventory your data and separate raw sensor records from algorithmically computed metrics.
- Do you have a mechanism (API or portal) to export raw data on request? That deadline passed on 12.09.2025.
- Are products you place on the market after 12.09.2026 designed for direct access from the device itself?
- Is there a trade-secret protocol under Art. 4(8) - as a written risk assessment, not an email thread?
I run a SaaS platform
- Have your B2B contracts been reviewed for blacklisted Art. 13 clauses?
- Do your terms carry the Art. 3(2) information - the type, volume and frequency of generated data?
- Are pre-2025 legacy contracts scheduled for revision before 12.09.2027?
I provide cloud infrastructure or managed services
- Have clauses restricting migration to another provider been removed?
- Are egress fees reduced to actual direct costs?
- Is there a plan for zero switching charges from 12.09.2028?
I'm building AI on third-party data
- Is it contractually established that your product isn't a directly competing connected product under Art. 4(4)?
- Is there a valid GDPR basis for every piece of personal data in your training sets?
The Data Act isn't another administrative burden you discharge with a policy PDF. It changes who controls the data your product generates - and therefore who gets to build a business on it. Startups that know today exactly which of their fields are raw and which are their own intellectual property will negotiate from strength. The rest will learn the difference from their first serious access request.