KPMG Law LLP logo

12 August 2026

Overview

The EU Data Act (Regulation (EU) 2023/2854) ("the Data Act") came into force on 11 January 2024. The first provisions of the Data Act to become applicable across the EU came into force on 12 September 2025, with the remaining provisions rolling out on a phased basis since.

Two major changes affecting a range of product and service providers are now due to come into force in 2026 and 2027.

KPMG Law LLP summarises the key developments below.

The Data Act - Background

The Data Act creates a harmonised framework to respond to the needs of the digital economy, removing barriers to data sharing and ultimately promoting a well-functioning EU internal market. In particular, the Data Act ensures users of a connected product or related services can access and share the data generated by their use of the product with third-parties of their choice. Data access must be provided under fair, reasonable and non-discriminatory terms and conditions and in a transparent and timely manner.

The Data Act also promotes easier data-switching for data users between product/service providers. Data holders are therefore subject to enhanced obligations to make data available and face increasing scrutiny of contractual arrangements, data governance, storage and retrieval mechanisms, and related processes.

Failure to comply with obligations under the Data Act exposes data holders to penalties (including administrative fines) which vary in severity across EU Member States.

Affected parties

The Data Act applies across all EU Member States and extends to non-EU businesses selling products or services in the EU, which must appoint an EU representative. Significantly affected parties include:

  1. Manufacturers of smart devices and/or connected products;
  2. Providers of related services (underlying software of technology etc);
  3. Cloud storage/service providers (SaaS, PaaS, IaaS);
  4. Data recipients (third party recipients).

Exempt parties include:

  1. Micro and small enterprises (enterprises with fewer than 50 employees and annual turnover of up to €50 million);
  2. New companies (medium-sized enterprises) in existence for less than one year.

Exemption does not preclude any duty on small/medium sized enterprises to ensure fair terms in business to business (B2B) and business to consumer (B2C) contracts including the ability for users to switch to competitors.

Upcoming deadlines in 2026 and 2027

The following Articles will come into effect across 2026 and 2027, introducing stringent changes for affected parties:

Next steps for affected organisations

  1. Design stage review and planning in relation to development of connected products;
  2. Review, remediation and alignment of existing data-sharing and cloud contracts to the updated regulatory requirements;
  3. Continued monitoring of ongoing regulatory updates, phased roll-out of the Data Act and upcoming Digital Omnibus proposals;
  4. Review of the national enforcement landscape of the relevant EU member state(s) which the organisation operates in.

Conclusion

Organisations should pro-actively respond to the Data Act in terms of how they manage data access and portability. While major changes under the Data Act already took effect in 2025, enterprises must remain alert as further changes are rolled out across 2026 and 2027.

How KPMG Law LLP can help

KPMG Law LLP offers multi-disciplinary regulatory, compliance, legal and advisory services, helping organisations manage change and meet their obligations with confidence. With experience supporting businesses of all sizes, our team is positioned to assist organisations as they navigate the evolving regulatory landscape. 

Contact the team

Yvonne quinn

Yvonne Quinn

Director

Discover more in Data Protection & Privacy Law