The definitive guide to the Data Act: What i is and how is affects your business
Este contenido está disponible únicamente para socios BAIDATA.
Regístrate o accede con tu cuenta para verlo.
The entry into force of the EU Data Act has rewritten the rules of the digital economy. If your company manufactures connected devices (IoT), offers cloud services or bases its business model on data analytics, the Data Act already applies directly to you. We explain the key aspects of this regulation and how to adapt your technical and legal infrastructure to avoid penalties and seize new market opportunities.
The Data Act (Regulation (EU) 2023/2854) is a cross-cutting piece of legislation that sets out who can generate value from data and under what conditions. Prior to its introduction, the information generated by connected products tended to remain exclusively in the hands of the hardware manufacturer.
The main aim of this law, which came into general effect on 12 September 2025, is to democratise access to information, balance the bargaining power of SMEs against that of tech giants, and ensure that users have control over the data generated by their devices.

The regulation does not distinguish between sectors; it affects the entire data value chain. It will have a direct impact on you if your organisation is:
Complying with the Data Act involves adapting your legal processes and technical architecture. These are the three operational cornerstones of the regulation:
Users have the inalienable right to access the data generated by their devices and to share it with third parties easily, free of charge and in real time.
Since September 12, 2026, all new devices must ensure this accessibility by design (Art. 3.1). This mandatory opening up of APIs is already transforming entire sectors, as we analyse in detail in our post ‘The Data Act and Digital Health: The End of the Wearables’ Monopoly’.
The law explicitly protects SMEs. It nullifies any clause imposed unilaterally by a company with greater commercial clout that prevents the fair use, equitable exchange or legitimate exploitation of shared data.
Gone are the days of being tied to a single cloud provider due to technical barriers or prohibitive exit costs. Infrastructure providers are obliged to facilitate the migration of data and applications to rival platforms, based on open interoperability standards.
Understanding the regulation is the first step; the real challenge lies in implementing it. Allowing third parties to access your data – or receiving it yourself on a scalable basis – whilst validating user consent and complying with the GDPR, requires a robust infrastructure.
This is where sovereign data spaces become the ultimate technical tool. By using certified connectors and standardised vocabularies, your organisation can automate compliance with the Data Act, controlling who accesses what information, when and under what conditions.
Do you need to adapt your company’s business model to the requirements of the Data Act?
At BAIDATA, we provide you with the ecosystem, legal support and technical infrastructure to make a secure transition. Access exclusive technical documentation via our BAIDATA Library or become a partner to connect your systems directly to our Demonstration Centres.