EU Data Act

European UnionTrade & Export2024
ByDecipherU Editorial

The EU Data Act governs cybersecurity and data sharing for IoT devices and cloud services, effective September 12, 2025. It requires IoT product manufacturers to make data generated by their products accessible to users and third parties. Cloud service providers must support customer switching and ensure contractual transparency about data processing and security measures.

Quick Reference

EnactedAdopted December 13, 2023; applicable September 12, 2025
Enforcement BodyNational authorities designated by member states
PenaltiesDetermined by member states; must be effective, proportionate, and dissuasive
Applicable ToIoT product manufacturers, cloud and edge service providers, data holders

Key Requirements

Article 3 (Obligation to make data accessible to the user)

Products must be designed and manufactured so that data generated by their use is accessible to the user by default

Article 23 (Technical protection measures)

Data holders may apply appropriate technical protection measures to prevent unauthorized access and ensure compliance with data sharing obligations

Article 30 (Switching between data processing services)

Cloud service providers must remove contractual, technical, and organizational barriers to switching, including ensuring data portability

How Does EU Data Act Affect Cybersecurity Careers?

IoT security professionals must understand how the Data Act affects device design and data accessibility. Cloud security architects need to build switching and portability capabilities. Cybersecurity engineers at IoT companies must balance data accessibility with security, protecting against unauthorized access.

How Does EU Data Act Affect Cybersecurity Sales?

IoT security, data access management, and cloud portability solutions all address Data Act requirements. Vendors offering secure data sharing platforms can position around the Act's accessibility mandates. Cloud providers must invest in switching capabilities, creating opportunities for migration and integration security tools.

Cybersecurity Roles That Work With EU Data Act

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of EU Data Act at the official source: https://eur-lex.europa.eu/eli/reg/2023/2854/oj

Frequently Asked Questions

The EU Data Act governs cybersecurity and data sharing for IoT devices and cloud services, effective September 12, 2025. It requires IoT product manufacturers to make data generated by their products accessible to users and third parties. Cloud service providers must support customer switching and ensure contractual transparency about data processing and security measures.

IoT security professionals must understand how the Data Act affects device design and data accessibility. Cloud security architects need to build switching and portability capabilities. Cybersecurity engineers at IoT companies must balance data accessibility with security, protecting against unauthorized access.

Determined by member states; must be effective, proportionate, and dissuasive

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?