← All frameworks
🇪🇺EUArticle 40

EU Data Act.

The EU Data Act establishes rules on data access and sharing, particularly for IoT-generated data. It gives users the right to access data generated by connected products and requires fair data sharing contracts.

Maximum penalty

€10M or 2% global turnover

Source: Article 40

Key requirements

User access to IoT-generated data

Fair data sharing contract terms

Data portability for cloud switching

Government access to private data in emergencies

+1 more requirements in the complete guide.

Get the full EU Data Act compliance guide →

Enforcement examples

Application from September 2025

Full application from September 12, 2025

-

2025

How Tessera automates EU Data Act compliance

IoT data access compliance tracking

Data sharing agreement management

Cloud switching facilitation monitoring

Data portability evidence collection

EU Data Act compliance checklist

Essential steps to achieve and maintain EU Data Act compliance.

1

Map IoT data flows and access rights

2

Review data sharing contracts for fairness

3

Implement data portability for cloud services

Industries affected

Technology & SaaS

Calculate your EU Data Act exposure.

See exactly how EU Data Act penalties apply to your revenue and industry profile.