Article content
In briefShow moreShow lessThe regulation governs access to and sharing of data from connected products, along with selected cloud-service arrangements.
- The regulation governs access to and sharing of data from connected products, along with selected cloud-service arrangements.
- It supports switching providers, interoperability and protection against unfair contractual terms and unlawful third-country access.
- The date applied in the EU and did not automatically start the rules in Norway.
The Data Act started applying in the EU on 12 September 2025. Its central measure is that a user of a connected product should be able to access data generated by that product and, in defined circumstances, request that the data be shared with a third party. This may change how manufacturers, service providers and business customers organise data flows around machinery, vehicles, sensors and other networked products.
The regulation does not mean that every item of information must be released without controls. It requires structured access arrangements while taking account of security, trade secrets and other protective interests. Those interests must form part of implementation, but they cannot become a general basis for refusing all access to product data.
Third-party sharing is another important area. Users may gain a more practical role in deciding who receives relevant data, while data holders must manage requests, contractual relationships and technical interfaces. Organisations should therefore map which data is generated, who controls it and which legitimate purposes the sharing could support.
For cloud services, the rules support switching providers and interoperability. This affects lock-in, technical dependencies, data extraction and the ability to move workloads. A transition may still require careful planning for identities, security controls, logs, encryption and integrations.
The regulation also addresses unfair contractual terms in business-to-business agreements. Standard terms that shift risk unilaterally or unreasonably restrict statutory rights may need to be reassessed. Procurement, product design and supplier governance should be considered together rather than as separate compliance exercises.
There are also safeguards concerning access from third countries. Organisations should assess where data, administration functions and subcontractors are located and what requests might arise. This is part of implementing the framework; it is not a reason to make all data unavailable.
Norwegian organisations must distinguish EU application from Norwegian law. Norway required EEA incorporation and national implementation, while groups with EU products or cloud customers could still be affected through their EU operations. The territorial and contractual reach therefore needed to be assessed for each service or product arrangement.
Sources
European Commission: “EU Data Act gives users control over connected-device data,” 12 September 2025.
EUR-Lex: “Regulation (EU) 2023/2854 – Data Act,” 22 December 2023.
For discussion
Which product data should the organisation make accessible, and how can access be combined with security, trade-secret protection and controlled provider switching?

