Appoint us
Authorities applying the Data Act and the GDPR to the same connected device

REP27 · Data Act · Compared

Regulation 2023/2854 · Regulation 2016/679 · overlap

Data Act and GDPR: same device, two regimes.

A connected product produces a stream of readings. Some of those readings identify a person, most do not, and both kinds travel through the same pipeline. The GDPR governs the first category and has done for years. The Data Act governs the whole stream as data generated by use, and gives the user a right to reach it. Neither replaces the other, the overlap is genuine, and the practical question is not which one applies but which duty attaches to which piece of data.

Personal dataNon-personal dataUser rightsAccessBoth mandates

Request this service   Ask a question

Scope, side by side

The Data Act and the GDPR compared by scope, rights and representation
The Data Act and the GDPR compared by scope, rights and representation

The first line on each side is the whole difference. The GDPR asks whether data relates to an identified or identifiable person. The Data Act asks whether data was generated by the use of a connected product. A machine reading with no person attached is invisible to one regime and central to the other.

Four cases where they meet

Four situations where the Data Act and the GDPR apply to the same data
Four situations where the Data Act and the GDPR apply to the same data
The rule of thumb that survives contact with reality: run the Data Act analysis on the stream, then run the GDPR analysis on the part of it that identifies people. Doing it in the other order produces a privacy project that misses most of the obligation.

Eight differences worth knowing

PointData ActGDPR
Data coveredPersonal and non-personal, generated by product usePersonal data only
Who holds the rightThe user of the product, business or consumerThe data subject, a natural person
Core rightAccess to product data and sharing with a chosen third partyAccess, rectification, erasure, portability and more
Legal basisDoes not create one for personal dataArticle 6 basis always required
RepresentativeRequired for entities outside the UnionRequired under Article 27
Where publishedPre-contractual informationPrivacy notice, Article 13(1)(a)
EnforcementNational competent authorities designated by Member StatesData protection authorities
PenaltiesSet nationally, effective and dissuasiveUp to €20 million or 4%, or €10 million or 2% depending on the article

What to do when both apply

  1. Classify the stream once

    One data dictionary, with a column marking which fields are personal. Two separate inventories is how contradictions get published.

  2. Keep the legal basis question separate

    The Data Act obliges you to make data available; it does not authorise you to process personal data for your own purposes. That still needs a GDPR basis.

  3. Watch third-party transmission

    When a user sends product data to a recipient and it contains personal data, the GDPR travels with it. Contracts and roles have to be settled before the first request.

  4. Publish in two places

    The Article 27 representative in the privacy notice, the Data Act representative in the pre-contractual information. Same entity if you like, different documents.

  5. Answer from one desk

    Requests do not arrive labelled with a regulation. One inbox, one log, one process, then route internally.

Common misreadings

"Our GDPR programme covers it"

It covers the personal part. Machine readings with no person attached fall entirely outside it and are the bulk of most industrial products.

"The Data Act gives us a basis to process"

It does not. Making data available to the user is an obligation; using it yourself still needs an Article 6 basis.

"One representative covers both"

One provider can, with two mandates. One mandate cannot, because they are different regulations with different scopes.

"Anonymised data escapes both"

Genuinely anonymous data escapes the GDPR. It does not escape the Data Act, which does not care whether data is personal.

"Business customers have fewer rights"

Under the GDPR they are not data subjects; under the Data Act they are users with the full access right. The reverse of what people assume.

"We can refuse for competitive reasons"

Only trade secrets, with safeguards, and only on the narrow grounds the regulation sets out.

Which mandates a connected device company ends up holding

This is the practical summary that most companies want and rarely find written down in one place.

If youYou need
Sell a connected product into the Union from outside itData Act representative, Article 27 GDPR representative, Article 16 GPSR responsible person
Also provide the cloud service behind itAdd NIS2 if cloud computing is offered as a service in the Union
Sell software or firmware with digital elementsConsider the CRA authorised representative, optional but decisive for the reporting route
Sell only to customers outside the UnionNone of the above
Have a real operating entity in the UnionNo representatives; the entity itself carries the duties

The overlap in practice: one request, two regimes

The clearest way to see how the two laws interact is to follow a single request through both, which is what actually happens when a user asks for data that contains personal elements.

StepData Act questionGDPR question
Request arrivesIs the requester the user of the product?Is any of the data personal, and whose?
Scope the answerWhich fields are product or related service data?Which fields identify a person?
Check limitsTrade secrets, safety, security restrictionsRights and freedoms of others, third-party data
DeliverMachine-readable, same quality, without undue delaySecure transmission, minimisation where relevant
To a third partyPermitted at the user's request, with recipient limitsRoles, basis and contract for the personal part
Record itLog for the competent authorityRecords under Article 30

Two columns, one process. Companies that build separate workflows for each regulation end up sending contradictory answers to the same customer, which is worse than being slightly late. One inbox, one log, one decision per request, with both questions asked at each step.

Why the Data Act catches people who thought they were finished

Industrial companies

Machine data is usually non-personal, so a mature GDPR programme covers almost none of it. The Data Act is the first European data regime that reaches them properly.

Companies selling only B2B

Under the GDPR that reduces exposure; under the Data Act it does not, because business users hold the access right.

Companies with anonymisation pipelines

Anonymisation is a GDPR answer. It does nothing under a regulation that applies regardless of whether data is personal.

Hardware companies without a privacy function

Nobody owns this internally, so it arrives as a customer complaint rather than as a project.

The short version

The GDPR asks whether data relates to a person; the Data Act asks whether data was generated by the use of a connected product. On a modern device both questions get a yes for part of the stream and a no for the rest, so both regimes apply to the same pipeline with different scopes. Neither creates a legal basis for the other, neither designation satisfies the other, and the practical answer is one data dictionary, one request process and two mandates held with the same provider so that a request never lands somewhere nobody is watching.

A checklist you can run in an hour

Six questions that place any connected product company on the map of both regimes, answered honestly and written down with a date.

  1. Does the product generate data through use?

    If yes, the Data Act is in play regardless of whether any of it is personal.

  2. Does any of that data identify a person?

    If yes, the GDPR applies to that part, with its own basis, notice and rights.

  3. Is any entity of ours established in the Union?

    If no, both regulations require a representative, and they are two separate mandates.

  4. Where do we publish each one?

    Privacy notice for Article 27, pre-contractual information for the Data Act.

  5. Who receives a request?

    One address, monitored, with a log. Requests do not arrive labelled by regulation.

  6. What can we not hand over?

    Derived data and identified trade secrets, with safeguards prepared for the second category.

If the answers to the first three are yes, yes and no, you need both designations and the only real decision left is whether they sit with one provider or two.

One sentence to take away

If your product generates data through use, the Data Act reaches all of that data and the GDPR reaches only the part that identifies people; both require a representative when you are established outside the Union, both are published in different documents, and the only sensible arrangement is one provider, two mandates and one process that asks both questions about every request that arrives.

Where each regime came from

The two laws read differently because they were written for different problems, and knowing the problem explains most of the drafting.

The problem it was written forHow that shows in the text
GDPRIndividuals losing control of information about themRights attach to a natural person, with a lawful basis required for every processing
Data ActData from machines locked inside the manufacturers that made themRights attach to whoever uses the product, with access as the default and design duties on the maker

That is why the Data Act says almost nothing about consent and a great deal about formats, and why the GDPR says almost nothing about formats and a great deal about basis and purpose. Applying the reflexes of one to the other is what produces the two classic errors: treating a Data Act request as a subject access request, and assuming a mature privacy programme has already covered machine data it never touched.

A worked example, end to end

Abstractions are hard to apply. Here is a single device followed through both regimes, which is usually the fastest way to see where the line falls.

Data the device producesData ActGDPR
Motor temperature, once per secondProduct data, user can obtain itNot personal, outside
Operating hours and cyclesProduct dataNot personal unless tied to one worker
Location traces during useProduct dataPersonal where the user is a person or the driver identifiable
The operator's login and shiftRelated service dataPersonal data, full GDPR duties
Predicted failure score we computedDerived, stays with the holderPersonal only if it relates to a person
Support chat transcriptsNot generated by product usePersonal data

Row five is where most arguments happen, and it is worth being precise: the raw inputs are the user's to reach, the model output is yours. Row three is where the two regimes genuinely overlap, and the correct handling is to satisfy the Data Act request while applying the GDPR to the personal part of what leaves your systems.

The short version

One regime protects people, the other opens data generated by machines, and a connected device produces both kinds through the same pipeline. Run the Data Act analysis on the whole stream and the GDPR analysis on the part that identifies people. Publish the Article 27 representative in your privacy notice and the Data Act representative with your pre-contractual information. Hold both mandates with one provider, on one renewal date, so that when a request arrives nobody has to work out which inbox it belongs in first.

Comparing Data Act and GDPR duties for a connected product
Comparing Data Act and GDPR duties for a connected product
Prague office holding both the Data Act and the Article 27 mandate

Questions we are actually asked

Does the Data Act replace the GDPR?

No. They apply in parallel. The GDPR continues to govern personal data in full, including data that is also product data.

Does the Data Act cover non-personal data?

Yes, and that is its main difference from the GDPR. Machine readings with no person attached are squarely inside it.

Do we need two representatives?

Two mandates, yes, one under each regulation. One provider can hold both, with separate designations and certificates.

Does the Data Act give us a legal basis to process personal data?

No. It obliges you to make data available; your own processing still needs an Article 6 basis under the GDPR.

Who is the user under the Data Act?

The person or company that owns, rents or leases the connected product, or receives the related service. Businesses included.

Is this the same as GDPR portability?

No. Article 20 GDPR covers personal data provided by the data subject. The Data Act covers data generated by product use, whoever it relates to.

What if data is anonymised?

It leaves the GDPR but stays inside the Data Act, because the Data Act does not depend on data being personal.

Which authority enforces the Data Act?

Competent authorities designated by each Member State, with data protection authorities supervising the personal data aspects.

Can a user send personal data to a third party through us?

Yes, and when they do, GDPR obligations follow the data. Settle roles and contracts before the first request.

Do business customers have data subject rights?

No, they are not natural persons. They do have the full Data Act access right, which is broader in this specific context.

Where do we publish each representative?

The Article 27 one in the privacy notice; the Data Act one with the pre-contractual information.

Are the penalties the same?

No. GDPR ceilings are set in the regulation; Data Act penalties are set nationally and must be effective, proportionate and dissuasive.

Does one designation satisfy both?

No. Different regulations require different mandates, even when the same entity signs both.

What if we only handle industrial data?

Then the GDPR may barely apply and the Data Act applies fully. That is the case most companies underestimate.

Does the Data Act apply to software alone?

It applies to connected products and related services. Pure software without a connected product is generally outside, though cloud switching rules may still catch you.

Do micro enterprises escape both?

Micro and small enterprises are largely carved out of the Data Act sharing duties. The GDPR has no such carve-out.

How fast can both mandates be signed?

Both within 24 hours of a completed form and a short call, with two certificates and one renewal date.

What does the pair cost?

€490 for the Data Act designation, with a combined price when held together with the Article 27 mandate.

Related: the Data Act mandate · the Article 27 test

Two mandates, one provider, one renewal

The Data Act representative and the Article 27 GDPR representative from Europe Services, SE in Prague, each with its own certificate and verification code.

Request this service