Databoostr meets all EU Data Act requirements

Here's what the EU Data Act asks of connected-product manufacturers, and exactly how Databoostr covers each part.

EU Data Act article
The requirement
What it means
How Databoostr covers it
Art. 3
Direct access by design
New products must give users easy, direct access to data
Access built into the product experience and your apps from day one
Art. 3 (2-3)
Transparency before sale
Users must be told what data a product generates
A clear data catalogue you can surface to customers
Art. 4
Data access for users
Customers can reach the data their product generates
A customer-facing portal, on the web or inside your apps
Art. 4(1)
Secure delivery
Data made available easily, securely, and in a machine-readable format
Secure packaging and delivery: live or on-demand
Art. 4(6-8)
Protecting trade secrets
Sensitive data must not leak through sharing
Data catalogue and filtering define what’s shareable, and what never is
Art. 5
Sharing with third parties
Users can send their data to the partners they choose
Governed B2B access, scoped to exactly what's authorized
Art. 5
Consent & authorization for third-parties
Every share must be authorized and controllable
Consent management with role-based access control, fully revocable
Arts. 3-5
Proof of compliance
You have to show that shares were lawful
A timestamped audit trail of every access and consent, one export away
The cost of getting it wrong:
fines up to EUR 20 million, or 4% of worldwide annual turnover.

Ready for what's next

The EU Data Act won't be the last regulation you face. Databoostr's modular design already extends to:

Right-to-Repair (US)

Direct access to vehicle data for owners and repair shops, in force in states like Maine and Massachusetts.

FIDA (EU financial data access)

The coming framework for sharing financial data.

Future amendments

Deployments are designed to adapt to member-state law and changes over time.

What is the EU Data Act?

The EU Data Act (Regulation (EU) 2023/2854) is EU law that governs access to the data generated by connected products and related services. It gives users — the people and businesses who own or use a connected product — the right to access the data it generates, and to share that data with third parties they choose.

It applies to manufacturers and data holders placing connected products on the EU market, regardless of where the company is based. It has been in force since January 2024, with data-access obligations applying from 12 September 2025 and direct-access-by-design from 12 September 2026. Non-compliance can lead to fines of up to EUR 20 million, or 4% of worldwide annual turnover.

Who does the EU Data Act apply to?

Any manufacturer of a connected product — vehicles, appliances, machinery, tools, batteries and more — placed on the EU market, regardless of where the company is based.

How is it different from the GDPR?

The GDPR governs personal data and privacy. The EU Data Act governs access to the data that connected products generate, personal and non-personal, and the right to share it.

What are the penalties for non-compliance?

Fines of up to EUR 20 million, or 4% of worldwide annual turnover.

Where the EU Data Act stands today

The last compliance deadline is here.

11 January 2024

The EU Data Act

The EU Data Act comes into force.

12 September 2025

Data-sharing and information obligation

Customers can request the data your products generate, for themselves or for third parties. This applies now.

12 September 2026

Direct-access obligation

New connected products must let users access their data directly, by design.