The EU Data Act has been in effect for a year—and most online stores have hardly noticed it. In part, this is understandable: Many obligations apply to manufacturers and cloud providers, not to retailers. But only to a certain extent—those who sell connected products already have information obligations today, and on September 12, 2026, the next phase of the regulation takes effect. It’s time for an honest assessment: What applies, who is affected, and what’s still to come.
At a Glance
- The Data Act (Regulation (EU) 2023/2854) has been directly applicable in all EU member states since September 12, 2025 (Art. 50).
- Already in effect: Anyone selling connected products must inform buyers about the product data generated before the contract is concluded (Art. 3, para. 2)—this obligation applies to the seller, not just the manufacturer.
- Effective September 12, 2026: Connected products newly placed on the market must be designed so that users can directly access their data (“accessibility by design,” Art. 3(1))—this primarily applies to manufacturers.
- For every retailer acting as a cloud customer: Switching hosting, SaaS, and cloud services will become easier (maximum 2-month notice period, regulated data export, Art. 25); Switching fees will be completely eliminated as of January 12, 2027 (Art. 29).
- Germany: The Implementing Act (DADG) has been in effect since May 30, 2026; the competent authority and complaints office is the Federal Network Agency.
- The Data Act is not a data protection law: The GDPR continues to apply unchanged in relation to personal data.
What is the Data Act—and who does it affect in the e-commerce sector?
The Data Act governs who owns the data generated by connected devices during operation—from fitness trackers to smart coffee makers to GPS tracking devices—and under what conditions cloud customers can switch providers. For online retailers, there are exactly two relevant roles: As sellers of connected products, they have their own information obligations (more on that in a moment). As customers of hosting, SaaS, and cloud services, they benefit from new rights to switch providers—here, the retailer is the beneficiary, not the party subject to obligations. For those who neither sell connected products nor enter into data contracts with other companies, the Data Act will have little impact on day-to-day business—let’s get that straight from the start.
What obligations do merchants who sell connected products have?
The most important rule for day-to-day shop operations has been in effect since September 12, 2025—and is still often overlooked today: According to Article 3(2) of the Data Act, the seller (“who may also be the manufacturer”) must clearly and comprehensibly inform the buyer of a connected product before the contract is concluded: what product data the device generates, in what format and to what extent; whether it generates data continuously and in real time; whether and for how long it stores data on the device or on a server—and how the user can access, retrieve, and delete this data. This also applies to pure resellers: Anyone listing smart home devices, wearables, GPS trackers, or smart home appliances should obtain this information from the manufacturer and make it available on the product page—in the XONIC Shop System, product tabs or additional fields are ideal for this purpose, ensuring the information is visible before purchase. Incidentally, one exemption applies to the manufacturer, not the size of the online store: Data from products manufactured by micro-enterprises or small businesses is exempt from the data disclosure requirements of this chapter (Art. 7).
What will change on September 12, 2026?
Starting September 12, 2026, the “Design” phase takes effect: Connected products and associated services placed on the market after this date must be designed so that users can access the generated data “easily, securely, and free of charge in a comprehensive, structured, commonly used, and machine-readable format” and—to the extent technically feasible—directly (Art. 3(1) in conjunction with Art. 50). This obligation applies primarily to manufacturers and importers, not to retailers. In practical terms, this means that for new products added to the product lineup starting in the fall of 2026, suppliers’ product data sheets should include the data access information right from the start—retailers who consistently request this information when purchasing will, as a result, also fulfill their own duty to provide information under Art. 3(2).
How does the Data Act benefit retailers as cloud customers?
The second aspect of the Data Act is relevant to any retailer who uses hosting, a SaaS store system, a cloud-based inventory management system, or online storage: Providers of data processing services must make it contractually and technically possible to switch to another provider (or to the retailer’s own infrastructure) —with a notice period of no more than two months to initiate the switch, a regulated transition period, data access for at least 30 days thereafter, and guaranteed deletion after a successful migration (Art. 25). Even today, switching fees may only be charged at a reduced rate to cover costs—and as of January 12, 2027, they may no longer be charged at all (Art. 29). Of particular practical relevance: Switching fees explicitly include data extraction fees —the much-discussed egress fees for downloading one’s own data (Art. 2 No. 36). Regular usage fees and agreed-upon penalties for early termination remain unaffected by this. This applies to all service models, including SaaS shop systems, cloud-based inventory management, and hosted email services. Anyone who feels locked in by their current provider now has, for the first time, an enforceable right to terminate the contract, including the right to export data—and a point of contact in case of problems (see below). Regardless of this, it is worth checking when choosing a system in which formats products, customers and orders can be exported.
Who enforces the Data Act in Germany—and what are the consequences of violations?
The German implementing law, the Data Regulation Application and Enforcement Act (DADG), has been in effect since May 30, 2026. The responsible authority is the Federal Network Agency: It serves as the central point of contact, informs the public, conducts national oversight, and operates a portal for complaints—which is also relevant for merchants who face obstacles when switching providers as cloud customers. The Federal Commissioner for Data Protection and Freedom of Information remains responsible for personal data (Section 16 DADG).
The DADG’s schedule of fines (§ 15) is tiered: up to €5 million for improper data incentives offered to users (for companies with total revenue exceeding €250 million, alternatively up to 2% of total revenue), up to €500,000 for , among other things, violations of the design requirement under Art. 3(1) and data provision obligations, and up to €100,000 and €50,000 for the remaining offenses. Noteworthy for retailers: The seller’s pre-contractual duty to provide information under Article 3(2) is not listed in this catalog —so retailers do not face an immediate threat of an administrative fine for this. However, this does not mean that the obligation is without consequences: specialized literature classifies it as a rule of market conduct, the violation of which can result in warnings from competitors and trade associations under competition law. The practical risk for retailers thus lies less with the authorities than with competitors.
The Data Act and the GDPR—What Applies to Personal Data?
The Data Act is data management law, not data protection law. As soon as product data is personal—which is often the case with devices used by end customers—the GDPR applies unchanged alongside it: legal bases, data subject rights, and erasure obligations remain in place; the Data Act does not create any new authorization for processing. For online store operators, therefore, nothing changes with regard to existing data protection processes; the two sets of regulations complement each other. We’ve summarized the fundamental requirements for a data protection-compliant online store system in our article “GDPR-Compliant Online Store System.”
The Timeline of the Data Act
| Date | Regulation |
|---|---|
| January 11, 2024 | Entry into force of Regulation (EU) 2023/2854. |
| As of September 12, 2025 | The Data Act applies immediately (Art. 50): including pre-contractual information obligations for the sale of connected products (Art. 3(2)), users’ rights of access to data, rights to switch cloud providers (Chap. VI), prohibition of unfair data clauses in newly concluded B2B contracts (Chapter IV). |
| Effective May 30, 2026 | German Implementation Act (DADG) in force: Federal Network Agency as the competent authority and complaints office; graduated fines. |
| Effective September 12, 2026 | “Accessibility by Design”: Newly placed on the market connected products and associated services must provide direct access to data (Art. 3(1) in conjunction with Art. 50). |
| Effective January 12, 2027 | Switching fees when changing providers of data processing services are completely prohibited (Art. 29(1)). |
| Effective September 12, 2027 | The provisions of Chapter IV also apply to existing contracts (entered into by September 12, 2025), provided they are open-ended or have a term extending at least through 2034 (Art. 50). |
What should retailers do now?
- Review your product lineup: Which items are “connected products” as defined by the Data Act (devices that can collect and transmit usage or environmental data)? Typical examples: smart home devices, wearables, GPS trackers, smart household and garden appliances, and connected tools.
- Obtain manufacturer information: For these items, request the data specified in Art. 3(2) from the supplier and make it available on the product page—this requirement is already in effect.
- Purchases starting in fall 2026: Pay attention to the design stage for new products—product data sheets should include data access information as standard in the future.
- Review cloud contracts: Notice periods exceeding two months and flat-rate switching fees are no longer permitted for data processing services; as of January 12, 2027, no switching fees may be charged at all.
- Leave GDPR processes unchanged: The Data Act does not replace data protection obligations—nor does it create a new legal basis.
Note: This article does not constitute legal advice (as of the editorial deadline). Binding information regarding your specific product range and contracts can be obtained from specialized law firms and the Chambers of Industry and Commerce.
