E-Law

One Year of the EU Data Act: What Applies to Online Retailers—and What’s Coming on September 12, 2026

Sep 10, 2026·Author: Stephan Dunger·Last update: Oct 4, 2026

The EU Data Act has been in effect for a year—and most online stores have hardly noticed it. In part, this is understandable: Many obligations apply to manufacturers and cloud providers, not to retailers. But only to a certain extent—those who sell connected products already have information obligations today, and on September 12, 2026, the next phase of the regulation takes effect. It’s time for an honest assessment: What applies, who is affected, and what’s still to come.

At a Glance

  • The Data Act (Regulation (EU) 2023/2854) has been directly applicable in all EU member states since September 12, 2025 (Art. 50).
  • Already in effect: Anyone selling connected products must inform buyers about the product data generated before the contract is concluded (Art. 3, para. 2)—this obligation applies to the seller, not just the manufacturer.
  • Effective September 12, 2026: Connected products newly placed on the market must be designed so that users can directly access their data (“accessibility by design,” Art. 3(1))—this primarily applies to manufacturers.
  • For every retailer acting as a cloud customer: Switching hosting, SaaS, and cloud services will become easier (maximum 2-month notice period, regulated data export, Art. 25); Switching fees will be completely eliminated as of January 12, 2027 (Art. 29).
  • Germany: The Implementing Act (DADG) has been in effect since May 30, 2026; the competent authority and complaints office is the Federal Network Agency.
  • The Data Act is not a data protection law: The GDPR continues to apply unchanged in relation to personal data.

What is the Data Act—and who does it affect in the e-commerce sector?

The Data Act governs who owns the data generated by connected devices during operation—from fitness trackers to smart coffee makers to GPS tracking devices—and under what conditions cloud customers can switch providers. For online retailers, there are exactly two relevant roles: As sellers of connected products, they have their own information obligations (more on that in a moment). As customers of hosting, SaaS, and cloud services, they benefit from new rights to switch providers—here, the retailer is the beneficiary, not the party subject to obligations. For those who neither sell connected products nor enter into data contracts with other companies, the Data Act will have little impact on day-to-day business—let’s get that straight from the start.

What obligations do merchants who sell connected products have?

The most important rule for day-to-day shop operations has been in effect since September 12, 2025—and is still often overlooked today: According to Article 3(2) of the Data Act, the seller (“who may also be the manufacturer”) must clearly and comprehensibly inform the buyer of a connected product before the contract is concluded: what product data the device generates, in what format and to what extent; whether it generates data continuously and in real time; whether and for how long it stores data on the device or on a server—and how the user can access, retrieve, and delete this data. This also applies to pure resellers: Anyone listing smart home devices, wearables, GPS trackers, or smart home appliances should obtain this information from the manufacturer and make it available on the product page—in the XONIC Shop System, product tabs or additional fields are ideal for this purpose, ensuring the information is visible before purchase. Incidentally, one exemption applies to the manufacturer, not the size of the online store: Data from products manufactured by micro-enterprises or small businesses is exempt from the data disclosure requirements of this chapter (Art. 7).

What will change on September 12, 2026?

Starting September 12, 2026, the “Design” phase takes effect: Connected products and associated services placed on the market after this date must be designed so that users can access the generated data “easily, securely, and free of charge in a comprehensive, structured, commonly used, and machine-readable format” and—to the extent technically feasible—directly (Art. 3(1) in conjunction with Art. 50). This obligation applies primarily to manufacturers and importers, not to retailers. In practical terms, this means that for new products added to the product lineup starting in the fall of 2026, suppliers’ product data sheets should include the data access information right from the start—retailers who consistently request this information when purchasing will, as a result, also fulfill their own duty to provide information under Art. 3(2).

How does the Data Act benefit retailers as cloud customers?

The second aspect of the Data Act is relevant to any retailer who uses hosting, a SaaS store system, a cloud-based inventory management system, or online storage: Providers of data processing services must make it contractually and technically possible to switch to another provider (or to the retailer’s own infrastructure) —with a notice period of no more than two months to initiate the switch, a regulated transition period, data access for at least 30 days thereafter, and guaranteed deletion after a successful migration (Art. 25). Even today, switching fees may only be charged at a reduced rate to cover costs—and as of January 12, 2027, they may no longer be charged at all (Art. 29). Of particular practical relevance: Switching fees explicitly include data extraction fees —the much-discussed egress fees for downloading one’s own data (Art. 2 No. 36). Regular usage fees and agreed-upon penalties for early termination remain unaffected by this. This applies to all service models, including SaaS shop systems, cloud-based inventory management, and hosted email services. Anyone who feels locked in by their current provider now has, for the first time, an enforceable right to terminate the contract, including the right to export data—and a point of contact in case of problems (see below). Regardless of this, it is worth checking when choosing a system in which formats products, customers and orders can be exported.

Who enforces the Data Act in Germany—and what are the consequences of violations?

The German implementing law, the Data Regulation Application and Enforcement Act (DADG), has been in effect since May 30, 2026. The responsible authority is the Federal Network Agency: It serves as the central point of contact, informs the public, conducts national oversight, and operates a portal for complaints—which is also relevant for merchants who face obstacles when switching providers as cloud customers. The Federal Commissioner for Data Protection and Freedom of Information remains responsible for personal data (Section 16 DADG).

The DADG’s schedule of fines (§ 15) is tiered: up to €5 million for improper data incentives offered to users (for companies with total revenue exceeding €250 million, alternatively up to 2% of total revenue), up to €500,000 for , among other things, violations of the design requirement under Art. 3(1) and data provision obligations, and up to €100,000 and €50,000 for the remaining offenses. Noteworthy for retailers: The seller’s pre-contractual duty to provide information under Article 3(2) is not listed in this catalog —so retailers do not face an immediate threat of an administrative fine for this. However, this does not mean that the obligation is without consequences: specialized literature classifies it as a rule of market conduct, the violation of which can result in warnings from competitors and trade associations under competition law. The practical risk for retailers thus lies less with the authorities than with competitors.

The Data Act and the GDPR—What Applies to Personal Data?

The Data Act is data management law, not data protection law. As soon as product data is personal—which is often the case with devices used by end customers—the GDPR applies unchanged alongside it: legal bases, data subject rights, and erasure obligations remain in place; the Data Act does not create any new authorization for processing. For online store operators, therefore, nothing changes with regard to existing data protection processes; the two sets of regulations complement each other. We’ve summarized the fundamental requirements for a data protection-compliant online store system in our article “GDPR-Compliant Online Store System.”

The Timeline of the Data Act

DateRegulation
January 11, 2024Entry into force of Regulation (EU) 2023/2854.
As of September 12, 2025The Data Act applies immediately (Art. 50): including pre-contractual information obligations for the sale of connected products (Art. 3(2)), users’ rights of access to data, rights to switch cloud providers (Chap. VI), prohibition of unfair data clauses in newly concluded B2B contracts (Chapter IV).
Effective May 30, 2026German Implementation Act (DADG) in force: Federal Network Agency as the competent authority and complaints office; graduated fines.
Effective September 12, 2026“Accessibility by Design”: Newly placed on the market connected products and associated services must provide direct access to data (Art. 3(1) in conjunction with Art. 50).
Effective January 12, 2027Switching fees when changing providers of data processing services are completely prohibited (Art. 29(1)).
Effective September 12, 2027The provisions of Chapter IV also apply to existing contracts (entered into by September 12, 2025), provided they are open-ended or have a term extending at least through 2034 (Art. 50).

What should retailers do now?

  • Review your product lineup: Which items are “connected products” as defined by the Data Act (devices that can collect and transmit usage or environmental data)? Typical examples: smart home devices, wearables, GPS trackers, smart household and garden appliances, and connected tools.
  • Obtain manufacturer information: For these items, request the data specified in Art. 3(2) from the supplier and make it available on the product page—this requirement is already in effect.
  • Purchases starting in fall 2026: Pay attention to the design stage for new products—product data sheets should include data access information as standard in the future.
  • Review cloud contracts: Notice periods exceeding two months and flat-rate switching fees are no longer permitted for data processing services; as of January 12, 2027, no switching fees may be charged at all.
  • Leave GDPR processes unchanged: The Data Act does not replace data protection obligations—nor does it create a new legal basis.

Note: This article does not constitute legal advice (as of the editorial deadline). Binding information regarding your specific product range and contracts can be obtained from specialized law firms and the Chambers of Industry and Commerce.

Frequently Asked Questions About the Data Act

No. Essentially, only those who sell connected products (pre-contractual information obligations under Art. 3(2)) or control device data as data controllers have specific obligations. For all other retailers, the Data Act primarily affects them as beneficiaries—for example, through the new rights to switch providers with regard to cloud and SaaS providers.

An object that collects data about its use or environment and can transmit this data via a communication connection or device access—and whose primary function is not the storage or processing of data for third parties (Art. 2(5) of the Data Act). Examples: fitness trackers, smart thermostats, GPS tracking devices, connected home appliances. A standard laptop or smartphone, as a device used solely for processing data, is not covered.

Yes. Art. 3(2) of the Data Act explicitly addresses the “seller, lessor, or lessor—who may also be the manufacturer.” Anyone offering connected products must provide the data information before the contract is concluded—even if they do not manufacture the products themselves. It makes sense for the manufacturer to provide the information; the retailer then incorporates it into the product page.

In Germany, the Implementation Act (DADG), which has been in effect since May 30, 2026, sets out a graduated scale of fines: up to 5 million euros for impermissible data incentives offered to users; up to 500,000 euros for violations of the design requirement and data provision obligations, among other things, including tiers of up to 100,000 and 50,000 euros. The Federal Network Agency is responsible for enforcing the law; for personal data, the Federal Commissioner for Data Protection is responsible. However, the seller’s pre-contractual duty to provide information under Art. 3(2) is not listed in the schedule of fines—in this case, a warning under competition law is the primary practical risk.

No. The Data Act regulates access to device data and contractual relationships in the data economy. As soon as data is personal, the GDPR applies in full alongside it—the Data Act does not create a new legal basis for its processing.

Sources

Stephan Dunger
About the author

Stephan Dunger

Lead developer & store system expert · XONIC Solutions GmbH · With the company since 2012

Stephan Dunger is one of the brains behind the XONIC store system. He has been developing the platform together with the team since 2012 - from the database to the interfaces to the checkout.

A passionate programmer, technical mind and consultant at the same time: with his in-depth knowledge of store systems and e-commerce, Stephan combines the depth of a developer with an eye for the big picture. Together with the XONIC team, he shapes the technical direction, consistently thinks about functions from the retailer's perspective and advises on customized solutions.

The result is software with a face: customers don't get an anonymous provider, but a direct line to the people who develop XONIC. Pragmatic, fast and at eye level.

Customer testimonials

write review
Never miss a thing.

Legal updates and new features straight to your inbox.

Subscribe to the newsletter