Data Act & DA-DG: The New Rulebook for Germany's Digital Economy

Martin Bastius
23.04.2026
5
min.

Use AI to summarize this article

Introduction: The Dawn of Data Fairness

As of the start of 2026, the transition period for the EU Data Act has largely expired. What began as an ambitious project to strengthen the European digital economy is now lived reality in the legal departments and IT hubs of German businesses. But while the EU regulation sets the guardrails, the national Data Act Implementation Law (DA-DG) provides the engine for enforcement.

The law aims to democratize the value of data — particularly non-personal industrial data. Until now, valuable information was often trapped in the silos of connected-product manufacturers or large cloud providers. The law now ensures this data can flow freely, fostering innovation, competition, and sovereignty. For German B2B companies, this is both an opportunity and a challenge: they now need to redefine their own role within this new value chain.

The Legal Anchor in Germany

As a regulation, the EU Data Act applies directly, but it leaves member states room to shape its institutional implementation. Germany's Implementation Law fills these gaps. It primarily governs three areas:

  1. Jurisdiction: It designates the Federal Network Agency (BNetzA) as the central data coordinator.
  2. Sanctions: It defines the fine amounts and enforcement powers for violations.
  3. Procedures: It establishes how complaints from users and businesses are filed and processed.

The law ensures that the theoretical right to data access can actually be enforced in Germany's courts.

Who Is Obligated? The Stakeholders in Focus

The reach of this law is often underestimated. It affects nearly every business that uses or provides digital interfaces:

  • Manufacturers of connected products (IoT): From connected machine tools to smart fleet vehicles to medical diagnostic devices. Anyone building hardware that captures data becomes a "data holder."
  • Providers of related services: Software companies whose programs communicate directly with IoT devices and generate or process data in the process.
  • Cloud and edge providers: Providers of computing capacity and storage solutions must radically simplify the migration of data and applications.
  • B2B end users: Businesses that lease or purchase connected technology. They're the big winners here, since for the first time they have a genuine legal claim to "their" data.

Data Access and Portability: The New Architecture

The heart of this regulation is the right to data access. Users now have the right to access the data they generate — without unnecessary hurdles.

Technical Access by Design

Businesses can no longer claim technical incapability as an excuse. Products must be designed so that data exports are possible "by design." In practice, this means:

  • Providing standardized APIs (interfaces).
  • Providing data in real time, wherever technically feasible.
  • Clear documentation of which data categories are actually collected.
Fairness in B2B Compensation
Providing data doesn't have to be free, but it does have to be fair. The DA-DG and the Data Act specifically protect SMEs: when a large corporation provides data to an SME, the compensation may only cover the direct costs of providing it. Charging a profit margin to SMEs is prohibited.

Protecting Trade Secrets: The Line of Defense

One of German industry's biggest concerns is the leakage of know-how. Here, the DA-DG offers important protective mechanisms. Under certain conditions, data disclosure can be refused or restricted if trade secrets are demonstrably at risk.

However, businesses need to act proactively: a general reference to "trade secrets" isn't enough. A detailed classification is required. Companies that fail to properly document their data assets and demonstrate protective measures (such as encryption or confidentiality agreements) will find it difficult to justify a refusal before the Bundesnetzagentur.

Cloud Sovereignty: The End of Vendor Lock-In

Switching cloud providers used to be a costly and technically complex undertaking. The law now sets clear limits here:

  • Elimination of switching fees: The infamous "data egress fees" — charges for extracting your own data — are a thing of the past.
  • Interoperability requirement: Providers must ensure their services can work together with those of other providers.
  • Contractual standards: Notice periods and migration support obligations must be explicitly set out in contracts.

This significantly strengthens businesses' negotiating position against global hyperscalers and enables a more flexible multi-cloud strategy.

The Bundesnetzagentur: Oversight with Teeth

With the DA-DG, the Bundesnetzagentur (BNetzA) gains far-reaching powers. It acts as the "watchdog" of the data economy. Businesses need to prepare for the following scenarios:

  • Requests for information: The authority can demand access to technical documentation and contracts.
  • Mediation: The BNetzA mediates disputes between data holders and users.
  • Sanctions: Fines are steep and modeled on the GDPR. Penalties of up to €20 million or 4% of global annual revenue are on the table. This makes data compliance a matter for company leadership (C-level).

Compliance Checklist: 6 Steps to Implementation

To stay compliant and competitive in 2026, businesses should follow this roadmap:

  1. Conduct a data audit: Identify all products and services that generate data within the meaning of the Data Act. Who is the legal user?
  2. Update your contract landscape: Review your terms and conditions, procurement terms, and service agreements. Clauses that unilaterally exclude data access are often invalid.
  3. Implement an API strategy: Invest in technical interfaces that enable automated, secure data flows.
  4. Manage IP protection: Create a register of your trade secrets. Define clear criteria for when data disclosure must be halted to protect intellectual property.
  5. Establish governance structures: Appoint people responsible for data access requests (similar to your data protection officer) to ensure deadlines and documentation requirements are met.
  6. Break the cloud lock-in & run a switching check: Check your cloud contracts for technical or financial hurdles. The Data Act puts an end to "vendor lock-in" — you need to be able to switch providers hassle-free. Make sure your exit strategy is solid and no nasty termination barriers hold you back.

Pro tip from heyData: Use the Vendor Risk Management tool in the heyData platform to check your current cloud providers directly for "Data Act Ready" compliance. That way, you'll immediately see where you might still hit roadblocks the next time you switch providers!

Conclusion: An Opportunity, Not a Bureaucratic Burden

The Data Act Implementation Law certainly brings new regulatory burdens. But it's worth looking at the opportunities, too: opening up data silos enables new business models such as predictive maintenance by third-party providers, data-driven insurance models, or more efficient resource management across the supply chain.

This ensures that Germany's Mittelstand isn't reduced to a mere data supplier for global platforms, but retains control over its digital assets. Businesses that treat transparency and portability as part of their quality promise today will earn their customers' trust and lay the groundwork for tomorrow's industrial AI applications.

FAQ

Does the DA-DG also apply retroactively to old machines?

As a rule, the obligation to provide data applies to products placed on the market after the cut-off date in 2025. However, certain aspects may apply when older systems receive substantial software updates.

How does the Data Act differ from the GDPR?

The GDPR protects natural persons and their privacy. The Data Act (and the DA-DG) primarily regulates the commercial use of (mostly non-personal) data. Where the two areas overlap (e.g., a driver's telematics data), the GDPR always takes precedence.

May data be shared with non-European companies?

Yes, provided that security standards are maintained (particularly with regard to access by third-country authorities). Here, the implementing act draws tight limits in line with EU requirements to protect European data sovereignty.

Published
23.04.2026
Martin Bastius
Co-Founder & CLO

More articles

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
View all articles
AI & Data Governance
8/18/26

Vibe coding in the enterprise: Understanding and avoiding GDPR risks from AI-powered apps

Vibe coding in the enterprise: Understanding and avoiding GDPR risks from AI-powered apps
AI & Data Governance
8/17/26

Shadow Builder Policy: How to securely manage AI-built apps in your company

Shadow Builder Policy: How to securely manage AI-built apps in your company
Compliance in Practice
8/14/26

Compliance software vs. legal expertise: What your company really needs for modern compliance

Compliance software vs. legal expertise: What your company really needs for modern compliance
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Discover all stories