Ailance Alt TM Logo

Data Act Implementation Act: What Companies Need to Do Now

Data Act Implementation Act
Picture of  Aristotelis Zervos

Aristotelis Zervos

Aristotelis Zervos, Editorial Director at 2B Advice, combines legal and journalistic expertise in Data protection, IT-Compliance and AI regulation.

The Data Act is changing the way data is handled commercially in Europe. For companies, this means that access to data is no longer just a contractual option, but a regulatory requirement. The Data Act Implementation Act will ensure that these regulations are effectively and concretely enforced in Germany as well. Here are the steps companies should take now to prepare.

Data Act Implementation Act Already Passed by the Bundestag

With EU Regulation 2023/2854 (the Data Act), the European Union is establishing, for the first time, a comprehensive set of rules governing access to and the use of data. The focus is particularly on data from networked products and connected services. The goal is to give users more control over their data while simultaneously promoting data-driven innovation.

While the Data Act is directly applicable as a regulation, its practical implementation requires national legislation. In Germany, this role is fulfilled by the Data Act Implementation Act (DADG, BT-Drs. 21/2998). In particular, it regulates responsibilities, procedures, and sanctions, thereby giving the European legal framework practical effect.

On March 26, 2026, the German Bundestag passed the Data Act Implementation Act; the Bundesrat has yet to approve it.

There is a transition period until September 12, 2026, for the requirements regarding the design of networked products and connected services under the Data Act.

Data Act: Who Will Oversee Companies in the Future?

A key component of the DADG is the designation of the competent authorities. The legislature has assigned a key role to the Federal Network Agency (BNetzA). It serves as the central enforcement and coordination authority for the obligations under the Data Act.

Its responsibilities include, in particular, monitoring compliance with regulations, handling complaints, and ordering companies to take specific actions.

However, this central authority is not exhaustive. To the extent that personal data For those affected, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) plays a special role. The DADG provides for coordinated cooperation among the authorities.

For companies, this results in a multi-tiered supervisory structure. The Federal Network Agency serves as the primary point of contact for data access issues, while data protection authorities can review data protection-related aspects in parallel.

Data Access Becomes Enforceable: What Will Change in Practice

The DADG translates the substantive rights of the Data Act into specific procedures. In the future, claims for data access can be enforced not only through contracts but also through regulatory measures.

The Federal Network Agency is granted extensive powers for this purpose. It can request information, conduct audits, and issue binding orders to companies. This provides an effective set of tools for enforcing data access rights.

In addition, the European legal framework provides for an independent system of dispute resolution bodies. These are authorized by the competent authority and enable the out-of-court resolution of disputes. Companies will therefore need to distinguish in the future between regulatory enforcement and alternative dispute resolution. This dual structure is intended to ensure that decisions on data access issues are made in a more structured, faster, and at the same time more strictly regulated manner.

Reading tip: Who Is Covered by the EU Data Act—Who Is Affected and What Are the Requirements?

Sanctions: Why the Pressure to Act Is Increasing Significantly

These stricter enforcement mechanisms will not be without consequences and will significantly increase regulatory pressure on companies.

The DADG provides for a separate framework of sanctions for violations of the Data Act. The draft contains a differentiated system of fines with graduated maximum limits, some of which were tightened during the subsequent legislative process.

The specific amount of the penalties is determined primarily by the severity and duration of the violation, as well as by the company’s financial capacity. In addition, there are daily fines and regulatory orders to restore compliance with the law. This poses a significant financial and operational risk to companies.

Impact of the Data Act: A Necessity or a Strategic Opportunity?

These regulatory developments have a direct impact on data-driven business models. Manufacturers of connected products, providers of digital services, and platform operators are particularly affected.

In the future, these companies will be required to grant their users access to certain data and, under certain conditions, to allow third parties access as well.

At the same time, they must ensure that this access is provided under fair, transparent, and non-discriminatory conditions.

This fundamentally changes the role of data. Data is no longer just an internal asset, but a regulated component of value chains.

For companies, this therefore presents not only a Compliance-It's not just a legal question, but also a strategic one: How can the new legal framework be actively utilized?

The Clock Is Ticking: Why Companies Must Act Now

The Data Act has already entered into force and has been largely applicable since September 12, 2025. Although the DADG is still going through the legislative process, its basic structure is already clear.

For companies, this means a limited window of time. Implementation requires both legal and technical adjustments and cannot be done on short notice.

Companies that react too late will face significant time and implementation pressures.

Immediate Measures for Implementing the Data Act

For companies, the key question now is how quickly and systematically they can implement the Data Act.

  1. Clarify the scope of application and data roles
    The first step is to analyze your own business model. Companies should assess as soon as possible whether—and to what extent—their connected products and associated services fall within the scope of the Data Act. In particular, they must clarify what data is generated and what roles—such as data owner, user, or recipient—the company assumes. Without this classification, legally compliant implementation is not possible.

  2.  Tailor Contract Structures to Specific Needs
    Based on this, the next step is contractual implementation. Companies should review existing data-related contracts and standardized contract terms. The Data Act sets forth specific requirements for data access and data use agreements, particularly with regard to fair contract terms. The focus here is on provisions regarding data access, data use, compensation, and confidentiality.

  3. Ensure the Provision of Technical Data
    The legal requirements can only be met if the technical foundation is in place as well.
    Companies must ensure that they can provide relevant data in a timely and secure manner, and in a structured and machine-readable format. The Data Act does not prescribe any specific technical solution. However, it requires the ability to provide data in a standardized and interoperable manner.

  4. Establish Internal Processes and Responsibilities
    In addition to legal and technical considerations, organizational structure is crucial. Companies should define clear responsibilities and processes for handling data access requests, user inquiries, and regulatory procedures.
    This is the only way to process such requests efficiently and in compliance with the law.

  5. Interface to the GDPR solve neatly
    Special attention must be paid to distinguishing it from GDPR. In many cases, there are also personal data affected, so that both sets of rules apply in parallel. Companies must therefore ensure that data access requests are handled in accordance with data protection requirements.

Take action now to secure a competitive edge

The implementation of the Data Act is not an isolated Compliance-Project. It affects contracts, IT architecture, data strategy, and governance in equal measure.

This is precisely where the challenge lies: Many companies understand the regulatory requirements but struggle to implement them in a structured and legally compliant manner.

2B Advice helps companies implement the Data Act in a comprehensive manner.
From analyzing the scope of application to adapting contract structures and integrating them into existing Compliance- and IT processes.

Our approach combines legal expertise with operational implementation—practical, scalable, and tailored to complex corporate structures.

Talk to us, if you:

  • would like to clarify what specific actions they need to take under the Data Act
  • want to adapt existing structures in a legally sound manner
  • or would like to strategically leverage the Data Act for your business model


Request a no-obligation initial consultation now.

Source: Data Act Implementation Act – Draft

Aristotelis Zervos is Editorial Director at 2B Advice, a lawyer and journalist with profound expertise in data protection, GDPR, IT-Compliance and AI governance. He regularly publishes in-depth articles on AI regulation, GDPR-Compliance and risk management. You can learn more about him on his Author profile page.

Questions and Answers

What does the Data Act Implementation Act regulate in Germany?

The Data Act Implementation Act supplements the directly applicable EU Data Act with national responsibilities, procedures, and penalty provisions. In particular, it specifies which authorities are responsible for monitoring compliance with the requirements and how data access rights can be enforced in Germany.

Which companies are particularly affected by the Data Act?

Manufacturers of connected products, providers of connected services, and other companies with data-driven business models are particularly affected. They must determine what data is generated by their products and services and what role they play under the Data Act—for example, as data owners, users, or data recipients.

Which government agency is responsible for enforcing the Data Act in Germany?

Under the Data Act Implementation Act, the Federal Network Agency plays a central role in enforcement and coordination. To the extent that personal data In addition, where data subjects are involved, data protection responsibilities come into play, meaning that companies must expect a multi-tiered supervisory structure.

What technical requirements does the Data Act impose on data provision?

Companies must be able to provide relevant data in a timely and secure manner, in a structured and machine-readable format. The Data Act does not prescribe any specific technical solution, but it does require that standardized and interoperable data provision be possible.

Which contracts should companies review in light of the Data Act?

Companies should review existing data-related contracts and standardized contract terms. Provisions regarding data access, data use, compensation, fair contract terms, and the protection of trade secrets are particularly relevant.

How should the Data Act and the GDPR be considered together?

With regard to data access claims personal data apply to, the Data Act and GDPR side by side. Companies must therefore ensure that the provision and use of data comply not only with the provisions of the Data Act but also with data protection requirements.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

Data Act Implementation Act: What Companies Need to Do Now