Data has long been a key driver of value creation. The Data Act (Regulation (EU) 2023/2854)[1] and the Data Governance Act (Regulation (EU) 2022/868)[2] therefore establish new rules governing the access, use and sharing of data, which are now being specifically enforced in Germany as well. For businesses, this raises not only the question of what the new requirements mean in legal terms, but above all how they can be implemented in practice and within organisational structures.
Specifically, the German implementation is particularly relevant because directly applicable EU rules are now being transformed into a clear national enforcement framework with designated authorities, procedures and fines.[3] For affected individuals and companies, this means greater clarity regarding who they can turn to in the event of complaints, data access queries and supervisory proceedings – but also a more tangible risk of sanctions in the event of breaches.[4]
What is the Data Act all about?
The Data Act has been in force in its essential parts since 12 September 2025 and regulates, in particular, who is permitted to use and share product data or associated service data, and under what conditions. In practice, this primarily affects manufacturers and providers of connected products, digital services, data owners, and companies that wish to use or obtain data from connected devices.
The Data Governance Act has been in force since 24 September 2023 and is intended to provide a legal framework for the re-use of certain protected public sector data, data brokerage services and data altruistic organisations. For many companies, the focus is less on traditional day-to-day business and more on new data-driven cooperation and business models, such as data rooms, research collaborations or cross-sector data usage.
On 26 March 2026, the Bundestag passed the implementing legislation for the two EU legal acts.
What will change for companies ?
The most significant practical change is that the German implementation now turns European obligations into a tangible national enforcement framework. Companies therefore no longer need to deal with the regulations in abstract terms, but must address specific responsibilities, complaint procedures, investigative powers, and the risks of fines.
In the context of the Data Act, the question of whether connected products are designed in such a way that users can actually access the data generated or recorded comes to the fore. Also relevant are processes for transferring data to users or third parties designated by users, the justification for refusals, and the organisational separation between assessments under data usage law and data protection law.
With regard to the Data Governance Act, companies should assess whether they intend to operate as data intermediary services or pursue data altruism models, as a clearer supervisory and registration regime is now envisaged for these purposes. For public bodies and data-driven projects, the Federal Statistical Office is also becoming a more important central information point when it comes to the re-use of protected public sector data.
Implications for data subjects
For data subjects – such as users of connected products – the Data Act primarily strengthens the practical enforceability of access to certain usage data. Politically, this was also described in the Bundestag as the Data Act being intended to give people back some decision-making power over the data they generate. With the exception of personal data, there are essentially no original rights, such as ownership or possession, attached to data.
However, distinguishing this from data protection remains challenging. Particularly where data access claims under the Data Act and obligations under the GDPR coexist, it can become unclear for data subjects and businesses which authority is responsible and according to which standards a case is assessed.
New and amended responsibilities
Under the Data Act Implementation Act, the Federal Network Agency remains the central authority for implementation, supervision and enforcement in Germany. It is to handle complaints, report rejections of data access requests to the European Commission, authorise dispute resolution bodies , conduct investigations, request information, issue interim orders and impose penalty payments.
In addition, the Federal Commissioner for Data Protection and Freedom of Information remains solely responsible for monitoring the application of the Data Act with regard to the protection of personal data when processed by non-public bodies. At the same time, the state data protection authorities remain responsible for processing by the data recipient, which does not entirely eliminate the risk of parallel supervision and differing assessments.
Another important point is a clarification made during the parliamentary procedure: the Federal Network Agency reviews data requests from federal public bodies in accordance with Chapter V of the Data Act, whilst data requests from state public bodies remain with the authorities responsible under state law. This has at least partially reversed the initially very broad centralised jurisdiction in favour of the states.
For the Data Governance Act, responsibilities are divided between the Federal Network Agency and the Federal Statistical Office. The Federal Network Agency is responsible in particular for the notification, monitoring and supervision of data intermediary services, as well as for the registration and control of data-driven organisations, whilst the Federal Statistical Office, as the central information point, supports public bodies in deciding on the re-use of protected data.
Which infringements are now subject to fines
Under the Data Act, the German implementing legislation provides for a graduated system of sanctions. For minor infringements, the maximum fine is EUR 50,000.00; for moderate infringements, EUR 100,000.00; and for serious infringements, EUR 500,000.00; these maximum limits may be exceeded if the infringement resulted in economic gain.
The current guidance cites as an example of a serious infringement the case where a connected product is not designed in such a way that the data generated or recorded by the product is accessible to the user. A moderate infringement may occur if a user is prevented from passing on data received; a minor infringement is described, for example, as a breach of the obligation to provide evidence in the event of a refusal to pass on data.
In addition, under the adopted draft, the Federal Network Agency may impose penalty payments of up to EUR 500,000.00 to enforce orders. For data protection infringements in connection with personal data, however, the data protection sanctions framework remains applicable.
In the case of the Data Governance Act, the German implementing law contains supplementary provisions on fines for breaches of the Data Governance Act, with fines of up to EUR 500,000.00 depending on the circumstances. The focus is primarily on breaches of obligations in the regulated areas of data intermediary services, data altruistic organisations and the re-use of protected public sector data as regulated under the DGA.
What companies should do now
Companies should view this issue primarily as a matter of governance, product and process. The key factor is whether the company has clear rules governing what data is generated by connected products, who has access to it, how requests for data access are handled, how refusals are documented, and at what stage data protection issues are examined separately.
It makes sense to carry out a brief implementation check based on four key questions:
The German implementation does not fundamentally overhaul data law, but makes it significantly more binding. For companies in Germany, the pressure to act is increasing, particularly in terms of organising data access, product design, responsibility management and compliance not merely in abstract terms under European law, but in a manner that is enforceable under the national implementation in Germany. It remains to be seen whether, in the course of the evaluation of the widely criticised regulatory and supervisory structure and the framework for fines in four years’ time, the ambiguities and, in some cases, contradictions in the regulations will also be scrutinised and definitions adjusted. In any case, a further (unpleasant) conclusion of the implementation is that the reduction of bureaucracy in Europe and also in Germany is still a long way off.
[1] https://bmds.bund.de/themen/digitale-wirtschaft/data-act.
[2] https://digital-strategy.ec.europa.eu/en/policies/data-governance-act.
[3] German Bundestag, “Bundestag adopts EU guidelines on data access and data use”: https://www.bundestag.de/dokumente/textarchiv/2026/kw13-de-datennutzung-1156734.
[4] https://www.bundestag.de/dokumente/textarchiv/2026/kw05-pa-digitales-data-act-1136784.
You are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information