Data Act Developments: 2026 and Beyond

The EU Data Act (the “Data Act”) continues to reshape how certain data is accessed, shared and governed across the European Union.  Several significant milestones are approaching in the coming months, starting on 12 September 2026.

This briefing highlights the upcoming developments that in-scope organisations operating in Ireland, and across the EU, should have on their radar.

The Data Act at a Glance

With the commencement of its general application on 12 September 2025, the Data Act introduced wide-ranging obligations covering data access by design, data sharing, unfair contract terms, cloud switching and safeguards for international data transfers for in-scope organisations, most of which are already applicable.  For further background on the Data Act's core provisions, our earlier overview briefing remains a useful reference.

Data Access by Design Deadline: 12 September 2026

The most immediate compliance milestone is 12 September 2026.  From this date, the “data access by design” obligation under Article 3(1) of the Data Act becomes applicable for all connected products and related services placed on the market.  Manufacturers of connected products and providers of related services must ensure that product data, related service data and associated metadata are accessible to users by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, directly accessible.

The scope of products and services caught is broad. Examples of connected products span smart household appliances, thermostats, coffee machines, wearable devices, connected vehicles and industrial and agricultural machinery, while examples of related services include an app that displays an electric vehicle’s charging history or links to a smart watch to record and process user metrics.

Critically, this is a forward-looking obligation, meaning it applies only to new products placed on the market after 12 September 2026 and does not apply retrospectively.  The practical impact is nonetheless substantial as both manufacturers and related service providers must embed data-accessibility functionality at the design stage.

The End of Cloud Switching Charges: 12 January 2027

Cloud service providers should note the approaching 12 January 2027 deadline, by which all switching charges must be fully eliminated under Article 29 of the Data Act.  Our earlier briefing on cloud switching rights discusses the switching framework under Chapter VI of the Data Act in detail.  Since its publication, the European Commission has published non-binding Model Contractual Terms for data access and use and Standard Contractual Clauses for cloud computing contracts.

Unfair Contractual Terms Scope Expansion: 12 September 2027

Looking slightly further ahead, from 12 September 2027, Article 13's prohibitions on unfair contractual terms unilaterally imposed on another enterprise will be extended to capture certain legacy contracts, specifically, contracts concluded on or before 12 September 2025 that are either of indefinite duration or due to expire at least ten years from 11 January 2024.  Organisations should begin reviewing existing B2B data-sharing and cloud service agreements now to assess their exposure.

The General Scheme of the Data Bill 2025

While the Data Act is an EU Regulation (and therefore directly applicable in Ireland without transposition), national legislation is still required to designate competent authorities, establish an enforcement framework and set out applicable penalties, as mandated by Articles 37 and 40 of the Data Act.

The draft General Scheme of the Data Bill 2025 sets out how Ireland proposes to implement these requirements.  The General Scheme is currently undergoing pre-legislative scrutiny, following which the legislation will progress through the Houses of the Oireachtas for debate and enactment.

The General Scheme divides enforcement responsibility across multiple bodies:

  • The Competition and Consumer Protection Commission (CCPC) is designated as both the Data Coordinator (the single point of contact for the Data Act) and the competent authority for the bulk of the Regulation, including the connected products and data-sharing obligations (Chapters II and III), unfair contractual terms (Chapter IV) and business-to-government data sharing (Chapter V).
  • ComReg is designated as the competent authority for switching between data processing services (Chapter VI) and data processing services interoperability provisions (Chapter VIII).
  • A third competent authority (not yet named) will be responsible for the provisions on unlawful third-country government access to data (Chapter VII).
  • The Data Protection Commission (DPC) retains its supervisory role for the personal data aspects of the Data Act and may impose administrative fines in accordance with Article 83 of the GDPR for infringements of Chapters II, III and V.

On penalties, the General Scheme envisages administrative financial sanctions of up to 4% of turnover in the EU, or up to €500,000 for natural persons. 

Organisations should monitor this Bill’s progress closely as it will determine the precise scope of enforcement powers and penalties applicable in Ireland.

The Digital Omnibus: Simplification Ahead

At the EU level, the European Commission's proposed Digital Omnibus would amend the Data Act alongside other digital legislation as part of a broader simplification of the EU digital regulatory framework. Proposed changes include:

The Digital Omnibus remains under legislative consideration. In the context of its Presidency of the Council of the EU, Ireland is aiming to reach an agreement with the European Parliament on various omnibus packages, including the digital and data omnibus, by the end of 2026.

Next Steps

Organisations in-scope of the Data Act should generally ensure compliance with the Data Act and in particular should prioritise the following actions ahead of the upcoming deadlines:

  • Product design review: Ensure that connected products and related services being brought to market after 12 September 2026 comply with the data access by design obligation.
  • Contract audit: Review existing data-sharing and cloud computing contracts for unfair terms exposure and switching-charge compliance.
  • Monitor the Data Bill: Track the progress of Irish implementing legislation to understand the domestic enforcement landscape.
  • Watch the Digital Omnibus: Keep abreast of the proposed EU-level simplification measures that may reshape the Data Act framework.

How can McCann FitzGerald LLP help?

For further information on any of the matters discussed in this briefing, please contact any of the key contacts below or your usual contact at McCann FitzGerald LLP.

This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.

Key Contacts