Data Act 2025: Duties for Energy Utilities and IoT Manufacturers
Charging station, heat pump, wind turbine, electricity meter: each of these generates data all the time. The Data Act now says who owns it. And that is rarely the manufacturer alone.
The EU Data Act (Regulation 2023/2854) applies since 12 September 2025. From that day, users have a right to access data from connected products (Chapter III) and unfair B2B contractual terms are banned (Chapter IV). Energy utilities are affected twice: as operators of connected assets such as charging stations, heat pumps and smart meters that must hand over data, and as possible recipients of third-party operating data. Further deadlines are staggered: access by design for new products from 12 September 2026, cloud switching fees removed from 12 January 2027. In Germany the Federal Network Agency is the central enforcement authority, and the implementation act from March 2026 provides for fines of up to 500,000 euros per case. The most important first step is a catalogue of your own connected products and the data they generate.
The Data Act is live
The Data Act is no longer a regulation you can still prepare for. It applies. Since 12 September 2025, anyone who uses a connected product can demand the data it produces. And they can demand that it goes to a third party, a service provider, a competitor, whoever they choose.
For energy utilities and device makers this is not a paperwork topic. A duty to disclose, a duty to inform, and behind them a supervisory authority with a fine framework. It bites now, not someday.
The 270 billion is a political figure from the impact assessment, not a guarantee. The reasoning behind it still holds up. The Commission estimates that around 80 percent of industrial data sits unused today. The Data Act is meant to open that reserve, including the data from your charging station and your metering cabinet.
What changed on 12 September 2025
Two chapters of the regulation went live that day. Chapter III governs data access for users, Chapter IV bans unfair contractual terms between businesses. In practice this means: whoever holds data from a connected product may no longer simply use it for their own purposes.
Disclosure comes with clear requirements. The data must be available free of charge, structured, machine-readable, and where technically feasible, continuously and in real time. The user decides who receives it. Only the large gatekeepers under the Digital Markets Act are excluded as recipients.
Product data no longer belongs to whoever built the sensors, but to whoever uses the product. The manufacturer moves from owner of the data to custodian who must hand it over on request.
Chapter IV draws a second line. Terms that one company imposes on another unilaterally and that deviate grossly from what is customary are void. The exclusion of liability for intent or gross negligence is one such case. If you have terms like these in your data contracts, strike them before a court does.
The phased deadlines up to 2027
The Data Act does not arrive all at once. The disclosure duties apply since 2025, the design duties and the cloud rules follow later. Knowing the order lets you time product development and contracts instead of shouldering everything at the same moment.
| Key date | What takes effect | Who it hits first |
|---|---|---|
| 12 Sep 2025 | User data access (Ch. III), ban on unfair B2B terms (Ch. IV) | All data holders of connected products |
| 12 Sep 2026 | Access by design under Article 3 for newly placed products | Manufacturers of new connected devices |
| 12 Jan 2027 | Cloud and edge providers remove switching fees, notice period max two months | Providers of cloud services |
| 12 Sep 2027 | Fairness control also for long-term B2B legacy contracts before 12 Sep 2025 | Companies with old data contracts |
For manufacturers, 12 September 2026 is the real turning point. Until then it is enough to provide data on request. After that a new product must build in access from the factory. That is a question of product architecture, not the legal department, and product cycles run longer than a year.
Concrete duties for energy utilities
Energy utilities sit right in the scope, because their assets generate machine data around the clock. A charging station, a heat pump, a PV inverter, a wind turbine: all of these are connected products under the Data Act. And the operator must disclose what data accrues and make it accessible on request.
Charging infrastructure is hit most clearly. Charge point operators (CPO) and e-mobility providers (EMP) count as data holders under Article 2 number 13. They must hand over not only the charging power but also the metadata needed for maintenance, repair and safety, meaning diagnostic data, error codes, temperature values. Anyone who already knows the DATEX II data obligation for charging infrastructure sees a second, broader set of rules laid on top.
Three asset types, three data duties
Charging stations
Charging, diagnostic and error data must be accessible to the user and named third parties. The operator is the data holder.
Smart meters
Utilities may use metering data for their own tariffs, but remain bound by the access rights of the connection user.
Heat pump, PV, wind
Operating data that often sits with the maintenance provider must reach the asset operator on request.
With the smart meter the double role becomes tangible. The utility may analyse the metering data for its tariffs, that stays allowed. At the same time the connection user has an access right to exactly this data and can take it to a different provider. Anyone tracking the smart meter rollout anyway now has one more data layer to serve.
Duties for IoT and device manufacturers
The heaviest adjustment falls on the makers of connected devices. They may no longer use the data of their own products without the user's consent, not even for product improvement. And from September 2026 new devices must build in direct access from the start.
Three duties have been active since 2025. First the data licence: any own use of the product data needs a contractual basis with the user, set out in Article 4. Second the pre-contractual information: before the sale it must be clear what data the device generates, in what format and by which route the access runs. Third the handling of trade secrets.
Trade secrets are the sore point. The Data Act forces disclosure but lets the data holder demand appropriate safeguards and confidentiality agreements. Where exactly the line runs, the regulation does not say sharply. As long as model clauses and first court rulings are missing, every disclosure remains a judgement call with residual risk.
Then there is the uncomfortable truth about competition. A user may pass their data to a direct competitor of the manufacturer. The Data Act does build in guardrails, for instance the ban on using the data to clone a rival product. Whether these guardrails hold in practice is open. A manufacturer that has treated data as a quiet competitive edge loses much of that edge.
Germany: implementation act and the Federal Network Agency
As an EU regulation the Data Act applies directly, but national law governs jurisdiction, procedure and sanctions. In Germany the Data Act Implementation Act has done that since 2026. The Bundestag passed it on 26 March 2026, and it was promulgated in May 2026.
The Federal Network Agency (Bundesnetzagentur) is the central enforcement authority. For personal data the Federal Data Protection Commissioner remains responsible, so there is no double supervision. The fine framework sits at up to 500,000 euros per case and generally applies only to intentional conduct.
Compared with the first draft, the catalogue of fines was noticeably softened. That takes some pressure off smaller companies but changes nothing about the substantive duties. Those apply since September 2025, independent of the national law.
The Bundestag was not entirely of one mind. In the expert hearing the specialists argued about the effort and the legal uncertainty, especially for mid-sized firms. That is an honest signal: the frame stands, practice still has to fill it. How hard the Federal Network Agency drives enforcement will show in 2026 and 2027.
Challenges and risks
The Data Act opens data. In doing so it also creates new tensions, and implementation ties up resources. Between the duty of transparency and the protection of your own advantages there is no comfortable middle path.
The most expensive mistake is to file the whole thing as a pure legal topic. The Data Act is a data task. Whoever only adjusts a clause and forgets the interfaces stands there without an answer at the first real request.
What companies should do now
No major project required. What counts first is a plain question: which connected products do you even operate, and what data do they spit out? Only once that list exists does the rest pay off. It happens to be the same list every later data project builds on.
Five steps in this order
-
Build a data catalogue
Which connected products do you operate, and what data do they generate in what format? Without this list every further discussion is guesswork. It is also the basis for any later data project.
-
Review contracts
Add data licences under Article 4, strike unfair terms. The non-binding EU model clauses give you a benchmark to measure against.
-
Define the access process
Who answers user and third-party requests, within what deadline, through which interface? A request without a responsible unit turns into a complaint at the Federal Network Agency.
-
Safeguard trade secrets
Decide which data is sensitive and prepare safeguards and confidentiality agreements for it. That is the condition for being able to disclose in a controlled way at all.
-
Plan for access by design
For the product generation from September 2026, direct data access belongs in the architecture, not bolted on afterwards. Product cycles need lead time, the deadline is closer than it looks.
For the strategic picture it helps to look beyond the Data Act. The European energy data space and AI regulation for energy utilities interlock. Whoever orders their data basis now is not just working off a duty, but laying the foundation for whatever is meant to happen with that data next.
Further reading
Frequently asked questions
Since 12 September 2025. Regulation (EU) 2023/2854 entered into force on 11 January 2024 and applies from 12 September 2025. From that day, Chapter III on data access and Chapter IV on unfair contractual terms between businesses take effect.
Operators of connected assets must make their data available. Charging stations, heat pumps, PV inverters and wind turbines generate machine data to which users and third parties they name have an access right. Charge point operators count as data holders and must make charging, diagnostic and error data accessible.
Access by design means a connected product provides direct data access to the user from the factory, without a detour through the manufacturer. This duty under Article 3 of the Data Act applies to products placed on the market from 12 September 2026. It does not apply to existing products.
The Federal Network Agency (Bundesnetzagentur) is the central enforcement authority. For personal data, the Federal Data Protection Commissioner remains responsible. Germany's Data Act Implementation Act was passed by the Bundestag on 26 March 2026 and promulgated in May 2026. It provides for fines of up to 500,000 euros per case, generally only for intentional conduct.
In most cases yes. Since 12 September 2025 a data holder needs a contractual licence with the user for any own use of the product data. Unfair, unilaterally imposed terms between businesses are void. For long-term B2B contracts concluded before 12 September 2025, the fairness control applies from 12 September 2027.
The Data Act forces disclosure of product data but protects trade secrets. The data holder may require appropriate safeguards and confidentiality agreements before sharing sensitive data. In practice this boundary is the biggest point of dispute, because clear enforcement mechanisms are still missing.