September 12, 2025 beganthe data regulation (Data Act), Regulation (EU) 2023/2854, to be applied throughout the EU. The regulation was adopted on 13 December 2023 and is directly applicable in Sweden without having to be converted into Swedish law. For many Swedish companies, this is the most underestimated regulation in years: it not only concerns personal data (like GDPR), butall data generated by connected products and related servicesas well as the conditions for changing cloud providers.

This guide goes through what the regulation actually requires, which dates apply, and what Swedish manufacturers, SaaS companies and IoT providers need to do now.

What is the data regulation, cards?

The Data Act is a horizontal regulation. It therefore applies across industries and complements the GDPR instead of replacing it. The aim is to unlock the value in the enormous amount of data that industrial machines, vehicles, smart products and cloud services generate, and to distribute that value more fairly between manufacturers, users and third parties.

In practice, the regulation deals with four things:

  • Right to datafrom connected products, for the user.

  • Data sharingbetween companies (B2B) and in exceptional cases to the public sector (B2G).

  • Cloud switchingbetween data processing services, without lock-in.

  • Reasonable contract termsas protection against unilaterally imposed unfair clauses.

The important dates you need to keep track of

The regulation is being rolled out in stages. According to Article 50, the following applies:

  • September 12, 2025- the regulation is applied as the main rule.

  • September 12, 2026– the requirement in Article 3.1 (that products must be designed so that data is directly accessible) applies to connected products and related services thatreleased to the market afterthis date. It is therefore a requirementbuilt-in data access (access by design)for new products.

  • January 12, 2027- cloud providers may no longer charge any fees for switching services (switching charges). Until then, onlyreducedfees are charged (Article 29).

  • September 12, 2027- the rules on unfair contract terms (chapter IV) also apply to contracts entered into no later than September 12, 2025, provided that they run for an indefinite period or expire at least ten years after January 11, 2024.

For agreements entered intoafterSeptember 12, 2025, the terms and conditions apply immediately.

Right to data from connected products

This is the core of the regulation and affects every Swedish manufacturer of connected products, from industrial equipment and sensors to vehicles, agricultural machinery and smart home products.

The user of a connected product has the right toget access to the data that the product generates during use, often directly from the device. The user can also request that the data holder share the data with athird partyof the user's own choosing, such as an independent repairer, a competing service provider or an analytics partner.

It changes the market logic. Manufacturers have long built aftermarket businesses on being the sole owner of machine data. That model is now being challenged in several ways:

  • You must be able to provide datasimple, secure and in a common, machine-readable format, free for the user.

  • You may not use your position as a data holder to outcompete the third party chosen by the user.

  • The regulation protects at the same timetrade secrets: these must still be disclosed under certain conditions, but with the possibility of safeguards, and in exceptional cases sharing may be refused if serious financial harm is likely.

Note the demarcation against GDPR: if the data concerns a natural person, a legal basis is still required according to the data protection regulation. The Data Act does not in itself create a new basis for collecting personal data, it only governs access to data that is already generated.

Cloud swap: the end of lock-in

Chapter VI targets suppliers ofdata processing services, in practice cloud (IaaS, PaaS, SaaS). If you're running a SaaS product, this is the area most likely to require concrete work.

According to Article 23, suppliers must remove barriers to effective switching and take the measures in Articles 25-30. The customer must be able to:

  • terminate the agreement with reasonable notice,

  • enter into an agreement with another supplier for the same type of service,

  • port out their exportable data and digital assetsto another supplier or to an own on-prem solution,

  • achievefunctional equivalencewhere applicable.

And the fees: according to Article 29, suppliers receive fromJanuary 12, 2027don't charge any exchange fees at all. That includes the infamous onesthe egress feesto move data out. Until then, only reduced, cost-based fees are allowed. For Swedish SaaS companies, this means that business models that rely on lock-in and expensive data migration have an expiration date.

Reasonable contractual terms in B2B

Chapter IV before onereasonableness test for unilaterally imposed contractual termson data access and data use between companies (Article 13). A condition that is unilaterally forced on a counterparty and that is grossly unfair is not binding. The regulation lists conditions that are presumed to be unreasonable, for example those that unduly limit one party's right to data it itself generated or contributed to.

For Swedish companies that write supplier and platform agreements, this means a concrete review: standard clauses on data rights, responsibility and termination need to be reviewed against the new reasonableness standard.

What does supervision look like in Sweden?

In Sweden, the government has pointed outThe Swedish Post and Telecommunications Agency (PTS)as the competent supervisory authority for the data regulation. However, the supplementary Swedish rules have not yet fully entered into force: in December 2025, the investigation report was submittedSOU 2025:118on supplementary provisions to the Data Act. This means that the national sanctions toolbox is still under construction.

However, there is no reason to wait for full supervision. The regulationalready appliesand the rights can be asserted between parties, including civil law. When the supplementary rules are in place, PTS is expected to be able to decide on penalty fees within the framework proposed in the investigation. For violations concerning personal data, the GDPR's sanction levels also apply in parallel.

Checklist: what you should do now

  • Map your data.What data do your products and services generate? Who are users, data holders and third parties?

  • Build data access into the product.New connected products from September 2026 must be designed for easy data access. It is a technical requirement, not just a legal one.

  • Before an export route.Secure a standardized, machine-readable format and APIs to release data and port it to another provider.

  • Review the cloud agreements.Remove or phase out switching and egress fees before January 2027 and describe the switching process clearly in the agreements.

  • Review the standard terms and conditions.Check B2B data rights clauses against the reasonableness test in Chapter IV.

  • Coordinate with GDPR.Ensure legal basis and safeguards when data contains personal data or trade secrets.

That's how ZORC helps

The Data Regulation is as much a technical issue as a legal one. The right to data, export formats, APIs for data sharing and functional equivalence in cloud switching must be built into the product and platform itself, not just written into an agreement. It is precisely at the intersection between law, architecture and development that we work.

Do you want to know what a data access or export flow would mean for your particular product? Describe your project this springquote calculator, or get in touch viacontactthen we look at your connected product or SaaS platform together.