The impact of the Data Act on contracts: from legacy agreements to new contract types
The Data Act changes not only access to data it also intervenes deeply in existing contractual structures. New contract types, stricter transparency obligations and clear rules on data portability and switching providers create a need for action for companies. Which contracts are affected and what specifically needs to be done now?
Content
- Why the Data Act affects contract drafting
- Which contractual relationships are particularly affected?
- 1. Users and data holders
- Data sharing with third parties: new obligations in data portability relationships
- Unfair contractual terms: new control of standard terms in the B2B sector
- Switching data processing services: contracts under pressure to adapt
- Which new contract types are emerging in concrete terms?
- Conclusion: contracts are becoming the key to data strategy
Why the Data Act affects contract drafting
The Data Act aims to make the use of data fairer and more transparent. Until now, factual control over data often determined who was able to use them. In future, this control is to be regulated legally and contractually.
The aim is to:
- create incentives for voluntary data sharing,
- avoid contractual imbalances, and
- ensure fair participation along the data value chain.
Contracts are therefore becoming the central governance instrument for data access, data use and data sharing.
Which contractual relationships are particularly affected?
The Data Act affects several contractual relationships. Three constellations are particularly relevant.
1. Users and data holders
Typically, several contracts already exist here, such as:
- purchase, rental or leasing agreements for connected products
- contracts for related digital services
- where applicable, data protection consents, for example in the case of mixed data sets containing both personal and non-personal data
Important: the GDPR continues to take precedence. The Data Act supplements existing data protection law; it does not replace it.
In many cases, an additional contractual framework will now be required.
2. The data licence agreement: a new central element
If the data holder wishes to use non-personal data, it requires a separate contract with the user.
In practice, this data licence agreement will often be linked to the main contract for the connected product. In terms of content, the following points in particular must be observed:
- Transparency requirement: the terms must be clear and understandable.
- Specific purposes of use: for example, improving functionality, developing new products or aggregating data in order to share derived data with third parties.
- Restriction of data use: no use for analysing the user’s economic situation, assets or production methods.
- Disclosure to third parties: non-personal product data may only be made available for the performance of the contract.
- Contract amendments: these require informed consent.
If the user is a consumer, additional consumer protection requirements apply. If the user is a business, the specific requirements of the Data Act for B2B contracts apply.
3. Statutory data access and its limits
The user’s right to access certain data is regulated by law. In principle, it does not require a separate contractual agreement.
However, if connected products are not designed in such a way that data are accessible by default, the data holder must provide the “readily available data” upon request.
In multi-user constellations, contract drafting becomes particularly demanding. The status of user may change dynamically — and the licence chain must be reflected in a legally robust manner.
Newsletter
For your Inbox
Current updates and important information on topics such as data law, information security, technology, artificial intelligence, and much more. (only in German)
Data sharing with third parties: new obligations in data portability relationships
The Data Act enables the user to request that data be made available to third parties.
This creates additional contractual relationships.
Data holder and data recipient
The terms under which the data are made available must be regulated contractually. Different standards apply.
In B2C relationships:
- simple and understandable wording
- prohibition of unfair contractual terms
- comprehensive control of standard terms and conditions
In B2B relationships:
- fair, reasonable, non-discriminatory and transparent terms
- express prohibition of unfair contractual terms
- the user’s rights must not be restricted
The provision of the data is free of charge for the user. However, consideration may be agreed between the data holder and the third party, including a reasonable margin.
User and data recipient
Clear rules are also required here:
- processing only for the agreed purposes
- compliance with the contractual terms
- deletion of the data once they are no longer required for the purpose
Unfair contractual terms: new control of standard terms in the B2B sector
The Data Act introduces a standalone unfairness control for data-related contractual terms between businesses.
Certain clauses must not be unfair. These requirements cannot be contractually waived.
If a clause proves to be unfair, it is not binding on the affected company.
Enforcement may take place in two ways:
- complaint to the competent national authority
- administrative sanctions imposed ex officio
In addition, the wording suggests that invalidity also has direct effect between the contracting parties.
For practice, this means that classic B2B standard clauses must be reviewed and, where necessary, adapted.
Switching data processing services: contracts under pressure to adapt
The Data Act also sets new minimum requirements for switching providers of data processing services, such as cloud services.
In future, contracts must regulate, among other things:
- rights and obligations during the switching process
- information obligations
- technical support for data migration
- the gradual abolition of switching charges
- cooperation in good faith
Existing and new contracts must be adapted accordingly.
Which new contract types are emerging in concrete terms?
The Data Act introduces several new or previously uncommon contractual constellations:
- data licence agreement between data holder and user
- data provision agreement between data holder and data recipient
- data use agreement between user and data recipient
- adapted contracts for data processing services with provisions on provider switching
In addition, model contractual terms at European level are intended to facilitate standardisation.
Conclusion: contracts are becoming the key to data strategy
The Data Act shifts control over data from factual power to legal structuring. Contracts are becoming the central instrument for data access, data use and data sharing.
The most important takeaway is this: existing contractual frameworks, particularly for connected products, data portability and cloud services, must be systematically reviewed and adapted.
Companies should carry out a contract inventory at an early stage, plan for new contract types and review standard clauses for unfairness risks. Those who proceed in a structured manner now create legal certainty and strengthen their data-driven business strategy at the same time.
Schedule your initial consultation
Describe your situation to us in a no-obligation phone call, and our lawyers will work with you to find the best solution.
Content
- Why the Data Act affects contract drafting
- Which contractual relationships are particularly affected?
- 1. Users and data holders
- Data sharing with third parties: new obligations in data portability relationships
- Unfair contractual terms: new control of standard terms in the B2B sector
- Switching data processing services: contracts under pressure to adapt
- Which new contract types are emerging in concrete terms?
- Conclusion: contracts are becoming the key to data strategy
Your experts