Regulating Data: EU Data Act & More – July 2026 Edition

The EU’s digital regulatory landscape is evolving at unprecedented speed, creating both new compliance challenges and strategic opportunities in Europe

30 July 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

As the first anniversary of the Data Act approaches, attention is increasingly turning to the next application milestone on 12 September 2026. At the same time, regulatory implementation efforts continue at both EU and national level.

In this edition, we cover:

  • The Bundesnetzagentur's guidance on the certification of Data Act dispute settlement bodies;
  • New CRA FAQ clarifications on the interaction between the CRA and the Data Act as well as;
  • FAQs clarification concerning the relationship between the European Health Data Space (EHDS) and the CRA;
  • New European Commission guidance on the implementation of the Cyber Resilience Act; and
  • Selected upcoming regulatory dates and deadlines including the Data Act's upcoming access-by-design requirements.

1. Data Act dispute settlement bodies: BNetzA guidance

Article 10 Data Act establishes a framework for out-of-court dispute settlement. Under the Regulation, users, data holders and data recipients may refer certain disputes to certified dispute settlement bodies as an alternative to court proceedings. In Germany, the Bundesnetzagentur is the competent authority responsible for certifying such bodies.

Key features of the dispute settlement framework

  • Eligible parties: users, data holders and data recipients may submit certain disputes arising under the Data Act to a certified dispute settlement body.
  • Examples of covered disputes: disputes relating to restrictions on data access, trade secret protections, data-sharing terms and conditions, and cloud switching obligations.
  • Certified bodies: dispute settlement bodies must be certified by the competent national authority. In Germany, certification is carried out by the Bundesnetzagentur.
  • Voluntary participation: out-of-court dispute settlement procedures are voluntary and generally require the agreement of the parties involved.
  • Binding effect: decisions are binding only where the parties have explicitly agreed to this before the start of the proceedings. Participation in an out-of-court dispute settlement procedure does not prevent the parties from subsequently seeking redress before courts or competent authorities.

The Bundesnetzagentur's May 2026 Guidelines on certification as an out-of-court dispute settlement body are available here.

2. CRA FAQs: interaction between the CRA and the Data Act

The European Commission has provided clarification on the interaction between the Data Act and the Cyber Resilience Act (CRA) through its CRA FAQs published on 1 July 2026. The document addresses the relationship between both frameworks and the role of Data Act obligations in CRA cybersecurity risk assessments.

Key Commission clarifications

  • Different objectives: the CRA governs the placing on the market of products with digital elements, whereas the Data Act governs, amongst others, access to and sharing of product data and related service data in relation to connected products.
  • Dual applicability: the same product may fall within the scope of both instruments. The FAQs use the example of a smart refrigerator that is both a product with digital elements and a connected product under the Data Act.
  • Risk assessments: where a product with digital elements is also subject to Data Act access or sharing obligations, those obligations must be taken into account in the CRA cybersecurity risk assessment.
  • Product design: the FAQs clarify that the Data Act does not impose a strict obligation to redesign products. Manufacturers remain free to design products as they see fit, provided Data Act obligations are complied with.

While the CRA and the Data Act pursue different regulatory objectives, the FAQs confirm that both frameworks may apply to the same product simultaneously. The clarifications therefore provide additional context on how Data Act data-access obligations interact with CRA cybersecurity requirements.

3. European Health Data Space and Cyber Resilience Act: new CRA FAQ clarifications

The Commission's CRA FAQs also contain new guidance on how the EHDS and the CRA interact where both frameworks apply to the same product. This is particularly relevant for electronic health record (EHR) systems.

The EHDS is entering a multi-year implementation phase, with application taking place in stages between 2027 and 2031. The Regulation will progressively establish a common framework for the exchange and reuse of electronic health data across the EU while introducing a harmonised framework for electronic health record systems.

Key Commission clarifications

  • Dual applicability: an EHR system may also qualify as a product with digital elements under the CRA.
  • Separate compliance obligations: compliance with one framework does not automatically ensure compliance with the other.
  • Risk assessments: for products with digital elements that are also EHR systems, the CRA cybersecurity risk assessment may form part of the EHDS risk assessment.
  • Conformity assessment: for such products, the EHDS conformity assessment procedure applies instead of the CRA conformity assessment procedure for cybersecurity conformity assessment.

The FAQs therefore provide additional guidance on how cybersecurity requirements under the CRA are intended to operate alongside the sector-specific framework established by the EHDS.

4. Commission publishes CRA implementation guidance

On 27 July 2026, the European Commission published guidance on the application of the Cyber Resilience Act (CRA). The guidance is intended to support economic operators in preparing for CRA compliance and provide practical clarification on a number of key concepts under the Regulation.

Key topics covered by the guidance

  • Remote data processing: the guidance provides further clarification on the treatment of remote data processing solutions under the CRA, including when they are considered part of a product with digital elements.
  • Free and open-source software: the document explains when open-source software falls within the scope of the CRA and clarifies the distinction between manufacturers, contributors and open-source software stewards.
  • Substantial modifications: practical examples to help determine when software updates or product changes constitute a substantial modification that may trigger additional CRA obligations.
  • Support periods: the Commission provides additional guidance on determining support periods and on the relationship between support obligations, software updates and product lifecycles.
  • Cybersecurity risk assessments: the guidance further explains how manufacturers should assess cybersecurity risks, including risks linked to integrated components, external dependencies and remote services.
  • Reporting obligations: the guidance also addresses the reporting of actively exploited vulnerabilities and severe incidents. These reporting obligations will apply from 11 September 2026, while the CRA will apply in its entirety from 11 December 2027.

The guidance contains numerous examples and use cases intended to support practical implementation of the CRA, particularly for microenterprises as well as small and medium-sized enterprises. The document is intended to assist economic operators in preparing for compliance with the Regulation and may be complemented by further guidance in the future.

The European Commission's Guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act), published on 27 July 2026, is available here.

5. Important dates and deadlines Overview

5.1 Data Act: access-by-design requirements apply from 12 September 2026

The next major Data Act milestone will take effect on 12 September 2026. From that date, the access-by-design requirements in Article 3(1) will apply to connected products and related services placed on the market. The requirements apply across sectors and are relevant for connected products such as vehicles, smart-home devices, consumer electronics and industrial equipment.

Key access-by-design requirements

  • Connected products: product data must be accessible by default.
  • Related services: related service data must be accessible by default.
  • Direct access: where relevant and technically feasible, data should be directly accessible to the user.
  • Secure access: data must be made available in a secure manner.
  • Scope: the requirements apply to connected products and related services placed on the market after 12 September 2026.

The 12 September 2026 milestone does not mark the final implementation step of the Data Act. Further milestones remain, including the withdrawal of switching charges from 12 January 2027 and the extension of Chapter IV to certain existing contracts from 12 September 2027. Technical standardisation work supporting implementation of the Regulation is also ongoing.

5.2 Further Dates to look out for

With several regulatory developments entering new implementation phases, the coming years will bring a number of important application dates across the EU data and digital regulatory framework. The table below summarises selected dates to watch.

11 September 2026 - Cyber Resilience Act - Article 14 reporting obligations apply, including notification requirements for actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.

12 January 2027 - Data Act - Providers of data processing services may no longer impose switching charges for the switching process.

26 March 2027 - EHDS Regulation - General application date of the EHDS Regulation, subject to the phased implementation timetable in Article 105.

12 September 2027 - Data Act - Chapter IV on unfair contractual terms also applies to certain pre-existing contracts of indefinite duration and certain long-term contracts.

11 December 2027 - Cyber Resilience Act - Most CRA obligations apply, including the essential cybersecurity requirements for products with digital elements.

26 March 2029 - EHDS Regulation - Mandatory cross-border exchange for first-priority primary data (patient summaries, ePrescriptions) and start of secondary use rules.

26 March 2031 - EHDS Regulation - Mandatory inclusion of second-priority primary data (medical images, lab results, hospital discharge reports).

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.