One of the most important things to understand about the EU Data Act is that it does not care where your company is headquartered. If you manufacture a connected product that ends up in an EU customer’s hands, or if you provide digital services that support a connected product operating in the EU, the regulation’s obligations apply to you — whether you are based in San Francisco, Chicago, or Austin. This extraterritorial reach is deliberate and mirrors the approach the EU has taken with the General Data Protection Regulation, which US businesses learned about the hard way over the past several years.
This page explains how the Data Act’s territorial scope works, what it means to “place a product on the EU market,” and walks through the four primary scenarios in which US businesses find themselves subject to Data Act obligations. Understanding which scenario applies to your business is the starting point for building a practical compliance program.
The Extraterritorial Logic of the EU Data Act
The EU Data Act establishes its territorial scope in Article 2, which states that the regulation applies to manufacturers of connected products and providers of related services that are placed on the market in the Union, as well as to data holders that make data available to data recipients in the Union, and to providers of data processing services offering such services to customers in the Union. Critically, the regulation does not limit these categories to EU-established entities. Any manufacturer, service provider, or data holder — regardless of where they are located — that meets these criteria is subject to the regulation.
This approach reflects a broader principle in EU digital regulation: the EU is asserting jurisdiction based on the location of the market and the consumer, not the location of the regulator or the service provider. The logic is straightforward from the EU’s perspective: if a company wants access to the EU market, it must play by EU rules. The same principle underlies the GDPR’s extraterritorial reach, the Digital Services Act, the Digital Markets Act, and a growing body of EU technology regulation. US businesses that assumed EU regulations only applied to EU companies have had to update that assumption repeatedly over the past decade, and the Data Act continues that trend.
What Does ‘Placing a Product on the EU Market’ Mean?
The concept of “placing on the market” is a term of art in EU product law with a specific legal meaning. A connected product is considered placed on the EU market when it is first made available for distribution, consumption, or use on the EU market in the course of a commercial activity, whether in exchange for payment or free of charge. This typically occurs at the point of the first transaction in the EU supply chain — when a manufacturer sells a product to an EU distributor, when a product is sold through an EU e-commerce platform, or when a product is directly imported and sold to an EU customer.
The practical implication is that a US manufacturer does not need to have a physical presence in the EU — no warehouse, no office, no employees — for its products to be considered placed on the EU market. If your products are available for purchase in Europe, whether through a European distributor, an Amazon EU storefront, a European subsidiary, or direct export sales to European business customers, your products are on the EU market. The moment of placement is when the product enters the EU distribution chain, not when an individual consumer receives it.
There is an important distinction between products placed on the EU market before the Data Act’s obligations began applying (September 12, 2025) and products placed on the market after that date. The regulation applies to products placed on the market from that date forward. Legacy products already deployed with EU customers before the compliance date are not immediately subject to all obligations, though related services to those products may be subject to certain provisions sooner. Companies with large installed bases of connected products in Europe should verify their specific timing exposure.
Scenario One: US Manufacturer Selling Connected Products in the EU
The most straightforward scenario is a US company that designs and manufactures a connected product and sells it — directly or through distributors — to customers in EU member states. Examples include a US agricultural equipment manufacturer selling GPS-guided planting equipment to EU farms, a US medical device company selling connected glucose monitors to EU hospitals and pharmacies, a US industrial automation company selling connected sensor packages to EU factories, and a US consumer electronics company selling smart home appliances through EU retail channels.
In this scenario, the US manufacturer is the primary entity that the Data Act addresses. The manufacturer has designed the product, controls the backend systems that receive device data, and has a commercial relationship with EU customers. Under Chapter II of the Data Act, the manufacturer has obligations to make data generated by product use accessible to users in real time or on request, to design the product technically to support that access, and to ensure that contract terms with distributors and end users do not undermine user access rights.
The manufacturer in this scenario also has an obligation under Article 5 to designate an EU legal representative if the manufacturer has no establishment in the EU. An EU establishment could be a subsidiary, an affiliate, or a registered branch office. Many US manufacturers with significant EU sales operate through a European subsidiary that handles sales and distribution; if that subsidiary is the entity placing products on the market, it may itself be the relevant party for Data Act purposes. But if the US parent entity is the manufacturer that designs the product and controls the data, the legal analysis requires examining which entity in the corporate structure bears the regulatory obligations.
For manufacturers with EU subsidiaries, the Data Act analysis needs to engage with the corporate structure carefully. The subsidiary may be formally placing the product on the market, but if all data infrastructure, product design authority, and compliance decisions sit with the US parent, the practical compliance work must happen at the parent level. National enforcement authorities are likely to look through formal corporate structures to identify the entity actually controlling the relevant activities.
Scenario Two: US Company Providing Companion Apps or Related Services
A US company may not manufacture hardware at all, but may provide digital services that attach to connected products already in the EU market. This is an increasingly common business model in the IoT space, where device manufacturers and software/services providers are separate companies. If your company provides a mobile application that is required to configure or operate a connected product, a cloud platform that receives and processes data from connected devices, a firmware update service that maintains device functionality, or a remote monitoring service that adds features to a connected product, your company is providing a related service under the Data Act.
The related service provider has independent obligations under the Data Act that parallel the manufacturer’s obligations. Chapter II’s data access requirements apply to related service providers just as they apply to manufacturers. If your cloud platform is collecting data from connected devices operating in the EU, users of those devices have the right to access that data from you directly, to request that you share it with third parties they designate, and to have that access provided free of charge in a machine-readable format.
The related service scenario often catches US software companies off guard. A company that built a SaaS platform for managing IoT devices may have substantial EU business — EU factories using the platform to manage their sensor networks, EU healthcare providers using the platform to monitor connected medical equipment — without having thought carefully about whether the Data Act applies. The answer is almost certainly yes if the services are connected to products that qualify as connected products under the regulation, and if those products are used by EU customers.
US companies in this scenario need to assess their data architecture and determine what data they hold, how they could provide user access to that data, what technical and contractual changes would be needed to enable users to direct that data to third parties, and whether they need to designate an EU legal representative. The legal representative obligation applies to related service providers that have no EU establishment, just as it applies to manufacturers.
Scenario Three: US Cloud Provider Serving EU Customers
US cloud infrastructure providers — infrastructure-as-a-service and platform-as-a-service companies — face a distinct set of obligations under Chapter V of the Data Act, which is specifically aimed at preventing vendor lock-in in cloud services. This chapter applies to providers of data processing services that offer their services to customers in the EU, regardless of where the provider is based.
Chapter V requires cloud providers to enable customers to switch to a competing provider or to bring data processing in-house. This must be achievable within a defined maximum period, must be technically possible through standardized data portability mechanisms, and must not be impeded by excessive switching fees. The regulation establishes a schedule for reducing and eventually eliminating switching fees: providers cannot charge fees for switching after a transitional period defined in the regulation.
For the major US cloud hyperscalers — Amazon Web Services, Microsoft Azure, Google Cloud — Chapter V is directly applicable to their EU business. These providers have all made public statements about Data Act compliance and have begun adapting their service agreements and technical offerings. But Chapter V also applies to smaller US cloud and data processing service providers that may not have been thinking about EU data regulation at all. If your company sells cloud-based data storage, data processing, database services, or machine learning infrastructure to EU businesses that themselves operate connected products, Chapter V obligations attach to your service offerings.
The practical demands of Chapter V compliance for cloud providers include ensuring that data can be exported in standard, interoperable formats; ensuring that switching to another provider or to an on-premises deployment is technically feasible; revising service level agreements and exit clauses to reflect the regulation’s requirements; and restructuring any pricing models that create economic barriers to switching. US cloud providers with material EU customer bases should be working through these changes now if they have not done so already.
Scenario Four: US Companies with B2B Data-Sharing Agreements with EU Counterparts
A fourth scenario arises when US businesses enter into data-sharing agreements with EU counterparts that involve data generated by connected products. Chapter III of the Data Act governs the sharing of data between businesses (B2B data sharing) and establishes a framework for fair, reasonable, and non-discriminatory terms in data-sharing contracts. Chapter IV addresses situations where EU regulation or contractual arrangement requires a data holder to make data available to a third party.
If your US business is a data recipient under such an agreement — meaning you receive data from an EU data holder pursuant to a Data Act-compliant arrangement — you are subject to the use restrictions that the Data Act imposes on data recipients. These restrictions prohibit using received data to develop competing products that directly compete with the connected product from which the data was generated, prohibit sharing the data with unauthorized third parties, and require appropriate security measures.
US companies that are negotiating data licensing agreements, data purchase agreements, or data access agreements with EU manufacturers or data platforms need to understand that those contracts now exist within a regulatory framework that imposes mandatory terms. Agreements that purport to grant data recipients broader rights than the Data Act permits, or that impose obligations on users or third parties that the Data Act prohibits, are unenforceable as to those provisions. Contracts structured before the Data Act took effect may need to be reviewed and updated.
Conversely, US companies that hold data from connected products and are sharing that data with EU counterparts need to understand the Data Act’s framework for B2B data sharing, including the requirement that contractual terms be fair, reasonable, and non-discriminatory. A US data holder that licenses proprietary device data to multiple EU business customers must ensure that its licensing terms comply with these standards, or face the risk that EU counterparts can challenge the terms before national authorities or courts.
The Interaction Between the Data Act and EU Market Access
For US businesses, the Data Act must be understood as a condition of EU market access, not an optional compliance exercise. EU national market surveillance authorities — the agencies responsible for enforcing product regulations in each member state — have authority to remove products from the EU market that do not comply with applicable regulations. While the Data Act’s primary enforcement mechanisms operate through administrative penalties assessed by data protection or market surveillance authorities, the ultimate threat is market exclusion.
The incentive structure is clear: a US manufacturer that wants to sell connected products in Germany, France, Italy, and the rest of the EU single market must comply with the Data Act. There is no exemption for foreign manufacturers, no de minimis threshold based on revenue or number of products sold, and no grace period for businesses that discover their non-compliance after the regulation has taken effect. The compliance question is binary: either the product and its associated services satisfy the Data Act’s requirements, or they do not.
US businesses that are in the early stages of EU market entry have an advantage: they can design Data Act compliance into their products and systems from the start, rather than retrofitting compliance onto existing infrastructure. For US businesses with large existing EU customer bases, the urgency is higher. The practical question is not whether to comply, but how quickly the necessary changes can be made and in what sequence.
Enforcement and the Cross-Border Dimension
Enforcement of the Data Act against non-EU entities raises practical questions that EU regulators are still working through. National market surveillance authorities in each EU member state are responsible for enforcement within their territory. They can require manufacturers to demonstrate compliance, can order products to be withdrawn from the market, and can impose administrative fines. However, actually reaching a US-based entity that has no EU presence to receive notices, respond to inquiries, or pay fines requires either the use of EU legal representative mechanisms (which is why the legal representative obligation exists) or complex cross-border enforcement cooperation.
The EU has tools available to address non-cooperative foreign entities, including blocking products at EU customs borders and working through mutual recognition arrangements and trade frameworks. But the most direct enforcement mechanism for non-EU companies is the legal representative system: by requiring manufacturers without EU establishments to designate an EU-based representative who can be held responsible for compliance, the Data Act creates a local enforcement point even when the manufacturer itself is abroad.
The practical lesson for US businesses is that maintaining a cooperative posture toward Data Act compliance — designating a legal representative, responding to user data access requests, engaging constructively with national authorities — is far less costly than the alternative. Companies that ignore the regulation and hope enforcement never reaches them are taking a risk that is increasingly difficult to justify as EU digital regulation matures and enforcement mechanisms become more sophisticated.
