Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Should You Treat EU Data Act Compliance as a Cost Center or a Revenue Play?Privacy and Security
5 min readFor Enterprise IT Leaders

Should You Treat EU Data Act Compliance as a Cost Center or a Revenue Play?

The question at hand

The EU Data Act presents a unique choice: build a basic compliance framework by the September 2025 deadline, or redesign your data architecture to prioritize user access rights and gain a competitive edge. The first approach views the regulation as a constraint on intellectual property and operational control. The second sees it as a catalyst for new service models and market differentiation.

This isn't just theoretical. By September 12, 2026, every new connected product in the EU market must implement "access by design," granting users direct, secure access to machine-generated data in structured formats. Your team needs to decide now whether you're building that capability as a compliance checkbox or as the foundation for your next revenue stream.

The case for defensive compliance

A defensive stance treats the Data Act as a risk to manage. This is sensible for manufacturers whose competitive advantage relies on proprietary telemetry, diagnostic algorithms, or operational insights embedded in product data.

You're required to give users access to raw sensor outputs, pre-processed data, metadata, and machine-generated insights. If your industrial machinery's performance data reveals production methods, or your medical device telemetry exposes algorithmic logic, you're handing potential trade secrets to users who can share that data with third parties. The act's "trade secrets handbrake" lets you identify proprietary information before disclosure, require confidentiality safeguards, and in limited cases refuse sharing if protections can't be agreed upon. But this mechanism isn't a veto right. You can't blanket-designate all telemetry as proprietary, and users can challenge overly broad assertions.

The defensive approach involves building the minimum technical infrastructure to comply, investing in trade secret identification and confidentiality frameworks, and slowing third-party data sharing wherever the handbrake applies. Your legal and IP teams should map every data flow against proprietary risk, update contracts to specify disclosure safeguards, and prepare to litigate boundary cases where user access rights conflict with legitimate trade secret protections.

This approach also acknowledges operational friction. If you operate closed ecosystems where proprietary data enables lock-in for maintenance, repairs, or complementary services, the act's interoperability mandate directly threatens your business model. Treating compliance as a cost center means you're protecting existing revenue rather than chasing new models.

The case for offensive opportunity

The offensive view sees the regulation as a chance to gain a first-mover advantage. If you're competing in multi-vendor environments, industrial IoT, or any market where interoperability matters, being Data Act-ready isn't just compliance. It's a trust signal and a differentiation point.

The act empowers users to instruct you to share their generated data with third parties. This provision unlocks after-market services, independent repair networks, cross-platform analytics, and modular service ecosystems previously blocked by proprietary constraints. If you're the manufacturer who makes data sharing frictionless while competitors resist, you capture the customer relationship and the downstream service revenue.

Consider the broader architecture play. You're already required to provide data in machine-readable formats. If you build that capability as a platform feature rather than a compliance bolt-on, you can offer premium data-enabled services, real-time analytics, and user-controlled data marketplaces. You can position your products as integration-friendly in B2B contexts where procurement teams increasingly value vendor-neutral data access.

The offensive strategy also anticipates future regulation. The Data Act applies extraterritorially to non-EU companies whenever EU users interact with your products or services. If you're a global manufacturer, you're building this capability anyway. The question is whether you build it as a regional compliance tax or as a global product feature that differentiates you in every market.

This approach requires cross-functional governance involving legal, privacy, product, engineering, IP, and security teams. You're not just updating user agreements and B2B contracts. You're redesigning data flows, API strategies, and service architectures around the assumption that users own access rights to the data your products generate.

Where practitioners actually land

Most organizations split the difference based on product line economics. If you manufacture high-margin industrial equipment where proprietary diagnostics drive service contracts, you're likely taking the defensive posture. You'll comply with access mandates but invest more in trade secret protections than in data-sharing infrastructure.

If you operate in competitive consumer markets, B2B platforms, or sectors where GDPR already forced transparency, you're more likely to treat the Data Act as an accelerant. You're building interoperability features, updating privacy controls to handle user-designated third-party sharing, and marketing your Data Act readiness as a procurement advantage.

The middle ground involves tiered compliance. You implement baseline "readily available data" access for all products, meaning you provide data upon request at no cost if direct access isn't technically feasible. But you reserve premium, real-time, API-enabled access for products where you see service revenue potential. You use the trade secrets handbrake selectively, applying it only where genuine proprietary risk exists rather than as a blanket objection to data sharing.

Where personal data overlaps with product-generated data, GDPR obligations take precedence. Your team already has minimization and transparency controls in place. The Data Act adds a layer of non-personal data governance that runs parallel to privacy compliance but doesn't replace it.

Our take

Treat the Data Act as a catalyst for data architecture modernization, not as a one-time compliance project. The regulation's real impact isn't the September 2025 effective date. It's the long-term shift toward user-controlled data ecosystems that make proprietary lock-in harder to sustain.

If your competitive advantage depends on closed data loops, invest in the trade secrets handbrake and prepare for friction with users who want broader sharing rights. But don't mistake compliance minimalism for strategy. Your competitors who build interoperability and data portability as product features will capture customers who value vendor neutrality, and you'll be defending margin in a shrinking addressable market.

If you can monetize data access, user-centric controls, or third-party integrations, build those capabilities now while the regulation is still new and customer expectations are forming. The companies that define "Data Act-ready" as a market category will set the standard everyone else has to meet.

The tradeoff is real: you're choosing between protecting existing revenue streams and positioning for new ones. But the regulation makes that choice unavoidable, and delaying the decision just means your competitors make it first.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like