EU · Scope comparison

EU Data Act vs GDPR: What SaaS and Connected-Product Teams Must Separate

The GDPR governs processing of personal data. The EU Data Act adds rules for specified data access, use and cloud switching situations. A connected-product feature and a SaaS switching service raise different Data Act questions; personal data in either remains subject to GDPR.

By The Data Protection OfficersReading time: 4 min
Original comparison diagram showing GDPR personal-data scope and distinct Data Act connected-product and cloud-switching tracks

What is the difference between the Data Act and GDPR?

The GDPR sets rules for processing personal data, including lawful basis, transparency, rights and security. The Data Act addresses access to and use of data generated by connected products and related services, plus other measures such as switching between data processing services. It can concern personal and non-personal data.

The Data Act has applied since 12 September 2025. Its provisions have distinct scopes and transition details. A SaaS label alone does not mean every connected-product provision applies. Identify the actual product, service, data and party before deciding which chapter matters.

An illustrative scope matrix

These fictional examples are issue-spotting tools. They are not a legal classification of a real product.

ActivityData Act questionGDPR question
Consumer fitness device sends usage data to an appConnected-product data access and sharing duties may be relevant; identify the user, holder and data.If the data identifies a person, assess roles, lawful basis, transparency and rights.
Standalone SaaS hosts customer recordsCloud/data-processing service switching provisions may be relevant; do not assume connected-product rules.Assess controller/processor roles, security, contracts and any transfers.
Industrial sensor records machine temperature onlyConnected-product data access may be relevant.GDPR applies if a person becomes identifiable in the particular dataset or context.

Handle overlap without treating one law as permission under the other

A Data Act access or sharing question does not remove GDPR conditions for personal data. Map the requested dataset, whether people can be identified, the parties' roles, legal basis, transparency, minimisation and security before any disclosure. Consult specialist Data Act advice for the chapter and contractual obligations actually engaged.

For a SaaS or connected-product team, a practical first step is a data map with the product feature, user, data holder, recipient, purpose and personal-data status. That map helps the privacy workstream and separate Data Act review ask the right questions.

Frequently asked questions

Does the EU Data Act replace the GDPR?

No. GDPR requirements continue to apply to personal data. The Data Act addresses separate data-access and switching issues and must be considered alongside applicable data protection law.

Does every SaaS provider have connected-product duties?

No. Assess which Data Act provisions fit the actual service. Cloud or SaaS switching provisions and connected-product data-access provisions have different scopes.

Keep researching

A practical next step

Make the next privacy decision clearer

Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.

This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.

Sources: EUR-Lex: GDPR, European Commission: Data Act explained

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services