EU Data Act vs GDPR: What SaaS and Connected-Product Teams Must Separate
The GDPR governs processing of personal data. The EU Data Act adds rules for specified data access, use and cloud switching situations. A connected-product feature and a SaaS switching service raise different Data Act questions; personal data in either remains subject to GDPR.

What is the difference between the Data Act and GDPR?
The GDPR sets rules for processing personal data, including lawful basis, transparency, rights and security. The Data Act addresses access to and use of data generated by connected products and related services, plus other measures such as switching between data processing services. It can concern personal and non-personal data.
The Data Act has applied since 12 September 2025. Its provisions have distinct scopes and transition details. A SaaS label alone does not mean every connected-product provision applies. Identify the actual product, service, data and party before deciding which chapter matters.
An illustrative scope matrix
These fictional examples are issue-spotting tools. They are not a legal classification of a real product.
| Activity | Data Act question | GDPR question |
|---|---|---|
| Consumer fitness device sends usage data to an app | Connected-product data access and sharing duties may be relevant; identify the user, holder and data. | If the data identifies a person, assess roles, lawful basis, transparency and rights. |
| Standalone SaaS hosts customer records | Cloud/data-processing service switching provisions may be relevant; do not assume connected-product rules. | Assess controller/processor roles, security, contracts and any transfers. |
| Industrial sensor records machine temperature only | Connected-product data access may be relevant. | GDPR applies if a person becomes identifiable in the particular dataset or context. |
Handle overlap without treating one law as permission under the other
A Data Act access or sharing question does not remove GDPR conditions for personal data. Map the requested dataset, whether people can be identified, the parties' roles, legal basis, transparency, minimisation and security before any disclosure. Consult specialist Data Act advice for the chapter and contractual obligations actually engaged.
For a SaaS or connected-product team, a practical first step is a data map with the product feature, user, data holder, recipient, purpose and personal-data status. That map helps the privacy workstream and separate Data Act review ask the right questions.
Frequently asked questions
Does the EU Data Act replace the GDPR?
No. GDPR requirements continue to apply to personal data. The Data Act addresses separate data-access and switching issues and must be considered alongside applicable data protection law.
Does every SaaS provider have connected-product duties?
No. Assess which Data Act provisions fit the actual service. Cloud or SaaS switching provisions and connected-product data-access provisions have different scopes.
Keep researching
Related resources
A practical next step
Make the next privacy decision clearer
Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.
This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.
Sources: EUR-Lex: GDPR, European Commission: Data Act explained
