Data Act and DPP: access to product data
The Data Act and the Digital Product Passport (DPP) are two different regulations, but they share a common direction: more access to data and less dependence on a single vendor. This article explains what the Data Act covers, why it is not the same as ESPR — and what connects the two approaches in practice.
What the Data Act is
The Data Act, Regulation (EU) 2023/2854, governs access to and sharing of data — including data generated by connected products. It also sets out rules on fair data sharing in B2B and B2C relationships, and on data portability.
The idea is that data produced while a product is used should not stay locked in with a single party. The user and other authorised parties should be able to access it and move it between services. This shifts data from something held by one provider toward something the user can genuinely control.
The Data Act is not ESPR
As with other neighbouring regulations, the Data Act must be kept clearly apart from ESPR and the DPP. The Data Act does not create a product passport and imposes no ecodesign obligations.
It is a separate regulation about data — about who has access to it and on what terms it can be moved. The DPP, by contrast, is a specific layer of product data required under ESPR. More on the passport itself in What is a DPP.
Data from connected products
A particularly important strand of the Data Act concerns connected products that generate data while they are used. The regulation pushes for the user and other authorised parties to be able to make use of that data, rather than leaving it solely in the hands of a single party.
For companies that design products, this signals that access to data is becoming part of the product itself — much as it is in the logic of the digital passport. Although the two regimes remain distinct, the direction is aligned: data should be available where it is needed, and to those entitled to it. That is a shift in how product data is expected to flow.
A shared direction: access and portability
Although they are different regimes, the Data Act and the DPP head in the same direction. Both strengthen data access, portability and the avoidance of vendor lock-in.
For a company this is an important signal: product data is increasingly expected to be open, exportable and shareable with various authorised parties. Choosing a solution that makes this possible fits the broader direction of EU data policy, rather than working against it.
What to require from a DPP provider
The same spirit shows up in the requirements placed on DPP service providers. When choosing a platform, three features are worth watching for:
- Portability and data export — data in a structured format, with no lock-in to a single provider.
- Backup and continuity — safeguarding the data and the ability to restore it.
- Layered access — roles and permissions: public data, B2B data and data for authorities.
These requirements are not accidental. They mirror the same spirit of openness and control over data that stands behind the Data Act.
Openness as an architectural choice
The way a company stores and shares product data is a decision that lasts for years. Choosing a closed solution that makes data hard to export complicates later migrations and the task of meeting new obligations.
The opposite choice — betting on open formats, clear access rules and the ability to export — reduces the risk of lock-in and loss of control. This approach sits well with both the DPP and the spirit of the Data Act, and it simply makes everyday work with product data easier. It also keeps your options open if you later change tools or partners.
Why this matters in practice
By choosing a DPP approach with open export and layered access, a company does more than meet the passport requirements. It also aligns its product data with the broader EU direction — toward greater access and less dependence on any single system.
This is a practical benefit independent of any specific rule: data that can be freely exported and shared with authorised parties is easier to reuse in later obligations. We describe links with other regimes in CSDDD and due diligence and PPWR and digital packaging marking.
Key takeaways
- The Data Act (Regulation (EU) 2023/2854) governs access to and sharing of data, including data from connected products.
- It is neither ESPR nor a DPP — the Data Act is about data, not ecodesign or a product passport.
- The shared direction of both approaches is access, portability and avoiding vendor lock-in.
- From a DPP provider, expect data export, backups and layered access.
- Open, portable product data fits the broader direction of EU data policy.
See how CyfroPass gives you full control over your product data through open export and layered access. Visit cyfropass.pl and keep your data in your own hands.