Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Dutch DPA and ACM begin supervision of European Data Act

On 25 November 2025, the Dutch Implementing Act for the European Data Act came into force, enabling national supervision. This legislation obliges manufacturers of connected devices to give users access to the data they generate. It also obliges cloud service providers to simplify switching between platforms.

The European Data Act, in force since September 2025, aims to give EU consumers greater control over data from connected products. The Dutch Implementing Act for the Data Act, effective 21 November 2025, designates the Autoriteit Persoonsgegevens AP and the Autoriteit Consument & Markt ACM as national supervisors.

The AP supervises Data Act provisions related to the General Data Protection Regulation GDPR. It confirms that the Data Act supplements the GDPR and does not detract from its rules, with the GDPR taking precedence in cases of conflicting rules. This means any data sharing involving personal data must comply with the GDPR. The AP also oversees data requests by government authorities in exceptional emergencies. The ACM is designated as the national data coordinator for the Data Act, supervising how companies provide consumers access to data from connected devices and handle data sharing requests. A key focus for the ACM is ensuring companies are transparent with consumers and other businesses about data collection and access. Additionally, the ACM supervises cloud services established in the Netherlands, focusing on simplifying switching between cloud providers and improving interoperability.

Key provisions of the Data Act include obliging manufacturers of connected devices to give users access to the data they generate, encouraging fair contractual agreements on data sharing between companies, obliging cloud service providers to simplify switching between platforms, and regulating government access to company data in exceptional emergencies.

Original title: Toezicht op Europese Dataverordening van start

Dataverordening

Who this binds
Manufacturers of connected devices, cloud service providers, and companies handling data from connected devices are now bound by these rules.
What changed
The Dutch Implementing Act for the Data Act came into force on 21 November 2025, enabling national supervision by the AP and ACM.
What to check
Organisations should review their data access and sharing practices for connected devices and cloud services to ensure compliance with the Data Act and GDPR.
What this does not mean
This does not mean that all data sharing is now subject to the Data Act; only data from connected products and related services are primarily in scope.

Send this to your team

The Dutch Autoriteit Persoonsgegevens and Autoriteit Consument & Markt began supervision of the European Data Act on 25 November 2025, obliging manufacturers of connected devices to give users access to their generated data and cloud service providers to simplify platform switching.

Today's question

A social media platform operating in the EU is considering implementing an age verification system to comply with potential future regulations aimed at protecting minors. Based on recent rulings, what is a critical consideration for such a system?

  1. The system must only collect age data and immediately delete it after verification.
  2. The system must be proportionate and include robust safeguards for the right to respect for private life.
  3. The system should rely solely on self-declaration of age to avoid data collection.
  4. The system must be approved by a national data protection authority before deployment.

Answer this question on the site

Worth knowing

  1. RingCentral suffers data dump of 1.6 million accounts after ShinyHunters extortion attack

    Organisations using RingCentral services should advise their employees to be vigilant for phishing attempts and review their security protocols following the exposure of 1.6 million accounts.

  2. Boston Healthcare for the Homeless Program breach affects over 185,000 state residents

    HIPAA covered entities and business associates should assess their data security practices, particularly in light of the significant breach at the Boston Healthcare for the Homeless Program affecting a large number of residents.

  3. North Carolina election vendor data exposed in cyberattack

    The potential exposure of North Carolina poll workers' data due to a cyberattack on an election software vendor highlights the critical vulnerabilities within election infrastructure and the sensitive personal data it handles.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.