Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Dutch Data Protection Authority to Oversee Data Act Compliance, Focusing on Connected Products

Effective 21 November 2025

On 25 November 2025, the Dutch Data Protection Authority (AP) announced its supervisory role for the European Data Act, following the Data Act Implementation Act coming into force on 21 November 2025. This new regulation obliges manufacturers of connected devices to give users access to the data they generate. It also mandates cloud service providers to simplify switching between platforms.

The European Data Act has been effective since September 2025, and in the Netherlands, its Implementation Act came into force on 21 November 2025. This enables the Autoriteit Consument & Markt (ACM) and the Autoriteit Persoonsgegevens (AP) to supervise its compliance. The Data Act aims to provide individuals with greater control over data from their connected products, such as smart devices, by increasing insight into collected data and facilitating user control over its use and sharing.

The AP is designated as the supervisor for Data Act provisions linked to the General Data Protection Regulation (GDPR). The Data Act supplements the GDPR and does not derogate from its rules; in cases of conflicting rules, the GDPR takes precedence. This means any data sharing involving personal data must comply with the GDPR. The AP also oversees data requests by government authorities in situations of exceptional necessity, for example, during disaster relief. The ACM acts as the national data coordinator, supervising how companies provide consumers access to connected device data and handle data sharing requests. The ACM also monitors Dutch cloud services, ensuring the Data Act's goal of easier switching between cloud providers and improved interoperability is met.

The Data Act specifically obliges manufacturers of connected devices to give users access to the data they generate. It also mandates cloud service providers to simplify switching between platforms. Furthermore, it regulates that governments can access company data in exceptional emergencies.

The recurring challenge of defining regulatory oversight for data sharing and access often turns on the division of responsibilities between national authorities like the AP and ACM, particularly when new EU instruments intersect with existing data protection frameworks.

Original title: Toezicht op Europese Dataverordening van start | Autoriteit Persoonsgegevens

Data Act

Who this binds
Manufacturers of connected devices, cloud service providers, and companies handling data sharing are now on the hook.
What changed
The Data Act Implementation Act came into force on 21 November 2025, establishing the supervisory roles of the AP and ACM for the Data Act.
What to watch
Organisations should watch for further guidance from the AP and ACM regarding specific compliance requirements for data access, sharing, and cloud switching.
What this does not mean
This does not mean that the Data Act overrides the General Data Protection Regulation; the GDPR takes precedence in cases of conflicting rules, especially concerning personal data.

Send this to your team

The Dutch Data Protection Authority (AP) and the Autoriteit Consument & Markt (ACM) now supervise the Data Act in the Netherlands, obliging connected device manufacturers to provide user data access and cloud providers to simplify platform switching.

Today's question

A company operating in the Netherlands offers smart home devices that collect user data on energy consumption and daily routines. Following the effective date of the Data Act Implementation Act, what new obligation primarily applies to this company regarding user data?

  1. The company must obtain explicit consent for all data processing activities, including anonymised data.
  2. The company must provide users with greater insight into the collected data and enhanced control over its sharing.
  3. The company must transfer all collected data to a government-approved data repository for public access.
  4. The company must cease collecting any data that is not strictly necessary for the device's core functionality.

Answer this question on the site

Worth knowing

  1. French Constitutional Council Strikes Down Under-15 Social Media Ban

    Organisations operating social media platforms in France should note this ruling, as it impacts age verification requirements and the scope of permissible restrictions on minors' access to services.

  2. RingCentral Data Dumped After ShinyHunters Extortion Attack Affecting 1.6 Million Accounts

    Organisations using RingCentral should advise their employees and customers to be vigilant against phishing attempts and consider credential resets, as personal data has been exposed.

  3. SafePal customers warned of phishing after data breach

    Privacy professionals should advise cryptocurrency hardware wallet users to be vigilant against phishing attempts following the SafePal data breach, as compromised order information can facilitate targeted social engineering attacks.

  4. Boston Healthcare for the Homeless Program data breach affects 185,000 residents

    Healthcare privacy professionals should note this breach affecting 185,000 residents signals increased scrutiny on data security for non profit organisations serving vulnerable populations.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.