Amid the promises of the Data Act and transatlantic uncertainties, the issue of data portability remains
The difficulties in implementing the new European regulations, which came into full effect in September, and the ruling that threatens the independence of the US Federal Trade Commission (FTC) are once again complicating the landscape of data and cloud services regulation on both sides of the Atlantic
Data portability was supposed to be the major achievement of the European Data Act, the regulation designed to give businesses back control over the information generated by their connected devices and cloud services. But just a few months before the main provisions come into force, the picture is becoming more complicated: on the one hand, there are operational teething problems in applying the new rules; on the other, a US court ruling that risks undermining the entire framework for data transfers between the European Union and the United States.
The alarm has been raised once again by a decision of the US Supreme Court, which undermines the Federal Trade Commission’s autonomy vis-à-vis the President’s powers. The ruling, which limits the powers of the federal agency responsible for overseeing privacy and unfair commercial practices, could have direct repercussions on the Data Privacy Framework – the agreement that, from 2023, will allow the transfer of personal data from the EU to the US.
That framework is, in fact, based on the premise that the US authorities provide adequate protection: if the FTC is weakened, the entire legal structure could collapse, reviving the situation we have already seen with the Schrems I and II judgements, which invalidated the previous Safe Harbour and Privacy Shield agreements.
It is against this backdrop of geopolitical uncertainty that the operational challenges posed by the Data Act arise; the Act came into force at the start of 2024, with its main provisions taking effect in September 2025.
The regulation introduces stringent obligations for manufacturers of connected devices and for cloud service providers: the former must make data generated through the use of their products accessible to users, whilst the latter must facilitate migration to alternative providers by removing the technical and contractual barriers that have hitherto fuelled vendor lock-in.


