The data position is generally transaction-ready.
Record assumptions, interfaces and contractual duties in the data room. The SPA should address key data rights, cooperation duties and switching risks expressly.
Data Act in acquisitions: review connected-product data, cloud switching, access rights and SPA risks before signing.
BRANDAUER Rechtsanwälte
Salzburg law firm for corporate, company and transaction law
Every transaction is handled by a coordinated team of lawyers, legal staff and specialists. In company acquisition matters we look at structure, contract, tax and liability together.
The Data Act changes data-driven acquisitions because the issue is no longer only who holds a database. Buyers must understand access rights, usage rights and switching possibilities around connected products, IoT services, platforms and cloud-based operations.
Seeing data in the data room is not enough. The legal review must ask whether the target may use the data, whether customers or users can request access and whether cloud contracts allow a technically and commercially viable switch.
These questions show whether the issue needs legal and technical review before signing.
Already know you want to get in touch? Go straight to the enquiry form.
If yes, the Data Act belongs in the legal, technical and commercial review.
Record assumptions, interfaces and contractual duties in the data room. The SPA should address key data rights, cooperation duties and switching risks expressly.
If data access, cloud portability or customer usage rights remain open, the buyer should clarify price effect, warranties, conditions and post-closing steps before closing.
Regulation (EU) 2023/2854 can matter when buying a software or SaaS business whose products or services generate usage data.
The buyer must know whether the target can exploit data exclusively or whether users, customers or third parties may have access rights. That affects valuation and integration planning.
The Data Act review sits next to data protection due diligence. GDPR compliance alone does not answer whether the target can keep, share or port data commercially.
Cloud contracts should be reviewed for switching rights, export formats, termination, support obligations and technical lock-in. A low price is unattractive if migration later blocks the operating model.
Data Act findings belong in warranties, disclosure, cooperation covenants and, where needed, conditions to completion. The deal should also allocate the costs of interfaces, contract amendments and technical remediation.
Legal and technical due diligence should work from one list: data sources, right holders, cloud dependencies, customer duties and integration steps.
The overview separates finding, risk and deal response.
| Point | Review | Consequence |
|---|---|---|
| Usage data Who may use product-generated data? | Warranty and data room disclosure | |
| Cloud switching Can the service be switched legally and technically? | Cost budget and cooperation duty | |
| Customer rights Are access or export claims possible? | Contract amendment or price risk | |
| Integration Do interfaces and export formats work? | Post-closing plan |
The concrete drafting depends on the target, data room and negotiating position.
Practical point: Data Act risks are rarely legal footnotes only. Buyers should review technical export capability, contract position and commercial effect together before fixing price and warranties.
No. Data protection law and the Data Act may both matter, but they ask different questions.
Because technical lock-in can affect integration cost, operating risk and bargaining power after closing.
Yes, if access or portability is economically relevant, warranties, disclosure and remediation should be drafted expressly.
Direct follow-up for deeper review.
Direct follow-up for deeper review.
Direct follow-up for deeper review.
Direct follow-up for deeper review.
Direct follow-up for deeper review.
When buying a company, structure, review and contract decide. Call us directly or send an email, callback within one business day.
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg
Phone
+43 662 6280000