Data
17/9/26

Connected products under the Data Act: what access by design demands from 12 September 2026

Connected products placed on the EU market after 12 September 2026 must give users their data by default. What access by design requires and how to prove it.

Tiempo Estimado de lectura:

10 min read

Guillermo Passas Varo

A smart thermostat records the temperature of a living room every few minutes. A combine harvester logs fuel burn, yield per hectare and every hydraulic fault. A running watch knows its owner's pace better than the owner does. For years, whoever built the device decided who could read that record, and the answer was usually the manufacturer. Connected products placed on the EU market after 12 September 2026 must be built so that their users can reach that data themselves. The Data Act calls this access by design, and it is a question of engineering long before it becomes a question of paperwork (Regulation (EU) 2023/2854, Articles 3(1) and 50).

The Regulation has applied since September 2025. What arrived on 12 September is the design deadline, and the Regulation measures it unit by unit. That detail decides which products in a catalogue are caught, and it is the one most summaries skip.

What is a connected product, and what is a related service?

A connected product is any item that obtains, generates or collects data about its use or its environment and can communicate that data through an electronic communications service, a physical connection or on-device access (Article 2(5)). The definition is wide on purpose: Recital 14 mentions vehicles, home equipment, medical devices, ships, aircraft and agricultural and industrial machinery. Prototypes stay outside, as do servers run entirely on behalf of third parties (Recitals 14 and 16).

The data at stake are product data: whatever the device generates through use and was designed to let someone retrieve (Article 2(15)). Think of them as the logbook the machine writes while it works, which the Regulation wants its owner to be able to read. The logbook covers raw sensor readings and data pre-processed to make them understandable, standby periods included. Insights the manufacturer derives with its own complex, proprietary algorithms fall outside (Recital 15).

A related service is the digital service that makes the product work, or that is connected later to add to, update or adapt its functions (Article 2(6)). The app that sets a thermostat's schedule is one. So is a platform that lets a farm contractor change a harvester's settings from a laptop. The Commission's FAQs read the definition as requiring data to travel both ways, with the service affecting how the product behaves. An analytics dashboard that sends nothing back to the device, routine maintenance, electricity and connectivity are left out (Recital 17). When the related service runs in the cloud and is sold to business customers, it may also be a data processing service caught by the switching rules, which we covered in our piece on the Data Act and SaaS providers outside Europe.

What does access by design require from 12 September 2026?

Article 3(1) sets the standard. Product data and related service data, together with the metadata needed to interpret and use them, must be accessible to the user by default: easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, directly.

Picture two houses. In the first, the fuse box sits in a locked room and the builder keeps the key, so the owner calls the builder every time a switch trips. In the second, the fuse box hangs in the hallway, within the owner's reach. Access by design asks manufacturers to build the second house. A user account that exports a CSV, a local API on the home network or a port that dumps readings to a laptop all put the fuse box in the hallway. A support email address leaves it in the locked room.

Two consequences are easy to miss. Metadata travel with the data, because a temperature reading is useless once separated from its unit and timestamp (Recital 15). And there is no duty to hoard: the Regulation does not oblige a device to store data it was never designed to keep, and it leaves the GDPR's data minimisation principle intact (Recital 20).

One trap sits in the backend. In the September 2025 update of its FAQs, the Commission made clear that anonymising or encrypting data once they reach the manufacturer's servers does not, by itself, take them out of scope. Users and the third parties they authorise should get a reasonable chance to obtain the raw or pre-processed copy first.

Placed on the market after 12 September 2026: each unit has its own birthday

Placing on the market means the first making available of a connected product on the Union market (Article 2(22)). The Commission's FAQs, drawing on the Blue Guide on EU product rules, attach that concept to each individual product, whatever model it belongs to.

Every unit has its own birthday, even when it comes out of the same mould as its siblings. A smart meter delivered to an EU distributor on 10 September was placed on the market before the cut-off and may stay as it is. An identical meter from the same batch, first supplied into the Union on 14 September, must comply with Article 3(1). For a product range that straddles the date, that means:

  • Units supplied to an EU distributor before the cut-off can be sold on as they are.
  • Units still held by the manufacturer, inside or outside the Union, are caught when first supplied for distribution or use in the EU after 12 September.
  • Two customers holding the same model can have different rights, and the manufacturer needs to know which unit is which.

The FAQs add two points for products that move. Registration in a Member State indicates that a car or a boat was placed on the EU market, and once it has been, the data it generates abroad still count. A device a consumer buys in a shop outside the Union, while physically there, has not been placed on the EU market. The practical upshot: a manufacturer that cannot show when each unit or batch entered the Union market cannot show which regime governs it.

The information users must get before they sign already applies

Only paragraph 1 of Article 3 was deferred. The information duties in paragraphs 2 and 3 have applied since 12 September 2025 under the general rule in Article 50. Before a sale, rental or lease, the seller, rentor or lessor must tell the user the type, format and estimated volume of data the product can generate, whether it does so continuously and in real time, where and for how long it stores them, and how the user can access, retrieve or erase them (Article 3(2)).

Before a related service contract, the provider must add, among other things, whether it will use the data itself and for what, whether third parties will use them, who holds any trade secrets in the data, and the user's right to complain to the competent authority (Article 3(3)). Recital 24 suggests a workable format: a stable URL, shared as a link or as a QR code on the box.

When direct access is not possible: requests, third parties and gatekeepers

Where the user cannot reach the data directly, the data holder must provide readily available data and metadata on a simple request, electronically where feasible, "without undue delay", at the same quality it enjoys, free of charge and, where relevant, continuously and in real time (Article 4(1)). Readily available data are those the holder can lawfully obtain with no more than a simple operation (Article 2(17)).

Choosing between direct access and access on request is a design decision that deserves to be written down. Article 3(1) makes direct access the rule where relevant and technically feasible, and Article 4 is the fallback. A manufacturer relying on the fallback should be able to explain why the hallway had no room for the fuse box.

The user can also have the data sent to a third party of its choice, such as an independent repair shop or an insurer pricing cover on real usage (Article 5(1)). That third party may use the data only for the purposes agreed with the user, must erase them once they are no longer needed and may not use them to build a competing product (Article 6). Gatekeepers designated under the Digital Markets Act are excluded altogether: they cannot receive the data, solicit it or pay users to pass it on (Article 5(3)), and no third party may hand it to them (Article 6(2)(d)).

Can a manufacturer refuse to share trade secrets?

Rarely, and only with a paper trail. The default is disclosure with safeguards: the holder identifies which data are trade secrets, including in the metadata, and agrees proportionate measures with the recipient, such as confidentiality agreements or strict access protocols (Articles 4(6) and 5(9)).

Refusal comes in two sizes. If the measures cannot be agreed, or the recipient ignores them or undermines confidentiality, the holder may withhold or suspend the trade secret data by a substantiated written decision notified to the competent authority (Articles 4(7) and 5(10)). In exceptional circumstances, a holder that owns the secret may refuse a specific request if it shows, on objective elements, that serious economic damage is highly likely despite the measures. The elements the Regulation names include the enforceability of trade secret protection in third countries and the novelty of the product (Articles 4(8) and 5(11)).

Recital 31 closes the obvious loophole: a trade secret label alone is no ground for refusal, and serious economic damage means serious and irreparable loss. Any refusal can be challenged before the competent authority, a dispute settlement body or the courts (Articles 4(9) and 5(12)).

Are small companies exempt?

Microenterprises and small enterprises are outside the whole of Chapter II for the connected products they manufacture or design and the related services they provide (Article 7(1)). The exemption falls away if the company has a partner or linked enterprise larger than small, or was subcontracted for the work. A hardware start-up in which an industrial group holds 25% or more should check that point before relying on it.

Medium-sized enterprises get a narrower window: one year from qualifying as medium-sized, and one year from placing each product on the market (Article 7(1), second subparagraph), closed again where there is a larger partner or linked enterprise or a subcontract (Recital 41). Whatever the size, a contractual term that dilutes the user's Chapter II rights to the user's detriment does not bind the user (Article 7(2)).

What happens when the data are personal and the user is someone else?

A connected car leased to a company generates personal data about whoever drives it. The Data Act covers personal and non-personal data alike, the GDPR applies in full (Recital 7), and where the two conflict, data protection law prevails (Article 1(5)).

The leasing company is the user; its drivers are the data subjects. The holder may hand over their personal data only where there is a valid legal basis under Article 6 GDPR and, where relevant, the conditions of Article 9 GDPR and Article 5(3) of the ePrivacy Directive are met (Articles 4(12) and 5(7)). The Data Act creates no legal basis of its own, and a business user requesting such data acts as a controller that must inform the drivers (Recitals 7 and 34). A holder can comply by anonymising, or by sending only the data that relate to the user (Recital 7).

Spotting a data protection problem at a glance is a trained skill. This month we published The Inspector, a hidden-object game with a 16-bit look set in a start-up office: sixteen objects, eight of them infringements, and about five minutes to tell which is which. For companies established outside the Union, the personal data side of this work is part of EU Data Compliance.

Who enforces access by design, and what does getting it wrong cost?

Each Member State designates one or more competent authorities (Article 37(1)), and data protection authorities keep charge of personal data (Article 37(3)). Penalties are set nationally and must be effective, proportionate and dissuasive, weighed against factors that include the gravity of the infringement and the offender's turnover in the Union (Article 40(1) and (3)). For Chapter II infringements, data protection authorities may fine up to the GDPR ceiling of €20 million or 4% of worldwide annual turnover, whichever is higher (Article 40(4)).

In Spain, we have found no published designation of a competent authority for the Data Act at the time of writing. Users can still complain (Article 38) and go to court (Article 4(3) and (9)).

What should a manufacturer be able to show?

When an authority, a large customer or an acquirer's due diligence team asks about access by design, the convincing answer is a file. At a minimum it should hold:

  • A catalogue of the data and metadata each product and related service generates, with format, frequency and storage location.
  • A documented decision, product by product, between direct access and access on request, with the technical reasons.
  • Evidence of the date each unit or batch was placed on the EU market, tied to serial numbers.
  • The pre-contractual information under Article 3(2) and (3), in the form users actually receive it.
  • The contracts with users that allow the holder's own use of non-personal data (Article 4(13)), and those with third parties, trade secret measures included.

We gather this work, and the rest of what we do on data law, in our Data practice. The same file is what makes a decision under Articles 4 and 5 defensible when a request arrives.

Could the Data Omnibus change these rules?

On 19 November 2025 the Commission proposed a Digital Omnibus that would amend the Data Act among other acts, including the rules on refusing access to protect trade secrets. At the time of writing, that part of the package was still under negotiation between the Parliament and the Council. None of its proposals applies until it is adopted and published. The package's AI half took a faster route and is already in force, as we explain in our piece on the Digital Omnibus on AI.

Frequently asked questions

Does anything change for units sold before 12 September 2026?

Their design can stay as it is. Their users can still request readily available data under Articles 4 and 5, which have applied since 12 September 2025, and the Commission's FAQs confirm that those rights extend to products sold before that date.

Is a smartphone a connected product?

Yes, according to the Commission's FAQs. Music, video and other content the phone records or plays stays outside the Regulation (Recital 16).

Our company is established outside the EU. Does this reach us?

Yes. The Regulation applies to manufacturers of connected products placed on the market in the Union and to providers of related services, wherever they are established (Article 1(3)(a)).

Who counts as the user of a rented or shared product?

The owner, and anyone to whom temporary rights of use have been transferred by contract, such as a renter or lessee (Article 2(12)). The Commission's FAQs require a stable right, so a relative who borrows the family car is not a user in their own right.

Can a data holder charge a third party for the data?

Yes, within limits. A business receiving the data at the user's request can be asked for reasonable compensation, capped at the costs of making the data available where that business is an SME (Article 9; Recital 49). The user never pays.

Our product only works through a cloud account. Is that account enough?

It can be, if it gives users their data on the terms of Article 3(1). Recital 21 treats user accounts and companion apps as normal channels, provided each request executes automatically once the user makes it.

If this sounds like your situation, you can book a Virtual Consultation here (€90, deducted from the first invoice if we take on the engagement).

did you find this article interesting?

Maybe You Are Interested in Our Tailored Related Services with Open Fees

Non-EU companies

EU Data Compliance

GDPR for non-European companies processing the personal data of EU users.

DESDE
€3,500 + VAT

Book your Virtual Consultation with a lawyer. Today.

60 minutes on Google Meet with a qualified lawyer specialising in TechLaw, litigation or international law. €90 including VAT, deducted from the first invoice if we take on your matter. You leave with legal judgement and a fixed price for whatever comes next.

Choose your lawyer and a time in the calendar. No forms first, no sales calls.