The EU Data Act: What It Means for Connected Products

Add as a preferred source on Google

The EU Data Act reshapes who can access and use the data generated by connected products, from industrial machinery to smart home devices and connected vehicles. It shifts control toward the users of those products and sets new rules for data sharing, cloud switching, and the contracts that govern all of it.

If you build, sell, or operate connected products in the European Union, the Data Act is not a privacy law bolted onto GDPR. It is a distinct framework about the economic value of machine-generated data, and it introduces design obligations that have to be built into products before they reach the market. This guide covers what the regulation does, who it affects, the dates that matter, and how to prepare.

What the EU Data Act does

The Data Act is formally Regulation (EU) 2023/2854. Because it is a regulation rather than a directive, it applies directly and uniformly across all Member States without national transposition. It entered into force on 11 January 2024 and its main provisions apply from 12 September 2025.

Its central aim is to unlock the value of data generated by connected products and related services, and to distribute that value more fairly among the parties who help create it. The regulation works across five main areas.

User access to product data. When a connected product or related service generates data through its use, the user (the person or business that owns, rents, or leases the product) gets the right to access that data. The obligation is meant to end the situation where only the manufacturer can see and monetize the data a customer's own machine produces.

Sharing data with third parties. Users can direct a data holder to share that data with a third party of the user's choosing, for example an independent repair shop, an insurer, or an analytics provider. This is the provision most likely to disrupt aftermarket services, because it lets customers route their data to competitors of the original manufacturer.

Cloud switching. The Data Act sets rules to make it easier for customers to switch between data processing services (cloud and edge providers) and to move their data and applications to another provider or on-premises. Providers must remove commercial, technical, and contractual obstacles to switching, and the regulation phases out egress (data transfer) charges over time.

Business to government (B2G) data access. In cases of exceptional need, such as responding to a public emergency, public sector bodies can request data held by businesses. The regulation defines narrow conditions and safeguards so this power is not a general-purpose data grab.

Contract fairness. The Data Act introduces an unfairness test for data-related contract terms that are unilaterally imposed on another business. Terms that grossly deviate from good commercial practice, contrary to good faith and fair dealing, are not binding. This protects smaller businesses from take-it-or-leave-it data clauses.

Who is affected

The Data Act reaches a broad set of actors across almost every sector that touches connected hardware or cloud infrastructure. Notably, several obligations apply regardless of where a company is established, as long as it places products or offers services on the EU market.

Manufacturers of connected products. Any company that designs or makes a connected product placed on the EU market is in scope, along with providers of related services (the software and digital services that make a connected product work as intended). This spans automotive, industrial equipment, consumer electronics, medical devices with connectivity, agricultural machinery, and the wider Internet of Things.

Data holders. A data holder is the party that has the right or the obligation, or the technical control, to make certain data available. Often this is the manufacturer, but it can also be a service provider or another party in the value chain. Data holders carry the core duties to make data available to users and, on the user's instruction, to third parties, on fair, reasonable, and non-discriminatory terms.

Cloud and data processing providers. Providers of cloud, edge, and other data processing services are subject to the switching and interoperability obligations. They must help customers move to competing services and, over the transition period, reduce and then remove switching charges.

Users and third-party recipients. Users (consumers and businesses alike) gain rights, but third parties that receive shared data also take on obligations. A recipient cannot use the data to develop a competing product, cannot pass it on without authorization, and must respect the limits set out in the regulation.

The key dates

The Data Act phases in over several years. The most consequential milestone for product teams is 12 September 2026, when the data access by design obligation begins to bite for newly placed products.

Date Milestone
11 January 2024 Regulation (EU) 2023/2854 enters into force
12 September 2025 Main provisions apply, including user data access rights, third-party sharing, cloud switching rules, B2G access, and the unfair contract terms test
12 September 2026 Data access by design obligation (Article 3) applies to connected products and related services placed on the EU market after this date
12 September 2027 Certain contract-term protections extend to agreements concluded on or before 12 September 2025, and further cloud switching provisions (including the phase-out of switching charges) take fuller effect

Two points deserve emphasis. First, the bulk of the Data Act is already applicable as of September 2025, so the sharing, switching, and contract-fairness duties are live obligations, not future ones. Second, the 12 September 2026 date is specifically about products designed and manufactured to make data accessible by default. Under Article 3, connected products placed on the market after that date must be built so that product data and related service data, including the metadata needed to interpret it, are, by default, easily, securely, and where technically feasible directly accessible to the user. This is an engineering requirement with a hard deadline, and it cannot be retrofitted the week before launch.

How to prepare

Readiness for the Data Act is a cross-functional exercise. It touches product engineering, legal, commercial, and cloud architecture, and the teams that own each piece rarely coordinate by default. A practical sequence looks like this.

Map your data and your role. Inventory the connected products and related services you place on the EU market, and the data each one generates. For every data set, determine whether you are the data holder, and identify who the users are. You cannot design an access mechanism until you know what data exists and who is entitled to it.

Engineer for access by design. For any product that will be placed on the market after 12 September 2026, build data accessibility into the design now. That means deciding how users will retrieve their data, in what structured and machine-readable format, and through which secure interface (often an API). Treat this as a product requirement with the same weight as safety or connectivity, because the deadline is fixed.

Stand up a data-sharing process. Because users can already instruct you to share data with third parties, you need a repeatable way to authenticate requests, verify the user's instruction, apply the permitted restrictions on the recipient, and deliver the data on fair, reasonable, and non-discriminatory terms. An ad hoc, case-by-case approach will not scale and invites disputes.

Review your contracts. Audit data-related clauses in customer, supplier, and cloud agreements against the Data Act's unfairness test. Terms that were standard a few years ago (broad exclusivity over machine data, one-sided liability, or barriers to switching) may now be unenforceable. Update templates and flag legacy contracts, keeping in mind the extended timeline that reaches certain existing agreements by 12 September 2027.

Address cloud switching. If you provide data processing services, document your switching and portability procedures, publish the required information, and plan for the removal of egress charges over the transition window. If you are a customer of such services, use the new rights as leverage to reduce lock-in and negotiate cleaner exit terms.

Coordinate with your GDPR program. Where product data includes personal data, the Data Act operates alongside the GDPR rather than replacing it. Access and sharing mechanisms must still respect data-protection principles, lawful bases, and the rights of data subjects. Align the two workstreams so that a Data Act access request does not create a GDPR exposure.

This article is general information, not legal advice. Always verify against the official text on EUR-Lex.