From September 12, 2026, manufacturers of connected products and providers of related services will be subject to new obligations and requirements that the products and services they provide must meet (Article 3(1) of the Data Protection Act in conjunction with Article 50 of the Data Protection Act). This change coincides with the end of one of the transitional periods provided for in Regulation (EU) 2023/2854 of the European Parliament and of the Council of December 13, 2023, commonly known as the Data Act. From that date, products entering the market must comply with the new requirements at the design stage.
The essence and objectives of the Data Act
This regulation harmonizes rules on fair access to and use of data. Its primary goals are to strengthen the EU's data-driven economy, foster a competitive data market, create conditions for innovation, and ensure the broadest possible access to data. In simple terms, the Data Act's main objective is to ensure that not only the producer owns and benefits from the data, but also grants users specific rights to access, use, and share this data with third parties of their choosing.
Therefore, the manufacturer must provide users with access to data in a structured, legible, secure, machine-readable manner, and without undue delay. The user's right to receive data from its owner is linked to the right to share this data with third parties of their choosing.
The Data Act focuses primarily on non-personal data, so where it intersects with personal data, the GDPR regulations should be applied in parallel. Therefore, particular caution is warranted, as failure to comply with the obligations arising from these legal acts will result in double liability for such entities. It should also be noted that this regulation applies to any entity operating in the EU market, regardless of its location.
Who does the Data Act apply to?
The regulation primarily imposes obligations on two categories of entities. The first are manufacturers of connected products. A connected product is an item that acquires, generates, or collects accessible data regarding its use or environment and is capable of communicating this data via an electronic communications service, physical connection, or device access—as long as its primary function is not to store, process, or transmit data on behalf of a party other than the user. The second category of entities are providers of connected services, i.e., digital services that are connected to the product in such a way that their absence would prevent the product from performing at least one of its functions, or that are connected to the product later to update or modify its functions (Article 2, points 5 and 6 of the DA).
This regulation should be of particular interest to manufacturers of consumer electronics and smart home devices, vehicle manufacturers and automotive subcontractors, manufacturers of industrial and agricultural machinery, and manufacturers of medical products and health monitoring devices. Devices such as smartphones and computers are excluded from the regulation's scope. Nevertheless, the Data Act affects virtually everyone, as the vast majority of us are users of such products or services.
What data is subject to mandatory disclosure?
According to the regulation, upon user request, primarily raw data is subject to disclosure, meaning data generated automatically by IoT devices—for example, data related to temperature, pressure, or location, acquired by sensors in such devices. This obligation also partially covers pre-processed data, to the extent that it is raw data converted to be understandable to the user, as well as metadata (e.g., units of measurement) necessary for correct data interpretation. However, highly processed, inferred, or derived data are not subject to this obligation. It should also be noted that the obligation to disclose data does not require the transfer of source code, algorithms, or manufacturer know-how.
New design obligation (access by design) after September 12, 2026
From that date, manufacturers and providers of related services—in addition to the existing obligation to provide data upon request—are also subject to a design obligation, known as access by design (Article 3 DA). All products and services entering the market after that date must comply with the new requirements. This means that access to data must be enabled by default at the design stage, so that the user does not have to request or demand it. Products must be designed so that the user can obtain the necessary data from their own device. This can be achieved in various ways, such as access via a device interface, an app, or access from a server. If it is technically impossible for a product to meet these requirements, the manufacturer must provide access to data under the same quality conditions and without undue delay.
To sum up
The Data Act undoubtedly imposes new obligations on manufacturers and related service providers, failure to comply with which carries the risk of sanctions. The end of the transitional period for the access by design requirement—September 12, 2026—poses a significant challenge for these entities, requiring them to conduct necessary audits, review the supply chain, examine contracts with subcontractors, and update disclosure requirements and pre-sale documentation.
This article is for informational purposes only and does not constitute legal advice.
The law is current as of September 23, 2026.
