Trade Secrets Under the Data Act: Not the Shield You Think
The Data Act lets users demand product data even when trade secrets are involved. Blanket refusals are non-compliant, the law requires identification, protection measures, and narrow exceptions.
The first instinct of every manufacturer reading the Data Act is: our telemetry is proprietary, so the sharing rules cannot really mean us. The regulation anticipated that instinct and legislated against it.
The default: sharing wins, with safeguards
Data holders must make product data available to users, and to third parties at a user's request, including when trade secrets are implicated. What the law provides is not an exemption but a procedure:
- The data holder identifies the specific data protected as trade secrets, specifically, not "all of it".
- The holder and the recipient agree proportionate technical and organisational measures to preserve confidentiality: NDAs, access controls, technical protections.
- Only if the user or recipient fails to implement or breaches the agreed measures can disclosure be suspended or refused, with the refusal notified and substantiated, and in exceptional circumstances where serious economic damage is highly likely despite the measures, a duly substantiated refusal is possible, subject to notification to the authority.
A one-line "no, it's proprietary" answer skips every step of that procedure and is, on its face, non-compliance.
What this means in practice
- Inventory first: know which of your product's data streams actually embody trade secrets. In most devices it is a small subset, model internals and calibration data, not the raw usage readings the user is asking for.
- Prepare a standard confidentiality package: a template NDA and a menu of protection measures you can offer a recipient. Having it ready converts each request from a legal crisis into a workflow.
- Write the refusal criteria down before you ever refuse: what would count as serious economic damage, and who signs off. Improvised refusals under time pressure are how companies end up on the wrong side of the substantiation duty.
The competitive-fear conversation
Yes: a user can route your product's data to a competitor. The regulation does place limits, recipients face restrictions on using the data to develop a competing connected product, and designated gatekeeper platforms are excluded as recipients, but the era of data moats built purely on refusal is closing in the EU. The defensible moats that remain are the ones built on what you do with data, not on hoarding it.
Where to start
Your user data access policy should contain the trade-secret procedure: identification, measures, escalation, refusal criteria. That single document does most of the compliance work in this area. The pack includes a template with the procedure pre-drafted; the free assessment will tell you whether the data-sharing chapter applies to you at all.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.