DataAct Ready

EU Data Act guides ·

The EU Data Act for IoT and Device Manufacturers

Connected-product makers carry the heaviest Data Act load: access by design, user data-sharing rights, third-party sharing, transparency duties. A practical map for hardware teams.

If you manufacture connected devices sold in the EU, industrial sensors, vehicles, appliances, wearables, machines, the Data Act is aimed primarily at you. Here is the load-out.

Your data is no longer only yours

The regulation's core move: users of a connected product (buyers, lessees, operators, businesses included) have the right to access the data the product generates through their use, easily and free of charge. On request, that data must also be shared with a third party of the user's choice, including, uncomfortably, a competitor or an independent repair shop. Limited carve-outs exist (gatekeeper platforms cannot be recipients; trade secrets get procedural protection), but the default has flipped from proprietary to shared.

Access by design, since 12 September 2026

Products placed on the EU market from this date must be designed so that product data is accessible by default, directly on the device where relevant and technically feasible, otherwise through a straightforward mechanism. For new models this is a requirements-document line item; for existing designs still being shipped, it is a retrofit decision that belongs on the engineering roadmap now, with written justification wherever direct access is genuinely unfeasible.

Before the sale: transparency

Pre-contractual information duties require telling the buyer what data the product generates, its nature and volume, how to access and retrieve it, whether you intend to use it yourself or share it, and how to contact you. In practice: a data transparency notice on the product page, in the manual, or in onboarding.

The B2B sharing rulebook

When you share data with third parties at a user's request, the terms must be fair, reasonable and non-discriminatory, any compensation for making data available to businesses must meet the regulation's conditions, and trade secrets must be identified specifically with protection measures agreed, a blanket refusal on proprietary grounds is not a compliant answer.

Your software partners are inside the perimeter

Related services, the apps and cloud platforms a device depends on, sit in the same framework. If a partner runs your companion app, your contract with them should allocate who answers user access requests, who builds the export, and who holds the transparency documentation. Ambiguity here becomes your problem, because the user's rights run against the product.

A manufacturer's minimum file

A scoping memo, an access-by-design engineering review, a user data access policy, a transparency notice, a third-party sharing procedure and an updated contract set. Our free assessment scores you across these areas in about three minutes and shows the gaps; the pack ships adaptable templates for the documentation layer.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.