DataAct Ready

EU Data Act guides ·

Does the EU Data Act Apply to Medical Devices and Health Wearables?

Connected glucose monitors, CPAP machines, hearing aids and fitness wearables generate valuable data. Here is what the EU Data Act expects from their makers.

A continuous glucose monitor streams readings to an app. A CPAP machine logs every night of therapy. A smartwatch tracks heart rhythm and sleep. All of these are connected products that generate data, and that means the EU Data Act is very likely part of your regulatory picture if you make, sell or run services for them in the EU. The twist for health-adjacent devices is that the data involved is usually personal, and often sensitive, so the Data Act lands on top of the GDPR rather than instead of it. Here is how the pieces fit together.

Why medical and health devices are in scope

The Data Act, which has applied since 12 September 2025, covers "connected products": items that obtain, generate or collect data about their use or environment and can communicate that data. There is no carve-out for medical or wellness devices as a category. A connected insulin pump, a smart inhaler, a hearing aid with an app, a hospital infusion pump that phones home for maintenance, and a consumer fitness band are all expected to qualify, along with the "related services" (typically the companion apps and cloud platforms) that make them work.

What the Act adds is a user right: the person or business using the device can ask the data holder for the readily available data the device generates, free of charge, and can direct that data to a third party of their choice. For a clinic, that might mean moving ventilator usage data to a new service partner. For a patient, it might mean handing their wearable data to a coaching app the manufacturer has never heard of.

The GDPR does not step aside

For most health devices, the data is personal data, and frequently health data in the GDPR's strict sense. The Data Act does not weaken any of that. Where device data is personal, a valid GDPR legal basis is still needed for any processing, and the Data Act's sharing mechanics have to operate within GDPR limits. In practice this means manufacturers need to think about the two regimes together: an access request under the Data Act may also look like a portability request under the GDPR, and the safest designs answer both at once.

This overlap also raises the enforcement stakes, as covered below.

Access by design started in September 2026

For connected products placed on the market from 12 September 2026, the access by design obligation is in force: products and related services are expected to be designed so that users can access their data directly, easily and securely, where relevant and technically feasible. For device makers with long hardware cycles, this is the requirement that bites earliest in engineering terms. A glucose monitor designed in 2024 and still shipping unchanged may need a data access route, whether in-device, via the app or through an API, for units placed on the market from that date onward.

Manufacturers worried about intellectual property should know that trade secret protections exist in the Act but are conditional: data holders can require confidentiality measures, yet refusing access outright is expected to be possible only in narrow, well-evidenced circumstances.

Who enforces this, and what fines look like

Enforcement is national. Each member state designates a competent authority and sets penalties, so exposure varies by country. Germany offers the clearest picture so far: its implementation act, the DADG, has been in force since 30 May 2026, with the Bundesnetzagentur enforcing the Data Act through tiered fines of up to EUR 500,000 depending on the obligation breached. Crucially for health device makers, where personal data is involved, Article 40(4) points to GDPR-level fines of up to 4 percent of global annual turnover. Since health device data is so often personal, companies in this sector should assume the higher ceiling is realistically in play more often than for, say, industrial sensor makers.

What about the Digital Omnibus?

The European Commission's Digital Omnibus proposals would soften parts of the Data Act, with ideas such as legacy contract exemptions and additional relief for SMEs on the table. These proposals are not law yet, and health device makers should not plan on relief that may never arrive in its proposed form. The obligations that already apply, including access by design for new products, remain the baseline.

A practical starting point

If you make or operate connected medical or wellness devices for the EU market, three questions are worth answering now. Can a user actually get their device data out, and could you fulfil a request within a reasonable time? Do products placed on the market since September 2026 offer direct access by design? And do your contracts and privacy documentation handle the Data Act and the GDPR as one coherent story rather than two conflicting ones? The free readiness assessment at [dataactready.org](https://www.dataactready.org) is built for exactly this: a few minutes of structured questions that show you where your gaps are and which deadlines apply to you.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.