Independent Repair and the EU Data Act: The End of the Diagnostic Monopoly?
How the EU Data Act lets users send device data to independent repair shops and aftermarket services, and what manufacturers must now allow.
For years, the repair economics of connected devices were decided by a simple fact: only the manufacturer could see the machine's data. Error codes, wear indicators, usage history and diagnostic readouts lived in a proprietary cloud, so the authorized service network got the work and everyone else got to guess. The EU Data Act, applicable since 12 September 2025, attacks that arrangement directly. The user of a connected product can now access its data and, crucially, send it to any third party they choose, including the independent repair shop down the street.
The legal mechanics in plain English
Two rights do the work. First, the user, whether the owner, renter or lessee of a device, can request the readily available data the product generates through its use, free of charge and in a structured, machine-readable format. Second, the user can instruct the data holder, usually the manufacturer, to make that data available to a third party on fair, reasonable and non-discriminatory terms. An independent garage, a machinery service firm or an appliance repair specialist can therefore receive the diagnostic data it needs, provided the customer asks.
For products placed on the EU market since 12 September 2026, the access-by-design obligation adds a layer: new units are expected to ship so that users can reach their data directly and easily where technically feasible, which in practice pushes manufacturers toward onboard access or self-service portals rather than manual exports.
What this means for repair businesses
If you run an independent repair or maintenance operation, the Act hands you a door that used to be locked. Fault histories, sensor readings and service counters that previously justified "only the dealer can diagnose this" are now reachable through the customer. The connected car is the famous example, and our [connected cars guide](https://www.dataactready.org/blog/eu-data-act-connected-cars) covers it, but the same logic reaches agricultural machinery, elevators, HVAC systems, medical imaging equipment, coffee machines in offices and industrial robots.
The rights come with fences. A third party receiving data may only use it for the purpose agreed with the user, must not keep it longer than needed, and cannot use it to develop a product that competes with the device it came from. Repairing and maintaining the device is exactly the kind of purpose the regime is built for; reverse-engineering a rival machine from its telemetry is not.
What manufacturers can and cannot do
Manufacturers retain real protections, but narrower ones than many assume. Trade secrets can be shielded, yet only by identifying the specific secrets and agreeing proportionate protection measures with the recipient; a blanket "our diagnostics are proprietary" refusal is generally considered non-compliance. Reasonable compensation can be charged to business recipients for making data available, though for small and medium-sized recipients it is expected to stay at cost level, and nothing may be charged to the user themselves. Withholding data to protect an authorized service network's revenue is precisely the behavior the Act was written to end.
The contract layer matters too. Unilaterally imposed terms that exclude these rights or gate them behind unfair conditions risk being void under Article 13, and from 12 September 2027 those fairness rules are expected to reach older contracts still in force.
Enforcement and the road ahead
National regulators are live. Germany's implementation act, the DADG, has been in force since 30 May 2026, with the Bundesnetzagentur enforcing through tiered fines of up to EUR 500,000; where personal data is involved, such as a private car's location history, fines can reach GDPR levels of up to 4% of worldwide turnover, though only in those personal-data cases. Meanwhile Brussels is debating the Digital Omnibus package, which proposes softening parts of the Act, mostly around cloud switching and legacy contracts; the repair-relevant access rights are not the focus, and in any case the proposals are not law yet.
The direction of travel is consistent with the EU's broader right-to-repair agenda: the customer, not the manufacturer, decides who services their machine, and data access is the enabler.
Check where you stand in three minutes
Whether you are a manufacturer wondering what you must now hand over, or a service business wondering what you can now request, the fastest way to orient yourself is our free readiness assessment at [dataactready.org](https://www.dataactready.org). It asks a handful of plain-English questions, scores your position, and maps each gap to the exact article of the regulation. Free, no signup, and everything runs in your browser.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.