Does the EU Data Act Apply to Smart Home Devices?
What the EU Data Act means for smart thermostats, cameras, speakers and other smart home devices, and what owners and manufacturers can expect.
If you sell a smart thermostat, a robot vacuum, a connected doorbell or any other smart home device in the EU, the Data Act almost certainly applies to you. And if you own one of these devices, the law gives you rights over the data it generates that most people have never heard of. The Data Act has been applicable since 12 September 2025, and smart home products sit squarely inside its definition of a connected product.
Why smart home devices are covered
The Data Act applies to connected products, meaning items that obtain, generate or collect data about their use or environment and can communicate that data. A smart speaker that logs voice commands, a thermostat that records temperature patterns, a video doorbell that stores motion events: all of these are expected to fall within scope. It does not matter whether the device is aimed at consumers or businesses, and it does not matter where the manufacturer is based. What matters is that the product is placed on the EU market.
The related services that come with these devices, such as the companion app or the cloud dashboard, are generally covered too. In practice, the device and its app are treated as one ecosystem for data access purposes.
What device owners can ask for
Since 12 September 2025, users of connected products can request access to the data their devices generate, including relevant metadata. For a smart home device, that could mean usage logs, sensor readings, event histories and similar readily available data. The request should be fulfilled without undue delay, free of charge for the user, and in a commonly used, machine-readable format where applicable.
Users can also ask the manufacturer, as data holder, to share that data with a third party of their choice. A practical example: a homeowner could direct their heating data to an independent energy advisor, or their appliance data to a third-party repair service, rather than being locked into the manufacturer's own ecosystem. There are limits, notably around trade secrets, but the default direction of the law is that the user, not the manufacturer, decides where the data goes.
Access by design changes product development
For products placed on the EU market from 12 September 2026, a stricter obligation applies: connected products must be designed so that users can access their data directly, easily and securely, by default. This access-by-design duty is in force now. For smart home manufacturers, that is expected to mean building data access into the product or app itself, such as an export function or a local API, rather than handling requests manually through support tickets.
Devices already sold before that date are not required to be redesigned, but manufacturers still need to answer access requests for them under the general rules.
Enforcement is national, and Germany is a live example
Enforcement of the Data Act happens at member state level. Germany adopted its implementation act, the DADG, which has been in force since 30 May 2026. The Bundesnetzagentur acts as the competent authority and can impose tiered fines of up to EUR 500,000 depending on the violation. Where personal data is involved, which is very often the case for smart home data such as camera footage or presence patterns, GDPR-level fines of up to 4 percent of annual worldwide turnover can apply under Article 40(4). Other member states are at different stages, so the enforcement picture varies across the EU.
What about the Digital Omnibus?
You may have read that Brussels plans to soften parts of the Data Act. The Digital Omnibus proposals do include ideas such as exemptions for legacy contracts and relief for smaller companies, but these are proposals, not law. Smart home manufacturers should plan against the rules as they stand today rather than against changes that may or may not be adopted, and may look different by the time they are.
Where to start
If you build or sell smart home devices in the EU, three questions are worth answering now. Can a user actually get their device data out, and how long would it take you to respond to a request? Do products you have placed on the market since September 2026 offer direct data access by design? And do your terms of service explain the user's data rights in plain language, as the transparency obligations expect?
If you are not sure where your product stands, our free Data Act readiness assessment walks you through the key obligations step by step and shows you where the gaps are likely to be. It takes a few minutes and gives you a concrete starting point for compliance.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.