Sharing Connected Product Data with Third Parties under the EU Data Act
How users can send connected product data to repair shops, insurers and analytics providers under Article 5, and what data holders must do when such a request arrives.
One of the least understood parts of the EU Data Act is that users do not just get access to the data their connected products generate. They can also tell the data holder to send that data directly to someone else: an independent repair shop, an insurer, an analytics platform, or any other service provider they choose. This third-party sharing right sits in Article 5, it has been applicable since 12 September 2025, and for many manufacturers it is the obligation most likely to arrive as a real request from a real customer.
What the third-party sharing right actually says
Under Article 5, a user of a connected product or related service can request that readily available data, including the metadata needed to interpret it, be made available to a third party of their choice. The data holder is expected to provide it without undue delay, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, continuously and in real time.
The key point is that the request comes from the user, not from the third party acting on its own. A repair shop cannot simply demand your telemetry. But once a user designates that repair shop, the data holder is generally expected to treat the request with the same seriousness as a direct access request from the user.
Who cannot receive data this way
The Data Act draws a hard line around the largest platforms. Companies designated as gatekeepers under the Digital Markets Act are not eligible third parties. A user cannot route their connected product data to a gatekeeper under Article 5, and gatekeepers are not supposed to solicit or incentivise users to do so. If a request names a gatekeeper as the recipient, declining that specific routing is expected to be the correct response.
What the third party is allowed to do with the data
Third parties that receive data under Article 5 face their own obligations, mostly set out in Article 6. They may process the data only for the purposes agreed with the user, and they are expected to delete it when it is no longer needed for those purposes. They cannot use the data to develop a product that competes with the connected product the data came from, cannot pass it on to another party except where agreed, and cannot use it to undermine the commercial position of the user.
Data holders worried about trade secrets keep some protection here too. Disclosure can be made subject to proportionate confidentiality measures agreed with the third party, and in exceptional cases where serious economic damage is likely and can be demonstrated, a data holder may withhold specific data, though this is expected to be a narrow exception rather than a routine answer.
Can you charge the third party?
Yes, within limits. Unlike data provided to the user, which must be free, data made available to a third party can be subject to reasonable compensation agreed between the data holder and the third party. Where the recipient is an SME or a not-for-profit research organisation, the compensation is generally capped at the costs directly related to making the data available. The compensation rules sit alongside the unfair terms rules in Article 13, so one-sided take-it-or-leave-it conditions carry legal risk.
What personal data changes
Where the data includes personal data, the GDPR continues to apply in full. A valid legal basis is needed for the transfer, and if the user making the request is not the data subject, the analysis gets harder. This also matters for enforcement: in Germany, the Data Act implementation act (DADG) has been in force since 30 May 2026, with the Bundesnetzagentur enforcing through tiered fines of up to EUR 500,000, while fines of up to 4 percent of worldwide turnover are reserved for infringements involving personal data under Article 40(4).
What to put in place now
A practical setup usually includes a way to verify that the requester is actually a user of the product, a standard confidentiality agreement for third-party recipients, a documented format for exports, and an internal routing so requests do not sit unanswered. The European Commission has also published non-binding model contractual terms that can serve as a starting point for data sharing agreements. Note that while the Digital Omnibus package proposes softening parts of the Data Act, those proposals are not law yet, so the obligations described here remain the ones to plan against.
If you are not sure whether your products and contracts are ready for a third-party sharing request, our free readiness assessment at dataactready.org walks you through the key questions in a few minutes and shows you where the gaps are.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.