What Data Does the EU Data Act Actually Cover?
Product data, related service data, metadata, and what falls outside: a plain-English guide to which data the EU Data Act's access and sharing rules reach.
Ask three founders what data the EU Data Act covers and you will get three different answers: "all data", "IoT sensor data" and "the same stuff as GDPR". None of these is right. The Act, applicable since 12 September 2025, draws its boundaries carefully, and those boundaries decide what your users can demand from you and what stays yours. Knowing where the line runs is often the difference between a manageable export endpoint and a panicked rebuild of your analytics stack.
Product data: what the device generates by being used
The core category is product data: data generated by the use of a connected product, which the product is designed to communicate outside the device, for example to the manufacturer's cloud. Think of a tractor's fuel consumption and GPS trace, a wind turbine's vibration readings, a smart thermostat's temperature log, or a connected coffee machine's brew counts and error codes. If the device collects it during use and sends it somewhere, it is expected to be in scope, whether or not any person appears in it. That last point matters: the Data Act covers non-personal data too, which is exactly the telemetry GDPR ignores.
Related service data: the app counts as well
The second category is related service data: data generated through a digital service that is connected to the product in such a way that the product could not perform one of its functions without it. The companion app that unlocks your smart lock, the platform that schedules a fleet's charging, the cloud service a sensor needs in order to report at all: data generated by using these services sits inside the Act alongside the device data itself. If your SaaS is the brain of somebody's hardware, you should assume the usage data it generates is reachable by the user.
Metadata rides along
Raw readings alone are often useless without context, and the legislators knew it. The access rights are generally understood to cover the relevant metadata needed to interpret and use the data: timestamps, units, event logs, identifiers linking a reading to a device. Handing over a pile of unlabeled numbers and calling it compliance is unlikely to survive contact with a regulator. When you design your export, plan for data plus the context that makes it usable.
What falls outside: derived and inferred data
Here is the boundary that saves most software companies from nightmare scenarios. Information that you derive or infer from the raw data, through your own algorithms, models or analysis, is generally considered outside the user's access right. The vibration readings are in scope; your proprietary failure-prediction score built on top of them is not expected to be. The GPS trace is in; your routing optimization model is not. The Act reaches the data generated by use, not the intellectual value you add afterwards. Trade secrets can also be protected, though only through specific, agreed measures rather than blanket refusals, and content like a document you typed on a smart device is not the kind of "product data" the access rules target.
"Readily available" is the practical filter
For products already on the market, the obligation since September 2025 attaches to readily available data: data you can obtain without disproportionate effort. You are not expected to re-engineer old hardware to capture signals it never recorded. But the comfort is shrinking. For products placed on the EU market since 12 September 2026, access by design applies: new units are expected to ship with direct, free user access to their data built in where technically feasible. What counted as "not readily available" in an old product line becomes a design requirement in the next one.
Why the scope question is worth an afternoon
Getting the scope wrong cuts both ways. Overestimate it and you may hand over derived analytics you were entitled to keep. Underestimate it and you refuse requests you were obliged to honor, which is where enforcement starts. Germany's implementation act, the DADG, has been in force since 30 May 2026, with the Bundesnetzagentur enforcing through tiered fines of up to EUR 500,000; where personal data is involved, fines can reach GDPR levels of up to 4% of worldwide turnover, but only in those cases. And while the Digital Omnibus debate in Brussels proposes softening parts of the Act, those proposals are not law yet, so today's scope is the one that binds.
A practical exercise: list the data flows your product or service generates, sort them into product data, related service data, metadata and derived data, and mark which are readily available today. Most companies find the list is both longer and less scary than they feared.
Map your data in three minutes
If you would rather not start from a blank page, our free readiness assessment at [dataactready.org](https://www.dataactready.org) walks you through exactly these scope questions in plain English, scores your exposure, and maps your gaps to the specific articles that apply to you. It takes about three minutes, needs no signup, and runs entirely in your browser.
Where does your product stand on the Data Act?
Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.
Start free assessmentThis article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.