The industry is now well aware of the EU Data Act obligations. The Data Act (Regulation (EU) 2023/2854) became applicable in the EU member states one year ago with the goal to create a framework for fair access to and use of data across the EU, giving users more control over product-generated data and foster the principles of transparency, fairness, and GDPR safeguards.
From 12 September 2026 a further obligation applies: connected products and related services should be designed so that product data and related service data (including the metadata needed to interpret them) are, by default, easily, securely, and free of charge accessible to the user.
What Do the Affected Manufacturers Now Need to Bear in Mind?
This Access by Design obligation is perfectly framed within the sets of rules enshrined within the Data Act, which require connected-product manufacturers and related-service providers to:
- inform customers, before the purchase, about what type, format, and volume of data the product generates;
- give users the right to request free, secure, real-time access to that data upon request;
- share data with a third party the user designates, on fair, reasonable, and non-discriminatory terms;
- move toward accessibility “by design” where technically feasible, which translated now in the Access by Design obligation.
Cloud service providers (Cloud, SaaS, PaaS, and IaaS services) are also included within the scope of the Data Act, by a parallel set of obligations aiming mainly to give more freedom to the users when choosing a service provider, especially in terms of switching to other vendors in an easy way, allowing data portability and reducing termination notice periods.
Very briefly, the 2026 Access by Design obligation is not a new one but rather the evolution of a right that already existed. The difference is that the responsibility relies directly on the connected products provider and does not rely exclusively on the request coming from the users.
The data covered by this obligation, hence that must be made available, is the raw and pre-processed data that is readily available on the product. The part of the data that is more commercially sensitive for the producers, like data that has been enriched by additional analysis or re-processed in line with product specifications, is excluded.
It is important to note that the obligation applies to the connected products that are made available on the market starting from 12 September 2026.
Overlap With GDPR
It has been already noted, by analysing the EU Data Act, that the provisions on the processing of personal data enshrined in the GDPR work in conjunction with the Act. Whenever personal data falls within the scope of the Act, it must be processed in accordance with the GDPR. If the user is at the same time a data subject, it is clear that the personal data should be handled in accordance with GDPR, however, it is more difficult when personal data of a third-subject are involved in the data access request under the scope of the Data Act. This means that, if data that are referrable as personal data are in scope of the request, those should be processed according to a legal basis for processing as required by Art.6 GDPR. This requires that a specific recognition mechanism should be part of the design of the access procedure because any personal data shared should be relevant only to the person who filed the request.
How Are Companies Complying?
One of the industries that is more concerned by the EU Data Act obligations, because of the nature of the products and the number of parties that are main actors of the Data Act is the automotive sector. To abide to the disclosure of data obligations, the main producers have invested to design different solutions. Some of them are maintaining specific data information pages with live updates, others have developed portals with API integrations, others have published product data information online.
Cloud / hosting providers have also moved towards compliance with the specific obligations they are subject to; for example many big tech companies have already developed solutions to eliminate egress fees for provider change, enabled portals or request centers to facilitate the access and portability of the data.
What Are the Main Upcoming Deadlines?
Besides the Access by Design deadline of 12 September 2026 that we discussed above, 2027 will set two other important milestones, specifically: in mid-January 2027 charges to switch provider will be prohibited. The transition period for the cloud and data processing providers to charge a fee on a cost-pass-through basis will be ended except for early termination proportionate fees. Mid of September 2027 the terms of agreements in place before that time shall be updated to integrate the provisions of fair contractual clauses.
Companies in scope of the EU Data Act compliance shall be prepared to implement the obligations of the regulation and plan the product / solutions and contractual developments according to the implementation plan defined in the Act. It is also very important to monitor the updates from the regulatory actors both at national and European level, especially in consideration of the national enforcement laws and the developments of the Digital Omnibus proposals.
No comments