bytevyte
bytevyte
Language
quick-beats

EU Data Act Access by Design Arrives: Connected Devices Must Export Your Data by Default

EU Data Act access by design

The EU Data Act access by design obligation took effect on 12 September 2026, and it shifts a task that once fell to the buyer onto the manufacturer. Connected products and their related services placed on the EU market from that date must be engineered so the data they generate reaches the user by default: easily, securely, at no cost, and in a structured, machine-readable format. Regulation (EU) 2023/2854 has applied since 12 September 2025, but until this month it worked mainly as a right to ask. The new duty removes the asking.

The reach is broad. Smartwatches, connected cars, medical devices, industrial machinery, smart home equipment and IoT sensors all fall inside the scope, together with the digital services attached to them, such as companion apps, remote monitoring platforms and connected software. The obligation binds manufacturers, importers and distributors. It attaches to the first time an individual unit enters the Union market, not to the original launch date of a product line.

What counts as covered data goes beyond personal information. Article 3(1) takes in raw sensor output, pre-processed telemetry, the metadata needed to interpret and use that data, and related service data. Highly enriched or derived data generally sits outside the requirement. Where access is relevant and technically feasible, it must also be direct and continuous, which in practice points to real time.

What the EU Data Act Access by Design Rule Changes for Owners

Under the 2025 regime, a user could demand their data and the manufacturer had to supply it. That still left friction: the user had to know the right existed, locate the request channel and wait for a response. Access by default closes that gap by making the export path part of the product itself.

The sharing right is the part consumers will notice first. Data obtained this way can be passed to third parties of the user's choosing, and independent repair shops sit explicitly inside that group. A connected car's diagnostic history, a smartwatch's heart-rate log or a home energy monitor's consumption record can move to a service the manufacturer does not control.

Business users are covered on the same terms. A factory running connected machinery, a logistics operator with a telematics fleet or a clinic with networked medical devices can pull their usage data and hand it to a service provider of their choice. That widens the supplier market for maintenance and analytics, and it reduces the control a manufacturer holds over who services its equipment.

In practice the requirement translates into concrete deliverables: an interface, app or technical tool that hands over the data without a formal request, a format that standard tools can read, and no fee. Manufacturers that treat the export as a premium feature are on the wrong side of the text.

Product Architecture Becomes the Compliance Surface

The duty lands hardest here. A manufacturer can no longer satisfy the law with a support workflow, because the obligation attaches to the design of the product and the service around it. Data models, export formats and permission layers become engineering decisions with a legal deadline attached, and the work has to hold up for every unit shipped after the cut-off.

Three questions remain unsettled. The first is coordination with the GDPR, since connected products routinely collect data about people who are not the user, including passengers, household members and bystanders. The second is trade secrecy, and how far a manufacturer can legitimately limit access without hollowing out the right. The third is the feasibility qualifier, which the regulation leaves to interpretation and therefore to dispute.

Ongoing maintenance adds a quieter cost. An export interface is not a one-off build. It needs documentation, versioning and support for as long as the device stays in use, and that lifetime can run well past the marketing cycle for the product.

Timing matters for buyers as well. Units placed on the EU market before 12 September 2026 keep the older request-based route, so a device bought last month does not gain the new default access. Shoppers weighing a purchase can check when a unit entered the market, because that date is the trigger, not the model name.

A Second Deadline One Day Earlier

Connected product makers are absorbing a second obligation in the same week. Under the Cyber Resilience Act, vulnerability and incident reporting duties took effect on 11 September 2026 for manufacturers of products with digital elements, a single day before the Data Act's design requirement. The CRA's main substantive obligations arrive later, on 11 December 2027.

The Data Act itself carries more than one track. Its switching provisions for data processing services, which in practice cover cloud and edge providers, have applied since 12 September 2025, and its rules on unfair contractual terms date from the same point. For a device maker, the September 2026 pair is the sharper of the deadlines because both demand changes inside the shipped product rather than in a contract.

MilestoneDateWhat it requires
Data Act applies12 Sept 2025Users may request product data; unfair contract terms can be challenged; cloud and edge switching rules apply
Cyber Resilience Act reporting11 Sept 2026Vulnerability and incident reporting for products with digital elements
Access by design, Article 3(1)12 Sept 2026New units on the EU market must offer data access by default, free of charge, machine-readable
Cyber Resilience Act core duties11 Dec 2027Substantive security requirements for connected products

Why this matters

For anyone buying a connected device, the practical value of the hardware now depends partly on what the maker allows them to do with its output, which turns data portability into a purchasing criterion rather than a support ticket. For manufacturers, access is a design input with a date attached, and the engineering cost lands whether or not the product ships on schedule. The qualifiers around feasibility and trade secrets are the ones to watch, because they will decide how much of the right survives contact with a real product.

Photo by smart-me AG on Unsplash

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.