Titolo copiabile:
Data Act: “Access by Design” Requirements for Data Generated by Connected Products Apply from 12 September 2026
The Irish Competition and Consumer Protection Commission (CCPC) has drawn businesses’ attention to a new phase in the application of Regulation (EU) 2023/2854 – the Data Act: from 12 September 2026, the obligation laid down in Article 3(1) will apply, requiring connected products and related services placed on the market after that date to be designed so as to enable users to access data generated through their use. The provision applies throughout the European Union and is therefore also relevant to manufacturers and service providers marketing products or services on the Italian market.
The Data Act has applied, as a whole, since 12 September 2025. Until now, however, the user’s right to obtain data generated through the use of a connected product may, in certain circumstances, require a specific request to the data holder. With this new phase of application, the EU legislature takes a further step towards an “access by design” model: data accessibility must be built into the design of the product or service itself, rather than being managed solely through subsequent request procedures.
More specifically, Article 3(1) of the Data Act provides that connected products must be designed and manufactured, and related services must be designed and provided, in such a manner that product data and related service data, including the relevant metadata necessary to interpret and use those data, are, by default, easily, securely and free of charge accessible to the user in a comprehensive, structured, commonly used and machine-readable format. Where relevant and technically feasible, access must also be direct.
The rules apply to a very broad range of Internet of Things (IoT) devices. The concept of a connected product includes, for example, smartwatches and health-monitoring devices, smart-home equipment, connected cars and other vehicles, industrial and agricultural machinery, and other devices capable of collecting or generating data concerning their use or environment and communicating such data electronically. “Related services” are also covered, including applications, software or remote-monitoring services connected to the product and necessary for its operation or capable of affecting its functionalities.
The data concerned generally include raw and pre-processed data generated by the use of the connected product or related service that are readily available to the data holder, together with the relevant metadata. Depending on the product, this may include data concerning temperature, pressure, location, speed, acceleration, use or equipment performance. By contrast, data inferred or derived through additional processing and protected content are, in principle, outside the scope of Chapter II, without prejudice to the specific provisions of the Regulation and to intellectual property law.
“Access by design” does not, however, mean that every item of data must necessarily be stored physically on the device or that direct access is required in every case. Article 3 requires direct access only where relevant and technically feasible. Where users cannot access the data directly from the product or related service, the mechanism laid down in Article 4 of the Data Act continues to apply, under which the data holder must make the relevant data and metadata available to the user, upon simple request and without undue delay, free of charge and, where relevant and technically feasible, continuously and in real time.
The right is not limited to consumers. For the purposes of the Data Act, users may also include businesses that own, rent or lease a connected product or receive a related service. The new regime is therefore particularly significant in B2B relationships, for example in relation to industrial machinery, vehicle fleets, professional devices and IoT equipment, enabling business users to exploit the data generated for maintenance, process optimisation, performance analysis or the use of aftermarket service providers other than the original manufacturer.
The requirement to make data accessible to users is closely linked to another central objective of the Data Act: enabling users to use the data themselves and make them available to third parties of their choice, thereby fostering the development of maintenance, repair and other data-driven services and reducing lock-in to the original manufacturer.
From an operational perspective, this new phase of application requires manufacturers and service providers to carry out a compliance assessment that cannot be limited to contractual documentation. Businesses should verify whether products and services placed on the market after 12 September 2026 fall within the definitions of “connected product” and “related service”; identify which data and metadata fall within the scope of the Data Act; assess whether the technical architecture enables direct user access; implement appropriate interfaces, dashboards, applications, APIs or other technical solutions; and adequately document the reasons why direct access may not be technically feasible in specific cases. The CCPC itself recommends that data holders carry out this assessment and be able to demonstrate and document the reasons for any absence of direct access.
Compliance must also be coordinated with requirements concerning security, trade secrets, intellectual property and personal data protection. The Data Act applies to both personal and non-personal data, but does not alter the lawfulness requirements laid down by the GDPR: where the requested data include personal data relating to individuals other than the user, their disclosure must in any event be supported by a valid legal basis under data protection law.
The 12 September 2026 deadline therefore marks a significant step in the implementation of the Data Act: access to data generated by connected products must no longer be treated merely as a right to be handled ex post, but as a requirement to be embedded in the architecture of the product and related service from the design stage onwards. For manufacturers, IoT providers and providers of related digital services, compliance with the Data Act is therefore becoming a matter of product design, data architecture and technical governance, in addition to contractual compliance.