Share This Article
The Data Act access by design obligation becomes applicable on 12 September 2026 to connected products and related services placed on the market after that date.
It requires manufacturers to build their products so that users can reach the data by default rather than on request, which raises questions of product architecture, of coordination with the GDPR where the data concern people other than the user, and of how far trade secrets can legitimately limit access.
The shift is easier to grasp if you compare it with what applied until now, because the question that decides whether a connected product complies is no longer whether the manufacturer can extract the data when somebody asks for them, but whether the user can reach those data without having to ask at all. The AI Act Regulation itself, EU Regulation 2023/2854, has been applicable since 12 September 2025, and I set out the obligations that became effective on that date in this article, so what changes now is not the existence of the obligation but the set of products that have to be built around it.
What Data Act access by design actually requires
Article 3(1) requires connected products and related services to be designed and manufactured so that product data and related service data, together with the metadata necessary to interpret and use them, are by default easily, securely and free of charge accessible to the user, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, directly accessible.
Because every element of Data Act access by design carries a design consequence, accessibility has to be the default state rather than something activated on request as it was until now. The format has to be machine-readable rather than a report a human can look at, and the metadata that make the data intelligible travel with the data, since a stream of values that nobody can interpret satisfies nothing.
The perimeter is broad and reaches sectors that do not usually think of themselves as data businesses, covering vehicles, industrial and agricultural machinery, IoT devices, monitoring equipment and smart home systems, a scope that the European Commission had already outlined in its guidance on connected devices, which I examined in this article, and further clarified in the FAQs published afterwards. What falls inside are the raw and pre-processed data readily available on the product, and not, as a general rule, information that has been further processed or inferred through operations producing significantly enriched data, which is where a good part of the manufacturers’ commercial value tends to sit.
Why this is an engineering problem before it is a legal one
For the products already on the market before September 2025, being able to extract data following a request was enough. For the new ones it is not, because accessibility has to be built into the architecture of the product or the service, through interfaces, applications, portals, export functions or APIs.
Data Act access by design is therefore a different order of requirement. A compliance function can write a procedure for handling access requests in a matter of weeks, whereas building an access mechanism into a product means touching the design phase, the firmware, the connectivity architecture and often the supplier contracts governing the components that generate the data in the first place. This change is crucial, companies that treated the Data Act as a legal project rather than a product project will discover the difference at the moment the first user asks for something the product was never built to give.
The point where the Data Act meets the GDPR, and where it stops
This is the part that generates most of the questions I receive, and the one where getting the analysis wrong creates exposure on both sides.
Data generated by connected products frequently include personal data. Where the user and the data subject are the same person, the Data Act and the GDPR operate in a complementary way and the analysis is relatively straightforward. The difficulty arises when the data concern individuals other than the user, which happens constantly in practice, as in the case of the employee driving a company vehicle, or of several people using the same device in a household.
In those situations the Data Act does not in itself provide a legal basis for disclosing personal data to the user. A legal basis under Article 6 GDPR has to be identified, and where special categories of data are involved, one of the derogations under Article 9 has to apply before the disclosure takes place rather than after it, a tension between connected devices and data protection that I discussed some time ago in this article and that the Data Act has made considerably more concrete.
The consequence is that Data Act access by design and data protection by design and by default have to be engineered together, because making data technically accessible is not the same as making them indiscriminately available. Systems have to be able to identify and authenticate the user, to delimit the data that user may legitimately reach, and to protect the data referable to third parties, which in a shared vehicle or a shared device means separating streams that were never designed to be separated.
Trade secrets are a defence, but not a general one
A similar balancing exercise applies to cybersecurity and trade secrets, and here I see the opposite error, namely the assumption that commercial sensitivity is a way out.
The Data Act does not allow a manufacturer to invoke its know-how in general terms in order to avoid sharing, and a defence built on that assumption tends to collapse under scrutiny. What the Regulation does provide is a set of specific safeguards and, in defined circumstances, the possibility of limiting or refusing access, which is the balance I looked at when the Data Act was approved in this article on trade secrets. The distinction matters enormously in practice, because the first approach produces a dispute the manufacturer is likely to lose, while the second produces a documented position that can be defended.
Where Data Act access by design will produce disputes
The sectors that will feel this first are the ones where somebody else already wants the data and has the commercial incentive to fight for them.
Automotive is the clearest case, since vehicles generate more data than any other consumer connected product, and there is an established chain of parties that want access to those data, from insurers to independent repairers to fleet operators. Access to vehicle data has until now been controlled by manufacturers in a way that protected their aftermarket, and that control is precisely what the Data Act unsettles, a dynamic that I discussed with the Head of Data Protection and Governance of Mobilisights, the data company of the Stellantis group, in this episode of my podcast.
Industrial and agricultural machinery follows closely, and it is the field where the tension between access and trade secrets is sharpest, because operating and maintenance data are commercially valuable to the manufacturer and equally valuable to the operator. It is also, and this is worth noting for anyone planning the next twelve months, the same population of companies that the Cyber Resilience Act reaches, as I set out in the analysis of the Commission guidance, which means two sets of design obligations landing on the same engineering department in the same period.
Where the connected product embeds an artificial intelligence system, a further layer applies, since the obligations of the AI Act and, in Italy, the criminal exposure attaching to missing safety measures and human oversight sit alongside the access duties considered here.
Healthcare and medical devices raise the GDPR question in its most acute form, since almost every data point is a special category of data and the Article 9 analysis is the rule rather than the exception.
And then there is the category of companies that will be caught without knowing it, which is the consumer electronics and smart home sector, where a large number of manufacturers do not perceive themselves as producers of connected products at all.
What to do now
The exercise that cannot be postponed is the classification one, meaning establishing which products and related services fall within the perimeter, which of them will be placed on the market after 12 September 2026, and which data they generate that qualify as readily available raw or pre-processed data.
Alongside it, the access architecture has to be defined rather than assumed, which means deciding through which interface the user will reach the data, in which format, with which authentication mechanism and with which filtering of third party data, and then verifying that the answer is technically achievable within the product roadmap rather than aspirationally described in a policy.
The third piece concerns contracts, because the data covered by the obligation are frequently generated by components supplied by third parties, and a manufacturer whose access obligation depends on a supplier who has not undertaken to support it is a manufacturer with an exposure it has not priced.
Companies that want to understand where they stand on Data Act access by design usually start by mapping products, data and access mechanisms together, which is a limited exercise with a defined scope and considerably cheaper than discovering the gap when a user, a competitor or an authority points at it.
Below are some FAQs that might help to better understand the obligations under the Data Act:
What is Data Act access by design?
It is the obligation under Article 3(1) of the Data Act to design and manufacture connected products and related services so that product and related service data, together with the metadata needed to interpret them, are by default easily, securely and free of charge accessible to the user in a structured, commonly used and machine-readable format, and directly accessible where relevant and technically feasible.
When does it apply?
The Data Act has been applicable since 12 September 2025, and the access by design obligation applies to connected products and related services placed on the market after 12 September 2026.
Which products are covered?
The obligation reaches a broad range of connected products, including vehicles, industrial and agricultural machinery, IoT devices, monitoring equipment and smart home systems, together with the services related to them.
Which data are covered?
Readily available raw and pre-processed data generated by the product or the related service, together with the metadata necessary to interpret and use them. Information that has been further processed or inferred through operations producing significantly enriched data generally falls outside the obligation.
Does the Data Act allow a manufacturer to disclose personal data of people other than the user?
No. Where the data concern individuals other than the user, the Data Act does not in itself constitute a legal basis for the disclosure, and a legal basis under Article 6 GDPR has to be identified, with the derogations under Article 9 applying where special categories of data are involved.
Can a manufacturer refuse access on the basis of trade secrets?
Not on a general invocation of know-how. The Regulation provides specific safeguards and, in defined circumstances, the possibility of limiting or refusing access, which requires a documented and specific position rather than a generic objection.
What should a manufacturer do first?
Classify the products and services within the perimeter, identify which data they generate that fall within the obligation, define the access architecture together with authentication and filtering of third party data, and verify that supply contracts support the obligations that depend on components provided by others.

