A practical legal guide for manufacturers of connected products navigating Regulation (EU) 2023/2854
The EU Data Act has applied since 12 September 2025. It creates binding obligations for manufacturers of connected products and related service providers, covering data access rights, data sharing obligations, contractual fairness requirements, and cloud switching obligations. For IoT device manufacturers specifically, the Data Act restructures who can access product-generated data, on what terms, and with what contractual constraints.
This guide provides a structured compliance checklist for IoT device manufacturers, covering every substantive obligation under the Data Act, the legal basis for each, and the practical steps required to meet it. It includes a self-assessment questionnaire, a obligations table by category, and a FAQ section addressing the questions IoT manufacturers most frequently ask about the regulation.
Key Definitions
| Term | Definition | Legal basis |
|---|---|---|
| Connected product | A physical object that obtains, generates or collects data concerning its use or environment and that is able to communicate data via an electronic communications service, the internet or direct communication | Article 2(5) |
| Related service | A digital service, other than an electronic communications service, connected to a product at the time of purchase, rent or lease, without which the product could not perform one or more of its functions | Article 2(6) |
| User | A natural or legal person that owns, rents or leases a connected product or receives a related service | Article 2(12) |
| Data holder | A natural or legal person that has the right or obligation, in accordance with the Data Act or other applicable Union law, to use and make available data | Article 2(13) |
| Data recipient | A natural or legal person, other than the user, to whom the data holder makes data available | Article 2(15) |
| Third party | A natural or legal person, other than the user or data holder, to whom data is made available | Article 2(16) |
| Trade secret | Information that meets the conditions set out in Article 2(1) of Directive (EU) 2016/943 | Article 2(19) |
| IoT device | A connected product incorporating sensors, actuators or other data-generating components that connect to the internet or other networks | Article 2(5), recitals |
Who This Guide Is For
This guide applies to any manufacturer that:
- Places a connected product on the EU market, regardless of where the manufacturer is established
- Provides a related service connected to a physical product sold, rented, or leased to EU users
- Collects, stores, or processes data generated by connected products through EU users
- Designs or develops IoT devices, smart home products, wearables, industrial sensors, medical devices with connectivity, connected vehicles, or similar hardware
Territorial scope follows market access, not establishment. A US, UK, Canadian, or Asian manufacturer placing connected products on the EU market is subject to the Data Act on the same basis as an EU-established manufacturer.
The Compliance Checklist
Category 1: Product Design and Default Data Access
The Data Act imposes design obligations on manufacturers. These are not obligations that can be addressed post-launch. They must be built into the product before it reaches the market.
| Obligation | What is required | Legal basis | Status |
|---|---|---|---|
| Default data access by design | Connected products must be designed to give users default access to data generated by the product, easily, securely, and in a comprehensive, structured, commonly used, machine-readable format | Article 3(1) | ☐ |
| Data generated by product | Identify and document all data generated by the product during its use, including operational data, sensor data, usage patterns, and performance data | Article 3(1) | ☐ |
| Real-time access capability | Where technically feasible, product data must be directly accessible to users in real time | Article 4(1) | ☐ |
| Access without friction | Data access must not be made contingent on user registration, account creation, or acceptance of additional terms beyond what is necessary | Article 4(1) | ☐ |
| Third-party access facilitation | The product must be capable of facilitating data sharing with third parties designated by the user, on equivalent terms to those applicable to the manufacturer | Article 5(1) | ☐ |
| Metadata provision | Provide users with metadata describing the nature of the data, how it is generated, and what it represents | Article 4(2) | ☐ |
| Pre-contractual information | Before purchase, rent, or lease, inform users in clear and plain language what data the product generates, whether the manufacturer has access to it, and whether third parties have access | Article 3(2) | ☐ |
Category 2: Data Sharing with Users
Article 4 sets out the data sharing rights of users and the corresponding obligations on data holders.
| Obligation | What is required | Legal basis | Status |
|---|---|---|---|
| Share data on user request | Make available to the user, without undue delay and free of charge, all data generated by the product that the user requests | Article 4(1) | ☐ |
| Format and quality | Data must be provided in a structured, commonly used, machine-readable format of sufficient quality for the user’s intended purpose | Article 4(1) | ☐ |
| Continuous access | Where data is generated continuously, provide continuous or real-time access where technically feasible | Article 4(1) | ☐ |
| No charging for basic access | Users cannot be charged for access to data generated by their own use of the product | Article 4(1) | ☐ |
| Response to requests | Respond to user data access requests without undue delay, and in any event within the timeframe specified in implementing acts | Article 4(1) | ☐ |
Category 3: Data Sharing with Third Parties
Article 5 gives users the right to instruct data holders to share product-generated data with third parties of their choosing. This obligation sits at the core of the Data Act’s market contestability objective.
| Obligation | What is required | Legal basis | Status |
|---|---|---|---|
| Share with third parties on user instruction | Make product data available to third parties designated by the user, on terms no less favourable than those applicable to the manufacturer’s own use | Article 5(1) | ☐ |
| Third-party data use limitations | Third parties receiving data under Article 5 may use it only for the purpose agreed with the user and must delete it when no longer needed for that purpose | Article 6(1) | ☐ |
| No data monetisation by third parties | Third parties receiving data under Article 5 may not sell, license, or otherwise make the data available to further parties for commercial gain | Article 6(2) | ☐ |
| No profiling restriction | Third parties may not use data received under Article 5 to build profiles of natural persons for purposes other than what the user requested | Article 6(2) | ☐ |
| Technically feasible access mechanisms | Implement technical mechanisms enabling third-party access that are secure, standardised where possible, and proportionate to the nature of the data | Article 5(5) | ☐ |
Category 4: Contractual Fairness
Chapter IV of the Data Act, Articles 13 to 15, sets out requirements for data sharing contracts between businesses. These apply where IoT manufacturers enter data sharing arrangements with other businesses, including downstream partners, platform operators, and data aggregators.
| Obligation | What is required | Legal basis | Status |
|---|---|---|---|
| Fair and reasonable terms | Contractual terms governing data access and sharing must be fair, reasonable, and non-discriminatory | Article 13(1) | ☐ |
| No unilateral variation | Contracts must not allow one party to unilaterally vary terms in a way that disadvantages the other party | Article 13(2)(a) | ☐ |
| No exclusive remedies | Contracts must not limit available remedies in a way that creates an imbalance between the parties | Article 13(2)(b) | ☐ |
| No impediment to disclosure obligations | Contracts must not prevent data holders from complying with their legal data sharing obligations | Article 13(2)(c) | ☐ |
| Unfair terms void | Contractual terms that do not comply with Articles 13 to 15 are not binding on the disadvantaged party | Article 13(4) | ☐ |
| SME protections | Additional protections apply where one party is an SME. Unfair terms imposed on SMEs are subject to challenge | Article 14 | ☐ |
Category 5: Trade Secrets
The Data Act provides a mechanism for data holders to protect trade secrets when complying with data sharing obligations, but the protection is conditional and narrow.
| Obligation | What is required | Legal basis | Status |
|---|---|---|---|
| Trade secret identification | Identify in advance which data or metadata constitutes a trade secret before invoking protection | Article 4(8) | ☐ |
| Confidentiality measures | Implement all necessary measures to preserve the confidentiality of trade secrets before data is shared | Article 4(8) | ☐ |
| No blanket refusal | Trade secret protection cannot be used as a blanket refusal to share data. It can only be invoked where specific data meets the trade secret definition and specific confidentiality measures have been taken | Article 4(9) | ☐ |
| Dispute mechanism | Where a data holder refuses to share data on trade secret grounds, the user or third party may refer the matter to the competent authority | Article 4(9) | ☐ |
Category 6: Public Sector Data Access
Chapter V of the Data Act, Articles 17 to 22, gives public sector bodies the right to request data from private holders where there is an exceptional need, including emergency situations, failure of official statistics, or climate-related crises.
| Obligation | What is required | Legal basis | Status |
|---|---|---|---|
| Respond to public sector requests | Where a public sector body or Union institution makes a data request under Article 17, respond without undue delay | Article 17(1) | ☐ |
| Assess and challenge requests | Where a request is disproportionate or affects trade secrets, challenge it through the established mechanism before the applicable deadline | Article 19 | ☐ |
| Compensation mechanism | Where data is provided to a public sector body at cost, claim reasonable compensation under the mechanism established by the implementing act | Article 20 | ☐ |
Category 7: Cloud Switching and Interoperability
Articles 23 to 31 of the Data Act impose obligations on cloud service providers regarding switching and interoperability. IoT manufacturers that offer cloud-connected services alongside their devices are within scope.
| Obligation | What is required | Legal basis | Status |
|---|---|---|---|
| Switching assistance | If you provide cloud services connected to your IoT product, you must assist customers in switching to another provider without functional degradation | Article 23(1) | ☐ |
| No switching fees after transition | Switching fees must be reduced and ultimately eliminated on the schedule set out in Article 25 | Article 25 | ☐ |
| Data export on switching | On customer request, make available all data, applications, and digital assets held on their behalf in a structured, commonly used, machine-readable format | Article 24(1) | ☐ |
| Minimum notice period | Provide customers with a minimum notice period before making changes that affect switching rights or data portability | Article 23(2) | ☐ |
| Interoperability standards | Comply with the interoperability specifications and European standards for cloud switching adopted under Article 30 | Article 30 | ☐ |
Category 8: Enforcement and Penalties
| Infringement | Maximum penalty | Legal basis |
|---|---|---|
| Failure to comply with data access and sharing obligations | Member states set penalties. Must be effective, proportionate, and dissuasive | Article 40 |
| Failure to comply with contractual fairness requirements | Member states set penalties. Must be effective, proportionate, and dissuasive | Article 40 |
| Failure to comply with cloud switching obligations | Member states set penalties. Must be effective, proportionate, and dissuasive | Article 40 |
| Unfair contract terms | Void and unenforceable against the disadvantaged party. Subject to national enforcement action | Article 13(4) |
Member states were required to designate competent authorities and establish penalty regimes by 12 September 2025. Penalty levels vary by member state. The Data Act does not set a Union-wide maximum fine in the way the GDPR or AI Act do.
Self-Assessment Questionnaire
Work through the questions below before completing the checklist above. The answers determine which obligations apply to your specific product and business model.
Q1. Does your product generate data during use?
Yes: Data Act applies. Proceed to Q2.
No: Data Act is unlikely to apply to your product. Reassess if product design changes.
Q2. Can your product communicate data via the internet, an electronic communications service, or direct communication?
Yes: Your product is a connected product within Article 2(5). All obligations in Categories 1 to 5 apply.
No: Your product may fall outside the connected product definition. Seek specific advice.
Q3. Do you retain access to data generated by your product after it reaches the user?
Yes: You are a data holder subject to Articles 4 and 5 sharing obligations.
No: You retain design obligations under Article 3 but have reduced ongoing data sharing obligations.
Q4. Do you share product-generated data with third parties, including analytics providers, platform partners, or data aggregators?
Yes: Article 5 obligations and Article 6 use restrictions apply to those sharing arrangements. Review all data sharing contracts against Articles 13 to 15.
No: Third-party sharing obligations do not currently apply but will arise if sharing begins.
Q5. Do you provide a cloud service connected to your IoT product?
Yes: Articles 23 to 31 cloud switching and interoperability obligations apply.
No: Chapter VI obligations do not apply to the cloud layer.
Q6. Is your product placed on the EU market?
Yes: The Data Act applies regardless of where your company is established.
No: The Data Act does not apply unless you intend to enter the EU market.
Q7. Are any of your data sharing contracts with SMEs?
Yes: Additional Article 14 protections apply. Review all contracts with SME counterparties against the unfair terms provisions.
No: Standard Articles 13 and 15 contractual fairness obligations apply.
Data Act Interaction with Other EU Regulations
The Data Act does not operate in isolation. IoT manufacturers typically face obligations under multiple EU instruments simultaneously.
| Regulation | Interaction with Data Act | Key intersection |
|---|---|---|
| GDPR (Regulation (EU) 2016/679) | Data Act applies to all product data. GDPR applies where that data includes personal data. Both apply concurrently | Data minimisation, purpose limitation, and data subject rights under GDPR apply alongside Data Act sharing obligations |
| EU AI Act (Regulation (EU) 2024/1689) | IoT devices incorporating AI may be high-risk AI systems under Annex I or Annex III. Data Act data governance obligations interact with AI Act Article 10 data quality requirements | Data governance documentation required under both instruments must be reconciled |
| Cyber Resilience Act (Regulation (EU) 2024/2847) | Applies to products with digital elements including most IoT devices. Security by design requirements interact with Data Act access-by-design obligations | Security measures protecting data must not be used to restrict legitimate data access rights under the Data Act |
| Radio Equipment Directive (Directive 2014/53/EU) | Applies to IoT devices using radio frequency spectrum. Delegated acts under Article 3(3)(d)-(f) are introducing cybersecurity and privacy requirements for connected devices | Security requirements under RED interact with Data Act technical access mechanisms |
| NIS2 Directive (Directive (EU) 2022/2555) | Applies to operators of essential services and digital infrastructure. IoT manufacturers supplying critical sectors face NIS2 cybersecurity obligations alongside Data Act requirements | Incident reporting obligations under NIS2 and data access mechanisms under Data Act must be coordinated |
| Machinery Regulation (Regulation (EU) 2023/1230) | Applies to machinery incorporating connected components. AI Act Omnibus moved machinery from Annex I Section A to Section B, creating a transitional gap in AI-specific requirements | Data generated by connected machinery is subject to Data Act sharing obligations regardless of the AI Act machinery classification |
Frequently Asked Questions
The Data Act started applying in September 2025. Does it apply to products we placed on the market before that date?
The Data Act applies to connected products placed on the market after 12 September 2025. Products placed on the market before that date are not immediately subject to the full set of obligations, but manufacturers should assess whether their products are capable of meeting the technical requirements as their product lines evolve and new versions are released. Related services connected to pre-September 2025 products are within scope where those services continue to be provided.
We are a US manufacturer selling IoT products in Europe. Does the Data Act apply to us?
Yes. The Data Act applies to connected products placed on the EU market and to related services provided to EU users, regardless of where the manufacturer is established. A US manufacturer selling connected products in Germany, France, or any other EU member state is subject to the same obligations as an EU-established manufacturer. Unlike some EU regulations, the Data Act does not have an Authorised Representative requirement equivalent to the AI Act, but market access is contingent on compliance.
Our product collects data but we do not retain it. Are we still subject to the Data Act?
Yes, in part. The design obligations in Article 3 apply regardless of whether you retain data after it is collected. Your product must be designed to give users default access to data it generates. If you genuinely do not retain access to user data, your ongoing data sharing obligations under Articles 4 and 5 are limited, but you must ensure the product itself is technically capable of providing users with direct access to the data it generates.
A user has asked us to share their product data with a third-party app. Can we charge for this?
No. Article 5 requires data holders to make data available to third parties designated by the user on terms no less favourable than those applicable to the data holder’s own use. You cannot charge users for access to data generated by their own use of your product. You may charge third parties a reasonable cost-based fee for making data available to them, but this fee must be transparent and non-discriminatory.
We consider some of our product data commercially sensitive. Can we refuse to share it?
You can invoke trade secret protection for specific data that genuinely meets the trade secret definition under Directive (EU) 2016/943, but only if you have taken all necessary measures to preserve its confidentiality before sharing is requested. You cannot use trade secret protection as a blanket refusal. Where you invoke it, the user or third party may refer the matter to the competent authority under Article 4(9). The burden of demonstrating that specific data constitutes a trade secret and that confidentiality measures are in place falls on you.
Our IoT product connects to our own cloud platform. Does the cloud switching obligation apply to us?
Yes. If you provide a cloud service that is connected to your IoT product and through which users access their product data or related services, Articles 23 to 31 apply. You must assist users in switching to alternative cloud providers, eliminate switching fees on the schedule set out in Article 25, and make available all data held on the user’s behalf in a portable format upon request.
How does the Data Act interact with GDPR where our IoT product collects personal data?
Both apply concurrently. The Data Act governs access to and sharing of product-generated data, including data that may be personal data. The GDPR governs the processing of personal data and gives data subjects rights including access, rectification, erasure, and portability. Where a user requests access to product data under the Data Act and that data includes personal data, both the Data Act’s access mechanism and the GDPR’s Article 15 right of access apply simultaneously. The legal bases, timeframes, and format requirements of both instruments must be satisfied.
What penalties apply if we do not comply with the Data Act?
The Data Act requires member states to establish effective, proportionate, and dissuasive penalties but does not set a Union-wide maximum fine. Penalty levels therefore vary by member state. Several member states have linked their Data Act penalty regimes to their GDPR enforcement infrastructure. In addition to financial penalties, non-compliant contractual terms are void and unenforceable, which creates direct commercial exposure independent of regulatory action.
The Cyber Resilience Act also requires security by design for our products. Do these two obligations conflict?
They can create tension but not an irresolvable conflict. The Cyber Resilience Act requires manufacturers to implement security measures protecting connected products from attack. The Data Act requires products to be designed to give users and third parties access to product data. The Data Act expressly provides that security measures may be used to protect data but may not be used to restrict legitimate access rights. Manufacturers must design products that are secure by default and accessible by default simultaneously. This requires careful technical architecture, particularly around authentication and access control mechanisms.
Compliance Timeline Summary
| Date | Obligation |
|---|---|
| 12 September 2025 | Data Act applies to connected products placed on market from this date and related services |
| 12 September 2025 | Data sharing with users (Articles 4-5) in force |
| 12 September 2025 | Contractual fairness requirements (Articles 13-15) in force |
| 12 September 2025 | Cloud switching obligations (Articles 23-31) in force |
| 12 September 2026 | Commission review of implementing acts on data formats and interoperability |
| Ongoing | Member state competent authorities enforcing from September 2025 |
DISCLAIMER
This guide reflects the text of Regulation (EU) 2023/2854 as published in the Official Journal on 22 December 2023 and applicable guidance issued through August 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. IoT manufacturers should obtain advice specific to their products, business models, and applicable member state penalty regimes.
