A practical legal guide for manufacturers of connected products navigating Regulation (EU) 2023/2854

The EU Data Act has applied since 12 September 2025. It creates binding obligations for manufacturers of connected products and related service providers, covering data access rights, data sharing obligations, contractual fairness requirements, and cloud switching obligations. For IoT device manufacturers specifically, the Data Act restructures who can access product-generated data, on what terms, and with what contractual constraints.

This guide provides a structured compliance checklist for IoT device manufacturers, covering every substantive obligation under the Data Act, the legal basis for each, and the practical steps required to meet it. It includes a self-assessment questionnaire, a obligations table by category, and a FAQ section addressing the questions IoT manufacturers most frequently ask about the regulation.

Key Definitions

TermDefinitionLegal basis
Connected productA physical object that obtains, generates or collects data concerning its use or environment and that is able to communicate data via an electronic communications service, the internet or direct communicationArticle 2(5)
Related serviceA digital service, other than an electronic communications service, connected to a product at the time of purchase, rent or lease, without which the product could not perform one or more of its functionsArticle 2(6)
UserA natural or legal person that owns, rents or leases a connected product or receives a related serviceArticle 2(12)
Data holderA natural or legal person that has the right or obligation, in accordance with the Data Act or other applicable Union law, to use and make available dataArticle 2(13)
Data recipientA natural or legal person, other than the user, to whom the data holder makes data availableArticle 2(15)
Third partyA natural or legal person, other than the user or data holder, to whom data is made availableArticle 2(16)
Trade secretInformation that meets the conditions set out in Article 2(1) of Directive (EU) 2016/943Article 2(19)
IoT deviceA connected product incorporating sensors, actuators or other data-generating components that connect to the internet or other networksArticle 2(5), recitals

Who This Guide Is For

This guide applies to any manufacturer that:

  • Places a connected product on the EU market, regardless of where the manufacturer is established
  • Provides a related service connected to a physical product sold, rented, or leased to EU users
  • Collects, stores, or processes data generated by connected products through EU users
  • Designs or develops IoT devices, smart home products, wearables, industrial sensors, medical devices with connectivity, connected vehicles, or similar hardware

Territorial scope follows market access, not establishment. A US, UK, Canadian, or Asian manufacturer placing connected products on the EU market is subject to the Data Act on the same basis as an EU-established manufacturer.

The Compliance Checklist

Category 1: Product Design and Default Data Access

The Data Act imposes design obligations on manufacturers. These are not obligations that can be addressed post-launch. They must be built into the product before it reaches the market.

ObligationWhat is requiredLegal basisStatus
Default data access by designConnected products must be designed to give users default access to data generated by the product, easily, securely, and in a comprehensive, structured, commonly used, machine-readable formatArticle 3(1)
Data generated by productIdentify and document all data generated by the product during its use, including operational data, sensor data, usage patterns, and performance dataArticle 3(1)
Real-time access capabilityWhere technically feasible, product data must be directly accessible to users in real timeArticle 4(1)
Access without frictionData access must not be made contingent on user registration, account creation, or acceptance of additional terms beyond what is necessaryArticle 4(1)
Third-party access facilitationThe product must be capable of facilitating data sharing with third parties designated by the user, on equivalent terms to those applicable to the manufacturerArticle 5(1)
Metadata provisionProvide users with metadata describing the nature of the data, how it is generated, and what it representsArticle 4(2)
Pre-contractual informationBefore purchase, rent, or lease, inform users in clear and plain language what data the product generates, whether the manufacturer has access to it, and whether third parties have accessArticle 3(2)

Category 2: Data Sharing with Users

Article 4 sets out the data sharing rights of users and the corresponding obligations on data holders.

ObligationWhat is requiredLegal basisStatus
Share data on user requestMake available to the user, without undue delay and free of charge, all data generated by the product that the user requestsArticle 4(1)
Format and qualityData must be provided in a structured, commonly used, machine-readable format of sufficient quality for the user’s intended purposeArticle 4(1)
Continuous accessWhere data is generated continuously, provide continuous or real-time access where technically feasibleArticle 4(1)
No charging for basic accessUsers cannot be charged for access to data generated by their own use of the productArticle 4(1)
Response to requestsRespond to user data access requests without undue delay, and in any event within the timeframe specified in implementing actsArticle 4(1)

Category 3: Data Sharing with Third Parties

Article 5 gives users the right to instruct data holders to share product-generated data with third parties of their choosing. This obligation sits at the core of the Data Act’s market contestability objective.

ObligationWhat is requiredLegal basisStatus
Share with third parties on user instructionMake product data available to third parties designated by the user, on terms no less favourable than those applicable to the manufacturer’s own useArticle 5(1)
Third-party data use limitationsThird parties receiving data under Article 5 may use it only for the purpose agreed with the user and must delete it when no longer needed for that purposeArticle 6(1)
No data monetisation by third partiesThird parties receiving data under Article 5 may not sell, license, or otherwise make the data available to further parties for commercial gainArticle 6(2)
No profiling restrictionThird parties may not use data received under Article 5 to build profiles of natural persons for purposes other than what the user requestedArticle 6(2)
Technically feasible access mechanismsImplement technical mechanisms enabling third-party access that are secure, standardised where possible, and proportionate to the nature of the dataArticle 5(5)

Category 4: Contractual Fairness

Chapter IV of the Data Act, Articles 13 to 15, sets out requirements for data sharing contracts between businesses. These apply where IoT manufacturers enter data sharing arrangements with other businesses, including downstream partners, platform operators, and data aggregators.

ObligationWhat is requiredLegal basisStatus
Fair and reasonable termsContractual terms governing data access and sharing must be fair, reasonable, and non-discriminatoryArticle 13(1)
No unilateral variationContracts must not allow one party to unilaterally vary terms in a way that disadvantages the other partyArticle 13(2)(a)
No exclusive remediesContracts must not limit available remedies in a way that creates an imbalance between the partiesArticle 13(2)(b)
No impediment to disclosure obligationsContracts must not prevent data holders from complying with their legal data sharing obligationsArticle 13(2)(c)
Unfair terms voidContractual terms that do not comply with Articles 13 to 15 are not binding on the disadvantaged partyArticle 13(4)
SME protectionsAdditional protections apply where one party is an SME. Unfair terms imposed on SMEs are subject to challengeArticle 14

Category 5: Trade Secrets

The Data Act provides a mechanism for data holders to protect trade secrets when complying with data sharing obligations, but the protection is conditional and narrow.

ObligationWhat is requiredLegal basisStatus
Trade secret identificationIdentify in advance which data or metadata constitutes a trade secret before invoking protectionArticle 4(8)
Confidentiality measuresImplement all necessary measures to preserve the confidentiality of trade secrets before data is sharedArticle 4(8)
No blanket refusalTrade secret protection cannot be used as a blanket refusal to share data. It can only be invoked where specific data meets the trade secret definition and specific confidentiality measures have been takenArticle 4(9)
Dispute mechanismWhere a data holder refuses to share data on trade secret grounds, the user or third party may refer the matter to the competent authorityArticle 4(9)

Category 6: Public Sector Data Access

Chapter V of the Data Act, Articles 17 to 22, gives public sector bodies the right to request data from private holders where there is an exceptional need, including emergency situations, failure of official statistics, or climate-related crises.

ObligationWhat is requiredLegal basisStatus
Respond to public sector requestsWhere a public sector body or Union institution makes a data request under Article 17, respond without undue delayArticle 17(1)
Assess and challenge requestsWhere a request is disproportionate or affects trade secrets, challenge it through the established mechanism before the applicable deadlineArticle 19
Compensation mechanismWhere data is provided to a public sector body at cost, claim reasonable compensation under the mechanism established by the implementing actArticle 20

Category 7: Cloud Switching and Interoperability

Articles 23 to 31 of the Data Act impose obligations on cloud service providers regarding switching and interoperability. IoT manufacturers that offer cloud-connected services alongside their devices are within scope.

ObligationWhat is requiredLegal basisStatus
Switching assistanceIf you provide cloud services connected to your IoT product, you must assist customers in switching to another provider without functional degradationArticle 23(1)
No switching fees after transitionSwitching fees must be reduced and ultimately eliminated on the schedule set out in Article 25Article 25
Data export on switchingOn customer request, make available all data, applications, and digital assets held on their behalf in a structured, commonly used, machine-readable formatArticle 24(1)
Minimum notice periodProvide customers with a minimum notice period before making changes that affect switching rights or data portabilityArticle 23(2)
Interoperability standardsComply with the interoperability specifications and European standards for cloud switching adopted under Article 30Article 30

Category 8: Enforcement and Penalties

InfringementMaximum penaltyLegal basis
Failure to comply with data access and sharing obligationsMember states set penalties. Must be effective, proportionate, and dissuasiveArticle 40
Failure to comply with contractual fairness requirementsMember states set penalties. Must be effective, proportionate, and dissuasiveArticle 40
Failure to comply with cloud switching obligationsMember states set penalties. Must be effective, proportionate, and dissuasiveArticle 40
Unfair contract termsVoid and unenforceable against the disadvantaged party. Subject to national enforcement actionArticle 13(4)

Member states were required to designate competent authorities and establish penalty regimes by 12 September 2025. Penalty levels vary by member state. The Data Act does not set a Union-wide maximum fine in the way the GDPR or AI Act do.

Self-Assessment Questionnaire

Work through the questions below before completing the checklist above. The answers determine which obligations apply to your specific product and business model.

Q1. Does your product generate data during use?
Yes: Data Act applies. Proceed to Q2.
No: Data Act is unlikely to apply to your product. Reassess if product design changes.

Q2. Can your product communicate data via the internet, an electronic communications service, or direct communication?
Yes: Your product is a connected product within Article 2(5). All obligations in Categories 1 to 5 apply.
No: Your product may fall outside the connected product definition. Seek specific advice.

Q3. Do you retain access to data generated by your product after it reaches the user?
Yes: You are a data holder subject to Articles 4 and 5 sharing obligations.
No: You retain design obligations under Article 3 but have reduced ongoing data sharing obligations.

Q4. Do you share product-generated data with third parties, including analytics providers, platform partners, or data aggregators?
Yes: Article 5 obligations and Article 6 use restrictions apply to those sharing arrangements. Review all data sharing contracts against Articles 13 to 15.
No: Third-party sharing obligations do not currently apply but will arise if sharing begins.

Q5. Do you provide a cloud service connected to your IoT product?
Yes: Articles 23 to 31 cloud switching and interoperability obligations apply.
No: Chapter VI obligations do not apply to the cloud layer.

Q6. Is your product placed on the EU market?
Yes: The Data Act applies regardless of where your company is established.
No: The Data Act does not apply unless you intend to enter the EU market.

Q7. Are any of your data sharing contracts with SMEs?
Yes: Additional Article 14 protections apply. Review all contracts with SME counterparties against the unfair terms provisions.
No: Standard Articles 13 and 15 contractual fairness obligations apply.

Data Act Interaction with Other EU Regulations

The Data Act does not operate in isolation. IoT manufacturers typically face obligations under multiple EU instruments simultaneously.

RegulationInteraction with Data ActKey intersection
GDPR (Regulation (EU) 2016/679)Data Act applies to all product data. GDPR applies where that data includes personal data. Both apply concurrentlyData minimisation, purpose limitation, and data subject rights under GDPR apply alongside Data Act sharing obligations
EU AI Act (Regulation (EU) 2024/1689)IoT devices incorporating AI may be high-risk AI systems under Annex I or Annex III. Data Act data governance obligations interact with AI Act Article 10 data quality requirementsData governance documentation required under both instruments must be reconciled
Cyber Resilience Act (Regulation (EU) 2024/2847)Applies to products with digital elements including most IoT devices. Security by design requirements interact with Data Act access-by-design obligationsSecurity measures protecting data must not be used to restrict legitimate data access rights under the Data Act
Radio Equipment Directive (Directive 2014/53/EU)Applies to IoT devices using radio frequency spectrum. Delegated acts under Article 3(3)(d)-(f) are introducing cybersecurity and privacy requirements for connected devicesSecurity requirements under RED interact with Data Act technical access mechanisms
NIS2 Directive (Directive (EU) 2022/2555)Applies to operators of essential services and digital infrastructure. IoT manufacturers supplying critical sectors face NIS2 cybersecurity obligations alongside Data Act requirementsIncident reporting obligations under NIS2 and data access mechanisms under Data Act must be coordinated
Machinery Regulation (Regulation (EU) 2023/1230)Applies to machinery incorporating connected components. AI Act Omnibus moved machinery from Annex I Section A to Section B, creating a transitional gap in AI-specific requirementsData generated by connected machinery is subject to Data Act sharing obligations regardless of the AI Act machinery classification

Frequently Asked Questions

The Data Act started applying in September 2025. Does it apply to products we placed on the market before that date?

The Data Act applies to connected products placed on the market after 12 September 2025. Products placed on the market before that date are not immediately subject to the full set of obligations, but manufacturers should assess whether their products are capable of meeting the technical requirements as their product lines evolve and new versions are released. Related services connected to pre-September 2025 products are within scope where those services continue to be provided.

We are a US manufacturer selling IoT products in Europe. Does the Data Act apply to us?

Yes. The Data Act applies to connected products placed on the EU market and to related services provided to EU users, regardless of where the manufacturer is established. A US manufacturer selling connected products in Germany, France, or any other EU member state is subject to the same obligations as an EU-established manufacturer. Unlike some EU regulations, the Data Act does not have an Authorised Representative requirement equivalent to the AI Act, but market access is contingent on compliance.

Our product collects data but we do not retain it. Are we still subject to the Data Act?

Yes, in part. The design obligations in Article 3 apply regardless of whether you retain data after it is collected. Your product must be designed to give users default access to data it generates. If you genuinely do not retain access to user data, your ongoing data sharing obligations under Articles 4 and 5 are limited, but you must ensure the product itself is technically capable of providing users with direct access to the data it generates.

A user has asked us to share their product data with a third-party app. Can we charge for this?

No. Article 5 requires data holders to make data available to third parties designated by the user on terms no less favourable than those applicable to the data holder’s own use. You cannot charge users for access to data generated by their own use of your product. You may charge third parties a reasonable cost-based fee for making data available to them, but this fee must be transparent and non-discriminatory.

We consider some of our product data commercially sensitive. Can we refuse to share it?

You can invoke trade secret protection for specific data that genuinely meets the trade secret definition under Directive (EU) 2016/943, but only if you have taken all necessary measures to preserve its confidentiality before sharing is requested. You cannot use trade secret protection as a blanket refusal. Where you invoke it, the user or third party may refer the matter to the competent authority under Article 4(9). The burden of demonstrating that specific data constitutes a trade secret and that confidentiality measures are in place falls on you.

Our IoT product connects to our own cloud platform. Does the cloud switching obligation apply to us?

Yes. If you provide a cloud service that is connected to your IoT product and through which users access their product data or related services, Articles 23 to 31 apply. You must assist users in switching to alternative cloud providers, eliminate switching fees on the schedule set out in Article 25, and make available all data held on the user’s behalf in a portable format upon request.

How does the Data Act interact with GDPR where our IoT product collects personal data?

Both apply concurrently. The Data Act governs access to and sharing of product-generated data, including data that may be personal data. The GDPR governs the processing of personal data and gives data subjects rights including access, rectification, erasure, and portability. Where a user requests access to product data under the Data Act and that data includes personal data, both the Data Act’s access mechanism and the GDPR’s Article 15 right of access apply simultaneously. The legal bases, timeframes, and format requirements of both instruments must be satisfied.

What penalties apply if we do not comply with the Data Act?

The Data Act requires member states to establish effective, proportionate, and dissuasive penalties but does not set a Union-wide maximum fine. Penalty levels therefore vary by member state. Several member states have linked their Data Act penalty regimes to their GDPR enforcement infrastructure. In addition to financial penalties, non-compliant contractual terms are void and unenforceable, which creates direct commercial exposure independent of regulatory action.

The Cyber Resilience Act also requires security by design for our products. Do these two obligations conflict?

They can create tension but not an irresolvable conflict. The Cyber Resilience Act requires manufacturers to implement security measures protecting connected products from attack. The Data Act requires products to be designed to give users and third parties access to product data. The Data Act expressly provides that security measures may be used to protect data but may not be used to restrict legitimate access rights. Manufacturers must design products that are secure by default and accessible by default simultaneously. This requires careful technical architecture, particularly around authentication and access control mechanisms.

Compliance Timeline Summary

DateObligation
12 September 2025Data Act applies to connected products placed on market from this date and related services
12 September 2025Data sharing with users (Articles 4-5) in force
12 September 2025Contractual fairness requirements (Articles 13-15) in force
12 September 2025Cloud switching obligations (Articles 23-31) in force
12 September 2026Commission review of implementing acts on data formats and interoperability
OngoingMember state competent authorities enforcing from September 2025

DISCLAIMER

This guide reflects the text of Regulation (EU) 2023/2854 as published in the Official Journal on 22 December 2023 and applicable guidance issued through August 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. IoT manufacturers should obtain advice specific to their products, business models, and applicable member state penalty regimes.