Data access is no longer only something to address after a customer submits a request.
Since the 12th of September 2026, in-scope connected products and related services placed on the EU market must be designed so that relevant data is accessible to users by default. Data must be made available easily, securely and free of charge, in a comprehensive, structured, commonly used and machine-readable format. Where relevant and technically feasible, users should be able to access it directly.
This is the EU Data Act’s “access by design” requirement, and it represents an important change in how businesses must think about connected-product data.
Vehicles, industrial machinery, agricultural equipment, smart appliances, medical and fitness devices and other connected products continuously generate information about how they operate, how they are used and the environments in which they function. Historically, much of that information has remained primarily within the manufacturer’s or service provider’s systems.
The Data Act is changing that relationship.
The Regulation has applied generally since 12th September 2025, establishing clearer rights concerning access to and use of data. The latest milestone moves those rights closer to the point at which products and services are designed.
For affected businesses, this is not simply a technical product requirement. It raises broader questions about data architecture, customer interfaces, security, third-party sharing, contractual responsibilities and governance throughout the data lifecycle.
What changed on September 12th
The EU Data Act already gave users rights to access certain data generated through their use of connected products and related services.
Since September 12th 2026, an additional requirement applies to connected products and related services placed on the market after that date.
In-scope connected products must be designed and manufactured, and related services designed and provided, so that relevant product data, related-service data and the metadata needed to interpret and use that information are accessible to the user by default.
This affects more than consumer technology. Connected products may include:
Vehicles and mobility systems
Industrial and manufacturing equipment
Agricultural machinery
Medical and fitness devices
Smart-home technologies
Connected energy systems
Aviation and transportation equipment
Other Internet-of-Things devices
The concept of a user is also broader than an individual consumer. It can include a person or business that owns, rents or leases a connected product.
A manufacturer operating connected production equipment, for example, may now have stronger rights to access data generated through its use of that machinery, rather than remaining entirely dependent on the original equipment manufacturer.
The result is a significant change in the relationship between the product, the organisation that manufactures or supplies it and the user who generates data through its operation.
What “access by design” requires
The new requirement brings data accessibility into the product-development lifecycle.
Relevant data must be accessible by default:
Easily and securely
Free of charge to the user
In a comprehensive and structured form
In a commonly used and machine-readable format
Together with the metadata needed to interpret and use it
Directly, where this is relevant and technically feasible
Direct access will not necessarily be appropriate or technically feasible in every situation. Where users cannot access the data directly through the product or related service, the applicable data holder may need to provide another suitable access mechanism.
Depending on the product and data involved, this could include a customer portal, application programming interface, structured export function or another secure retrieval process.
Access by design
close
Relevant questions include:
What data does the product or service generate?
Where is that data stored?
Can the user locate and access it without unnecessary difficulty?
Is it presented in a usable and machine-readable format?
What metadata is needed for the user to understand it?
Can the data be used outside the manufacturer’s own platform?
How will the identity and authority of the user be verified?
Can access be provided without exposing another person’s data?
How will cybersecurity and trade-secret risks be managed?
Can access be maintained continuously or in real time where required?
The requirement therefore goes further than placing a download button on an existing platform. Businesses need to consider whether the complete access journey is genuinely usable.
These are technical questions, but they are also questions of governance, ownership and operating model.
Who and what is covered
The obligations apply across sectors and can affect both business-to-consumer and business-to-business relationships.
The principal organisations involved may include:
Manufacturers, which design or produce connected products;
Providers of related services, such as applications or digital services that affect how a connected product behaves;
Data holders, which have the right or obligation to use and make relevant data available;
Users, meaning individuals or organisations that own, rent or lease connected products; and
Third-party data recipients, which may receive data at the user’s request.
The precise role of each organisation may depend on the product, service and contractual arrangements involved. A single connected-product ecosystem may also contain more than one data holder.
The Data Act includes exemptions and qualifications. For example, Chapter II obligations may not apply to data generated by connected products manufactured or designed, or related services provided, by qualifying microenterprises and small enterprises, provided the Regulation’s additional conditions are satisfied.
Organisations should therefore perform a product-specific and role-specific assessment rather than assuming that every connected device is treated identically.
Understanding which data must be accessible
The Data Act does not require every piece of information held within a connected system to be disclosed automatically.
Its connected-product provisions principally concern raw and pre-processed data generated using a connected product or related service that is readily available to the data holder, together with the relevant metadata.
Examples may include sensor information relating to:
Temperature
Pressure
Flow rate
Location or position
Acceleration and speed
Energy consumption
Equipment status
Usage or operating conditions
Both personal and non-personal data may fall within scope.
By contrast, substantially enriched, derived or inferred information produced through additional analysis may fall outside these provisions. Content, such as audiovisual material accessed through a connected product, is also treated differently.
The Regulation preserves intellectual-property protections and contains safeguards concerning trade secrets, cybersecurity, health and safety. These safeguards require careful assessment and should not be interpreted as automatic grounds for refusing access.
A useful starting point is to classify information into four categories:
Data generated using a connected product.
Data generated through the use of a digital service associated with that product.
Information required to interpret, retrieve or use the underlying data.
Information created through further analysis, enrichment or proprietary processing.
Without this classification, an organisation may struggle to determine what must be made accessible, what can legitimately be protected, and which controls should govern disclosure.
How data access may reshape competition
The Data Act is not only concerned with giving users visibility over data. It may also allow users to request that relevant information be made available to a third party of their choice, subject to the Regulation’s conditions.
Consider a company operating connected industrial machinery.
Operational data that was previously accessible mainly to the equipment manufacturer could potentially be shared with an independent provider selected by the user. That provider might use the information to deliver:
Predictive maintenance
Performance monitoring
Energy-efficiency analysis
Equipment optimisation
Insurance or risk-analysis services
Independent repair and aftermarket support
For established manufacturers and service providers, this could increase competition in aftermarket services.
For technology companies, analytics providers and specialist maintenance businesses, it could create opportunities to develop services using data that was previously difficult to obtain.
The commercial question is therefore no longer simply,
“How do we protect the data generated by our products?”
Organisations must also ask,
“How can that data be accessed, shared and reused legitimately, securely and competitively?”
Why this is a data-governance issue
“Access by design” may begin with product architecture, but its impact extends across the organisation.
Product teams may need to reconsider how connected products generate and expose information. Technology teams may need to implement interfaces, exports and identity controls. Legal and procurement teams may need to review contracts and data rights. Cybersecurity teams must assess whether expanded access could introduce new vulnerabilities.
Data governance connects these responsibilities.
Access by design
close
Organisations need a clear understanding of:
What data they generate and retain
Which products and related services are in scope
Whether they act as a manufacturer, data holder, user or recipient
Where relevant data is stored
Who is permitted to access, use and share it
Which contracts govern those activities
How personal and non-personal data are distinguished
What security, intellectual-property and trade-secret protections apply
Who approves or responds to access and sharing requests
How decisions and disclosures are recorded
How complaints and disputes will be handled
The relationship with the General Data Protection Regulation is particularly important.
Where connected-product data contains personal data, the GDPR continues to apply. If the person requesting the information is not the relevant data subject, the data cannot be disclosed merely because the Data Act provides access rights. An appropriate legal basis and any other applicable data-protection conditions must still be established.
The Data Act therefore complements the GDPR. It does not replace it.
What organisations should do now
The 12th September deadline has just passed. For affected organisations, the focus should now move from preparing for the rule to demonstrating how it has been implemented.
A practical response should include the following actions.
Create an inventory of connected products and related services placed on the EU market after 12th September 2026. Record the manufacturer, service provider, intended user and applicable markets.
Determine whether the organisation acts as a manufacturer, provider of a related service, data holder, user, data recipient or a combination of these roles.
Document what data each product and service generates, where it is stored, how frequently it is collected, whether it contains personal data and what metadata is required to interpret it.
Distinguish raw and pre-processed product data from derived information, inferred insights, protected content and information that may contain trade secrets.
Assess whether users can access relevant data easily, securely and free of charge. Confirm that formats are structured, commonly used and machine-readable, and determine whether direct or real-time access is relevant and technically feasible.
Ensure that authentication, authorisation, data minimisation and disclosure controls prevent unauthorised access. Consider how personal data, information relating to other users and security-sensitive information will be handled.
Confirm that contracts, pre-contractual notices, customer terms and related-service agreements clearly explain what data is generated, how it can be accessed, how it may be used and how users can request third-party sharing.
Define which teams are responsible for product compliance, technical access, request management, cybersecurity, legal interpretation, data protection and escalation.
Maintain records of design decisions, technical-feasibility assessments, data classifications, access tests and decisions involving security or trade-secret protections.
Readiness begins with understanding the data landscape. A standalone policy will have limited value if the organisation cannot show what data exists, where it resides and how users can obtain it.
Looking beyond
More requirements remain to be implemented.
From 12th January 2027, switching charges for data-processing services are due to disappear.
From 12th September 2027, the Data Act’s rules concerning unfair contractual terms will extend to certain contracts concluded on or before 12 September 2025. This includes qualifying contracts of indefinite duration and contracts due to expire at least ten years after 11th January 2024.
The regulatory framework may also continue to evolve. The European Commission’s Digital Omnibus proposal includes proposed amendments to the Data Act, but those proposals should not be treated as final law while the legislative procedure remains ongoing.
Businesses should therefore continue implementing the Data Act as it currently applies while monitoring future amendments and implementation guidance.
The wider direction is already clear: generating data no longer necessarily means retaining exclusive control over how that data is accessed or used to create value.
For organisations, the challenge is to adapt to that shift without weakening security, confidentiality or accountability.
How we can support you
As organisations adapt to the EU Data Act’s new requirements, compliance should be viewed as more than a regulatory obligation. Effective implementation requires a clear understanding of how data is generated, accessed, governed and protected across the organisation.
Grant Thornton’s Technology and Advisory teams can support businesses with connected-product and related-service assessments, data discovery and classification, access journey reviews, governance frameworks, security assessments, cloud portability considerations and Data Act readiness programmes.
By establishing a robust product inventory, reliable data mapping, practical access mechanisms and clear accountability, organisations can not only meet their regulatory obligations but also strengthen their ability to unlock value from data while maintaining security, transparency and trust.