Summary
- Article 3(1) now applies to connected products and related services placed on the EU market after 12 September 2026.
- Relevant data must by default be easy, secure, free to access, and available in a structured, machine-readable form.
- Product makers now have to reconcile data accessibility with security, privacy, trade-secret protection, and other European digital-product requirements.
A new product-design requirement under the EU Data Act now applies to connected products and related services placed on the European market after 12 September 2026, adding data accessibility to the engineering requirements facing manufacturers of internet-connected equipment.
Article 3(1) requires connected products to be designed and manufactured, and related services designed and provided, so that relevant product and service data are accessible to the user by default. The information must be easy and secure to access, free of charge, comprehensive, structured, commonly used, and machine-readable.
Where relevant and technically feasible, the data should be directly accessible from the product itself. Where that is not possible, other provisions in the regulation require data holders to make readily available data accessible without undue delay and, where appropriate, continuously and in real time.
The wording reaches far beyond consumer smart-home equipment. The regulation’s recitals identify vehicles, health equipment, ships, aircraft, household devices, medical products, agricultural machinery, and industrial machinery among the kinds of connected products capable of falling within its scope.
Manufacturers also have to provide prospective users with information before a contract is concluded, including the type, format, and estimated volume of data a product can generate, whether it produces data continuously or in real time, and how users can access or retrieve it.
The requirement creates an architectural problem as well as a compliance one. A product must expose useful data to legitimate users without turning the access mechanism into an uncontrolled interface for attackers or providing one customer with information belonging to somebody else.
The Data Act includes safeguards around those tensions. Access to personal data still has to comply with European data-protection law, while trade-secret protections can justify proportionate technical and organisational measures. The regulation also allows access or sharing to be restricted where processing could undermine legally established product-security requirements and create a serious adverse effect on health, safety, or security.
Those provisions leave manufacturers with design decisions that cannot be resolved solely by legal wording. Authentication, authorisation, API design, data segregation, logging, revocation, and lifecycle support determine whether an access mechanism remains usable without weakening the product it was designed to serve.
The obligation is arriving as European product regulation becomes more interconnected. Cyber Resilience Act reporting duties have also entered their operational phase, placing new vulnerability and incident-reporting responsibilities on manufacturers of products with digital elements.
The two regimes address different problems. The Data Act concentrates on access to and use of data generated by connected products, while the Cyber Resilience Act is establishing cybersecurity requirements across the product lifecycle. In practice, both can influence the same engineering decisions where a manufacturer builds data interfaces, supports remote services, controls software updates, or handles security events.
Procurement is another likely pressure point. Buyers of industrial machinery and connected equipment have often depended on proprietary interfaces or manufacturer-controlled access to operational data. A regulatory expectation that users can obtain the data generated by a product changes the balance around maintenance, aftermarket services, analytics, and switching between suppliers.
The design obligation does not remove questions about which data a product is capable of making available, nor does it override sector-specific safety or security requirements. It does, however, mean that data accessibility can no longer be treated solely as an optional commercial feature for newly covered products entering the EU market.
Manufacturers now have to make that access part of the product architecture while preserving the controls that stop availability from becoming exposure.





