Data Act and connected products: who can use the data generated by machinery and devices?
Cars, household appliances, medical devices, industrial plants and agricultural machinery continuously generate data during their use. Until recently, however, this information often remained under the exclusive control of the manufacturer or the provider of the related service.
The Data Act, namely Regulation (EU) 2023/2854, introduces new rules aimed at making such data more accessible and usable. The Regulation has applied since 12 September 2025 and affects, among others, manufacturers of connected devices, providers of applications and digital services, and businesses using smart machinery.
What is a connected product?
A connected product is an item capable of collecting, generating or communicating data concerning its use or its surrounding environment.
Examples include:
a connected car;
industrial machinery equipped with sensors;
a health or fitness monitoring device;
a household appliance that can be controlled through an application;
a smart air-conditioning system;
a robot or agricultural machine.
The Data Act also applies to so-called related services, such as applications required to control the device or modify its operation.
Who owns the data?
The Data Act does not simply provide that all data “belongs” to the user. Rather, it introduces specific rights of access, use and sharing.
The user may be a consumer or a business that owns, leases or rents the product. For example, a company using industrial machinery may request access to data concerning its operation, performance, energy consumption or maintenance needs.
As a general rule, access must be provided through a straightforward procedure and free of charge for the user. At the user’s request, the data may also be transmitted to a third party, such as an independent maintenance provider or a data analytics service provider.
This may have significant consequences for after-sales service markets. Customers will not necessarily be required to rely on the manufacturer for maintenance or repairs, as they may make the data available to alternative service providers.
Which data must be made available?
The rules mainly concern raw data and data that has undergone initial processing, generated through the use of the product and already available to the manufacturer or service provider.
This may include, for example, information concerning:
temperature, pressure or speed;
location and acceleration;
energy consumption;
duration and manner of use;
operating status;
errors and maintenance requirements.
Content, such as films viewed on a smart TV, and data that has been substantially processed or enriched through specific analyses carried out by the manufacturer are generally excluded.
Can the manufacturer continue to use the data?
The manufacturer or service provider cannot assume that it may freely use all non-personal data generated by the product. The Data Act requires such use to be governed by an agreement with the user.
It is therefore essential to review the terms and conditions of sale, rental or licensing and clearly establish which data is generated, who may access it, the purposes for which it may be used, whether it may be shared with other parties and how long it will be retained.
However, the contract may not exclude or unjustifiably restrict the rights granted to the user under the Regulation.
What happens when trade secrets are involved?
The obligation to share data does not remove the protection afforded to trade secrets.
The manufacturer may require appropriate measures to protect confidential information, such as confidentiality agreements, access restrictions or technical security measures.
However, the existence of a trade secret does not automatically justify refusing all access. Refusal is permitted only in limited circumstances, where a high risk of serious economic damage resulting from disclosure can be demonstrated.
The Data Act and the GDPR
Data generated by a connected product may also include personal data. Examples include the location of a car, data collected by a wearable device or information concerning the use of an application.
In such cases, the Data Act applies alongside the GDPR. The transmission of personal data must therefore be based on an appropriate legal basis and comply with the principles of transparency, data minimisation and security. The right of access under the Data Act does not replace or modify the rights granted to data subjects under the GDPR.
What should businesses do?
Businesses concerned should first identify the connected products and digital services they offer, determine which data is actually generated and establish who controls it.
They should then:
update the information provided to customers before the sale or conclusion of the contract;
review contractual clauses concerning access to and use of data;
establish a simple procedure for handling user requests;
implement secure methods for transmitting data to third parties;
identify information that may qualify as trade secrets;
coordinate Data Act compliance with GDPR requirements.
A further deadline concerns connected products placed on the market after 12 September 2026. Such products must be designed and manufactured in a way that makes data easily, securely and free of charge accessible to the user by default and, where relevant and technically feasible, directly accessible.
This will require not only legal coordination, but also technical and product design measures.
The Data Act is therefore not merely a set of rules on the circulation of data. The new requirements may affect how products are designed, contracts are drafted and maintenance and support services are organised. For manufacturers and users of connected devices, a timely assessment of data flows is the first step towards identifying the applicable obligations and the new business opportunities.