EUREP

EU Data Act for connected products: what makers must do

Stefan Hülsiggensen

10 min read

EU Data Act for connected products: what makers outside the EU must build in after 12 September 2026, tell buyers and why they need a legal representative.

White smart home devices, including a camera, a smart plug, a sensor and a light bulb, on a light grey surface

You make smart home devices in Asia, such as app-controlled air purifiers or robot vacuums, and sell them in the EU. Under the EU Data Act, connected products placed on the EU market after 12 September 2026 must give users access to their data by design and by default (Articles 3(1) and 50 of Regulation (EU) 2023/2854). Here is what applies, who must do what, and when you need a legal representative.

What the EU Data Act covers for connected products

The Data Act is a regulation, directly applicable in all member states since 12 September 2025 (Article 50 (opens in a new tab)). It covers manufacturers of connected products and providers of related services wherever they are established (Article 1(3)(a)).

A connected product obtains, generates or collects data about its use or environment and can communicate them over a network, a physical connection or on-device access, as long as its main function is not storing or processing data for others (Article 2(5)). Prototypes are excluded (recital 14).

The Data Act covers raw and pre-processed product data and related service data with the metadata needed to use them, but not content such as a film on a TV (Articles 1(2)(a), 2(15), 2(16) and 3(1); recitals 15 and 16).

What applies since 2025, and what after 12 September 2026

For connected products, Article 50 deferred only the design obligation:

Data Act duties for connected products and when they apply
DutyData ActApplies
Access on request, sharing with third parties the user namesArt. 4(1), 5(1)Since 12 September 2025, according to the Commission's FAQ also for products already on the market
Information before a sale, rental, lease or related service contractArt. 3(2), (3)Since 12 September 2025
Legal representative for companies outside the EUArt. 37(11)Since 12 September 2025
Access by design and by defaultArt. 3(1), 50Products and related services placed on the market after 12 September 2026
Data Act duties for connected products and when they apply

Article 3(1) requires access by default, easily, securely, free of charge and in a comprehensive, structured, commonly used and machine-readable format, directly where relevant and technically feasible. According to the Commission's FAQ, you may choose direct access without your involvement or indirect access on request, typically via your server (question 22).

Micro and small enterprises are exempt from the Chapter II duties (Articles 3 to 6) unless a partner or linked enterprise is larger or they design or make the product as a subcontractor; medium-sized enterprises are exempt in their first year at that size and for each product's first year on the market (Article 7(1)). The legal representative (Article 37(11)) is not exempted.

The Digital Omnibus proposal of 19 November 2025 (COM(2025) 837 (opens in a new tab)) would amend parts of the Data Act, such as the trade secret refusal in Article 4(8), but as published not Articles 3, 7, 37 or 50. As of 5 October 2026, it was awaiting a committee decision in the European Parliament (2025/0360(COD) (opens in a new tab)).

Who is the data holder, and what it owes users

The data holder is whoever has the right or obligation to use and make available the data (Article 2(13)). According to the Commission's FAQ, that is typically the manufacturer, but what counts is who controls access: an app provider can be a separate data holder, and if only the user can access the data, there is none (question 21). The data holder must:

  • answer access requests without undue delay, free of charge and in the quality it has itself (Article 4(1));
  • share data with a third party the user names, such as a repair service, but not with gatekeepers under the Digital Markets Act (Article 5(1), (3));
  • use non-personal data only under a contract with the user (Article 4(13));
  • identify trade secrets and agree protective measures; withholding data or, exceptionally, refusing access must be substantiated in writing and notified to the competent authority (Article 4(6) to (8)).

What buyers must be told before the contract

Before a contract to buy, rent or lease a connected product, the seller, rentor or lessor, which may be the manufacturer, must tell the user at least (Article 3(2)):

  • the type, format and estimated volume of product data;
  • whether data are generated continuously and in real time;
  • whether data are stored on the device or a remote server, and for how long;
  • how the user can access, retrieve or erase them.

Before its own contract, the provider of a related service such as the app must add which data it will obtain, who will use them and for what, the data holder's identity and address, how to contact it and the right to complain to the competent authority (Article 3(3)).

If retailers sell your devices, they owe the information, but only you know the data: supply it, and tell users about changes, for example after an update (recitals 20 and 24). Your privacy notice under the General Data Protection Regulation (GDPR) remains a separate obligation.

A company that makes connected products available or offers services in the EU without an establishment there must designate a legal representative in one of the member states (Article 37(11) (opens in a new tab)). Competent authorities can address it in addition to or instead of you, and on request it must comprehensively demonstrate the measures you have taken to comply (Article 37(12)).

You then fall under that representative's member state, and your own liability stays unaffected. Until you designate one, the authorities of every member state are competent, though not twice on the same facts (Article 37(13)). Penalties are national; data protection authorities may also fine, within their competence, up to the Article 83(5) GDPR amounts (Article 40(1), (4)).

EU representative roles one connected device can involve
RoleLegal basisWhen requiredMain task
Legal representative (Data Act)Art. 37(11) to (13) Data ActNo EU establishment; any member stateContact for Data Act authorities
GDPR representativeArt. 27 GDPRGDPR applies under Art. 3(2), no exemption; where data subjects areContact for data protection authorities and data subjects
EU Authorized RepresentativeArt. 4 Regulation (EU) 2019/1020; for radio equipment Art. 11 Directive 2014/53/EUOne option for the EU economic operator of most CE-marked productsDeclaration of Conformity, cooperation with market surveillance
Authorized representative (Cyber Resilience Act)Art. 18 Regulation (EU) 2024/2847Optional, from 11 December 2027Documentation, cooperation with market surveillance
EU representative roles one connected device can involve

How the Data Act fits with the GDPR and the Cyber Resilience Act

In a conflict, data protection law such as the GDPR prevails over the Data Act (Article 1(5)). If you offer devices and app accounts to people in the EU and process their personal data, the GDPR applies to you (Article 3(2) GDPR (opens in a new tab)), and you may need a GDPR representative.

The Cyber Resilience Act (CRA) sets cybersecurity rules for products with digital elements: reporting since 11 September 2026, full application from 11 December 2027 (Article 71(2) CRA (opens in a new tab); see CRA reporting obligations). Internet-connected radio equipment has had cybersecurity requirements under the Radio Equipment Directive since 1 August 2025 (Delegated Regulation (EU) 2022/30). Data Act access must be secure (Article 3(1)), and contracts may restrict it where it could undermine statutory security requirements and seriously endanger health, safety or security (Article 4(2)).

Practical example: a smart air purifier maker from Asia

An Asian manufacturer sells Wi-Fi air purifiers through an EU retail chain and its own web shop. Its app shows air quality and filter life and sets the fan speed, so it is a related service. Readings go to the manufacturer's cloud, making it the data holder. It has no EU establishment and is not a small enterprise.

For units placed on the market after 12 September 2026, the app offers a free export of sensor readings, settings and filter status with timestamps as JSON or CSV.

Who does what in the example
TaskWhoData Act
Information before the saleRetail chain and web shop, with the manufacturer's data sheetArt. 3(2)
Information before app registrationManufacturer as app providerArt. 3(3)
Access requests for older units, data for a repair serviceManufacturer as data holderArt. 4(1), 5(1)
Contact for competent authoritiesLegal representative in one member stateArt. 37(11), (12)
Who does what in the example

Six steps for makers outside the EU

  1. Check the exemption for micro and small enterprises (Article 7(1)).
  2. Map products, related services and data flows, and name each data holder (Article 2(13)).
  3. Build in access by default for units placed on the market after 12 September 2026 (Article 3(1)).
  4. Write the pre-contractual information once, at a stable address for every seller (Article 3(2), (3)).
  5. Set up request handling with a trade secrets procedure; the Commission's non-binding model contractual terms can help (Articles 4, 5, 41).
  6. Designate your legal representative in one member state (Article 37(11)).

Common mistakes with the Data Act

  • Treating it as a privacy law. It also covers non-personal data such as sensor readings (Article 1(2)).
  • Charging users for access. Access is free for the user (Articles 3(1), 4(1), 5(1)); compensation can only be agreed with a business receiving the data (Article 9(1)).
  • Leaving the information to the retailer. The seller owes it (Article 3(2)), but needs your data sheet.
  • Relying on another representative. A GDPR or product law representative covers the Data Act only with its own mandate (Article 37(12)).

Conclusion: build access in, inform buyers, name a representative

Access requests, sharing requests, pre-contractual information and the legal representative are due now; access by design follows for every unit placed on the market after 12 September 2026.

If you are planning the EU launch of a connected device, our compliance consulting helps you plan the product compliance side, from the applicable rules to the documentation.

Frequently asked questions

Does the EU Data Act apply to manufacturers outside the EU?

Yes. It applies to manufacturers of connected products placed on the EU market and to providers of related services, irrespective of where they are established (Article 1(3)(a) Data Act). A company without an EU establishment must also designate a legal representative in a member state (Article 37(11)).

Does Article 3(1) of the Data Act apply to products already on the market?

It applies to connected products and related services placed on the market after 12 September 2026 (Article 50). According to the Commission's FAQ, this refers to each unit, so new units of an older model are covered. Access on request under Article 4 has applied since 12 September 2025.

Is the Data Act legal representative the same as a GDPR representative?

No. They rest on different laws: Article 37(11) Data Act and Article 27 GDPR. The GDPR representative must be in a member state where the data subjects are, and the GDPR duty has exemptions; the Data Act representative can be in any member state, and Article 37(11) has no comparable exemption. Each role needs its own mandate.

Do small manufacturers have to comply with the Data Act?

Chapter II does not apply to products of micro or small enterprises (under 50 staff, turnover or balance sheet total up to EUR 10 million) unless a partner or linked enterprise is larger or they act as a subcontractor. Medium-sized ones are exempt in their first year at that size and for each product's first year on the market (Article 7(1) Data Act). The legal representative duty still applies.

Do I have to share analytics derived from the data?

Not unless you agree to it with the user. The Data Act covers raw and pre-processed product and related service data with metadata; information you derive with proprietary, complex algorithms is outside its scope (recital 15).

More insights

Apply this to your product

Talk to our team: we identify which of these requirements apply to you.

Stefan HülsiggensenFounder and Managing Director