Connected kit placed on the market since 12 September must be built to hand its data to the buyer. The paperwork that says how has been owed for a year.
The design duty is real and narrower than the coverage suggests: it stops at raw data, qualifies its most useful word with 'technically feasible', and says nothing about how long the access lasts. That last part is the contract's job, and most contracts have not been asked to do it.

Draft, not yet edited. Written by Bram Coppens, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.
Since 12 September, anything connected placed on the EU market has to have been built so that the buyer can get its data out. That is Article 3(1) of the Data Act, and it is the only new part. The information you are owed before signing, which is being sold alongside it as news, has applied since 12 September 2025. If your last connected purchase arrived without it, you were owed it then, and nobody asked.
My verdict for the tender pack is simple. Ask for the disclosures in writing, ask when the units were first placed on the market, and put the length of access in the contract, because the regulation does not.
What the design duty actually says
Article 3(1) requires connected products to be "designed and manufactured", and related services "designed and provided", so that product data and related service data, with the metadata needed to read them, are "by default" accessible to the user: easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format.
Then the phrase every vendor's lawyer has highlighted: "where relevant and technically feasible, directly accessible to the user". The qualifier sits on directly, not on accessible. Accessibility is not optional. What a manufacturer may avoid, if it can argue feasibility, is letting you reach the data without going through it. When it does, you are into Article 4(1): you ask the data holder, and it must supply the data without undue delay, free, of the same quality it gets itself.
On a fleet the difference is everything. An export button on the device is something you can test at goods-in. A request process run by the vendor's cloud is something you find out about in month three, from a helpdesk ticket.
The "user", for these purposes, is you. Article 2(12) covers a legal person that owns a connected product or leases it, so the organisation that signed the purchase order holds the right, not the employee holding the device.
| Provision | Who owes it | Applies from | What you get |
|---|---|---|---|
| Article 3(1) | Manufacturer; related service provider | Products and services placed on the market after 12 Sep 2026 | Data accessible by default; directly, where feasible |
| Article 3(2) | Seller, rentor or lessor | 12 Sep 2025 | Before contract: data type, format, volume, storage, retention, how to access and erase |
| Article 3(3) | Related service provider | 12 Sep 2025 | Before contract: who holds the data, what they will use it for, contract length and termination |
| Article 4(1) | Data holder | 12 Sep 2025 | Data on request, where it cannot be reached directly |
What it does not give you
It does not give you the vendor's intelligence. Recital 15 puts raw and pre-processed data inside the scope and puts "inferred or derived" data outside it, naming sensor fusion. So the temperature readings from the building management system are yours. The predictive maintenance score built on them is not, unless the contract says so. Content is out as well, by Article 1(2)(a).
It does not name a format, an API or a standard. "Commonly used and machine-readable" is satisfied by a CSV file, and I expect to receive a great many CSV files.
It does not say how long. Article 3(2)(c) makes the seller disclose the intended retention period without setting one; Article 3(3)(i) makes the service provider disclose how long its contract runs and how it ends. Put those two disclosures next to each other and you have the day the access stops. That is the date I care about, and the regulation leaves it to the negotiation.
It does not reach every supplier. Article 7(1) exempts micro and small manufacturers from the whole chapter, unless they belong to a larger group or are subcontracted to make someone else's product, and gives a medium-sized one a year. Industrial kit from a specialist firm of forty people may owe you nothing under this text.
And it leaves the vendor two exits. Under Article 4(2) the contract may restrict access where it could undermine the product's security to the point of endangering people. Under Articles 4(6) to 4(8) a data holder may withhold identified trade secrets if you cannot agree protective measures, or refuse if serious economic damage is highly likely. A refusal means notifying the competent authority, a higher bar than saying the export feature is on the roadmap.
If the devices are carried by staff, some of that data is about them. Article 4(12) releases personal data to a user who is not the data subject only where GDPR gives a lawful basis. Your DPO will want to see the Article 3(2) sheet before your MDM team does.
The date counts something, and the text does not say what
Article 50 says the design duty applies to products "placed on the market after 12 September 2026", and Article 2(22) defines placing on the market as the "first making available of a connected product". Model or unit, it does not say. If it follows the unit-by-unit reading common in EU product law, a 2024 model shipped from the warehouse last week is inside the duty. I could not settle that from the Data Act, and the Commission's FAQ, where its view would be, is not relied on here. The Digital Omnibus proposal would amend parts of the regulation; nothing here assumes it passes.
What to put to a supplier this quarter
Six questions, in order. First: for each SKU on the quote, when were these units first made available on the EU market, and do you treat Article 3(1) as applying to them? Second: the Article 3(2) information in writing, as a schedule to the contract, including the technical means of access and the retention period. Third: which data can be reached on the device, and which only through your service, and what happens to the second kind on the day the service contract ends.
Fourth: which data you classify as derived and therefore withhold, listed, not described. Fifth, for industrial suppliers: do you rely on the Article 7 exemption, and are you part of a larger group? Sixth: the clause governing your own use of our non-personal data. Article 4(13) allows a data holder to use it only on the basis of a contract with the user, and recital 25 confirms the parties may limit that use. It is the one lever the regulation hands the buyer outright, and Article 7(2) stops the vendor's standard paper taking it back: a term waiving your rights under the chapter does not bind you.
Enforcement of the regulation sits with national competent authorities, under penalties each Member State sets; I have not checked which Belgian body has the file. What you can enforce yourself is the contract. The Commission's model terms under Article 41 were due a year ago and are non-binding by design, so they help only if somebody staples them to the contract.
The sensor will be fine. Nobody has ever failed an audit on a sensor. The question is what its data is still connected to in 2031, and the only document that can answer that is the one you have not signed yet.
Written from
Primary The document itself. Claims in this piece rest only on these.
- Regulation (EU) 2023/2854 of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act), OJ L, 2023/2854, 22.12.2023Read for this piece, from the Official Journal text as served by the Publications Office, not the consolidated version. Articles 1 to 8, Articles 40, 41 and 50, and recitals 15 and 25 read in full; the rest of the regulation was not reread. Source for: the Article 3(1) design duty, quoted in part, and the placement of 'where relevant and technically feasible' on direct access only; the Article 3(2) and 3(3) pre-contract lists; the Article 2(12) definition of user as including a legal person that owns or leases the product; the Article 2(22) definition of placing on the market as the first making available of a connected product; the exclusion of content at Article 1(2)(a); Article 4(1) on access by request, 4(2) on security restrictions, 4(6) to 4(8) on trade secrets, 4(12) on personal data where the user is not the data subject, and 4(13) on the data holder's use of non-personal data only on the basis of a contract with the user; Article 7(1) on the small and micro enterprise exemption and the one-year grace for medium-sized ones, and 7(2) on terms that derogate from user rights not binding the user; Article 40 on penalties set by Member States; Article 41 on non-binding model terms due before 12 September 2025. Article 50 is the source for every date in the piece: application from 12 September 2025; Article 3(1) applying to connected products and related services placed on the market after 12 September 2026. Recital 15 is the source for the exclusion of inferred or derived data, including sensor fusion. Recital 25 is the source for the statement that parties may contractually exclude or limit the data holder's use of non-personal data.
- Commission frequently asked questions on the Data ActNot opened for this piece. Named in the body only as the place a reader would look for the Commission's reading of whether 'placed on the market' in Article 50 is counted per model or per unit. Nothing in the body rests on it, and the body says the question is not answered by the regulation.
- The Blue Guide on the implementation of EU product rules 2022, OJ C 247, 29.6.2022Not opened for this piece. The general proposition that EU product legislation counts placing on the market per individual unit is stated in the body as a question, not relied on as the answer for the Data Act. An editor should either open the Guide and confirm it or cut the sentence that mentions how product law usually counts.
- Digital Omnibus proposals amending Regulation (EU) 2023/2854, November 2025Not opened for this piece. It is a proposal, not law, and the body says only that. Law-firm summaries found while checking describe it as leaving the Chapter II access rules intact; those are lead-tier and are relied on for nothing. An editor must check before publication that nothing adopted since has amended Article 3 or Article 50.
- National competent authority designations and penalty rules under Articles 37 and 40Not checked. The body says enforcement sits with national authorities and penalty regimes set by Member States, which is what the regulation says. It does not name the Belgian authority or any penalty level, because this desk has not established either.