Skip to content
EU Data Act

Data Access Rights Under the EU Data Act

5 min readUpdated 14 October 2026

The EU Data Act creates a new category of rights — the right to access data generated by connected product use. These rights exist alongside GDPR rights but are broader in scope: they cover non-personal data as well as personal data, and they apply not just to individuals but to business users of connected products.


Who Has Access Rights Under the Data Act

The Data Act grants data access rights to:

Users of connected products: Any person or business who uses a connected product — a smart appliance, industrial sensor, vehicle, wearable device — has a right to access the data their use generates.

Persons who have been authorised by the user: Users can grant access rights to third parties on their behalf.

Access rights apply regardless of whether the user is a consumer or a business. An SME operating connected industrial equipment has the same right to access equipment data as a consumer using a smart home device.


What Data Is Covered

The Data Act focuses on data generated by the use of a connected product or related service. This includes:

  • Performance data generated by the product's operation (speed, temperature, pressure readings, operational cycles)
  • Usage data reflecting how the product is used (time of use, frequency, settings, mode)
  • Environmental data collected by the product's sensors (location, ambient conditions, interaction data)
  • Error and maintenance data (fault codes, maintenance triggers, diagnostic readings)

What is not covered:

  • Data the user independently creates and inputs into the product (documents, messages, media files)
  • Derived data where the manufacturer has substantially processed or enriched the raw data (trade secret protection may apply)
  • Proprietary algorithms, models, or software embedded in the product

Core Data Access Rights

Right to Access By Default

Data access must be "by default" — users should not need to submit a special request for each access event. The product or related service must provide a mechanism for continuous or on-demand access to usage data.

This means:

  • An interface in the device or accompanying app through which users can view their data
  • An API or structured download mechanism for accessing historical data
  • No requirement to contact customer support to obtain data that is generated routinely

Right to Receive Data in a Machine-Readable Format

Data must be provided in a commonly used, machine-readable format. The Data Act does not mandate a single format, but the intent is clear: the format must be usable by the recipient — by a third-party service, an analytics tool, or a switching provider.

Formats that qualify: JSON, CSV, XML, industry-standard data schemas. Formats that do not qualify: proprietary binary formats, PDFs of device logs, screenshots.

Right to Share Data with Third Parties

Users can instruct the data holder to transmit their data directly to a third party they designate. The third party must be a legitimate recipient — a business or service provider the user has chosen.

Once data is shared:

  • The third party can use the data only for the agreed purpose
  • The third party cannot sell the data or use it beyond the specified purpose
  • The third party cannot process the data to harm the data holder's competitive position

Data Holder Obligations

A data holder — typically the IoT manufacturer or related service provider — must comply with access requests:

Without undue delay: Access must be provided promptly. The Data Act does not specify an exact timeframe, but the standard mirrors GDPR's approach — within a reasonable period and certainly within days, not weeks.

Free of charge to the user: Data holders cannot charge users for exercising their access rights. They may charge third parties (business recipients) a reasonable fee reflecting the marginal cost of making the data available.

Without discrimination: A user who exercises access rights must not be penalised. The data holder cannot degrade service, restrict features, or otherwise discriminate against a user who accesses or shares their data.

Maintaining technical security: When transmitting data to a third party, the data holder must ensure secure transmission and verify that the third party is legitimate.


Limits on Data Access Rights

Trade secrets: Data holders can refuse or limit access where providing access would disclose trade secrets — but only where a genuine trade secret claim exists. The data holder must be able to substantiate the claim. Blanket trade secret assertions are not a valid basis for refusing all access.

Personal data of others: If the product generates data that contains personal data about a person other than the user (e.g., a smart doorbell that records visitors), access rights must be balanced against those individuals' GDPR rights.

Technical impossibility: In cases where the data is technically impossible to separate (e.g., aggregated dataset where individual user data cannot be extracted without disproportionate effort), data holders may invoke technical impossibility — but the burden of proof is on the data holder.


Relationship to GDPR

Data access rights under the Data Act and GDPR subject access rights (Article 15) operate in parallel:

GDPR Article 15Data Act
CoversPersonal dataPersonal and non-personal data generated by connected product use
Who benefitsData subjects (natural persons)Users (individuals and businesses)
Who must respondData controllersData holders
Response timeframe1 monthWithout undue delay
Format requirementCommonly used electronic formatCommonly used, machine-readable format

If personal data is involved, both frameworks apply. A response to a Data Act access request involving personal data must also satisfy GDPR requirements.

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →