The EU Data Act creates a new category of rights — the right to access data generated by connected product use. These rights exist alongside GDPR rights but are broader in scope: they cover non-personal data as well as personal data, and they apply not just to individuals but to business users of connected products.
Who Has Access Rights Under the Data Act
The Data Act grants data access rights to:
Users of connected products: Any person or business who uses a connected product — a smart appliance, industrial sensor, vehicle, wearable device — has a right to access the data their use generates.
Persons who have been authorised by the user: Users can grant access rights to third parties on their behalf.
Access rights apply regardless of whether the user is a consumer or a business. An SME operating connected industrial equipment has the same right to access equipment data as a consumer using a smart home device.
What Data Is Covered
The Data Act focuses on data generated by the use of a connected product or related service. This includes:
- Performance data generated by the product's operation (speed, temperature, pressure readings, operational cycles)
- Usage data reflecting how the product is used (time of use, frequency, settings, mode)
- Environmental data collected by the product's sensors (location, ambient conditions, interaction data)
- Error and maintenance data (fault codes, maintenance triggers, diagnostic readings)
What is not covered:
- Data the user independently creates and inputs into the product (documents, messages, media files)
- Derived data where the manufacturer has substantially processed or enriched the raw data (trade secret protection may apply)
- Proprietary algorithms, models, or software embedded in the product
Core Data Access Rights
Right to Access By Default
Data access must be "by default" — users should not need to submit a special request for each access event. The product or related service must provide a mechanism for continuous or on-demand access to usage data.
This means:
- An interface in the device or accompanying app through which users can view their data
- An API or structured download mechanism for accessing historical data
- No requirement to contact customer support to obtain data that is generated routinely
Right to Receive Data in a Machine-Readable Format
Data must be provided in a commonly used, machine-readable format. The Data Act does not mandate a single format, but the intent is clear: the format must be usable by the recipient — by a third-party service, an analytics tool, or a switching provider.
Formats that qualify: JSON, CSV, XML, industry-standard data schemas. Formats that do not qualify: proprietary binary formats, PDFs of device logs, screenshots.
Right to Share Data with Third Parties
Users can instruct the data holder to transmit their data directly to a third party they designate. The third party must be a legitimate recipient — a business or service provider the user has chosen.
Once data is shared:
- The third party can use the data only for the agreed purpose
- The third party cannot sell the data or use it beyond the specified purpose
- The third party cannot process the data to harm the data holder's competitive position
Data Holder Obligations
A data holder — typically the IoT manufacturer or related service provider — must comply with access requests:
Without undue delay: Access must be provided promptly. The Data Act does not specify an exact timeframe, but the standard mirrors GDPR's approach — within a reasonable period and certainly within days, not weeks.
Free of charge to the user: Data holders cannot charge users for exercising their access rights. They may charge third parties (business recipients) a reasonable fee reflecting the marginal cost of making the data available.
Without discrimination: A user who exercises access rights must not be penalised. The data holder cannot degrade service, restrict features, or otherwise discriminate against a user who accesses or shares their data.
Maintaining technical security: When transmitting data to a third party, the data holder must ensure secure transmission and verify that the third party is legitimate.
Limits on Data Access Rights
Trade secrets: Data holders can refuse or limit access where providing access would disclose trade secrets — but only where a genuine trade secret claim exists. The data holder must be able to substantiate the claim. Blanket trade secret assertions are not a valid basis for refusing all access.
Personal data of others: If the product generates data that contains personal data about a person other than the user (e.g., a smart doorbell that records visitors), access rights must be balanced against those individuals' GDPR rights.
Technical impossibility: In cases where the data is technically impossible to separate (e.g., aggregated dataset where individual user data cannot be extracted without disproportionate effort), data holders may invoke technical impossibility — but the burden of proof is on the data holder.
Relationship to GDPR
Data access rights under the Data Act and GDPR subject access rights (Article 15) operate in parallel:
| GDPR Article 15 | Data Act | |
|---|---|---|
| Covers | Personal data | Personal and non-personal data generated by connected product use |
| Who benefits | Data subjects (natural persons) | Users (individuals and businesses) |
| Who must respond | Data controllers | Data holders |
| Response timeframe | 1 month | Without undue delay |
| Format requirement | Commonly used electronic format | Commonly used, machine-readable format |
If personal data is involved, both frameworks apply. A response to a Data Act access request involving personal data must also satisfy GDPR requirements.