Skip to content
EU Data Act

IoT and the EU Data Act: What Manufacturers Must Do

5 min readUpdated 14 October 2026

IoT manufacturers are the primary target of the EU Data Act's data access obligations. If you manufacture connected products — devices that collect and transmit data about their use or environment — the Data Act creates concrete product design requirements, data sharing obligations, and contractual requirements that must be in place by 12 September 2025.


What Counts as a Connected Product Under the Data Act

The Data Act defines a connected product as a physical item that obtains, generates, or collects data concerning its use or environment and that is able to communicate that data via an electronic communications service, physical connection, or on-device access.

In practice this covers:

Consumer IoT:

  • Smart home devices (thermostats, appliances, lighting, security cameras)
  • Wearables (fitness trackers, smartwatches, health monitors)
  • Connected vehicles
  • Smart meters

Industrial IoT:

  • Manufacturing equipment with embedded sensors
  • Agricultural machinery
  • Medical devices with connected monitoring
  • Energy management systems
  • Building automation and HVAC systems

Commercial IoT:

  • Fleet telematics
  • Point-of-sale systems with data collection
  • Smart retail equipment
  • Connected office equipment

Core Obligations for IoT Manufacturers

1. Design for Data Access

Connected products must be designed to make the data they generate accessible by default. This is a product design requirement — not just a contractual or policy obligation.

What this means in practice:

  • Data generated by the product's use must be accessible through the product interface or an accompanying app
  • The access mechanism must be easy to use — not buried in settings or requiring technical expertise
  • The product must support structured data export in a machine-readable format

For manufacturers already in production: products placed on the EU market from September 2025 onwards must meet this requirement. Products already in circulation have a transition arrangement, but new product launches must comply.

2. Enable Third-Party Data Sharing

Users must be able to instruct you to share their product data with a third party of their choice. This requires:

A sharing mechanism: Either an API through which authorised third parties can retrieve user data, or a structured data export capability that the user can direct to a recipient.

Identity verification: You must be able to verify that a data request is genuine — that it is the authorised user (or their delegate) instructing the share, not an unauthorised third party.

Purpose limitation enforcement: You must implement or verify purpose limitations. The third party cannot use the data beyond the agreed purpose. Your terms with third parties should reflect this.

3. Pre-Purchase Transparency

Before a connected product is purchased, the manufacturer must provide clear information about:

  • What data the product collects
  • How the data is stored (on-device, manufacturer cloud, third-party cloud)
  • Whether data access is by default or requires activation
  • The data formats in which access is provided

This information must be provided in a concise, clear form — before the sale, not buried in the manual.

4. Contractual Restrictions on Users Are Void

The Data Act renders void any contractual term that purports to prevent users from accessing or sharing their product data. If your terms of service or product licence currently includes provisions that:

  • Prohibit users from sharing device data with third parties
  • Restrict access to data to specific use cases only
  • Require users to waive their Data Act rights as a condition of product use

...those provisions are unenforceable as of September 2025.


B2B Data Sharing: Separate Framework

The Data Act also governs B2B data sharing — where a business (the data holder, typically the manufacturer) makes data available to another business under a commercial arrangement.

Fair dealing requirements: B2B data sharing agreements must reflect fair, reasonable, and non-discriminatory terms. Manufacturers cannot impose grossly unfair contractual terms on businesses that need access to their device data.

Trade secret protection: Manufacturers can protect genuine trade secrets. If providing access to raw sensor data would disclose a proprietary manufacturing algorithm, trade secret protection applies. But manufacturers must be specific — general assertions that "all product data is trade secret" are not valid.

Data recipient obligations: Businesses receiving data under B2B arrangements cannot:

  • Use the data to develop competing products
  • Share the data with further parties without authorisation
  • Use the data beyond the agreed purpose

SME Exemption

Microenterprises and small enterprises — fewer than 50 employees and under €10M turnover — are exempt from the IoT data access and B2B sharing obligations. The exemption applies to the data access provisions but not to cloud switching provisions.

If your manufacturing business is growing towards these thresholds, plan for Data Act compliance as part of your growth roadmap.


Overlap with Other Regulations

GDPR: If your IoT product processes personal data (location data, health metrics, identity-linked usage data), GDPR governs that processing. Data Act access rights operate alongside GDPR — providing access to personal data must also satisfy GDPR's data subject rights framework.

Product safety regulations: Connected products in specific verticals face additional requirements. Medical devices (MDR/IVDR), vehicles (type-approval), and industrial machinery have their own regulatory frameworks that overlap with Data Act data governance requirements.

AI Act: If your IoT product incorporates an AI system (predictive maintenance, automated decision-making, computer vision), the AI Act may apply alongside the Data Act. An industrial robot with predictive AI and sensor data collection faces both frameworks simultaneously.


Action Plan for IoT Manufacturers

Immediate (before September 2025):

  • Audit all connected products against the Data Act scope test
  • Confirm or build a data access interface for each product
  • Review and update product terms — remove clauses that restrict user data rights
  • Map all data flows: what is collected, where it goes, who holds it
  • Prepare pre-purchase disclosure language for product listings

Medium-term:

  • Build an API or structured export for third-party data sharing
  • Implement identity verification for data sharing requests
  • Review B2B data sharing arrangements for fair dealing compliance
  • Train customer-facing teams on handling Data Act requests

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →