Skip to content

Data Act: design obligation on 12 September 2026

News · Upcoming deadline

Article 3(1) of Regulation (EU) 2023/2854, the Data Act, applies to connected products and related services placed on the market after 12 September 2026, now less than a month away. From that date a connected product must have been designed and manufactured so that the data it produces is accessible to the user by default. The access right that opened on 12 September 2025 governed how the data holder behaves; this second deadline governs the architecture of the product itself, and it closes on product lines whose hardware freeze is already behind them.

In short:

  • The Article 3(1) design obligation covers connected products and related services placed on the market after 12 September 2026.
  • The timetable has not moved: at the date of this update, EUR-Lex records no act amending Regulation (EU) 2023/2854.
  • Only Article 3(1) is deferred. The information duties in Article 3(2) and 3(3) have applied since 12 September 2025.
  • The text requires access by default; direct access from the product is required only "where relevant and technically feasible".
  • It is not a CE marking instrument, but it constrains product architecture just as firmly.

This is the part that lands directly on development teams, and it is often discovered late.

Article 50 of the regulation states that the obligation resulting from Article 3(1) applies to connected products, and their related services, placed on the market after 12 September 2026. The trigger is placing on the market, not the design date and not the order date: a product whose first unit crosses onto the Union market on 13 September 2026 is caught, even if its architecture was frozen two years earlier.

Article 50 sets out four distinct dates, and they have to be read separately:

ProvisionDateScope
Entry into force11 January 2024Twentieth day following publication in the Official Journal of 22 December 2023
General application12 September 2025The regulation as a whole, including the access and sharing rights in Articles 4 and 5
Article 3(1)12 September 2026Connected products and related services placed on the market after that date
Chapter IV12 September 2027Contracts concluded on or before 12 September 2025 that are of indefinite duration or due to expire at least ten years from 11 January 2024

Article 3(1) requires connected products to be designed and manufactured, and related services to be designed and provided, in such a manner that product data and related service data, including the metadata needed to interpret them, are by default easily, securely and free of charge accessible to the user, in a comprehensive, structured, commonly used and machine-readable format.

One point of drafting matters here, because it is routinely misquoted: the regulation adds that the data is directly accessible to the user "where relevant and technically feasible". It does not therefore mandate a local interface on every device. But where direct access is not feasible, Article 4(1) takes over and obliges the data holder to make the readily available data accessible without undue delay, on a simple request by electronic means. In other words, an architecture cannot simply close both routes.

Three concrete design consequences:

TopicWhat it implies
InterfaceProvide a data access path that does not depend exclusively on the manufacturer's cloud
FormatMove away from opaque proprietary formats towards documented, machine-readable structures
SecurityAccess must be secure, which meets the mechanisms already required by RED 3.3 and coming under the CRA

A product whose architecture assumes only the manufacturer's app can read the measurements does not satisfy this requirement, and fixing it after hardware freeze is expensive.

On the question of a postponement, the answer is no. The Digital Omnibus Regulation proposal, COM(2025) 837 of 19 November 2025, would amend Regulation (EU) 2023/2854, but its text touches neither Article 3(1) nor the application dates in Article 50. No amending act to the regulation is recorded on EUR-Lex as things stand.

What the regulation opened in September 2025

Section titled “What the regulation opened in September 2025”

The Data Act corrects an imbalance: until then, data generated by using a connected object stayed in practice under the exclusive control of the manufacturer or the operator of the related service. Since 12 September 2025, the user, business or consumer, can:

  • access the data the product and related service generate through their use, including the metadata needed to interpret it;
  • require its transmission to a third party of their choosing, for example an independent repairer or a competing maintenance provider.

Two information duties also apply from that date, and they are independent of the 2026 deadline. Before a contract of purchase, rent or lease is concluded, the seller must state the type, format and estimated volume of the data the product can generate, whether generation is continuous and in real time, whether storage is on-device or on a remote server and for how long, and by what technical means the user can access, retrieve or erase the data. The provider of a related service owes equivalent information.

The perimeter is deliberately broad. The definition of a connected product covers any item that obtains, generates or collects data concerning its use or environment and is able to communicate it. It excludes items whose primary function is storing, processing or transmitting data on behalf of a party other than the user: a server is not a connected product for the purposes of the regulation, whereas a home sensor, a vehicle, an industrial machine or a wind turbine is.

How it sits alongside the other instruments

Section titled “How it sits alongside the other instruments”

The Data Act replaces neither the RED nor the Cyber Resilience Act, and adds no CE marking requirement. It operates on a different register: data governance rather than security or radio compliance. But all three converge on architecture:

  • RED 3.3 requires personal data to be protected.
  • The CRA will require vulnerability handling and signed updates across the support period.
  • The Data Act requires usage data to be extractable by the user, securely.

Treating these three separately leads to three successive redesigns. Treating them together when the architecture is defined requires only one.

  1. Map the data the product and related service generate, separating raw data, derived data and interpretation metadata.
  2. Check the placing-on-the-market date of product lines in development: those first placed on the market after 12 September 2026 fall under the design obligation, variants of an existing product that amount to a new model included.
  3. Plan a documented, secure access path, direct from the device where relevant and technically feasible, and a fallback route compliant with Article 4(1) where it is not.
  4. Review the contracts for the related service and the terms of use, which must reflect the access and sharing rights as well as the pre-contractual information required since 2025.

Sources & references

  1. Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data , Publications Office of the European Union / EUR-Lex eur-lex.europa.eu/eli/reg/2023/2854/oj
  2. Data Act, overview and timeline , European Commission digital-strategy.ec.europa.eu/en/policies/data-act
  3. Digital Omnibus Regulation proposal, COM(2025) 837 of 19 November 2025 , European Commission digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal