Data Act: design obligation on 12 September 2026
News · Upcoming deadline
Article 3(1) of Regulation (EU) 2023/2854, the Data Act, applies to connected products and related services placed on the market after 12 September 2026, now less than a month away. From that date a connected product must have been designed and manufactured so that the data it produces is accessible to the user by default. The access right that opened on 12 September 2025 governed how the data holder behaves; this second deadline governs the architecture of the product itself, and it closes on product lines whose hardware freeze is already behind them.
In short:
- The Article 3(1) design obligation covers connected products and related services placed on the market after 12 September 2026.
- The timetable has not moved: at the date of this update, EUR-Lex records no act amending Regulation (EU) 2023/2854.
- Only Article 3(1) is deferred. The information duties in Article 3(2) and 3(3) have applied since 12 September 2025.
- The text requires access by default; direct access from the product is required only "where relevant and technically feasible".
- It is not a CE marking instrument, but it constrains product architecture just as firmly.
The 12 September 2026 design deadline
Section titled “The 12 September 2026 design deadline”This is the part that lands directly on development teams, and it is often discovered late.
Article 50 of the regulation states that the obligation resulting from Article 3(1) applies to connected products, and their related services, placed on the market after 12 September 2026. The trigger is placing on the market, not the design date and not the order date: a product whose first unit crosses onto the Union market on 13 September 2026 is caught, even if its architecture was frozen two years earlier.
Article 50 sets out four distinct dates, and they have to be read separately:
| Provision | Date | Scope |
|---|---|---|
| Entry into force | 11 January 2024 | Twentieth day following publication in the Official Journal of 22 December 2023 |
| General application | 12 September 2025 | The regulation as a whole, including the access and sharing rights in Articles 4 and 5 |
| Article 3(1) | 12 September 2026 | Connected products and related services placed on the market after that date |
| Chapter IV | 12 September 2027 | Contracts concluded on or before 12 September 2025 that are of indefinite duration or due to expire at least ten years from 11 January 2024 |
Article 3(1) requires connected products to be designed and manufactured, and related services to be designed and provided, in such a manner that product data and related service data, including the metadata needed to interpret them, are by default easily, securely and free of charge accessible to the user, in a comprehensive, structured, commonly used and machine-readable format.
One point of drafting matters here, because it is routinely misquoted: the regulation adds that the data is directly accessible to the user "where relevant and technically feasible". It does not therefore mandate a local interface on every device. But where direct access is not feasible, Article 4(1) takes over and obliges the data holder to make the readily available data accessible without undue delay, on a simple request by electronic means. In other words, an architecture cannot simply close both routes.
Three concrete design consequences:
| Topic | What it implies |
|---|---|
| Interface | Provide a data access path that does not depend exclusively on the manufacturer's cloud |
| Format | Move away from opaque proprietary formats towards documented, machine-readable structures |
| Security | Access must be secure, which meets the mechanisms already required by RED 3.3 and coming under the CRA |
A product whose architecture assumes only the manufacturer's app can read the measurements does not satisfy this requirement, and fixing it after hardware freeze is expensive.
On the question of a postponement, the answer is no. The Digital Omnibus Regulation proposal, COM(2025) 837 of 19 November 2025, would amend Regulation (EU) 2023/2854, but its text touches neither Article 3(1) nor the application dates in Article 50. No amending act to the regulation is recorded on EUR-Lex as things stand.
What the regulation opened in September 2025
Section titled “What the regulation opened in September 2025”The Data Act corrects an imbalance: until then, data generated by using a connected object stayed in practice under the exclusive control of the manufacturer or the operator of the related service. Since 12 September 2025, the user, business or consumer, can:
- access the data the product and related service generate through their use, including the metadata needed to interpret it;
- require its transmission to a third party of their choosing, for example an independent repairer or a competing maintenance provider.
Two information duties also apply from that date, and they are independent of the 2026 deadline. Before a contract of purchase, rent or lease is concluded, the seller must state the type, format and estimated volume of the data the product can generate, whether generation is continuous and in real time, whether storage is on-device or on a remote server and for how long, and by what technical means the user can access, retrieve or erase the data. The provider of a related service owes equivalent information.
The perimeter is deliberately broad. The definition of a connected product covers any item that obtains, generates or collects data concerning its use or environment and is able to communicate it. It excludes items whose primary function is storing, processing or transmitting data on behalf of a party other than the user: a server is not a connected product for the purposes of the regulation, whereas a home sensor, a vehicle, an industrial machine or a wind turbine is.
How it sits alongside the other instruments
Section titled “How it sits alongside the other instruments”The Data Act replaces neither the RED nor the Cyber Resilience Act, and adds no CE marking requirement. It operates on a different register: data governance rather than security or radio compliance. But all three converge on architecture:
- RED 3.3 requires personal data to be protected.
- The CRA will require vulnerability handling and signed updates across the support period.
- The Data Act requires usage data to be extractable by the user, securely.
Treating these three separately leads to three successive redesigns. Treating them together when the architecture is defined requires only one.
What to do
Section titled “What to do”- Map the data the product and related service generate, separating raw data, derived data and interpretation metadata.
- Check the placing-on-the-market date of product lines in development: those first placed on the market after 12 September 2026 fall under the design obligation, variants of an existing product that amount to a new model included.
- Plan a documented, secure access path, direct from the device where relevant and technically feasible, and a fallback route compliant with Article 4(1) where it is not.
- Review the contracts for the related service and the terms of use, which must reflect the access and sharing rights as well as the pre-contractual information required since 2025.
Further reading
Section titled “Further reading”- CE scope: which directives apply to which product
- Cyber Resilience Act: timeline and obligations
- EN 303 645, IoT cybersecurity: the reference technical baseline
Sources & references
- Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data , Publications Office of the European Union / EUR-Lex eur-lex.europa.eu/eli/reg/2023/2854/oj
- Data Act, overview and timeline , European Commission digital-strategy.ec.europa.eu/en/policies/data-act
- Digital Omnibus Regulation proposal, COM(2025) 837 of 19 November 2025 , European Commission digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal