Appoint us
Connected products whose usage data falls under the EU Data Act

REP27 · Data Act · Connected products

Articles 3 to 5 · product data · related service data

Connected products: what the user can ask for.

The Data Act gives the user of a connected product the right to reach the data that product generates, and to have it sent to a third party of their choosing. It is a plain right with sharp edges: it covers readings, not the inferences you built from them; it protects trade secrets, but not as an excuse to refuse everything; and it starts before the sale, with information that most product pages in Europe still do not contain. This page separates what is inside from what is outside, in the regulation's own order.

Product dataRelated service dataArticle 3Article 4Article 5

Request this service   Ask a question

Inside the right, and outside it

Data a user can obtain from a connected product and data that falls outside the right
Data a user can obtain from a connected product and data that falls outside the right

The distinction that decides most cases is the first on the right: data you inferred or derived is yours. Readings the product produced are the user's to reach. A temperature series is product data; the predictive maintenance score you computed from it is not.

What has to be said before the sale

The information a seller must give before a connected product contract is concluded
The information a seller must give before a connected product contract is concluded
This is where most companies are behind. The duty bites on the product page, the datasheet and the manual, not on the back end, and it applies before the user buys or subscribes rather than on request afterwards.

The three rights, in sequence

  1. Access by design

    Article 3(1): connected products and related services are designed so that product data and related service data are accessible to the user by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and where relevant and technically feasible directly.

  2. Access on request

    Article 4: where data cannot be reached directly from the device, the data holder makes it available to the user without undue delay, of the same quality as available to the holder, easily and securely.

  3. Sharing with a third party

    Article 5: at the user's request, the data holder makes the data available to a third party the user names. This is the provision that opens repair, insurance and analytics markets, and the one competitors watch most closely.

  4. Limits that survive

    The third party cannot use the data to develop a competing product, and cannot be a designated gatekeeper under the Digital Markets Act.

Trade secrets, handled properly

The most common question from manufacturers, and the one where the regulation is more nuanced than either side would like.

PositionWhat the regulation actually says
"Everything is a trade secret"Secrets must be identified and justified. A blanket claim over all product data does not hold
"Secrets mean we can refuse"Disclosure can proceed with agreed technical and organisational safeguards, not simple refusal
"We can refuse if the user will not sign"Where no agreement on safeguards is reached, the holder may withhold, and must inform the competent authority
"Serious economic damage allows refusal"In exceptional cases, on a case-by-case basis and with reasons given, not as policy
"Nobody checks"Member States designate competent authorities, and refusals are notifiable

The workable position is the boring one: identify what is genuinely secret, prepare a standard safeguards agreement, and hand over the rest promptly. Companies that do this answer requests in days. Companies that argue spend months and end up disclosing anyway.

Terms, compensation and who pays

To the user, free

Access for the user themselves is free of charge. There is no reading fee for your own product's data.

To a third party, compensable

Where data is shared with a third party at the user's request, reasonable compensation may be agreed with that recipient, non-discriminatory and, for small recipients, limited to the costs of making it available.

Fair terms

Contractual terms unilaterally imposed and unfair are not binding. Chapter IV sets the test and gives examples.

No lock-out clauses

You cannot contract out of the user's rights, and a clause that tries to is simply unenforceable.

Format matters

Structured, commonly used, machine-readable. A PDF export is not compliance.

Timing matters

Without undue delay. In practice, a request that sits for weeks is the one that reaches an authority.

What to change first, in order

  1. The product page and the manual

    Add the pre-contractual information. It is the cheapest item on this list and the most visible to a regulator.

  2. The data inventory

    List what the product generates, at what frequency, where it is stored and for how long. You cannot describe what you have not catalogued.

  3. The access route

    A documented way for a user to obtain their data, and a route for transmission to a named third party.

  4. The safeguards template

    A short agreement covering trade secret protection, ready to send rather than drafted under pressure.

  5. The representative

    If you are not established in the Union, the mandate, so that requests land somewhere that answers.

A worked example

Abstract categories are hard to apply. Take an industrial pump with a cloud portal, sold from outside the Union to a factory in Germany, and run the whole thing through.

DataCategoryCan the user obtain it?
Pressure and flow readings, one per secondProduct dataYes, at that frequency, with units and timestamps
Vibration spectraProduct dataYes, including the metadata to interpret them
Runtime hours and cycle countsProduct dataYes
Fault codes raised by the deviceProduct dataYes
Portal login times of the factory's staffRelated service data, also personalYes under the Data Act; the GDPR governs the personal aspect
Remaining-life estimate from your modelDerivedNo, it is your inference
Your maintenance pricing algorithmTrade secret, not product dataNo
Aggregate benchmarks across your fleetDerived and third-party dataNo

Notice how much of the list is a plain yes. The readings the machine produced belong within reach of whoever runs the machine, and the parts you built on top stay yours. Once a team accepts that split, the engineering becomes ordinary work rather than a negotiation, and the argument moves to formats and frequency, which is where it should be.

What a good request process looks like

One entry point

An address that is published and monitored. If you are outside the Union, that is where the representative sits.

Identity check

Confirm the requester is the user of that product. A serial number and proof of ownership or lease is normally enough.

A standard export

Prepared once, not assembled per request. This is the difference between answering in a day and answering in a month.

A safeguards template

For anything genuinely secret, ready to send rather than drafted under pressure.

A log

Date received, date answered, what was provided. It is what you produce if a complaint reaches an authority.

An escalation route

Someone who can decide when a request is unusual, so it does not sit while everyone waits for a policy.

The short version

Readings the product generated are within the user's reach; inferences you built on top of them are not. Access for the user is free and has to arrive in a structured, machine-readable format with the metadata needed to interpret it, at the same quality you hold internally. The user can also direct the data to a third party, who cannot use it to build a competing product. Trade secrets are protected through safeguards rather than refusal, and refusal itself is possible only on narrow grounds, with reasons and notification. And all of it starts before the sale, with information about what the product generates and how to obtain it, which is the item most European product pages still lack.

Formats, frequency and the arguments they cause

Once a company accepts the principle, the disagreements move to three technical questions. They are worth settling in advance, because each of them has a defensible answer in the regulation.

QuestionDefensible positionPosition that fails
What resolution?The same quality available to you, so the internal sampling rateA downsampled feed built for the mobile app
What format?JSON, CSV or a documented API with a published schemaPDF reports, screenshots or a dashboard-only view
How fast?Without undue delay, and continuously or in real time where the product works that wayA quarterly export batch
How much metadata?Units, timestamps, identifiers and schema, enough to interpret without your helpBare numbers with no context
How is it authenticated?Standard credentials or tokens, documentedA support ticket and a manual export by an engineer

The pattern across all five rows is the same: whatever your own analytics consumes is the benchmark. If your internal systems read the stream at one sample per second with full metadata over an API, an export at one sample per hour in a spreadsheet is not the same quality, and that is the phrase the regulation actually uses.

Answering a request without a project

Requests arrive by email, in the language of the user, and rarely quote an article number. A short internal procedure turns them into routine work.

  1. Log it the day it arrives

    Date, requester, product, what is being asked and whether a third-party recipient is named. This is what the representative does automatically when the request reaches it.

  2. Identify the user

    The person or company that owns, rents or leases the product. Verification should be proportionate: an order number and account ownership, not a passport.

  3. Pull the readings

    From the same source your own analytics uses, at the same quality, with the metadata to interpret them.

  4. Check for secrets and personal data

    Identify anything genuinely secret and propose safeguards; where the export contains personal data of others, filter or handle it under the GDPR.

  5. Deliver in a machine-readable format

    JSON or CSV with a schema, through a link or an API. Attaching a spreadsheet is acceptable; a screenshot is not.

  6. Record what you sent

    Fields, period, format, date. Two years later that record is the answer to a complaint.

Companies that write this procedure once answer in days and never hear from an authority. Companies that treat each request as a novel legal problem take weeks and eventually disclose the same data anyway, having spent far more on the argument than on the export.

The short version

Readings belong to the user's access right; your derivations do not. Access for the user is free, in a machine-readable format, at the quality you hold. Trade secrets are protected through safeguards rather than refusal. The disclosure duty starts before the sale, on the product page and in the manual. And if you are outside the Union, the requests need somewhere to land, which is what the representative mandate is for.

Assessing which product data a user can obtain under the Data Act
Assessing which product data a user can obtain under the Data Act
Signing the mandate that names a Data Act representative in the Union

Questions we are actually asked

What is product data?

Data generated by the use of a connected product that the manufacturer designed to be retrievable by the user, data holder or a third party, including the metadata needed to interpret it.

What is related service data?

Data representing the digitisation of user actions or events related to the connected product, generated during the provision of a related service.

Can users get data we derived from readings?

No. Inferred or derived data resulting from your own investment stays outside the access right.

Is access free for the user?

Yes. Access by the user to data from their own product is free of charge. Compensation can arise only when data goes to a third party.

What format must we use?

Structured, commonly used and machine-readable, of the same quality as the data available to you. A PDF or a screenshot does not satisfy it.

Can we refuse on trade secret grounds?

Not as a blanket answer. Identify the secrets, propose safeguards, and refuse only in the defined exceptional cases, with reasons and notification to the authority.

Who can the user send data to?

Any third party they name, except a designated gatekeeper under the Digital Markets Act, and subject to the recipient not using it to build a competing product.

Does this apply to business customers?

Yes. Users include businesses as well as consumers; the terms differ, the right does not.

What has to be told before the sale?

Type and volume of data, how it is generated, whether continuously and in real time, how it is stored, and how the user can access, retrieve or delete it.

Are prototypes covered?

No. Data from products not yet placed on the market is outside the regulation.

Does the GDPR still apply?

Yes, in full, to any personal data involved. The Data Act does not create a legal basis for processing personal data by itself.

What if the product is sold through a distributor?

The duties follow the roles, not the sales channel. The manufacturer and data holder remain who they are.

Do we need a representative for this?

If no entity of yours is established in the Union, yes. It is a separate mandate from the Article 27 GDPR designation.

How quickly must we answer a request?

Without undue delay. There is no fixed number, and in practice speed is what keeps a request from becoming a complaint.

Can we charge the user for exports?

No. Charges may be agreed only with third-party recipients, on the terms the regulation allows.

What about safety and security limits?

Access can be restricted where necessary for safety or security reasons, but the restriction has to be justified, not assumed.

Are micro and small enterprises exempt?

The sharing obligations largely do not apply to them, with a transitional position for enterprises that have recently grown.

What does the representative cost?

€490 a year, less when combined with the other mandates you hold with us.

Related: the representative mandate · what to build

Someone in the Union to receive the requests

Europe Services, SE in Prague as your Data Act representative, signed within 24 hours, with requests logged and forwarded the same working day.

Request this service