
REP27 · Data Act · Connected products
Articles 3 to 5 · product data · related service data
The Data Act gives the user of a connected product the right to reach the data that product generates, and to have it sent to a third party of their choosing. It is a plain right with sharp edges: it covers readings, not the inferences you built from them; it protects trade secrets, but not as an excuse to refuse everything; and it starts before the sale, with information that most product pages in Europe still do not contain. This page separates what is inside from what is outside, in the regulation's own order.
Product dataRelated service dataArticle 3Article 4Article 5

The distinction that decides most cases is the first on the right: data you inferred or derived is yours. Readings the product produced are the user's to reach. A temperature series is product data; the predictive maintenance score you computed from it is not.

Article 3(1): connected products and related services are designed so that product data and related service data are accessible to the user by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and where relevant and technically feasible directly.
Article 4: where data cannot be reached directly from the device, the data holder makes it available to the user without undue delay, of the same quality as available to the holder, easily and securely.
Article 5: at the user's request, the data holder makes the data available to a third party the user names. This is the provision that opens repair, insurance and analytics markets, and the one competitors watch most closely.
The third party cannot use the data to develop a competing product, and cannot be a designated gatekeeper under the Digital Markets Act.
The most common question from manufacturers, and the one where the regulation is more nuanced than either side would like.
| Position | What the regulation actually says |
|---|---|
| "Everything is a trade secret" | Secrets must be identified and justified. A blanket claim over all product data does not hold |
| "Secrets mean we can refuse" | Disclosure can proceed with agreed technical and organisational safeguards, not simple refusal |
| "We can refuse if the user will not sign" | Where no agreement on safeguards is reached, the holder may withhold, and must inform the competent authority |
| "Serious economic damage allows refusal" | In exceptional cases, on a case-by-case basis and with reasons given, not as policy |
| "Nobody checks" | Member States designate competent authorities, and refusals are notifiable |
The workable position is the boring one: identify what is genuinely secret, prepare a standard safeguards agreement, and hand over the rest promptly. Companies that do this answer requests in days. Companies that argue spend months and end up disclosing anyway.
Access for the user themselves is free of charge. There is no reading fee for your own product's data.
Where data is shared with a third party at the user's request, reasonable compensation may be agreed with that recipient, non-discriminatory and, for small recipients, limited to the costs of making it available.
Contractual terms unilaterally imposed and unfair are not binding. Chapter IV sets the test and gives examples.
You cannot contract out of the user's rights, and a clause that tries to is simply unenforceable.
Structured, commonly used, machine-readable. A PDF export is not compliance.
Without undue delay. In practice, a request that sits for weeks is the one that reaches an authority.
Add the pre-contractual information. It is the cheapest item on this list and the most visible to a regulator.
List what the product generates, at what frequency, where it is stored and for how long. You cannot describe what you have not catalogued.
A documented way for a user to obtain their data, and a route for transmission to a named third party.
A short agreement covering trade secret protection, ready to send rather than drafted under pressure.
If you are not established in the Union, the mandate, so that requests land somewhere that answers.
Abstract categories are hard to apply. Take an industrial pump with a cloud portal, sold from outside the Union to a factory in Germany, and run the whole thing through.
| Data | Category | Can the user obtain it? |
|---|---|---|
| Pressure and flow readings, one per second | Product data | Yes, at that frequency, with units and timestamps |
| Vibration spectra | Product data | Yes, including the metadata to interpret them |
| Runtime hours and cycle counts | Product data | Yes |
| Fault codes raised by the device | Product data | Yes |
| Portal login times of the factory's staff | Related service data, also personal | Yes under the Data Act; the GDPR governs the personal aspect |
| Remaining-life estimate from your model | Derived | No, it is your inference |
| Your maintenance pricing algorithm | Trade secret, not product data | No |
| Aggregate benchmarks across your fleet | Derived and third-party data | No |
Notice how much of the list is a plain yes. The readings the machine produced belong within reach of whoever runs the machine, and the parts you built on top stay yours. Once a team accepts that split, the engineering becomes ordinary work rather than a negotiation, and the argument moves to formats and frequency, which is where it should be.
An address that is published and monitored. If you are outside the Union, that is where the representative sits.
Confirm the requester is the user of that product. A serial number and proof of ownership or lease is normally enough.
Prepared once, not assembled per request. This is the difference between answering in a day and answering in a month.
For anything genuinely secret, ready to send rather than drafted under pressure.
Date received, date answered, what was provided. It is what you produce if a complaint reaches an authority.
Someone who can decide when a request is unusual, so it does not sit while everyone waits for a policy.
Readings the product generated are within the user's reach; inferences you built on top of them are not. Access for the user is free and has to arrive in a structured, machine-readable format with the metadata needed to interpret it, at the same quality you hold internally. The user can also direct the data to a third party, who cannot use it to build a competing product. Trade secrets are protected through safeguards rather than refusal, and refusal itself is possible only on narrow grounds, with reasons and notification. And all of it starts before the sale, with information about what the product generates and how to obtain it, which is the item most European product pages still lack.
Once a company accepts the principle, the disagreements move to three technical questions. They are worth settling in advance, because each of them has a defensible answer in the regulation.
| Question | Defensible position | Position that fails |
|---|---|---|
| What resolution? | The same quality available to you, so the internal sampling rate | A downsampled feed built for the mobile app |
| What format? | JSON, CSV or a documented API with a published schema | PDF reports, screenshots or a dashboard-only view |
| How fast? | Without undue delay, and continuously or in real time where the product works that way | A quarterly export batch |
| How much metadata? | Units, timestamps, identifiers and schema, enough to interpret without your help | Bare numbers with no context |
| How is it authenticated? | Standard credentials or tokens, documented | A support ticket and a manual export by an engineer |
The pattern across all five rows is the same: whatever your own analytics consumes is the benchmark. If your internal systems read the stream at one sample per second with full metadata over an API, an export at one sample per hour in a spreadsheet is not the same quality, and that is the phrase the regulation actually uses.
Requests arrive by email, in the language of the user, and rarely quote an article number. A short internal procedure turns them into routine work.
Date, requester, product, what is being asked and whether a third-party recipient is named. This is what the representative does automatically when the request reaches it.
The person or company that owns, rents or leases the product. Verification should be proportionate: an order number and account ownership, not a passport.
From the same source your own analytics uses, at the same quality, with the metadata to interpret them.
Identify anything genuinely secret and propose safeguards; where the export contains personal data of others, filter or handle it under the GDPR.
JSON or CSV with a schema, through a link or an API. Attaching a spreadsheet is acceptable; a screenshot is not.
Fields, period, format, date. Two years later that record is the answer to a complaint.
Companies that write this procedure once answer in days and never hear from an authority. Companies that treat each request as a novel legal problem take weeks and eventually disclose the same data anyway, having spent far more on the argument than on the export.
Readings belong to the user's access right; your derivations do not. Access for the user is free, in a machine-readable format, at the quality you hold. Trade secrets are protected through safeguards rather than refusal. The disclosure duty starts before the sale, on the product page and in the manual. And if you are outside the Union, the requests need somewhere to land, which is what the representative mandate is for.


Data generated by the use of a connected product that the manufacturer designed to be retrievable by the user, data holder or a third party, including the metadata needed to interpret it.
Data representing the digitisation of user actions or events related to the connected product, generated during the provision of a related service.
No. Inferred or derived data resulting from your own investment stays outside the access right.
Yes. Access by the user to data from their own product is free of charge. Compensation can arise only when data goes to a third party.
Structured, commonly used and machine-readable, of the same quality as the data available to you. A PDF or a screenshot does not satisfy it.
Not as a blanket answer. Identify the secrets, propose safeguards, and refuse only in the defined exceptional cases, with reasons and notification to the authority.
Any third party they name, except a designated gatekeeper under the Digital Markets Act, and subject to the recipient not using it to build a competing product.
Yes. Users include businesses as well as consumers; the terms differ, the right does not.
Type and volume of data, how it is generated, whether continuously and in real time, how it is stored, and how the user can access, retrieve or delete it.
No. Data from products not yet placed on the market is outside the regulation.
Yes, in full, to any personal data involved. The Data Act does not create a legal basis for processing personal data by itself.
The duties follow the roles, not the sales channel. The manufacturer and data holder remain who they are.
If no entity of yours is established in the Union, yes. It is a separate mandate from the Article 27 GDPR designation.
Without undue delay. There is no fixed number, and in practice speed is what keeps a request from becoming a complaint.
No. Charges may be agreed only with third-party recipients, on the terms the regulation allows.
Access can be restricted where necessary for safety or security reasons, but the restriction has to be justified, not assumed.
The sharing obligations largely do not apply to them, with a transitional position for enterprises that have recently grown.
€490 a year, less when combined with the other mandates you hold with us.
Related: the representative mandate · what to build
Europe Services, SE in Prague as your Data Act representative, signed within 24 hours, with requests logged and forwarded the same working day.
Request this service