EU / Connected Products & IoT
The EU Data Act's "data by design and by default" obligation for connected products takes full effect on 12 September 2026. Any newly-placed connected device must be built so users can access the data it generates directly, free of charge, in a structured machine-readable format — a real engineering requirement, not a policy statement.
Last updated 1 September 2026
Under Articles 3-6 of the Data Act, a connected product placed on the EU market from 12 September 2026 must be designed and manufactured so that the data it generates is, by default, easily and securely accessible to the user — directly from the device where feasible, free of charge, in a comprehensive, structured, commonly used, machine-readable format, and continuously/in real time where technically feasible. This is a step beyond the baseline access-and-portability right that already applied from September 2025: it's a design obligation that has to be built into the product itself, not a data-request process bolted on afterward.
Source: thingshost.de, "EU Data Act & IoT 2026: Connected Product Obligations by 12 September".
The definition is broad by design: any item that obtains, generates or collects data about its use or environment and can communicate that data via an electronic communications service, physical connection or on-device access. That covers consumer IoT — smart appliances, wearables, connected toys, home sensors — as well as industrial equipment, connected vehicles and machinery. If a device already logs sensor or usage data and has any path to transmit it, treat it as in scope by default rather than arguing an exemption after the fact.
Enforcement isn't theoretical. Germany has already designated its Federal Network Agency (Bundesnetzagentur) as the national competent authority for the Data Act, and other member states are following the same pattern of naming a regulator ahead of the deadline. Penalties are set nationally but the Data Act anticipates fines on a GDPR-comparable scale — up to 4% of global annual turnover for the most serious infringements — which puts data-access design failures in the same financial-risk category as a data-protection breach, not a minor labeling gap.
Source: ComplianceHub.Wiki, "EU Data Act Enforcement Accelerates... September 2026 Deadline Looms".
The design obligation applies to connected products placed on the market from 12 September 2026 onward; it isn't retroactive for devices already sold. In practice that means the trigger isn't the calendar date on its own — it's your next hardware revision, new SKU, or product launch after that date. Anything already in your 2026 product roadmap that ships after mid-September needs data-access-by-design considered at the hardware and firmware spec stage, not left until certification.
Source: KPMG Law LLP, "EU Data Act – Upcoming deadlines (2026 - 2027)".
From 12 September 2026, connected products and related services newly placed on the EU market must be designed and manufactured so that the data they generate is, by default, easily, securely and directly accessible to the user — free of charge, in a comprehensive, structured, commonly used and machine-readable format, and where relevant and technically feasible, continuously and in real time. This is the Data Act's Article 3 "data by design and by default" obligation, the second-phase deadline after the baseline access-and-portability rights that took effect 12 September 2025.
A connected product is any item that obtains, generates or collects data about its use or environment and is able to communicate that data via an electronic communications service, physical connection or on-device access — a broad definition covering consumer IoT (smart appliances, wearables, connected toys), industrial equipment, connected vehicles and machinery. If a device already collects sensor or usage data and can transmit it, it is very likely in scope; products that are purely mechanical with no data-generation capability are not.
The design obligation applies to connected products and related services placed on the market from 12 September 2026 onward. Products already on the market before that date are not retroactively required to be redesigned, but any new model, revision, or product newly placed on the market after the deadline must meet the by-design access requirement — so a manufacturer's next hardware revision is the practical trigger point, not a calendar-only one.
Each EU member state designates its own competent authority; Germany has already named its Federal Network Agency (Bundesnetzagentur) as its enforcement body. Penalties are set at the member-state level but the Data Act itself anticipates fines comparable in scale to GDPR — up to 4% of a company's global annual turnover for the most serious infringements, alongside data-protection-authority powers where personal data is involved.
They are separate but overlapping obligations that will increasingly land on the same connected-device engineering team. The Data Act governs who can access the operational data a device generates and on what terms; the Digital Product Passport (under ESPR) governs product lifecycle and sustainability data disclosure; RED Article 3.3(d)-(f) and the Cyber Resilience Act govern the device's cybersecurity posture. A connected product shipped into the EU from 2026 onward increasingly needs all three addressed together, not as separate late-stage compliance tasks.
Data-access-by-design is an engineering spec problem before it's a certification problem — it has to be decided at the hardware/firmware architecture stage, alongside the RED, CRA and Digital Product Passport obligations already landing on the same connected-device programmes. We fold Data Act readiness into the same market-access engagement as those other connected-product requirements, so it gets scoped once rather than discovered late.
Book a scoping call