DATA ACT: Access by Design Becomes Mandatory as of 12 September – What Companies Need to Know Now
Update Data Protection No. 262
Data is regarded as the raw material of the digital economy, yet who was actually permitted to use it was previously determined above all by the data holder’s de facto control. This is where the Data Act comes in as a central pillar of the European data strategy, making the data holdings of connected products consolidated by the data holder accessible to users and third parties. Although the Regulation has largely been applicable since 12 September 2025, another cut-off date will take effect on 12 September 2026. From that date, the obligation to design products in a manner conducive to data access under Art. 3 Abs. 1 DA (the so-called Access by Design obligation) will apply to connected products and related services newly placed on the market. In practice, this again raises the question of which companies fall within the scope of the Regulation at all and in which capacity they are affected. This article first categorizes the group of companies concerned and then examines the obligations already in place and those newly introduced.
I. Who is affected?
The Data Act addresses a broad range of actors. Art. 1 Abs. 3 DA names, among others, manufacturers of connected products, providers of related services, users of such products or services, data holders and data recipients, as well as providers of data processing services. Whether and in what capacity a company is affected is not determined in the abstract, but by the specific link to a connected product.
1. The “connected product" as the central point of reference
The personal and material scope of the Data Act stands or falls with the concept of a connected product. Under Art. 2 Nr. 5 DA, this means a tangible object that obtains, generates or collects data concerning its use or environment and can transmit that product data via an electronic communications service, a physical connection or an on-device access point, provided that its main function does not consist in storing, processing or transmitting data on behalf of a third party. As a starting point, this therefore covers virtually any tangible object across all sectors of the economy, from vehicles and medical equipment to household appliances and consumer goods, and extending to agricultural and industrial machinery and equipment. The mobility of the object is irrelevant, meaning that infrastructure and installations may also qualify.
The definition is, however, less clear-cut than it may initially appear. It does not refer to data in general, but to product data, which in turn are defined in Art. 2 Nr. 15 DA by reference to the connected product that is itself to be defined. This circular relationship has a practically significant consequence: a connected product would presumably exist only if the manufacturer has envisaged access to the generated data as part of the product’s design. If the manufacturer designs its product so that data can be stored only locally and cannot be transmitted, no product data exist and the obligations under Art. 3 and 4 DA do not apply in that respect. Whether a product falls within the scope is therefore, to a considerable extent, a matter of how the manufacturer designs the product—an area of freedom that may come into tension with the Access by Design obligation taking effect on 12 September 2026.
2. Manufacturers as the addressees of the obligation under Art. 3 Abs. 1 DA
For the Access by Design obligation added as of 12 September 2026, the group of parties directly subject to the obligation is narrower. Art. 3 Abs. 1 DA is directed at the person who designs and manufactures the connected product or designs and provides the related service, but not at every person who merely distributes such a product. The relevant criterion is placing on the market after the cut-off date, which is why the obligation is limited to new products and does not require products already placed on the market to be retrofitted. It should also be noted that, through Art. 1 Abs. 4 DA, the group of addressees may extend to providers of virtual assistants insofar as those assistants interact with a connected product or related service, which is likely to include, in particular, providers of voice and user interfaces. Finally, it must be borne in mind that the same company may simultaneously assume several roles, for example as manufacturer and data holder, so that the respective obligations overlap.
II. Obligations of the manufacturers concerned
Since 12 September 2025, the user’s right of access under Art. 4 DA has been in force. Accordingly, the data holder must make the readily available product data and related service data accessible to the user and, upon request, also to a third party designated by the user (Art. 5 DA). This right covers the entire existing inventory, including products already placed on the market, insofar as the data holder already has the relevant data. It is supplemented by the pre-contractual information obligations under Art. 3 Abs. 2 and 3 DA, under which the provider must inform the prospective user, before the contract is concluded, about the nature, scope, format and methods for retrieving the generated data.
On 12 September 2026, the Access by Design obligation under Art. 3 Abs. 1 DA will be added. It requires connected products and related services to be designed from the outset so that the product data and related service data are accessible to the user by default, easily, securely, free of charge and in a structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly from the device. The difference from the right of access already in force lies in the point of departure: while Art. 4 DA concerns data that already exist, Art. 3 Abs. 1 DA shifts the requirement to the product-development stage. Unlike the right of access, which concerns existing data holdings, this obligation applies only to products newly placed on the market after the cut-off date and does not require existing products to be retrofitted.
There are also requirements governing the handling of the data made available. Access must in principle be granted free of charge; charges imposed on third parties are subject to the requirement that they be reasonable and non-discriminatory. The protection of trade secrets remains intact, but justifies a refusal of access only exceptionally and under strict conditions, meaning that the relevant data holdings must be classified in advance and subject to appropriate protective measures. In addition, Art. 13 DA places limits, in business-to-business relationships, on abusive contractual terms concerning data access and data use.
III. Recommendations for action
- Separate the product portfolio by the cut-off date: Manufacturers should categorize the upcoming product generations according to which models will be placed on the market for the first time after 12 September 2026, because only these are subject to the Access by Design obligation under Art. 3 Abs. 1 DA. For example, a manufacturer that places a machine series on the market in August 2026 can still supply it without direct access, whereas the successor model launched in October must meet the requirements. For products with long development lead times, such as vehicles or medical devices, the access channel should therefore already be built into ongoing development, because retrofitting later is technically more complex than taking it into account from the outset.
- Make deliberate use of the design discretion: Since a product falls within the scope only if the manufacturer envisages transmission of the generated data at all, it is worthwhile, before any new development, to determine which sensor and usage data should be retrievable in the future. A household-appliance manufacturer that processes operating data exclusively locally in the device and does not provide an external interface does not, in that respect, trigger obligations under Art. 3 and 4 DA. If, however, it makes the same data accessible through an app or cloud portal, this creates product data along with the corresponding follow-on obligations. This decision should be coordinated from both business and legal perspectives and documented.
- Coordinate pre-contractual information with trade-secret protection: The information obligations under Art. 3 Abs. 2 and 3 DA can in practice be fulfilled only if it has first been determined what data the product generates and which of them require protection. An industrial-machinery provider should classify the generated data holdings in advance, for example distinguishing between operating data to be made freely available, on the one hand, and design or process data requiring confidentiality, on the other, and should establish specific protective measures for the latter, such as tiered access rights or confidentiality agreements. This is the only way to grant access without disclosing competitively relevant know-how, because a blanket refusal based on trade secrets is permissible only exceptionally.
- Adapt contracts to reflect the parties’ roles: Because a company may simultaneously be a manufacturer, data holder and user, existing supply, rental, leasing and service agreements should be reviewed to determine who receives access to which data in each configuration. A lessor that has previously reserved the exclusive right to analyse vehicle or machine data must take into account that the user now has its own right of access under Art. 4 DA and may require that the data be disclosed to third parties. Clauses that unilaterally restrict data access must also be assessed against the limits imposed by Art. 13 DA on abusive contractual provisions and adjusted where necessary.
IV. Conclusion and outlook
As of 12 September 2026, the Data Act’s obligations will include the Access by Design obligation under Art. 3 Abs. 1 DA, which, unlike the right of access already in force, applies only to connected products and related services newly placed on the market. Whether and in what capacity a company is affected continues to depend on the interpretation of the connected product, which, despite initial commentary in the legal literature, remains unclear at the margins. In practice, companies are therefore advised to organize their own product portfolio early on by reference to the cut-off date, make deliberate use of the design discretion, and adapt existing agreements to the new access rights.
The detailed impact of the requirements under Art. 3 Abs. 1 DA will become clear only through the administrative practice of the Bundesnetzagentur (Federal Network Agency), which has monitored compliance as the competent authority since the end of May 2026. Companies should closely monitor further developments, in particular any interpretative guidance from the authority and the first enforcement proceedings, and continually align their implementation measures accordingly.
This article was created in collaboration with our student employee Emily Bernklau.