From when does this apply?
The regulation entered into force on 11 January 2024 and has applied since 12 September 2025. For connected products placed on the market from 12 September 2026, a design requirement also applies: the product must be built so that data is accessible to the user by default and easily. The provisions on switching charges for cloud services follow their own timeline, under which those charges are gradually phased out.
What exactly counts as "data generated by the product"?
Raw data and what directly follows from it: measurements, states, events, usage data. What falls outside this is information that is the result of substantial investment in processing and analysis. That line is not sharply drawn and there will be discussion about it in the coming years. For your design, the main implication is to keep the two separate, so that you can expose one layer without taking your system apart.
May we charge for access?
For the user requesting their own product data, access must not be unnecessarily hindered, and there are limits on what you may charge. When making data available to a third party at the user's request, different rules apply, including the possibility of reasonable compensation, with a lighter regime for small enterprises. This is very much a question for your lawyer; we ensure that your system can support both.
What happens to our trade secrets?
They remain protected. The regulation expressly provides for measures you can attach to sharing data that contains trade secrets, and in exceptional cases allows you to refuse sharing. What does not work is labelling everything a trade secret to escape the obligation. In practice, separating raw and derived data largely resolves this: your analysis is where your secret lies, not in the measured value.
Do we have to offer this in real time?
Where the product generates data continuously or almost continuously and this is technically possible, direct availability is the obvious choice. For many applications, periodic delivery is sufficient. What matters most is that access is simple, secure and in a common format, without anyone from your side needing to be in between. We design the integration so you can adjust the rhythm later without rebuilding.
How long do we need to keep data available?
That cannot be captured in a single period. It depends on the nature of the product, on what you have agreed contractually and on other retention obligations that apply to you. What we do is justify that choice and record it, rather than guess, and set up the retention policy so that it differs per type of data. That saves storage costs and makes it easier to explain.
We are a recipient, not a supplier. Is this of any use to us?
Certainly. As a recipient you gain rights: access to the data from the equipment you use, and the ability to have another party work with that data. That opens up maintenance contracts that were previously closed off and makes comparison possible. On your side, we help with retrieving that data, making it usable, and working out what you need to set out contractually to actually receive it.
How does this relate to the GDPR?
They sit alongside each other. If the product data relates to an identifiable person, the GDPR applies in full and you need a lawful basis for it; the Data Act does not widen that. In practice, most machine data is not personal, but with vehicles, wearables and devices in the home it is different. We flag this in the working session so that your lawyer knows where to look.
What does this mean for our architecture?
Three things. Data must sit somewhere it can be accessed without anyone needing to get into your system; that is an integration, not database access. There must be an access-control layer around it, because giving access to the user is different from giving access to everyone. And logging belongs with it, so that access is verifiable. These three are straightforward work if you include them in the design, and a rebuild if you have to add them later.
What belongs in an exit arrangement?
The format in which data is handed over, the timeframe, the terms, and how long you continue to deliver after termination so that the transition can be made. That last point is most often missing and gives the greatest peace of mind. Add to that that the customer may test the export format in advance – that is the difference between an arrangement that works and one that exists only on paper.
Will we lose our customers as a result?
That is the fear, and rarely the outcome. Customers leave mainly when they feel they cannot get away. In procurement processes, a demonstrably working exit arrangement is now an advantage, not a risk. What you do need to think about is which part of your service relied on exclusive access – that part becomes vulnerable, and that is a strategic question better put on the table now than later.