EU / Connected Products & IoT

From 12 September 2026, your connected product has to hand its own data over — by design.

The EU Data Act's "data by design and by default" obligation for connected products takes full effect on 12 September 2026. Any newly-placed connected device must be built so users can access the data it generates directly, free of charge, in a structured machine-readable format — a real engineering requirement, not a policy statement.

Last updated 1 September 2026

12 Sep 2025baseline access & portability rights took effect
12 Sep 2026data-by-design-and-default deadline, connected products
4% turnovermaximum fine anticipated for serious infringements

What "data by design and by default" actually means

Under Articles 3-6 of the Data Act, a connected product placed on the EU market from 12 September 2026 must be designed and manufactured so that the data it generates is, by default, easily and securely accessible to the user — directly from the device where feasible, free of charge, in a comprehensive, structured, commonly used, machine-readable format, and continuously/in real time where technically feasible. This is a step beyond the baseline access-and-portability right that already applied from September 2025: it's a design obligation that has to be built into the product itself, not a data-request process bolted on afterward.

Source: thingshost.de, "EU Data Act & IoT 2026: Connected Product Obligations by 12 September".

Who counts as a "connected product"

The definition is broad by design: any item that obtains, generates or collects data about its use or environment and can communicate that data via an electronic communications service, physical connection or on-device access. That covers consumer IoT — smart appliances, wearables, connected toys, home sensors — as well as industrial equipment, connected vehicles and machinery. If a device already logs sensor or usage data and has any path to transmit it, treat it as in scope by default rather than arguing an exemption after the fact.

Enforcement is already standing up

Enforcement isn't theoretical. Germany has already designated its Federal Network Agency (Bundesnetzagentur) as the national competent authority for the Data Act, and other member states are following the same pattern of naming a regulator ahead of the deadline. Penalties are set nationally but the Data Act anticipates fines on a GDPR-comparable scale — up to 4% of global annual turnover for the most serious infringements — which puts data-access design failures in the same financial-risk category as a data-protection breach, not a minor labeling gap.

Source: ComplianceHub.Wiki, "EU Data Act Enforcement Accelerates... September 2026 Deadline Looms".

New product, or next revision — that's the practical trigger

The design obligation applies to connected products placed on the market from 12 September 2026 onward; it isn't retroactive for devices already sold. In practice that means the trigger isn't the calendar date on its own — it's your next hardware revision, new SKU, or product launch after that date. Anything already in your 2026 product roadmap that ships after mid-September needs data-access-by-design considered at the hardware and firmware spec stage, not left until certification.

Source: KPMG Law LLP, "EU Data Act – Upcoming deadlines (2026 - 2027)".

Questions

What does the EU Data Act's 12 September 2026 deadline actually require?

From 12 September 2026, connected products and related services newly placed on the EU market must be designed and manufactured so that the data they generate is, by default, easily, securely and directly accessible to the user — free of charge, in a comprehensive, structured, commonly used and machine-readable format, and where relevant and technically feasible, continuously and in real time. This is the Data Act's Article 3 "data by design and by default" obligation, the second-phase deadline after the baseline access-and-portability rights that took effect 12 September 2025.

Which products count as "connected products" under the Data Act?

A connected product is any item that obtains, generates or collects data about its use or environment and is able to communicate that data via an electronic communications service, physical connection or on-device access — a broad definition covering consumer IoT (smart appliances, wearables, connected toys), industrial equipment, connected vehicles and machinery. If a device already collects sensor or usage data and can transmit it, it is very likely in scope; products that are purely mechanical with no data-generation capability are not.

Does this apply to products already on the market, or only new ones?

The design obligation applies to connected products and related services placed on the market from 12 September 2026 onward. Products already on the market before that date are not retroactively required to be redesigned, but any new model, revision, or product newly placed on the market after the deadline must meet the by-design access requirement — so a manufacturer's next hardware revision is the practical trigger point, not a calendar-only one.

Who enforces the Data Act and what are the penalties?

Each EU member state designates its own competent authority; Germany has already named its Federal Network Agency (Bundesnetzagentur) as its enforcement body. Penalties are set at the member-state level but the Data Act itself anticipates fines comparable in scale to GDPR — up to 4% of a company's global annual turnover for the most serious infringements, alongside data-protection-authority powers where personal data is involved.

How does the Data Act relate to the Digital Product Passport and RED cybersecurity rules?

They are separate but overlapping obligations that will increasingly land on the same connected-device engineering team. The Data Act governs who can access the operational data a device generates and on what terms; the Digital Product Passport (under ESPR) governs product lifecycle and sustainability data disclosure; RED Article 3.3(d)-(f) and the Cyber Resilience Act govern the device's cybersecurity posture. A connected product shipped into the EU from 2026 onward increasingly needs all three addressed together, not as separate late-stage compliance tasks.

Where we fit

Data-access-by-design is an engineering spec problem before it's a certification problem — it has to be decided at the hardware/firmware architecture stage, alongside the RED, CRA and Digital Product Passport obligations already landing on the same connected-device programmes. We fold Data Act readiness into the same market-access engagement as those other connected-product requirements, so it gets scoped once rather than discovered late.

Book a scoping call