You have a product that not only works, but also measures. And not only measures, but also communicates: for example, with an app, with the cloud, via a platform. That is exactly the sort of product many entrepreneurs are making money from today — and which the EU Data Act (Data Regulation) focuses on. The ACM has now published (provisional) guidance on this, intended to explain to companies offering a connected product or related service what they need to do.
At its core, the Data Act is a data-sharing framework. It sets out who has access to what data, under what conditions and for what purpose. And this affects not only the party that ‘generates’ data in an IoT (Internet of Things) device. Depending on the chapter, data controllers, data recipients (third parties) and, in some cases, public authorities may have obligations. Users, in particular, are granted rights: access and the right to have data forwarded.
What are ‘smart’ products under the Data Act?
The ACM explicitly mentions them in the guidance: these are devices that generate or collect data and are capable of exchanging that data (so-called connected products, also known as ‘smart devices’).
And please note: it’s not just about the hardware. The Data Act also covers related services: digital services linked to the connected product that can influence the product’s functionality, behaviour or operation — for example, an app used to control a smart thermostat.
A rule of thumb for business owners: if your product generates data and is connected, you’re often within the scope. And if your app or cloud service can control its operation, you’ll quickly find yourself within the scope with a related service as well.
Who is responsible for what? (user, data controller, data recipient)
Under the Data Act, roles are more important than labels such as ‘manufacturer’ or ‘platform’.
The user
The user (who may also be a legal entity) is informed of the basic principle: they have control over the data collected through the use of the connected product. The user may request access to this data and may also request that it be transferred to a third party.
The data controller
The data controller is the party which (usually on the basis of a contract) has the right or the obligation to use or make data available. This is often the manufacturer or provider of the relevant service, but this is not always the case: the role may be transferred by contract, and there may be more than one data controller.
The data recipient (third party)
A third party receiving data must adhere to clear restrictions on its use. For example, the ACM states that the third party must not pass the data on to ‘gatekeepers’ (DMA), must not use it in a way that has a negative impact on security, and must comply with the agreed measures regarding trade secrets.
What exactly do you need to comply with when bringing smart products to market?
Preliminary contract: provide information before the customer signs
The Data Act imposes a transparency obligation: before concluding a contract (for the sale, hire or lease of the product, or the provision of the related service), the user must be provided with information regarding access to and use of data. In the case of connected products, this obligation rests with the seller, hirer or lessor.
This includes, amongst other things: the type of data the product generates, its format and estimated volume (including continuous/real-time data), where the product stores the data and for how long, and how the user can view, retrieve or delete the data. The aim is for this information to be clear and understandable, and to be provided again should it change.
Disclosure to third parties: “Send my data to Party X”
The user may request the data controller to grant access to a third party; this option is always available, regardless of whether the user themselves has direct or indirect access. For such third-party access, the data controller must agree on the terms (and, where applicable, a fee) with the third party.
What do you need to sort out now?
If you offer connected products or related services, you can approach this as if you were incorporating a new “right” into your product and contract chain:
1) Determine: is this a connected product or related service? (check for bidirectional app/cloud integration).
2) Assign roles: who is the data controller (and are there several)?
3) Finalise your pre-contractual information: type of data, format/volume, storage/retention period, access method.
4) Set up access: direct where appropriate (particularly looking ahead to 2026), otherwise ‘immediately upon request’ with proportionate verification.
5) Make third-party sharing workable: terms and conditions/FRAND terms and operational workflow.
6) Prepare safeguards: trade secrets/security substantiated and with a reporting procedure.