This update is written by:

Thomas Kriense
Update

ACM publishes guidance on the Data Act: what do you need to do if you sell ‘smart’ products?

You have a product that not only works, but also measures. And not only measures, but also communicates: for example, with an app, with the cloud, via a platform. That is exactly the sort of product many entrepreneurs are making money from today — and which the EU Data Act (Data Regulation) focuses on. The ACM has now published (provisional) guidance on this, intended to explain to companies offering a connected product or related service what they need to do.

At its core, the Data Act is a data-sharing framework. It sets out who has access to what data, under what conditions and for what purpose. And this affects not only the party that ‘generates’ data in an IoT (Internet of Things) device. Depending on the chapter, data controllers, data recipients (third parties) and, in some cases, public authorities may have obligations. Users, in particular, are granted rights: access and the right to have data forwarded.

What are ‘smart’ products under the Data Act?

The ACM explicitly mentions them in the guidance: these are devices that generate or collect data and are capable of exchanging that data (so-called connected products, also known as ‘smart devices’).

And please note: it’s not just about the hardware. The Data Act also covers related services: digital services linked to the connected product that can influence the product’s functionality, behaviour or operation — for example, an app used to control a smart thermostat.

A rule of thumb for business owners: if your product generates data and is connected, you’re often within the scope. And if your app or cloud service can control its operation, you’ll quickly find yourself within the scope with a related service as well.

Who is responsible for what? (user, data controller, data recipient)

Under the Data Act, roles are more important than labels such as ‘manufacturer’ or ‘platform’.

The user

The user (who may also be a legal entity) is informed of the basic principle: they have control over the data collected through the use of the connected product. The user may request access to this data and may also request that it be transferred to a third party.

The data controller

The data controller is the party which (usually on the basis of a contract) has the right or the obligation to use or make data available. This is often the manufacturer or provider of the relevant service, but this is not always the case: the role may be transferred by contract, and there may be more than one data controller.

The data recipient (third party)

A third party receiving data must adhere to clear restrictions on its use. For example, the ACM states that the third party must not pass the data on to ‘gatekeepers’ (DMA), must not use it in a way that has a negative impact on security, and must comply with the agreed measures regarding trade secrets.

What exactly do you need to comply with when bringing smart products to market?

Preliminary contract: provide information before the customer signs

The Data Act imposes a transparency obligation: before concluding a contract (for the sale, hire or lease of the product, or the provision of the related service), the user must be provided with information regarding access to and use of data. In the case of connected products, this obligation rests with the seller, hirer or lessor.

This includes, amongst other things: the type of data the product generates, its format and estimated volume (including continuous/real-time data), where the product stores the data and for how long, and how the user can view, retrieve or delete the data. The aim is for this information to be clear and understandable, and to be provided again should it change.

Disclosure to third parties: “Send my data to Party X”

The user may request the data controller to grant access to a third party; this option is always available, regardless of whether the user themselves has direct or indirect access. For such third-party access, the data controller must agree on the terms (and, where applicable, a fee) with the third party.

What do you need to sort out now?

If you offer connected products or related services, you can approach this as if you were incorporating a new “right” into your product and contract chain:

1) Determine: is this a connected product or related service? (check for bidirectional app/cloud integration).
2) Assign roles: who is the data controller (and are there several)?
3) Finalise your pre-contractual information: type of data, format/volume, storage/retention period, access method.
4) Set up access: direct where appropriate (particularly looking ahead to 2026), otherwise ‘immediately upon request’ with proportionate verification.
5) Make third-party sharing workable: terms and conditions/FRAND terms and operational workflow.
6) Prepare safeguards: trade secrets/security substantiated and with a reporting procedure.

Read more updates
The LEGO Group takes action not only against counterfeit building bricks, but also against the (commercial) use of its word mark ‘LEGO’ outside the toy market. A recent substantive case before The Hague District Court centred on the fact that Boon Beton was offering concrete stacking blocks online using terms such as ‘Lego’, ‘concrete Lego bricks’ and ‘concrete Lego blocks’. The crux of the matter: LEGO is challenging, on the basis of its word mark, the way in which Boon Beton presents its products and makes them discoverable, in particular through the excessive and SEO-driven use of “LEGO/LEGO blocks” in web content.
A striking red ‘ball’ on a package may be a powerful point of recognition for marketers, but in trade mark law this is by no means a given: the question is whether the average consumer actually perceives such a simple visual element as an indication of origin and not merely as packaging decoration. A recent ruling by the Benelux Court of Justice concerning a shiny red circle/sphere on dishwasher tablets illustrates just how strict that test can be and why market context and sector conventions carry significant weight in this regard. In this blog, I use that ruling to discuss when a sign is intrinsically distinctive, when it is not, and how an initially ‘decorative’ element can nevertheless obtain trade mark protection through acquired distinctiveness.
Five foamy beer glasses, arranged in a pattern on a bar. At first glance, an innocent reference to carnival or conviviality. The International Olympic Committee (IOC) thought otherwise and ordered Bavaria to immediately discontinue the advertising campaign. Why? Because this arrangement is so reminiscent of the iconic logo of the Olympic Games, the five coloured interlocking rings, that (in all likelihood) this constitutes trademark infringement according to the IOC.