EU's 'access by design' rule takes effect, forcing connected products to build in data access

A new obligation under the EU Data Act took effect Saturday: any connected product or related service placed on the European market from September 12, 2026 onward must be designed with data access built in from the start, rather than made available only when a user requests it. The requirement, often called "access by design," applies to everything from cars and smart TVs to industrial machinery and medical devices sold in the EU.
What changed today
The Data Act (Regulation (EU) 2023/2854) first became applicable a year ago, on September 12, 2025, requiring manufacturers and service providers to give users access to product data and related service data — but only on request. Today's deadline closes that gap for new products: manufacturers must now build direct, secure, and free data-access capability into the product itself, by default, wherever that is relevant and technically feasible. In practice, that means a connected car, smart appliance, or piece of factory equipment sold in the EU from today can no longer treat data access as an optional add-on handled through a support ticket — it has to be part of the product's basic architecture.
Why the EU wrote it this way
The underlying goal of the Data Act is to prevent manufacturers from using data access as a lock-in mechanism — for example, requiring a car owner to use only the manufacturer's own repair network because independent mechanics can't see the vehicle's diagnostic data, or forcing a farm to buy the same brand's analytics software because no other company can read the tractor's sensor data. By mandating access-by-design rather than access-on-request, the regulation aims to make data portability the default state of the market rather than something that depends on how responsive a company's request process happens to be.
The compliance tension points
Legal advisories tracking the deadline have flagged two recurring friction points. First, GDPR coordination: many connected products generate data about people other than the primary user — a shared family car, a rented apparatus, a hospital device used on multiple patients — and manufacturers now have to reconcile built-in access design with existing personal-data protections for those other individuals. Second, trade secrets: companies are testing how far they can legitimately withhold specific data elements on trade-secret grounds without violating the spirit of an access-by-design requirement, an area regulators have not yet fully clarified through enforcement precedent.
Who this affects and what happens next
The obligation applies specifically to new connected products and related services placed on the market from today — existing products already in the field are governed by the request-based access rules that took effect last year, not this stricter design mandate. Sectors with long product-development cycles, including life sciences and industrial equipment manufacturers, have been the most vocal in flagging compliance timelines, since products already deep in development before the rule was finalized now need retrofitted data-access architecture before EU launch.
Non-compliance carries the same enforcement exposure as other Data Act provisions: national regulators can levy fines, and affected users or business customers can pursue civil claims. As with the Data Act's cloud-switching provisions that took effect last year, enforcement intensity over the coming months will likely depend more on early regulatory test cases than on the text of the rule itself.
Compiled from EU Digital Strategy documentation and legal industry analysis.
Originally reported by European Commission Digital Strategy. Read the original article for additional details.
View original source