The EU Data Act is now one year old. Since 12 September 2025, the Regulation generally applies across the EU. 12 September 2026 marks another important milestone: Article 3(1)'s “access-by-design” requirement now applies to connected products and related services placed on the EU market after that date. Art. 3(1) shows that Data Act compliance is a product-design issue, not merely a legal or contractual exercise.
What US companies should do now
For manufacturers and providers of connected products that fall under the Data Act, the September 12 milestone should trigger a product-level review:
-
Which product and related-service data are generated?
-
Which of those data are “readily available”?
-
Can users access them directly, where technically feasible?
-
Are the necessary interfaces, formats and metadata built into the architecture?
-
Do the product documentation and pre-contractual disclosures match the actual data generated?
-
Where is the data stored and processed, and could international access restrictions under Article 32 become relevant?
-
Who is responsible internally for responding to Data Act access requests?
Data access must be built in
Article 3(1) Data Act requires connected products and related services to be designed and manufactured so that product data and related-service data, together with relevant metadata, are by default, easily and securely accessible, free of charge, comprehensive, structured and in a commonly used format machine-readable; and where relevant and technically feasible, directly accessible to the user.
The provision covers a broad range of products, from vehicles and industrial machinery to household appliances, wearables and smart infrastructure. Whether data are actually “readily available” can depend on how a product and its related services have been designed. The wording may give manufacturers a legal argument in some cases to resist opening up their products. They could argue that data need not be made accessible where obtaining or extracting it would require disproportionate effort beyond a simple operation. The Recitals of the Data Act also expressly say that the Data Act does not require manufacturers to store data that their product design does not otherwise store or transmit. The scope of this limitation will be an important point of contention between manufacturers seeking to protect their product architecture and users seeking broader data access. Yet many product designers in Europe still appear to treat the Data Act as a legal compliance topic rather than as an engineering requirement.
Lessons from the first year of the Data Act
The first year of the Data Act has shown that formal legal access rights do not automatically translate into effective data access. Too little data is currently flowing from manufacturers to data users. The reasons are, among other things, missing use cases, established structures, lack of standards, insufficient trust as practical obstacles.
The Data Act is not confined to European companies. Its market-location approach can bring manufacturers of connected products and providers of related services within its scope even if they are established outside the EU, provided their products or services are offered on the EU market. Article 32 Data Act requires providers of data-processing services to take adequate technical, organizational and legal measures to prevent certain third-country governmental access to or transfers of non-personal data held in the EU where this would conflict with EU or Member State law. This creates an additional compliance layer for globally operated cloud and data-processing infrastructures.
Germany: BNetzA now has the enforcement role
Germany has meanwhile put the enforcement machinery in place. The Data Act Implementation and Enforcement Act (DADG) entered into force on 30 May 2026 and designates the Bundesnetzagentur (BNetzA) as the central German authority for the Data Act. BNetzA is now the responsible authority and central point of contact for Data Act questions and compliance as well as its enforcement body. This matters because the Data Act is no longer simply a new EU regulation for which companies can wait and see what happens.
The Data Act’s penalty regime comes in tiers and is significant. Violations of Article 3(1)'s product-design obligation and certain data-provision obligations can trigger fines of up to €500,000. Other infringements can attract fines of up to €100,000 or €50,000. The highest tier reaches €5 million or, for companies with worldwide annual turnover above €250 million, 2% of worldwide annual turnover for certain defined violations. Where Data Act obligations concern personal data, the Data Act also preserves the role of data protection authorities (DPA) under the GDPR and their sanctions.
The conclusion after one year of the Data Act is that the required data access cannot be fixed at the end of the product-development process. The compliance discussion needs to start with the engineers and product designers.

