The short answer
From 12 September 2026, the EU Data Act requires new connected products and their related services placed on the EU market to be designed so users can access the data they generate directly, easily and securely. The right for users to get and share their data has existed since the Act became applicable on 12 September 2025; what arrives now is the harder obligation — Article 3(1) — that the access has to be engineered into the product itself.
If you build IoT devices, industrial machinery or the firmware and companion apps that connect them, treat this as a design deadline, not a legal footnote. A data-access pathway that has to exist by default cannot be retrofitted the week before launch.
What actually changes on 12 September
The Data Act (Regulation (EU) 2023/2854) entered into force on 11 January 2024 and became applicable on 12 September 2025. Most of its user-facing rights — the right to access data a product generates, and to have it shared with a third party of the user's choice — have been live since then. The 12 September 2026 milestone adds the part manufacturers cannot solve with a policy document: the obligation in Article 3(1) that products and related services be designed and manufactured so that the relevant data is, by default, accessible to the user easily, securely and, where appropriate, directly.
The distinction matters. A right of access that a company satisfies through a support ticket and a manual export is a workflow. A product that must be built so the user can reach its data is an engineering specification — one that touches firmware, APIs, data formats, authentication and documentation. For products with long hardware design cycles, a September 2026 application date means the decisions are being locked in now, on boards and in schematics that will ship next year.
Who is in scope — including US teams
A connected product, in the Act's language, is any physical item that obtains, generates or collects data about its use or environment and can communicate that data. That is deliberately broad: connected vehicles, agricultural and industrial machinery, medical devices, home appliances, wearables and the wider field of IoT sensors all qualify. The related services that make the product function — the mobile app, the cloud backend, the analytics layer — are pulled in alongside the hardware.
Crucially, the obligations attach to products and services placed on the EU market and to data made available to users in the EU, not to where the vendor is incorporated. A US or UK company selling smart devices or an industrial SaaS into Europe is as much a data holder under the Act as a Berlin manufacturer. That extraterritorial reach is why the deadline belongs on North American roadmaps too, and why it sits next to the GDPR and the EU AI Act as a third pillar of European digital compliance that non-EU teams cannot treat as someone else's problem.
The cloud-switching clock is also running
The Data Act is not only about devices. It also reshapes how data-processing services — cloud and edge providers — must let customers leave. Since 12 September 2025, in-scope providers have had to support switching and data portability, remove unreasonable obstacles, and cooperate technically so a customer can move workloads and export data. The commercial squeeze comes next: under Article 29, switching charges are being withdrawn gradually and are prohibited outright from 12 January 2027, after which providers may recover only the direct costs of an in-progress switch during any transition.
For anyone architecting a cloud and DevOps platform, the practical message is the same as the device rule: portability has to be designed in. Confirm that a customer's data and configuration can actually be exported in a usable, structured form, that switching does not depend on proprietary formats only your stack can read, and that the 30-day switching window the Act contemplates is technically achievable. Providers that treated stickiness as a business model will feel this more than the deadline dates alone suggest.
What it means for US & EU software teams
For product teams, the useful framing is that the Data Act turns data access into a functional requirement with an acceptance test. The question a reviewer — or a customer, or a regulator — will ask is simple: can the user get the data this product generates, in a form they can use, without depending on your goodwill? If the honest answer is "not without engineering", that is the gap to close before September.
There is a real tension to manage, not ignore. The Act protects trade secrets and lets data holders apply proportionate security measures, so opening data does not mean exposing proprietary models or handing competitors a blueprint. But those protections are meant to be scoped and justified, not used as a general excuse to keep everything closed. The teams that navigate this well will separate the user's raw generated data, which has to flow, from the derived intelligence and secrets that can be protected — and they will document that reasoning so it holds up if challenged. For regulated HealthTech and connected-device makers, that documentation is also what an enterprise buyer's due-diligence team will ask to see.
The strategic read is that portability is becoming the European default across both the device and the cloud layers. Teams that build exportable, interoperable systems now will meet not just this deadline but the direction of travel — while those betting on lock-in will keep paying a compliance tax as each new obligation lands.
What to do before the deadline
You do not need a sprawling programme. You need a short, honest inventory and a few concrete builds.
- Classify your products. List which of your devices and related services are connected products under the Act, and which are being placed on the EU market after 12 September 2026.
- Build the access interface. Provide a documented, secure way for users to obtain the data their product generates, in a common, machine-readable format — not a manual export behind a support desk.
- Prepare third-party sharing. Users can direct their data to a provider of their choice; make sure your sharing path exists and runs on fair, non-discriminatory terms.
- Scope trade secrets deliberately. Decide what is genuinely a protected secret versus raw user data that must flow, and record the justification rather than defaulting to "no".
- Pressure-test cloud portability. Confirm you can export a customer's data and configuration in a usable form and meet a 30-day switch, ahead of the January 2027 fee ban.
- Write it down. Keep a record of your classification, access design and security measures — the evidence a supervisor or enterprise customer will ask for.
None of this is legal advice, and the exact scope of the Act depends on your products and contracts. But the direction is unambiguous: from September, a connected product sold into Europe is expected to open its data to the person using it. The teams that engineered for that will treat 12 September as a normal release; the rest will treat it as a deadline.
Frequently asked questions
What changes on 12 September 2026 under the EU Data Act?
From 12 September 2026, the Data Act's Article 3(1) design obligations apply to connected products and related services placed on the EU market. New products must be designed and manufactured so that users can access the data they generate directly, easily, securely and, where relevant, continuously and in real time. The data-access pathway has to be built into the product, not bolted on afterwards.
Which products count as connected products?
A connected product is any physical item that obtains, generates or collects data about its use or environment and can transmit it. That covers smart vehicles, industrial and agricultural machinery, medical devices, home appliances, wearables and IoT sensors. The related digital services that make such a product work, such as its companion app or cloud backend, fall in scope too.
Does the EU Data Act apply to companies outside the EU?
Yes. The obligations attach to products and related services placed on the EU market and to data made available to users in the EU, regardless of where the manufacturer or data holder is established. A US or UK company selling connected hardware or SaaS into Europe is in scope, which is why the deadline matters well beyond EU-based teams.
When do the cloud-switching rules take effect?
Cloud and data-processing switching rights have applied since 12 September 2025, but switching charges are being phased out gradually and are prohibited outright from 12 January 2027. From that date providers may only recover the direct costs of the switch during a transition. Teams should design portability and data-export paths now rather than wait for the fee ban.
What should software teams do before the deadline?
Map which of your products and services are connected products under the Act, build a documented data-access interface that lets users pull their generated data in a common, machine-readable format, prepare a data-holder-to-third-party sharing path with fair terms, and confirm your cloud architecture supports export and switching. Treat trade-secret protection and security as design inputs, not reasons to withhold access.
Sources
European Commission — Data Act policy page and application timeline (primary source)
Latham & Watkins — EU Data Act: What Businesses Need to Know
Bird & Bird — The EU Data Act: Where Things Stand Now