The EU Data Act’s access-by-design duty reaches every connected product placed on the Union market on or after 12 September 2026, converting an abstract data-sharing principle into a hard engineering and legal requirement that manufacturers, importers and distributors must build into the product itself. Under Regulation (EU) 2023/2854, most of the Data Act has applied since 12 September 2025, but Article 50 defers the design obligation in Article 3(1) so that it bites specifically on products first placed on the market after the 2026 date.
For companies serving the Spanish and wider EU market, this is not a compliance formality that can be papered over with policies, it changes how hardware and firmware are conceived, how data flows are exposed, and how commercial contracts allocate risk across the supply chain. This guide sets out, in practitioner terms, who is in scope, what “placed on the market” means, what “directly accessible” requires in practice, how trade secrets interact, and the contractual and documentary steps Spanish counsel should take before the deadline.
Who this is for: legal counsel, compliance teams, product managers and importers in Spain preparing for the Data Act’s design obligations effective for products placed on the market after 12 September 2026. This article explains scope, the technical tests for “directly accessible”, trade secret interaction, contracting and a compliance checklist.
The Data Act, Regulation (EU) 2023/2854, is a horizontal regulation designed to unlock the value of data generated by connected products and related services, giving users (whether consumers or businesses) meaningful control over the data their devices produce. It sits alongside, rather than replacing, the GDPR and the trade secrets framework, and it applies directly across all Member States, including Spain, without the need for national transposition, though Member States must designate competent authorities and lay down penalties.
The regulation entered into force in January 2024 and its core obligations became applicable on 12 September 2025. However, the legislator recognised that the most demanding requirement, designing products so that data is accessible by default, cannot sensibly be retrofitted to goods already in production or on shelves. Article 50 therefore introduces a deferred timeline for the design obligation, and it is this phasing that gives 2026 its significance.
Article 50 provides that the access-by-design obligation in Article 3(1) applies to connected products, and the related services connected to them, placed on the market after 12 September 2026. In practical terms, there are two dates that matter: the general application date of 12 September 2025, from which the bulk of the Data Act’s data-sharing and contractual obligations apply, and 12 September 2026, from which the design duty in Article 3(1) attaches to newly placed products. The distinction is deliberate, existing obligations can be met contractually and operationally, but the design duty requires lead time to engineer.
Article 3(1) requires that connected products and related services be designed and manufactured, and the related services provided, in such a manner that product data and related service data, including the relevant metadata necessary to interpret and use that data, are, by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user. The phrasing is dense but each element is operative: “by default” removes any need for the user to request; “free of charge” bars access fees for the user obtaining data about their own use; “machine-readable format” excludes closed or proprietary-only outputs; and “directly accessible” reaches toward local, user-controlled retrieval.
The scope of the design duty is defined by the concepts of “connected product” and “related service”, together with the actors who place such products on the Union market. Understanding these definitions is the first analytical step for any Spanish manufacturer or importer.
A connected product, in the sense of the Data Act, is an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, a physical connection or on-device access, the classic examples being connected vehicles, smart home appliances, wearables, and industrial machinery fitted with sensors. A related service is a digital service, other than an electronic communications service, connected to the product at the time of purchase, rent or lease in such a way that its absence would prevent the product from performing one or more of its functions, or that is subsequently connected to it.
The obligation is imposed on the party that designs and manufactures the product and, functionally, on those who place it on the Union market. This means manufacturers based in Spain, elsewhere in the EU, or in third countries can all be caught, and importers and distributors may carry obligations where the manufacturer is outside the EU. The EU Data Act’s access-by-design duty reaches non-EU manufacturers through the market-placement trigger rather than through their place of establishment.
The clearest cases are physical devices that plainly generate usage or environmental data. Consider the following typical categories and their likely treatment:
Borderline cases, for example, a product with only intermittent connectivity, or firmware that logs data locally but never transmits it, require a careful reading of whether the item “obtains, generates or collects” data within the meaning of the regulation. Where doubt exists, the safer working assumption is that the EU Data Act’s access-by-design duty reaches the product and that a documented feasibility assessment is needed to justify any narrower position.
Because Article 50 keys the design duty to products placed on the market after 12 September 2026, the definition of “placed on the market” is decisive for determining which units must comply. This is one of the most practically important, and potentially litigable, questions counsel will face.
Drawing on established EU product-law concepts, “placed on the market” is generally understood as the first making available of a product on the Union market, in Spanish regulatory language, the primera comercialización en el mercado de la Unión. The concept turns on the first supply for distribution, consumption or use in the EU in the course of a commercial activity, whether against payment or free of charge. Practical markers that counsel can use to fix the moment include:
For imports from third countries, the release for free circulation typically marks the relevant point at which a unit is first made available, meaning non-EU manufacturers cannot escape the design duty simply by manufacturing abroad. The EU Data Act’s access-by-design duty reaches imported units at the point they enter the Union market for supply.
The design duty attaches per unit at the moment of first making available, not to a product line as a class. This produces important transitional consequences. A consumer device manufactured and warehoused in Spain in mid-2026, then first offered for sale to a consumer on 20 September 2026, is placed on the market after the deadline and must comply. The identical device first supplied to a distributor on 1 September 2026 was placed on the market before the deadline and is not subject to the Article 3(1) design duty, though other Data Act obligations still apply.
For industrial rigs assembled to order, the analysis may differ again: a bespoke machine handed over to an EU customer after the deadline will need to meet the design requirements, even if components were procured earlier. Counsel should therefore map inventory and expected supply dates unit by unit, or at least by clearly defined batches, and document the placement date to evidence the position taken.
The phrase “directly accessible to the user”, qualified by “where relevant and technically feasible”, is where legal analysis meets engineering reality. It is the element of the design duty most likely to generate disputes and the one most in need of a structured feasibility assessment.
Direct accessibility contemplates the user obtaining data without needing to route a request through the manufacturer’s discretionary gatekeeping. Depending on the product, this can be delivered through several modalities:
The data must be provided in a comprehensive, structured, commonly used and machine-readable format, together with the metadata needed to interpret it, and free of charge to the user. Proprietary formats that only the manufacturer’s own tools can read are unlikely to satisfy the standard.
The qualifier “where relevant and technically feasible” is not a general escape hatch. It recognises that some products, because of hardware constraints, storage limitations, or the absence of any local interface, cannot practicably offer direct on-device access. In such cases, the Data Act still requires that data be made available to the user by the data holder upon request, easily, securely and free of charge; direct access is what is excused, not access itself. Manufacturers relying on infeasibility should record the technical reasons in a feasibility assessment, so the position can be evidenced if challenged.
Accessibility must not come at the cost of security. The regulation’s requirement that data be provided “securely” aligns with secure-by-default engineering principles, and technical guidance from ENISA on secure design and machine-readable data handling is a useful reference point for calibrating authentication, access control and integrity measures around any access mechanism. A well-designed access channel authenticates the user, protects data in transit, and exposes only the data the user is entitled to, avoiding the over-exposure of unrelated information.
On the recurring question of whether remote or cloud access is sufficient, the answer depends on the facts: cloud-mediated access can satisfy the duty where it gives the user genuine, controlled, machine-readable access and meets the security and free-of-charge conditions, but it should not be used to reintroduce discretionary gatekeeping that direct access is meant to remove.
Manufacturers frequently ask whether they can withhold data on the basis that it embeds proprietary know-how. The Data Act does not abolish trade secret protection, but it disciplines how such protection may be invoked.
Trade secrets remain protected under Directive (EU) 2016/943, which defines a trade secret by reference to information that is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. The Data Act allows data holders to take proportionate measures, including agreeing technical and organisational safeguards with the user, to preserve the confidentiality of data that qualifies as a trade secret, but it does not permit a blanket refusal. Restrictions must be genuinely tied to identified trade secrets and must be proportionate.
The regulation provides only narrow circumstances in which disclosure may be withheld or suspended, and trade secret status cannot be used as a pretext to defeat the user’s access rights entirely.
Where a manufacturer intends to restrict or condition access on trade secret grounds, it should be able to demonstrate the basis for doing so. Good practice includes identifying with specificity which data elements are asserted to be trade secrets, recording why each meets the Directive (EU) 2016/943 criteria, and setting out what protective measures or alternative access can be offered instead. This documentary trail both supports a lawful restriction and reduces the risk that a proportionality challenge succeeds. The practical effect is that trade secret claims should be prepared in advance and mapped to the product’s data set, rather than asserted reactively.
Because the design duty operates across a supply chain, the allocation of obligations, costs and liability between manufacturers, importers, distributors and users should be addressed contractually. Contract terms cannot override the user’s statutory rights, and the Data Act contains an unfairness test for certain unilaterally imposed terms in business-to-business relationships, but contracts can and should allocate responsibility for delivering compliance.
When revising manufacturing, supply and distribution agreements, counsel should consider clauses addressing the following (these are drafting considerations, not model clauses):
Supply agreements should include warranties that products placed on the market after 12 September 2026 comply with Article 3(1), representations as to the accuracy of technical documentation, and a considered allocation of liability, including indemnities for non-compliance and any liability caps negotiated between commercial parties, bearing in mind the Data Act’s limits on unfair contractual terms. Importers and distributors dealing with non-EU manufacturers should be especially careful, since they may find themselves bearing regulatory exposure that is best backed by contractual protection upstream. It is also important to distinguish data-access clauses under the Data Act from data-processing clauses under the GDPR: they serve different regimes and should be drafted separately even where they touch the same data.
Preparation for the deadline is best structured as a sequenced programme rather than a single legal review. The following steps translate the design duty into operational action for Spanish organisations.
Maintain a defensible evidence base demonstrating how each in-scope product satisfies the duty. This should include:
The Data Act is enforced through competent authorities designated by each Member State, with coordination at EU level. In Spain, the data-protection dimension of compliance intersects with the Agencia Española de Protección de Datos (AEPD), which is the supervisory authority for personal-data aspects, alongside the national authority or authorities designated for Data Act supervision. Penalties are set by Member States and must be effective, proportionate and dissuasive; where personal data is involved, the GDPR’s administrative fines regime may apply. Because a non-compliant unit cannot lawfully be placed on the market after the deadline, the commercial consequences of failure extend beyond fines to the potential inability to sell affected stock.
The European Commission’s policy materials on the Data Act provide further context on the regime’s objectives and implementation.
Prioritise remediation by risk. High-risk products are those with high sales volumes crossing the deadline, complex data sets, or significant trade secret sensitivity; medium-risk products are lower-volume or technically simpler items; low-risk products are those clearly outside scope or already engineered for open, machine-readable access. Concentrating engineering and legal resource on the high-risk tier before September 2026 is the pragmatic way to manage the transition.
| Scenario | Applicable law | Design obligations (Article 3(1)) | Practical implication |
|---|---|---|---|
| Product placed on the EU market before 12 September 2026 | Data Act obligations applicable since 12 September 2025, excluding the Article 3(1) design duty | No mandatory access-by-design retrofit required, though contractual data-sharing obligations may still apply | Existing products may be supplied under their current design, but other Data Act duties must still be met |
| Product placed on the EU market after 12 September 2026 | Full Data Act, including the Article 3(1) access-by-design duty | Must be designed so product and related service data are, by default, easily, securely, free of charge, in a machine-readable format and, where relevant and feasible, directly accessible to the user | New shipments must meet the design requirements; non-compliant units cannot lawfully be placed on the market after this date |
The EU Data Act’s access-by-design duty reaches its first mandatory application on 12 September 2026, and the intervening months are the window in which compliance is either engineered in or missed. For Spanish counsel and their clients, the priority actions are clear: inventory connected products and related services; run design and feasibility assessments against Article 3(1); fix and document placement dates so the deadline can be applied unit by unit; prepare trade secret positions under Directive (EU) 2016/943 in advance rather than reactively; and revise supply and distribution contracts to allocate responsibility, warranties and liability across the chain.
Because the design duty cannot be bolted on late, the organisations that treat it as a product-engineering programme, not a last-minute legal review, will be the ones able to keep placing goods on the market after the deadline without interruption.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.
posted 16 minutes ago
posted 27 minutes ago
posted 37 minutes ago
posted 56 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message