[codicts-css-switcher id=”346″]

Global Law Experts Logo
eu data acts accessbydesign duty reaches

Our Expert in Spain

The EU Data Act: Access-by-design Duty for Connected Products Placed on the Market After 12 September 2026

By Global Law Experts
– posted 2 hours ago

The EU Data Act’s access-by-design duty reaches every connected product placed on the Union market on or after 12 September 2026, converting an abstract data-sharing principle into a hard engineering and legal requirement that manufacturers, importers and distributors must build into the product itself. Under Regulation (EU) 2023/2854, most of the Data Act has applied since 12 September 2025, but Article 50 defers the design obligation in Article 3(1) so that it bites specifically on products first placed on the market after the 2026 date.

For companies serving the Spanish and wider EU market, this is not a compliance formality that can be papered over with policies, it changes how hardware and firmware are conceived, how data flows are exposed, and how commercial contracts allocate risk across the supply chain. This guide sets out, in practitioner terms, who is in scope, what “placed on the market” means, what “directly accessible” requires in practice, how trade secrets interact, and the contractual and documentary steps Spanish counsel should take before the deadline.

Who this is for: legal counsel, compliance teams, product managers and importers in Spain preparing for the Data Act’s design obligations effective for products placed on the market after 12 September 2026. This article explains scope, the technical tests for “directly accessible”, trade secret interaction, contracting and a compliance checklist.

Intro, TL;DR and key takeaways

  • What changes: the EU Data Act’s access-by-design duty reaches connected products placed on the market after 12 September 2026, requiring product and related service data to be accessible by default.
  • Who acts: manufacturers (including non-EU manufacturers), importers and distributors that first make a connected product available on the Union market.
  • What it demands: data that is easily, securely and free of charge accessible in a structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user.
  • What to watch: the “placed on the market” line, technical feasibility carve-outs, trade secret protection under Directive (EU) 2016/943, and clear contractual allocation of obligations.

1. Background: the Data Act and the phased rollout

The Data Act, Regulation (EU) 2023/2854, is a horizontal regulation designed to unlock the value of data generated by connected products and related services, giving users (whether consumers or businesses) meaningful control over the data their devices produce. It sits alongside, rather than replacing, the GDPR and the trade secrets framework, and it applies directly across all Member States, including Spain, without the need for national transposition, though Member States must designate competent authorities and lay down penalties.

The regulation entered into force in January 2024 and its core obligations became applicable on 12 September 2025. However, the legislator recognised that the most demanding requirement, designing products so that data is accessible by default, cannot sensibly be retrofitted to goods already in production or on shelves. Article 50 therefore introduces a deferred timeline for the design obligation, and it is this phasing that gives 2026 its significance.

Timeline: Article 50 and the 12 September 2026 line

Article 50 provides that the access-by-design obligation in Article 3(1) applies to connected products, and the related services connected to them, placed on the market after 12 September 2026. In practical terms, there are two dates that matter: the general application date of 12 September 2025, from which the bulk of the Data Act’s data-sharing and contractual obligations apply, and 12 September 2026, from which the design duty in Article 3(1) attaches to newly placed products. The distinction is deliberate, existing obligations can be met contractually and operationally, but the design duty requires lead time to engineer.

Article 3(1) explained

Article 3(1) requires that connected products and related services be designed and manufactured, and the related services provided, in such a manner that product data and related service data, including the relevant metadata necessary to interpret and use that data, are, by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user. The phrasing is dense but each element is operative: “by default” removes any need for the user to request; “free of charge” bars access fees for the user obtaining data about their own use; “machine-readable format” excludes closed or proprietary-only outputs; and “directly accessible” reaches toward local, user-controlled retrieval.

2. Who and what is in scope, how the EU Data Act’s access-by-design duty reaches the supply chain

The scope of the design duty is defined by the concepts of “connected product” and “related service”, together with the actors who place such products on the Union market. Understanding these definitions is the first analytical step for any Spanish manufacturer or importer.

Definitions: connected product, related service and the actors bound

A connected product, in the sense of the Data Act, is an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, a physical connection or on-device access, the classic examples being connected vehicles, smart home appliances, wearables, and industrial machinery fitted with sensors. A related service is a digital service, other than an electronic communications service, connected to the product at the time of purchase, rent or lease in such a way that its absence would prevent the product from performing one or more of its functions, or that is subsequently connected to it.

The obligation is imposed on the party that designs and manufactures the product and, functionally, on those who place it on the Union market. This means manufacturers based in Spain, elsewhere in the EU, or in third countries can all be caught, and importers and distributors may carry obligations where the manufacturer is outside the EU. The EU Data Act’s access-by-design duty reaches non-EU manufacturers through the market-placement trigger rather than through their place of establishment.

Examples and borderline cases

The clearest cases are physical devices that plainly generate usage or environmental data. Consider the following typical categories and their likely treatment:

  • Connected vehicles. Squarely in scope; telematics, drivetrain and diagnostic data are product data, subject to safety and type-approval interactions.
  • Smart appliances. In scope where the appliance generates and communicates usage data; the related app is typically a related service.
  • Industrial sensors and equipment. In scope; industrial machinery generating operational telemetry is a paradigm case for business-to-business data access.
  • Medical devices. Potentially in scope but subject to significant interplay with sector-specific regulation, safety rules and health data protection.
  • Software-only services. A pure software service that is not connected to a product may fall outside the design duty, though it can be caught by other Data Act obligations depending on function.

Borderline cases, for example, a product with only intermittent connectivity, or firmware that logs data locally but never transmits it, require a careful reading of whether the item “obtains, generates or collects” data within the meaning of the regulation. Where doubt exists, the safer working assumption is that the EU Data Act’s access-by-design duty reaches the product and that a documented feasibility assessment is needed to justify any narrower position.

3. “Placed on the market”: crossing the 12 September 2026 line

Because Article 50 keys the design duty to products placed on the market after 12 September 2026, the definition of “placed on the market” is decisive for determining which units must comply. This is one of the most practically important, and potentially litigable, questions counsel will face.

EU-first making available: import versus intra-EU supply

Drawing on established EU product-law concepts, “placed on the market” is generally understood as the first making available of a product on the Union market, in Spanish regulatory language, the primera comercialización en el mercado de la Unión. The concept turns on the first supply for distribution, consumption or use in the EU in the course of a commercial activity, whether against payment or free of charge. Practical markers that counsel can use to fix the moment include:

  • The first offer for sale or supply of a specific unit within the EU;
  • Customs release into free circulation for imported goods;
  • The first handover of the product to an EU-based distributor or reseller for onward supply.

For imports from third countries, the release for free circulation typically marks the relevant point at which a unit is first made available, meaning non-EU manufacturers cannot escape the design duty simply by manufacturing abroad. The EU Data Act’s access-by-design duty reaches imported units at the point they enter the Union market for supply.

Transitional stock and worked examples

The design duty attaches per unit at the moment of first making available, not to a product line as a class. This produces important transitional consequences. A consumer device manufactured and warehoused in Spain in mid-2026, then first offered for sale to a consumer on 20 September 2026, is placed on the market after the deadline and must comply. The identical device first supplied to a distributor on 1 September 2026 was placed on the market before the deadline and is not subject to the Article 3(1) design duty, though other Data Act obligations still apply.

For industrial rigs assembled to order, the analysis may differ again: a bespoke machine handed over to an EU customer after the deadline will need to meet the design requirements, even if components were procured earlier. Counsel should therefore map inventory and expected supply dates unit by unit, or at least by clearly defined batches, and document the placement date to evidence the position taken.

4. What “directly accessible” requires in practice

The phrase “directly accessible to the user”, qualified by “where relevant and technically feasible”, is where legal analysis meets engineering reality. It is the element of the design duty most likely to generate disputes and the one most in need of a structured feasibility assessment.

Direct access modalities

Direct accessibility contemplates the user obtaining data without needing to route a request through the manufacturer’s discretionary gatekeeping. Depending on the product, this can be delivered through several modalities:

  • Standardised APIs. A documented interface allowing the user or an authorised third party to pull machine-readable data.
  • Local physical interfaces. A USB port, diagnostic connector or comparable local socket enabling on-device export.
  • Local wireless access. Bluetooth Low Energy or local network access allowing retrieval within the user’s environment.
  • Product-specific ports. For vehicles, an on-board diagnostic port; for industrial equipment, machine-to-machine protocols exposing operational data.
  • Exportable machine-readable files. Structured outputs such as CSV, JSON or, in industrial settings, OPC-UA data streams.

The data must be provided in a comprehensive, structured, commonly used and machine-readable format, together with the metadata needed to interpret it, and free of charge to the user. Proprietary formats that only the manufacturer’s own tools can read are unlikely to satisfy the standard.

When “not technically feasible” applies

The qualifier “where relevant and technically feasible” is not a general escape hatch. It recognises that some products, because of hardware constraints, storage limitations, or the absence of any local interface, cannot practicably offer direct on-device access. In such cases, the Data Act still requires that data be made available to the user by the data holder upon request, easily, securely and free of charge; direct access is what is excused, not access itself. Manufacturers relying on infeasibility should record the technical reasons in a feasibility assessment, so the position can be evidenced if challenged.

Security and data minimisation considerations

Accessibility must not come at the cost of security. The regulation’s requirement that data be provided “securely” aligns with secure-by-default engineering principles, and technical guidance from ENISA on secure design and machine-readable data handling is a useful reference point for calibrating authentication, access control and integrity measures around any access mechanism. A well-designed access channel authenticates the user, protects data in transit, and exposes only the data the user is entitled to, avoiding the over-exposure of unrelated information.

On the recurring question of whether remote or cloud access is sufficient, the answer depends on the facts: cloud-mediated access can satisfy the duty where it gives the user genuine, controlled, machine-readable access and meets the security and free-of-charge conditions, but it should not be used to reintroduce discretionary gatekeeping that direct access is meant to remove.

5. Trade secrets and confidentiality, exclusions and limits

Manufacturers frequently ask whether they can withhold data on the basis that it embeds proprietary know-how. The Data Act does not abolish trade secret protection, but it disciplines how such protection may be invoked.

The trade secret test and lawful restrictions

Trade secrets remain protected under Directive (EU) 2016/943, which defines a trade secret by reference to information that is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. The Data Act allows data holders to take proportionate measures, including agreeing technical and organisational safeguards with the user, to preserve the confidentiality of data that qualifies as a trade secret, but it does not permit a blanket refusal. Restrictions must be genuinely tied to identified trade secrets and must be proportionate.

The regulation provides only narrow circumstances in which disclosure may be withheld or suspended, and trade secret status cannot be used as a pretext to defeat the user’s access rights entirely.

Documentation and demonstrable reasons for restricting access

Where a manufacturer intends to restrict or condition access on trade secret grounds, it should be able to demonstrate the basis for doing so. Good practice includes identifying with specificity which data elements are asserted to be trade secrets, recording why each meets the Directive (EU) 2016/943 criteria, and setting out what protective measures or alternative access can be offered instead. This documentary trail both supports a lawful restriction and reduces the risk that a proportionality challenge succeeds. The practical effect is that trade secret claims should be prepared in advance and mapped to the product’s data set, rather than asserted reactively.

6. Contracting and commercial measures for manufacturers, importers and distributors

Because the design duty operates across a supply chain, the allocation of obligations, costs and liability between manufacturers, importers, distributors and users should be addressed contractually. Contract terms cannot override the user’s statutory rights, and the Data Act contains an unfairness test for certain unilaterally imposed terms in business-to-business relationships, but contracts can and should allocate responsibility for delivering compliance.

Key clause checklist

When revising manufacturing, supply and distribution agreements, counsel should consider clauses addressing the following (these are drafting considerations, not model clauses):

  • Compliance responsibility. Which party is responsible for designing and delivering access-by-design functionality and its ongoing maintenance.
  • Technical specifications. The agreed access modalities, data formats, metadata and security standards the product must meet.
  • Testing and acceptance. Acceptance criteria confirming that access functionality works before placement on the market.
  • Placement records. Obligations to record and share the date and circumstances of first making available, given its legal significance.
  • Trade secret handling. How trade secret assertions and confidentiality measures are coordinated between the parties.
  • Audit rights. Rights to verify a counterparty’s compliance and access to underlying documentation.

Warranties, representations and liability

Supply agreements should include warranties that products placed on the market after 12 September 2026 comply with Article 3(1), representations as to the accuracy of technical documentation, and a considered allocation of liability, including indemnities for non-compliance and any liability caps negotiated between commercial parties, bearing in mind the Data Act’s limits on unfair contractual terms. Importers and distributors dealing with non-EU manufacturers should be especially careful, since they may find themselves bearing regulatory exposure that is best backed by contractual protection upstream. It is also important to distinguish data-access clauses under the Data Act from data-processing clauses under the GDPR: they serve different regimes and should be drafted separately even where they touch the same data.

7. Compliance checklist and enforcement risk in Spain and the EU

Preparation for the deadline is best structured as a sequenced programme rather than a single legal review. The following steps translate the design duty into operational action for Spanish organisations.

Documentation and evidence

Maintain a defensible evidence base demonstrating how each in-scope product satisfies the duty. This should include:

  1. A product inventory identifying which items are connected products and related services;
  2. A design assessment mapping the product and related service data generated, and the metadata needed to interpret it;
  3. A technical feasibility study addressing direct accessibility and any infeasibility findings;
  4. Records of access modalities, data formats and security measures implemented;
  5. User interface and user-information documentation;
  6. Trade secret assessments where confidentiality restrictions are applied;
  7. Placement-date records fixing when each unit or batch is first made available;
  8. Testing and acceptance logs evidencing that access functionality works as designed.

Enforcement bodies and penalties

The Data Act is enforced through competent authorities designated by each Member State, with coordination at EU level. In Spain, the data-protection dimension of compliance intersects with the Agencia Española de Protección de Datos (AEPD), which is the supervisory authority for personal-data aspects, alongside the national authority or authorities designated for Data Act supervision. Penalties are set by Member States and must be effective, proportionate and dissuasive; where personal data is involved, the GDPR’s administrative fines regime may apply. Because a non-compliant unit cannot lawfully be placed on the market after the deadline, the commercial consequences of failure extend beyond fines to the potential inability to sell affected stock.

The European Commission’s policy materials on the Data Act provide further context on the regime’s objectives and implementation.

Risk matrix

Prioritise remediation by risk. High-risk products are those with high sales volumes crossing the deadline, complex data sets, or significant trade secret sensitivity; medium-risk products are lower-volume or technically simpler items; low-risk products are those clearly outside scope or already engineered for open, machine-readable access. Concentrating engineering and legal resource on the high-risk tier before September 2026 is the pragmatic way to manage the transition.

8. Comparison: products placed before versus after 12 September 2026

Scenario Applicable law Design obligations (Article 3(1)) Practical implication
Product placed on the EU market before 12 September 2026 Data Act obligations applicable since 12 September 2025, excluding the Article 3(1) design duty No mandatory access-by-design retrofit required, though contractual data-sharing obligations may still apply Existing products may be supplied under their current design, but other Data Act duties must still be met
Product placed on the EU market after 12 September 2026 Full Data Act, including the Article 3(1) access-by-design duty Must be designed so product and related service data are, by default, easily, securely, free of charge, in a machine-readable format and, where relevant and feasible, directly accessible to the user New shipments must meet the design requirements; non-compliant units cannot lawfully be placed on the market after this date

9. Conclusion and recommended next steps for Spanish counsel

The EU Data Act’s access-by-design duty reaches its first mandatory application on 12 September 2026, and the intervening months are the window in which compliance is either engineered in or missed. For Spanish counsel and their clients, the priority actions are clear: inventory connected products and related services; run design and feasibility assessments against Article 3(1); fix and document placement dates so the deadline can be applied unit by unit; prepare trade secret positions under Directive (EU) 2016/943 in advance rather than reactively; and revise supply and distribution contracts to allocate responsibility, warranties and liability across the chain.

Because the design duty cannot be bolted on late, the organisations that treat it as a product-engineering programme, not a last-minute legal review, will be the ones able to keep placing goods on the market after the deadline without interruption.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2023/2854 (Data Act), Official Journal of the EU
  2. Directive (EU) 2016/943 (Trade Secrets), Official Journal of the EU
  3. European Commission, Data Act policy page
  4. ENISA (European Union Agency for Cybersecurity)
  5. Agencia Española de Protección de Datos (AEPD)

FAQs

When does the Data Act access-by-design duty become mandatory?
Article 50 of Regulation (EU) 2023/2854 phases in Article 3(1) so that connected products placed on the market after 12 September 2026 must meet the access-by-design obligations. Most other Data Act obligations have applied since 12 September 2025.
It refers to the first making available of a product on the Union market. Practical indicators include the first offer for sale or supply within the EU, customs release into free circulation for imports, and the first handover to an EU-based distributor.
Yes. The EU Data Act’s access-by-design duty reaches any manufacturer, including a non-EU entity, that places a connected product on the Union market. Importers and distributors may also carry obligations where the manufacturer is outside the EU.
It depends. The Data Act requires direct accessibility where relevant and technically feasible. Cloud or remote access can suffice where it gives the user genuine, controlled access in a machine-readable format and meets the security and free-of-charge requirements, but it should not reintroduce discretionary gatekeeping.
The Data Act recognises legitimate trade secret protection under Directive (EU) 2016/943, but restrictions must be proportionate and documented. A manufacturer should identify which data qualifies as a trade secret, record why, and apply proportionate protective measures rather than refusing outright.
Retain technical design files, data-mapping logs, security and technical feasibility assessments, user interface documentation, placement-date records, trade secret assessments, and testing and acceptance reports. This evidence base supports the position taken on each in-scope product.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

The EU Data Act: Access-by-design Duty for Connected Products Placed on the Market After 12 September 2026

Send welcome message

Custom Message