Every sensor installed in a water network, every smart meter, every active traceability tag and every connected machine generates data, and until recently it was the manufacturer’s contract that decided who could use it. Regulation (EU) 2023/2854, known as the Data Act, changes that: since 12 September 2025 the user of a connected product has had the right to access the data that product generates and to have it shared with a third party of the user’s choosing, and since 12 September 2026 products placed on the market have had to be designed so that such access is direct. This guide explains, as at 16 September 2026, who it binds, which data is covered, what rights the user has, which contractual terms no longer hold, what changes in cloud services and what all this means for an IoT sensing or traceability project, whether it belongs to a public authority or to a company.

Who it binds and from when

The Data Act entered into force on 11 January 2024 and has applied since 12 September 2025. It binds:

  • Manufacturers of connected products placed on the market in the Union: any item that obtains, generates or collects data concerning its use or its environment and is able to communicate it (sensors, meters, vehicles, machinery, household appliances, medical devices, wearables).
  • Providers of related services: the digital service without which the product cannot perform one or more of its functions (the platform that receives and displays the sensor’s data, for example).
  • Data holders in general, meaning whoever has the right or the ability to make the data available.
  • Providers of data processing services (cloud, edge) as regards switching provider.

And it protects users, who may be natural or legal persons, including public authorities that buy or rent the product.

Two more dates: the access by design obligation in Article 3 applies to products and services placed on the market after 12 September 2026, and cloud providers’ switching charges must disappear on 12 January 2027.

Which data is covered

Product data and related service data: the data the device generates when it is used (measurements, statuses, events, position, consumption) and the metadata needed to interpret it, both the data the user triggers and the data generated while the device is idle. Derived or inferred data that the manufacturer calculates from it using its own algorithms (a leak prediction, for example) is not covered, although the readings that feed the prediction are. The regulation protects the data holder’s trade secrets through measures agreed with the user, but it does not allow access to be refused on those grounds other than in exceptional, duly substantiated cases.

The user’s rights

  1. Direct access (Article 3): the product must be designed so that the data is accessible to the user by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant, in real time.
  2. Access on request (Article 4): if direct access is not possible, the data holder makes the data available to the user without undue delay and free of charge.
  3. Sharing with third parties (Article 5): at the user’s request, the data holder makes the data available to the third party the user designates, on the same terms, with reasonable compensation if the third party is a business (limited to cost if it is an SME).
  4. Pre-contractual information: before buying, the user must know what data the product generates, in what volume and format, whether it is generated in real time, how to access it and whether the manufacturer itself will use it.
  5. Limits on the data holder: the manufacturer may use the product’s non-personal data only on the basis of a contract with the user, and may not use it to gain insight into the user’s economic situation or processes in a way that undermines the user’s commercial position.

Contractual terms that no longer hold

Chapter IV declares unfair terms not binding where they have been unilaterally imposed on another business and concern access to and use of data: excluding liability for intentional acts or gross negligence, preventing the user from accessing or using its data, allowing the data holder to terminate the contract at unreasonably short notice, or giving the data holder exclusive rights over data that the other party has generated. For sensor deployment and IoT platform contracts signed with public authorities and companies, this means reviewing who can do what with the data.

Cloud: switching provider without penalty

Chapter VI obliges cloud service providers to remove the obstacles to switching provider: a maximum transition period, export of all data and digital assets in open formats, assistance during the migration and the abolition of switching charges from 12 January 2027. For a public authority procuring a hosted IoT platform, it means that the tender specifications can require today what the regulation will impose tomorrow: a complete exit, in a reusable format and at no cost.

What it means for an IoT sensing or traceability project

  • An open data model: every reading and every event with its identifier, its time stamp and its metadata, in structured, documented formats; no data trapped in a proprietary format.
  • User access by design: an interface or API so that the entity that owns the project can extract its data in full and, where appropriate, in real time, without asking the sensor manufacturer for permission.
  • Governed sharing: a mechanism for the user to authorise third parties (a maintenance company, a university, another public authority) and for the system to hand over the data with a record of what, to whom and when.
  • Separation between raw and derived data: the predictive models belong to the developer; the readings that feed them belong to the user and must be capable of being handed over.
  • Revised contracts: with device manufacturers, to make sure their data reaches the platform in open form, and with users, to settle uses, compensation and exit.
  • Cloud exit clauses: full export, open formats and no switching charges.
  • Trade secrets and security: technical and contractual measures to protect what needs protecting without blocking the right of access.
  • Coexistence with the GDPR: when the device data is personal (household meters, wearables), the Data Act does not replace the GDPR; both apply.

In a water network sensing project such as the one we describe in IoT sensing in water networks, this means that the consortium or local council that owns the project must be able to extract every reading from every sensor in an open format, and share them with whomever it decides, without depending on the manufacturer of each device. In traceability, it means that the events recorded by tags and readers belong to whoever uses the system.

How it relates to other legislation

The Data Act comes on top of the Data Governance Act (2022/868), the directive on open data in the public sector and the Digital Product Passport under the Ecodesign for Sustainable Products Regulation (ESPR), which we explain in the Digital Product Passport and NFC traceability. And it provides, in Chapter V, for public bodies to be able to require data from companies in situations of exceptional need, such as emergencies, under strict conditions.

How CEDESA does it

CEDESA develops IoT sensing, data integration and predictive analytics platforms for public authorities and companies, with projects such as the water network sensing for the Consorcio de Medio Ambiente de Badajoz (the provincial environmental consortium) and NFC traceability systems for industry. Our design approach matches what the Data Act now requires: the data belongs to the project owner, lives in open, documented models, is exported in full, and every instance of sharing is logged. With certification to Spain’s National Security Framework (Esquema Nacional de Seguridad, ENS), ISO 27001 and ISO 56001, that data governance is audited and is part of the development cycle.

Frequently asked questions about the Data Act and IoT

Since when has the Data Act applied?

Since 12 September 2025 as a general rule. The obligation to design connected products so that the user has direct access to the data (Article 3) applies to products and services placed on the market after 12 September 2026, and the abolition of charges for switching cloud provider applies from 12 January 2027.

What is a connected product under the Data Act?

Any item that obtains, generates or collects data concerning its use or its environment and is able to communicate it via a communications service or a physical connection: sensors, meters, vehicles, industrial machinery, household appliances, medical devices or wearables. The digital service without which the product cannot perform its functions is a related service and is also covered.

What data is the user of an IoT device entitled to receive?

The product data and related service data that the device generates when it is used, with the metadata needed to interpret it, in a structured, commonly used and machine-readable format, free of charge and, where relevant, in real time. It does not include the derived or inferred data that the manufacturer calculates using its own algorithms.

Can the manufacturer refuse to hand over the data on the grounds of trade secrets?

Only in exceptional, duly substantiated cases. The rule is that the data holder and the user agree measures to protect trade secrets without preventing access; refusing or suspending access requires the data holder to demonstrate serious economic damage and to follow the procedure laid down in the regulation.

What changes in cloud service contracts?

Providers must make it easier to switch provider: a limited transition period, export of data and assets in open formats, assistance with the migration and the removal of switching charges from 12 January 2027. Public tender specifications can require those conditions today.

Conclusion

The Data Act turns into a right what a well-designed IoT project was already doing: the data that devices generate belongs to the user, is handed over in open formats, is shared with whomever the user decides and does not end up trapped in the manufacturer’s platform or the provider’s cloud. Since September 2026 it has also been a design requirement for new products. If you have an IoT sensing or traceability project and do not know whether it complies, tell us how your data is stored and extracted today.