Data Act timeline showing the September 2025 application date, the September 2026 design obligation and the January 2027 switching charge deadline

The EU Data Act: Your Sensor Data Stops Being the Vendor’s

TL;DR: The EU Data Act has applied since 12 September 2025, and it already gives the user of a connected product a legal right to the data that product generates, free of charge and in a machine-readable format. What changes on 12 September 2026 is narrower and more consequential: from that date, products placed on the EU market must be designed so the data is accessible by default. It catches manufacturers irrespective of where they are established, so a UK sensor maker selling into the EU is in scope. There is no UK equivalent.

Last updated: 29 July 2026

Key takeaways

  • Regulation (EU) 2023/2854, the Data Act, has applied since 12 September 2025.
  • Article 3(1), the design obligation, applies to connected products and related services placed on the market after 12 September 2026.
  • Article 1(3) catches manufacturers of connected products placed on the EU market “irrespective of the place of establishment”. Being outside the EU is not an exemption.
  • Under Article 4(1) a user can demand their data free of charge, machine-readable, and where technically feasible continuously and in real-time.
  • Under Article 5(1) the user can direct the data holder to send that data to a third party, including a competing platform.
  • From 12 January 2027, cloud and edge providers may impose no switching charges at all.
  • Penalties are set by each Member State, not by the Regulation. There is no headline EU-wide fine.
Data Act timeline showing the September 2025 application date, the September 2026 design obligation and the January 2027 switching charge deadline
Three dates, and only one of them is about how the product is built.

What the Data Act actually does

The Data Act is the EU regulation that decides who gets to use the data a connected product generates. Not who owns it, which is a question the Regulation deliberately sidesteps, but who can access it, use it and pass it on. The European Commission sets out the aims on its Data Act policy page. For anyone deploying industrial sensors, this is the question underneath every procurement argument about lock-in.

The Data Act’s mechanism is simple to state. The user of a connected product, meaning the person or business that owns, rents or leases it, gets rights over the data they co-generate by using it. The data holder, usually the manufacturer or the platform operator, gets obligations. Contracts cannot be used to take those rights away.

The Data Act names industrial machinery in scope alongside cars and smart TVs. A LoRaWAN sensor, a gateway, a metering device and the cloud service behind them are all squarely inside the definition of connected products and related services.

The right exists now. The design duty starts in September

This is the part of the Data Act almost every summary gets muddled, so it is worth being precise. Article 50 says the Regulation applies from 12 September 2025. One obligation is carved out and deferred: “The obligation resulting from Article 3(1) shall apply to connected products and the services related to them placed on the market after 12 September 2026.”

So there are two different things happening. The access rights in Articles 4 and 5 are already live and apply to in-scope products now. The design duty in Article 3(1) bites only on products placed on the market after this September, and it requires that products “shall be designed and manufactured, and related services shall be designed and provided, in such a manner that product data and related service data” are “by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format” and, where relevant and technically feasible, directly accessible to the user.

Put plainly: since last September you have been able to ask for your data. From this September, the product has to be built so that asking is not necessary. That is a hardware and firmware roadmap question, not a legal-department question, which is why the date matters to anyone specifying kit now for delivery later.

One more date sits behind those. Chapter IV, on unfair contract terms, applies to contracts concluded after 12 September 2025, and from 12 September 2027 it reaches back to older contracts that are either of indefinite duration or due to expire at least ten years from 11 January 2024.

Does it reach a UK manufacturer?

Yes, if the product reaches the EU market. The Data Act’s Article 1(3)(a) applies the Regulation to “manufacturers of connected products placed on the market in the Union and providers of related services, irrespective of the place of establishment of those manufacturers and providers”. Point (f) does the same for providers of data processing services serving customers in the Union.

This is the same extraterritorial pattern as the Cyber Resilience Act, and the two land within a year of each other on the same product lines. A UK sensor manufacturer selling only into the UK is untouched by both. One that ships to a distributor in Ireland or Germany is inside both.

For a UK buyer the position is less direct but still useful. You get no rights from the Data Act on a UK-only deployment. What you do get is leverage, because any vendor building to comply for the EU market is building the capability anyway, and there is no good reason for it to be switched off on your side of the Channel.

Who the Data Act applies to, showing manufacturers and cloud providers caught irrespective of place of establishment
Place of establishment is explicitly irrelevant. Market access is what counts.

What a user can now demand

Article 4(1) is the Data Act’s operative provision. Data holders must make readily available data, plus the metadata needed to interpret it, accessible to the user “without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time”. A simple electronic request is enough to trigger it.

Two phrases in there do most of the work. “Of the same quality as is available to the data holder” closes the loophole of shipping the customer a daily CSV while the vendor keeps the raw stream. And “continuously and in real-time”, where feasible, means an export button is not automatically enough.

Article 5(1) is the one with teeth for competition. On the user’s request, the data holder must make that data available to a third party, free of charge to the user, in the same machine-readable form and, where technically feasible, continuously and in real-time. In practice that means a customer can instruct a sensor vendor to pipe their data into a rival platform, and the vendor has to do it.

If you have ever been told that getting your own readings out of a vendor cloud requires a professional services engagement, that is the clause that ends the conversation, at least for products on the EU market.

Cloud switching and the January 2027 cliff

The second half of the Data Act deals with data processing services, meaning cloud and edge. Article 29 sets a hard schedule for the exit fees that have historically made migration uneconomic.

  • From 11 January 2024 to 12 January 2027: providers may impose only reduced switching charges, which “shall not exceed the costs incurred by the provider of data processing services that are directly linked to the switching process concerned”.
  • From 12 January 2027: providers “shall not impose any switching charges on the customer for the switching process”. None.
  • Before contracting: the provider must give clear information on standard service fees, early termination penalties, and any reduced switching charges that may apply in the meantime.

Egress cost is the quiet reason many IoT estates never move platform, and the Data Act removes it in two steps rather than one. Removing it does not make migration easy, because the data model and the integrations are the real work, but it removes the number that made the business case impossible.

Switching charge schedule under Article 29 falling from reduced charges to zero on 12 January 2027
Reduced, then nothing. The cliff is 12 January 2027.

What the Data Act does not do

Three honest limits on the Data Act, because the enthusiastic version of this article is misleading.

There is no UK equivalent. The Data (Use and Access) Act 2025 is a different animal and does not create these connected-product rights. A purely domestic deployment gets nothing from the Data Act, and anyone telling a UK buyer they now have a statutory right to their sensor data is wrong.

There is no EU-level fine. Article 40 requires Member States to lay down penalties that are “effective, proportionate and dissuasive” and to notify the Commission by 12 September 2025. So enforcement and severity vary by country, and the headline percentage-of-turnover figure people expect from EU regulation simply is not in this one.

There are carve-outs. Article 4(2) lets users and data holders contractually restrict access where sharing could undermine security requirements laid down in law and cause a serious adverse effect on health, safety or security, with any refusal notified to the competent authority designated under Article 37. Trade secrets are also protected, and a data holder can withhold where disclosure would be highly likely to cause serious economic damage. Expect those routes to be tested.

Five steps if you buy or build connected kit

  1. Ask your vendor one question. Will products you ship after 12 September 2026 meet Article 3(1), and will that capability be available on UK deployments too? The answer tells you a lot. Our buying guides cover what else to ask.
  2. Read your existing contract for data clauses. Terms concluded after 12 September 2025 already have to comply with Chapter IV, and older indefinite contracts get caught in 2027.
  3. Test the export before you need it. Ask for the same quality of data the vendor holds, in a machine-readable format, and see what actually arrives. Vendor datasheets rarely say.
  4. Price your exit now. Switching charges are capped today and gone in January 2027, so any quoted egress fee should be shrinking.
  5. Prefer open protocols regardless. A LoRaWAN gateway that speaks to any network server, or a Modbus data logger writing to your own database, sidesteps the argument entirely.

Frequently asked questions

When does the Data Act apply?

The Data Act has applied since 12 September 2025. The design obligation in Article 3(1) applies separately, to connected products and related services placed on the market after 12 September 2026. Switching charges must be fully withdrawn from 12 January 2027, and Chapter IV reaches older indefinite contracts from 12 September 2027.

Does the Data Act apply to UK companies?

It applies to manufacturers of connected products placed on the EU market irrespective of where they are established, and to cloud providers serving customers in the Union. So a UK manufacturer exporting into the EU is in scope. A UK company selling only domestically is not, and the UK has no equivalent legislation.

Does the Data Act say who owns IoT data?

No, and that is deliberate. The Data Act creates access, use and portability rights rather than a property right. The user can obtain the data, use it and direct it to a third party, while the data holder retains its own position, subject to the limits on using non-personal data without the user’s agreement.

What are the penalties under the Data Act?

Set nationally, not centrally. Article 40 requires Member States to adopt effective, proportionate and dissuasive penalties and to notify them to the Commission, which maintains a public register. There is no single EU-wide maximum in the Regulation itself, unlike the Cyber Resilience Act.

Can a vendor refuse to share my sensor data?

Only on narrow grounds under the Data Act. Access can be restricted where sharing could undermine legal security requirements and cause a serious adverse effect on health, safety or security, and a refusal must be notified to the competent authority. Trade secrets are protected where disclosure would be highly likely to cause serious economic damage.

Lock-in stops being a design choice

For twenty years the default assumption in industrial IoT has been that the data lands in the vendor’s cloud and getting it out is a negotiation. The Data Act does not fix that everywhere, and it does not fix it in the UK at all. What it does is remove the excuse, because from this September a product sold into the EU has to be built to hand the data over.

The practical move for a UK buyer is to specify the capability rather than wait for the law. For related reading see our IoT sensor buyer’s guide, the LoRaWAN sensor range, the Cyber Security and Resilience Bill for the UK regulatory picture, and wireless versus wired retrofit costs for the deployment side. The wider context is in smart sensors for Industry 4.0.

User rights under Articles 4 and 5 including same quality data, real-time access and third party sharing
Article 4 gets you the data. Article 5 lets you send it to a competitor.
Three limits of the Data Act: no UK equivalent, nationally set penalties and security and trade secret carve-outs
The three limits worth knowing before you rely on any of it.

Specifying sensors and worried about where the data ends up? Talk to Indiott about open protocols, self-hosted network servers and what to put in the contract.

Next step

Get a priced kit list for your site

Answer three quick questions and tell us where to send it. An engineer replies within one working day with the parts, the prices and the lead time.

Rather talk it through? Call 023 9223 3611

How many sites is it for?
Roughly how many sensors or points to monitor?
When do you need it?

Answered within one working day

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *