EU Data Act Access by Design 2026 and manufacturer obligations
As of September 12, 2026, manufacturers of connected products must ensure that users and authorized third parties can access generated data directly, easily, and free of charge. The Regulation (EU) 2023/2854, known as the Data Act, makes Access by Design a mandatory requirement for sales. Anyone building machines, equipment, or smart devices must design the data architecture so that it is machine-readable and interoperable by default.
Why September 12, 2026 is crucial for EU Data Act Access by Design
On this deadline, the obligation to technically integrate data access directly into the product design takes effect, as required by Article 3 Paragraph 1 of the Data Act. Many companies confuse this date with the general application date of the regulation on September 12, 2025. While the legal obligation to provide data upon request already exists from 2025, the 2026 deadline forces manufacturers to technically build this provision into the devices as a default function. Those who consider their current product line exempt are confusing the two deadlines. The requirement is explicitly aimed at those who design and manufacture connected products, as well as providers of related services.
Which products and data are affected by the regulation
A connected product is any item that generates and can transmit data about its use or environment, provided its main function is not purely data processing for third parties. A machine control system that reports operating hours and error codes to a portal falls exactly under this definition. The regulation requires that these product and service data, including the necessary metadata, be provided in a comprehensive, structured, common, and machine-readable format. Where relevant and technically feasible, the user must be able to access this data without the intervention of another party. The legislator's goal is to provide users with the data they need for third-party repair services or for more efficient internal data use.
Why existing products do not need technical retrofitting
A subsequent retrofitting of already sold existing products is not legally required. The starting point for the obligation under Article 3 Paragraph 1 is the placing on the market, i.e., the first making available of a specific device on the Union market. However, this does not mean a blanket grandfathering for old product series. Even for product lines that have been offered for years, every single device that leaves the factory and enters the market after September 12, 2026, must meet the requirements. Those planning regular product refreshes must adapt the data architecture now. For older devices already at the customer's site, there is no obligation for technical modification, but the information and provision obligations towards the user still apply, provided the data is available without disproportionate effort.
How the exemptions for small and medium-sized enterprises apply
Micro and small enterprises are completely exempt from the obligations of Chapter II and thus from the Access by Design obligation according to Article 7. According to EU Recommendation 2003/361/EC, a micro-enterprise is one with fewer than 10 employees and a maximum annual turnover or balance sheet total of 2 million euros. Small enterprises may have up to 50 employees and 10 million euros in turnover or balance sheet total. For medium-sized enterprises with up to 250 employees and up to 50 million euros in turnover, there is no permanent exemption, but only a transitional rule: They are exempt from the obligations as long as they have met the threshold for a medium-sized enterprise for less than a year. Those permanently above this must deliver.
When switching fees for cloud providers will be completely eliminated
The complete ban on switching fees for cloud providers comes into force separately on January 12, 2027. The regulation under Article 29 Data Act flanks the data access rights by removing commercial barriers to data transfer. Until this deadline, a transitional rule applies, according to which cloud providers may only charge purely cost-covering fees for switching. For medium-sized businesses, this means significantly higher flexibility in choosing infrastructure. Those storing and processing large amounts of IoT data from connected products are no longer bound to a hyperscaler by artificially high exit fees.
How standardized machine data changes internal analysis
The regulatory obligation to provide structured data ends the era of closed data silos and proprietary interfaces in mechanical engineering. When heterogeneous machine data and IoT interfaces must be provided in a legally standardized manner, an auditable data basis is created that can be used directly. In the practice of a modular foundation, this means that raw data from a wide variety of systems can be merged without complex middleware projects. Management configures processes and rules according to their vision, and this rolls out directly to the departments.
An analysis center designed to normalize scattered data from many systems into a single, actionable truth benefits massively from this development. Previously, evaluations across the machinery often failed because the number was in six systems and none was correct. Through the Data Act, machines deliver their operating data, error codes, and metadata in a machine-readable format. This data can be directly linked with ERP data, inventories, and maintenance plans. The system then models the business not only in dashboards but provides concrete recommendations with justification, such as for reordering wear parts or adjusting maintenance intervals. Nothing fires without approval; the approval-first principle is maintained.
When this normalized data flows into an overarching memory that brings together the memories of all tools in a common knowledge base, correlations across tool boundaries become visible. A campaign spike in sales leads to higher utilization, which in turn shortens the maintenance cycles of the machines. The system recognizes such connections automatically. Since data sovereignty is maintained and processing runs via EU endpoints, this transparency forced by the Data Act fits seamlessly into a clean governance structure. Quality and traceability are guaranteed, as every answer and every action remains traceable with source references.
Researched and drafted with AI assistance, reviewed and approved before publication by Martin Reichle. More
Frequently asked
Gilt die Access-by-Design-Pflicht des Data Acts auch für bereits verkaufte Maschinen?
Nein, eine nachträgliche technische Umrüstung von Bestandsprodukten ist nicht erforderlich. Die Pflicht greift nur für Geräte, die nach dem 12. September 2026 erstmals auf dem Unionsmarkt bereitgestellt werden.
Sind kleine Unternehmen von den Pflichten des EU Data Acts befreit?
Ja, kleine und Kleinstunternehmen mit weniger als 50 Mitarbeitern und maximal 10 Millionen Euro Jahresumsatz oder Bilanzsumme sind von der Access-by-Design-Pflicht vollständig ausgenommen. Für mittlere Unternehmen gilt lediglich eine einjährige Übergangsfrist nach Erreichen des Schwellenwerts.
Was passiert, wenn eine alte Produktserie nach dem Stichtag 2026 weiter produziert wird?
Es gibt keinen Bestandsschutz für alte Baureihen. Jedes einzelne Gerät, das nach dem 12. September 2026 neu in Verkehr gebracht wird, muss die Vorgaben zur standardmäßigen Datenbereitstellung erfüllen.
Wann fallen die Wechselentgelte für Cloud-Anbieter weg?
Das vollständige Verbot von Wechselentgelten für Cloud-Verträge tritt am 12. Januar 2027 in Kraft. Bis zu diesem Datum dürfen Anbieter nur noch rein kostendeckende Gebühren für den Wechsel berechnen.