Since September 12, connected equipment sold into the EU has to hand the business using it the data it generates, free and in a usable format. The manufacturers are treating that as a compliance project. It is actually the first legal claim buyers have ever had on that data, and procurement doesn't know it exists.
Two weeks ago, a single sentence of European law flipped the default on who controls the data your machines produce. Article 3(1) of the EU Data Act, applicable from September 12, requires that connected products placed on the EU market from that date, and the services that come with them, be designed so that the data they generate is accessible to the user: easily, securely, free of charge, and in a structured, commonly used, machine-readable format.
"The user" here is not a consumer in a kitchen. In most cases it is the business that owns, leases or rents the equipment. The forklift fleet, the packaging line, the HVAC plant in your distribution center, the diagnostic equipment in your service vans, the compressors your field engineers maintain. If it collects data about its own use and sends that data somewhere, and it went on sale in the EU after September 12, the business running it now has a legal right to that data.
Coverage of the deadline has been written almost entirely for manufacturers, which makes sense, because they carry the obligation. The more interesting consequences sit on the other side of the contract.
The data was always part of the vendor's business model
For fifteen years, the economics of industrial and commercial equipment have been drifting from the machine toward the service around it. The margin on the compressor is thin; the margin on the predictive maintenance subscription, the uptime guarantee and the authorized service network is not. What holds that model together is exclusive access to operating data. The manufacturer can see the vibration signature that predicts a bearing failure. You, the owner of the bearing, can see a dashboard the manufacturer chose to build.
The Data Act does not ban that model. It removes the exclusivity underneath it. Alongside the design obligation, the user can require the data holder to share the data with a third party of the user's choosing: an independent maintenance provider, an analytics firm, an insurer, or your own data platform. And the manufacturer may only use the non-personal data your equipment generates on the basis of a contract with you. Its right to that data is now something you grant, not something it assumes.
The vendor still collects the data. What changed is that it now needs your permission to treat it as its own.
Why almost nobody will notice this year
The right arrives quietly for three reasons, and all three work in the vendor's favor.
First, it applies only to products placed on the market after September 12. Your installed base is untouched. The right shows up one purchase order at a time, spread across dozens of equipment categories and years of replacement cycles, which is exactly the pattern least likely to reach anyone's agenda.
Second, the main thing a buyer receives is a disclosure. Before the contract is signed, the seller has to tell you what data the product generates, in what format and volume, and how you can access it. That information will be delivered, in most cases, as an annex that procurement files and nobody in operations or IT ever reads.
Third, "accessible" has a wide range of technically compliant answers. A monthly CSV export behind a support ticket and a real-time API are both, in some readings, a way of making data available. The regulation sets a floor on format and quality; the gap between that floor and something your engineers could actually use will be settled in negotiation, or not at all.
Figure 1
What the Act gives the user | Where vendors will push back | What to put in the RFP |
|---|---|---|
Access to product and related-service data, free of charge | Access method: export on request versus continuous, direct access | Delivery mechanism, latency and frequency, not only format |
Data of the same quality the vendor has | Raw versus pre-processed data; which fields count as "product data" | A field-level data dictionary as a pre-contract deliverable |
Sharing with a third party the user chooses | Compensation charged to that third party; security conditions | Named use cases (independent service, internal analytics) agreed up front |
Control over the vendor's own use of non-personal data | Broad data-use clauses in standard terms | Explicit, limited license back to the vendor, with purpose stated |
Protection against unfair data terms | Trade-secret carve-outs used to narrow what is shared | Agreed confidentiality measures instead of withheld data |
The regulation sets the floor. Negotiation sets everything above it. Trade secrets are the main lever vendors have: they can require confidentiality measures before sharing, and in exceptional cases refuse. A buyer who has specified the use case in advance is in a much stronger position than one who asks after installation. Illustrative, not a legal assessment.
A calendar, not a deadline
September 12 is the first date in a sequence, and seen together the sequence reads less like compliance and more like a shift in bargaining power toward the party that pays. On January 12, 2027, cloud providers lose the ability to charge switching fees under the same law. On September 12, 2027, the Act's rules against unfair data-sharing terms extend to long-running contracts signed before September 2025. And the Commission's proposed Digital Omnibus would fold other EU data rules into this framework and adjust parts of it, so some details will move.
For an enterprise running operations in Europe, that adds up to roughly eighteen months in which the renewal cycle for equipment, service contracts and cloud infrastructure can be renegotiated against a changed default. Vendors know it. Their account teams are being briefed now on how to present the minimum.
The question that decides whether any of this matters
A right to data you have no use for is decoration. The companies that will get value from Article 3 are the ones who already know what they would do with the data if they had it: move maintenance to an independent provider on a subset of the fleet, feed machine data into their own planning models, give an insurer evidence of usage, or benchmark uptime claims against what the equipment actually reports. Each of those is a business case with an owner. None of them is currently owned by the person who signs the purchase order.
What to do before the next equipment renewal
Find the new purchases.List the connected equipment categories you expect to buy or lease in the EU over the next two years. That list, not the installed base, is where the right exists.
Pick one use case per category.Independent maintenance, internal analytics, or insurance. Without a named use, the negotiation defaults to the vendor's export portal.
Make the data dictionary a pre-contract deliverable.The seller already owes you disclosure before signature. Ask for it in a form your engineers can evaluate.
Rewrite the data-use clause.Grant the vendor what it needs to service and improve the product, and state it. Silence now works against the vendor, which is a better position than you have had.
There is one more thing worth checking, and it is less comfortable. Many BusinessInfomatics readers work for companies that also make connected products. The same article that gives your operations team a new right gives your customers the same right against you, and your customers' procurement teams will eventually read the regulation more carefully than yours has. Which side of Article 3 your company learns about first will shape how the next few years of renewals go.
Sources and notes. Regulation (EU) 2023/2854, the Data Act, applicable generally from September 12, 2025. Article 3(1), the access-by-design obligation for connected products and related services, applies to products and services placed on the EU market after September 12, 2026, including those of non-EU manufacturers; micro and small enterprises benefit from certain exemptions. Users may also require data holders to share data with third parties, and data holders may use non-personal product data only on the basis of a contract with the user; trade secrets may be protected through agreed measures and, in exceptional cases, sharing may be refused. Cloud switching charges must be removed from January 12, 2027; the Chapter IV unfair-terms rules extend to certain long-term contracts concluded on or before September 12, 2025, from September 12, 2027. The Commission's Digital Omnibus proposal would amend parts of the framework. Dates and obligations are drawn from published law-firm guidance (including Faegre Drinker and McCann FitzGerald) rather than directly from the Regulation text; scope is product-specific and member-state enforcement varies. Verify with counsel before acting. Journalism, not legal advice. Corrections welcome.



