Law & Compliance · 2026-08-23 · 14 min read

Data Act From 12 September 2026: Why the Deadline Covers Only New Products and the Real Obligation Has Applied for a Year

Michael Kaiser

Michael Kaiser

Co-Founder & Head of Systems, Vincency

12 September 2026 is in a lot of calendars right now, usually under a heading like Data Act comes into force. That heading is wrong on two counts. The regulation has been in force since January 2024 and applicable since September 2025. What happens on 12 September 2026 is narrow, and it is almost certainly not the part of the Data Act that will reach your company first.

Three dates, routinely confused

The final article of Regulation (EU) 2023/2854 sets out a staggered application, and reading it carefully answers most of the questions people are currently asking.

DateWhat appliesTo what
12 Sept 2025The regulation as a whole, including the access rights in Articles 4 and 5Every connected product, regardless of when it was placed on the market
12 Sept 2026The design obligation in Article 3(1) onlyOnly products placed on the market after that date
12 Sept 2027Chapter IV, on unfair contract termsContracts concluded before 12 September 2025 and running indefinitely or beyond that date

Read the middle row again, because it is the one that gets summarised away. The obligation under Article 3(1) applies to connected products and related services placed on the market after 12 September 2026. Your installed base is untouched by that date. And the top row is the one that matters today.

What Article 3(1) demands, and why the deadline has effectively passed

The wording is a construction requirement, not a documentation duty. Connected products must be designed and manufactured, and related services designed and provided, such that product data and related service data, including the metadata needed to interpret and use it, are by default easily, securely and free of charge accessible to the user in a comprehensive, structured, commonly used and machine-readable format, and where relevant and technically feasible directly accessible.

By default. Directly. Free of charge. Machine-readable. Those four words describe an architecture, and architecture is decided early. In machinery, a development cycle from concept to market runs somewhere between one and three years. Which means that for anything currently in that pipeline and destined for release after 12 September 2026, the decision has already been taken, correctly or otherwise. This deadline does not ask what you will do next month. It reveals what you decided last year.

That is uncomfortable but also freeing: if the answer is no, no amount of work between now and September changes the status of those products. The useful question is a different one, and it concerns the machines already out in the field.

The obligation nobody is talking about

Article 4(1) has applied since September 2025, and it covers everything, new and old alike. Where the user cannot access the data directly from the product, the data holder must make readily available data and the metadata needed to interpret it available to the user without undue delay, easily, securely, free of charge, in a comprehensive, commonly used and machine-readable format, and where relevant and technically feasible continuously and in real time.

Then comes the sentence that decides how this plays out in practice: this happens upon a simple request by electronic means, as far as technically feasible. No form. No stated reason. No negotiation. An email from a customer is enough to trigger the obligation.

And Article 5(1) extends it. At the user’s request, the data holder must make the same data available to a third party, again without undue delay, free of charge to the user, and in the same quality the data holder has. For a manufacturer with its own service business, that is the commercially sharpest edge in the regulation. The customer can direct the operating data of their machine to an independent maintenance provider. If your service margin rested on being the only party who could read the machine, that assumption expired a year ago.

Whether this concerns you at all

The definition in Article 2(5) is broad. A connected product is an item that obtains, generates or collects data about its use or environment and can transmit that product data over an electronic communications service, a physical connection or on-device access, provided its main function is not storing or processing data on behalf of someone else. That last clause excludes servers and cloud platforms. It does not exclude machines.

A machine tool with condition monitoring is covered. A commercial vehicle with telematics. A heating system with remote maintenance. A medical device that logs. A packaging line that reports cycle counts. The fact that the data is currently only read internally, or only by your own service team, changes nothing about the classification. And under Article 2(12) a user is any natural or legal person owning the product or holding temporary contractual rights to it, which puts commercial buyers and lessees squarely inside the scope.

Germany now has an authority for this

Article 40 does not set penalty levels itself. It leaves them to the member states and requires only that they be effective, proportionate and dissuasive. Germany’s implementing act was published in the Federal Law Gazette on 29 May 2026 and entered into force the next day, naming the Bundesnetzagentur as the competent authority.

For day-to-day purposes, Article 38 matters more than any fine. It gives users a right to lodge a complaint with that authority. A customer whose data request goes unanswered does not need a lawyer or a court; they need a form. That lowers the threshold for enforcement considerably compared with regimes where the only route is litigation, and it means the first contact with this regulation is more likely to arrive as a letter from Bonn than as a claim.

On waiting for the Omnibus

The Commission proposed amendments to the Data Act in November 2025 as part of the Digital Omnibus package, and the procedure in Parliament and Council is still running. Some of the proposals touch commercially sensitive parts of the regime. None of them is law.

We watched exactly this pattern with the AI Act. A softening was announced, widely reported, and taken by many as a reason to pause, and in the end only one part moved while the obligations most companies actually faced arrived on schedule. Until a change stands in the Official Journal, the text in force is the text that applies. Planning around a softening means planning around a draft.

What is worth doing in the next four weeks

  • Decide who answers the first request. An email arrives asking for machine data. Who reads it, who decides, in what timeframe? Without a named owner, “without undue delay” becomes three weeks of internal forwarding, and that alone is the breach.
  • Establish what you can actually export today. Not what the system could do in principle. Take one machine type, request its data as a customer would, and time it. That measurement is worth more than any gap analysis.
  • Look at your service contracts before someone else does. Clauses that make data access exclusive to your own service organisation are the ones that collide with Article 5. Better to find them yourself than to have a customer’s lawyer find them.
  • Separate personal from non-personal data in the export. Machine data frequently carries operator identifiers, shift patterns or badge numbers. The Data Act does not suspend the GDPR; where both apply, both apply.
  • Put the pre-contractual information from Article 3(2) into your sales documents. Type, format and estimated volume of the data, whether it is generated continuously, whether it is stored on the device or remotely, how access works. This is comparatively cheap and it is the part a customer notices first.

Conclusion

12 September 2026 is a real deadline, but a narrow one: it covers the design obligation in Article 3(1), and only for products placed on the market after that day. If your development pipeline did not account for it, September will not fix that, and pretending otherwise wastes the four weeks that remain. The obligation that reaches your installed base has been in force for a year, arrives by simple email, extends to third parties your customer names, and now has an authority behind it with a complaint form. That is the one worth preparing for, and preparing means knowing who answers, how fast, and with which file. If you want to know what your systems can actually deliver today rather than in principle, that is what a first conversation is for, and the wider budget picture is in IT strategy for the mid-market.

Frequently asked questions about the Data Act for connected products

What actually changes on 12 September 2026?

One thing only, and it is narrower than the coverage suggests. From that day the design obligation in Article 3(1) of Regulation (EU) 2023/2854 applies, and exclusively to connected products and related services placed on the market after 12 September 2026. The final article of the regulation says so verbatim. For anything that reached the market earlier, nothing changes on that day. The rest of the regulation, including the obligations that matter most in practice, has applied since 12 September 2025.

Which obligation has applied for a year, then?

The one in Article 4(1). Where a user cannot access the data directly from the product itself, the data holder must make the readily available data, together with the metadata needed to interpret it, available to the user: without undue delay, easily, securely, free of charge, in a comprehensive, commonly used and machine-readable format, and where feasible continuously and in real time. And here is the part that hurts operationally: upon a simple request by electronic means. No form, no justification, no contract negotiation. This applies to the entire installed base of connected products, not only to new ones.

Do I have to hand data to third parties as well?

Yes, if the user requests it. Article 5(1) obliges the data holder to make the data available to a third party at the user's request, likewise without undue delay, free of charge to the user, and in the same quality available to the data holder. For manufacturers with their own service business this is the commercially most sensitive point in the regulation: the customer can require that the operating data of their machine goes to an independent maintenance provider. Anyone whose service margin rested on exclusive data access should redo that calculation.

Does the Data Act apply between businesses?

Yes. Under Article 2(12) a user is any natural or legal person that owns a connected product or has been granted temporary contractual rights to use it. The commercial buyer of a machine is therefore a user exactly as a consumer is, and so is the lessee. The Data Act is not consumer law with B2B side effects; at its core it is a B2B instrument.

Which products are covered?

More than most assume. Article 2(5) defines a connected product as an item that obtains, generates or collects data concerning its use or environment and that can communicate product data via an electronic communications service, physical connection or on-device access, provided its primary function is not processing data on behalf of others. That final clause excludes servers and cloud services, not machines. A machine tool with condition monitoring falls under it, a commercial vehicle with telematics, a heating system with remote maintenance, a medical device with logging. Including cases where the data is currently only evaluated internally.

Who enforces this in Germany?

The Bundesnetzagentur. The German implementing act was published in the Federal Law Gazette on 29 May 2026 and entered into force the following day. The regulation itself does not settle penalties conclusively: Article 40 leaves them to the member states and only requires that they be effective, proportionate and dissuasive. More consequential in practice than the level of fines is Article 38, the right to lodge a complaint. A customer whose data request goes unanswered needs no court, only a form at the authority.

Is the Data Act not being softened anyway?

That is proposed, not decided. In November 2025 the Commission put forward amendments to the Data Act as part of the Digital Omnibus package, and the procedure in Parliament and Council is running. Until an amendment appears in the Official Journal, the text in force applies unchanged. The AI Act taught the same lesson: in the end only part of it moved, while the obligations most companies actually had to deal with entered into force on schedule. Planning around a softening means planning around a draft.

Sources, status and note: All provisions checked verbatim against the German text of Regulation (EU) 2023/2854 on EUR-Lex, retrieved 23 August 2026. Staggered application from the final article: the regulation applies from 12 September 2025; the obligation under Article 3(1) applies to connected products and related services placed on the market after 12 September 2026; Chapter III applies only to data-provision obligations under Union law entering into force after 12 September 2025; Chapter IV applies to contracts concluded after 12 September 2025 and from 12 September 2027 to older contracts. Article 3(1) requires design and manufacture such that data is accessible by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and where relevant and technically feasible directly. Article 4(1) requires provision without undue delay upon a simple request by electronic means. Article 5(1) extends this to third parties named by the user. Article 2(5) defines the connected product, Article 2(12) the user as any natural or legal person. Article 38 grants the right to complain, Article 40 leaves sanctions to member states with the requirement that they be effective, proportionate and dissuasive. The German implementing act is documented by the Federal Ministry: published in the Federal Law Gazette on 29 May 2026, in force the following day, Bundesnetzagentur as competent authority. Note on what is not settled: the Digital Omnibus amendments proposed in November 2025 are still in the legislative procedure and are described here as a proposal, not as law; their final content is open. The development-cycle range of one to three years for machinery is our own project experience, not a measured figure. This article states the position as of 23 August 2026 and is general information, not legal advice on an individual case. Transparency: Michael Kaiser is a co-founder of Vincency, which advises companies on the systems work this article discusses.