- This topic has 3 replies, 2 voices, and was last updated 1 week ago by László Bocskai.
-
AuthorPosts
-
June 12, 2026 at 11:56 pm #19225László BocskaiKeymaster
With the Data Act’s access-by-design requirement kicking in this September for any connected product placed on the market after that date, we’re in the final stretch of getting our engineering and legal teams aligned — and it’s proving trickier than expected.
A few things we’re still working through:
- How granular does “direct access” to product data need to be for users to satisfy the requirement — raw sensor data, or is a summarised export sufficient?
- Where’s the line between data generated by the product itself versus data generated by a related service, for the purposes of access obligations?
- Has anyone built a reusable access API that also plays nicely with GDPR data subject access requests, or are you running two separate pipelines?
Would love to hear how other manufacturers and service providers are approaching this before the deadline hits — especially anyone who’s already shipped a compliant product line.
July 30, 2026 at 4:33 pm #19329Marcu-Andrei SolomonParticipantThis is one of the more genuinely ambiguous parts of the Data Act, and it’s a live discussion among practitioners too — the recitals point toward raw or minimally processed data being the default expectation, with summarised exports only acceptable where the raw form would be disproportionate or technically unworkable. I’d treat “summarised only” as the exception you need to justify, not the default.
On the product-versus-related-service question: the safest working assumption is that if the data wouldn’t exist without the connected product operating, it’s in scope, regardless of which system happens to store it. A few national authorities have been informally signalling that they’ll read this broadly rather than narrowly.
On unifying with GDPR access request pipelines — several organisations I’ve spoken with are converging on a single access layer with jurisdiction- and purpose-specific rules sitting on top, rather than duplicating pipelines. It’s more setup work upfront but avoids two teams maintaining inconsistent logic long-term.
August 6, 2026 at 1:14 pm #19393László BocskaiKeymastertest
-
AuthorPosts
- You must be logged in to reply to this topic.
