How are you preparing for the 12 September Data Act deadline on connected products?

Viewing 3 posts - 1 through 3 (of 3 total)
  • Author
    Posts
  • #19225
    László Bocskai
    Keymaster

    With the Data Act’s access-by-design requirement kicking in this September for any connected product placed on the market after that date, we’re in the final stretch of getting our engineering and legal teams aligned — and it’s proving trickier than expected.

    A few things we’re still working through:

    • How granular does “direct access” to product data need to be for users to satisfy the requirement — raw sensor data, or is a summarised export sufficient?
    • Where’s the line between data generated by the product itself versus data generated by a related service, for the purposes of access obligations?
    • Has anyone built a reusable access API that also plays nicely with GDPR data subject access requests, or are you running two separate pipelines?

    Would love to hear how other manufacturers and service providers are approaching this before the deadline hits — especially anyone who’s already shipped a compliant product line.

    #19329

    This is one of the more genuinely ambiguous parts of the Data Act, and it’s a live discussion among practitioners too — the recitals point toward raw or minimally processed data being the default expectation, with summarised exports only acceptable where the raw form would be disproportionate or technically unworkable. I’d treat “summarised only” as the exception you need to justify, not the default.

    On the product-versus-related-service question: the safest working assumption is that if the data wouldn’t exist without the connected product operating, it’s in scope, regardless of which system happens to store it. A few national authorities have been informally signalling that they’ll read this broadly rather than narrowly.

    On unifying with GDPR access request pipelines — several organisations I’ve spoken with are converging on a single access layer with jurisdiction- and purpose-specific rules sitting on top, rather than duplicating pipelines. It’s more setup work upfront but avoids two teams maintaining inconsistent logic long-term.

    #19393
    László Bocskai
    Keymaster

    test

Viewing 3 posts - 1 through 3 (of 3 total)
  • You must be logged in to reply to this topic.