Data Act Article 4 explained: rights and obligations over product data

Data Act Article 4: Balancing data access rights with business protection

The EU Data Act (Regulation (EU) 2023/2854) introduces a fundamental shift in how companies handle product data. Article 4 establishes clear rights for users to access data generated by connected products while also protecting legitimate business interests. For manufacturers and service providers, this means building data-sharing systems that are both accessible and secure.

At its core, Article 4 requires data holders—typically manufacturers or service providers—to provide users with straightforward access to product data. This isn’t optional or conditional on lengthy negotiations. The data must be provided without undue delay, at no charge, and in a format that computers can read and process automatically. This principle supports the Data Act and portability, enabling users to move their data between services and make informed decisions about their products.

What data holders must provide and how

When a user requests access to product data, companies must deliver it in a structured, machine-readable format with accompanying metadata—essentially the information about the information. Machine-readable means data in a format that systems can interpret without human intervention, rather than a PDF or printed document. This supports interoperability and allows users to analyze, compare, or transfer data efficiently.

The requirement applies to both direct product data (how the product performs, its technical specifications, energy consumption, maintenance history) and related service data (information from repair services, warranty claims, or connected services). For companies managing Digital Product Passport systems, this aligns with the structured data formats already required for passport information.

Speed matters too. “Without undue delay” means companies cannot indefinitely postpone providing access as a negotiating tactic. While the regulation doesn’t specify an exact deadline, the expectation is that access should be granted promptly after a valid request—typically within weeks rather than months.

When companies can restrict or refuse access

The Data Act recognizes that not all data can be shared immediately and unconditionally. Data holders can restrict access when doing so is genuinely necessary to protect:

  • Security of systems or networks
  • Physical safety of people or property
  • Public health or environmental protection
  • Legal compliance under applicable EU or national law

These restrictions must be based on real, documented risks—not speculation or general anxiety about data sharing. A manufacturer cannot simply claim that sharing data “might” create security problems. The refusal must be justified under specific legal grounds and be proportionate to the actual risk.

If a company refuses a data access request, the user has recourse. They can file a complaint with regulatory authorities or request a dispute resolution process through third-party settlement bodies. This means companies cannot refuse arbitrarily; they must be prepared to explain and defend their decision.

Protecting trade secrets through agreement

Article 4 acknowledges that some product data contains commercially sensitive information—trade secrets, proprietary formulas, or business-critical insights. Companies are not forced to expose these unprotected. Instead, they can share trade secret data with users, but only if both parties implement appropriate confidentiality measures first.

This works through documented agreements. Before sharing sensitive data, the data holder and user should establish a confidentiality agreement that specifies:

  • Which data is considered confidential
  • How the user must handle, store, and protect it
  • Technical safeguards required (encryption, access controls)
  • Permitted uses of the data
  • Duration of the confidentiality obligation

If the user agrees to these terms and implements the required protections, the data holder can provide the sensitive information. The confidentiality agreement creates a binding framework that protects the company’s intellectual property while still enabling legitimate data access.

When data holders can withhold trade secret information

Even with a confidentiality framework in place, data holders retain the right to withhold trade secret data in two specific scenarios:

  • The user fails to implement or maintain the agreed-upon confidentiality measures. If a user signs an agreement but doesn’t actually implement the required technical safeguards or violates confidentiality terms, the data holder can refuse continued access.
  • Disclosure would cause demonstrable, serious economic damage. If the data holder can prove that sharing the data would result in substantial, measurable financial harm despite confidentiality protections, access can be denied.

These exceptions require documentation. Companies should keep records showing what protections were required, whether the user implemented them, and any evidence of attempted breaches. This supports any future challenge to the withholding decision.

Controlling user access logs and data about users

A less obvious but important requirement: data holders cannot collect or retain excessive logs of user access behavior. They can record access for legitimate security purposes (detecting intrusions, preventing unauthorized access) and for service delivery (understanding how many users access the system to plan capacity). Beyond that, retaining detailed logs of who accessed what, when, and how often is not permitted.

This reflects a wider principle in the Data Act: data holders should not use the data-sharing obligation as an opportunity to gather intelligence about users. Access logs should be retained only as long as needed for the stated security or service purpose, then deleted.

Practical implications for connected product manufacturers

For companies manufacturing connected products or managing product data systems, Article 4 creates operational requirements:

  • Build accessible systems: Invest in APIs, data export functions, or portals that allow users to retrieve their product data in standard, machine-readable formats (such as EPCIS 2.0 for supply chain data or other relevant schemas).
  • Develop clear data access policies: Document which data users can access, what constitutes a valid request, and your expected response time.
  • Create confidentiality templates: Prepare standard confidentiality agreements for users requesting access to trade secret data, specifying required protections and acceptable uses.
  • Implement technical safeguards: Use encryption, role-based access controls, and audit trails to protect sensitive data shared under confidentiality agreements.
  • Establish security protocols: Clearly document security and safety-related reasons for any data access restrictions, so refusals can be justified if challenged.
  • Manage access logs appropriately: Audit your logging practices to ensure you’re not retaining excessive user behavior data beyond security and service delivery needs.

Frequently asked questions

  • Does Article 4 apply to all product data? It applies to product-generated data and related service data from connected products. Non-connected products and purely historical records may fall outside scope, but regulatory guidance continues to evolve.
  • Can we charge users for data access? No. Article 4 requires access to be free of charge. However, costs for providing data in a specific technical format or through specialized delivery channels may be clarified further in implementing guidance.
  • What if a user asks for data in a format we don’t currently support? You must provide data in a machine-readable format. If you don’t have the technical capability to export in the user’s requested format, working with standards like GS1 or EPCIS 2.0 helps ensure compatibility without building endless custom exports.
  • How long should we keep access logs? Only as long as needed for the specific security or service purpose. If logs are not actively needed, delete them. Document your retention policy and the security/service justification for the periods you do retain.
  • What counts as “serious economic damage” justifying trade secret withholding? This should be substantial, measurable harm—not potential or speculative loss. Document the basis for any such claim carefully, as it may be challenged through dispute resolution.

Official text (Data Act Article 4): “data holders shall make readily available data accessible to user without undue delay, free of charge, in machine-readable format” — Regulation (EU) 2023/2854, EUR-Lex

Portable passports, no lock-in

GovGDS distributes DPPs on open standards, aligned with the Data Act on data portability.

Request a demo →

Related: The EU Data Act & portability · What is a Digital Product Passport?

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *