Data Act Article 3 explained: making product data accessible
Data Act Article 3: Making Product Data Accessible to Users
Article 3 of the EU Data Act introduces a fundamental shift in how manufacturers and service providers must handle data generated by connected products. At its core, this article requires companies to automatically give users access to the data their devices collect—without charging fees and in formats that are easy for both people and computer systems to understand and use.
This requirement applies to any company that sells a connected product or provides related services in the EU market. Whether you manufacture smart home devices, industrial equipment, automotive systems, or wearables, Article 3 establishes clear obligations around data transparency, accessibility, and user control that you must meet before and after a customer makes a purchase.
What “Product Data” and “Service Data” Mean Under Article 3
The article distinguishes between two types of information you must make accessible:
- Product data is information generated by or related to a connected device itself—sensor readings, usage patterns, performance metrics, error logs, and any other technical data the device produces or collects during operation.
- Service data is information collected when you provide services related to that product, such as maintenance, updates, diagnostics, or customer support. This includes data about how the service is delivered and what information you need to deliver it.
The key point is that users must be able to access both categories easily. This has direct implications for how you design your product infrastructure and how you structure contracts with customers and any third-party service providers involved in your supply chain.
Pre-Purchase Transparency: What You Must Disclose
Before a customer buys a connected product or signs up for a related service, Article 3 requires you to provide clear, accessible information about data practices. This is not a simple privacy notice tucked into terms and conditions—it must be straightforward enough that a non-technical person can understand what they’re agreeing to.
Specifically, you must explain:
- What types of data your device or service collects
- How much data is involved (volume or frequency of collection)
- Whether data collection happens in real-time or at intervals
- Where the data is stored—on the device itself, on your company’s servers, or elsewhere
- How long you keep the data before deleting or archiving it
- Any other relevant details about data handling that affect how users can access or control their information
This transparency requirement shifts responsibility onto you to communicate clearly about data practices upfront, not after the sale is complete. It also means you need to audit your actual data flows to ensure you can accurately describe them to customers.
Service Provider Obligations and Third-Party Access
If you work with service providers—contractors, cloud hosting providers, data analytics firms, or other partners—Article 3 requires you to be explicit about what those relationships mean for user data.
You must tell users:
- What data service providers can access and use
- How long they can retain that data
- Whether they can share it with other organisations and under what conditions
- The specific terms that govern the data-sharing arrangement
This means you cannot simply hand customer data to third parties without clear contractual terms and user notification. The regulation treats data access as something users should control or at least understand, rather than as a hidden benefit of your business model.
User Access Rights: How People Get Their Data
Beyond pre-purchase disclosure, Article 3 establishes practical rights for users to access and control their data. You must tell users:
- Who holds their data and how to contact that person or department
- How to request a copy of their data
- How to ask for their data to be shared with third parties (such as repairers, competitors, or researchers)
- How to stop data sharing or request deletion
These aren’t optional features—they’re core obligations. Users need to understand that they can exercise control over their data, and you must provide the practical means to do so.
Technical and Format Requirements
Article 3 explicitly requires that product and service data be provided in a structured, machine-readable format. This means data cannot simply be a PDF printout or a web page; it must be in a format that computer systems can parse and process automatically.
This requirement is designed to support the Data Act and portability, enabling users to move their data between services, share it with repairers or researchers, or feed it into their own analysis tools without manual re-entry or conversion.
Your obligations include:
- Specifying the technical means users can use to access their data (API, download link, automated export, etc.)
- Defining quality-of-service standards for how quickly data is delivered, how often it can be requested, and system uptime expectations
- Ensuring the format includes necessary metadata so the data is understandable and usable
- Making retrieval and erasure requests practical and timely
These technical requirements mean you cannot avoid the obligation by making data access slow, expensive, or technically burdensome.
Contract Terms and User Rights
Article 3 also requires you to be transparent about the contractual arrangements affecting data access. Before purchase, users must learn:
- Whether your company or someone else holds trade secrets or intellectual property related to the data or the device
- How long the contract lasts and what happens when it ends
- How either party can terminate the arrangement
- Users’ right to lodge complaints with regulatory authorities if they believe you’re not complying
This transparency is meant to prevent scenarios where users discover, after purchase, that they cannot access their own data because of contract terms they didn’t understand.
Business Implications and Compliance Priorities
Meeting Article 3 requires significant operational changes for most organisations:
- Data architecture redesign: You must map all data flows, identify where data is stored, and ensure you can retrieve it in machine-readable formats on demand.
- Contract revision: Service agreements, privacy notices, and customer terms must be rewritten to meet the transparency and disclosure requirements.
- API and system development: You need technical infrastructure to deliver data to users in structured formats, likely including APIs or automated export systems.
- Operational procedures: Customer-facing teams must be equipped to handle data access requests, deletion requests, and questions about data practices.
- Audit and governance: You should establish processes to regularly verify that your disclosures are accurate and that your systems deliver on the promised data access capabilities.
These obligations also align with broader EU initiatives like the Digital Product Passport, which aims to give users and regulators clearer visibility into product information throughout a product’s lifecycle.
Frequently Asked Questions
Do I have to provide data for free?
Yes. Article 3 explicitly states that access to product and service data must be provided at no cost to the user. You cannot charge for data access, retrieval, or export services.
What if I claim the data contains trade secrets?
You must disclose upfront if trade secrets or intellectual property claims apply to any data. However, this does not exempt you from providing the data itself to users. The regulation assumes that users have a right to their own data even if some elements involve proprietary business information. You cannot use intellectual property claims as a blanket reason to deny access.
Can I delay or make data access inconvenient?
No. Article 3 requires that technical means, quality of service standards, and retrieval timelines be clearly defined and practical. Making data access slow, cumbersome, or unreliable would likely violate the regulation.
Do I need to comply if I only sell outside the EU?
If you sell connected products or services to customers in the EU, Article 3 applies to those offerings. The regulation covers any manufacturer or service provider offering products or services to EU users.
Does this mean competitors can access user data?
Users can request that you share their data with third parties, including competitors. However, the user must initiate the request. You don’t automatically share data with competitors; users control whether and with whom their data is shared.
Official text (Data Act Article 3): “Product data and related service data are easily, securely, free of charge, in a structured, commonly used and machine-readable format” — Regulation (EU) 2023/2854, EUR-Lex
Portable passports, no lock-in
GovGDS distributes DPPs on open standards, aligned with the Data Act on data portability.
Related: The EU Data Act & portability · What is a Digital Product Passport?
