The case, explained
European Data Act: Access by Design Obligations for IoT
6 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
September 12, 2026, marks a watershed date for the Digital Single Market: the «Access by Design» obligation under EU Regulation 2023/2854, known as the Data Act, officially comes into force. According to reports from specialized press, such as Agenda Digitale and industry publications, this deadline forces manufacturers of connected objects (IoT) to radically rethink their product architecture to ensure users have immediate and free access to generated data. The matter unfolds in a period of high tension between the European push for data sovereignty and resistance from companies concerned about protecting their know-how. While manufacturers raise technical objections, the regulatory framework opens up unprecedented litigation scenarios that we will explore through the twin case of Gaio Sventura, struggling with a smart device that «talks» either too much or too little.

In brief
The article analyzes the Access by Design obligation introduced by the Data Act, requiring IoT manufacturers to make data accessible by default starting in 2026. It explores the balance between user access rights and trade secret protection (Trade Secret Handbrake), examining administrative sanctions and civil consequences for unfair contractual terms. A practical case illustrates operational challenges for SMEs and the importance of compliant-by-design engineering.
The facts
The case concerns the implementation of Regulation (EU) 2023/2854, which entered into force in 2024, specifically focusing on the September 12, 2026 deadline. According to reports from publications like Agenda Digitale and Focus Namirial IT, manufacturers of connected devices are currently in a phase of mandatory compliance. The heart of the dispute is not a single trial, but a systemic conflict: the obligation to design hardware and software so that data is accessible «by default».
Currently, the process is at the stage of regulatory dialogues and initial opinions from supervisory authorities, including the Data Protection Authority. Many companies have raised objections regarding the alleged technical impossibility of separating raw data, belonging to the user, from inferred data, which often incorporates protected algorithms. A season of preventive litigation is emerging to define the limits of EU-imposed transparency versus the right to industrial confidentiality.

The rules in play
- Article 3 of the Data Act imposes the Access by Design obligation, establishing that products must be designed to make generated data directly accessible to the user.
- Articles 4 and 5 regulate data sharing, requiring the holder to provide information to the user or authorized third parties without undue delay.
- Article 4(3) introduces the so-called Trade Secret Handbrake, allowing restricted sharing to protect trade secrets, but only subject to strict confidentiality measures.
- Article 40 establishes severe financial penalties, modeled on the GDPR, which can reach 20 million euros or 4% of total annual global turnover.
What the jurisprudence says
Although specific jurisprudence on the Data Act is still developing, European Union case law has already established fundamental guidelines. The Court of Justice of the European Union (CJEU) has clarified that trade secrets do not constitute an absolute right and cannot be invoked to systematically deny access to data or algorithmic logic, especially when access is intended to ensure competition or user rights.
The established orientation indicates that balancing transparency and intellectual property must be resolved through the principle of proportionality. In other words, the manufacturer must demonstrate a risk of serious economic harm to deny data access, as a generic designation of secrecy is insufficient. The protection of know-how thus shifts from data secrecy to protecting the processing method, preserving innovation without paralyzing the IoT ecosystem.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- Contractual review: it is essential to remove clauses claiming exclusive ownership of user-generated data, as they are susceptible to being deemed unfair.
- Tech-legal audit: lawyers must collaborate with technical teams to distinguish raw data from inferred data before disputes arise.
- Trade secret strategy: protocols for protected disclosure must be drafted to comply with Data Act obligations without exposing source code or proprietary formulas.
- Regulatory monitoring: following the evolving guidelines of national Authorities is necessary to establish the threshold of serious economic damage required for a lawful denial.
References: Regolamento (UE) 2023/2854 (Data Act)Direttiva (UE) 2016/943 (Segreti Commerciali)Regolamento (UE) 2016/679 (GDPR)
Related cases

Frequently asked questions
Which devices are subject to the Access by Design obligation?
All connected products capable of collecting or generating data about their operation or environment, including smart appliances, industrial machinery, and vehicles, placed on the EU market from September 12, 2026.
Can data access be denied by invoking trade secrets?
Yes, but only in exceptional cases and by proving a serious risk of economic damage; the data holder must still seek a confidentiality agreement and cannot issue an absolute and generic refusal.
What happens if a contract limits the user's right to data?
Contractual clauses that prevent or unreasonably restrict access and portability rights under the Data Act are null or unenforceable, in both B2B and B2C relationships.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free