The case, explained

European Data Act: Access by Design Obligations for IoT

6 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa

Starting from September 2025, the Internet of Things (IoT) sector will undergo a radical transformation with the full applicability of Regulation (EU) 2023/2854, known as the Data Act. As highlighted by the specialized press, compliance efforts are bringing to light the operational complexity of the «Access by Design» principle, which requires manufacturers to design devices so that generated data are directly and immediately accessible to the user. The core issue addressed in this article concerns the delicate balance between the user's right to access data generated through product use and the manufacturer's right to protect its industrial know-how. While other aspects concerning data portability and abuse of economic dependence are examined in dedicated articles within this column, this piece analyzes how product design must comply with specific legal mandates to avoid sanctions and litigation. Through the examination of the twin case, we will explore the practical impact of these rules on small and medium-sized enterprises.

European Data Act: Access by Design Obligations for IoT

In brief

The article analyzes the «Access by Design» obligation introduced by the Data Act (EU Regulation 2023/2854). It focuses on the balance between the IoT user's data access rights and the protection of manufacturers' trade secrets. Article 3 of the Regulation and the sanctions for lack of technological adaptation are examined, illustrating through a practical case the operational challenges for companies and the defensive strategies available when balancing competing interests.

  1. The fact

    According to reporting by outlets such as Agenda Digitale and Focus Namirial IT, the upcoming full application of the Data Act in September 2025 is generating intense debate regarding the design standards of smart devices. The matter stems from the adoption of Regulation (EU) 2023/2854, which mandates that every connected product be manufactured to ensure data accessibility «by default». The current phase is characterized by operational preparation and the assessment of potential enforcement actions by national supervisory authorities regarding the inadequacy of the access interfaces provided by manufacturers.

    Reports indicate growing concern among industrial machinery manufacturers, who fear that unconditioned access to data streams could expose their proprietary optimization algorithms to competitors. At present, the situation involves risk assessment and potential future actions before Regional Administrative Courts to challenge guidance documents regarding the trade secret exception. Industry observers highlight that adapting software architecture within the prescribed deadlines is revealing structural criticalities in pre-existing IoT production lines.

  2. The norms at play

    The relevant regulatory framework centers on Regulation (EU) 2023/2854.

    1. Article 3 (Access by Design) establishes the duty to design products so that data are easily accessible to the user; non-compliance prevents the product from being marketed within the European Economic Area.
    2. Article 4 governs the user's right to access and use generated data, obligating the data holder to provide them free of charge and without undue delay.
    3. Article 8 sets out the balancing test with trade secret protection, allowing the holder to refuse access only upon proving a risk of serious economic harm and following notification to the competent authority.
    4. Directive (EU) 2016/943 defines the legal requirements for trade secret status, requiring reasonable secrecy measures and intrinsic commercial value.
  3. What the jurisprudence says

    Pending direct judicial interpretation of the Data Act, European jurisprudence has established firm principles in analogous regulatory contexts. The CJEU has held that statutory transparency and data-sharing obligations prevail over generic claims of commercial secrecy, unless the manufacturer specifically proves that disclosure would destroy the core value of its intellectual property. European and national courts have further clarified that trade secret protection cannot create an informational monopoly over raw data, as legal protection attaches to inventive processing rather than data generated by mere mechanical operation. Furthermore, established case law requires that exceptions to data access rights be interpreted restrictively and proportionately to the goal of protecting proprietary know-how.

  4. Analysis drafted and verified with edit.legal

    To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.

    Try edit.legal AI
  5. What it teaches professionals

    1. Revision of IoT procurement contracts to include precise provisions governing the format and availability of generated data.
    2. Implementation of internal compliance protocols to classify trade secrets under Directive (EU) 2016/943 standards, preventing generic refusals that could trigger regulatory enforcement.
    3. Integration of preventive legal and technical counsel during product development («Legal by Design») to ensure structural segregation between proprietary algorithms and user-accessible data streams.

References: Regolamento (UE) 2023/2854Direttiva (UE) 2016/943Principio di prevalenza degli obblighi di trasparenza previsti da norme di settore sui segreti commerciali

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAMContent drafted with AI support and subject to editorial source checks. Despite these controls, inaccuracies may remain: reports and rectification requests are welcome. Report a correction

Frequently asked questions

What happens if an IoT device purchased before 2025 does not allow data access?

The design obligation applies to products placed on the market after the Regulation's application date; for older devices, direct technical access may not be legally required.

Can the manufacturer charge a fee to provide data to the user?

No, the Data Act provides that access to generated data must be free of charge for the end user, although reasonable compensation may be charged for data sharing with third parties.

How can a company prove that data is a trade secret?

It must prove that the information is secret, derives commercial value from being secret, and is subject to reasonable technical, legal, and operational protection measures.

Verified legal research and drafting with edit.legal

Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.

Try edit.legal for free