Data Act, User Access to Connected-Product Data and Sharing with Third Parties (Articles 3 to 5)
Regulation (EU) 2023/2854, Arts. 3-5
In force since .
A data subject rights rule binding public and private bodies.
- Obligation class
- Data subject rights, Disclosure
As of .
What it requires
- For connected products, and the services related to them, placed on the market after (Article 50), design and manufacture the connected product, and design and provide the related service, so that product data and related service data, including the relevant metadata necessary to interpret and use those data, are by default easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, directly accessible to the user (Article 3(1)).
- Before concluding a contract for the purchase, rent or lease of a connected product, and as the seller, rentor or lessor (which may be the manufacturer), give the user in a clear and comprehensible manner at least the type, format and estimated volume of product data the product is capable of generating, whether it is capable of generating data continuously and in real-time, whether it is capable of storing data on-device or on a remote server (with the intended duration of retention, where applicable), and how the user may access, retrieve or, where relevant, erase the data, including the technical means and the terms of use and quality of service (Article 3(2)).
- Before concluding a contract for the provision of a related service, and as the provider of the related service, give the user in a clear and comprehensible manner at least the information listed in Article 3(3), points (a) to (i), among them the nature, estimated volume and collection frequency of the product data the prospective data holder is expected to obtain, whether it expects to use readily available data itself and for which purposes, how the user can request that the data are shared with a third party, the user's right to lodge a complaint with the competent authority designated under Article 37, and the duration of the contract and the arrangements for terminating it (Article 3(3)).
- Where data cannot be directly accessed by the user from the connected product or related service, make readily available data, as well as the relevant metadata necessary to interpret and use those data, accessible to the user without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time, on the basis of a simple request through electronic means where technically feasible (Article 4(1)).
- Do not make the exercise of choices or rights under Article 4 by the user unduly difficult, including by offering choices to the user in a non-neutral manner or by subverting or impairing the autonomy, decision-making or choices of the user via the structure, design, function or manner of operation of a user digital interface or a part thereof (Article 4(4)).
- To verify whether a person qualifies as a user, do not require that person to provide any information beyond what is necessary, and do not keep any information, in particular log data, on the user's access to the data requested beyond what is necessary for the sound execution of the user's access request and for the security and maintenance of the data infrastructure (Article 4(5)).
- Identify the data protected as trade secrets, including in the relevant metadata, and agree with the user the proportionate technical and organizational measures necessary to preserve the confidentiality of the shared data, in particular in relation to third parties (Article 4(6)).
- Where the data holder refuses to share data pursuant to Article 4, notify the competent authority designated under Article 37 (Article 4(2)); where the data holder withholds or suspends the sharing of data identified as trade secrets (Article 4(7)), or refuses a request on the ground of serious economic damage from the disclosure of trade secrets (Article 4(8)), also give the user a duly substantiated decision in writing without undue delay (Article 4(7) and (8)).
- Where the user is not the data subject whose personal data is requested, make personal data generated by the use of a connected product or related service available to the user only where there is a valid legal basis for processing under Article 6 of Regulation (EU) 2016/679 and, where relevant, the conditions of Article 9 of that Regulation and of Article 5(3) of Directive 2002/58/EC are fulfilled (Article 4(12)).
- Use readily available data that is non-personal data only on the basis of a contract with the user, and do not use it to derive insights about the economic situation, assets and production methods of, or the use by, the user in any other manner that could undermine the commercial position of that user on the markets in which the user is active (Article 4(13)).
- Do not make non-personal product data available to third parties for commercial or non-commercial purposes other than the fulfillment of the data holder's contract with the user, and where relevant contractually bind third parties not to further share the data received (Article 4(14)).
- Upon request by a user, or by a party acting on behalf of a user, make readily available data, as well as the relevant metadata necessary to interpret and use those data, available to a third party without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge to the user, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time, in accordance with Articles 8 and 9 (Article 5(1)).
- Treat an undertaking designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925 as not an eligible third party under Article 5 (Article 5(3)).
- To verify whether a person qualifies as a user or as a third party, do not require that person to provide any information beyond what is necessary, and do not keep any information on the third party's access to the data requested beyond what is necessary for the sound execution of the third party's access request and for the security and maintenance of the data infrastructure (Article 5(4)).
- Do not use any readily available data to derive insights about the economic situation, assets and production methods of, or the use by, the third party in any other manner that could undermine the commercial position of the third party on the markets in which the third party is active, unless the third party has given permission to such use and has the technical possibility to easily withdraw that permission at any time (Article 5(6)).
- Where the user is not the data subject whose personal data is requested, make personal data generated by the use of a connected product or related service available to the third party only where there is a valid legal basis for processing under Article 6 of Regulation (EU) 2016/679 and, where relevant, the conditions of Article 9 of that Regulation and of Article 5(3) of Directive 2002/58/EC are fulfilled (Article 5(7)).
- Do not let a failure to agree with the third party on arrangements for transmitting the data hinder, prevent or interfere with the exercise of the rights of the data subject under Regulation (EU) 2016/679, in particular the right to data portability under Article 20 of that Regulation (Article 5(8)).
- Identify the data protected as trade secrets, including in the relevant metadata, agree with the third party all proportionate technical and organizational measures necessary to preserve the confidentiality of the shared data, and disclose trade secrets to third parties only to the extent that disclosure is strictly necessary to fulfill the purpose agreed between the user and the third party (Article 5(9)).
- Where the data holder withholds or suspends the sharing of data identified as trade secrets (Article 5(10)), or refuses a request on the ground of serious economic damage from the disclosure of trade secrets (Article 5(11)), give the third party a duly substantiated decision in writing without undue delay and notify the competent authority designated under Article 37 (Article 5(10) and (11)).
If you get it wrong
Private right of actionNo
Penalty structure
Article 40(4) of Regulation (EU) 2023/2854 lets the supervisory authorities responsible for monitoring Regulation (EU) 2016/679 impose, within their scope of competence, administrative fines in accordance with Article 83 of that Regulation and up to the amount referred to in Article 83(5), for infringements of the obligations in Chapter II; Article 37(3) makes those authorities responsible for monitoring the Regulation insofar as the protection of personal data is concerned. Article 83(5) of Regulation (EU) 2016/679 sets that amount at EUR 20,000,000 or, for an undertaking, 4 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher. The Data Act does not print the amount, so the pin sits on Article 83(5) of Regulation (EU) 2016/679. The fine is coded for the personal-data route only: Article 40(1) leaves the rules on penalties applicable to infringements of the Regulation to the Member States and states no figure, so no Member State penalty is coded.
- Rule
- Higher of
- As of
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
The competent authorities that each Member State designates to be responsible for the application and enforcement of the Regulation (Article 37(1)); insofar as the protection of personal data is concerned, the supervisory authorities responsible for monitoring the application of Regulation (EU) 2016/679 (Article 37(3)); an entity falls under the competence of the Member State where it is established (Article 37(10)).
What this law does
Article 1(5) provides that, insofar as users are data subjects, the rights laid down in Chapter II of the Regulation complement the rights of access by data subjects and rights to data portability under Articles 15 and 20 of Regulation (EU) 2016/679.
Article 1(5) provides that the Regulation is without prejudice to Union and national law on the protection of personal data, which applies to personal data processed in connection with the rights and obligations laid down in the Regulation, in particular Regulation (EU) 2016/679 and Directive 2002/58/EC.
Article 1(5) adds that, in the event of a conflict between the Regulation and Union law on the protection of personal data or privacy, or national legislation adopted in accordance with such Union law, the relevant Union or national law on the protection of personal data or privacy prevails.
Article 1(2) provides that the Regulation covers personal and non-personal data, and that point (a) applies Chapter II to data, with the exception of content, concerning the performance, use and environment of connected products and related services. Article 1(3), point (a), applies the Regulation to manufacturers of connected products placed on the market in the Union and providers of related services, irrespective of the place of establishment of those manufacturers and providers.
Article 1(3), point (c), applies the Regulation to data holders, irrespective of their place of establishment, that make data available to data recipients in the Union.
Article 2, point (5), defines a connected product as an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data via an electronic communications service, physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of any party other than the user.
Article 2, point (6), defines a related service as a digital service, other than an electronic communications service, including software, which is connected with the product at the time of the purchase, rent or lease in such a way that its absence would prevent the connected product from performing one or more of its functions, or which is subsequently connected to the product by the manufacturer or a third party to add to, update or adapt the functions of the connected product.
Article 2, point (12), defines a user as a natural or legal person that owns a connected product or to whom temporary rights to use that connected product have been contractually transferred, or that receives related services.
Article 2, point (13), defines a data holder as a natural or legal person that has the right or obligation, in accordance with the Regulation, applicable Union law or national legislation adopted in accordance with Union law, to use and make available data, including, where contractually agreed, product data or related service data which it has retrieved or generated during the provision of a related service.
Article 2, point (17), defines readily available data as product data and related service data that a data holder lawfully obtains or can lawfully obtain from the connected product or related service, without disproportionate effort going beyond a simple operation.
Article 3(1) provides that connected products shall be designed and manufactured, and related services designed and provided, in such a manner that product data and related service data, including the relevant metadata necessary to interpret and use those data, are, by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user.
Article 3(2) requires the seller, rentor or lessor of a connected product, which may be the manufacturer, to provide the user with at least the information listed in points (a) to (d), in a clear and comprehensible manner, before concluding a contract for the purchase, rent or lease of the product.
Article 3(3) requires the provider of a related service to provide the user with at least the information listed in points (a) to (i), in a clear and comprehensible manner, before concluding a contract for the provision of the related service.
Article 4(1) requires data holders, where data cannot be directly accessed by the user from the connected product or related service, to make readily available data, as well as the relevant metadata necessary to interpret and use those data, accessible to the user without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time.
Article 4(12) provides that, where the user is not the data subject whose personal data is requested, personal data generated by the use of a connected product or related service shall be made available by the data holder to the user only where there is a valid legal basis for processing under Article 6 of Regulation (EU) 2016/679 and, where relevant, the conditions of Article 9 of that Regulation and of Article 5(3) of Directive 2002/58/EC are fulfilled.
Article 5(1) requires the data holder, upon request by a user or by a party acting on behalf of a user, to make readily available data, as well as the relevant metadata necessary to interpret and use those data, available to a third party without undue delay, of the same quality as is available to the data holder, easily, securely, free of charge to the user, in a comprehensive, structured, commonly used and machine-readable format and, where relevant and technically feasible, continuously and in real-time.
Article 5(2) provides that Article 5(1) does not apply to readily available data in the context of the testing of new connected products, substances or processes that are not yet placed on the market, unless their use by a third party is contractually permitted. Article 5(3) provides that an undertaking designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925 shall not be an eligible third party under Article 5.
Article 7(1) provides that the obligations of Chapter II do not apply to data generated through the use of connected products manufactured or designed, or related services provided, by a microenterprise or a small enterprise, provided that the enterprise does not have a partner enterprise or a linked enterprise within the meaning of Article 3 of the Annex to Recommendation 2003/361/EC that does not qualify as a microenterprise or a small enterprise and is not subcontracted to manufacture or design a connected product or to provide a related service.
Article 7(1) applies the same exclusion to data generated through the use of connected products manufactured by, or related services provided by, an enterprise that has qualified as a medium-sized enterprise for less than one year, and to connected products for one year after the date on which a medium-sized enterprise placed them on the market.
Article 7(2) provides that any contractual term which, to the detriment of the user, excludes the application of, derogates from or varies the effect of the user's rights under Chapter II shall not be binding on the user.
Article 38(1) gives natural and legal persons the right to lodge a complaint, individually or collectively, with the relevant competent authority in the Member State of their habitual residence, place of work or establishment if they consider that their rights under the Regulation have been infringed.
Article 40(1) requires Member States to lay down the rules on penalties applicable to infringements of the Regulation, and provides that the penalties shall be effective, proportionate and dissuasive.
Article 40(4) provides that, for infringements of the obligations laid down in Chapters II, III and V, the supervisory authorities responsible for monitoring the application of Regulation (EU) 2016/679 may within their scope of competence impose administrative fines in accordance with Article 83 of that Regulation and up to the amount referred to in Article 83(5) of that Regulation.
Article 50 provides that the obligation resulting from Article 3(1) applies to connected products and the services related to them placed on the market after .
When LexLint raises it
When your app profile says your app distributes a software product or ships a mobile app.