Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page

Last updated: September 2026

<

div style=”background:#f0f7ff;border-left:5px solid #2563eb;padding:18px 22px;border-radius:8px;margin-bottom:32px;color:#1e3a5f”>
⚑ TL;DR
Starting September 12, 2026, the EU Data Act’s “access by design” obligation becomes mandatory: new connected products and related services placed on the EU market must let users access their own product data easily, securely, and free of charge by default. According to Wilson Sonsini and Lexology, Germany, Finland, the Netherlands, and Poland have already adopted implementing legislation with fines up to 4% of annual EU turnover. This piece explains who is affected, what “by design” actually requires, and the concrete steps legal and compliance teams should take before enforcement scrutiny increases.

The EU Data Act’s September 12, 2026 Deadline: What “Access by Design” Means for Global Businesses

If your company manufactures or sells connected products in the European Union β€” anything from industrial sensors to smart appliances to connected vehicles β€” the EU Data Act September 2026 deadline is not a future compliance item anymore. As of September 12, 2026, a stricter phase of the regulation takes effect: connected products and related services placed on the market after that date must be designed so that relevant data generated by their use is, by default, easily, securely, and directly accessible to users, free of charge, where technically feasible. According to Wilson Sonsini’s Data Advisor and Lexology, this “access by design” requirement is materially tougher than the baseline obligations that applied when the Data Act first became applicable a year earlier, on September 12, 2025.

This article explains what actually changes, who is in scope, how enforcement is shaping up across EU member states, and what legal, product, and compliance teams should be doing right now β€” whether your company is headquartered in the EU or simply sells connected products into it. For related coverage, see kurums.com’s Law department hub.

What is the EU Data Act, and what changed on September 12, 2026?

The EU Data Act (Regulation (EU) 2023/2854) governs who can access data generated by connected products, and its September 12, 2026 milestone introduces a mandatory “access by design” obligation for any qualifying product or related service placed on the market after that date.

The regulation itself became applicable on September 12, 2025, giving businesses their first set of data-access obligations. The September 2026 deadline is the second, stricter phase: rather than simply providing data access on request, in-scope products must now be engineered from the outset β€” “by design” β€” so that users can access their own product and related-service data by default, in a comprehensive, structured, commonly used, and machine-readable format, according to Wilson Sonsini’s summary of the requirement. This is a meaningful shift in compliance posture, moving the obligation from a legal/contractual fix applied after a product ships to an engineering requirement built into the product itself before it ever reaches an EU customer.

Which companies and products are actually in scope?

The obligation applies to manufacturers of connected products and providers of related services placed on the EU market, covering both B2B and B2C users β€” a scope broad enough to include industrial IoT equipment, consumer electronics, connected vehicles, and smart home devices alike.

Because the Data Act’s definition of “connected product” is intentionally broad, a wide range of manufacturers now need to determine whether their products qualify β€” including companies based outside the EU that simply sell into the EU market. Wilson Sonsini’s guidance recommends businesses start by inventorying every product and related service with any EU market presence, then identifying which specific data elements generated by that product or service qualify as “product data” or “related service data” under the regulation. This inventory step matters because the Data Act’s access rights extend to both business customers and individual consumers, meaning a company cannot assume the obligation applies only to consumer-facing products.

Is there any flexibility if direct data access isn’t technically feasible?

Yes β€” the regulation allows companies to rely on indirect data access where they can justify that direct, by-design access is not technically feasible, citing legitimate concerns such as cost, trade secret protection, intellectual property, or security risk.

This flexibility provision is important, but it is not a blanket exemption, and regulators are expected to scrutinize these justifications rather than accept them automatically. According to ComplianceHub.Wiki’s analysis of the enforcement landscape, companies invoking the technical-feasibility exception should expect to document their reasoning β€” why direct access was assessed and rejected, and what indirect access mechanism was implemented instead. Given that Germany’s implementing legislation designates the Federal Network Agency as enforcement authority with fines of up to 4% of annual EU turnover, treating the technical-feasibility exception as an easy default rather than a genuinely justified engineering decision is a real compliance risk, not a formality.

How is enforcement actually shaping up across EU member states?

Enforcement infrastructure is being built out unevenly but is accelerating β€” Germany, Finland, the Netherlands, and Poland have adopted implementing legislation naming enforcement authorities and penalty structures, while other member states are still finalizing their national frameworks.

Germany’s approach is instructive for what other member states are likely to follow: designating the Federal Network Agency (Bundesnetzagentur) as the central enforcement authority, with fines reaching 4% of annual EU turnover for violations β€” comparable in scale to GDPR’s penalty structure. ComplianceHub.Wiki notes that while no major enforcement actions had been publicly reported as of the deadline’s approach, regulators across the EU are expected to increase scrutiny “throughout the coming year” as the access-by-design obligation takes hold. For companies with meaningful EU revenue, the practical risk calculus should already reflect GDPR-scale penalties, even in the absence of a headline enforcement case yet.

⚠️ Warning: Non-compliant products placed on the market after September 12, 2026 face market prohibition and recall risk in addition to financial penalties. Unlike a pure data-privacy fine, this can mean a product physically cannot be sold in the EU until it is redesigned β€” a far more disruptive consequence for hardware manufacturers than a monetary penalty alone.

What should legal and compliance teams do before enforcement scrutiny increases?

Start with a scoping exercise, then move to contract and engineering updates in parallel β€” waiting for regulators to clarify ambiguous points before acting is the riskiest posture given the deadline has already passed for new products entering the market.

Wilson Sonsini’s recommended sequence is a reasonable template for most in-scope businesses. First, identify every product or related service with EU market exposure and determine Data Act applicability β€” this cannot be delegated entirely to engineering, since it requires legal interpretation of what counts as a “connected product.” Second, catalog exactly which data elements each product generates that qualify as product data or related service data, distinguishing between B2B and B2C users where access rights or contractual terms might differ. Third, update pre-contractual disclosures and end-user terms to clearly describe data access rights β€” this is a legal drafting exercise that can run in parallel with any engineering work. Fourth, for any product where direct by-design access is genuinely not feasible, document the technical-feasibility analysis contemporaneously, not retroactively after a regulator asks. Companies that treat this as solely an engineering problem, or solely a legal problem, tend to move slower than those who run both workstreams together from the start.

How does this compare to GDPR and other EU digital regulations?

The Data Act’s penalty structure closely mirrors GDPR’s, but its subject matter is different β€” it governs access to machine-generated product and usage data rather than personal data protection, meaning many companies with mature GDPR compliance programs still need a separate Data Act compliance track.

This distinction trips up some legal and compliance teams, who reasonably assume that a mature data protection program covers adjacent obligations. It does not. GDPR governs how personal data is collected, processed, and protected; the Data Act governs who has the right to access data generated by connected products and services, regardless of whether that data is personal in the GDPR sense. A connected industrial sensor generating purely operational, non-personal data is squarely within Data Act scope even though it may fall entirely outside GDPR. Legal teams should treat Data Act compliance as its own workstream with its own inventory, risk assessment, and documentation β€” not as an extension of an existing privacy program, even where the two efforts share some data-mapping work.

Frequently Asked Questions

What is the EU Data Act’s September 2026 deadline?

From September 12, 2026, connected products and related services placed on the EU market must be designed so that relevant data they generate is, by default, easily, securely, and directly accessible to users free of charge, where technically feasible β€” a stricter phase than the Data Act’s initial September 2025 obligations.

Does the EU Data Act apply to companies outside the EU?

Yes. Any manufacturer or service provider placing connected products or related services on the EU market is in scope, regardless of where the company is headquartered.

What are the penalties for non-compliance with the EU Data Act?

Member states are adopting their own implementing legislation; Germany, for example, has set fines of up to 4% of annual EU turnover, comparable to GDPR-level penalties, in addition to potential market prohibition or recall of non-compliant products.

Can a company avoid the “access by design” requirement?

Only where direct access is genuinely not technically feasible β€” companies can rely on indirect access mechanisms in that case, but should document the technical-feasibility justification, since regulators are expected to scrutinize these exceptions rather than accept them by default.

Is the EU Data Act the same as GDPR?

No. GDPR governs personal data protection, while the Data Act governs access rights to data generated by connected products and services, whether or not that data is personal β€” most companies need separate compliance tracks for each.

Which EU countries have already implemented Data Act enforcement rules?

As of September 2026, Germany, Finland, the Netherlands, and Poland have adopted implementing legislation designating enforcement authorities and penalty frameworks, with other member states expected to follow.

Key takeaways for legal and compliance leaders

The EU Data Act’s September 12, 2026 “access by design” deadline converts what was previously a contractual and disclosure obligation into an engineering requirement built into products before they reach the EU market. With Germany and several other member states already naming enforcement authorities and GDPR-scale penalties, treating this as a lower-priority compliance item than GDPR would be a mistake β€” even in the absence yet of a headline enforcement action. For further reading, see kurums.com’s Global Competition & Antitrust hub and the latest posts on the Law category page.

Sources: Wilson Sonsini / WSGR Data Advisor (“EU Data Act September 2026 Deadline: What Businesses Need to Know”); Lexology summary of the same analysis; ComplianceHub.Wiki reporting on EU Data Act enforcement acceleration and member-state implementing legislation. Last updated: September 2026.


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading