The EU Data Act marks a structural shift in Europe’s digital economy, one that rebalances power among manufacturers, users and service providers, Peter Lando and Stefica Milor of Lando & Anastasi explain.
The EU Data Act, effective since September 2025, has become one of the most consequential regulatory developments for companies operating connected products, related services and cloud environments within the EU market. Framed as a horizontal law designed to harmonize data access and use across sectors, the act reshapes the interplay among intellectual property, privacy, data governance and competition.
Crucially, the regulation applies extraterritorially, meaning non-EU companies are within its scope whenever EU-based users interact with their products or services.
The act changes how companies must treat data generated with connected products, such as smart appliances, industrial machinery, vehicles and medical technologies. It covers all usage‑generated data: raw sensor outputs, pre‑processed data, metadata and machine‑generated insights. When a connected product or related service collects or generates data, the user (whether a consumer or business) gains a statutory right to access it.
By Sept. 12, 2026, new connected products placed on the EU market must be designed for “access by design,” ensuring data is directly, securely and easily available to the user in structured, machine‑readable formats. If direct access is not technically feasible, the data holder must provide “readily available data” upon request without delay and at no cost to the user.
The act also empowers users to instruct data holders to share their generated data with third parties of the users’ choosing. This provision enables interoperability, multi‑vendor maintenance, independent repair and cross‑service innovation while introducing new competitive dynamics into traditionally closed ecosystems.
Illinois Genetic Information Protection Act Comes of Age
Illinois’ experience with biometric privacy offers a cautionary tale for companies that keep genetic information in the AI era
Read moreDetailsGDPR, proprietary protections & downstream use
Although the act covers both personal and non‑personal data, GDPR rules continue to govern personal data. Where overlaps occur — for example, vehicle telemetry associated with a driver — GDPR obligations take precedence. Companies must carefully distinguish data types, implement minimization and transparency measures and ensure user‑initiated sharing does not violate data privacy obligations.
Beyond GDPR, one of the most intricate aspects of the act involves the intersection of user data rights with proprietary protections like trade secrets and rights in databases.
Manufacturers often argue that device telemetry and operational data can reveal commercially sensitive information, such as production methods, algorithmic performance, diagnostics logic or product design insights. The act anticipates this risk and provides a “trade secrets handbrake” mechanism. Before disclosing data that may contain trade secrets, the data holder may identify information considered a trade secret; require proportionate confidentiality and technical safeguards; and, in certain cases, refuse disclosure if no adequate protections can be agreed upon.
This handbrake is not a loophole but rather a structured balancing tool. Companies cannot simply designate all data as proprietary, and users can challenge excessively broad assertions.
The act also expressly prohibits the use of certain rights in databases to block user access to data generated through connected products. This targeted measure prevents companies from using database protections to monopolize machine‑generated datasets.
As for downstream use, user‑designated third parties receiving data must comply with strict restrictions, including: handling personal data under GDPR; disallowing use of shared data to create competing products; limiting use of data only for the specific purpose agreed with the user; and confirming that misuse of trade secret-protected data carries legal and commercial consequences. These obligations help ensure that data access rights foster innovation rather than unfair competition.
Economic opportunities & organizational readiness
While the act introduces compliance requirements, it also unlocks significant commercial potential. Companies that modernize their data architectures, interoperability capabilities and contractual frameworks now will be positioned to offer premium data‑enabled services and analytics; expand into after‑market services previously closed by proprietary constraints; build trust by marketing themselves as Data Act ready; enhance customer value with transparent, user‑centric data controls; and compete more effectively in multi‑vendor or modular ecosystems.
To capitalize on these opportunities, businesses might consider: assessing product data flows by identifying all data generated, collected and transmitted by connected products and related services; updating user material and B2B agreements to reflect data access rights, third-party sharing processes and fair-terms requirements; preparing cloud and SaaS playbooks that detail migration support; and establishing internal and cross‑functional governance that include legal, privacy, product, engineering, IP and security teams to implement obligations outlined by the act.
It also would be useful to begin identifying trade secrets by mapping telemetry and operational data that may constitute trade secrets; defining appropriate disclosure safeguards; updating contracts by incorporating user access and sharing rights; and specifying confidentiality measures for sensitive data.


Peter C. Lando
Stefica Milor








