No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

European Data Act: Balancing IP & Privacy

Companies that delay meeting the act’s requirements may find themselves challenged by enforcement and outpaced by competitors

by Peter Lando and Stefica Milor
August 24, 2026
in Data Privacy
EU flags in sun

The EU Data Act marks a structural shift in Europe’s digital economy, one that rebalances power among manufacturers, users and service providers, Peter Lando and Stefica Milor of Lando & Anastasi explain.  

The EU Data Act, effective since September 2025, has become one of the most consequential regulatory developments for companies operating connected products, related services and cloud environments within the EU market. Framed as a horizontal law designed to harmonize data access and use across sectors, the act reshapes the interplay among intellectual property, privacy, data governance and competition. 

Crucially, the regulation applies extraterritorially, meaning non-EU companies are within its scope whenever EU-based users interact with their products or services.

The act changes how companies must treat data generated with connected products, such as smart appliances, industrial machinery, vehicles and medical technologies. It covers all usage‑generated data: raw sensor outputs, pre‑processed data, metadata and machine‑generated insights. When a connected product or related service collects or generates data, the user (whether a consumer or business) gains a statutory right to access it.

By Sept. 12, 2026, new connected products placed on the EU market must be designed for “access by design,” ensuring data is directly, securely and easily available to the user in structured, machine‑readable formats. If direct access is not technically feasible, the data holder must provide “readily available data” upon request without delay and at no cost to the user.

The act also empowers users to instruct data holders to share their generated data with third parties of the users’ choosing. This provision enables interoperability, multi‑vendor maintenance, independent repair and cross‑service innovation while introducing new competitive dynamics into traditionally closed ecosystems.

double helix of lego
Data Privacy

Illinois Genetic Information Protection Act Comes of Age

by Michael C. McCutcheon and Ruby Borja
August 17, 2026

Illinois’ experience with biometric privacy offers a cautionary tale for companies that keep genetic information in the AI era

Read moreDetails

GDPR, proprietary protections & downstream use

Although the act covers both personal and non‑personal data, GDPR rules continue to govern personal data. Where overlaps occur — for example, vehicle telemetry associated with a driver — GDPR obligations take precedence. Companies must carefully distinguish data types, implement minimization and transparency measures and ensure user‑initiated sharing does not violate data privacy obligations.

Beyond GDPR, one of the most intricate aspects of the act involves the intersection of user data rights with proprietary protections like trade secrets and rights in databases.

Manufacturers often argue that device telemetry and operational data can reveal commercially sensitive information, such as production methods, algorithmic performance, diagnostics logic or product design insights. The act anticipates this risk and provides a “trade secrets handbrake” mechanism. Before disclosing data that may contain trade secrets, the data holder may identify information considered a trade secret; require proportionate confidentiality and technical safeguards; and, in certain cases, refuse disclosure if no adequate protections can be agreed upon.

This handbrake is not a loophole but rather a structured balancing tool. Companies cannot simply designate all data as proprietary, and users can challenge excessively broad assertions.

The act also expressly prohibits the use of certain rights in databases to block user access to data generated through connected products. This targeted measure prevents companies from using database protections to monopolize machine‑generated datasets.

As for downstream use, user‑designated third parties receiving data must comply with strict restrictions, including: handling personal data under GDPR; disallowing use of shared data to create competing products; limiting use of data only for the specific purpose agreed with the user; and confirming that misuse of trade secret-protected data carries legal and commercial consequences. These obligations help ensure that data access rights foster innovation rather than unfair competition.

Economic opportunities & organizational readiness

While the act introduces compliance requirements, it also unlocks significant commercial potential. Companies that modernize their data architectures, interoperability capabilities and contractual frameworks now will be positioned to offer premium data‑enabled services and analytics; expand into after‑market services previously closed by proprietary constraints; build trust by marketing themselves as Data Act ready; enhance customer value with transparent, user‑centric data controls; and compete more effectively in multi‑vendor or modular ecosystems.

To capitalize on these opportunities, businesses might consider: assessing product data flows by identifying all data generated, collected and transmitted by connected products and related services; updating user material and B2B agreements to reflect data access rights, third-party sharing processes and fair-terms requirements; preparing cloud and SaaS playbooks that detail migration support; and establishing internal and cross‑functional governance that include legal, privacy, product, engineering, IP and security teams to implement obligations outlined by the act.

It also would be useful to begin identifying trade secrets by mapping telemetry and operational data that may constitute trade secrets; defining appropriate disclosure safeguards; updating contracts by incorporating user access and sharing rights; and specifying confidentiality measures for sensitive data.

Tags: Data Governance
Previous Post

GRC News Roundup: Speeki, Napier AI, Descartes & More

Next Post

The Greenwashing Reckoning Isn’t About Marketing

Peter Lando and Stefica Milor

Peter Lando and Stefica Milor

Peter C. Lando is a founding partner of the Boston-based boutique intellectual property law firm Lando & Anastasi.
Stefica Milor is an associate at Lando & Anastasi.

Related Posts

turning out light

5 Questions to Ask Before a Legacy System Goes Dark

by Mani Chandra Raparla
September 21, 2026

When an ERP is retired, the closed records left behind are often the ones a regulator, auditor or opposing counsel...

manage subscription page on phone

New York City’s ‘Click to Cancel’ Rule Reinforces Important Auto-Renewal Requirements

by Zach Lerner, Maddie Rana and Emma Bourgeois
September 17, 2026

Rules may be mostly familiar, but the practical significance of the NYC regime lies in enforcement

user data privacy notice in app

What Companies Need to Know About the Evolving Youth Privacy Landscape

by Greg Szewczyk and Madison Etherington
August 10, 2026

With numerous state youth data laws passed and more in the works, count on a patchwork adding to compliance requirements

news roundup_062124

Activist Investors Significantly Increase M&A Sale Pushes

by Staff and Wire Reports
July 30, 2026

Massive data security confidence comes with high data security concerns.

Next Post
greenwashing painting white bottle concept

The Greenwashing Reckoning Isn’t About Marketing

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights