17.07.2026

9 Min. read time

The right to access readily available product data has been in effect since September 12, 2025 – covering the entire fleet, including existing machinery, provided the data holder already possesses the data. What changes on September 12, 2026, is Access by Design for newly placed connected products on the market. Direct access must then be structurally integrated. Existing products do not need to be retrofitted. The EU Data Act has been in force for a year. Chapter II governs user access – for owners, tenants, and lessees – to product data. The critical interface lies in procurement and operations.

Key Takeaways

  • Access applies now, including for existing products. Since September 12, 2025, users have the right to access readily available product and related service data – even for legacy systems, as soon as the data holder possesses it (e.g., in the OEM portal).
  • Access by Design from 12.09.2026, new products only. For connected products placed on the EU market after this date, direct access must be structurally integrated. Existing products do not require retrofitting.
  • The leverage lies in contracts – today. Accepting portal-only access and blanket third-party bans means waiving a right you already have. Procurement and operations define interfaces, formats, and ownership.

RelatedWhen the shop floor and data center become one network  /  Supply chain obligations require a data architecture

Contracts stay silent while manufacturers hold the data

In many OT and fleet deals, the data question lies in the fine print – or is missing entirely. The OEM delivers the machine. The raw data ends up in its portal. The operator receives dashboards and alarms, rarely structured exports for own systems or third parties.

Against this backdrop, the Data Act has applied since 12 September 2025. Chapter II grants users – owners, lessees, and leaseholders – the right to access readily available raw and pre‑processed data of connected products and related services. Derived or processed evaluations usually do not fall under this. Data holders must enable this access free of charge and easily; where feasible, directly. At the user’s request, sharing with third parties is included – free of charge for the user, while for the recipient it is tied to fair conditions. Gatekeepers are excluded as recipients. Another strict rule: the data may not be used to develop a competing product.

The management question resides in the purchase, rental, lease, or service contract as soon as the manufacturer technically and organizationally holds the data. CIOs and CDOs steer this interface together with procurement. Whoever leaves it to the OEM inherits the manufacturer’s defaults.

Trade‑off one: control versus speed. A standardized OEM‑portal access goes live quickly. A contractually enforced, machine‑readable export consumes negotiation time and often project budget for integration. Trade‑off two: scope of released data versus protection of trade secrets. The Data Act recognizes trade‑secret and security limits – they qualify the access, but they are poorly suited as a blanket exclusion in contract wording.

Ownership is often unclear in DACH organizations. IT knows cloud contracts. OT knows machine availability. Procurement signs off volume and SLA. Data formats and third‑party sharing fall between the cracks. That is exactly where the OEM gains leverage – and exactly where the statutory right of access already applies today, as soon as the data are readily available.

Typical contract practice (observation)

  • Access only via the manufacturer’s proprietary portals
  • Raw data and metadata without a machine‑readable export path
  • Third‑party use either broadly restricted or unregulated
  • Related services without their own data clause
  • No clear user definition for rental, leasing, and operator models

Data‑Act logic (Chapter II)

  • Free, simple access to readily available product data for the user
  • Where feasible: direct access and machine‑readable formats
  • Sharing with third parties upon explicit user request – gatekeepers excluded
  • Distinction between product data and related‑service data
  • Role clarification: user, data holder, internal owner in operation

The left column is an industry observation from OT and fleet procurement. It is based on no survey. The right column follows the Chapter II logic: access for users to readily available data, sharing on request, obligation of the data holder. Where the line to derived data and related services lies in each case remains disputed in practice. Whoever leaves this open in the contract leaves the interpretation to the manufacturer – and forfeits a claim that has applied since September 2025.

Access by Design from 12 September 2026 – Access already applies

Two levels cleanly separate. First: Since 12 September 2025, the right of access to readily available product and related service data applies – also for existing machines, as soon as the data holder holds them. Second: Access by Design – the constructive obligation to provide direct access in the product – applies to networked products placed on the market in the Union after 12 September 2026. This is a design requirement for new products. Existing machines do not need to be retrofitted for this.

For operations, this means: The fleet remains mixed, the legal situation is not. Existing plants are subject to the right of access to the extent that data is readily available – often in the OEM portal or the service backend. New deliveries as of the cut‑off date must be designed so that constructive direct access becomes possible. Those planning larger replacement or expansion investments in 2026 and 2027 are thereby negotiating the data architecture of the next decade. Those who today leave portal‑only and blanket third‑party bans in place are giving up the lever that Chapter II has already opened.

Three risks are real and budget‑relevant. First: contracts that reduce the existing right of access to portal‑only and omit machine‑readable exports. Second: unclear user status in leasing, rental models and operator concepts – Chapter II ties to owners, tenants and lessees, not to the pure IT service provider. Third: a patchwork of existing plants with portal access and new plants with constructive direct access. The integration effort then shifts into your own architecture budget.

since 12.09.2025
The right of access to readily available product data applies since this date – also for existing machines. On 12 September 2026, Access by Design is added for newly placed‑on‑the‑market products.
EU Data Act · Access by Design Connected Products

What remains intentionally vague: the exact scope of trade secrets and security limits on a case‑by‑case basis, national supervisory practice and future simplifications in the digital rulebook. The exemption for micro‑ and small enterprises, by contrast, is a hard rule. What is reliable: applicability since September 2025, the Chapter II access logic for readily available data, and the design cut‑off date for new products from September 2026.

Cloud and edge switching under Chapter VI is a separate track. For the procurement of machines and sensors, it is a sideshow. The primary decision lies with product data and related services – and with the question of which interface the OEM provides in the device and in the aftermarket.

Procurement and Operations Govern Data Access Within 90 Days

The sequence follows the logic of leverage. First, inventory: Which connected products are already in stock-and which related services are tied to them, where the data holder already manages data? In parallel: Which procurements are planned for 2026/27 as purchases, rentals, leasing, or operator models? Without this list, it remains unclear where the right to access already applies today and where *access by design* will kick in after the deadline.

Next, procurement: A standardized data annex for tenders and framework agreements locks in data categories (readily available raw data, pre-processed data, metadata), formats, update frequency, direct access where feasible, onward sharing with designated third parties at the user’s request, and the boundary for competitor product development. Phrases like “access at the manufacturer’s discretion” have no place here. They shift interpretive authority back to the OEM and undermine the existing right.

Then internal ownership: A designated owner-typically the CIO/CDO together with OT leadership-decides where the data flows: MES, analytics, aftermarket partners, maintenance providers. Procurement signs off. Operations integrates. Without this division, parallel access points and shadow integrations emerge. The 90-day window is a realistic timeframe to finalize inventory, a template annex, and a pilot on an ongoing tender-before the next major order wave defaults to OEM settings.

In the DACH region, co-determination comes into play where machine data actually acquires personal references-such as through operator assignments or performance profiles. Machine data isn’t automatically personal data. The Data Act governs product data rights. It doesn’t replace data protection or works council processes. Anyone analyzing sensor data on the shop floor separates machine and personal data early, as soon as personal references become foreseeable.

Budget question: The costs rarely lie in the OEM’s license line. They lie in integration, export quality assurance, and maintaining separate fleet pathways for legacy and new systems. Those treating this as a pure legal project underestimate the Capex and Opex share. Those approaching it as a procurement and architecture project can set the interface while the right to access is already in effect-and before the next investment wave hits.

Concrete steps in the first 90 days: Inventory list of existing and planned connected-product procurements. Template data annex with legal and OT review. Pilot on an ongoing tender-one production line, one OEM, one related service. Clear role matrix for users, data holders, and internal owners. Flag soft spots (trade secrets, boundaries of *readily available data*, related services) as negotiation points, without presenting them as settled legal matters.

The core question remains operational: What does the contract say when the manufacturer holds the data? Those who leave the right to access unresolved today and wait for *access by design* starting September 2026 will inherit the OEM’s defaults-and foot the integration bill themselves.

Frequently Asked Questions

When does the data access right apply – and when does Access by Design apply?

The entitlement to access readily available product and related service data has been in effect since September 12, 2025, also for existing machines, provided the data holder retains the data. Access by Design – the constructive obligation for direct access – applies to networked products placed on the market in the Union after September 12, 2026.

Do existing machines need to be retrofitted?

There is no general retrofitting obligation for Access by Design. Existing stock does not need to be modified to create direct access constructively. The entitlement to access readily available data nevertheless already applies today – for example, if the OEM holds the same data in the portal or service backend. Old and new installations often run in parallel in operation, with different integration paths.

What must data holders provide to users?

Access to readily available raw and pre‑processed data of networked products and related services – free of charge, simple, and direct where feasible. Derived evaluations are generally excluded. Upon user request, sharing with third parties is envisaged; gatekeepers are excluded as recipients. The recipient is subject to fair terms of use. The data may not be used to develop a competing product. Trade secrets and security may limit access on a case‑by‑case basis.

Who counts as a user under Chapter II?

Users are primarily owners, lessees, and leaseholders. In procurement, purchase, lease, leasing, and operator models must therefore be clearly distinguished. Anyone acting solely as an IT service provider without user status does not automatically inherit the same access.

What should be included in the procurement contract – already now?

At a minimum: data categories (readily available data), formats, access routes including direct access where feasible, rules for third‑party sharing upon user request, distinction from related‑service data, prohibition on use for developing a competing product, and internal roles. Flex points such as trade secrets and case‑by‑case delineations remain subject to negotiation and are not suitable as blanket exclusion clauses. The leverage lies in the ongoing and the next deal, not only at the design cutoff date.

Image source: AI-generated (July 2026)

Share this article:

Also available in

More Articles

04.08.2026

Local AI: Governance Before Hardware Purchase

Benedikt Langer

10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...

Read Article
03.08.2026

AI Regulation: Up to 3 Percent of Corporate Revenue

Tobias Massow

5 min read Article 50 of the AI Act has bound providers and deployers to concrete transparency obligations ...

Read Article
31.07.2026

You are paying for the R&D of the next competitor

Benedikt Langer

4 min read You are funding the R&D of your next competitor and calling it AI transformation. Frontier ...

Read Article
29.07.2026

Model Harness Instead of Model Marriage: Who Controls the AI Chain?

Eva Mickler

6 min read The lock-in is shifting from the individual model to the orchestration layer. Those who don’t ...

Read Article
28.07.2026

Washington decides which AI is allowed to run here

Eva Mickler

6 Min. read time In just eight days, Washington has shifted the dispute over Chinese AI models from ...

Read Article
23.07.2026

Orphaned Access: The Silent Cybersecurity Gap

Benedikt Langer

5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...

Read Article
A magazine by Evernine Media GmbH