Compare the EU Data Act's connected-product and related-service data access rules with GDPR duties for personal data, data subjects, controllers, processors, and lawful basis.
Separate access obligations from privacy limits before sharing raw or pre-processed product data with users or third parties.
The EU Data Act can require access to product data and related service data for connected products placed on the Union market and related services provided in the Union, including personal and non-. still governs every processing operation involving personal data within its own material and territorial scope. First decide whether the data and request fall within Data Act Chapter II. Then identify the data subject, controller, processor, recipient, purpose, Article 6 lawful basis, any Article 9 condition for special-category data, and any ePrivacy rule. A Data Act duty does not supply the GDPR lawful basis or override a data subject's rights.
Side-by-side comparison
EU Data Act vs GDPR for connected-product data
This matrix helps separate Data Act access duties from personal-data duties when a connected-product or related-service data request may include .
The Data Act creates harmonised rules for fair access to and use of data, including Chapter II rights for users of connected products and related services.
Start with the Data Act only for the access question. If is involved, Article 1(5) makes the privacy-law boundary explicit: and related privacy law prevail in a conflict.
Data Act roles include the user, , data recipient, third party, manufacturer, related-service provider, and public-sector requester depending on the chapter and request type.
roles include data subject, controller, processor, joint controller, recipient, data protection authority, and European Data Protection Supervisor where EU institutions are involved.
Do not translate roles mechanically. A Data Act user can be a data subject in one flow, a controller in another flow, and neither in a request involving another person's .
Chapter II focuses on raw and pre-processed product data and related service data that is readily available to the , plus metadata needed to interpret and use it. Inferred or derived data and content are outside that Chapter II scope.
applies to in the export, including pseudonymised data and personal-data fields inside mixed datasets. Properly anonymised information falls outside GDPR only when the person is not or is no longer identifiable, taking account of means reasonably likely to be used.
Build exports at field level. Separate raw or pre-processed data from inferred, derived, and content fields; then mark personal, non-personal, mixed, pseudonymised, anonymous, and trade-secret material before deciding what can be sent.
The Data Act gives users access to product data and related service data generated by their use of a connected product or related service, regardless of whether the data is personal or non-personal, when the data is in scope.
Article 15 gives a data subject access to undergoing processing and related information. Article 20 portability is narrower: it covers personal data the data subject provided to the controller, when processing is automated and based on consent or contract. Both rights protect the rights and freedoms of others.
If the requester is the data subject, assess Data Act access, access, and GDPR portability separately. A failed Data Act scope test does not decide a GDPR request, and Article 15 access does not automatically meet Article 20 portability conditions.
The Data Act can oblige a to make available to the user or a third party at the user's request, but it does not create a legal basis to collect or generate personal data.
requires a valid Article 6 basis for each personal-data processing purpose. Special-category data also needs an Article 9(2) condition. Transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability still apply.
Record who the data subject is, who will receive the data, the requested purpose, the Article 6 basis, any Article 9 condition, the fields needed for that purpose, the retention rule, and the information given to affected people.
The Data Act has applied generally since 12 September 2025. Article 3(1)'s access-by-design duty applies to connected products and related services placed on the market after 12 September 2026. Chapter II has enterprise-size exclusions in Article 7, subject to its linked-enterprise and subcontracting conditions.
has applied since 25 May 2018. Data subject requests are generally answered without undue delay and within one month, with a possible two-month extension where necessary because of complexity or number. That GDPR deadline is not the response period for every Data Act request.
Record the legal route, product placement date, enterprise-size facts, request date, requester identity, and deadline. When one request invokes both laws, track the duties separately and coordinate the response.
Member States designate competent authorities for Data Act enforcement and set penalties that must be effective, proportionate, and dissuasive. Users can challenge certain withholding, suspension, refusal, and access disputes through competent authorities, courts, or dispute settlement routes.
Data protection authorities remain responsible for Data Act application insofar as personal-data protection is concerned, and enforcement paths continue for GDPR infringements.
Escalate to the right authority path. A Data Act access dispute, a trade-secret refusal, and a unlawful-disclosure complaint may involve different competence even when they arise from the same export.
The Data Act requires trade secrets to be preserved through agreed technical and organisational measures. Withholding, suspension, or refusal must be justified and tied to the Data Act conditions.
requires data minimisation and appropriate security. Anonymisation may remove data from GDPR only if people are no longer identifiable; pseudonymisation is a safeguard but the data remains .
Run separate reviews for trade-secret confidentiality and serious economic damage, and for personal-data lawfulness, minimisation, and security. Neither label is a generic refusal reason.
Beyond Chapter II, the Data Act also covers B2G exceptional-need requests, switching between data processing services, and safeguards against unlawful third-country government access to non-.
For B2G requests involving , the Data Act requires privacy safeguards and does not lower personal-data protection. International transfers of personal data remain governed by rather than the Data Act's non-personal-data third-country access rules.
Do not apply the connected-product access analysis to every Data Act chapter. B2G and cloud matters need their own scope check, and still moves back to .
The Data Act creates harmonised rules for fair access to and use of data, including Chapter II rights for users of connected products and related services.
Start with the Data Act only for the access question. If is involved, Article 1(5) makes the privacy-law boundary explicit: and related privacy law prevail in a conflict.
Data Act roles include the user, , data recipient, third party, manufacturer, related-service provider, and public-sector requester depending on the chapter and request type.
roles include data subject, controller, processor, joint controller, recipient, data protection authority, and European Data Protection Supervisor where EU institutions are involved.
Do not translate roles mechanically. A Data Act user can be a data subject in one flow, a controller in another flow, and neither in a request involving another person's .
Chapter II focuses on raw and pre-processed product data and related service data that is readily available to the , plus metadata needed to interpret and use it. Inferred or derived data and content are outside that Chapter II scope.
applies to in the export, including pseudonymised data and personal-data fields inside mixed datasets. Properly anonymised information falls outside GDPR only when the person is not or is no longer identifiable, taking account of means reasonably likely to be used.
Build exports at field level. Separate raw or pre-processed data from inferred, derived, and content fields; then mark personal, non-personal, mixed, pseudonymised, anonymous, and trade-secret material before deciding what can be sent.
The Data Act gives users access to product data and related service data generated by their use of a connected product or related service, regardless of whether the data is personal or non-personal, when the data is in scope.
Article 15 gives a data subject access to undergoing processing and related information. Article 20 portability is narrower: it covers personal data the data subject provided to the controller, when processing is automated and based on consent or contract. Both rights protect the rights and freedoms of others.
If the requester is the data subject, assess Data Act access, access, and GDPR portability separately. A failed Data Act scope test does not decide a GDPR request, and Article 15 access does not automatically meet Article 20 portability conditions.
The Data Act can oblige a to make available to the user or a third party at the user's request, but it does not create a legal basis to collect or generate personal data.
requires a valid Article 6 basis for each personal-data processing purpose. Special-category data also needs an Article 9(2) condition. Transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability still apply.
Record who the data subject is, who will receive the data, the requested purpose, the Article 6 basis, any Article 9 condition, the fields needed for that purpose, the retention rule, and the information given to affected people.
The Data Act has applied generally since 12 September 2025. Article 3(1)'s access-by-design duty applies to connected products and related services placed on the market after 12 September 2026. Chapter II has enterprise-size exclusions in Article 7, subject to its linked-enterprise and subcontracting conditions.
has applied since 25 May 2018. Data subject requests are generally answered without undue delay and within one month, with a possible two-month extension where necessary because of complexity or number. That GDPR deadline is not the response period for every Data Act request.
Record the legal route, product placement date, enterprise-size facts, request date, requester identity, and deadline. When one request invokes both laws, track the duties separately and coordinate the response.
Member States designate competent authorities for Data Act enforcement and set penalties that must be effective, proportionate, and dissuasive. Users can challenge certain withholding, suspension, refusal, and access disputes through competent authorities, courts, or dispute settlement routes.
Data protection authorities remain responsible for Data Act application insofar as personal-data protection is concerned, and enforcement paths continue for GDPR infringements.
Escalate to the right authority path. A Data Act access dispute, a trade-secret refusal, and a unlawful-disclosure complaint may involve different competence even when they arise from the same export.
The Data Act requires trade secrets to be preserved through agreed technical and organisational measures. Withholding, suspension, or refusal must be justified and tied to the Data Act conditions.
requires data minimisation and appropriate security. Anonymisation may remove data from GDPR only if people are no longer identifiable; pseudonymisation is a safeguard but the data remains .
Run separate reviews for trade-secret confidentiality and serious economic damage, and for personal-data lawfulness, minimisation, and security. Neither label is a generic refusal reason.
Beyond Chapter II, the Data Act also covers B2G exceptional-need requests, switching between data processing services, and safeguards against unlawful third-country government access to non-.
For B2G requests involving , the Data Act requires privacy safeguards and does not lower personal-data protection. International transfers of personal data remain governed by rather than the Data Act's non-personal-data third-country access rules.
Do not apply the connected-product access analysis to every Data Act chapter. B2G and cloud matters need their own scope check, and still moves back to .
Scope the product data, related service data, metadata, readily available data, exclusions, recipient, and Article 7 enterprise conditions under the Data Act.
Map personal-data fields, data subjects, roles, Article 6 bases, Article 9 conditions, transparency, retention, security, and transfer rules.
Document separate conclusions where Data Act access and disclosure point in different directions; personal-data law prevails in a conflict.
1
Section 1
An access duty does not override privacy law
Article 1(5) of the Data Act says the regulation is without prejudice to EU and national law on , privacy, confidentiality of communications, and terminal-equipment integrity. It also says that, if there is a conflict, the personal-data or privacy law prevails.
Product and related-service data can contain personal and non- in the same export. A Data Act request can start the access analysis, but it does not create a lawful basis for disclosing another person's personal data or collecting personal data that was not already lawfully processed.
Use the Data Act to decide whether product data or related service data must be made accessible.
Use to decide whether the personal-data processing in that access, use, or sharing is lawful.
If the user is also the data subject, assess the Data Act request and the separate rights of access and portability. GDPR portability applies only when its own conditions are met.
If the user is not the data subject, check Article 6 and, where relevant, Article 9 and ePrivacy conditions before disclosure.
If one request invokes both laws, log two legal routes and deadlines; answering one route does not close the other.
For Data Act Chapter II access, the Commission explains the scope as raw and pre-processed data generated from use of a connected product or related service that is readily available to the , including relevant metadata. Inferred or derived data and content are outside that Chapter II scope.
does not use the Data Act's product-data boundary. It applies to the personal-data fields in a mixed dataset. Pseudonymised data remains when it can be attributed to a person with additional information; only data rendered anonymous so that a person is no longer identifiable falls outside GDPR. The same export can therefore contain Data Act in-scope non-personal data, Data Act in-scope personal data, and material outside Chapter II such as inferred or derived information and content.
List raw sensor or event fields separately from enriched scores, analytics, recommendations, and audiovisual content.
Mark each field as personal, non-personal, mixed, outside Chapter II, redacted, anonymised, or pseudonymised before disclosure.
Include metadata needed to interpret the export, such as timestamps, units, sensor identifiers, quality limits, and collection context.
Do not use privacy-preserving transformations alone as a reason to treat otherwise in-scope raw or pre-processed data as derived data.
The Data Act has users, data holders, data recipients, third parties, manufacturers, related-service providers, and public-sector requesters. asks a different question: who determines the purposes and means of personal-data processing, who processes for someone else, and who is the data subject?
When the user is not the data subject, Articles 4(12) and 5(7) of the Data Act allow the to disclose only if there is a valid Article 6 basis and, where relevant, the conditions in GDPR Article 9 and ePrivacy Directive Article 5(3) are met. A business user that determines why and how it will use the received personal data may be a controller for that processing; the role depends on the facts, not the Data Act label.
Identify whether the requester is the Data Act user, the data subject, both, or neither.
Identify the and any third-party recipient under the Data Act.
Identify the controller, processor, joint-controller, and recipient positions under for the same flow; do not assign them by contract label alone.
Record the specific Article 6 basis before sending to a user that is not the data subject or to a third party chosen by that user.
For health, biometric identification, genetic, or other Article 9 data, record both an Article 6 basis and an Article 9(2) condition. Check national law where the selected condition permits or requires it.
Use the comparison to prepare a field-level export map, role analysis, lawful-basis note, recipient review, and trade-secret safeguard record for a connected-product data request.
The Data Act lets a user ask the to make in-scope data available to an eligible third party in the Union, but the route is not unlimited. A Digital Markets Act gatekeeper is not eligible under Article 5. The third party must use the data only for the purposes and on the conditions agreed with the user, comply with personal-data law, and follow the additional restrictions in Article 6.
Trade secrets are not a blanket refusal ground. The Data Act requires confidentiality measures first, allows withholding or suspension where agreed measures are missing or undermined, and allows refusal only in exceptional circumstances where serious economic damage is highly likely despite safeguards.
Check whether the chosen third party is eligible under the Data Act and not a prohibited recipient for the requested route.
Limit third-party personal-data disclosure to the user's requested purpose and the lawful basis.
Document trade-secret identification, confidentiality measures, technical controls, and any written withholding, suspension, or refusal reason.
Escalate refusals or suspensions to the competent-authority and dispute paths described in the Data Act instead of relying on informal denials.
Check dates and Chapter II exclusions before building the response
The Data Act has applied generally since 12 September 2025. The Article 3(1) duty to design covered products and related services so that data is readily accessible applies to connected products and related services placed on the market after 12 September 2026. That later date does not postpone every Chapter II access duty.
Chapter II does not apply to data generated through connected products manufactured or designed, or related services provided, by qualifying microenterprises and small enterprises, subject to the partner, linked-enterprise, and subcontracting conditions in Article 7. A limited one-year rule also covers certain enterprises that have newly become medium-sized. These exclusions do not remove duties from personal-data processing.
Record the product and related-service provider, enterprise size and relationships, subcontracting facts, and product placement date.
Separate the Article 3(1) access-by-design question from an Article 4 user request for readily available data.
Apply to even if a Data Act Chapter II duty or route is unavailable.
Supports the Commission's explanation that Chapter V cannot lower protection for personal data or trade secrets and that GDPR governs international personal-data transfers.