Cleo
CompanyLegal Data
Request a demo
Anaelle GuezNaomie Halioua
Request a demo
Cleo

AI-powered regulatory intelligence.

contact@cleolabs.co

Solutions

  • Product Compliance
  • For manufacturers
  • For importers & distributors
  • For marketplaces

Company

  • About
  • Research
  • Blog
  • Skills
  • Compliance Guides
  • Event
  • Careers

Legal Data

  • Coverage Atlas
  • API Docs
  • Playground

Jurisdictions

  • 🇪🇺 European Union
  • 🇫🇷 France
  • 🇩🇪 Germany
  • 🇬🇧 United Kingdom
  • 🇺🇸 United States

Legal

  • Privacy
  • Terms
  • Security

© 2026 Cleo Labs. All rights reserved.

GDPREU DataSOC 2 Type IIISO 27001
Blog/Product Compliance
Product Compliance2026-09-22·6 min read
Naomie Halioua

Naomie Halioua

Co-founder & CRO, AI Research

From 12 September, EU law makes connected products hand over their own data by design: the duty catches only the next model a brand launches, not the one already on the shelf

From 12 September, EU law makes connected products hand over their own data by design: the duty catches only the next model a brand launches, not the one already on the shelf

On 12 September 2026, a second obligation of the EU Data Act, Regulation (EU) 2023/2854, started applying: the design duty in Article 3(1). It requires that any connected product, an item that collects data about its own use or environment and can communicate that data, from smart appliances to wearables to connected toys, be designed so that the data it generates is, by default, accessible to its user easily, securely, free of charge and in a structured, machine-readable format. The Data Act itself has applied generally since 12 September 2025, a year earlier. The design duty got its own, later start date, and Article 3(1) says explicitly that it applies only to connected products and related services placed on the market from 12 September 2026 onward. A product already sold in the EU before that date owes its owner nothing new under this article, whatever data it collects and however long it stays on shelves.

What actually changed on 12 September

Article 2(5) of the Data Act defines a connected product broadly: an item that obtains, generates or collects data concerning its use or environment and can communicate that product data, whose primary function is not itself storing, processing or transmitting data for someone else. That reaches far past routers and industrial sensors: a smart baby monitor, a connected kettle, a fitness tracker, a Bluetooth-enabled toy and a smart suitcase all qualify. Article 3(1) then requires that these products, and any related service sold with them, be designed so the data they generate is accessible to the user by default, without the user having to request it, in a comprehensive, structured, commonly used and machine-readable format, at no charge. Before 12 September 2026, that duty existed on paper but had no live start date for the product-design piece specifically; the rest of the Data Act, rules on business-to-business data sharing, cloud-switching and unfair contract terms, had already been in force for a year. From 12 September 2026, any connected product a brand places on the EU market for the first time has to be built, not retrofitted after the fact, to meet Article 3(1).

Three details behind the 12 September deadline

01

A design duty, not a data-sharing duty

Article 3(1) is about how the product itself is built, giving its own user default access; it sits apart from the Data Act's separate rules on sharing data with third parties.

02

A one-year gap behind the rest of the law

The Data Act applied generally from 12 September 2025. Article 3(1) got its own start date, 12 September 2026, one year later.

03

Only what launches from here on

The duty binds connected products and related services placed on the EU market from 12 September 2026 onward, not the ones already sold before that date.

27 Dec 2023

Regulation (EU) 2023/2854, the Data Act, is published in the Official Journal of the European Union.

12 Sep 2025

Article 50 makes the Data Act generally applicable: data sharing, cloud switching and unfair contract term rules take effect.

11 Sep 2026

A separate EU law, the Cyber Resilience Act, starts requiring 24-hour reporting of exploited vulnerabilities in connected products, for products already on the market too.

12 Sep 2026

Article 3(1) of the Data Act starts applying: connected products and related services placed on the EU market from this date must give users default access to the data they generate.

The numbers behind the deadline

One number marks when the design duty itself started applying. One marks how far behind the rest of the Data Act it lagged. The third is how many separate national regimes now enforce it.

12 Sep 2026

the date Article 3(1)'s design duty started binding connected products and related services newly placed on the EU market

1 year

the gap between the Data Act's general application date, 12 September 2025, and the later start date given to the product-design duty specifically

27

EU member states, each required to designate its own competent authority to enforce the Data Act, with no single EU-wide penalty figure set by the regulation itself

The real subject: the compliance line runs through the launch date of the SKU, not the product category

Most coverage of the 12 September deadline reports it as a flat rule: connected products must now give users access to their own data. What that framing skips is that Article 3(1) is not keyed to the product category or the brand; it is keyed to the date a specific product was first placed on the EU market. A smart kettle model that has been sold since 2023 stays outside the design duty indefinitely, however much data it collects, unless the brand places a new version on the market. A near-identical kettle from a competitor launching this month has to be built with default data access from day one. Two functionally similar devices, two different legal statuses, decided entirely by launch date. That makes 'placed on the market', a term EU product law already uses for CE marking and the General Product Safety Regulation, into a data-compliance question as much as a safety one: a brand relabelling, re-sourcing or adding a feature to an existing connected product needs to know whether that change counts as placing a new product on the market, because that is the event that starts the clock on Article 3(1), not the product's age or its data collection itself.

Why it matters for brands

Three groups should read past the headline date. First, any brand selling connected physical products in the EU, smart home appliances, wearables, connected toys, luggage or beauty devices, now needs a per-SKU record of when each product was first placed on the EU market, because that single date decides whether Article 3(1) applies at all. From here on, 'data access by design' belongs on the same new-product checklist as CE marking and GPSR conformity, not as a separate IT project handled after launch. Second, enforcement is not centralised the way GDPR's is: each of the 27 member states designates its own competent authority, and the regulation leaves the penalty regime to national law rather than setting one EU-wide figure, so a brand selling the same connected product across several member states can face different authorities applying different sanctions to the same design gap. Third, do not merge this with two other EU obligations landing the same week: the Cyber Resilience Act's 24-hour vulnerability-reporting duty, which started a day earlier on 11 September 2026 and, unlike the Data Act's design duty, explicitly covers products already sold before its deadline, and the Digital Product Passport under the Ecodesign for Sustainable Products Regulation, which is about lifecycle and sustainability data, not user data access. Three different EU regimes, three different scopes, landing within days of each other on the same connected-product catalogue.

Two ways to read the 12 September deadline

The narrow read

From 12 September 2026, EU law requires connected products to give users default access to the data those products generate.

The structural read

The duty attaches to the date a specific product is placed on the market, not to the product category or the data it collects. Two near-identical connected products can sit on opposite sides of the line depending purely on when each one launched, and each new SKU, relaunch or private-label variant is the event that decides which side it lands on.

Frequently asked questions

What exactly changed in EU law on 12 September 2026?

Article 3(1) of the Data Act, Regulation (EU) 2023/2854, started applying. It requires that connected products, items that collect data about their own use or environment and can communicate it, and any related service sold with them, be designed so their data is accessible to the user by default, easily, securely, free of charge, and in a structured, machine-readable format. The Data Act as a whole has applied generally since 12 September 2025; the design duty for products and services got its own, later application date, 12 September 2026.

Does this apply to connected products already sold in the EU before 12 September 2026?

No. Article 3(1) applies to connected products and related services placed on the EU market from 12 September 2026 onward. A product a brand was already selling in the EU before that date is not brought into scope retroactively by this article, whatever data it collects, unless the brand places a new version of it on the market after the deadline.

How is this different from the Cyber Resilience Act or the Digital Product Passport?

All three land on connected products within roughly the same window but cover different things. The Cyber Resilience Act's Article 14, in force since 11 September 2026, requires reporting an actively exploited vulnerability within 24 hours and, unlike the Data Act's design duty, explicitly covers products already sold before its deadline. The Digital Product Passport under the Ecodesign for Sustainable Products Regulation concerns lifecycle and sustainability data, not user access to the data a product generates in use. The Data Act's Article 3(1) is specifically about giving the product's own user default access to the data that product collects, only for products placed on the market from 12 September 2026.

Sources

  1. EUR-Lex: Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act), on Articles 2(5), 3(1) and 50
  2. European Commission, Shaping Europe's digital future: "Data Act explained," on the general 12 September 2025 application date and the connected-product scope of the Data Act
  3. Bird & Bird: "The EU Data Act: Where Things Stand Now," 2026, corroborating the 12 September 2026 application date of the Article 3 product-design duty
  4. DIHK (German Chambers of Industry and Commerce): "Data Act: Next level as of 12 September 2026," corroborating the transition from the 2025 general application date to the 2026 product-design duty
  5. Gaming Tech Law: "Data Act Access by Design: What Changes for Connected Products from 12 September 2026," August 2026, corroborating that the design duty applies only to products placed on the market after that date
  6. Kemp IT Law: "Enforcement and penalties under the EU Data Act, navigating the new regulatory landscape," corroborating the decentralised, member-state-level enforcement structure and the absence of a single EU-wide penalty figure
  7. DLA Piper: "Data Act Implementation: Enforcement Structures and Sanctions Regimes in Malta and Germany," October 2025, corroborating that member states set their own competent authorities and penalty regimes under Article 40
  8. Cleo Labs blog: "On 11 September, EU law forces manufacturers to report an exploited vulnerability in any connected product," 8 September 2026, this site's own prior verified coverage of the Cyber Resilience Act's Article 14 and Article 69(3), cited here for the contrast between the two deadlines

Note on verification: this session's network access allows search but blocks direct page retrieval from eur-lex.europa.eu, digital-strategy.ec.europa.eu and every law-firm domain cited above. The regulation number, Regulation (EU) 2023/2854, and the text of Articles 2(5), 3(1) and 50 were confirmed through search-indexed excerpts and dedicated legal-text mirror sites quoting the operative language, cross-checked against independent summaries from Bird & Bird, DIHK, Alston & Bird, Loyens & Loeff and Gaming Tech Law, all of which independently state the same 12 September 2025 general application date and 12 September 2026 product-design start date. The absence of a single EU-wide penalty figure, and the requirement that each member state designate its own competent authority under Article 40, were confirmed through Kemp IT Law's and DLA Piper's independent analyses, both describing a decentralised enforcement structure rather than a harmonised cap; no specific penalty amount is stated in this article because it could not be independently cross-checked as a figure set by the regulation itself. The contrast with the Cyber Resilience Act's Article 14 and Article 69(3) draws on this same blog's own prior article on that deadline, published 8 September 2026, which was independently verified at the time against cpsc-equivalent EU primary sources. Where a figure or claim could not be cross-checked across at least two independent sources, it has been left out of this article. This article names eur-lex.europa.eu and digital-strategy.ec.europa.eu as the underlying primary sources and gives their addresses above for independent verification, since this session could not retrieve their page content directly.

Frequently asked questions

What exactly changed in EU law on 12 September 2026?

Article 3(1) of the Data Act, Regulation (EU) 2023/2854, started applying. It requires that connected products, items that collect data about their own use or environment and can communicate it, and any related service sold with them, be designed so their data is accessible to the user by default, easily, securely, free of charge, and in a structured, machine-readable format. The Data Act as a whole has applied generally since 12 September 2025; the design duty for products and services got its own, later application date, 12 September 2026.

Does this apply to connected products already sold in the EU before 12 September 2026?

No. Article 3(1) applies to connected products and related services placed on the EU market from 12 September 2026 onward. A product a brand was already selling in the EU before that date is not brought into scope retroactively by this article, whatever data it collects, unless the brand places a new version of it on the market after the deadline.

How is this different from the Cyber Resilience Act or the Digital Product Passport?

All three land on connected products within roughly the same window but cover different things. The Cyber Resilience Act's Article 14, in force since 11 September 2026, requires reporting an actively exploited vulnerability within 24 hours and, unlike the Data Act's design duty, explicitly covers products already sold before its deadline. The Digital Product Passport under the Ecodesign for Sustainable Products Regulation concerns lifecycle and sustainability data, not user access to the data a product generates in use. The Data Act's Article 3(1) is specifically about giving the product's own user default access to the data that product collects, only for products placed on the market from 12 September 2026.

Related resources

Product Compliance · 2026-09-08

From 11 September, EU law forces manufacturers to report an exploited vulnerability in any connected product, smart toys and wearables included, within 24 hours: the duty already covers products sold years ago, 15 months before the same regulation's CE-marking deadline

Product Compliance · 2026-08-07

On 20 July, the European Commission opened its Digital Product Passport registry, and on 6 August the rules governing it took effect: the one step every brand must complete first has no product-category deadline of its own

Product Compliance · 2026-03-13

Digital Product Passport (DPP): What Retail Brands Need to Know

Product Compliance · 2026-05-27

Why your PLM is only as good as the regulatory data you feed it

Try Cleo: free regulatory risk scan

See your regulatory landscape mapped in minutes. No signup, no credit card.

See the product in action
Book a call
Anaelle GuezNaomie Halioua
Request a demo