Bonn: The smart thermostat on the wall, the fitness band on the wrist and the sensor humming inside a tractor all share a quiet secret. They generate streams of data that, until now, have belonged in practice to the manufacturer rather than the person or business that paid for the device. The European Data Act sets out to change that, and from the twelfth of September its design duties begin to bite for every newly placed connected product. After that date, anyone selling a wearable, a connected car or a piece of factory machinery must build it so that the user can reach the data it produces, easily and free of charge.
The principle sounds modest and the implications are not. For years the data thrown off by connected products has been a private asset, locked behind proprietary apps and closed interfaces, and used by the maker to sell spare parts, repairs and follow-on services with little competition. The new rules treat that data as something co-generated by the user, who gains the right to see it, to use it and to hand it to a rival service provider. A farmer could take the readings from a tractor to an independent mechanic, a factory could feed sensor data to a cheaper maintenance firm, and the manufacturer’s quiet monopoly on aftercare would lose its grip.
Enforcement is where intentions meet teeth, and member states have been busy naming the authorities that will wield them. Germany has handed the job to its Federal Network Agency and signalled that violations touching personal data can draw the familiar penalties of the privacy regime, fines reaching four percent of worldwide turnover. Where a country appoints more than one watchdog, a coordinator must act as the single door for complaints, a small structural detail that determines whether the law feels coherent or fragmented to the companies trying to comply.
A second deadline looms behind the first. From January the rules on cloud computing tighten, banning the switching fees that providers have used to make leaving a platform expensive enough to discourage anyone from trying. The aim is to let a business move its workloads from one cloud to another without paying a ransom on the way out, loosening the grip of a handful of dominant providers. Until the ban takes full effect, only genuine cost-recovery charges are permitted, and providers must publish the plans that show how a customer can actually decamp.
Industry’s complaints are predictable and not wholly unreasonable. Retrofitting data access into products designed without it is costly, the line between protecting trade secrets and hoarding data is genuinely blurry, and smaller manufacturers fear the compliance burden falls hardest on those least able to carry it. Yet the underlying bet is a familiar European one, that opening a closed market to competition rewards the customer more than it punishes the incumbent. Whether that bet pays off depends on enforcement that is brisk rather than ornamental, and on watchdogs willing to test the new powers against firms large enough to argue back. The deadline is fixed. The appetite to use it is the variable.




