European retailers that sell anything with a chip in it have one more hard date on the autumn calendar. On September 12, 2026, the design obligation at the centre of the EU Data Act begins to bite, and it lands on products rather than on paperwork.
The rule is short in text and long in consequence. Any connected product or related service placed on the EU market after that date must be built so that the data it generates is accessible to the user by default, in a structured, commonly used and machine-readable format, and directly where that is technically feasible.
The Data Act itself is not new. Regulation (EU) 2023/2854 entered into force on January 11, 2024 and became applicable on September 12, 2025, according to the European Commission’s own policy pages. What arrives in September 2026 is the part that manufacturers were given an extra year to engineer, and the part that changes what a retailer is legally selling.
For merchants, the practical question is narrower than the regulation’s ambition. It is whether the smart speaker, robot vacuum, e-bike, connected oven or fitness tracker on the shelf in October was placed on the market before or after the cut-off, and whether the product page says the right things at the point of sale.
In short
- September 12, 2026 is the date the Data Act’s Article 3(1) data access by design obligation starts to apply, and it applies only to connected products and related services placed on the EU market after that date.
- Retailers are already bound. The pre-contractual disclosure duties in Article 3(2) fall on the seller, renter or lessor, not just the manufacturer, and they have applied since September 12, 2025.
- Scope is cross-sectoral, covering smart home devices, wearables, connected vehicles, industrial machinery and medical devices, and it reaches manufacturers wherever they are established.
- Penalties are national, not harmonised. Article 40 leaves the level to member states, and the announced ceilings already range from roughly EUR 50,000 for minor breaches in the German draft to 10% of EU-wide turnover in the Netherlands.
- It is one of four EU deadlines inside seven weeks, arriving the day after the Cyber Resilience Act reporting duties and two weeks before the green claims ban.
What actually changes on September 12, 2026
The Data Act is built in layers, and most of them switched on a year ago. The layer that switches on this September is the one that touches the product itself rather than the contract or the disclosure.
Under Article 3(1), connected products and related services must be designed and manufactured so that product data and related service data are, by default, easily, securely and free of charge accessible to the user. Where relevant and technically feasible, the data must be directly accessible rather than routed through a request process.
The design obligation in Article 3(1)
The wording matters because it is a design mandate, not a disclosure mandate. A manufacturer cannot satisfy it by publishing a policy or by promising to answer data requests within a month. The access route has to be engineered into the product and its related service.
Law firm analyses of the regulation, including published guidance from Alston & Bird and Latham & Watkins, describe the requirement as covering the format as well as the availability. Data must be structured, commonly used and machine-readable, which in practice points at documented APIs and standard export formats rather than a proprietary app screen.
The obligation is not limited to firms established in the European Union. It applies to manufacturers of connected products placed on the EU market and providers of related services irrespective of where those companies sit, which is why it reaches Chinese, US and UK device makers selling into the bloc.
Why the date splits the product catalogue in two
The single most operationally awkward feature of the September 12 date is that it does not apply to the shelf. It applies to the placing on the market.
Products placed on the EU market before September 12, 2026 are not caught by the Article 3(1) design obligation, even if they are still being sold in December. Products placed on the market after that date are caught, even if they are functionally identical to the earlier batch.
That creates a live inventory problem for anyone with deep stock and long product cycles. Two SKUs of the same connected kettle can sit on the same page with different legal statuses, and only the placing date distinguishes them.
Bird & Bird has noted in published analysis that firms with existing product lines therefore have additional runway, while new product development needs revisiting now. The practical read for retail buyers is that supplier assurance letters need to state a placing date, not just a compliance claim.
What the Data Act already required before this deadline
It is worth separating the September 2026 obligation from the ones already running, because a great deal of retail exposure is in the older tranche. The bulk of the regulation has applied since September 12, 2025.
Articles 4 and 5 give users the right to access product and related service data and to direct the data holder to share that data with a third party of the user’s choosing. Access must be easy, secure, comprehensive, structured and machine-readable, and free of charge where technically feasible, including continuous real-time availability where the product generates data continuously.
Article 5 is the one with competitive consequences. A consumer who buys a connected appliance can instruct the data holder to pass the device data to an independent repairer or a rival aftermarket service, which unpicks a good deal of the closed-loop servicing economics that device makers have built.
The cloud switching chapter runs on its own clock. Providers have faced switching obligations for new contracts since September 2025, and switching charges are scheduled to disappear entirely in January 2027, which matters for retailers running commerce workloads on a single hyperscaler. That is a separate compliance track from the product rules, and it sits alongside the Cyber Resilience Act reporting duties that start on September 11.
The trade secret safeguard, and its limits
The regulation does not force disclosure of everything. Data holders may withhold or condition access where sharing would reveal a trade secret, but the safeguard is narrower than device makers initially hoped.
To rely on it, the holder must identify the data it claims as a trade secret, take the reasonable steps needed to preserve confidentiality, and agree proportionate measures with the user rather than refuse outright. A blanket refusal on trade secret grounds is not contemplated by the text.
The seller is drawn into this too. Article 3(2) requires the pre-contractual disclosure to identify whether the seller is itself a trade secret holder and to name any trade secret holder involved, which means the answer has to be settled with the supplier before the product page goes live.
What retailers must tell shoppers before they buy
This is the part of the Data Act that most directly names retail, and it is already in force. Article 3(2) puts a pre-contractual information duty on the seller, renter or lessor of a connected product, not only on the manufacturer.
The duty runs before the user concludes the contract. That means the disclosure belongs on the product page and in the pre-purchase flow, not in a post-sale email or a manual in the box.
The Article 3(2) disclosure list
Published analysis of the article sets out a consistent list of what has to be communicated in clear and comprehensible language. The items are specific enough that a generic privacy notice will not cover them.
- The type, format and estimated volume of product data the connected product is capable of generating.
- Whether the product is capable of generating data continuously and in real time.
- Where the data is stored, on-device or on remote infrastructure, and for how long it is retained.
- The identity of the data holder, including trading name and contact details, and how the user can contact it.
- How the user can access, retrieve, or request erasure of the data, and how to complain to a competent authority.
- Whether the data holder itself intends to use the data, and whether it intends to share it with third parties.
- Whether the seller is a trade secret holder, and the identity of any trade secret holder involved.
- The duration of the contract and the arrangements for terminating it.
Where the disclosure has to sit on a product page
There is no prescribed template, which is both the flexibility and the trap. A retailer that buries the information behind a tab labelled “legal” is exposed to an argument that it was not provided in clear and comprehensible language before the contract.
The safer pattern that has emerged in early compliance work is a dedicated, expandable data section on the product detail page, positioned with the specification block rather than the footer. It sits naturally next to the energy label, the warranty statement and the sustainability claims a merchant already carries.
Marketplaces face a harder version of the same question. Where the third-party seller concludes the contract, the disclosure duty travels with that seller, but the platform controls the page template that determines whether the field exists at all.
That structural point is familiar from the pricing rules. It is the same architecture problem retailers hit when all-in checkout pricing rules forced a change to how totals are assembled rather than how they are worded.
Which products are in scope, and which are not
The Data Act defines a connected product as an item that obtains, generates or collects data about its use, performance or environment, and that can communicate that data through an electronic communications service, a physical connection or on-device access. A related service is a digital service explicitly linked to the operation of the product and capable of affecting its functions.
That definition is deliberately technology-neutral and cross-sectoral. It does not carve out consumer goods, and it does not set a price floor.
| Product category | Typically in scope | Main retail channel | Practical trigger |
|---|---|---|---|
| Smart speakers and displays | Yes | Electronics multiple, marketplace | Usage and voice-session telemetry |
| Robot vacuums and connected appliances | Yes | Electronics, DIY, marketplace | Run logs, error codes, maintenance data |
| Wearables and fitness trackers | Yes | Sports, electronics, D2C | Continuous sensor data |
| Connected vehicles and e-bikes | Yes | Dealer, specialist retail | Diagnostics, battery and route data |
| Smart meters and heating controls | Yes | Utility, DIY, trade counter | Consumption and performance data |
| Non-connected apparel and grocery | No | All | No data generation |
| Standalone software and apps | Generally not as products | Digital | Caught only as a related service |
The category that surprises merchants most often is the low-ticket connected accessory. A EUR 29 (about USD 34 at current rates) smart plug generates usage data, communicates it, and is therefore a connected product in the same sense as a car.
For cross-border sellers the reach is the point. The obligation follows the placing on the EU market, which is the same jurisdictional hook the bloc has used to reshape low-value import economics over the past year.
Who carries the obligation: manufacturer, data holder or seller
The Data Act allocates duties by role, and one company can occupy several roles at once. Getting the mapping wrong is the most common early compliance failure.
The manufacturer carries Article 3(1), the design obligation arriving in September 2026. The data holder carries the access and sharing duties in Articles 4 and 5. The seller, renter or lessor carries the pre-contractual disclosure in Article 3(2).
When a retailer becomes a data holder
A data holder is the entity that has the right or obligation to control access to the data of a connected product. Published guidance describes this as capable of including manufacturers, sellers, renters, lessors and third-party service providers with a contractual relationship to the user.
Private-label programmes are the obvious exposure. A grocer or electronics chain that commissions an own-brand connected device and operates the companion app is not only the seller, it is very likely the data holder and, depending on the arrangement, the manufacturer for regulatory purposes.
Retail media and loyalty programmes add a second layer. Where a merchant ingests device telemetry into a customer data platform for targeting, it needs a lawful basis under the Data Act as well as under the GDPR, and Article 4 restricts using non-personal product data to derive insights that would compete with the user’s own product.
Service contracts are the third. Extended warranty and repair propositions built on exclusive access to diagnostic data become harder to defend once the user can direct that data to a competitor under Article 5.
What enforcement looks like across member states
The Data Act does not set an EU-wide fine ceiling. Article 40 requires member states to lay down penalties that are effective, proportionate and dissuasive, and to designate competent authorities, which is why the enforcement map is uneven.
Published analysis from Wilson Sonsini notes that Finland, Germany, the Netherlands and Poland have adopted or advanced local implementing legislation, and that no major enforcement action has been reported to date. DLA Piper has published comparative analysis of the German and Maltese sanction regimes.
| Member state | Designated or proposed authority | Reported penalty ceiling | Status |
|---|---|---|---|
| Germany | Bundesnetzagentur (Federal Network Agency) | Tiered, reported up to EUR 5m (about USD 5.8m) or 2% of global turnover for the most serious gatekeeper breaches | Implementing law advanced |
| Netherlands | ACM (Authority for Consumers and Markets) | EUR 1.03m (about USD 1.2m) or 10% of EU-wide annual turnover, whichever is higher | Implementing framework in place |
| Poland | National authority under implementing act | Set nationally | Legislation advanced |
| Finland | National authority under implementing act | Set nationally | Adopted or advanced |
| Malta | National sanction regime | Set nationally | Analysed in comparative guidance |
The German tiers reported in law firm analyses descend from the gatekeeper ceiling through roughly EUR 500,000 (about USD 583,000) for significant breaches, EUR 100,000 (about USD 117,000) for mid-level infringements and EUR 50,000 (about USD 58,000) for minor ones. Reports of the headline German maximum differ, and the final figures depend on the text as adopted.
The gap between national ceilings
A Dutch ceiling expressed as 10% of EU-wide turnover and a German ceiling expressed as a tiered euro amount are not the same instrument. For a large multinational the Dutch formulation is materially more severe.
That divergence creates the familiar forum problem. A pan-European retailer will be assessed against whichever national regime its establishment and its sales footprint expose it to, and compliance programmes will be built to the strictest one.
The absence of enforcement actions so far should not be read as tolerance. The pattern across recent EU digital files has been a quiet first year followed by concentrated action, which is roughly the arc that produced the EUR 200 million DSA penalty now in its remedy phase, worth about USD 233 million at current rates.
Why the first cases will probably not be about design
The Article 3(1) design obligation is the headline, but it is the hardest thing for a regulator to open a file on. Proving that a product was not designed for data access by default requires technical assessment of the device and evidence of its placing date.
The Article 3(2) disclosure duty is the opposite. It is visible from the outside, it is testable by loading a product page, and it has been in force since September 2025 without a design grace period.
Consumer authorities across the bloc have historically run coordinated sweeps against exactly this kind of on-page duty. That pattern makes the retailer-facing disclosure a more plausible first target than the manufacturer-facing engineering mandate.
How this sits inside the wider EU autumn compliance stack
The Data Act deadline does not arrive alone. It lands inside a seven-week window that already carries three other retail-facing EU instruments, and merchants are resourcing all of them from the same compliance and engineering budget.
| Date | Instrument | Primary duty | Who it binds in retail |
|---|---|---|---|
| August 12, 2026 | Packaging and Packaging Waste Regulation | Packaging composition and substance limits | Everyone shipping goods into the EU |
| September 11, 2026 | Cyber Resilience Act | Incident and vulnerability reporting timelines | Importers and distributors of digital products |
| September 12, 2026 | Data Act Article 3(1) | Data access by design for new connected products | Manufacturers, with knock-on duties on sellers |
| September 27, 2026 | EmpCo green claims directive | Ban on unsubstantiated environmental claims | Anyone marketing goods to EU consumers |
The September 11 and September 12 pairing is the awkward one. The Cyber Resilience Act and the Data Act both attach to connected devices, both reach importers and distributors, and both landed on the same product teams within twenty-four hours of each other.
They pull in mildly opposing directions. One instrument demands the device be locked down and its vulnerabilities reported quickly, the other demands its data be opened up by default, and the reconciliation happens in the same firmware.
The packaging rules that took effect earlier in August are the outlier only in that they touch physical goods rather than data. Retailers working through the EU packaging regulation and its PFAS restrictions are drawing on the same supplier assurance process the Data Act now needs.
What it means for pricing, assortment and non-EU sellers
Compliance cost in connected hardware does not distribute evenly. It falls hardest on low-margin, low-ticket devices where the engineering work to expose a documented data interface is fixed but the unit economics are thin.
The predictable response is assortment rationalisation rather than price increases. Where a EUR 25 connected accessory cannot carry the cost of an API and a maintained data export, the rational move is to drop the SKU from the EU catalogue or to remove the connectivity.
How big the exposed category is
The connected-goods category the Data Act touches is substantial rather than marginal. Industry estimates put the European smart home market at roughly USD 24 billion in 2026, growing at a mid-single-digit compound rate toward the low USD 30 billions by the start of the next decade.
Distribution is concentrated in exactly the channels the disclosure duty binds. Research cited across market trackers puts retail and e-commerce at close to 58% of European smart home revenue, with Germany accounting for roughly a quarter of it.
Installed base is the number that scales the compliance work. Gartner has estimated that connected devices in European households would reach about 1.2 billion by 2026, up from roughly 700 million in 2022, and each of those units sits behind a product page that now needs a data disclosure.
Those figures are estimates from commercial market trackers rather than official statistics, and they vary by methodology. The direction is consistent across sources even where the levels are not.
The non-EU seller question
Because the obligation attaches to placing on the EU market, a manufacturer in Shenzhen or Ohio is caught in the same terms as one in Bavaria. Enforcement reach is a different question from legal scope, and it runs through importers and distributors who are established in the bloc.
That is the same enforcement geometry the EU has used elsewhere. Where the manufacturer is beyond practical reach, the pressure lands on the European entity that put the product on the shelf.
The marketplace exposure
Marketplaces carrying long-tail connected goods from third-country sellers face the most concentrated version of the risk. The catalogue is large, the seller base is fragmented, and verifying a placing date across thousands of SKUs is not a manual task.
Platforms have generally responded to comparable EU obligations with attestation fields and delisting powers rather than with verification. The pattern in product safety and environmental claims suggests the same approach will be applied here, and that a wave of catalogue attestation requests will hit sellers before the date.
Sustainability marketing is where the two compliance tracks meet commercially. Any device brand preparing for the green claims ban that lands on September 27 is already rewriting the same product pages the Data Act disclosure has to sit on.
What to watch between now and September 12
Three things will determine how disruptive the date actually is, and none of them is settled.
The first is national implementation. Several member states have advanced or adopted implementing laws, but the designation of competent authorities and the final penalty schedules are not uniform, and firms cannot build a single compliance target until they are.
The second is Commission guidance. Interpretive material on the boundary between product data and inferred or derived data would resolve a genuine ambiguity, because the regulation covers data generated by the use of the product rather than analytics built on top of it.
The third is supplier documentation. Retail buyers need placing-date attestations in purchase agreements for autumn and winter intake, and that is a procurement change rather than a legal one.
The forecast is not that September 12 produces enforcement. It is that it produces a two-tier catalogue, a wave of supplier attestation requests, and a quiet trimming of the cheapest connected SKUs from EU assortments in the first half of 2027.
Frequently asked questions
What exactly happens on September 12, 2026?
The data access by design obligation in Article 3(1) of the EU Data Act starts to apply. Connected products and related services placed on the EU market after that date must be designed so that product data is accessible to the user by default, in a structured, commonly used and machine-readable format, and directly where technically feasible.
Does the deadline apply to stock already sitting in my warehouse?
No. The obligation attaches to products placed on the EU market after September 12, 2026, so goods placed on the market before that date are not caught by Article 3(1), even if they are still being sold afterwards. The practical difficulty is evidencing the placing date per batch.
Am I affected if I only sell the product and do not make it?
Yes, but under a different article. Article 3(2) puts a pre-contractual information duty on the seller, renter or lessor, and that duty has applied since September 12, 2025. It requires you to tell the buyer, before the contract, what data the product generates, where it is stored, who the data holder is and how the buyer can access or complain.
What counts as a connected product?
An item that obtains, generates or collects data about its use, performance or environment and communicates it over an electronic communications service, a physical connection or on-device access. The definition is cross-sectoral and covers smart home devices, wearables, connected vehicles, industrial machinery and medical devices, with no price floor.
How large are the fines?
There is no EU-wide cap. Article 40 leaves penalties to member states, and the announced regimes diverge sharply: the Dutch framework reaches EUR 1.03 million (about USD 1.2 million) or 10% of EU-wide annual turnover, whichever is higher, while German analyses describe a tiered schedule running down to roughly EUR 50,000 (about USD 58,000) for minor breaches.
Does the Data Act apply to sellers outside the European Union?
Yes. The obligations follow the placing of the product on the EU market and apply to manufacturers and related service providers irrespective of where they are established. In practice, enforcement pressure tends to land on the EU-established importer or distributor.
How is this different from the Cyber Resilience Act deadline the day before?
They are separate regulations with opposite emphases. The Cyber Resilience Act, which starts its reporting duties on September 11, 2026, is about securing digital products and reporting vulnerabilities and incidents quickly, while the Data Act is about opening the data those products generate to the user.
Can a customer send my device data to a competitor?
Yes, under Article 5. A user can instruct the data holder to make the product and related service data available to a third party of the user’s choosing, which is the provision that opens aftermarket repair and servicing to competitors of the original manufacturer.
What should a retailer do first?
Two things in parallel: add the Article 3(2) disclosure block to connected-product detail pages, since that duty is already live, and write a placing-date attestation into purchase agreements for autumn and winter intake so the catalogue can be split cleanly at the September 12 boundary.