Manufacturing
Does the EU Data Act apply to US equipment manufacturers?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
The EU Data Act can apply to a US equipment manufacturer with no EU office. The usual trigger is placing connected products, or offering related digital services, on the EU market, including through distributors and OEM customers. If your machines generate and transmit data about their use and some reach EU users, have counsel assess your obligations.
Key takeaways
- Where your connected products end up matters more than where your company is incorporated.
- Machines that generate data about their use and can communicate it are the main concern; purely mechanical equipment usually is not.
- Likely duties center on user access to product data, information before purchase and limits on the manufacturer's own use.
- Internal business records, such as ERP and quality files, are a separate question from product data.
- Applicability is assessed product by product, with EU counsel.
Short answer: yes, if your connected products reach EU users#
The EU Data Act is likely relevant to a US manufacturer if connected products it makes, or related services it provides, are placed on the market in the EU. The regulation states that it covers manufacturers of connected products placed on the EU market and providers of related services irrespective of where they are established, so the product's destination, not the company's address, is the starting point.
The table is a first screen to bring to counsel, not a legal conclusion. A yes in any of the first three rows is reason enough to ask the question formally.
| Screening question | If yes | If no |
|---|---|---|
| Does the product generate data about its use or environment? | Possibly in scope; keep going | Likely outside the product rules |
| Can it send that data out, by network, cable or download? | Possibly a connected product | Less likely to be in scope |
| Do units reach EU users, directly or through distributors or OEM customers? | Assess with counsel | Product rules may not apply today; check future sales plans |
| Do you offer an app or digital service that changes how the product works? | May be a related service | Product rules may still apply |
| Do you use product data from EU units yourself? | Your own use may need a basis in user agreements | Fewer data-holder questions arise |
What counts as a connected product and a related service#
A connected product, in general terms, is one that obtains, generates or collects data about its use or surroundings and can communicate that data. Compressors with remote monitoring, machine tools that report to a cloud portal, smart pumps and connected packaging lines are the kinds of equipment manufacturers ask about.
A related service is, broadly, a digital service tied to the product that affects how it functions, such as a control app or a remote configuration service. The regulation's definitions and exclusions are detailed, so counsel should read them against your actual product, firmware and software architecture rather than a marketing description.
Obligations that may reach a manufacturer#
The obligations that may reach an equipment manufacturer cluster around access, transparency and use. How they apply depends on your role, because the regulation distinguishes manufacturers, data holders, users and third-party data recipients, and one company can hold several roles at once.
The obligations apply on a phased timetable, and some design requirements look ahead to products placed on the market after certain dates. Ask counsel which duties are already in force for your products and which arrive with future models.
- Making product data accessible to the user, either by design or on request.
- Sharing product data with a third party at the user's request, under conditions the regulation sets.
- Telling users before purchase what data the product generates and how they can access it.
- Basing the data holder's own use of non-personal product data on an agreement with the user.
- Protecting trade secrets through agreed safeguards rather than refusing access outright.
- Avoiding unfair terms in certain business-to-business data contracts.
How US manufacturers get pulled in indirectly#
US manufacturers often get pulled in indirectly, through customers and channels rather than their own EU sales. A component maker whose connected sensors are built into an OEM's machine, a builder whose equipment an EU distributor resells, or a supplier to a US customer's European plant may all find EU users at the end of the chain.
Contracts are usually where this surfaces first. OEM customers may ask suppliers to support user data requests, provide technical documentation or accept new data clauses, and distributors may ask who answers users. Map where connected products actually go before deciding the regulation is someone else's problem.
What the Data Act means for licensing machine data to AI developers#
For licensing, the EU Data Act matters mainly for product data generated by units in EU users' hands. If the regulation applies, your ability to use that data, and so to license it, may depend on your agreements with those users, and the users may have their own rights to access and share it.
Your internal records are a separate question. ERP history, quality decisions, work orders on your own plant equipment and engineering change records are generally assessed under contracts, privacy laws and confidentiality duties rather than as product data. A cautious first scope covers those records, plus product data from units outside the EU, pending counsel's view.
Where product data includes personal data, such as operator logins or location, the GDPR continues to apply alongside the Data Act.
A readiness checklist for the general counsel#
A readiness checklist turns a broad legal question into a set of facts counsel can assess. Most of the answers sit with product, sales and service teams rather than with the legal department.
| Step | Question to answer | Usual owner |
|---|---|---|
| Product map | Which models collect and transmit data, and what data? | Head of product or engineering |
| Market map | Which units have reached EU users, through which channels? | Sales operations |
| Service map | Which apps, portals or remote services affect product functions? | Software or service lead |
| Contract map | What do user terms, portal terms and distributor agreements say about data? | General counsel |
| Use map | How does the company use product data today, including analytics and AI? | COO or CTO |
| Gap review | What must change for in-scope products, and by when? | General counsel with EU counsel |
Illustrative: a compressor maker maps its exposure#
Illustrative: a fictional US maker of industrial air compressors sells mainly to North American plants. Its newer models include a controller that reports pressure, run hours and fault codes to a cloud portal, and some units reach EU users through an EU distributor and through US customers with European plants.
The general counsel and the head of product list the connected models, trace where units shipped and review the portal terms. EU counsel advises that the connected models sold into the EU are likely in scope and that the portal terms need updating for EU users.
The CEO had been weighing a license of service history to an AI developer. The company scopes the first review to field service work orders, warranty diagnoses and portal data from North American units, and parks EU-origin telemetry until the user agreements are updated and counsel confirms the basis for using it.
How SourceX handles product data that may be in scope#
SourceX handles connected-product data in the Rights step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Where the EU Data Act or similar rules may apply, data from affected units stays out of scope until the supplier's counsel confirms the basis for using it.
The SourceX Evidence Packet records licensing rights, permitted use and the privacy record for each record family, so the geography and contractual basis of any product data included are documented rather than assumed. SourceX does not give legal advice on the regulation itself; that stays with the supplier's counsel.
Frequently asked questions
Does it matter that we have no EU office or subsidiary?
Not necessarily. The regulation's scope turns on whether connected products are placed on the EU market, irrespective of where the manufacturer is established. Having no EU entity can affect practical questions such as enforcement and representation, which counsel can explain for your situation.
Does the EU Data Act replace the GDPR for personal data?
No. The GDPR continues to govern personal data, and the Data Act is designed to sit alongside it. Product data can include personal data, such as operator logins or location, so both may need to be considered for the same dataset.
Does it apply to products we sold years ago?
Some obligations depend on when a product was placed on the market, and the timetable is phased, so products already in the field may be treated differently from new designs. Counsel should review your installed base and product roadmap together rather than one at a time.
Does the regulation cover our ERP and quality records?
Generally, the product rules concern data generated by connected products and related services, not a company's internal business records. ERP, QMS and plant maintenance records are usually assessed under contracts, privacy laws and confidentiality duties instead, though counsel should confirm for any records that contain product data.
Can users make us share product data with our competitors?
The regulation gives users rights to have product data shared with third parties, but it also contains safeguards, including for trade secrets, and limits on how recipients may use what they receive. How those safeguards apply to your products is a question for EU counsel.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.