Skip to content

Manufacturing

What the EU Data Act means for US manufacturers of connected products

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

The EU Data Act can apply to US manufacturers whose connected products are placed on the EU market, wherever the manufacturer is based. It generally gives users access to data their product use generates, lets them direct it to third parties, and ties the manufacturer's own use of non-personal product data to a contract with the user.

Key takeaways

  • Where a manufacturer is based does not settle the question; placing connected products on the EU market can bring it into scope.
  • Users can generally access product and related service data and ask for it to be shared with third parties.
  • A manufacturer's own use of non-personal product data generally needs a basis in a contract with the user.
  • Internal records such as NCRs and ECOs are generally not product data, but other laws and contracts still apply to them.

Who does the EU Data Act reach?#

The EU Data Act reaches manufacturers of connected products placed on the EU market and providers of related services offered there, regardless of where the company is established. A Midwest maker of compressors, machine tools or building controls can be covered if its products are placed on the EU market, whether it sells directly or through EU distributors.

Connected products are items that obtain, generate or collect data about their use or environment and can communicate it, which covers much industrial equipment with telemetry. Related services are digital services, such as an app used to monitor, control or adjust the product, that the product needs to perform a function or that add to or adapt its functions. The user is the business or person that owns, rents or leases the product or receives the service.

Some smaller manufacturers may fall under exemptions, and how the rules apply to products sold through distributors or built into another maker's equipment depends on the facts. Those are among the first questions to put to counsel.

The main obligations at a glance#

The main Data Act obligations cover user access, third-party sharing, compensation, contract terms, trade secrets, pre-contract information and product design. The table summarizes them in general terms, with something concrete to check inside the business for each; the precise requirements, exceptions and timelines need review against the regulation itself.

The main obligations at a glance
Obligation areaWhat the regulation generally requiresWhat to check
User accessUsers can access readily available product and related service data, with metadata, generally without charge to the userWhich data each product generates and where it lands: device, dealer tool or your cloud
Third-party sharingAt the user's request, the data holder makes data available to a third party the user names, on fair termsHow requests would be received, verified and fulfilled
CompensationReasonable, non-discriminatory compensation can generally be agreed with third-party recipients, limited to cost when the recipient is a small or medium-sized businessWhether you can document the cost of providing data
Contract termsThe data holder's use of non-personal product data generally rests on a contract with the user; unfair terms imposed on businesses may not bindSales, lease, service and software terms
Trade secretsSharing can be conditioned on confidentiality measures and, in exceptional cases, refusedWhich data reveals trade secrets, and the measures you would require
Pre-contract informationBuyers and lessees are told what data the product generates and how to access itProduct documentation and the sales process
Product designProducts designed so data is accessible, on its own timetableEngineering roadmap for new models

How the Data Act interacts with licensing equipment data#

The Data Act matters most for licensing when the data comes from customer installations. If a manufacturer wants to license telemetry, fault codes or usage logs from machines in EU customer plants, the regulation generally limits its own use and onward sharing of non-personal product data to what the contract with the user allows. It also generally bars using that data to derive insights about the user's economic situation, assets or production methods in ways that could undermine the user's commercial position, which matters when machine data shows how a customer runs its plant.

That makes the customer contract the starting point. Many older sales and service agreements say nothing about data use, or reserve broad rights in language that was never tested against these rules. How far a contract can authorize licensing to an AI developer is a question for counsel, and the answer may differ by contract and customer.

Personal data adds a second layer. Where machine data can be linked to an operator or another person, GDPR applies alongside the Data Act and needs its own legal basis.

Which of your records are in scope#

Only some of a manufacturer's records are in scope: the Data Act focuses on data generated by the use of connected products and related services. A plant's own production, quality and engineering records usually sit outside that definition, though contracts, trade secret law and privacy law still apply to them.

The useful habit is to classify record families before any licensing conversation. A short note against each family, stating whether it comes from customer installations or from your own operations, saves repeated debate later.

Which of your records are in scope
Record typeLikely Data Act relevanceNotes
Telemetry, sensor readings and fault codes from customer installationsLikely in scope as product dataYour use generally depends on the user contract
Data from a remote monitoring app or fleet portalLikely in scope as related service dataCheck service terms and data flows
Your own production, quality and engineering recordsGenerally not product dataContracts and other laws still apply
Field service work orders by your techniciansMixed: may include readings taken from the machineReview case by case
Analytics and insights you derive from raw dataGenerally outside the access rightContract terms may still address them
Data identifying operators or other peopleGDPR applies alongsideNeeds its own legal basis

Practical steps for a US manufacturer#

A practical response starts with knowing which products reach EU users and what data they produce. From there, most of the work is contract review and process design rather than engineering.

Each step produces records worth keeping. A documented data map and contract review also make later licensing decisions faster, because the rights questions have already been asked and answered.

  • List connected products that reach EU users, directly, through distributors or inside other makers' equipment.
  • Map the data each product and related service generates, and where it is stored.
  • Review sales, lease, service and software terms for data use and sharing clauses.
  • Design a process to receive, verify and answer user and third-party requests.
  • Identify trade secrets in product data and the confidentiality measures you would require.
  • Coordinate with the GDPR program on data that relates to people.
  • Decide whether to license any customer-generated data, and on what contract basis.

Illustrative: a compressor maker sorts its data before licensing#

Illustrative: a fictional US maker of industrial air compressors sells into the EU through distributors and offers a remote monitoring portal. Its general counsel learned that the engineering team hoped to license years of fault codes and repair outcomes to an AI developer.

The legal team mapped the data. Fault codes and run hours from EU installations came through the portal and were product or related service data, and the service contracts were silent on data use. The repair narratives written by the company's own technicians were a separate record family.

The general counsel held EU fleet telemetry back while outside counsel reviewed and updated the contracts. A first package was scoped from internal repair narratives with customer identities removed, adding US fleet data only where customer contracts had been reviewed and permitted it.

How SourceX treats Data Act questions in a license#

SourceX does not give legal advice; Data Act questions are assessed deal by deal with the supplier's counsel. Within the SourceX five-step transaction, the Rights step records, for each record family, whether it comes from customer installations or the supplier's own operations, which jurisdictions and contracts apply, and what basis supports licensing.

The SourceX Evidence Packet then documents provenance, licensing rights, permitted use, the privacy record and release authorization. For equipment data, the licensing rights section is where the contract basis with EU users is written down, so a buyer can see why fleet telemetry was included or held back.

Frequently asked questions

Does the Data Act apply if we sell only through EU distributors?

It can. Placing products on the EU market through distributors, dealers or integrators may bring a manufacturer into scope even without an EU entity or direct sales. How the rules apply depends on the product, the data flows and the commercial chain, so counsel should review the specific setup.

Is the Data Act the same as GDPR?

No. GDPR governs personal data. The Data Act covers access to and sharing of data generated by connected products and related services, much of which is non-personal. Where data relates to an identifiable person, GDPR applies alongside the Data Act and takes priority on personal data questions.

Can we charge customers for access to their own data?

Generally not the user. The regulation generally provides that users access their product data without charge. Compensation is a matter between the data holder and third-party recipients, where reasonable compensation may be agreed, with tighter limits when the recipient is a smaller business.

When do these obligations apply?

The regulation already applies, but not every obligation started at once. Product design requirements and some contract rules for existing agreements follow their own timelines. Confirm the dates that matter for your products and contracts with counsel, because they affect both new models and the installed base.

Do we have to share data with our competitors?

Possibly. A user can direct its product data to a third party of its choice, and that may be an independent firm competing for your maintenance work. What the recipient generally may not do is use the data to develop a competing connected product. Trade secret measures and compensation terms also shape what is shared and how.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify