← Back to insights

The Machine Generates the Data. Who Can Ask for a Copy?

Reconstruct an EU Data Act connected-product request from the product, user, readily available data, delivery route, third party and qualified restrictions.

A connected-product data request envelope holds the product, user, available data, delivery route, third party and restrictions
#EU Data Act#Connected Products#Industrial IoT#Data Access#Article 4#Article 5

Signals to watch

  • A manufacturer or service provider has a dated request for raw and pre-processed product data but the exact user and product remain identifiable
  • A user has asked that connected-product data go to a named maintenance or analytics provider, creating an Article 5 third-party handoff question
  • The discussion names a missing machine-readable export or API while privacy, trade-secret and security safeguards are still open

Under the EU Data Act, the fact that a manufacturer operates the cloud account does not by itself settle who may access data generated by a connected product. The first answer depends on the product, the user and the readily available data. Article 4 concerns access by the user; Article 5 concerns making data available to a third party at the user’s request. Personal-data law, trade secrets and security safeguards still apply.

An industrial-IoT data platform or integration provider’s sales director needs those nouns in authorised device-OEM, vehicle-data and machine-service Telegram groups. “Need a Data Act application programming interface (API)” is too broad. A useful discussion identifies a product, user, available data and dated reason to move them. A one-day delay can cost the workshop where the OEM, user and maintenance partner assign the route.

Start with the physical product, not the desired API

Article 2 of Regulation (EU) 2023/2854 defines a connected product as an item that obtains, generates or collects data concerning its use or environment and can communicate product data through an electronic communications service, physical connection or on-device access. Its primary function is not storing, processing or transmitting data on behalf of someone other than the user.

The definition reaches beyond consumer gadgets to machinery, connected vehicles, health devices and agricultural equipment. It also stops the analysis from beginning with every hosted database.

A related service is a digital service connected to the product at purchase, rent or lease, or later connected in a way that affects its functions. A service dashboard may be relevant, but its operator is not the whole legal answer.

Open a request envelope around one product

Place the surviving facts in one request envelope:

  • Product: model, serial or fleet scope, and how it communicates data;
  • User: the person or organisation that owns, rents or leases the product, or receives the related service under the applicable basis;
  • Data: the raw and pre-processed product or related-service data that are readily available to the data holder;
  • Route: direct access, an export, an interface or continuous and real-time access where relevant and technically feasible;
  • Third party: any maintenance, analytics, insurance or other service provider designated by the user;
  • Restrictions: personal-data basis, trade-secret measures, security concerns and any disputed derived data; and
  • Date: the contract, repair, switching or project event that makes access necessary now.

This request envelope is the article’s original contribution. It prevents a missing field from being replaced by an assumption when the discussion arrives as fragments rather than a procurement document.

Article 3 changes what should be known before the contract

Article 3 says connected products and related services must be designed and provided so that product data and related-service data, including relevant metadata necessary to interpret and use them, are by default easily, securely and free of charge accessible to the user in a comprehensive, structured, commonly used and machine-readable format. Where relevant and technically feasible, access should be direct.

Before a purchase, rent or lease contract is concluded, the user must receive specified information in a clear format, including the type, format and estimated volume of generated data, whether generation is continuous and real time, the access route and retention period. Related-service contracts have corresponding information duties.

A message saying “the manual never described the telemetry export” may reveal a documentation issue. It does not prove who is the data holder or that every field is covered.

Article 4 puts the user inside the envelope

Where the user cannot directly access data from the product or related service, Article 4 requires the data holder to make readily available data and the necessary metadata accessible to the user. The official text specifies without undue delay, with the same quality available to the data holder, easily and securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format. Where relevant and technically feasible, access may be continuous and in real time.

“Readily available data” is a defined boundary. It concerns product data and related-service data that the data holder lawfully obtains or can lawfully obtain from the connected product or related service without disproportionate effort going beyond a simple operation. An integration provider should not promise to create an entirely new sensor history merely because a user asks for it.

The scope also does not automatically include every insight. The Regulation distinguishes raw and pre-processed data from certain inferred or derived data produced through additional investment, especially by proprietary complex algorithms. The request envelope should name the fields rather than use the phrase “all data.”

Article 5 adds a third-party destination

A user may ask the data holder to make readily available data and metadata available to a third party. That can turn a maintenance provider, fleet-analytics company or aftermarket service into a real integration destination.

The destination cannot be inferred from “the customer wants an export.” The reviewer needs the designated third party, its service, required fields, delivery cadence and the user’s instruction. The rules also govern third-party use and restrict some routes involving designated Digital Markets Act gatekeepers.

Direct user access and user-directed third-party access may use similar APIs, but the actors, terms and evidence differ.

Example: the maintenance company is waiting for vibration data

Consider this illustrative composite thread, not a real customer exchange:

“Line 4 press is still under lease. OEM portal shows alarms but only PDF export.”

“Our vibration contractor needs the readings before the September shutdown. OEM says Data Act request has to come from the user.”

The messages identify a press, lease, OEM portal, alarm data, maintenance provider and September event. They do not establish the legal user, data holder, available fields, metadata, restrictions or formal designation.

The request envelope would read:

  • Product: Line 4 press; model and connected-service contract unknown.
  • User: lessee appears likely but must be confirmed from the lease.
  • Data: alarm and vibration readings requested; current availability and metadata unknown.
  • Route: portal provides PDF; machine-readable or continuous route unconfirmed.
  • Third party: named vibration contractor, authority from the user unconfirmed.
  • Restrictions: no facts yet about personal data, secrets or security.
  • Date: maintenance preparation before a September shutdown; exact deadline unknown.

That envelope can justify a controlled scoping call. It cannot prove that a particular API, field or real-time frequency is mandatory.

Privacy and trade secrets do not disappear

The Data Act operates alongside the GDPR. If requested data are personal and the user is not the data subject, the data holder still needs a valid data-protection legal basis.

Trade-secret protection is a qualified process, not a phrase that ends every request. The Regulation provides for identifying secrets and agreeing proportionate technical and organisational measures before disclosure. In specified exceptional circumstances, a data holder may withhold or suspend sharing where serious economic damage is highly likely despite those measures, but it must substantiate and communicate that decision. Product-security requirements can also affect access.

For opportunity discovery, these issues belong in the “restrictions” part of the envelope as questions with owners. They should never be marked resolved because one group participant wrote “GDPR” or “trade secret.”

TOP Prospect finds the fragments; people decide the request

TOP Prospect can filter and combine fragments from Telegram groups the user deliberately connects and is authorised to access. It preserves messages, sources and timestamps, removes obvious duplicates, summarises why a product, data field, third party and deadline appeared together, and ranks candidates for human review.

It cannot decide who is the statutory user or data holder, obtain data, override access controls, determine a GDPR basis, disclose trade secrets, write contract terms or contact group members. Pricing and access options cover the discovery layer. The data holder, user, third party and their advisers remain responsible for the lawful access route.

The Data Act also regulates switching between data-processing services. That different topic is covered by the cloud-switching demand article and the switching-charge deadline article. Those pages should not be used as proof of connected-product access obligations.

Key facts

  • The EU Data Act is Regulation (EU) 2023/2854.
  • A connected product obtains, generates or collects data about its use or environment and can communicate product data; its primary function is not data storage, processing or transmission for another party.
  • Article 3 covers product design and pre-contract information about product and related-service data.
  • Article 4 covers user access to readily available data and relevant metadata.
  • Article 5 covers user-requested availability to a third party.
  • Article 4 specifies access without undue delay, securely, free to the user and in a comprehensive, structured, commonly used and machine-readable format; continuous real-time access applies where relevant and technically feasible.
  • Certain inferred or derived insights produced through proprietary complex algorithms fall outside the mandatory access scope described in the cited provisions.
  • GDPR legal bases, trade-secret safeguards and product-security concerns remain relevant.

FAQ

What is a connected product under the EU Data Act?

Article 2 describes an item that obtains, generates or collects data about its use or environment, can communicate product data through an electronic communications service, physical connection or on-device access, and whose primary function is not storing, processing or transmitting data for someone other than the user.

Must a data holder provide every inferred insight produced from product data?

No. The Regulation excludes certain inferred or derived data that result from additional investment in assigning values or insights, particularly through proprietary complex algorithms, from the mandatory access scope described in the cited provisions.

Is connected-product data access always free?

Article 4 says the data holder must make readily available product data and related-service data accessible to the user without undue delay, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format. A third-party relationship under Article 5 has additional terms and should be scoped separately.

Does the Data Act replace GDPR rules for personal data?

No. When requested data include personal data and the user is not the data subject, a valid GDPR legal basis is still required. The Data Act does not create a blanket legal basis for personal-data disclosure.

Before anyone prices an API, close the request envelope: product, user, data, route, third party, restrictions and date.

Frequently asked questions

What is a connected product under the EU Data Act?

Article 2 describes an item that obtains, generates or collects data about its use or environment, can communicate product data through an electronic communications service, physical connection or on-device access, and whose primary function is not storing, processing or transmitting data for someone other than the user.

Must a data holder provide every inferred insight produced from product data?

No. The Regulation excludes certain inferred or derived data that result from additional investment in assigning values or insights, particularly through proprietary complex algorithms, from the mandatory access scope described in the cited provisions.

Is connected-product data access always free?

Article 4 says the data holder must make readily available product data and related-service data accessible to the user without undue delay, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format. A third-party relationship under Article 5 has additional terms and should be scoped separately.

Does the Data Act replace GDPR rules for personal data?

No. When requested data include personal data and the user is not the data subject, a valid GDPR legal basis is still required. The Data Act does not create a blanket legal basis for personal-data disclosure.

Sources and further reading

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage