Data Act: user right to product data
Users of connected products can access and share generated data with third parties; exam trap: confusing this with GDPR's right of access.
Listen to this page (beta)
The Data Act gives users of connected products—like smart thermostats, fitness wearables, or connected cars—a new right to access data their device generates and to share that data with third parties, such as repair shops or analytics firms. This is not about personal data under GDPR; it covers machine telemetry, usage logs, and performance metrics that are often non-personal. For example, a tractor's engine diagnostics or a smart meter's energy consumption patterns fall here, not your name or email address.
To avoid mixing up regulations, remember: GDPR is about 'your data about you' (personal), while the Data Act is about 'your device's data about its operation' (product-generated). A quick elimination trick: if the data identifies a person, it's GDPR; if it's raw sensor readings or performance stats, it's the Data Act. Also, the Data Act's right to share with third parties is broader than GDPR's portability, which only covers personal data you provided.
Test yourself: a connected coffee machine logs brew cycles and water usage. Can you share that data with a repair service? Yes, under the Data Act. If the machine also stores your name, that part stays under GDPR. This contrast—device data vs. personal data—is the core distinction the exam will probe.
What new practical right does the Data Act give users of connected products?
Access to data generated by their connected products and the ability to share it with third parties.