Do not design Data Act access as a bypass around CRA security controls. Product architecture should support user data rights with authentication, authorisation, integrity, confidentiality and abuse resistance appropriate to the product. The Data Act has applied generally since 12 September 2025, while its Article 3(1) design obligation applies to connected products and related services placed on the market after 12 September 2026. Personal-data processing remains subject to GDPR and privacy law.
The CRA and Data Act Regulate Different Product Questions
The CRA asks whether a product with digital elements is cybersecure and whether vulnerabilities are handled throughout its support period. The Data Act asks who can access and use data generated by connected products and related services and under what conditions. A connected device can therefore be subject to both regimes without either one replacing the other.
The Data Act Has Applied Generally Since 12 September 2025
Regulation (EU) 2023/2854 applies generally from 12 September 2025. Its Article 3(1) design obligation applies to connected products and related services placed on the market after 12 September 2026. Product teams should therefore distinguish the Regulation's general application date from the later product-design applicability date.
The Data Act Uses Its Own Connected-Product Definition
A Data Act connected product is an item that obtains, generates or collects data concerning its use or environment and can communicate product data, while its primary function is not storing, processing or transmitting data on behalf of another party. That definition is not identical to the CRA definition of a product with digital elements, so scope should be tested separately under each Regulation.
Related Service and CRA Remote Data Processing Are Not Identical Concepts
The Data Act defines a related service as a digital service, including software, connected with the product so that its absence prevents one or more product functions or that is later connected to add, update or adapt functions. The CRA has a separate definition of remote data processing tied to manufacturer responsibility and product functionality. The concepts can overlap factually, but they should not be treated as interchangeable legal definitions.
Article 3 Creates a Secure Data-Access-by-Design Obligation
Article 3 requires connected products and related services covered by the provision to make product data and related-service data, together with necessary metadata, accessible by default in a manner that is easy, secure, free of charge, comprehensive, structured, commonly used and machine-readable, with direct access where relevant and technically feasible. Security therefore forms part of the access architecture rather than being an afterthought.
Data Access Should Not Disable CRA Security Controls
Data access interfaces can create authentication, authorisation, confidentiality, integrity and availability risks. CRA risk assessment should include Data Act access paths, APIs, export functions and third-party sharing mechanisms where they are part of the product attack surface. The Data Act requirement to provide access securely is compatible with using proportionate security controls.
Article 4 Recognises a Product-Security Restriction in Serious Cases
Data Act Article 4 permits users and data holders to contractually restrict or prohibit data access, use or further sharing where processing could undermine security requirements of the connected product laid down by Union or national law and result in a serious adverse effect on the health, safety or security of natural persons. The provision includes notification and dispute mechanisms, so it should not be treated as a broad discretionary cybersecurity exception.
Security Decisions Need Evidence
Where a manufacturer or data holder relies on a security restriction, preserve the product architecture, threat scenario, affected security requirement and evidence of the serious adverse effect being avoided. A generic statement that access is insecure is weaker than a product-specific risk analysis linked to the relevant Union or national security requirement.
The Data Act Does Not Override GDPR for Personal Data
Data Act Article 1 states that the Regulation is without prejudice to Union and national data-protection and privacy law. Where the data are personal data, GDPR and other applicable privacy rules continue to apply, and in a conflict the relevant personal-data or privacy law prevails. Data Act access rights therefore do not create a general legal basis for unrestricted personal-data processing.
Coordinate Product, Security, Data and Privacy Architecture
A connected-product design should map which data are generated, where they are stored, who can access them, which interfaces provide access, which security controls protect them and whether the data are personal data or trade secrets. This shared architecture record can support CRA risk analysis, Data Act access compliance and GDPR governance without merging their legal tests.
Product Changes Can Affect Both CRA and Data Act Compliance
Adding a new sensor, API, cloud service, data export or related service can alter the product's attack surface and the data-access obligations. Change management should therefore trigger both CRA cybersecurity review and Data Act review where the facts change materially.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.