European Data Act: Balancing IP & Privacy

The EU Data Act signifies a fundamental change in the digital economy of Europe, redistributing power among manufacturers, users, and service providers, as explained by Peter Lando and Stefica Milor from Lando & Anastasi.

Since its implementation in September 2025, the EU Data Act has emerged as one of the most significant regulatory changes for businesses involved with connected products, associated services, and cloud environments in the EU market. Designed as a horizontal regulation to standardize data access and usage across various sectors, the act alters the dynamics between intellectual property, privacy, data governance, and competition.

Importantly, this regulation has extraterritorial applicability, meaning that non-EU companies fall under its jurisdiction whenever EU-based users engage with their products or services.

The act modifies the way companies handle data produced by connected products, including smart appliances, industrial equipment, vehicles, and medical devices. It encompasses all data generated from usage: raw sensor data, pre-processed information, metadata, and insights produced by machines. When data is collected or generated by a connected product or related service, the user (whether an individual or a business) is granted a legal right to access it.

By September 12, 2026, any new connected products introduced to the EU market must be designed for “access by design,” ensuring that data is available to users in a direct, secure, and easily accessible manner in structured, machine-readable formats. If direct access is not technically possible, the data holder is required to provide “readily available data” upon request without delay and at no cost to the user.

The act also allows users to direct data holders to share their generated data with third parties of their choice. This provision fosters interoperability, multi-vendor maintenance, independent repairs, and cross-service innovation, while also introducing new competitive dynamics into traditionally closed ecosystems.

Illinois’ experience with biometric privacy serves as a cautionary example for companies that manage genetic information in the age of AI.

While the act addresses both personal and non-personal data, GDPR regulations still apply to personal data. In cases of overlap—such as vehicle telemetry linked to a driver—GDPR obligations take precedence. Companies must carefully differentiate between data types, implement measures for minimization and transparency, and ensure that user-initiated sharing does not infringe on data privacy obligations.

Beyond GDPR, one of the most complex elements of the act involves the intersection of user data rights with proprietary protections like trade secrets and database rights.

Manufacturers frequently contend that device telemetry and operational data can disclose commercially sensitive information, including production techniques, algorithmic performance, diagnostic logic, or insights into product design. The act acknowledges this risk and introduces a “trade secrets handbrake” mechanism. Before revealing data that may contain trade secrets, the data holder can identify information deemed a trade secret; impose appropriate confidentiality and technical safeguards; and, in certain situations, refuse to disclose if adequate protections cannot be established.

This handbrake is not a loophole but a structured balancing mechanism. Companies cannot simply label all data as proprietary, and users have the right to contest overly broad claims.

Furthermore, the act explicitly forbids the use of certain database rights to obstruct user access to data generated by connected products. This specific measure prevents companies from leveraging database protections to monopolize machine-generated datasets.

Regarding downstream use, third parties designated by users who receive data must adhere to strict limitations, including: managing personal data in accordance with GDPR; prohibiting the use of shared data to develop competing products; and restricting data usage solely for the specified purpose.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *