What EU Data Act Changes For IoT Device Owners
A connected doorbell, smartwatch, car, heat pump or industrial sensor produces a steady stream of information while it performs an ordinary task. Until recently, the company behind the product generally controlled how that information was accessed, packaged and shared. The European Union’s Data Act changes that balance by giving users stronger rights over data generated through connected products and related digital services.
The law is part of the EU’s wider attempt to make the data economy less dependent on a small group of technology platforms. It sits alongside the General Data Protection Regulation, the Digital Markets Act and cybersecurity rules, but it addresses a different problem. The Data Act is chiefly about access to and use of data, including data that is not personal information.
For an Australian owner, the practical effect depends on the product, the seller and the connection to the European market. Buying a smart speaker in Brisbane does not automatically turn every European data right into an Australian one. However, many devices sold globally are designed around EU compliance, so the regulation may influence product settings, contracts and support policies in Australia as well.
The change is therefore less dramatic than a new privacy dashboard appearing overnight, but more important than a minor terms-and-conditions update. It may make it easier to retrieve sensor data, move cloud services, authorise an independent repairer or challenge a contract that gives a manufacturer excessive control.
The Rule Behind The New Rights
The Data Act is Regulation (EU) 2023/2854. It entered into force in 2024, with most obligations applying from 12 September 2025. Its central idea is that a person who uses a connected product should be able to access data produced by that use, rather than being locked out by the manufacturer’s software or cloud infrastructure.
The law covers “connected products” that obtain, generate or collect data about their use or environment and can communicate that data electronically. That description includes smart appliances, connected vehicles, fitness trackers, agricultural equipment, medical-adjacent devices and many industrial machines. A related service, such as the app or subscription that helps operate the product, can also fall within the framework.
The rules distinguish between the product user and the data holder. The user might be the owner, lessee or another person with a contractual right to use the device. The data holder is commonly the manufacturer or service provider, although the legal position can vary. Data holders must make relevant data and metadata available to the user, usually in a structured, commonly used and machine-readable format.
This does not mean every internal company file becomes available. Trade secrets, security-sensitive material and information protected by other laws can limit disclosure. Nor does the Act erase intellectual property rights or permit a user to demand source code. Its focus is usable information produced by the device and the service surrounding it.
What Owners Can Ask For
A user may request data generated by a connected product and receive it without charge. The request should cover both the information itself and the metadata needed to understand how it was created. For a smart meter, that could include readings and timestamps; for a vehicle, it might include diagnostic or usage information; for a wearable, it may include activity measurements stored by the device or its service.
The user can also ask for the data to be made available to a third party. That could support an independent maintenance provider, an insurance service, a competing analytics platform or a home automation system. The third party must have a legitimate basis for receiving the information, and personal data still requires a lawful processing ground under privacy law.
This is where the Data Act intersects with GDPR principles. A person’s heart-rate history, location trail or voice recording may be both “data generated by use” and personal information. The Data Act does not provide a shortcut around consent, transparency, purpose limitation or data minimisation. A useful overview of that relationship appears in this GDPR context, particularly where device data can identify a household member.
Access should become more practical because manufacturers must design products and related services with data accessibility in mind. For new products, information about what is collected, how it can be accessed and who may use it should be supplied before a purchase or lease. That information may affect whether a buyer chooses a device in the first place.
What Changes For Australian Households
The law has its clearest reach in the EU, but Australian consumers encounter the same connected-device brands in Sydney, Melbourne, Perth and regional areas. A global manufacturer may build one firmware architecture and one account system rather than maintain separate rights for every country. An EU-compliant export function can therefore appear in an Australian app even when local law does not require it.
The direct legal benefit is more limited when a device is bought and used entirely in Australia. A product placed on the EU market or a service offered to users in the EU is more likely to fall within the regulation. An Australian buyer should check the local contract, privacy policy and retailer relationship instead of assuming that the EU rules apply merely because the brand has a European website.
Australia already has relevant protections through the Australian Consumer Law, privacy legislation and sector-specific rules. The Australian Consumer Law can help with faulty goods, misleading representations and services that do not meet consumer guarantees, but it does not create a broad equivalent to the Data Act’s right to obtain machine-readable usage data. The Privacy Act also focuses on personal information rather than the full category of industrial or environmental data covered by the EU regulation.
Local buying habits matter. A smart irrigation controller purchased from Bunnings, a security camera ordered online or a connected appliance supplied through JB Hi-Fi may involve a manufacturer, Australian importer, retailer and overseas cloud provider. Data access may depend on which of those parties operates the account and where the relevant service is legally supplied.
For Australian owners, the practical expectation should be cautious optimism: EU-facing products may offer better portability and transparency, but a request may still need to be grounded in the seller’s Australian terms, consumer guarantees or privacy commitments.
The Difference Between Personal And Non-Personal Data
Privacy discussions often focus on names, email addresses and precise location. The Data Act goes further by recognising that valuable information can be non-personal. Temperature readings from a commercial refrigeration unit, battery performance data from an electric vehicle or vibration records from a factory motor may not identify an individual, yet they can be commercially significant.
That distinction matters for owners who want to use a repairer or a competing service. A manufacturer may be able to protect confidential algorithms or trade secrets, but it should not be able to make routine maintenance impossible simply by keeping ordinary machine data inaccessible. The regulation is intended to reduce that kind of lock-in.
The rights are not absolute. A request involving personal data may need consent from another person whose information is captured. A request that creates a serious security risk can be restricted. Data holders may also refuse a demand that would disclose a protected trade secret, although the exception is not supposed to become a blanket excuse for withholding everything.
The following comparison shows how the main categories differ in practice:
| Situation | Likely Data Act relevance | What the owner may receive or do |
|---|---|---|
| Smart appliance records energy use | High if the product is covered and placed on the EU market | Request usage data in a usable format |
| Fitness tracker stores health metrics | High, with GDPR safeguards | Access personal data and authorise a third party where lawful |
| Connected car sends diagnostic readings | High, subject to safety and trade-secret limits | Obtain vehicle data or share it with an independent provider |
| Device reveals another person’s private information | Limited by privacy law | Access may require consent or protective restrictions |
| Old product with no practical data interface | Potentially covered, but implementation may be difficult | Ask the data holder how access is provided |
| Australian-only purchase with no EU market connection | Uncertain or outside direct scope | Rely mainly on Australian law and contract terms |
Repair, Switching And Competition
One of the most useful effects may be felt after the initial purchase. If device data can be shared with an authorised third party, an owner may have more choice between the original manufacturer and an independent service. That could matter for agricultural equipment, fleet vehicles, commercial refrigeration and complex home energy systems.
The law also addresses switching between data processing services, including cloud and edge providers. Providers must reduce technical and contractual barriers that make it difficult to move data and applications elsewhere. Charges for switching are being phased out, which could improve competition among storage, analytics and device-management platforms.
For a household, this might mean moving a smart-home history from one service to another or using a different platform to analyse solar generation. It will not necessarily create instant compatibility. A new provider still needs to support the relevant formats, APIs and security requirements, and a manufacturer may not be obliged to redesign an old device to work perfectly with every rival service.
Connected cars demonstrate the stakes. A driver could want diagnostic data sent to an independent mechanic rather than the dealership network. A fleet operator might need to combine information from several vehicle brands. The Data Act could make those uses easier, but safety, cybersecurity, insurance and personal-data rules will continue to shape the result.
Owners should also distinguish data access from repair access. Being able to download a log does not automatically provide physical parts, firmware tools or permission to modify safety-critical software. The regulation helps reduce information asymmetry, but it is not a universal right to dismantle or reprogram every product.
Contracts, Surveillance And Everyday Control
The Data Act places limits on unfair contractual terms imposed on smaller businesses. A clause that gives a data holder excessive control, excludes mandatory rights or makes the user liable for obligations that should sit with the provider may be challenged. This is especially relevant to small Australian businesses dealing with European suppliers, although the precise jurisdictional position needs legal assessment.
The law also permits public-sector bodies to request certain data in exceptional circumstances, such as a public emergency. That power is intended for situations where the data is necessary and cannot reasonably be obtained another way. It is not a general licence for routine government surveillance, but it reinforces the importance of knowing what a connected product records and where that information travels.
For individuals, the larger cultural issue is visibility. A person may own a camera, speaker or watch without knowing whether the device continuously uploads recordings, derives behavioural profiles or retains detailed histories. Data access can expose the scale of collection, while portability can make it easier to leave a service that uses intrusive practices.
A phone can reveal more than its visible apps suggest. Hardware-level location behaviour deserves separate attention, and a technical guide to checking whether a phone’s baseband is leaking location information can help explain why ordinary privacy settings are not the whole story: baseband location leak.
What Owners Should Do With The Change
The first step is to identify the data relationship around each important device. Record the manufacturer, app, cloud account, retailer, subscription provider and repair channel. A connected alarm installed by a security company may have a different data holder from a camera bought directly from a retailer, even if both use the same mobile app.
Next, look for an export, download or data-sharing function in the account settings. If the device is likely to be covered by the EU rules, make a specific written request describing the product, the relevant period and the format required. Ask for the data and the metadata needed to interpret it, rather than requesting “everything” in vague terms.
Security should remain part of the decision. Giving a third party access to vehicle telemetry, household occupancy patterns or health information can create a new privacy risk. Use the narrowest permission available, check how long the recipient retains the information and avoid sending raw data to an unfamiliar service simply because it offers a free analysis.
Australian owners should also keep receipts, warranty records and copies of privacy policies. If a seller makes a claim about data access, repairability or compatibility, that representation may matter under Australian Consumer Law. For a business, the records can help distinguish a routine support request from a dispute over contractual access.
The EU Data Act will not make every IoT product open, private or interoperable. It does, however, challenge the assumption that the company operating the cloud should have exclusive control over information produced by a device in someone else’s home, car, farm or workplace.
A concrete next step is to choose one connected device you use regularly, download its current account data and write down which information remains inaccessible.