Article · Data Protection

The EU Data Act in practice: a new era for connected product data

In force since September 2025, the Data Act has changed the contractual order of the data economy with its rules on access to, sharing of, and cloud switching for IoT product data. A guide for manufacturers and users.

12 May 20264 dk okumaBy Sven Köksal · Data Protection
Köksal Attorney Partnership — data, artificial intelligence, cybersecurity and legal tech work
Summary · At a glance
  • The Data Act makes user access to and sharing of connected product data mandatory.
  • Turkish manufacturers selling IoT products into the EU market are also within scope.
  • Unfair data clauses imposed on SMEs are not binding.
  • Trade secret protection continues; but a categorical refusal is not possible.

What does the Data Act introduce?

The EU Data Act aims to end the locking of data at the manufacturer: for the data produced by connected products (vehicles, machines, devices) and related digital services, the user has a right of access and sharing. Since September 2025 the main obligations have been in force, and contractual practice is changing rapidly.

Practical guidance

The first step is a data-flow map: what data does your product generate, where is it stored, and who can access it? The contract revision is built on this map.

Let us analyse your Data Act scope

We scan your product portfolio and set up a contract and process suite that is ready for access requests.

Data law advisory

Who is within scope?

Three groups stand out: those offering connected products or related services to the EU market (including manufacturers established in Türkiye), cloud and SaaS providers (switching rules), and industrial data users. Since scope is determined by the market in which the product is sold, the “we are not an EU company” defence does not work.

The access and sharing regime

The user can access the product data and can request that this data be shared with a third party of their choice (e.g., an independent service provider, an analytics provider). The sharing conditions are established on fair, reasonable, and non-discriminatory principles. Trade secrets are protected; however, the trade secret rationale cannot serve as a basis for a categorical refusal of access — the balance is struck by technical and contractual measures.

Impact on contracts

Sales, service, and cloud contracts must be updated in three directions: creating data access addenda, weeding out unfair data terms unilaterally imposed on an enterprise — the rule is not limited to SMEs, and building switching periods and fee limits into cloud contracts. In product design, the “accessible by design” obligation has entered the engineering agenda for next-generation products.

Relationship with GDPR and KVKK

If the data set contains personal data, the Data Act does not replace data protection law; they apply together. The practical consequence for Turkish manufacturers: the process that handles access requests must be designed together with the KVKK/GDPR filter.

How to build a trade secret defence

The Data Act’s most debated balance is between data sharing and trade secret protection. The Regulation does not grant the secret holder a categorical right of refusal; it does grant the right to condition sharing on protective measures: confidentiality agreements, technical access limits, purpose-of-use restrictions, and, in exceptional cases, suspension of sharing. In practice, this requires three preparations: an inventory of which data fields carry the character of a secret, documentation of the secret-protection measures, and a standard response protocol for access requests. A trade secret defence is built not when the request arrives but when the product is designed — the work of our intellectual property team in this area begins precisely with this inventory.

An impact map by sector

Automotive and machinery manufacturers: independent service providers’ requests to access vehicle and machine data; warranty and liability provisions need to be rebalanced. Energy and IoT-based services: the regime for sharing meter and sensor data with the customer and with third parties. Logistics: the status of fleet telemetry in customer contracts. Software/SaaS: building cloud switching periods and data export formats into the contract — in the procurement negotiations of our Legal Tech focus area, these provisions are now a standard bargaining item. For Turkish brands expanding into the EU market via e-commerce as well, selling a connected product means direct entry into the scope of the Data Act.

The Köksal approach

Our Data focus area combines Data Act scope analysis with GDPR/KVKK compliance and data contract architecture into a single project. Our Data & Cybersecurity Desk speaks the same language as technical teams to build processes that handle access requests.

Conclusion

The Data Act has made data contracts part of the product. Early compliance both reduces enforcement risk and creates commercial opportunity in the market for independent service and data collaboration. This file should be on the 2026 agenda of every Turkish manufacturer that sells a connected product.

This content is for general information purposes only and does not constitute legal advice. Please get in touch with our team for an assessment relating to your specific situation.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all

No; its main novelty is that it also covers non-personal product and service data. Where personal data is involved, GDPR/KVKK apply in addition.

If the product is placed on the EU market, the access and sharing rules apply even if the manufacturer is in Türkiye.

No; this is general information. Contact our team for your products.

Knowledge Centre

Let us analyse your Data Act scope

We scan your product portfolio and set up a contract and process suite that is ready for access requests.