Are your Connected Vehicles ready for the compliance deadline of 12 September 2026?
While the first part of the EU Data Act (Regulation 2023/2854) applies since last year, as of 12 September 2026 manufacturers of Connected Vehicles and providers of related services will be required to design and provide their products and services in such a manner that the associated data is accessible to the user.
Remote locking, pre-conditioning, EV charging management and dynamic route optimization are all examples of related services in the automotive context.
Complying with these requirements is not limited to the design and manufacturing phase, nor is this limited to the user’s personal data. Stay informed and prevent significant fines and/or other regulatory sanctions.
What products and services are in scope of the Data Act?
The Data Act focuses on connected products and related services. A connected product is broadly defined as an item that obtains, generates or collects data about its use, performance or environment and can communicate that data, such as a Connected Vehicle.
A related service is a digital service connected to the product in such a way that it affects the product’s functions, behavior, or operation. Remote locking, pre-conditioning, EV charging management and dynamic route optimization are all examples of related services in the automotive context.
Who needs to comply with the Data Act?
While manufacturers of Connected Vehicles and providers of related services need to ensure compliance, the Data Act also introduces the role of the ‘data holder’. The data holder is the entity that has the right or obligation to use or make available the data of connected products and/or related services. In many cases this will be the manufacturer or the service provider, but not necessarily. A manufacturer may, for example, contractually transfer its role of data holder to a different party.
Data Access: access-by-design vs. indirect access by request.
The core requirements of the Data Act are centered around providing access to data to users of connected products and related services. Manufacturers and service providers must design their products and services so that the relevant data are easily, securely, free of charge, and in a comprehensive format accessible to the user.
There are two ways to facilitate access to the data, either by providing direct access, also referred to as access-by-design, or indirect access. Data are directly accessible when the user can access the data without the intervention of any other party. Indirect access in essence entails the data holder making the readily available data available to the user upon request.
The Data Act offers some level of discretion to data holders in their design choices to provide either direct or indirect access, by only requiring direct access where relevant and technically feasible. The choice for direct or indirect access is highly relevant, as it influences what requirements data holders have to comply with.
Data Sharing with third parties: at the request of the user.
The Data Act does not merely provide a user with the right of access to data but also gives the user the right to instruct the data holder to make data available to a third party of the user’s choice.
That is particularly relevant in the Connected Vehicle ecosystem, where independent repairers, fleet service providers, charging optimization services, insurers, and other aftermarket players may seek access to vehicle data at the user’s request. The data holder must make the relevant data available to that third party without undue delay and at the same quality as is available to the data holder.
What data actually has to be shared?
Not all data in possession of the data holder needs to be made accessible. The data that needs to be shared includes raw data and pre-processed data, together with the relevant metadata needed to interpret and use that data.
Raw data includes source-level information that is not substantially modified, such as sensor signals, raw camera outputs, basic user commands, and component status data. Pre-processed data are data that have been processed for the purpose of making it understandable and usable prior to further processing and analysis, i.e. the nature of the underlying data remains unchanged by the processing. Examples include calculations of average speed in km/h and measurement of acceleration.
By contrast, inferred or derived data is excluded where the data holder’s additional investment creates genuinely new insights such as optimal routing outputs, advanced driver-assistance system outputs, driver scoring or personalized fuel consumption predictions. Moreover, under certain circumstances data relating to security or trade secrets may be excluded from being made accessible.
(Pre)-contractual requirements
The Data Act also lays down transparency requirements for the precontractual phase. Before purchase, lease, rent, or service onboarding, users must receive information about what data is generated, in what format and volume, how it can be accessed, etc. Related services trigger additional information requirements, such as in relation to expected data uses and third-party sharing.
The Data Act also includes several contractual requirements. When a data holder must make data available to a third party, such as at the request of a user, the data sharing needs to be subject to a contractual agreement. Although in principle parties are free to discuss and negotiate the terms, the Data Act does contain multiple rules and requirements in relation to this agreement. For example, the terms need to be Fair, Reasonable and Non-Discriminatory. In addition, the Data Act stipulates that a data holder can only use non-personal data of users when they have concluded a contract.
Need assistance? Reach out to our Connected Vehicles / Automotive specialists Laura Poolman and Reindert van der Zaal – who are happy to assist.