From 13 September 2026, SMEs will be able to make better use of machine data because new connected products placed on the EU market must provide easier access to data. The data must be available securely, free of charge and in a machine-readable format. This new design requirement does not apply generally to older equipment already in use. However, the rights under the EU Data Act have generally applied since 12 September 2025.
Which devices are covered by the new data requirements?
The requirements apply to connected products that generate data during use and can transmit it via a connection. According to the Bundesnetzagentur (the German federal network agency), these include vehicles, medical devices, pumps, and industrial and agricultural machinery.
A connected product could, for example, be a CNC machine with sensors, a delivery vehicle with telematics or a heating system with remote monitoring. An associated digital service may also be covered, such as an application used to control or analyse the device.
According to the Bundesnetzagentur, conventional servers and routers are generally excluded. The decisive factor is not simply whether a device is connected to the internet. It must generate data about its use or environment and be capable of transmitting that data.
Exemptions apply to small manufacturers and service providers. According to the Bundesnetzagentur FAQ, these generally apply to businesses with no more than 49 employees and annual turnover or a balance sheet total of no more than 10 million euros. Some medium-sized businesses benefit from transitional arrangements of one year, so each case should be reviewed individually.
How can SMEs use machine data?
SMEs can use the data for maintenance, cost control and selecting independent service providers. This requires the relevant device to actually generate the necessary values.
A pump, for example, may record operating hours, pressure, temperature and vibrations. If vibration levels increase over several weeks, an inspection can be scheduled before a bearing fails. This predictive maintenance approach means that maintenance is not carried out solely according to a fixed schedule or only after a fault occurs.
Depending on their equipment, vehicles may provide data on mileage, energy consumption, charge levels or fault messages. A business can use this information to identify vehicles that consume unusually large amounts of energy or require more frequent workshop visits. The data can also be transferred to independent fleet management software or a workshop.
This reduces dependence on the manufacturer’s portal. However, it does not guarantee lower costs or compatibility with every type of software. Before introducing such a system, businesses should determine what data is available, how frequently it is generated and what specific operational benefit its analysis would provide.
The data often also needs to be combined with existing order, maintenance or cost information. In such cases, it may be useful to digitalise processes and replace individual Excel spreadsheets. For specialised analysis, custom software for processing machine and vehicle data may also be suitable.
How must manufacturers provide access to data?
Product data and the associated metadata must be accessible easily, securely and free of charge. Metadata is additional information that describes, for example, when a measurement was taken, its unit or the source of a value.
Under Article 3 of the EU Data Act, the data must be provided in a structured, commonly used and machine-readable format. Machine-readable means that software can import the values automatically, rather than employees having to copy them from PDF files or on-screen displays.
Where technically feasible, access should be direct, continuous and in real time. Direct access could, for example, be provided through a technical interface on the device. Such an interface, often called an API, enables controlled data exchange between two software applications.
If direct access is not technically possible, the data holder must, according to the Bundesnetzagentur, provide indirect access, for example through a web portal. At the user’s request, the data must generally also be transferred to a selected third-party provider. This could be an independent workshop, a maintenance company or a fleet management software provider.
The EU Data Act does not override other rules. If datasets contain personal information, the Datenschutz-Grundverordnung (General Data Protection Regulation) and any consent or contractual requirements continue to apply. Trade secrets may also require specific protective measures, but they must not be used as a blanket reason for refusal without proper assessment.
What should businesses check before buying, renting or leasing?
Providers must supply information about the data generated and the intended access options before a contract is concluded. Businesses should request this information in writing and compare it with their actual requirements.
Under the EU Data Act, the pre-contractual information must include the type, format and estimated volume of the data generated. It must also make clear whether access is provided directly through the product, via a portal or by another technical solution.
A short procurement checklist:
- What operational, usage and sensor data does the device generate?
- How often are the values updated?
- In what file format or through which interface are they provided?
- Can the data be transferred automatically to the business’s own software?
- Can the data be shared with an independent workshop or analytics service?
- How long is the data stored and how can it be exported?
Businesses should also ask about export options for older equipment already in use. However, according to the Bundesministerium für Digitales und Staatsmodernisierung (the German federal ministry for digital transformation and government modernisation), the additional product design requirement applies only to connected products and related services first placed on the EU market after 12 September 2026. It does not automatically create a right to a new interface in every existing older machine.
What must manufacturers and providers prepare now?
Manufacturers and providers should document their data holdings, access methods and pre-contractual information. Businesses covered by the rules should also establish how they will review and process requests from users and third-party providers.
Since 30 May 2026, the Bundesnetzagentur has been Germany’s supervisory authority and complaints body for the EU Data Act. The national implementing legislation is called the Datenverordnung-Anwendungs-und-Durchsetzungs-Gesetz (Data Regulation Application and Enforcement Act), abbreviated to DADG.
Anyone who breaches the prescribed product design or data provision requirements risks a fine of up to 500,000 euros under the DADG. In addition, the Bundesnetzagentur can impose penalty payments of up to 500,000 euros each to enforce ordered measures.
A stocktake is a useful first step in preparing: Which products are affected, what data is generated and who technically holds it? Interfaces, portals, permissions and contractual information can then be reviewed systematically.
ibx company advises small and medium-sized businesses in Hannover and the surrounding region on assessing and making practical use of operational data. If you would like to review your equipment or a specific use case, you can arrange a no-obligation initial consultation on digitalisation.