
Who Owns Your Connected Device Data?
From 12 September 2026 the EU Data Act forces connected products to open their data. What it means for Monaco firms that sell — or buy — smart kit.
A deadline ten days away
On 12 September 2026, the last major piece of the EU Data Act — Regulation (EU) 2023/2854 — comes into force. From that date, any connected product placed on the European market must be designed so that the data it generates is accessible to the person using it.
Not accessible on request. Not accessible after a support ticket and a six-week wait. Accessible by default, in a structured, machine-readable format, and free of charge.
The rest of the Data Act has applied since 12 September 2025. What changes now is that "we would have to re-engineer the firmware" stops being an excuse for new products. If you place it on the EU market after this date, the access has to be built in.
What counts as a connected product
Wider than most people assume. The Regulation covers any physical product that obtains, generates or collects data about its own use, performance or environment, and communicates that data — over a network, a physical connection, or on-device access.
In practice that means industrial machinery, connected vehicles, medical and wellness devices, wearables, smart building systems, marine electronics, commercial kitchen equipment, and a long tail of ordinary business hardware that quietly logs telemetry.
It also covers related services: the digital layer explicitly tied to a product's operation and capable of affecting how it behaves. Remote diagnostics, predictive maintenance, navigation, fleet dashboards — those sit in scope alongside the hardware.
One important boundary: the obligation attaches to readily available raw and pre-processed data. Data you have genuinely derived or inferred through your own investment — scoring models, analytics output, proprietary insight — is not what the Regulation is handing over.
What "access by design" actually demands
Article 3(1) is the design rule: where relevant and technically feasible, product and related-service data must be directly available to the user, easily, securely, comprehensively, in a structured and machine-readable format — and where relevant, continuously and in real time.
Article 3 also carries a transparency duty that bites before the sale. Buyers must be told, in advance, the type, format and volume of data the product generates, how to access it, who the data holder is and how to reach them, whether third parties will receive the data, where to complain, and how the arrangement ends.
Article 4 gives the user a right to that data free of charge. Article 5 lets the user instruct the data holder to send it to a third party of their choosing — which is the provision that will genuinely reshape aftermarket servicing.
For most companies this is less a legal drafting exercise than an engineering and web development one: an API, an export route, an authenticated portal, and honest documentation of what the device records.
Monaco is not in the EU — so who is caught
Monaco is not an EU member state, and the Data Act is not Monegasque law. It does not apply to a purely domestic transaction between two Monaco businesses.
But the Regulation's scope follows the market, not the manufacturer. It applies to connected products and related services made available on the EU market, irrespective of where the provider is established. A Monaco-registered company that sells or leases connected equipment to customers in France, Italy or anywhere else in the Union is in scope for those products.
Where personal data is involved, Monaco's own regime under Law No. 1.565 of 3 December 2024 and the oversight of the APDP applies in parallel — the two frameworks sit side by side rather than replacing one another, and the data-mapping work behind data protection compliance will carry most of the way here.
Penalties are set by each member state rather than centrally. Where the infringement also touches personal data, supervisory authorities can reach for GDPR-level fines — up to €20 million or 4% of worldwide annual turnover. That is a ceiling, not a forecast, but it sets the tone.
The part most Monaco businesses miss
Read the Data Act only as a compliance burden and you will miss the half that works in your favour. Most companies in the Principality are not device manufacturers — they are users of connected equipment, and this Regulation makes them beneficiaries.
Think about what a Monaco business already runs: building management and HVAC systems, lifts, EV chargers, POS terminals, refrigeration in a restaurant, connected navigation and monitoring aboard a vessel. Each of those generates data that has, until now, mostly flowed one way — to the vendor, who then sells the analysis back.
From 12 September 2025 you can already demand that data. From 2026, new equipment must be built so you can get at it. And Article 5 means you can route it to an independent maintenance provider instead of the original supplier. For the yachting and property sectors especially — where service contracts are long, expensive and sticky — that is real commercial leverage. Firms in yachting and connected-asset businesses should be looking at their vendor contracts now, not in 2027.
There is a related date worth marking. Article 13 voids unfair, unilaterally imposed B2B terms about data access and use. From 12 September 2027, that control also reaches back into pre-existing long-term contracts — those of indefinite duration, or running past January 2034. Contracts signed today should not assume the vendor's data clause is permanent.
What to do before the deadline
If you sell connected products into the EU: inventory what your devices actually record, decide what is raw versus genuinely derived, specify the access route, and rewrite the pre-sale documentation. The engineering usually takes longer than the paperwork.
If you buy connected equipment: list your vendors, ask each one in writing how you access your own data, and check what your current contract says about it before you renew. That single exercise often pays for itself.
Either way, this is a data-architecture question before it is a legal one, and it belongs in the same conversation as your wider digital strategy.
A necessary caveat: this is a summary, not legal advice. The Data Act interacts with sector rules, data-protection law and your own contracts in ways that depend on your specific facts, and enforcement detail varies by member state. Where the answer affects your product roadmap or your supplier relationships, have it confirmed by a qualified lawyer.
If you build, sell or depend on connected products in Monaco and you are not sure which side of this you sit on, get in touch — we will map it with you.
Related services