WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
EU Data Act September 2026 Deadline: What Businesses Need to Know
Alerts
June 18, 2026

Starting September 12, 2026, connected products sold in the EU must be built with data access functionality. This alert discusses the new access-by-design obligation and provides practical steps for compliance.

The New Access-by-Design Obligation

The EU Data Act (Regulation (EU) 2023/2854) became applicable on September 12, 2025. Among other things, it requires data holders to provide users, upon request, with access to certain product data and related service data generated by connected products and related services.

From September 12, 2026, an additional obligation will apply. Connected products and related services placed on the market after that date must be designed so that relevant data are, by default, easily, securely and directly accessible to users, free of charge, where relevant and technically feasible. The “technically feasible” condition gives some leeway to businesses to design a product or service so that all or part of the relevant data is directly or indirectly accessible, taking into account technical feasibility, costs, trade secrets, intellectual property, security concerns, and the relevance of direct access in the specific scenario. Where indirect access is relied on, businesses should be able to justify their decision.

Once access is enabled, the relevant data must be made available in a comprehensive, structured, commonly-used and machine-readable format, together with the information necessary to understand and use it.

Impact of the Digital Omnibus Proposal

The European Commission recently proposed changes to several EU digital regulations, including the Data Act (the Digital Omnibus Proposal). For instance, the proposal provides greater flexibility for data holders to refuse data access requests for reasons of trade secret protection. However, the proposal does not impact the Data Act’s core rules on data access, and it is currently unclear if/when the proposal could be adopted. Businesses should continue developing their compliance programs under the current version of the Data Act.

For more information about the European Commission's Digital Omnibus Proposal, please refer to our previous alert.

Next Steps

With the September 2026 deadline approaching, businesses should:

  • identify if they have any products or related services in scope of the Data Act;
  • identify the data elements that qualify as product data or related service data to which users have rights under the Data Act, which includes both B2B and B2C users;
  • update their pre-contractual information and user terms to describe users’ data access rights, as necessary to comply with the Data Act; and
  • determine whether direct access is relevant and technically feasible for in-scope products and services.

EU countries are putting national Data Act enforcement frameworks in place, including designating competent authorities and setting penalties for noncompliance. For example, Finland, Germany, the Netherlands, and Poland have adopted or advanced local implementing legislation. Although no major enforcement actions have been reported to date, the coming year is likely to bring closer scrutiny by regulators. Businesses should monitor regulatory enforcement across relevant jurisdictions.

Wilson Sonsini will host a webinar on September 9, 2026, examining the state of play of the Data Act one year on, including the status of implementation across EU countries and emerging market practices. Registration is available here.

Wilson Sonsini Goodrich & Rosati routinely advises clients on EU data regulatory issues. For more information about the Data Act and other data regulations, please contact Laura De Boel, Laura Brodahl or any attorney from Wilson Sonsini's EU Data, Privacy, and Cybersecurity practice.

Yaron Moszynski contributed to the preparation of this alert.

Contributors

  • Laura Brodahl
  • Laura De Boel
  • Christopher N. Olsen
  • Yaron Moszynski
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.