Data Act (Regulation (EU) 2023/2854)
The EU's connected-device data-access law, published in the Official Journal on 22 December 2023 (OJ L, 2023/2854), in force since 11 January 2024 and applying since 12 September 2025 (Art. 50). It gives users of connected products rights over the data those products generate: the data must be accessible ("accessible by design" for products placed on the market after 12 September 2026, Art. 3(1) via Art. 50), the user can access and use it (Art. 4), and the user can require it to be shared with a third party (Art. 5).
Applicability to EdTech
- A headset is very likely a "connected product": "an item that obtains, generates or collects data concerning its use or environment and that is able to communicate product data" (Art. 2(5)); the cloud service operating it is a candidate "related service" (Art. 2(6)). That makes the manufacturer/provider a data holder for "readily available" product and related-service data.
- The user holding the rights is the school (or whoever bought/leases the device) — usage telemetry, sensor data and related-service data are things the customer can demand, in a comprehensive, structured, machine-readable format, and can have ported to a competitor or integrator (Arts. 4–5).
- Pre-contractual information duties (Art. 3(2)–(3)): before purchase/rent/lease, the customer must be told what data the product generates, how to access it, whether the seller intends to use it, and more — a sales-collateral obligation, not just an engineering one.
- Timing: rights exercisable since 12 September 2025; access-by-design binds products placed on the market after 12 September 2026 (Art. 50).
Contents
| Document | Covers |
|---|---|
| SCOPE-AND-DEFINITIONS.md | Arts. 1–2 — subject matter, scope, definitions |
| DATA-ACCESS-RIGHTS.md | Arts. 3–5 — access by design, user access, sharing with third parties |
| APPLICATION.md | Art. 50 — entry into force and application dates |
Scope note: compensation and dispute settlement (Arts. 8–12), B2G access (Chapter V), cloud-switching (Chapter VI), interoperability (Chapter VIII), penalties (Art. 40) and enforcement can be added with the same tooling when needed. A Commission "Digital Omnibus" proposal to amend the Data Act was pending at last check — re-verify amendment status on rebuild.
Key obligations at a glance
- Design and manufacture so that product/related-service data is "directly accessible to the user" where relevant and technically feasible (Art. 3(1)) — for post-12 Sep 2026 products.
- Provide pre-contractual data information (Art. 3(2)–(3)).
- Make readily available data accessible to the user without undue delay, free of charge, and continuously and in real-time where relevant (Art. 4(1)).
- Share with a user-designated third party on request (Art. 5(1)); trade secrets are protected through agreed measures, not blanket refusal (Art. 4(6) and Art. 5(9)).
Enforcement
National competent authorities and penalties (Arts. 37, 40 — not extracted); GDPR authorities police the interplay for personal data. Data-holder duties are also privately enforceable through the user rights themselves.
Related
- EU GDPR — the Data Act is without prejudice to it; much headset telemetry about identifiable pupils is personal data, so both regimes apply
- Product-safety cluster — the same devices' market-access rules
Sources
Meta
Article text in the content documents is reproduced verbatim from the EUR-Lex OJ text (CELEX 32023R2854) and built/re-verified mechanically by tools/eur-lex/build_eu_data_act.py (verify mode; do not hand-edit). The only consolidated edition holds no EN datastream in Cellar; the sole English corrigendum (OJ L 2024/90790) renumbers a point in Article 48, not extracted here (checked via Cellar RDF, 2026-09-06). Anchors: official ELI ids plus derived paragraph/point anchors from printed labels.