Two Dates, Two Rights: What the EU Data Act Actually Gives a Machine Shop
The quote arrives by email and it is for four thousand euros.
A shop wants the cycle data off a machining centre it bought three years ago — not a report, the underlying values, so its own people can put them next to the values from the four other machines in the cell. The machine builder's service desk is helpful and quick. There is a portal, it says, and the portal is included. If you want the data as a file, that is a data package, and here is what the data package costs, per machine, per year.
Nobody in the shop thinks this is outrageous. They think it is how it works. The machine is theirs, the electricity is theirs, the parts coming off it are theirs, and the record of how it made them is a product sold back to them at a subscription price. That has been the arrangement for so long that it reads as a commercial fact rather than a choice.
It is no longer either. Since 12 September 2025 that shop has had a statutory right to those values, and since 12 September 2026 a second and narrower duty has applied to machines sold from that date. Almost nobody in the sector has been told which of those two is the one that helps them, because almost everything written about the European Data Act has been written for the company that builds the machine rather than the company that runs it.
This article is written the other way round.
Listen — audio overview
The date everyone is quoting is the wrong one for your shop
Open any piece published about the Data Act this month and it will lead with 12 September 2026. That date is real and it matters. It is also, for most German machine shops, the less useful of the two dates in the regulation, and leading with it produces exactly the wrong conclusion: that this is a rule about the future.
Here is what that clause actually says. Article 3(1) of the Regulation requires that connected products "shall be designed and manufactured, and related services shall be designed and provided, in such a manner that product data and related service data, including the relevant metadata necessary to interpret and use those data, are, by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user."
Read it slowly, because it is a good sentence and it is doing several things at once. Data has to be accessible by default, not on request. It has to be free. It has to be machine-readable, which is a format requirement and not a permission. And it has to include "the relevant metadata necessary to interpret and use those data" — which is the clause that separates a useful obligation from a shrug, and we will come back to it.
Now the limit. Article 50 sets out when the Regulation applies, and it draws a line that most coverage skips: the Regulation as a whole "shall apply from 12 September 2025", but "the obligation resulting from Article 3(1) shall apply to connected products and the services related to them placed on the market after 12 September 2026."
After. Placed on the market after.
So the design duty — the one in every headline — binds machines that went on sale only days ago, and everything sold from here on. If your newest machining centre is three years old, Article 3(1) says precisely nothing about it. If you are a shop whose fleet averages twelve years, the clause that dominated the coverage covers none of your equipment, and the natural conclusion from reading that coverage is that the law is something to think about the next time you buy.
That conclusion is wrong, and it is wrong because there is a second right that nobody put in the headline.
The right that has been sitting there for a year
Articles 4 and 5 are the ones that matter to a shop with machines already on the floor. They are not limited to products placed on the market after any date. They have applied since September 2025.
Article 4 covers the situation where the data is not directly accessible from the product itself — which is to say, the ordinary situation. Where that is the case, the data holder makes readily available data accessible to the user without undue delay, free of charge, in a comprehensive, structured, commonly used and machine-readable format, at the same quality as it is available to the data holder, and continuously and in real time where that is technically feasible.
Three phrases in there are worth underlining. Without undue delay — there is no annual data-package cycle contemplated. Free of charge — the four thousand euros has a problem. Same quality as available to the data holder — you are entitled to what they actually have, not to a reduced export they prepared for customers.
Article 5 is the one with the sharper commercial edge. On the user's request, the data holder makes that data available to a third party of the user's choosing. Not a third party from an approved list. Not a partner in an ecosystem programme. A third party the user chooses — an integrator, a consultant, a software supplier, a university, whoever the shop decides should receive it.
There are real limits on this and they should be stated rather than glossed. Trade-secret protections apply and a data holder can withhold or suspend sharing where confidentiality measures have not been agreed. Personal data only moves where there is a lawful basis under the GDPR. And undertakings designated as gatekeepers under the Digital Markets Act are excluded from being eligible third parties altogether — the regulation deliberately closes that door, and it is worth knowing the door is closed rather than discovering it later.
But the shape of the right survives all of that. A shop can direct its own machine data to a party of its own choosing, and has been able to for a year, and the overwhelming majority of shops have never sent the letter.
"But we signed something"
This is the objection that ends the conversation in most plants, usually raised by whoever negotiated the purchase and remembers a clause about data.
Article 7(2) addresses it directly. Any contractual term which, to the detriment of the user, excludes the application of, derogates from or varies the effect of the user's rights "shall not be binding on the user."
That is a short sentence with a lot of weight. It means the standard move — write the right away in the supply contract and rely on the customer not wanting a fight — does not work in the way it used to. A term that signs away these rights is not a term the user is bound by.
Two honest caveats, because this is the point where an article like this can tip into pretending to be legal advice, and it is not. First, whether a particular clause in a particular contract falls foul of Article 7(2) is a question for a lawyer reading that contract, not for a software company writing a blog. Second, none of this tells you how a supplier will behave when you raise it; a right and a comfortable commercial relationship are different things, and shops with one supplier and one lathe make that calculation differently from shops with forty machines across six brands.
What it does mean is that "we signed something" is no longer the end of the conversation. It is the beginning of one, and the shop is on better ground in it than it thinks.
The SME carve-out protects the builder, not you — and it leaks
A recurring misreading deserves killing early, because it lets people conclude the law is not for them.
There is a small-enterprise exemption in Article 7(1), and it runs in the opposite direction to how most people assume. The obligations do not apply to data generated through the use of connected products manufactured or designed by a micro or small enterprise. The carve-out protects a small machine builder from the duty. It does not protect a small shop from the right. You are the user. The right is yours, and your own headcount is irrelevant to it.
It also leaks in ways that matter. The exemption falls away where that enterprise has a partner enterprise or a linked enterprise that does not itself qualify as micro or small, and where the enterprise is subcontracted to manufacture or design the products. A newly medium-sized firm keeps the benefit for one year from the date a product was placed on the market, and then it does not. Between the group-structure test and the subcontracting test, a large share of the machine builders a contract shop actually buys from will not be sheltered by it.
Article 7 defines micro and small by reference to the Commission's own SME recommendation rather than stating thresholds itself, which is worth knowing because several numbers are circulating in secondary commentary. Check the definition rather than the commentary.
Who is the data holder, and whose letterhead does the letter go to?
Everything above is a right addressed to "the data holder", and in a real plant that phrase resolves to a person only after some work. This is the most practical obstacle to using any of it, and it gets almost no coverage because it is unglamorous.
For one machining centre there may be four candidates. The builder that assembled it. The control vendor whose software is running on it. The dealer or agent who sold it into the region and holds the service relationship. And whoever operates the telemetry or condition-monitoring service, which is sometimes a separate arm and sometimes a separate company.
They are not interchangeable, and the request goes to whoever actually holds the readily available data. Getting this wrong is the ordinary reason a request dies: it lands with the salesman, who forwards it to service, who explains that the portal exists.
So the first piece of work is not legal and not technical. It is a list. One row per machine, with four columns: what the machine emits, who holds the data that comes off it, what the purchase or service contract says about it, and who inside your business is authorised to send a written request to that party. Most shops cannot fill in the second column today, and finding out takes an afternoon rather than a project.
What goes in the letter itself is short, and it is worth writing once and reusing. Identify yourself as the user of a named machine, with its serial number and the date it was purchased. State that you are requesting access to the readily available product data under Article 4, or that you are requesting it be made available to a named third party under Article 5. Say what you want in return: the data in a machine-readable format, with the metadata needed to interpret it. Ask which format and which interface they propose to use. And ask that, if they decline any part of it, they give the reason in writing.
That last sentence does more work than all the others combined. A refusal that has to be written down is a refusal somebody has to think about first, and it gives you something specific to take to your own counsel if you decide to.
Access is not a format
Here is where an entitlement quietly turns into nothing.
A supplier can be entirely within the letter of an access obligation and leave you no better off. The mechanism is a portal: a login, a machine at a time, a rendered page with charts on it, an export button that produces a document laid out for reading. Everything is accessible. Nothing is usable. You can look at the number, and you cannot join it to anything.
This is why the metadata phrase in Article 3(1) is the most important part of the sentence. Data "including the relevant metadata necessary to interpret and use those data" is a materially different thing from data. A column of integers with no units, no machine state alongside them, and no time base you can align to another machine is technically a machine-readable file and practically a filing cabinet in another building.
The test is unforgiving and easy to apply. If two of your machines each handed you an export tomorrow, could you put them in the same table? Same units. Same time base. Same definition of what counts as running. If the answer is no, you have received two files and acquired one new problem, which is reconciling them.
That is not a legal problem and the regulation will not solve it for you. It is the reason the interoperability standards exist, and it is the point at which this stops being a story about law.
Where umati comes in, and why nobody has said so
There is a piece of this that the legal commentary cannot see, because it is written by people who do not work in machine tools.
Article 3(1) sets an outcome: data out, by default, structured, machine-readable, with the metadata needed to interpret it. It does not prescribe how. In the German machine tool sector, the mechanism that already delivers that outcome exists, is a published standard, and has the industry's own association behind it. umati — the interface the VDW has driven, sitting on OPC UA companion specifications — is exactly a machine publishing its state in a common information model, with the semantics travelling alongside the values.
Put the two next to each other and the overlap is close to complete. A control that speaks a standard information model over OPC UA is already doing the thing the design duty describes. One is a legal outcome and the other is an engineering standard that produces it, and as far as we can find, no one has written that sentence down.
This matters for a buyer in a very concrete way. "Does it comply with the Data Act?" is a question a salesperson can answer yes to, cheerfully and vaguely, and it commits them to almost nothing. "Does the control publish over OPC UA against a published companion specification, and which one?" is a question that has a checkable answer. The second question is the useful one, and it is useful precisely because it moves the conversation from a legal assertion to a technical fact that can be tested at acceptance.
It is also, for a shop buying into the aerospace and defence work that is currently replacing automotive volume, the question that ages best. Those customers ask for process evidence, and evidence assembled from a portal you cannot export is evidence you will be reassembling by hand for years.
Getting the data and using the data are two different projects
This is the honest ending, and it needs saying plainly because the temptation at this point in an article like this is to imply that the law hands you an outcome.
It does not. It hands you an input.
Suppose every request succeeds. Every data holder responds without undue delay, every export is genuinely machine-readable, every file carries its metadata. You now have a set of files from a set of machines, and none of the following is true yet: the machine states use a common vocabulary, the timestamps share a base, "running" means the same thing on all of them, or anyone in the business has decided which question the data is supposed to answer.
Every one of those is a separate piece of work, and every one of them is where industrial data projects actually fail. We have written elsewhere about what happens when a plant buys visibility and calls it transformation; this is the same failure arriving one step earlier. A right of access, exercised perfectly, produces raw material. What it removes is the excuse — the data is no longer withheld, so the question becomes what you intend to do with it, and that question has an owner and a cost.
The good news is that this sequence is cheap at the front. The letter costs nothing. The list of machines and data holders costs an afternoon. Both happen before any purchase decision, and both improve your position whether you go on to build anything or not. In a year where machine tool order intake rose fourteen per cent in the first half while production fell seven per cent, and capacity utilisation sat around seventy-five per cent, a step that costs an afternoon and creates optionality is the right shape of step.
What to put in the next purchase order
The design duty applies to machines placed on the market after 12 September 2026, which means that from now on, every quotation you receive is for equipment the duty covers. That is the one respect in which the headline date is genuinely yours, and it argues for changing a document rather than starting a project.
There is also a part of Article 3 that gets even less attention than the rest, and it is the part that works before you sign anything. Paragraphs 2 and 3 impose disclosure duties at the pre-contractual stage: the seller has to tell the prospective buyer what kind of data the product generates, in what volume, how often, whether it is stored on the device or elsewhere, and how the buyer will access it. Where a related service is involved, the disclosure extends further — what is collected, how long it is kept, whether it will be shared and with whom, who the data holder is and how to reach them, and how to complain.
Read commercially rather than legally, that is a set of questions you are entitled to have answered before you commit, by the person trying to sell you the machine, in writing. Most buyers do not ask them because they do not know they can. The cheapest moment to settle a data question is the moment before a purchase order exists, and this is the clause that puts you there.
Five things belong in the specification, and they are all checkable at acceptance rather than promised in a brochure:
- The data the machine produces, named. Not "machine data" — the actual signals, states and counters, listed, with their units.
- The interface they come out of, named, with the standard and the companion specification identified by name and version. "Supports OPC UA" is not an answer. Which information model is.
- Whether access is direct from the machine or mediated by a service, and if mediated, what happens to your access when the service contract lapses.
- What it costs. The regulation says free of charge for the data the duty covers; a quotation that prices a data package is worth a question before signature rather than after.
- An acceptance test. One line: on handover, the machine exports a named set of values in the named format, and someone on your side opens the file. A specification nobody tests at handover is a specification you discover the truth about eighteen months later.
None of that requires a lawyer and none of it requires a software purchase. It requires a paragraph in a document you are already sending.
Seven questions to take into the plant on Monday
- Of the machines on your floor, how many were placed on the market after 12 September 2026 — and therefore how much of the coverage you have read applies to you at all?
- For your most recently purchased machine, what does the contract actually say about who holds the data, and has anyone read that clause since signature?
- Who is the data holder for each machine — the builder, the control vendor, the dealer, or the service operator? Whose letterhead does a written request go to?
- When you last saw your own machine data, was it a file you could open or a page you could look at? Only one of those is a format.
- If two of your machines handed you an export tomorrow, could you put them in the same table — same units, same time base, same definition of "running"?
- Who in your business is authorised to send a written request to a supplier, and has anyone ever sent one about data?
- If you received everything you are entitled to next week, what is the first question you would answer with it, and what is that answer worth?
The arithmetic
The letter costs an afternoon of somebody's time. The list of machines and data holders costs another. Neither requires a budget line, a supplier, or a decision anyone has to defend.
Against that: downtime in discrete manufacturing is commonly costed somewhere in the range of five to twenty thousand euros per hour, and the shops that can attribute their downtime to a cause are the shops that can see across machines rather than one portal at a time.
The regulation did not give anyone a system. It removed a reason the data could not be had, and it did that for the machines already on the floor a year before it did it for the machines not yet built. The half of it that helps you most is the half nobody reported, it has been available since last September, and the number of German shops that have exercised it is, as far as anyone can tell, very close to none.
A note on what this article is and is not: this is a description of what the Regulation says, written for people who buy and run machines. It is not legal advice, and whether a particular clause in a particular contract survives Article 7(2) is a question for a lawyer with that contract in front of them. In Germany, the Bundesnetzagentur is the competent authority for the Data Act and approves the dispute-resolution bodies, which is the right starting point if a supplier's answer is no.
Sources
Every legal statement above was checked against the text of the Regulation itself rather than against commentary, because most of the commentary in circulation leads with the date that matters least. All accessed 16 September 2026.
Regulation (EU) 2023/2854 (the Data Act) — Article 3, design and pre-contractual disclosure: data-act-law.eu/article/3/ · Article 4, access where data is not directly available: data-act-law.eu/article/4/ · Article 5, making data available to a third party of the user's choosing: data-act-law.eu/article/5/ · Article 7, the small-enterprise carve-out and the non-binding-term rule: data-act-law.eu/article/7/ · Article 50, entry into force and the dates: data-act-law.eu/article/50/
VDMA on the design obligation for machine builders: vdma.eu/de/eu-datenverordnung
Bundesnetzagentur as the competent German authority under the DADG, in force 30 May 2026: bundesnetzagentur.de
Machine-tool order intake, production and capacity utilisation for the first half of 2026 are as reported by the VDW in September 2026; German industrial production for July 2026 is from the Federal Statistical Office, release PD26_316.
Start with the list. It costs an afternoon, it needs no budget line, and it tells you which of your suppliers is going to be easy and which is going to be a conversation.
Read next
- How to Choose the Right IoT Platform — the evaluation framework this article adds a statutory question to.
- MQTT vs OPC UA vs Modbus — the protocol layer underneath — what each one actually carries, and what it costs.
- Your Oldest Machine Is the Easy One — the organisational counterpart: legacy is a permission state, not an age.
- Why Your Dashboard Did Not Change Anything — what happens after you have the data and still change nothing.
Full blog text — board-ready report format
Two Dates, Two Rights: What the EU Data Act Actually Gives a Machine Shop
The quote arrives by email and it is for four thousand euros.
A shop wants the cycle data off a machining centre it bought three years ago — not a report, the underlying values, so its own people can put them next to the values from the four other machines in the cell. The machine builder's service desk is helpful and quick. There is a portal, it says, and the portal is included. If you want the data as a file, that is a data package, and here is what the data package costs, per machine, per year.
Nobody in the shop thinks this is outrageous. They think it is how it works. The machine is theirs, the electricity is theirs, the parts coming off it are theirs, and the record of how it made them is a product sold back to them at a subscription price. That has been the arrangement for so long that it reads as a commercial fact rather than a choice.
It is no longer either. Since 12 September 2025 that shop has had a statutory right to those values, and since 12 September 2026 a second and narrower duty has applied to machines sold from that date. Almost nobody in the sector has been told which of those two is the one that helps them, because almost everything written about the European Data Act has been written for the company that builds the machine rather than the company that runs it.
This article is written the other way round.
The date everyone is quoting is the wrong one for your shop
Open any piece published about the Data Act this month and it will lead with 12 September 2026. That date is real and it matters. It is also, for most German machine shops, the less useful of the two dates in the regulation, and leading with it produces exactly the wrong conclusion: that this is a rule about the future.
Here is what that clause actually says. Article 3(1) of the Regulation requires that connected products "shall be designed and manufactured, and related services shall be designed and provided, in such a manner that product data and related service data, including the relevant metadata necessary to interpret and use those data, are, by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user."
Read it slowly, because it is a good sentence and it is doing several things at once. Data has to be accessible by default, not on request. It has to be free. It has to be machine-readable, which is a format requirement and not a permission. And it has to include "the relevant metadata necessary to interpret and use those data" — which is the clause that separates a useful obligation from a shrug, and we will come back to it.
Now the limit. Article 50 sets out when the Regulation applies, and it draws a line that most coverage skips: the Regulation as a whole "shall apply from 12 September 2025", but "the obligation resulting from Article 3(1) shall apply to connected products and the services related to them placed on the market after 12 September 2026."
After. Placed on the market after.
So the design duty — the one in every headline — binds machines that went on sale only days ago, and everything sold from here on. If your newest machining centre is three years old, Article 3(1) says precisely nothing about it. If you are a shop whose fleet averages twelve years, the clause that dominated the coverage covers none of your equipment, and the natural conclusion from reading that coverage is that the law is something to think about the next time you buy.
That conclusion is wrong, and it is wrong because there is a second right that nobody put in the headline.
The right that has been sitting there for a year
Articles 4 and 5 are the ones that matter to a shop with machines already on the floor. They are not limited to products placed on the market after any date. They have applied since September 2025.
Article 4 covers the situation where the data is not directly accessible from the product itself — which is to say, the ordinary situation. Where that is the case, the data holder makes readily available data accessible to the user without undue delay, free of charge, in a comprehensive, structured, commonly used and machine-readable format, at the same quality as it is available to the data holder, and continuously and in real time where that is technically feasible.
Three phrases in there are worth underlining. Without undue delay — there is no annual data-package cycle contemplated. Free of charge — the four thousand euros has a problem. Same quality as available to the data holder — you are entitled to what they actually have, not to a reduced export they prepared for customers.
Article 5 is the one with the sharper commercial edge. On the user's request, the data holder makes that data available to a third party of the user's choosing. Not a third party from an approved list. Not a partner in an ecosystem programme. A third party the user chooses — an integrator, a consultant, a software supplier, a university, whoever the shop decides should receive it.
There are real limits on this and they should be stated rather than glossed. Trade-secret protections apply and a data holder can withhold or suspend sharing where confidentiality measures have not been agreed. Personal data only moves where there is a lawful basis under the GDPR. And undertakings designated as gatekeepers under the Digital Markets Act are excluded from being eligible third parties altogether — the regulation deliberately closes that door, and it is worth knowing the door is closed rather than discovering it later.
But the shape of the right survives all of that. A shop can direct its own machine data to a party of its own choosing, and has been able to for a year, and the overwhelming majority of shops have never sent the letter.
"But we signed something"
This is the objection that ends the conversation in most plants, usually raised by whoever negotiated the purchase and remembers a clause about data.
Article 7(2) addresses it directly. Any contractual term which, to the detriment of the user, excludes the application of, derogates from or varies the effect of the user's rights "shall not be binding on the user."
That is a short sentence with a lot of weight. It means the standard move — write the right away in the supply contract and rely on the customer not wanting a fight — does not work in the way it used to. A term that signs away these rights is not a term the user is bound by.
Two honest caveats, because this is the point where an article like this can tip into pretending to be legal advice, and it is not. First, whether a particular clause in a particular contract falls foul of Article 7(2) is a question for a lawyer reading that contract, not for a software company writing a blog. Second, none of this tells you how a supplier will behave when you raise it; a right and a comfortable commercial relationship are different things, and shops with one supplier and one lathe make that calculation differently from shops with forty machines across six brands.
What it does mean is that "we signed something" is no longer the end of the conversation. It is the beginning of one, and the shop is on better ground in it than it thinks.
The SME carve-out protects the builder, not you — and it leaks
A recurring misreading deserves killing early, because it lets people conclude the law is not for them.
There is a small-enterprise exemption in Article 7(1), and it runs in the opposite direction to how most people assume. The obligations do not apply to data generated through the use of connected products manufactured or designed by a micro or small enterprise. The carve-out protects a small machine builder from the duty. It does not protect a small shop from the right. You are the user. The right is yours, and your own headcount is irrelevant to it.
It also leaks in ways that matter. The exemption falls away where that enterprise has a partner enterprise or a linked enterprise that does not itself qualify as micro or small, and where the enterprise is subcontracted to manufacture or design the products. A newly medium-sized firm keeps the benefit for one year from the date a product was placed on the market, and then it does not. Between the group-structure test and the subcontracting test, a large share of the machine builders a contract shop actually buys from will not be sheltered by it.
Article 7 defines micro and small by reference to the Commission's own SME recommendation rather than stating thresholds itself, which is worth knowing because several numbers are circulating in secondary commentary. Check the definition rather than the commentary.
Who is the data holder, and whose letterhead does the letter go to?
Everything above is a right addressed to "the data holder", and in a real plant that phrase resolves to a person only after some work. This is the most practical obstacle to using any of it, and it gets almost no coverage because it is unglamorous.
For one machining centre there may be four candidates. The builder that assembled it. The control vendor whose software is running on it. The dealer or agent who sold it into the region and holds the service relationship. And whoever operates the telemetry or condition-monitoring service, which is sometimes a separate arm and sometimes a separate company.
They are not interchangeable, and the request goes to whoever actually holds the readily available data. Getting this wrong is the ordinary reason a request dies: it lands with the salesman, who forwards it to service, who explains that the portal exists.
So the first piece of work is not legal and not technical. It is a list. One row per machine, with four columns: what the machine emits, who holds the data that comes off it, what the purchase or service contract says about it, and who inside your business is authorised to send a written request to that party. Most shops cannot fill in the second column today, and finding out takes an afternoon rather than a project.
What goes in the letter itself is short, and it is worth writing once and reusing. Identify yourself as the user of a named machine, with its serial number and the date it was purchased. State that you are requesting access to the readily available product data under Article 4, or that you are requesting it be made available to a named third party under Article 5. Say what you want in return: the data in a machine-readable format, with the metadata needed to interpret it. Ask which format and which interface they propose to use. And ask that, if they decline any part of it, they give the reason in writing.
That last sentence does more work than all the others combined. A refusal that has to be written down is a refusal somebody has to think about first, and it gives you something specific to take to your own counsel if you decide to.
Access is not a format
Here is where an entitlement quietly turns into nothing.
A supplier can be entirely within the letter of an access obligation and leave you no better off. The mechanism is a portal: a login, a machine at a time, a rendered page with charts on it, an export button that produces a document laid out for reading. Everything is accessible. Nothing is usable. You can look at the number, and you cannot join it to anything.
This is why the metadata phrase in Article 3(1) is the most important part of the sentence. Data "including the relevant metadata necessary to interpret and use those data" is a materially different thing from data. A column of integers with no units, no machine state alongside them, and no time base you can align to another machine is technically a machine-readable file and practically a filing cabinet in another building.
The test is unforgiving and easy to apply. If two of your machines each handed you an export tomorrow, could you put them in the same table? Same units. Same time base. Same definition of what counts as running. If the answer is no, you have received two files and acquired one new problem, which is reconciling them.
That is not a legal problem and the regulation will not solve it for you. It is the reason the interoperability standards exist, and it is the point at which this stops being a story about law.
Where umati comes in, and why nobody has said so
There is a piece of this that the legal commentary cannot see, because it is written by people who do not work in machine tools.
Article 3(1) sets an outcome: data out, by default, structured, machine-readable, with the metadata needed to interpret it. It does not prescribe how. In the German machine tool sector, the mechanism that already delivers that outcome exists, is a published standard, and has the industry's own association behind it. umati — the interface the VDW has driven, sitting on OPC UA companion specifications — is exactly a machine publishing its state in a common information model, with the semantics travelling alongside the values.
Put the two next to each other and the overlap is close to complete. A control that speaks a standard information model over OPC UA is already doing the thing the design duty describes. One is a legal outcome and the other is an engineering standard that produces it, and as far as we can find, no one has written that sentence down.
This matters for a buyer in a very concrete way. "Does it comply with the Data Act?" is a question a salesperson can answer yes to, cheerfully and vaguely, and it commits them to almost nothing. "Does the control publish over OPC UA against a published companion specification, and which one?" is a question that has a checkable answer. The second question is the useful one, and it is useful precisely because it moves the conversation from a legal assertion to a technical fact that can be tested at acceptance.
It is also, for a shop buying into the aerospace and defence work that is currently replacing automotive volume, the question that ages best. Those customers ask for process evidence, and evidence assembled from a portal you cannot export is evidence you will be reassembling by hand for years.
Getting the data and using the data are two different projects
This is the honest ending, and it needs saying plainly because the temptation at this point in an article like this is to imply that the law hands you an outcome.
It does not. It hands you an input.
Suppose every request succeeds. Every data holder responds without undue delay, every export is genuinely machine-readable, every file carries its metadata. You now have a set of files from a set of machines, and none of the following is true yet: the machine states use a common vocabulary, the timestamps share a base, "running" means the same thing on all of them, or anyone in the business has decided which question the data is supposed to answer.
Every one of those is a separate piece of work, and every one of them is where industrial data projects actually fail. We have written elsewhere about what happens when a plant buys visibility and calls it transformation; this is the same failure arriving one step earlier. A right of access, exercised perfectly, produces raw material. What it removes is the excuse — the data is no longer withheld, so the question becomes what you intend to do with it, and that question has an owner and a cost.
The good news is that this sequence is cheap at the front. The letter costs nothing. The list of machines and data holders costs an afternoon. Both happen before any purchase decision, and both improve your position whether you go on to build anything or not. In a year where machine tool order intake rose fourteen per cent in the first half while production fell seven per cent, and capacity utilisation sat around seventy-five per cent, a step that costs an afternoon and creates optionality is the right shape of step.
What to put in the next purchase order
The design duty applies to machines placed on the market after 12 September 2026, which means that from now on, every quotation you receive is for equipment the duty covers. That is the one respect in which the headline date is genuinely yours, and it argues for changing a document rather than starting a project.
There is also a part of Article 3 that gets even less attention than the rest, and it is the part that works before you sign anything. Paragraphs 2 and 3 impose disclosure duties at the pre-contractual stage: the seller has to tell the prospective buyer what kind of data the product generates, in what volume, how often, whether it is stored on the device or elsewhere, and how the buyer will access it. Where a related service is involved, the disclosure extends further — what is collected, how long it is kept, whether it will be shared and with whom, who the data holder is and how to reach them, and how to complain.
Read commercially rather than legally, that is a set of questions you are entitled to have answered before you commit, by the person trying to sell you the machine, in writing. Most buyers do not ask them because they do not know they can. The cheapest moment to settle a data question is the moment before a purchase order exists, and this is the clause that puts you there.
Five things belong in the specification, and they are all checkable at acceptance rather than promised in a brochure:
1. The data the machine produces, named. Not "machine data" — the actual signals, states and counters, listed, with their units.
2. The interface they come out of, named, with the standard and the companion specification identified by name and version. "Supports OPC UA" is not an answer. Which information model is.
3. Whether access is direct from the machine or mediated by a service, and if mediated, what happens to your access when the service contract lapses.
4. What it costs. The regulation says free of charge for the data the duty covers; a quotation that prices a data package is worth a question before signature rather than after.
5. An acceptance test. One line: on handover, the machine exports a named set of values in the named format, and someone on your side opens the file. A specification nobody tests at handover is a specification you discover the truth about eighteen months later.
None of that requires a lawyer and none of it requires a software purchase. It requires a paragraph in a document you are already sending.
Seven questions to take into the plant on Monday
1. Of the machines on your floor, how many were placed on the market after 12 September 2026 — and therefore how much of the coverage you have read applies to you at all?
2. For your most recently purchased machine, what does the contract actually say about who holds the data, and has anyone read that clause since signature?
3. Who is the data holder for each machine — the builder, the control vendor, the dealer, or the service operator? Whose letterhead does a written request go to?
4. When you last saw your own machine data, was it a file you could open or a page you could look at? Only one of those is a format.
5. If two of your machines handed you an export tomorrow, could you put them in the same table — same units, same time base, same definition of "running"?
6. Who in your business is authorised to send a written request to a supplier, and has anyone ever sent one about data?
7. If you received everything you are entitled to next week, what is the first question you would answer with it, and what is that answer worth?
The arithmetic
The letter costs an afternoon of somebody's time. The list of machines and data holders costs another. Neither requires a budget line, a supplier, or a decision anyone has to defend.
Against that: downtime in discrete manufacturing is commonly costed somewhere in the range of five to twenty thousand euros per hour, and the shops that can attribute their downtime to a cause are the shops that can see across machines rather than one portal at a time.
The regulation did not give anyone a system. It removed a reason the data could not be had, and it did that for the machines already on the floor a year before it did it for the machines not yet built. The half of it that helps you most is the half nobody reported, it has been available since last September, and the number of German shops that have exercised it is, as far as anyone can tell, very close to none.
A note on what this article is and is not: this is a description of what the Regulation says, written for people who buy and run machines. It is not legal advice, and whether a particular clause in a particular contract survives Article 7(2) is a question for a lawyer with that contract in front of them. In Germany, the Bundesnetzagentur is the competent authority for the Data Act and approves the dispute-resolution bodies, which is the right starting point if a supplier's answer is no.
Sources
Every legal statement above was checked against the text of the Regulation itself rather than against commentary, because most of the commentary in circulation leads with the date that matters least. All accessed 16 September 2026.
Regulation (EU) 2023/2854 (the Data Act) — Article 3, design and pre-contractual disclosure: data-act-law.eu/article/3/ · Article 4, access where data is not directly available: data-act-law.eu/article/4/ · Article 5, making data available to a third party of the user's choosing: data-act-law.eu/article/5/ · Article 7, the small-enterprise carve-out and the non-binding-term rule: data-act-law.eu/article/7/ · Article 50, entry into force and the dates: data-act-law.eu/article/50/
VDMA on the design obligation for machine builders: vdma.eu/de/eu-datenverordnung
Bundesnetzagentur as the competent German authority under the DADG, in force 30 May 2026: bundesnetzagentur.de
Machine-tool order intake, production and capacity utilisation for the first half of 2026 are as reported by the VDW in September 2026; German industrial production for July 2026 is from the Federal Statistical Office, release PD26_316.
No comments yet. Be the first to comment.