The EU Data Act’s most fundamental threshold question is whether your product qualifies as a “connected product” under the regulation. That single classification determines whether a substantial body of legal obligations — covering data access rights, technical design requirements, contract rules, and in some cases the duty to appoint an EU legal representative — attaches to your business. This page walks through the definition in detail, examines examples across industries, addresses the edge cases that create the most uncertainty, and explains why getting the answer right matters for product teams, legal teams, and executives.
The Legal Definition of a Connected Product
Under Regulation (EU) 2023/2854, a connected product is defined as an article that (1) obtains, generates, or collects data concerning its use or its environment, (2) is able to communicate that data via an electronic communications service, a physical connection, or by means of on-device processing, and (3) whose primary function is not the storage, processing, transfer, or transmission, or display of data.
Each element of this definition deserves individual attention, because the definition operates conjunctively — all three elements must be present for an article to qualify.
Element One: Obtaining, Generating, or Collecting Data About Use or Environment
The first element is broad and captures almost any device that includes sensors, meters, counters, cameras, microphones, GPS receivers, or other data capture components. A thermostat that measures temperature and records when the user adjusts the setpoint obtains data about its environment and its use. An agricultural sprayer that tracks which fields it has covered and how much chemical it has dispensed generates data about its use. A construction crane equipped with load sensors and GPS tracking collects data about both its environment and its operation.
The key limiting word is “concerning its use or its environment.” The data must be about the product itself — how it is being operated, what conditions it is operating in, what inputs it is receiving, what outputs it is producing. A device that merely passes through externally created data — for example, a dumb relay that transmits whatever signal is fed into it without generating any additional data — probably does not satisfy this element. But any device with embedded intelligence — even basic intelligence — that records something about its own operation will almost certainly satisfy it.
Element Two: Ability to Communicate Data
The second element requires that the product be able to communicate data. Communication can occur via an electronic communications service (Wi-Fi, cellular, Bluetooth, Zigbee, or any other wireless or wired network protocol), via a physical connection (USB, Ethernet, or other direct connection), or by means of on-device processing that makes data available to users or downstream systems. The regulation does not require that the product constantly stream data in real time. Periodic uploads, batch transfers, manual syncs via physical connection, or passive storage of data that a technician later downloads from the device all satisfy this element.
The communication requirement is relatively easy to satisfy with modern products. Almost any product that has been designed in the last decade with any connectivity feature will meet this element. The inclusion of on-device processing as a communication mechanism is particularly significant: a device that processes sensor data locally and stores results for later retrieval counts as communicating data, even if it never connects to an external network. This prevents manufacturers from designing around the rule by eliminating external connectivity while retaining data collection.
Element Three: Primary Function Not Data Processing
The third element — that the product’s primary function must not be data storage, processing, transmission, or display — carves out general-purpose computing devices. A laptop, desktop computer, tablet, or smartphone is primarily a data processing device, so it is not a connected product under the Data Act. A dedicated network router or storage appliance is primarily a data transmission or storage device, so it is also excluded.
The difficult cases arise in the middle of the spectrum. A smart display that shows weather data or controls a home automation system has both a display function and a data collection function. Industrial computers that are embedded in machines and perform both control functions and data processing may be harder to classify. The general principle is that if the product has a clear physical-world primary purpose — washing clothes, monitoring a patient’s heart rate, drilling a hole — and data collection is a secondary or ancillary function that supports that purpose, the product is a connected product. If the product’s entire value proposition is the processing or display of data, it is not.
Consumer IoT: Smart Appliances and Wearables
Consumer IoT represents the most visible category of connected products. Smart home appliances — washing machines, dishwashers, refrigerators, ovens, and air conditioners that connect to home networks — clearly qualify. These devices collect data about usage cycles, energy consumption, internal temperatures, error states, and user settings. They communicate that data to manufacturer cloud platforms, and their primary function is the physical service the appliance provides, not data processing.
Smart speakers and voice assistants occupy a more complex position. Their primary function could be characterized as data processing or audio output, which might exclude them. Manufacturers of these devices should conduct a careful primary-function analysis and should not assume they fall outside the regulation without doing that work. A smart security camera similarly presents complexity — a camera whose primary function is recording and displaying video may qualify as a data-processing device rather than a connected product in the Data Act’s sense, but a camera integrated into a broader home security system where the camera is a sensor in a larger physical-world security service is more likely to qualify.
Wearable devices — fitness trackers, smartwatches, health monitors, continuous glucose monitors, smart clothing — are strong candidates for connected product status. Their primary function is tracking a physical-world attribute of the wearer (activity, health metrics, location, biometrics), and they communicate that data to companion apps and cloud platforms. Wearable devices are particularly significant under the Data Act because the data they generate is often highly personal and the user who generated it has a strong interest in accessing and controlling it.
Industrial IoT: Manufacturing Sensors and Logistics
Industrial IoT may be the sector where the EU Data Act’s practical impact is most significant, even if consumer IoT gets more press attention. Manufacturing facilities, logistics networks, energy infrastructure, and construction sites are increasingly saturated with connected sensors and controllers. The data these devices generate is often extremely valuable — and historically has been extremely locked-down.
A factory floor vibration sensor that monitors equipment health and sends readings to a predictive maintenance platform is a connected product. The sensor’s primary function is measuring physical vibration; data communication is a means of delivering that measurement to the people and systems who need it. A smart flow meter on a chemical processing line, a connected air quality monitor in a ventilation system, a temperature sensor in a cold chain refrigeration unit — all of these qualify.
More complex industrial systems — programmable logic controllers, industrial robots, CNC machines — raise harder questions. A CNC machining center’s primary function is cutting metal. It also collects extensive data about spindle load, tool wear, cycle times, and error conditions. That data is typically collected by the machine’s embedded control system and may be available for export to a factory management platform. This product likely qualifies as a connected product, and if a US manufacturer sells such equipment into EU factories, the Data Act’s data access obligations apply.
Logistics presents another major application area. GPS-equipped vehicles and trailers that track location and route data are connected products. Warehouse management systems involving connected scanning equipment, automated guided vehicles, and connected conveyor systems all involve connected products. The businesses that purchase, lease, or operate this equipment — logistics companies, distributors, third-party warehousing operators — are users with data access rights under the regulation.
Vehicles
Modern vehicles are among the most data-intensive connected products that exist. A passenger car produced today may have hundreds of sensors recording engine performance, fuel consumption, braking behavior, lane position, speed, acceleration, infotainment system usage, cabin climate, tire pressure, and dozens of other parameters. All of this data is continuously generated during vehicle use and is typically transmitted to the manufacturer’s cloud infrastructure, either in real time over cellular connection or during periodic sync events.
Vehicles clearly satisfy the connected product definition. The vehicle’s primary function is transportation, not data processing, even though the data systems on modern vehicles are extraordinarily sophisticated. The Data Act explicitly acknowledges the vehicle sector as a covered category, and the European Commission has noted that the regulation will have significant implications for the automotive industry’s data business models.
For US automakers and their suppliers, the implications are substantial. A US manufacturer selling vehicles in the EU market — even selling through a European subsidiary or distributor — is placing a connected product on the EU market and triggering Data Act obligations. The question of which entity holds the vehicle data, and whether that data holder can currently satisfy user access requests in machine-readable format, is an urgent compliance question for the automotive sector.
Medical Devices
Connected medical devices span an enormous range: implantable cardiac monitors, continuous glucose monitors, wearable ECG patches, infusion pumps with remote monitoring, connected ventilators, smart inhalers that record usage and technique, hospital bed sensors that track patient movement, and diagnostic imaging equipment with networked connectivity. All of these are candidates for connected product status under the Data Act.
The medical device sector involves a particular complication: much of the data generated by medical devices is also personal health data, which receives heightened protection under the GDPR. The Data Act requires that its access and sharing obligations be implemented in a manner consistent with the GDPR. This does not eliminate the Data Act obligations, but it does mean that access to data generated by medical devices must be structured in a way that respects the applicable data protection framework. Medical device manufacturers and their US-based parent companies need to understand both regulatory regimes and how they interact.
Medical devices are also subject to the EU Medical Devices Regulation and In Vitro Diagnostic Regulation, which create their own data and cybersecurity requirements. The Data Act adds another layer. US medical device companies with EU market presence — a substantial category given the global medical device industry — are operating in a multi-layered regulatory environment that requires coordinated compliance.
Agricultural Equipment
Connected agricultural equipment is one of the most commercially significant and politically contested categories in the Data Act’s history. Modern tractors, harvesters, planters, and sprayers from major manufacturers are loaded with sensors, GPS systems, yield monitors, and diagnostic systems. These machines generate detailed data about field conditions, crop yields, application rates, machine performance, and operator behavior. That data has enormous value for agronomic optimization, precision farming, and agricultural supply chain management.
Agricultural machinery manufacturers have historically maintained tight control over this data, and farmers have complained loudly that they cannot access data from equipment they own outright. This tension was a direct driver of the EU Data Act. For US agricultural equipment manufacturers with European sales — and the major US manufacturers all have significant EU market presence — the Data Act creates enforceable data access rights for EU farmers and agribusinesses that own or operate their equipment.
Connected sensors used in precision agriculture beyond the machinery itself — soil moisture sensors, weather stations, drone systems, irrigation controllers — are also connected products. The agricultural sector is likely to be one of the most active enforcement areas in the early years of Data Act implementation.
Edge Cases and Classification Challenges
Several categories of products present genuine classification difficulty. Understanding these edge cases is important for product teams and legal advisors doing classification work.
Smart Packaging and RFID
Product packaging embedded with RFID chips or QR codes is sometimes cited as a potential connected product. In most cases, passive RFID tags do not generate data about use — they store a fixed identifier that can be read by external equipment. A passive tag does not independently generate or collect data, so it likely does not qualify as a connected product on its own. However, an active sensor tag that records temperature or humidity over time and communicates that data qualifies much more clearly.
Smart Meters and Energy Infrastructure
Smart electricity and gas meters are connected products. They measure consumption, communicate readings, and their primary function is metering — not data processing. Smart meters are typically deployed by utilities under regulatory mandates, and the Data Act’s application in the energy sector intersects with sector-specific energy data frameworks. The European Commission has acknowledged this overlap and has indicated that sector-specific rules may prevail in some contexts, but the baseline Data Act obligations remain relevant.
Software-Only Products
Pure software applications — mobile apps, SaaS platforms, desktop software — are not connected products because they are not physical articles. However, software that functions as a related service to a connected product can trigger Data Act obligations even without being embedded in hardware. If your company builds a companion application or cloud platform that is necessary for a connected product to function, your software is a related service and Chapter II obligations may apply to you as the related service provider.
Connected Products in Beta or Development
Products that are placed on the EU market trigger Data Act obligations from the moment they are available for purchase or use in the EU. A product that is in beta testing with EU users, or that is being piloted with EU business customers, may already be “on the market” within the meaning of the regulation. US companies running EU pilots of connected products should assess whether Data Act obligations apply during the pilot phase, particularly if the pilot involves paying customers or widespread deployment.
Why Product Classification Drives Everything Else
If your product qualifies as a connected product, Chapter II of the Data Act applies. Chapter II is the heart of the regulation for manufacturers: it requires that users be able to access data generated by their use of the product, that data be made available in real time or on request in a machine-readable format, that the product be designed to enable this access, and that the manufacturer designate an EU legal representative if the manufacturer has no EU establishment.
These are not trivial requirements. Satisfying them requires design decisions about data architecture, decisions about what APIs or interfaces to provide, decisions about contract terms with distributors and end users, and organizational decisions about who is responsible for compliance. For many US companies with existing connected product lines that were designed before the Data Act existed, meeting these requirements may require engineering changes to both the device firmware and the backend systems that receive and store device data.
Starting the classification analysis early — before products are shipped to EU customers, if possible — gives companies the time to make design changes at reasonable cost. Waiting until the regulation is being actively enforced by national market surveillance authorities will mean making those same changes under pressure and potentially facing administrative penalties in the process.
