TL;DR: Since 12 September 2025, every person in the EU who owns a connected device, fitness watches included, has a legal right to the health data that device generates, the heart rate, sleep, activity and location it records all day, and the right to have that data sent to a company of their choosing. This is not a technicality. It moves an important question out of contract and into law, and it applies to devices already on people's wrists, cannot be signed away in a terms of service, and can only be refused in specific, documented circumstances. This piece breaks down what the regulation says, which of a wearable's readings it covers and which it does not, who enforces it, and how to design a health product around it. The law itself is public and readable: you can find the full text of
the Data Act on EUR-Lex, and the European Commission's own summary on its
Data Act policy page.
What is the EU Data Act?
The Data Act (Regulation (EU) 2023/2854, in force since January 2024 and applicable since 12 September 2025) answers a question that used to be settled in terms-of-service documents rather than in law: who gets to use the health and activity data that connected products generate? For the categories of data it covers, the answer is the user. The significance is less the answer than where it now lives. An entitlement written into a regulation behaves differently from a permission written into a product.
Three of its rights matter for health data, and it helps to know the article numbers, because they come up in every legal discussion of the subject.
Article 4 gives the user the right to access the data their product generates, free of charge, "without undue delay", in "a comprehensive, structured, commonly used and machine-readable format" and, "where relevant and technically feasible, continuously and in real-time".
Article 5 goes further. "Upon request by a user, or by a party acting on behalf of a user, the data holder shall make available readily available data ... to a third party without undue delay." In plain terms, a user in the EU can name a company and ask the manufacturer to send that company the heart rate, sleep, movement and location records their device holds, at the same quality the manufacturer itself holds.
Article 3(1) requires products to be designed so that data is directly accessible by default. This one is a design-stage obligation: under Article 50 it applies to products placed on the market after 12 September 2026.
The EU Data Act in plain English: a glossary of the key terms
The regulation leans on a small set of defined terms, and almost every argument about it turns on one of them. This is the whole vocabulary in one place, so the rest of this piece reads without a law dictionary open beside it.
| Term | What it means in plain English | Why it matters to you |
|---|
| Data Act | Regulation (EU) 2023/2854, the EU law that decides who may use the data a connected product generates. | Applicable since 12 September 2025. It is what everything below sits inside. |
| Connected product | Any item that collects data about its own use or its surroundings and can send that data on. A fitness watch qualifies. | If your users wear one, these rules are live for them today. |
| Data holder | The company holding the data and carrying the obligation to share it, normally the device manufacturer. | This is who a request is made to. It is not you. |
| User | The person or business that owns, rents or leases the device. | The rights belong to them. Your product exercises those rights on their instruction, never instead of it. |
| Third party / data recipient | A company the user names to receive their data. | This is the role your product plays under the Act. |
| Readily available data | Data the manufacturer already holds without extra effort, meaning raw and pre-processed readings. | Covered by the Act. This is the layer you can actually ask for. |
| Inferred or derived data | Figures produced by running algorithms over the raw readings, such as a proprietary recovery or readiness score. | Outside the Act. Build your own interpretation rather than depending on someone else's. |
| Sensor fusion | Combining several sensors' streams through an algorithm to produce a single figure. | The regulation names it as a marker of derived data, so anything built this way is excluded. |
| Placed on the market | The moment a product is first made available for sale in the EU. | Decides whether the 2026 design obligation applies to a given device. |
| Article 3(1) | Products must be designed so data is directly accessible by default. | Applies only to products placed on the market after 12 September 2026. |
| Article 4 | The user's right to access the data their own product generates. | Free of charge, machine-readable, without undue delay, and in real time where feasible. |
| Article 5 | The user's right to have that data sent to a third party they name. | The provision your product depends on. It can be triggered by a party acting on the user's behalf. |
| Article 6 | The conditions a third party must meet once it receives data. | Your obligations: use it only for the agreed purpose, and do not pass it to a gatekeeper. |
| Article 7(2) | The rights cannot be waived or overridden by a contract term. | No terms-of-service update can remove them. |
| Article 8(4) | Data may only be passed to a recipient when the user has asked for it. | Consent is mandatory. The Act is a consent regime, not an open-access one. |
| Article 9 | The compensation a data holder may charge a recipient. | Free for the user, capped at cost for an SME or non-profit researcher, negotiated above that. |
| Article 4(8) | The trade-secret refusal route, sometimes called the trade secrets handbrake. | Narrow and case-by-case. It must be justified in writing and reported to the regulator. |
| Article 40 | Penalties, which the Act leaves to each member state to set. | Why the practical exposure differs so much between countries. |
| Gatekeeper | A very large platform company designated under the Digital Markets Act. | Named in law as ineligible to receive data through Article 5 at all. |
| Recital | The explanatory preamble that sits ahead of an EU law's operative articles. | Not binding on its own, but courts use recitals to interpret what the articles mean. |
When did the EU Data Act come into force, and what applies when?
If you take one thing from this piece, take the dates, because the most common and most expensive misreading is that the whole regime began in September 2026. It did not. The European Commission's FAQ on the Data Act (guidance rather than binding law, as the document itself notes) is explicit that by 12 September 2025, "products already on the market and new products (when placed on the market) must allow for data to be accessed by the user." The access and sharing rights have been live since that date, for devices people already own. Only the design obligation waited for 2026.
Two further details from the same FAQ describe what compliance is expected to look like. The Commission expects the plumbing behind these rights to resemble up-to-date infrastructure: data holders "should proactively implement solutions such as APIs (automated data retrieval) and event architectures ... to ensure real-time or near instantaneous access wherever feasible", and formats subject to licensing constraints do not count as "commonly used". Recital 21 adds that user access should work through a "simple request mechanism granting automatic execution and not requiring examination or clearance by the manufacturer or data holder". A recital is the explanatory preamble of an EU law rather than an operative rule, and courts use recitals to interpret what the articles mean, so this one sets an expectation that exercising the right should feel closer to pressing a button than to filing an application.
Does the Data Act apply to fitness watches and health wearables?
The word "wearable" appears nowhere in the regulation, which surprises most people who go looking for it. The scope comes instead from the definition of a connected product in Article 2(5), an item that "obtains, generates or collects data concerning its use or environment" and can communicate that data, read together with Recital 14, which lists "health and lifestyle equipment" and "medical and health devices" among the places connected products are found. The Commission's own explainer names "medical and fitness devices" as examples. A fitness watch, which collects heart rate, movement and location data and syncs it to a phone, fits that definition about as squarely as anything can.
Nor does it matter where the manufacturer is headquartered. Article 1(3) applies the regulation to "manufacturers of connected products placed on the market in the Union ... irrespective of the place of establishment of those manufacturers". Selling a device to users in Europe brings its maker into scope, wherever the company is based.
What it means for your users, and for the apps they choose
For the person wearing the device, access that used to depend on how a product was designed is now an entitlement that exists independently of it. They can ask for the health data their device records, the heart rate, sleep stages, steps, workouts and location it captures, and they can ask for it to be sent somewhere else.
Three provisions keep that from being theoretical. Article 7(2) makes the rights non-waivable, so they survive any contract term. Article 4(4) requires that they not be made "unduly difficult" to exercise through interface design. And Article 5 extends them beyond the user personally: the request can come from "a party acting on behalf of a user", which is a role infrastructure providers are placed to play.
The same structure sets a firm limit in the other direction, and this half gets far less attention than it deserves. Under Article 8(4), a data holder is forbidden from passing product data to a recipient "unless requested to do so by the user". A manufacturer that handed data to every company that asked, without those users instructing it, would itself be in breach. The Act is not an open-access regime. It is a consent regime, and the consent belongs to the individual rather than to any company in the chain.
One more provision shapes who benefits. Article 5(3) excludes companies designated as gatekeepers under the Digital Markets Act, the EU law that names the largest platform companies, from being eligible third parties. The very largest platforms cannot receive data through this channel, by name of law. The recipients the legislation contemplates are smaller developers, researchers and infrastructure providers, which is a deliberate piece of industrial policy and worth noticing if you are one of them.
What the consequences are
What data does the Data Act cover, and what does it exclude?
The Act draws a line through the middle of a wearable's data catalogue. This is the single most important paragraph in the regulation for anyone planning a health product, and it is the one most often skipped.
Recital 15 puts data "collected from a single sensor or a connected group of sensors", such as position, acceleration or temperature, squarely in scope. It excludes "information inferred or derived from such data, which is the outcome of additional investments into assigning values or insights from the data, in particular by means of proprietary, complex algorithms", and it specifically mentions inference by sensor fusion, which is the technique of combining several sensors' streams to produce a single figure. In its analysis of the Act's consequences for health devices, the law firm CMS gives the example of a glucose monitoring app: the glucose reading itself must be shared, while the app's conclusion that a level is abnormal, and the advice attached to it, need not be.
Applied to a modern fitness watch, that reading suggests raw heart rate, steps, location and accelerometry are covered, while proprietary composite figures built by fusing several sensor streams most likely are not. We think this is the right line, and not a grudging compromise. A company that invests in building an interpretation layer keeps it; the measurements underneath it, which the user's own body produced, follow the user. Both halves of that are necessary if the market is going to keep producing better devices and better software at the same time.
The cost structure surprises people who expect the Act to mandate open access to everything. Under Article 9, when data goes to a third party at a user's request, the manufacturer may charge that third party compensation that is "non-discriminatory and reasonable" and, for larger recipients, "may include a margin". Only where the recipient is a small or medium-sized enterprise, or a non-profit research organisation, is the amount capped at the cost of making the data available. Access for the user is free; access for the user's chosen startup is at cost; access for a large corporation is a commercial discussion with a legal ceiling of reasonableness rather than a ceiling of zero. The regulation is more commercially realistic than its reputation suggests.
Refusals are possible, and deliberately narrow. A data holder may refuse or restrict a specific request on trade-secret grounds only "in exceptional circumstances", where it can demonstrate it is "highly likely to suffer serious economic damage" despite confidentiality safeguards, and it must substantiate that in writing to the user and notify the national regulator (Article 4(8); the Commission FAQ calls this the "trade secrets handbrake"). The ordinary remedy for a trade-secret concern is a protective measure such as a confidentiality agreement, and the route is built for individual cases.
What the Act does not do is require anyone to run an open developer program. The Commission FAQ says so directly: Article 3(1) "does not oblige manufacturers to grant direct access to data in all situations and for all connected products." The two things sit in different layers. A partner program governs a commercial relationship between two companies, with its own terms, support commitments and review. Articles 4 and 5 govern the relationship between a manufacturer and its own user. Our reading is that these are complements rather than substitutes, and that most serious products in Europe will end up resting on both.
Who enforces the Data Act, and what are the penalties?
The Data Act arrived without its own fine schedule. Article 40 leaves penalties to each member state, unlike the GDPR, the EU's 2016 data protection regulation, and the national implementing laws have filtered in over more than a year. Finland had its law in force by 1 January 2026, with the transport and communications agency Traficom as the competent authority and fines running up to 2 per cent of annual turnover, rising to 4 per cent for breaches of the core data-sharing obligations, according to Hannes Snellman's analysis. Malta set its ceiling at 5 per cent of turnover, per Corporate Compliance Insights. Germany, the EU's largest market, took until 26 March 2026 to get its implementing act through the Bundestag; Härting's summary has the Federal Network Agency as sole competent authority, with four fine tiers topping out at 5 million euros or 2 per cent of turnover for large companies. Several member states had designated nobody at all well into the application period, so the practical exposure still varies a great deal by country.
Two things cut against reading that patchwork as toothlessness. First, where the data involved is personal data, and health and fitness data almost always is, Article 40(4) lets the existing GDPR supervisory authorities impose fines under the GDPR's own Article 83(5), which reaches up to 4 per cent of worldwide annual turnover. That enforcement machinery did not need to be built, because it already exists in every member state. Second, it has started moving: the first Data Act complaint has been filed in Finland, concerning a refusal to provide data free of charge, and was transferred to the competent authority in Sweden where the data holder is established. Kemp IT Law expects early enforcement to be user-led, through complaints and private action, rather than driven by regulators acting on their own initiative.
What this means in practice if you build on health data in the EU
Three practical conclusions are worth separating from the legal theory.
Design for consent, because the law now assumes it. Article 5 lets a party acting on behalf of a user trigger a sharing request, and Article 6 sets the conditions a third party must meet once it receives data, including using it only for the agreed purpose and not passing it to gatekeepers. A product where every data flow traces back to a specific user's request is built the way the regulation expects. This was good architecture before it was a legal expectation, and the Act has simply made the cost of the alternative explicit.
Be disciplined about scope when you plan a product. Raw sensor streams, the heart rate, accelerometry, location and temperature a device measures directly, are the durable layer. Proprietary composite figures belong to the companies that built them. Our view is straightforward: build on the raw layer and derive your own interpretation on top of it. A product resting on somebody else's derived analytics is resting on a commercial agreement; a product resting on raw and pre-processed data has a statutory floor under it in the EU. Note also that the Act creates no right to historical backfill, so per Commission guidance only data generated after 12 September 2025 falls within the sharing regime, and any product that needs deep history still needs it from somewhere else.
None of this replaces partnerships. Reading the Data Act as a workaround would be a mistake, and a costly one. The regulation itself contemplates compensation, security conditions and contractual terms between data holders and recipients, which is to say it expects exactly the kind of ongoing bilateral relationships that partner programs formalise. Terra operates as health data infrastructure across wearables, sensors, health apps and lab and blood results, through the partner relationships it maintains with each platform, and its model is consent-first: a connection exists because a user authorised it (the developer-facing detail is in the docs).
What to expect next
The access-by-design obligation, the one requiring new products to ship with direct data access built in, applies to connected products placed on the EU market after 12 September 2026. That date has now passed, which means every connected health device newly placed on the European market has been designed under it. The effect will be gradual, because it reaches devices as they are released rather than the installed base, so expect the practical difference to show up over a replacement cycle rather than a quarter.
Expect the shape of this law to be drawn from the bottom up. National implementing laws are still landing, competent authorities are still being designated in several member states, and the first complaint came from an individual rather than a regulator. Where personal data is involved, and in health it nearly always is, the GDPR authorities already have both the jurisdiction and the fining power, which is the likeliest route for anything significant in the near term.
This is a fast-moving area and a young regulation, so treat any summary, including this one, as a starting point rather than advice. The primary sources are public and readable: the regulation itself, the Commission's FAQ, and the Data Act policy page.