Anyone selling connected machines, drives, sensors, meters or measuring instruments through a B2B shop has had a duty since 12 September 2025 (Data Act, Art. 50) that hardly any product data model provides for: before the purchase contract is concluded, the seller provides the buyer with at least four items of information (Data Act, Art. 3(2)) on the data the product generates. This expressly applies to business customers too, because a user within the meaning of the regulation is any natural or legal person that owns a connected product. For products placed on the market after 12 September 2026 (Data Act, Art. 50), the duty of data access by design is added – a manufacturer duty that still shows up in the catalogue, because it separates two product generations. Official statistics show how common connected technology is in companies: as early as 2021, 29% (Eurostat) of EU enterprises with at least ten employees used connected devices or systems. This article does not cover data rights in general but a practical question: where do the mandatory disclosures sit in the ordering process, and how can you prove that they were visible before the contract was concluded?
Key takeaways
- Before the contract, the seller of a connected product provides at least four items of information (Data Act, Art. 3(2)): type, format and volume of the data, real-time capability, storage location including period, and the way to access and erase the data.
- The duty applies in B2B just as it does towards consumers: under Art. 2 point 12, a user also includes a legal person. A buyer in a punchout catalogue has the same claim to the disclosures as a private customer.
- The reliable place for the disclosures is a dedicated attribute set per product family in the PIM, filled from manufacturer data and with a mandatory field check before release. Free text in the description can be neither checked nor versioned.
- “Before the contract” becomes provable when quote, basket and order confirmation carry the version of the disclosures and the buyer can store them and retrieve them unchanged (Data Act, recital 24).
- For products placed on the market after 12 September 2026 (Data Act, Art. 50), data access by design applies in addition. A placed-on-market flag separates the two product generations in the catalogue.
What the Data Act requires of the seller before the purchase
Regulation (EU) 2023/2854, the Data Act for short, governs who may use data from connected products. Most of the text addresses manufacturers and data holders. One provision, however, directly affects trade: under Art. 3(2), certain information is provided to the user “before concluding a contract for the purchase, rent or lease” by the seller, rentor or lessor, “in a clear and comprehensible manner”. The seller may also be the manufacturer – but the duty attaches to whoever concludes the contract. For a wholesaler selling drives, controls or measuring equipment from several manufacturers, this means: it needs the disclosures of all manufacturers in a form its shop can show before the purchase.
The regulation has applied since 12 September 2025 (Data Act, Art. 50). There is no separate transitional rule for the information duty, as Art. 50 provides for data access by design. The duty is tied to the conclusion of the contract, not to the date of placing on the market – so, by its wording, stock items that have been in the catalogue for years are affected too. The Cyber Resilience Act, by contrast, governs the security of connected products. Both regulations often concern the same items but require different information and can be kept cleanly apart in the data model.
Who counts as a user
The four items under Article 3(2)
The regulation lists at least four items of information (Data Act, Art. 3(2)) in points (a) to (d). They describe not the product but its data behaviour – and that is exactly what many catalogues lack, because nobody has asked for it so far. The overview below maps each item to an attribute that can be maintained in the PIM and carried into every output channel.
| Point | Content under the regulation | Attribute in the PIM | Typical content |
|---|---|---|---|
| a | type, format and estimated volume of product data | data types, data format, data volume per time unit | measured values, states, error codes; JSON or CSV; estimated volume per operating day |
| b | whether the product can generate data continuously and in real time | real-time capability (yes/no), capture interval | continuously every second or only on events |
| c | whether the product is capable of storing data on the device or on a remote server, including, where applicable, the intended retention period | storage location, retention period, ring buffer (yes/no) | locally in the device, additionally in the maker portal; period as stated by the manufacturer |
| d | how the user can access, retrieve or, where relevant, erase the data, including technical means, terms of use and quality of service | access route, interface, erasure route, link to terms | export via web interface or fieldbus, erasure by factory reset, link to terms of use |
The words “at least” matter: the four points are a floor. If you set them up as mandatory fields, keep the data model open. Recital 24 includes, where available, information on data structures, data formats, vocabularies, classification schemes, taxonomies and code lists, as well as the terms of use and quality of service of application programming interfaces. That is not an additional duty, but it indicates what makes information clear and comprehensible – and it fits into the same attribute set.
Which products are concerned – and which manufacturers are not
Under Art. 2 point 5, a connected product is an item that obtains, generates or collects data concerning its use or environment, is able to communicate product data via an electronic communications service, a physical connection or on-device access, and whose primary function is not the storing, processing or transmission of data on behalf of another party. The recitals expressly mention agricultural and industrial machinery. In a B2B shop range, this includes frequency inverters with a diagnostic interface, energy meters, pressure and temperature sensors, cordless tools with app connection, compressors with remote monitoring or measuring instruments with memory. Among enterprises using connected devices, 24% (Eurostat) used sensors in 2021 to monitor the condition of equipment in real time. The range is especially dense in B2B shops for industry, in electrical engineering and in technical trade.
Not every manufacturer is subject to the duties of the chapter. Art. 7(1) excludes data from connected products manufactured or designed by a micro or small enterprise, provided it has no larger partner or linked enterprises and does not act as a subcontractor. Under the Commission recommendation, a small enterprise employs fewer than 50 persons (Recommendation 2003/361/EC) and has an annual turnover or balance sheet total not exceeding EUR 10 million (Recommendation 2003/361/EC). For enterprises that have only recently qualified as medium-sized, the paragraph provides a time-limited relief. By its wording, the exemption also covers the disclosures under Art. 3(2), because they sit in the same chapter.
The exemption depends on the manufacturer, not the retailer
The attribute set “data disclosure” in the PIM
The information duty can be met in two ways: as text in the product description or as a structured attribute set. The first is quicker to set up and expensive later. Free text cannot be checked for completeness, output per channel or versioned. An attribute set “data disclosure”, by contrast, is attached to the product family, passes its values on to all variants and is carried into shop, quote and catalogue export via PIM integration. Many values apply to a whole series: a frequency inverter generates the same data types in the same format at every power rating.
Data types and format
Which product data arise, in which format and in what estimated volume. Pick lists instead of free text, so that values can be compared and filtered.
Real time and interval
Whether the product generates data continuously and in real time, plus the capture interval. A yes-no field with a short explanation covers most cases.
Storage and period
Storage on the device, on a remote server or both, each with the intended retention period, as far as the manufacturer states it.
Access and erasure
Technical route to retrieval and erasure, interface, terms of use and quality of service as a link to a versioned document.
Placing on the market
Date of first placing on the market or a flag for products after the cut-off date, so that data access by design can be traced per product.
Version and source
Version number of the disclosures, origin in the manufacturer delivery and date of the last check. Without these three fields, any proof remains incomplete.
If you are already building product data for the digital product passport, you can use the same structure: both projects require manufacturer information with origin and version. The content differs, the procedure is the same. The foundation remains reliable data quality in the PIM – an attribute set is only as good as the rules that fill and check it.
Import from manufacturer data and mandatory field check
The disclosures originate with the manufacturer. It knows the data types, storage location and access route; the retailer usually does not. In practice, the values therefore come from three sources: the manufacturer’s structured catalogue, an information page the manufacturer refers to, or a query to the supplier. Recital 24 expressly mentions a stable internet address that can be distributed as a web link or QR code. For the shop, that is the simplest case: the link is imported as an attribute, and the core disclosures are still stored in structured form, so that they are available in the quote and in the punchout catalogue without a click to a third-party page. Before release, the PIM then checks the following points:
- Every product with the feature “connected” has all four items under Art. 3(2) filled in or a documented exemption under Art. 7
- The values come from a named manufacturer source with a date, not from an estimate by product management
- The link to terms of use and quality of service points to a document with a version number
- The placed-on-market flag is set as soon as the manufacturer supplies the date
- Changes to the disclosures create a new version and trigger a new release
- Products without complete disclosures do not go into the shop, the quote template or the catalogue export
The last rule is the most effective. As long as a product can be released without disclosures, it will sooner or later be sold that way. The mandatory field check therefore belongs in the PIM release workflow, not in a subsequent report. What remains open is what the feature “connected” itself depends on. A practical approach is to derive it from the product classification, supplemented by a manual flag for borderline cases – such as tool ranges in which only one variant has a radio interface.
Where the disclosures sit in the ordering process
In B2B trade, there is rarely only one route to a contract. A buyer sees the product in the shop, requests a quote, orders via their company’s procurement catalogue or receives an order confirmation for a telephone order. The regulation does not ask about the channel but about the timing: the disclosures are provided before the contract is concluded. Every channel through which a contract can come about therefore needs its own output.
| Channel | Output of the disclosures | Timing | What can be proven |
|---|---|---|---|
| Product detail page | dedicated “data disclosure” block plus stable link | before the basket | version active at the time of the order |
| Quote PDF | section per connected line with version | before the quote is accepted | quote number, version, date sent |
| Punchout catalogue | attribute or link in the catalogue export | before the basket is transferred | export status and version per item |
| Basket and checkout | note with link per connected line | before the order is submitted | timestamp and version in the order |
| Order confirmation | disclosures or link per line, version noted | after the contract, as documentation | permanently stored document in the customer account |
| Customer portal | archive of disclosures per purchased product | at any time after purchase | unchanged reproduction of the stored version |
On the product detail page, the block belongs next to the technical data and not in a tab that hardly anyone opens. If you already offer data sheet downloads on the product detail page, you can add the disclosures as a separate document with a version number. In the quote process, the quote is often the last step before the contract; if nothing is stated there, the information is missing exactly where it counts. With punchout via OCI, the buyer leaves the shop before the order is created. The disclosures must therefore be in the catalogue export, as an attribute or link that the procurement system displays. How such fields can be mapped in punchout catalogues depends on the target system. After the purchase, the customer portal keeps the version that applied at the time of purchase.
The core in one sentence
Making “before the contract” provable
The regulation requires provision, not proof. In a dispute, however, the seller must be able to show that it met its duty. A shop can do this if it links three things: the version of the disclosures, the time of display and the transaction it belongs to. Technically, this means: every change to the attribute set creates a new version number. Quote, basket and order store this number per line, and the order confirmation states it as well. For every order, you can later trace which disclosures the buyer could see before the contract.
Recital 24 sets a clear benchmark for this: the user must be able to store the information in a way that is accessible for future reference and that allows the unchanged reproduction of the information stored. A page whose content changes without marking hardly meets this. A PDF with a version number or a versioned address whose old versions are retained comes much closer. For implementation in the shop, a table of versions per product family is enough: the product page shows the current version, the customer account the one purchased.
Stable address plus version
Cut-off date 12 September 2026: data access by design
From the cut-off date, the duty under Art. 3(1) applies: connected products and related services are designed so that product data and related service data, including the relevant metadata, are by default easily, securely, free of charge and in a commonly used, machine-readable format accessible to the user, and, where relevant and technically feasible, directly accessible. Under Art. 50, this applies to products and services placed on the market after 12 September 2026 (Data Act, Art. 50). Placing on the market means the first making available on the Union market – a point in time at the manufacturer or importer, not the day the item was created in the shop. A retailer’s warehouse can therefore hold, for months, devices with the same item number, some placed on the market before and some after the cut-off date.
The duty under paragraph 1 falls on the manufacturer. It is still relevant for the shop, because buyers ask about it and because the disclosures under paragraph 2 may differ for newer devices: direct access instead of export via a service interface, other formats, other terms. A flag for placing on the market after the cut-off date separates both generations in the PIM. It can be kept per item or, with mixed stock, per batch or serial number range, provided the manufacturer supplies this information.
Supervision and fines in Germany
Related services: app, portal, remote maintenance
Many connected products are sold with a service: an app for configuration, a portal for consumption data, remote maintenance by the manufacturer. For such related services, Art. 3(3) applies. Before the contract for the service is concluded, its provider gives the user at least nine items of information (Data Act, Art. 3(3)). The duty lies with the provider of the service, often the manufacturer. If the shop itself sells the service, for example as a service contract or as a licence for a device platform, it should at least be able to pass the information on. The list is considerably longer than for the product purchase:
- type, estimated volume and collection frequency of the product data the data holder is expected to obtain
- type and estimated volume of the service data the service itself generates, including the access route
- whether the data holder intends to use the data itself, for which purposes, and whether third parties may use them
- identity of the data holder with trading name and address
- means of communication for quick contact
- how the user can request sharing with a third party and end it again
- the right to lodge a complaint with the competent authority
- whether the data holder holds trade secrets in the data or who else is their holder
- duration of the contract and options for early termination
In the PIM, related services therefore get their own attribute set, attached to the service item and linked to the product. If the shop sells device and service as a bundle, it shows both sets before the contract. For services the buyer concludes with the manufacturer only after the purchase, a note in the shop that the information will be provided when the contract with the provider is concluded is usually enough.
Reliable data disclosures in six steps
The effort depends less on technology than on obtaining the data. The following steps form a sensible order, because each builds on the previous one:
- Record the range: identify connected products via classification and features, flag borderline cases and assign each product family to its manufacturer.
- Create the attribute set: the four items under Art. 3(2), plus placing on the market, exemption under Art. 7, version and source.
- Obtain manufacturer data: request a structured delivery or a stable information address and file the replies with a date.
- Activate the mandatory field check: release in the PIM only with a complete attribute set or a documented exemption.
- Wire up the output: product detail page, quote template, punchout export, basket, order confirmation and customer portal.
- Secure the proof: store the version number per line and keep old versions retrievable unchanged.
None of this is unusual technically: attribute sets, release checks and document templates are standard tools of any Shopware development. What matters is connecting the systems, so that the version from the PIM runs through to the order confirmation. We set up the attribute set and its output via the PIM connection and review existing catalogues beforehand in a no-obligation initial consultation.
Sources and legal basis
Related Articles
Where Order Documents Live and How Long They Stay
Order confirmation, delivery note, invoice and price list in the customer account: which retention period applies, when it starts and where the files may sit.
Showing Declarations of Performance Before Checkout
Regulation (EU) 2024/3110: how the declaration of performance and conformity, CE details and safety information become visible in the shop before the contract binds.
WEEE Duties When You List Electricals in a B2B Shop
The registration number as an item field, a block for unregistered manufacturers, output on quote and invoice, and a take-back duty measured by storage and dispatch space.