Data Act and Digital Health: The End of the Wearables´ Monopoly
Este contenido está disponible únicamente para socios BAIDATA.
Regístrate o accede con tu cuenta para verlo.
Just a few weeks ago, on 12 September 2026, one of the Data Act‘s most disruptive technical obligations came into force: devices placed on the market from that date must be designed so that their data is accessible from the outset (Art. 3.1). This is a fundamental change, because control over the information moves from each manufacturer’s terms and conditions to being protected by European law. If you run an SME or a HealthTech project, this removes long-standing barriers to your business.
The Data Act, or Data Regulation (Regulation (EU) 2023/2854), has applied generally since 12 September 2025. Its aim is to give users more control over the data generated by their connected devices.
In healthcare, this has a very concrete meaning. A smartwatch or an activity band continuously records heart rate, sleep quality or blood oxygen saturation. Until now, buying a wearable meant, in practice, accepting that its data lived in the manufacturer’s ecosystem. If you wanted to build a patient monitoring programme or a rehabilitation app, you had to wait for the brand to open an API and accept its conditions.
The Data Act reverses that starting point, clarifying concepts, rights and responsibilities. The manufacturer is no longer the owner of the data, but simply its custodian (Data Holder), and as such it is obliged to make the data available to third parties when the true owner, the user, requires it. And it must do so in a simple, secure and free-of-charge way, in a machine-readable format and, where feasible, in real time (Arts. 4 and 5).
The first thing that changes is the starting point of any integration. With the Data Act there is no longer any need to wait: if the user asks, the manufacturer must open that channel. This will let you build all kinds of services on data from several manufacturers at once, without being tied to a single device ecosystem.
The regulation is designed to protect the competitiveness of SMEs:

Opening up data does not mean handing it to just anyone. Whoever receives the data takes on strict conditions:
You should also bear in mind that the Data Act coexists with the European Health Data Space (EHDS) Regulation. While the former governs access to data from connected devices, the EHDS focuses on data from the healthcare system, such as electronic health records.
To orchestrate this complex flow of consents (GDPR) and integrations (Data Act + EHDS), the ideal infrastructure is sovereign data spaces.
Do you need to adapt your technical infrastructure to start receiving data flows under the Data Act?
At BAIDATA, we help you integrate your services through certified connectors that audit regulatory compliance. Train with our Data Space Professional Qualification Program or, if you are ready to test your developments, connect with the EDS2 Socio-Health Data Space Demonstrator Centre, led by GAIA and with which we actively collaborate.