What the new EU Data Act means for IoT device owners in Australia
The European Union's Data Act, which entered into force in January 2024 with staggered application through 2025 and 2026, sets out a sweeping framework for how data generated by connected products must be handled. For the millions of Australians who own smart speakers, fitness trackers, connected appliances, and industrial sensors, the law introduces rights and obligations that will ripple well beyond Europe's borders. Devices never sold inside the bloc will fall under the regulation if their makers operate in the EU market, which captures most major consumer-electronics brands.
Most Australians will not notice the Act landing directly on their doorstep, because Australia is not a member state. Yet the country's retail landscape is dominated by the same global manufacturers — Apple, Samsung, Google, Bosch, Philips — that ship to Frankfurt and Melbourne alike. When European rules tighten, firmware updates tend to be pushed to every region, meaning a fridge sold in Brisbane inherits the compliance behaviour built for Berlin.
Smart speakers, robot vacuums, smartwatches, connected cars, and even some agricultural sensors now form part of daily life across the country, from Bondi apartments to broadacre farms in the Riverina. Data generated by those gadgets — location, usage patterns, biometrics — has historically been locked inside proprietary clouds. The Data Act aims to pry that lock open.
The basics of the EU Data Act
At its core, the legislation treats data produced by an internet-of-things device as something the user can access, port, and share with third parties. Manufacturers must design products so that raw or pre-processed data, not just polished dashboard views, can be extracted easily. A treadmill owner, for example, should be able to hand their workout history to a new fitness app without reverse-engineering proprietary files.
The Act also imposes fairness rules on cloud switching. Once data portability becomes a contractual reality, hyperscalers must remove charges that lock customers into their ecosystem. This complements existing EU efforts such as the Digital Markets Act and is meant to prevent data silos from calcifying into permanent moats around big platforms.
Importantly, the law distinguishes between personal data, which remains protected by GDPR, and non-personal machine data, which the Act specifically targets. For the first time, industrial operators and everyday consumers share a coherent right to the data their things generate.
Comparing data rights before and after
The shift is easier to grasp side by side. The table below maps what connected-device owners could and could not do under the previous patchwork of voluntary standards versus what the Data Act guarantees.
| Aspect | Before the Data Act | After the Data Act |
|---|---|---|
| Access to raw device data | Restricted to vendor dashboards | Direct, real-time access to raw and pre-processed data |
| Porting data to another service | Manual exports, often partial | Standardised formats, machine-readable, by default |
| Switching cloud providers | Transfer fees and friction common | Caps on switching costs, mandatory transparency |
| Sharing data with third parties | Vendor-controlled, opt-out by default | User-initiated, opt-in, revocable |
| Security obligations for makers | Sector-specific and uneven | Baseline cybersecurity duties across the EU |
Why Australian households should pay attention
Australia's consumer protection regime, including the Australian Consumer Law administered by the ACCC, already gives shoppers guarantees about goods and services. What it does not yet provide is a portable-data right for connected products. ACMA has signalled interest in IoT security labelling, but a binding portability regime similar to the European approach is still missing. That gap matters because Australian households have embraced connected gear at speed.
A JB Hi-Fi catalogue in 2025 typically lists more smart-home stock than ever, and Harvey Norman runs entire aisles devoted to Matter-compatible lighting, locks, and energy monitors. Sydney and Melbourne households in particular have driven uptake of solar inverters and battery systems that report back to cloud platforms, often run by overseas vendors. Once the Data Act is fully applicable, those vendors will need to expose granular data to customers across their footprint, including Australia, simply to keep their European operations tidy.
There is also a local angle around how Australians talk about their gadgets. In the pub, on the office whiteboard, in community Facebook groups, people ask "does this thing actually work with Telstra's network?" or "will my data stay onshore?" The Data Act does not guarantee onshore storage, but it does force vendors to disclose where data sits and who else can read it.
Smart home ecosystems and portability rights
Owners of multi-device households often find themselves hostage to a single brand's app. A home running Philips Hue, a Google Nest thermostat, and a Bosch dishwasher typically requires three separate accounts, three separate privacy policies, and three separate cloud logins. The Data Act pushes back against this by mandating interoperability hooks.
In practical terms, an Australian should be able to point their robot vacuum's cleaning maps at a local home-automation controller without begging the manufacturer for an API key. Related thinking about personalisation flows through adjacent spaces too, including how the rise of AI powered personal stylists is reshaping consumer expectations of data portability in lifestyle tech. The same portability muscle users build for fashion assistants will, over time, make locked-down IoT ecosystems feel increasingly archaic.
For renters in inner-city Melbourne share houses, where six flatmates might each own a smart plug or speaker, portability also means smoother handovers when someone moves on. Data tied to the device rather than the vendor account should travel with the hardware.
Business-to-business sharing reaches consumers
The Act's B2B dimension covers machine-to-machine data flows in factories, logistics, and agriculture. Australian broadacre farmers running connected tractors and soil-moisture probes supplied by European OEMs will, in time, find their equipment generating data that can be shared with competing agronomy services. That carries competitive implications well beyond Europe, especially across the Murray-Darling Basin where precision agriculture is booming.
The consumer side overlaps when a service provider relies on data sourced from a connected device. Insurance companies offering usage-based policies on connected cars, for instance, will need clearer consent flows when the underlying telemetry originates from a third-party manufacturer rather than the insurer itself.
Security and firmware obligations under the Act
Cybersecurity sits at the centre of the new regime. Manufacturers must ship devices that are vulnerability-managed throughout their lifecycle, not just at launch. That means mandatory patches, transparent disclosure of support windows, and obligations on third-party software components. For Australians who often keep gear for years — a typical Aussie household replaces a fridge every twelve to fifteen years — this is significant.
Devices covered by older voluntary standards pale next to what the Act demands. A smart lock sold in Adelaide inherits the same duty of care as one sold in Amsterdam, which sets a higher floor than anything currently required under Australian law.
Practical moves for Aussie connected-device owners
Australians do not need to wait for local law to catch up. A handful of habits will keep them ahead of the curve.
- Audit which devices in the home send data to overseas clouds and decide whether the convenience is worth the exposure.
- Push back on retailers and manufacturers that cannot explain how to export your data in a usable format.
- Prefer gear that supports the Matter standard, which already implements many portability principles the Act codifies.
- Keep firmware up to date and replace devices whose manufacturers stop issuing security patches.
- Ask Australian regulators, including the Office of the Australian Information Commissioner, to clarify how portability rights interact with local privacy law.
The first step is simply knowing that the data pouring out of a smart speaker or a connected car is yours to claim, not just a courtesy the vendor may grant. Australians who internalise that idea before the Act's provisions bite into global product roadmaps will find the transition to a more open connected-device world almost invisible.