The EU Data Act Deadline Is 12 September. Your Part of It Was Last Year.

VisioncarePro by

If you sell smart glasses into Europe, two regulations land on your catalogue on consecutive days this month.

On 11 September, the Cyber Resilience Act's vulnerability reporting clocks start running. On 12 September, the EU Data Act's access-by-design obligation applies to connected products placed on the market after that date.

Same handful of SKUs. Two different regimes. One day apart.

The Cyber Resilience Act has at least been written about. The Data Act, for this vertical, has not — and the coverage that does exist is aimed squarely at manufacturers, which is why most optical retailers reading about the 12 September date will reasonably conclude it is somebody else's problem.

It mostly is. But not entirely, and the part that is yours is not the part being reported.

What the Data Act actually is

Regulation (EU) 2023/2854 governs who gets access to the data that connected products generate. Its animating idea is that when a device collects data about its own use, the person using it should be able to get at that data rather than having it disappear into the manufacturer's cloud.

A connected product, in the Regulation's terms, is one that obtains, generates or collects data about its use, performance or environment, and that communicates that data over an electronic communications service, a physical connection, or on-device access. Products that merely store or transmit data on someone else's behalf are excluded, as are prototypes.

Read that definition against a modern eyewear catalogue and the line is not hard to draw. A pair of acetate frames is not a connected product. A pair of AI glasses with a camera, microphones, open-ear audio and an onboard assistant is one, comfortably. So is a frame that logs wear time to a phone app. So, probably, is any frame whose selling point involves a companion app doing something with sensor readings.

Most eyewear stores have zero of these. Some have one or two, added in the last eighteen months without much thought, because a supplier offered them and the category is growing. This post is for the second group.

The date being reported binds your supplier

12 September 2026 is the access-by-design date. From that day, connected products and related services placed on the EU market must be designed so that the data they generate is, by default, easily, securely and directly accessible to the user, free of charge, in a structured, commonly used, machine-readable format. Where direct access is not technically feasible, indirect access is permitted, with the reasons documented.

That is an engineering obligation. It attaches to how the product is built, which means it attaches to whoever built it. If you are reselling a major manufacturer's smart frames, you are not the one redesigning the firmware.

Two things follow that are still yours, though.

First, the deferral is not a date on which a duty switches on for everybody. Article 50(3) says the obligation resulting from Article 3(1) “shall apply to connected products and the services related to them placed on the market after 12 September 2026.” Products already in circulation are not caught. That splits a catalogue in two, and the split runs through your stock rather than your listings. Somewhere around the middle of this month, the same product name starts arriving in boxes governed by a rule the earlier boxes were not.

Second — and this is the part worth your afternoon — there is a separate obligation that has never depended on 12 September 2026 at all.

Article 3(2) is the retailer's obligation, and it is already live

The Data Act has applied since 12 September 2025. Only the access-by-design rule in Article 3(1) was deferred.

Among the provisions that have been in force for the past twelve months is a pre-contractual information duty, and its opening words settle the question of who it is for:

“Before concluding a contract for the purchase, rent or lease of a connected product, the seller, rentor or lessor, which may be the manufacturer, shall provide at least the following information to the user, in a clear and comprehensible manner…”

Read the parenthetical carefully. Which may be the manufacturer is permissive, not restrictive. It exists to make clear that the seller need not be a separate party from the manufacturer — not to limit the duty to manufacturers who sell direct. A pure retailer, selling somebody else's connected frames, is the addressee of this provision. The recitals put it the same way.

That is the sentence that turns a manufacturing regulation into a product-page problem, and it is the reason this post exists.

The information runs, in substance, to:

  • the type, format and estimated volume of product data the device generates
  • whether it generates data continuously and in real time
  • how it is stored, where, and for how long, and whether it is held on-device or remotely
  • how the user accesses, retrieves or erases it

A word on the neighbouring provision, because summaries tend to run the two together. Article 3(3) imposes a parallel and longer disclosure for related services — a companion app, a cloud assistant, a subscription tier — covering collection frequency, what the data holder intends to do with the data, who it is shared with and how to reach them, how to end the arrangement, and how to complain. But 3(3) is addressed to “the provider of such related service,” not to the seller. If the app and the subscription are the manufacturer's, that duty is the manufacturer's. Yours is 3(2). Do not let a consultant sell you the longer list as though it were your obligation, and do not assume the manufacturer has discharged it either — if you are the one taking the subscription payment, ask who the provider is.

“Before concluding the contract” means before checkout. On an online store, that means on the product page or somewhere a customer plainly reaches from it. It is not a clause you can bury in terms of sale that a buyer accepts at the payment step.

The awkward part: you cannot write this yourself

Every other compliance task in this vertical is something a merchant can do alone. Rewrite the copy, fix the alt text, add the disclosure, change the artwork.

This one is not. You do not know the estimated volume of data a supplier's frames generate, whether the audio buffer is retained on-device, or what the retention period is on the assistant transcripts. Nobody selling those frames knows, because the answer is in a document the manufacturer has and has probably not sent you.

So the work is a supplier email, and the honest version of the advice is that the email should have gone out last autumn. Ask each supplier of a connected SKU for their Article 3(2) information set — and, where they also run the app or the subscription, their Article 3(3) set. If they are an EU manufacturer of any size they should have it prepared. If they do not know what you are asking about, that is itself informative — both about the 12 September obligation that is about to land on them and about whether the listing is worth keeping.

While you wait, the interim position is not to invent the figures. A short, accurate statement of what you do know, with a link to the manufacturer's own data documentation, is better than a confident paragraph you cannot evidence. Under a regulation about data transparency, a fabricated transparency notice is the worst available outcome.

The small-business exemption does not do what you want it to

This is the section most likely to catch a reader out, because the exemption reads like relief for small merchants and is not.

Article 7 disapplies the Chapter II obligations — Article 3 included — but it is keyed to the object, not the addressee. The relief runs to “data generated through the use of connected products manufactured or designed or related services provided by a microenterprise or a small enterprise.”

Read that against your own situation and the consequence is counterintuitive in both directions:

Being small does not help you. If you are a two-person optical shop reselling a large manufacturer's smart frames, the exemption does nothing for you. Your size is legally irrelevant to it. The Article 3(2) duty applies to you in full.

Your supplier being small does help you. If the frames were designed and made by a genuine micro or small enterprise, Chapter II does not apply to that product's data at all — and your seller-side duty falls away with it. Not because of your status, but because of theirs. Which means “how big is your company?” is now a question worth asking a small supplier, and worth getting the answer in writing.

Three carve-outs cut the relief back even where it applies. It falls away if the small enterprise has a partner or linked enterprise that is not itself micro or small — group structures are common in eyewear, and a small brand inside a larger holding company is not covered. It falls away where the enterprise is subcontracted to manufacture or design the connected product or provide the related service, which is the same private-label trap flagged in the Cyber Resilience Act post, appearing again under a different regulation, and not a coincidence. And for enterprises that have only recently grown into the medium-sized bracket there is a time-limited grace period rather than a permanent exclusion.

The practical read: a disclosure you can produce cheaply is cheaper than the argument about whether you had to.

Enforcement, realistically

Member States designate one or more competent authorities and, where there are several, a national data coordinator as the single point of contact. Penalties are set nationally and must be effective, proportionate and dissuasive. There is no harmonised headline percentage of the kind the GDPR made famous, and no eyewear enforcement action to point to.

Which means the near-term risk here is not a regulator's letter. It is the same risk the GPSR enforcement phase produced: a marketplace or a large retail partner adds a compliance field, and listings without an answer stop selling. That is how every one of these regimes has actually reached merchants in this vertical, and it arrives faster than any authority does.

What none of this touches

Four European regimes now attach to a connected frame. The Cyber Resilience Act governs how it is secured and how quickly a vulnerability is reported. The Product Liability Directive makes the software in it a product and puts somebody in Europe on the hook for it. The Data Act governs the data it generates and what you must say about that before you sell it. The General Product Safety Regulation governs whether it may be listed at all.

None of them attaches to the lens.

Prescription lens work generates no product data. There is no data holder, no access-by-design question, no companion app, no retention period, no disclosure to obtain from a supplier who may not answer. A prescription is configured per customer and made domestically, and the value in it comes from the configuration rather than from an imported device with firmware you cannot inspect.

That is a real distinction, and it is worth stating the limit of it: a prescription is health-adjacent personal data, and the GDPR obligations that come with it are genuine and not trivial. The difference is that those are obligations an optical retailer already has, understands, and has built its processes around. What arrived this month is a second, unfamiliar regime layered on top, governing a different category of data, on a small number of SKUs, with a supplier dependency you do not control.

Every regulatory development this project has tracked in 2026 has pointed the same way from a different direction: the compliance surface sits on the imported object, and the margin sits on the prescription. This is the fifth direction.

The checklist, before the 12th

  1. List your connected SKUs. Anything with a camera, a microphone, an onboard assistant, sensors, or a companion app. For most stores this list is empty and you can stop here.
  2. Email each supplier for their Data Act Article 3(2) information set — data types, volume, real-time status, storage location and retention, and access, retrieval and erasure routes. Where the supplier also runs the app or the subscription, ask for the Article 3(3) set as well.
  3. Ask how big they are. If a supplier is a genuine micro or small enterprise with no larger parent and no subcontracting arrangement, Chapter II may not reach that product at all. Get it in writing.
  4. Ask one more question in the same email: whether stock shipping to you after 12 September 2026 is designed to the access-by-design requirement. You will want the answer on record.
  5. Build one disclosure block on the product page template rather than per listing. The fields are the same for every connected product; only the values change.
  6. Put it before checkout, not in terms of sale.
  7. Do not fill gaps with guesses. Say what you know and link to the manufacturer's documentation for the rest.
  8. Handle it alongside the CRA work, since it is the same SKU list, the same suppliers, and the dates are one day apart.

Frequently asked questions

Does the Data Act apply to a shop that only sells ordinary prescription glasses and sunglasses? No. Non-connected eyewear generates no product data and falls outside the definition of a connected product. The Regulation reaches a catalogue only through smart or sensor-equipped frames and their related services.

I only resell someone else's smart glasses. Isn't this the manufacturer's problem? The access-by-design obligation that applies on 12 September 2026 is, in substance, the manufacturer's. The pre-contractual information duty in Article 3(2) is addressed to “the seller, rentor or lessor”, which is you. You will need the manufacturer's information in order to discharge it, which is why the supplier email is the first step rather than the last.

Is 12 September 2026 when the Data Act starts applying? No. The Data Act has applied since 12 September 2025. 12 September 2026 is the date the access-by-design requirement in Article 3(1) bites, and it applies to connected products placed on the market after that date rather than to existing stock.

We're a small business. Are we exempt? Almost certainly not, and this is the most commonly misread provision in the Regulation. The Article 7 exemption is keyed to the size of the enterprise that manufactured or designed the product, not the size of the shop selling it. A small retailer selling a large manufacturer's connected frames gets no relief from it. If your supplier is a micro or small enterprise, that is a different matter — ask them, and check for a larger parent company and for any subcontracting arrangement, both of which cancel it.

What is the penalty? Penalties are set by each Member State and must be effective, proportionate and dissuasive; there is no single EU-wide figure. In practice the earlier and more likely consequence is a marketplace or retail partner requiring the disclosure as a listing condition.


This article is general information about regulatory developments, not legal advice. Rules of this kind apply differently depending on your catalogue, your suppliers and where you sell; take advice on your own position before acting.

VisioncarePro puts prescription capture inside the buying flow — upload, manual entry or email, with AI reading the uploaded prescription and a built-in PD scanner. It works on the part of your catalogue that has no firmware, no data holder and no supplier dependency.

Install VisioncarePro free on the Shopify App Store →

Sources: Regulation (EU) 2023/2854 (Data Act), Articles 3, 7 and 50, and recital 24 · European Commission, “Data Act explained” · Wilson Sonsini, “EU Data Act September 2026 Deadline” · Loyens & Loeff, “New obligations for data holders of connected products and related services” · Travers Smith, “The EU Data Act: compliance countdown for connected products” · Alston & Bird, “The Data Act: 7 Things to Know”.

RuffRuff Apps RuffRuff Apps by Tsun