Who owns robot data? The EU Data Act, explained

A robot, a capture rig, and a sensor array all emit machine-generated data. How the EU Data Act reshapes who can access, share, and license it.

7 min read

A robot arm on a pilot assembly line does its job. Without anyone thinking about it, the arm produces a second output: a stream of joint angles, force readings, camera frames, and timestamps. A person wearing a capture rig to record a kitchen task produces the same kind of exhaust. So does a fixed sensor array watching a warehouse. Three very different machines, one shared trait. Each generates data as a byproduct of being used.

Who owns that data? For years the honest answer was a shrug, backed by whatever the purchase contract happened to say. The EU Data Act changes the shrug. Most of its obligations began applying in 2025, and it rewrites who can reach machine-generated data, who can share it, and on what terms.

The surprising part is what it does not do. It largely refuses to hand anyone a clean ownership title over the data a device produces. Instead it distributes rights to access and use that data. For a company whose whole business is turning device output into a training corpus, that distinction is the ballgame.

Every used device is a data source

Start with the category the Act cares about: data generated by the use of a connected product, plus the related services that go with it. A connected product is anything that senses the physical world and communicates what it records. An industrial robot qualifies. So does a wearable rig with cameras and inertial sensors. So does a smart machine on a factory line. The EU Data Act treats the data these things emit as a regulated resource, not a private spoil that flows automatically to whoever built the hardware.

This is a real shift. The default assumption in industry was that the manufacturer of a device controlled the data it threw off, because the manufacturer wrote the firmware and ran the cloud. The Act pushes against that default. It says the user of the product, the business or person operating it, holds rights to the data their use creates, including the right to get at it and to pass it to someone else.

For robot training data this reframing is not abstract. A demonstration recording is machine-generated data in the plainest sense. The rig captured it. Someone used the rig. On what each party can do next, the Act now has opinions.

It reallocates access, not ownership

Here is the point most summaries miss. The Data Act does not invent a new property right in data. Lawmakers weighed a data-ownership regime and declined to build one. What the Act creates instead is a set of access and use rights, allocated between the parties around a connected product.

Three of those rights matter most for anyone assembling a dataset. Users can access the data their device generates, and can ask a data holder to share it with a third party of their choosing. Data holders, often the manufacturer, cannot use their technical position to lock users out or to strong-arm them with unfair contract terms. And a cloud or processing provider has to let a customer switch and take their data with them, which drags portability into the picture.

Read those together and the ownership question dissolves into something more practical. The interesting question is no longer who holds title. It is who can lawfully access a given stream, who they may share it with, and what a contract can and cannot demand in exchange.

The Data Act mostly refuses to say who owns machine-generated data. It says who can reach it, who they can pass it to, and which contract terms are off the table. For a training corpus, that is the more useful answer.

Three EU regimes, three different questions

The Data Act does not arrive on an empty desk. A robot dataset already sits under two other regimes, and confusing them is how teams get compliance wrong. The GDPR governs the personal data inside a recording: the face, the voice, the biometric signature of the hands. The EU AI Act governs the provenance and governance of data used to train an AI system. The Data Act governs access to and use of the machine-generated data itself, personal or not. Same dataset, three separate questions.

How three EU regimes divide up a single robot-demonstration dataset, and what each asks of the supplier
RegimeWhat it governsWhat it asks of a robot-data supplier
GDPRPersonal data captured in the recording: faces, voices, biometric hand and body dataA lawful basis, informed consent, and the ability to honor access and deletion requests
EU AI ActProvenance and governance of data used to train higher-risk AI systemsDocumented origin, logged collection conditions, and records of how the data was labeled
EU Data ActAccess to and use of machine-generated data from connected products, personal or non-personalHonor user access and sharing rights, fair contract terms, no unfair lock-in, transfer safeguards

The rows do not collapse into each other. You can be fully GDPR-compliant on consent and still fall foul of an unfair data-sharing term the Data Act voids. You can have spotless provenance under the AI Act and still owe a user access to the raw stream their device produced. A supplier that treats data compliance as one checkbox is going to be surprised by at least two of these.

Why it lands hardest on training data

A training corpus for humanoid robots is built from exactly the kind of output the Data Act regulates. Every demonstration is a device recording a use. That raises questions the old contract-only world never forced anyone to answer.

Who is the user, and who is the data holder? If a person wears a capture rig to perform a task, and the rig belongs to the capture company, the roles are not obvious, and the answer changes who can demand access and who must grant it. The Act's logic runs through the arrangement whether or not the paperwork mentions it.

What can a licensee do downstream? Because the Data Act constrains how a data holder may restrict reuse and sharing, the terms attached to a corpus become part of its value. A dataset that can be shared cleanly, without a lurking unfair-term challenge, is worth more than one wrapped in clauses a court might strike.

Then there is a sovereignty thread. The Data Act includes safeguards against compelled access to non-personal data held in the EU by non-EU authorities, which rhymes with the jurisdiction concerns that already shadow personal data. That is its own long argument. It connects to why corporate structure, not just server location, decides who can be forced to hand a dataset over.

The intermediary layer the market is growing

The Data Act has a sibling. The EU Data Governance Act sets rules for data intermediation services: neutral parties that sit between those who hold data and those who want to use it, without taking the data for themselves. The framing matters, because it sketches a plausible shape for a robot-data market that is more than a pile of bilateral deals.

Picture a corpus of demonstrations whose access rights are clear, whose personal data is handled under GDPR, whose provenance satisfies the AI Act, and which can be offered through a trusted intermediary on fair, documented terms. That is a licensable asset a regulated buyer can actually deploy. Now picture the same footage with tangled rights and an unfair-term cloud over it. Technically identical, commercially worlds apart.

This is where the three regimes stop being separate burdens and start compounding into a single property: whether a dataset is cleanly transferable. The International Federation of Robotics tracks an installed base of industrial robots in the millions, a large share of it in Europe. As those fleets, and the humanoid programs behind them, generate ever more machine-generated data, the rules for reaching and sharing it stop being a footnote.

So the honest answer to who owns robot data is that the EU Data Act would rather you ask a sharper question. Ownership is a blunt instrument for something copied, blended, and reused a thousand times. Access, sharing rights, and fair terms are the levers that actually decide what a dataset is worth and who can use it. Teams that treat those levers as design parameters, settled while the sensor is still recording, will hold the corpora a European robot maker can license without a second thought. The rest will hold footage and a contract argument.

eu-data-actmachine-generated-datadata-ownershiprobot-datadata-governance

Sources