Two regulatory deadlines landed in September 2026, one day apart.
On September 11, the EU Cyber Resilience Act’s reporting obligations for actively exploited vulnerabilities and severe incidents took effect. On September 12, the EU Data Act’s access-by-design requirements applied to connected products and their related services. From that point forward, a machine sold is not a transaction closed. Users can reach the data their equipment generates and direct it to third parties, including repair and maintenance providers. Manufacturers have to know what their products generate, control who receives them, protect what is personal or commercially sensitive, and demonstrate the same discipline across their supplier and service networks.
Privacy governance just moved into product design, engineering, software maintenance, and supplier contracts.
Where Manufacturing Stands
The 2026 TrustArc Global Privacy Benchmarks surveyed 233 manufacturing respondents, the third-largest sector sample in a study of 1,844 privacy professionals across 17 industries. These are not privacy novices. More than half work at companies above $1 billion in revenue. Three quarters have been with their current employer five years or more. Eighty-one percent have a dedicated Privacy Office.
The results still reveal a significant gap.
Manufacturing scores 47% on the 2026 Global Privacy Index, against an all-respondent benchmark of 53%. The sector ranks 10th of 17 industries measured. Sixty-two percent of manufacturing respondents say their organization should be doing much more on privacy. The distance is not between intent and awareness. It is between intent and execution.
Where the Gaps Are
The sector has a credible foundation. Data inventory and mapping is fully implemented by 49% of manufacturers, level with the global benchmark. Breach notification sits close behind at 50%. Manufacturers can find their data and respond when something goes wrong.
The picture changes where a connected product model demands more.
Supply chain and vendor assessments are fully implemented by 41% of manufacturers, versus 49% overall. Third-party privacy certifications sit at 38%, nine points below the 47% benchmark. That is the largest single initiative gap in the sector. Trust Centers, where a company makes its program visible to customers and partners, sit at 39% versus 47%. Just 29% report fully integrated privacy tooling, against 39% globally.
Here is the integration problem in plain terms. Manufacturers with fully integrated tooling score 71% on the Global Privacy Index and have fully implemented 7.5 of the 11 privacy initiatives tracked. One step down, where most tools connect but some manual work remains, the score falls to 43% and implementation nearly halves to 3.9 initiatives. For obligations that require incident evidence, access decisions, and supplier records to be produced on demand across a product’s service life, “some manual work required” is effectively the same as “cannot be reliably done.”
The Harm is Already Showing Up Commercially
Manufacturing’s consequence profile is not primarily a breach story. Twenty-seven percent of manufacturers report a data breach, close to the 28% global benchmark.
The harm that is growing is the loss of trade partners.
Nineteen percent of manufacturers report losing trade partners because of privacy concerns, up from 14% in 2025. The global figure moved only from 12% to 13% over the same period. Consequences from AI adoption climbed from 22% to 29% in manufacturing, above the global rise from 17% to 24%.
The EU Data Act formalizes exactly the relationship this harm describes. Connected products open a continuing data relationship among manufacturers, operators, suppliers, service providers, and third parties the user brings in. A privacy program that cannot demonstrate controls across that chain is now a commercial liability, not just a compliance one.
What the Data Says to Do
The brief identifies four priorities for manufacturers.
First, govern the product data lifecycle. Map what connected products generate from design through operation, maintenance, and aftermarket access. Define who may receive it, on what legal basis, and with what protections for personal data and trade secrets.
Second, connect the control architecture to an operating model. Manufacturers value the right standards. ISO/IEC 27701 leads the list of frameworks considered most valuable, followed by ISO 27002, 27018, and 29100. Valuing a standard and holding externally validated assurance are different things. The nine-point certification gap is where that difference shows up.
Third, make supply chain accountability continuous. The sector’s fastest-growing harm is the loss of trade partners. Supplier assessments need to follow product data through the commercial ecosystem, with clear contracts, access rules, and incident escalation.
Fourth, treat AI governance as part of the privacy system, not a parallel track. Seventy-one percent of manufacturing respondents use AI tools often or very often. Manufacturers with active AI monitoring score 66% on the Global Privacy Index, against 34% for those without it.
The Bottom Line
Manufacturing built the product. The next phase is governing the data it keeps sending.
The full 2026 State of Privacy Management in Manufacturing brief includes the complete benchmark data, sector-by-sector comparisons, and a detailed analysis of what separates exceptional privacy programs from the rest.
Download the Full Manufacturing Brief