Skip to content
EU Data Act

EU Data Act Compliance Checklist

4 min readUpdated 21 October 2026

The EU Data Act applies from 12 September 2025. This checklist covers the key compliance obligations for IoT manufacturers, related service providers, cloud service providers, and B2B data sharing arrangements. Work through the relevant sections for your business model.


Section 1: Scope Assessment (All Companies)

  • Identify whether you manufacture connected products (IoT)
  • Identify whether you provide related services (digital services connected to physical products)
  • Identify whether you are a cloud service provider (IaaS, PaaS, SaaS with significant data holdings)
  • Identify whether you hold data generated by third parties' use of connected products (data holder in B2B context)
  • Confirm whether the SME exemption applies (under 50 employees AND under €10M turnover exempts from IoT provisions only)
  • Map the data flows: what data is generated, where it is held, who holds it

Section 2: IoT Manufacturers and Related Service Providers

Product Design and Access

  • Confirm connected products provide user data access by default (through device interface or app)
  • Verify data access mechanism is easy to use — not buried in settings or requiring technical expertise
  • Confirm data is provided in a commonly used, machine-readable format (JSON, CSV, or industry standard)
  • Verify the access mechanism covers the full scope of product-generated data

Pre-Purchase Transparency

  • Pre-purchase product information identifies what data is collected
  • Pre-purchase information discloses how data is stored and who holds it
  • Format of data access is disclosed before sale

Third-Party Data Sharing

  • Mechanism exists for users to authorise third-party access to their data
  • Identity verification in place for third-party data access requests
  • Process documented for how third-party sharing requests are handled
  • Terms with third-party recipients include purpose limitation and no competing product development clause

Terms of Service Review

  • Service terms reviewed for provisions that restrict user data access — void under Data Act
  • Provisions preventing users from sharing their data with third parties — identified and removed
  • No clause requires users to waive Data Act rights as a condition of using the product

Section 3: Cloud Service Providers

Switching Support

  • Structured data export capability in place (full data export in portable format)
  • Export format is commonly used and non-proprietary
  • Switching support process documented — how you handle migration requests
  • Maximum 30-day standard transition period confirmed (extended by agreement up to 180 days)

Egress Fee Policy

  • Current egress fees reviewed against Data Act requirements
  • Egress fees for switching purposes reduced to cost-of-transmission by September 2025
  • Plan in place to eliminate switching egress fees by September 2027
  • Egress fee policy disclosed transparently in customer-facing documentation

Contract Updates

  • Standard contracts reviewed for lock-in provisions
  • Disproportionate termination penalties — identified and removed or adjusted
  • Unreasonably long minimum notice periods — reviewed
  • Switching provisions added: process, timelines, data format, functional equivalence documentation
  • Egress fee disclosure added to contract terms

Functional Equivalence Documentation

  • Documentation of service architecture and configurations maintained and available to customers
  • Documentation enables customers (or their new provider) to replicate the service elsewhere

Section 4: B2B Data Sharing Arrangements

Existing Arrangements Review

  • All existing B2B data sharing agreements reviewed
  • FRAND (fair, reasonable, non-discriminatory) terms confirmed or negotiated
  • Purpose limitation clauses in place
  • No competing product development prohibition confirmed in agreements
  • No sub-licensing without authorisation confirmed in agreements

Trade Secret Assessment

  • Data elements for which trade secret protection is claimed are specifically identified
  • Trade secret positions documented with substantive justification
  • Non-trade-secret data remains accessible despite trade secret claims on specific elements

New Agreements

  • Template B2B data sharing agreement updated for Data Act compliance
  • Standard terms include: purpose, data scope, duration, restrictions, security obligations, termination provisions

Section 5: Governance and Documentation

  • Data Act compliance owner identified (legal, compliance, or product owner)
  • Data Act obligations mapped in records of processing activities or equivalent
  • Staff with relevant responsibilities trained on Data Act requirements
  • Process for handling user data access requests established
  • Process for handling user third-party sharing requests established
  • Data Act compliance reviewed annually or when product/service changes

Key Dates

DateRequirement
12 September 2025Full Data Act application — all IoT and cloud obligations apply
12 September 2027Egress fees for cloud switching must be eliminated entirely

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →