What does the Data Act introduce?
The EU Data Act aims to end the locking of data at the manufacturer: for the data produced by connected products (vehicles, machines, devices) and related digital services, the user has a right of access and sharing. Since September 2025 the main obligations have been in force, and contractual practice is changing rapidly.
Practical guidance
The first step is a data-flow map: what data does your product generate, where is it stored, and who can access it? The contract revision is built on this map.
Let us analyse your Data Act scope
We scan your product portfolio and set up a contract and process suite that is ready for access requests.
Who is within scope?
Three groups stand out: those offering connected products or related services to the EU market (including manufacturers established in Türkiye), cloud and SaaS providers (switching rules), and industrial data users. Since scope is determined by the market in which the product is sold, the “we are not an EU company” defence does not work.
The access and sharing regime
The user can access the product data and can request that this data be shared with a third party of their choice (e.g., an independent service provider, an analytics provider). The sharing conditions are established on fair, reasonable, and non-discriminatory principles. Trade secrets are protected; however, the trade secret rationale cannot serve as a basis for a categorical refusal of access — the balance is struck by technical and contractual measures.
Impact on contracts
Sales, service, and cloud contracts must be updated in three directions: creating data access addenda, weeding out unfair data terms unilaterally imposed on an enterprise — the rule is not limited to SMEs, and building switching periods and fee limits into cloud contracts. In product design, the “accessible by design” obligation has entered the engineering agenda for next-generation products.
Relationship with GDPR and KVKK
If the data set contains personal data, the Data Act does not replace data protection law; they apply together. The practical consequence for Turkish manufacturers: the process that handles access requests must be designed together with the KVKK/GDPR filter.
How to build a trade secret defence
The Data Act’s most debated balance is between data sharing and trade secret protection. The Regulation does not grant the secret holder a categorical right of refusal; it does grant the right to condition sharing on protective measures: confidentiality agreements, technical access limits, purpose-of-use restrictions, and, in exceptional cases, suspension of sharing. In practice, this requires three preparations: an inventory of which data fields carry the character of a secret, documentation of the secret-protection measures, and a standard response protocol for access requests. A trade secret defence is built not when the request arrives but when the product is designed — the work of our intellectual property team in this area begins precisely with this inventory.
An impact map by sector
Automotive and machinery manufacturers: independent service providers’ requests to access vehicle and machine data; warranty and liability provisions need to be rebalanced. Energy and IoT-based services: the regime for sharing meter and sensor data with the customer and with third parties. Logistics: the status of fleet telemetry in customer contracts. Software/SaaS: building cloud switching periods and data export formats into the contract — in the procurement negotiations of our Legal Tech focus area, these provisions are now a standard bargaining item. For Turkish brands expanding into the EU market via e-commerce as well, selling a connected product means direct entry into the scope of the Data Act.
The Köksal approach
Our Data focus area combines Data Act scope analysis with GDPR/KVKK compliance and data contract architecture into a single project. Our Data & Cybersecurity Desk speaks the same language as technical teams to build processes that handle access requests.
Conclusion
The Data Act has made data contracts part of the product. Early compliance both reduces enforcement risk and creates commercial opportunity in the market for independent service and data collaboration. This file should be on the 2026 agenda of every Turkish manufacturer that sells a connected product.


