Compliance · Alt Service

For your connected products, a Data Act-ready framework.

EU Data Act scope analysis and compliance: designing access to connected-product data, sharing processes, contract revision and cloud-switching rules.

Parent ServiceCompliance
Sub-service Dossier
Overview

Are you in scope?

The Data Act covers companies that offer a connected product (vehicle, machine, device) or a related digital service on the EU market — even if they are established in Türkiye. The first step is an honest scope analysis: which of your products generate data, who can access that data today, and what happens if a user in the EU requests it?

Data Act Compliance
01

The four work packages of compliance

a)

Access design

the way product data is made available to the user (in-product access or on request) and the authentication process.

b)

Sharing process

transfer to third parties chosen by the user on fair, reasonable and non-discriminatory terms; the request-response protocol.

c)

Contract revision

embedding data clauses into sales, service and cloud contracts; weeding out unfair terms that cannot be imposed on SMEs.

d)

Trade-secret strategy

an inventory of trade-secret areas and balancing sharing against a set of protective measures.

02

The opportunity side

The Data Act is not only a burden: it opens new room for access to the independent service market, data collaborations and licensing models. The manufacturer that achieves compliance early becomes the party able to tell its customer, “you can take your data.”

How We Work

From scope opinion to go-live

The Regulation ((EU) 2023/2854) has applied since September 2025, and we run the work in five steps against that calendar. Product-data inventory: in a workshop with your technical team, we map which product generates which data. Scope opinion: which product is a “connected product” and which service a “related service” is fixed in a reasoned legal opinion. Design: the user access channel and fair, reasonable and non-discriminatory terms for third-party sharing are structured. Contract revision and trade-secret protection: your existing set is updated within the contract management discipline. Go-live: a request-logging and response routine is tied into operations. Deliverables: the scope matrix, revised templates and the user-request procedure. Typical clients are machinery and automotive suppliers delivering to German OEMs, connected-appliance and IoT manufacturers, and fleet or telematics providers — the early mover sits down to these negotiations with its own template, within the single framework of our Data focus.

Who Engages Us

Who typically comes to us

The service is used most by machinery and automotive suppliers shipping parts and systems to German OEMs, by manufacturers of connected appliances and IoT devices, and by providers of fleet, telematics and smart farming services. The pressure arrives from two directions at once: the end user in the EU asks the manufacturer for access to the data, while the OEM customer asks its supplier for contractual undertakings to support its own Data Act compliance. A manufacturer that prepares early comes to those negotiations with its own template, and the terms are then not set by the other side’s paper. The whole data strategy, from classification through to licensing, is run inside a single frame in our Data focus area.

Why Köksal?

We are by your side for Data Act Compliance

Our Data & Cybersecurity Desk maps the scope product by product with your technical teams and updates the contract set together with your GDPR/KVKK framework in a single architecture. For a detailed analysis, see our Data Act article.

Köksal team multidisciplinary work
03

Other Applications of This Service

Compliance — our other specialised solutions in this area.

Compliance — back to the parent service
04

Matter Connections

The focus areas, practice areas, desks and legislation connected with this sub-service.

06

The Team Delivering This Service

With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

07

Related Publications

Fresh perspectives and guides from the Knowledge Centre.

No — what is decisive is that the product is placed on the EU market; where the data is held does not remove the scope, it only adds a transfer layer.

The third party chosen by the user may be a competitor; however, the Regulation places limits on using the data to develop a competing product, and contractual protection can be structured.

With a product-data inventory and a “request scenario drill”: what would happen if an access request came in today? The gaps become visible from there.

Service

Data Act Compliance — get the right legal support.

Let us identify the right solution together, drawing on our experience in Türkiye and the DACH region.