For your connected products, a Data Act-ready framework.
EU Data Act scope analysis and compliance: designing access to connected-product data, sharing processes, contract revision and cloud-switching rules.
Are you in scope?
The Data Act covers companies that offer a connected product (vehicle, machine, device) or a related digital service on the EU market — even if they are established in Türkiye. The first step is an honest scope analysis: which of your products generate data, who can access that data today, and what happens if a user in the EU requests it?

The four work packages of compliance
Access design
the way product data is made available to the user (in-product access or on request) and the authentication process.
Sharing process
transfer to third parties chosen by the user on fair, reasonable and non-discriminatory terms; the request-response protocol.
Contract revision
embedding data clauses into sales, service and cloud contracts; weeding out unfair terms that cannot be imposed on SMEs.
Trade-secret strategy
an inventory of trade-secret areas and balancing sharing against a set of protective measures.
The opportunity side
The Data Act is not only a burden: it opens new room for access to the independent service market, data collaborations and licensing models. The manufacturer that achieves compliance early becomes the party able to tell its customer, “you can take your data.”
From scope opinion to go-live
The Regulation ((EU) 2023/2854) has applied since September 2025, and we run the work in five steps against that calendar. Product-data inventory: in a workshop with your technical team, we map which product generates which data. Scope opinion: which product is a “connected product” and which service a “related service” is fixed in a reasoned legal opinion. Design: the user access channel and fair, reasonable and non-discriminatory terms for third-party sharing are structured. Contract revision and trade-secret protection: your existing set is updated within the contract management discipline. Go-live: a request-logging and response routine is tied into operations. Deliverables: the scope matrix, revised templates and the user-request procedure. Typical clients are machinery and automotive suppliers delivering to German OEMs, connected-appliance and IoT manufacturers, and fleet or telematics providers — the early mover sits down to these negotiations with its own template, within the single framework of our Data focus.
Who typically comes to us
The service is used most by machinery and automotive suppliers shipping parts and systems to German OEMs, by manufacturers of connected appliances and IoT devices, and by providers of fleet, telematics and smart farming services. The pressure arrives from two directions at once: the end user in the EU asks the manufacturer for access to the data, while the OEM customer asks its supplier for contractual undertakings to support its own Data Act compliance. A manufacturer that prepares early comes to those negotiations with its own template, and the terms are then not set by the other side’s paper. The whole data strategy, from classification through to licensing, is run inside a single frame in our Data focus area.
We are by your side for Data Act Compliance
Our Data & Cybersecurity Desk maps the scope product by product with your technical teams and updates the contract set together with your GDPR/KVKK framework in a single architecture. For a detailed analysis, see our Data Act article.

Other Applications of This Service
Compliance — our other specialised solutions in this area.
Matter Connections
The focus areas, practice areas, desks and legislation connected with this sub-service.
Our Matters in This Service
The anonymised examples of our work that relate to this service.
Uninterrupted legal counsel for a multinational supplier
Retainer-based support across day-to-day commercial operations, contract management and compliance processes.
Review the matter →ESG & ComplianceSupply chain due diligence (LkSG) compliance programme
Risk assessment and compliance architecture for a Turkish supplier network under the German LkSG.
Review the matter →Market AccessEstablishing a distribution network in Türkiye
Designing a market entry strategy, distributorship agreements and competition compliance.
Review the matter →The Team Delivering This Service
With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

Mehmet Köksal
Founder and Managing PartnerIstanbul · Berlin · KyreniaProfile →
Kübra Köksal-Yılmaz
PartnerBerlin · İstanbulProfile →
Gül Efem
Of CounselİstanbulProfile →
Sven Köksal
Legal EngineerBerlin · İstanbulProfile →
Gökçe Yıldırım
Of CounselİstanbulProfile →Related Publications
Fresh perspectives and guides from the Knowledge Centre.
No — what is decisive is that the product is placed on the EU market; where the data is held does not remove the scope, it only adds a transfer layer.
The third party chosen by the user may be a competitor; however, the Regulation places limits on using the data to develop a competing product, and contractual protection can be structured.
With a product-data inventory and a “request scenario drill”: what would happen if an access request came in today? The gaps become visible from there.
Data Act Compliance — get the right legal support.
Let us identify the right solution together, drawing on our experience in Türkiye and the DACH region.
