Skip to content
  • Members Area
  • EU Data Act 2026:From Compliance Requirements to Implementation

EU Data Act 2026:
From Compliance Requirements to Implementation

 
Practical Lessons and Best Practices from EU Data Act Implementations

 

The EU Data Act is changing how organizations manage data generated by connected products and related services. This replay explains the regulation’s practical implications and how organizations can turn its requirements into an actionable implementation plan.
Nemko Digital AI experts Mónica Fernández and Bas Overtoom cover key Data Act concepts, data access models, and practical requirements such as authentication, machine-readable formats, timely delivery, and clear request processes. The session also highlights key milestones, including the requirement for new connected products to support data access from 12 September 2026, and explores the contractual, technical, and governance changes needed for compliant data sharing.

 

What You Will Learn

  • How to determine whether your connected products, related services, and data sets may be in scope.
  • The difference between direct and indirect data-access models, and the organizational and technical controls each may require.
  • What a practical data-sharing process should cover, from user authentication and approval to delivery, safeguards, and logging.
  • How to approach contract and terms-and-conditions reviews in light of Data Act requirements.
  • Why product scoping and a well-maintained data inventory are essential foundations for implementation.
  • How to structure a cross-functional roadmap spanning policies, processes, technology, commercial terms, and compliance evidence.

 


Key Takeaways

  • Scope and inventory data. Identify in-scope products, services, and data sets, including trade-secret and personal-data considerations.
  • Design for data access. Build data access into new connected products by 12 September 2026.
  • Choose an access model. Establish direct or indirect access with appropriate authentication, controls, security, and timely delivery.
  • Make data usable. Provide complete, structured, machine-readable formats such as JSON, CSV, or XML, with automated access where feasible.
  • Assign cross-functional ownership. Coordinate legal, product, engineering, data, privacy, cybersecurity, and commercial teams.
  • Review contracts and terms. Cover access rights, third-party sharing, permitted use, confidentiality, security, personal data, liability, pricing, and evidence.
  • Prepare for third-party requests. Define verification, safeguards, documentation, and data-delivery procedures.
  • Maintain ongoing compliance. Keep inventories, policies, processes, technical controls, contracts, and evidence updated as products and services evolve.


Ready to move forward with EU Data Act implementation?

Watch the replay to learn how Nemko Digital helps organizations translate EU Data Act requirements into practical action—from identifying connected products and product data in scope to designing data-access arrangements, updating contracts, and building effective governance.


Exclusive opportunity: apply for a complimentary EU Data Act implementation scoping session

Special Offer: Call with our EU Data Act Experts Now!

Ready to get started? Scan the QR code in the webinar materials or visit the link below to apply for your expert consultation:

CLICK HERE: https://digital.nemko.com/data-act-webinar-offer


EU Data Act 2026 Webinar Offer

 

Take control of your AI strategy today with Nemko Digital. 

 

 

Q&A Session Highlights

Can a service provider still use customer-generated data for aggregated statistics and product improvement? Yes. The Data Act does not prevent the use of data to generate insights or improve services, although other requirements, such as consent, may apply under other regulations.
Must a data holder share raw data, aggregated statistics, or both? Raw product-generated data and available metadata needed to interpret it. Processed, enriched, or aggregated statistics are outside the scope of the data access obligation discussed in the webinar.
What does “new connected products” mean—existing products or newly created products? Connected products placed on the market and put into service. The relevant consideration is when the product is placed on the market and put into service, rather than when it was developed.
Can Data Act requirements be communicated through terms and conditions or policies rather than an individual contract? Yes. Requirements can be addressed through terms and conditions and policies when they are appropriately incorporated into the contractual arrangement. A separate contract for every user is not required.
Can a user request data later if the data holder has already deleted it? No. If the data has been deleted and is no longer available to the data holder, it cannot be provided to the user.
Is a computer an IoT-connected device, and are app data included? Yes, computers and phones can be connected products. However, data from standalone apps, such as Instagram, is not necessarily considered data from a related service of the phone itself.

Book Your Free Consultation Call

Ready to elevate your AI product’s trustworthiness and compliance?
Don’t wait - connect with our experts for a free 15-minute consultation call to discuss how our trusted services can help your business thrive in today's competitive landscape.