Connected products combine technical, organisational, commercial and contractual Data Act tasks. A shared work status connects responsibilities, data access, information duties, protection boundaries and evidence.
Implementing the EU Data Act for Connected Products
Work through the data inventory, roles, data access, requests, contracts and protection checks for your concrete product/service case and keep the resulting evidence in a traceable work status.
- Map data & roles structure the product/service case, relevant roles, generated data and open classification points.
- Prepare data access & requests work through Access by Design, technical access, pre-contractual information and request readiness.
- Protect data & preserve evidence integrate security, trade secrets, personal-data interfaces, contracts, release review and reassessment.
Turn EU Data Act requirements into a concrete product/service work status
The Practice Kit is designed for organisations working with connected products and related services, including machinery, equipment and IoT-enabled products. It helps you structure the concrete case from scope and roles through the data inventory, Access by Design, technical data access, pre-contractual information, user and third-party requests, contract topics, protection checks, evidence and reassessment.
The principal legal reference is Regulation (EU) 2023/2854 (EU Data Act). The regulation has applied since 12 September 2025; product- or obligation-specific transition and application provisions must still be assessed for the concrete case. The package's professional baseline is 23 August 2026.
A practical path from scope to evidence
Connect your product or service case in a traceable work status, follow the eight-step workflow or use individual work tools, and keep open specialist reviews, actions and evidence visible.
Work on one concrete product/service case
Keep roles, product/service context, generated data, access paths, information duties, contracts, risks and decisions connected.
Use the full workflow or individual work tools
Follow the guided eight-step path, or use individual work tools when a specific implementation task is already known.
Start with a blank system and compare with a worked case
The NordWerk sample case shows how the components can be used together without replacing your own product, data and role assessment.
Make Access by Design actionable
Translate the legal requirement into product and engineering questions that can be assigned, evidenced and reviewed before release milestones.
Keep protection boundaries visible
Integrate security, trade-secret and personal-data specialist checks instead of treating data access as an isolated technical interface task.
Prepare for requests and reassessment
Use structured case files, communication building blocks, contract mapping, release review and evidence so that later requests or product changes can be handled from a documented baseline.
A prepared structure for your own implementation
The data inventory, roles, Access by Design, access, requests, protection checks, contracts and evidence are prepared as a connected workflow for your product or service case.
Reduce preparation effort
Prepared processes, work tools and evidence structures help reduce internal research and setup effort.
Use your internal expertise
Use your team's existing expertise within a structured working process.
Bring in specialist expertise where needed
Individual legal, technical and specialist questions remain with the responsible functions. External support can focus on the points that require an individual review or decision.
Tasks & requirements
Which products, related services, roles and special cases are relevant?
Regulation (EU) 2023/2854, including Articles 1 and 2, Chapter II and Article 7 where applicable.
Which products, related services, roles and special cases are relevant?
Regulation (EU) 2023/2854, including Articles 1 and 2, Chapter II and Article 7 where applicable.Structure the product/service case, relevant actors, role assumptions and open scope questions before assigning implementation tasks.
Work tools: Scope and Roles Check; Data Act Navigator; Data Act Cockpit
Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.
What does Access by Design mean for our product before the next release milestone?
Article 3(1), read with the applicable access and protection framework.
What does Access by Design mean for our product before the next release milestone?
Article 3(1), read with the applicable access and protection framework.Translate the requirement into technical access planning, responsibilities, evidence and release-review questions.
Work tools: Access by Design Requirements Profile; Technical Data Access Planning
Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.
Which pre-contractual information is required for the connected product and related service?
Article 3(2) and (3).
Which pre-contractual information is required for the connected product and related service?
Article 3(2) and (3).Prepare the product- and service-specific information in a controlled working format and route unresolved legal questions for specialist review.
Work tools: Pre-contractual Product / Service Information
Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.
How do we provide data to users and, on a valid request, to third parties?
Articles 4–6, depending on the concrete role and request scenario.
How do we provide data to users and, on a valid request, to third parties?
Articles 4–6, depending on the concrete role and request scenario.Document the access path, request case, relevant data, recipient and decision/evidence status.
Work tools: Technical Data Access Planning; Request Readiness and User / Third-Party Request File
Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.
How do security, trade secrets and personal data constrain data access?
the relevant protection provisions of the Data Act, including Articles 4–8 where applicable, and the GDPR interface for personal data.
How do security, trade secrets and personal data constrain data access?
the relevant protection provisions of the Data Act, including Articles 4–8 where applicable, and the GDPR interface for personal data.Use dedicated protection checks and specialist routing instead of treating access as an unconditional disclosure obligation.
Work tools: Security / Trade-Secret / Personal-Data Review
Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.
Which contracts, model contractual terms and own-use questions need to be addressed?
the applicable Data Act contract framework, including Chapters III and IV and relevant provisions such as Articles 8–13.
Which contracts, model contractual terms and own-use questions need to be addressed?
the applicable Data Act contract framework, including Chapters III and IV and relevant provisions such as Articles 8–13.Map contractual relationships, identify open clauses and use current EU model contractual terms where they are relevant to the concrete relationship.
Work tools: Contract / MCT Mapping
Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.
Which competent authority or specialist interface is relevant in the applicable EU Member State for notifications, complaints or personal-data issues?
applicable national enforcement and competence rules, together with the EU Data Act and GDPR allocation of responsibilities.
Which competent authority or specialist interface is relevant in the applicable EU Member State for notifications, complaints or personal-data issues?
applicable national enforcement and competence rules, together with the EU Data Act and GDPR allocation of responsibilities.Determine the Member State and issue-specific authority/interface for the concrete case. Do not assume a German authority or German implementing provision applies EU-wide.
Work tools: Scope and Roles Check; Request Communication
Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.
How do we close gaps, approve the implementation and retain evidence for reassessment?
Practice Kit working method; no separate regulatory obligation.
How do we close gaps, approve the implementation and retain evidence for reassessment?
Practice Kit working method; no separate regulatory obligation.Use the design/release review, evidence structure, action tracking and reassessment triggers to preserve a traceable decision status for later product, service or legal changes.
Work tools: Design / Release Review; Data Act Cockpit
Outcome / evidence: A documented case status with responsibilities, open questions and evidence references.
What is included
Coordinated work tools for structured independent implementation.
START HERE and practical implementation guidance
PDF · DOCX · XLSXA controlled entry point plus practical guidance for using the package in a real connected-product or related-service case.
Central EU Data Act Cockpit with 15 functional sheets
XLSXA connected working view for scope, data, tasks, evidence, decisions, gaps and follow-up.
Guided EU Data Act Navigator
HTMLA browser-based guidance tool that helps route the product/service case through the relevant working questions without replacing specialist judgement.
9 editable Word work tools
DOCXWork tools covering role/scope, Access by Design requirements, technical data-access planning, product/service information, data-access and third-party request files, security/trade-secret review, contract/MCT mapping, request communication and design/release review evidence.
Worked NordWerk sample case
PDF · DOCX · XLSXA populated example case including the cockpit, work tools and selected pre-contractual information outputs for orientation.
Data Act Work & Review Assistant
MD · PDFPrompt-based support for structured work and review steps. It does not make legal, security, trade-secret or personal-data decisions.
Explore the work tools




Eight steps from product case to evidence
Work through EU Data Act tasks for connected products and related services and document the evidence.
Define the case & roles
Map product, service & data
Determine access requirements
Plan technical access
Prepare information, contracts & request readiness
Review protection boundaries
Close gaps & run the release review
Preserve evidence & reassess
Start with your first case
Open START HERE, create a working copy and follow the next steps for your own case.
1. Create a working copy of the central cockpit and assign a case/product identifier.
2. Record the connected product, related service and current role assumptions.
3. Build the first data inventory from the actual product/service architecture.
4. Use the Navigator to identify the next working modules and unresolved specialist questions.
5. Assign owners for Access by Design, technical access, information, request, contract and protection tasks.
6. Use the NordWerk sample only as orientation; document your own facts and decisions independently.
Designed for
- manufacturers of connected products, machinery and equipment;
- providers of related services;
- product management, engineering, IT/data and security teams;
- legal, compliance, privacy and contract functions coordinating EU Data Act implementation;
- organisations that need a traceable working and evidence structure for concrete product/service cases.
Prerequisites
- a concrete connected product and/or related service;
- basic knowledge of the product architecture and generated/available data;
- responsible product, technical and commercial owners;
- access to legal, privacy, security and trade-secret specialists when the case requires specialist judgement.
Not included
- legal advice or a binding determination of scope, role or entitlement;
- a guarantee that a specific technical data-access solution is sufficient;
- privacy, cybersecurity or trade-secret specialist approval;
- contract negotiation or authority representation;
- automatic ongoing regulatory monitoring unless separately agreed.
Further Practice Kits
Price, licence, support and updates
Licence
The supplied licence terms govern internal organisational use, editing and permitted use of completed outputs. The original product package, blank template library and source files may not be redistributed outside the licensed scope.
Support
Support covers download/file access, package structure and technical product issues. It does not include individual legal, privacy, security, trade-secret or contract advice unless separately agreed.
Updates
Updates are included only where the product or checkout explicitly states that they are included. Before applying the work to a live product/release, revalidate legal dates, authority routes, model terms and other time-dependent references that are material to the concrete case.
Questions before purchase
Key questions about use, scope and boundaries before purchase.
Does the Practice Kit provide legal advice or guarantee Data Act compliance?+
No. It provides a structured implementation and evidence system. Binding legal interpretation and specialist decisions remain with the responsible functions.
Do we need to have received a data-access request before using it?+
No. The kit is also designed for proactive readiness: scope, data inventory, Access by Design, pre-contractual information, request handling, contracts and protection checks can be prepared before the first request arrives.
Can individual work tools be used independently?+
Yes. You can follow the full eight-step workflow or use an individual work tool when a specific implementation task is already known. Keep cross-references to the overall case where decisions depend on other modules.
Does the AI assistant decide legal, security or trade-secret questions?+
No. It supports structured work and review. Specialist judgement remains mandatory where the case requires it.
Does the package cover connected products and related services?+
Yes. The work structure is designed around concrete connected-product and related-service cases and the data/access relationships relevant to them.
Is Access by Design covered?+
Yes. The package includes a dedicated requirements profile and technical data-access planning so that product/design tasks can be prepared, assigned and evidenced.
Are pre-contractual information duties covered?+
Yes. The package includes work on product/service information and worked example outputs. Your concrete wording and legal applicability still require case-specific review.
Does the English EU version use German authorities?+
No. The EN_EU edition is Member-State neutral. The competent national authority or specialist interface must be determined for the applicable EU Member State and issue; German authorities are not presented as EU-wide defaults.
Does it include the EU model contractual terms?+
The kit supports contract/MCT mapping and use of the relevant current EU model contractual material. Always verify the current official version and applicability for the concrete relationship.
Are later product or legal updates automatically included?+
Only if the product or checkout explicitly states that updates are included. Use the reassessment path when facts, technical design, contracts or legal sources change.
Implementing the EU Data Act for Connected Products
Use the Practice Kit to connect roles, data, Access by Design, requests, contracts, protection checks, actions and evidence instead of building the implementation structure from scratch.
