Transparency
Assessment methodology
This page sets out exactly how the Data Act Checker assessment works, how each question maps to a specific provision of Regulation (EU) 2023/2854, and how the compliance score and findings in your report are derived.
Regulatory basis
The assessment is based on Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act), as published in the Official Journal of the European Union on 22 September 2023 (OJ L, 2023/2854).
The regulation became fully applicable on 12 September 2025. References to specific articles and recitals are to the regulation as published.
What the assessment covers
The assessment is structured around six obligation modules derived directly from the regulation's chapter structure. Each module is shown only where it is relevant to the company type identified in the profiling questions.
Module A — Product data access (Art. 3–4)
Covers design and pre-contract information duties for connected products and related services (Art. 3), and the user-access obligation where data are not directly accessible (Art. 4).
- Art. 3(1) — connected products and related services must be designed, manufactured and provided so relevant data and metadata are accessible by default, directly where relevant, securely and free of charge.
- Art. 3(2)–(3) — users must receive pre-contract information about the data generated and the arrangements for access, use and sharing.
- Art. 4(1) — where data are not directly accessible, the data holder must make readily available data and metadata accessible to the user without undue delay and free of charge.
Module B — Third-party data sharing (Art. 5–6, 9)
Covers the obligation to make data available to a third party chosen by the user (Art. 5), the third party's permitted use of those data (Art. 6), fair, reasonable and non-discriminatory terms (Art. 8), and compensation rules (Art. 9).
- Art. 5(1) — at the user's request, the data holder must make data available to a nominated third party without undue delay and in the same quality available to the data holder.
- Art. 6(1) — the third party may process the data only for the purposes and under the conditions agreed with the user, and must delete them when no longer necessary unless otherwise agreed.
- Art. 6(2)(e) — the recipient must not use the data to develop a connected product that competes with the product from which the data originate, or share them for that purpose.
- Art. 8(1) — mandatory business-to-business data-sharing terms must be fair, reasonable, non-discriminatory and transparent.
- Art. 9 — compensation must be non-discriminatory and reasonable; for SMEs and non-profit research organisations it is limited to the costs directly related to making the data available.
Module C — Contract fairness (Art. 13)
Covers unfair contractual terms concerning data access and use, or liability and remedies for breaches of data-related obligations, where a term has been unilaterally imposed on another enterprise (Art. 13).
- Art. 13(1) — an unfair term concerning data access or use, or liability and remedies for breach of data-related obligations, that is unilaterally imposed on an enterprise is not binding.
- Art. 13(3) — identifies contractual terms that are always considered unfair.
- Art. 13(4) — identifies contractual terms that are presumed to be unfair.
- Art. 13(5) — explains when a term is regarded as having been unilaterally imposed.
Module D — Cloud switching (Art. 23–31)
Covers removing obstacles to effective switching (Art. 23), minimum contractual switching terms (Art. 25), the withdrawal of switching charges (Art. 29), and technical switching and export requirements (Art. 30).
- Art. 23 — providers must remove commercial, technical, contractual and organisational obstacles to effective switching and to the simultaneous use of several data-processing services.
- Art. 25 — customer rights and provider obligations relating to switching must be set out clearly in a written contract.
- Art. 29(1)–(2) — switching charges are prohibited from 12 January 2027; before that date, reduced charges may not exceed costs directly linked to switching.
- Art. 30 — providers must meet technical switching duties, including assistance, export and interoperability measures appropriate to the service type.
Module E — Public-sector data access (Art. 14–22)
Covers requests by public-sector bodies, the Commission, the European Central Bank and Union bodies for data held by businesses where there is an exceptional need (Art. 14–22).
- Art. 14 — data holders must make data available in response to a duly justified request based on an exceptional need.
- Art. 15 — defines the circumstances in which an exceptional need exists.
- Art. 17 — sets requirements for requests, including that they be specific, transparent, proportionate and limited to what is necessary.
- Art. 18 — sets the data holder's obligations when responding and the grounds for declining or seeking modification of a request.
- Art. 19 — sets duties for the requesting public-sector or Union body, including purpose limitation, protection and deletion.
Module F — GDPR and personal data interface
The Data Act applies without prejudice to EU data-protection and privacy law. Where data include personal data, any access, use or sharing must also have an appropriate GDPR legal basis and comply with applicable GDPR duties.
- Data Act Art. 1 — the Regulation applies without prejudice to EU law on the protection of personal data and privacy, including the GDPR.
- GDPR Art. 6 — processing of personal data requires an appropriate lawful basis.
- GDPR Art. 35 — a Data Protection Impact Assessment may be required where processing is likely to result in a high risk to individuals.
Scoring methodology
Each applicable obligation is scored: Compliant (1.0), Partial (0.5), or Gap (0.0). The module score is the mean of all finding scores, expressed as a percentage. The overall readiness score is the mean of all applicable module scores.
Limitations
The assessment is based on self-reported responses. Data Act Checker does not verify responses, audit technical systems, or review contract documents. The report is a structured starting point for compliance review, not a substitute for legal advice.
Version
This methodology reflects Regulation (EU) 2023/2854, which has applied since 12 September 2025. Last reviewed: July 2026.
Official sources
Transparent by design
Every finding in your report cites the specific article it derives from. Get your free report today.