1. Identify your connected products and services

  • List any connected products you manufacture, sell, lease or operate.
  • Identify any related digital services, apps, dashboards or monitoring tools.
  • Map what data is generated by each product or service.
  • Separate personal data, non-personal data, machine data, sensor data and usage data where possible.

2. Review user data-access rights

  • Check whether users can access data generated by their use of a connected product.
  • Review whether users can ask for that data to be shared with a third party.
  • Document how requests will be received, verified and handled.
  • Check whether data can be made available securely and in a usable format.

3. Review B2B data-sharing contracts

  • Identify contracts that restrict access to or use of generated data.
  • Check whether data-sharing terms are fair, transparent and proportionate.
  • Review compensation or pricing mechanisms for making data available.
  • Pay particular attention to contracts involving SMEs.

4. Review cloud and data-processing services

  • Check whether you provide cloud, SaaS, hosting, platform or data-processing services.
  • Review customer switching and exit processes.
  • Check whether technical, contractual or commercial barriers make switching difficult.
  • Document export formats, migration support and termination processes.

5. Prepare internal processes

  • Assign ownership for Data Act requests inside your business.
  • Create a simple request-handling workflow.
  • Review security, confidentiality and trade-secret safeguards.
  • Prepare standard responses for customers, business users and third parties.
Important: This checklist is for general information only. It is not legal advice. Businesses with potential exposure should seek legal or compliance advice.

Want a personalised gap analysis?

Answer a short set of questions and get a PDF report tailored to your business — free during beta.

Start free assessment