Classify connected products, related services and virtual assistants against the Data Act's scope tests.
EU Data Act Obligations for Connected Product Data Sharing and Cloud Switching
Learn to map data holder duties under the EU Data Act, draft compliant data-sharing terms and remove cloud switching barriers before the 2025 deadlines bite.
Course Overview
Regulation (EU) 2023/2854 rewrites who may see and reuse the data generated by connected products, from industrial sensors to smart appliances, and forces cloud providers to let customers leave without technical or contractual lock-in. Manufacturers, cloud providers and in-house counsel now face concrete drafting problems: who is the data holder, what must a user access request contain, which terms count as unfair under Article 13, and how quickly must egress charges disappear. This course works through the regulation clause by clause using the obligations that apply from September 2025, then turns each duty into a document: a data holder assessment, a data-sharing agreement template, a switching notice and an internal compliance file. Participants leave with a working method for classifying products and services against the Act's scope, negotiating FRAND-compatible pricing with counterparties, and coordinating obligations that overlap with the GDPR, the Digital Markets Act and trade secret protection. The approach is document-led throughout: every session produces a clause, checklist or register that can be adapted directly to a live compliance programme.
Expected Learning Outcomes
Determine when an organisation is a data holder, data recipient or user under the regulation.
Draft a data access request procedure that meets the timing and format requirements of Article 4.
Build data-sharing contract clauses covering FRAND pricing, liability and permitted use restrictions.
Screen third-party data contracts for terms the Act treats as unilaterally imposed and unfair.
Design a cloud switching plan that removes technical barriers and phases out egress charges on schedule.
Assemble a compliance file demonstrating coordination between the Data Act, GDPR and the Digital Markets Act.
Who Should Attend
In-house counsel advising manufacturers of connected devices and industrial IoT equipment.
Commercial lawyers negotiating cloud, hosting and data-sharing agreements.
Product and data governance managers responsible for connected product design decisions.
Cloud service provider legal and compliance staff handling switching requests.
Procurement leads drafting or reviewing B2B data access clauses.
Compliance officers coordinating overlapping EU digital regulation obligations.
Course Modules
Select any module to see its sessions and points.
01Scope, Roles and Data Access Rights under the EU Data Act
2 sessions · 8 points
Session 1Connected Products, Related Services and Who Counts as a Data Holder
- Apply the Data Act's definition of a connected product to physical goods that generate usage data through sensors or software.
- Distinguish a related service from a standalone digital service to decide whether its data falls inside the regulation's scope.
- Map internal roles against the Act's categories of data holder, user and data recipient before any contract is drafted.
- Identify exempt categories, including prototypes, safety-critical military systems and small enterprises below the size thresholds.
Session 2User Access Rights and Data Sharing Requests with Third Parties
- Design a request intake process that captures the identity checks Article 4 requires before releasing readily available data.
- Set response timelines and data formats that satisfy the without undue delay and machine-readable standards in the regulation.
- Build a decision tree for when a user may direct their data to a competing manufacturer or independent repairer.
- Draft refusal and restriction notices for the limited grounds permitted, such as trade secret protection or security risk.
02Drafting Data Sharing Agreements and Contractual Terms
2 sessions · 8 points
Session 1Mandatory Contract Terms, FRAND Pricing and Unfair Terms Screening
- Draft data-sharing agreement clauses that set fair, reasonable and non-discriminatory compensation for non-personal data.
- Calculate a defensible pricing methodology that a small or medium enterprise counterparty can query under Article 9.
- Screen incoming and outgoing contract terms against the Article 13 blacklist of terms treated as unilaterally imposed.
- Negotiate liability and indemnity clauses that allocate risk for misuse of shared data by a third-party recipient.
Session 2Trade Secrets, IP Protection and Technical Safeguards in Data Sharing
- Identify data sets that qualify for trade secret protection and the confidentiality undertakings needed before disclosure.
- Draft technical and organisational safeguard clauses required when sharing data that could reveal a trade secret.
- Reconcile Data Act sharing duties with existing intellectual property and database right clauses in supply contracts.
- Build a suspension procedure for a data holder to halt sharing where a recipient breaches confidentiality terms.
03Cloud and Edge Switching Obligations (Chapter VI)
2 sessions · 8 points
Session 1Removing Switching Barriers, Notice Periods and Egress Charge Phase-Out
- Audit existing cloud contracts for pre-commercial, commercial and technical barriers the Act requires providers to remove.
- Draft a maximum thirty-day switching notice clause compliant with the transitional period rules in Article 25.
- Schedule the phased removal of switching charges and egress fees against the regulation's compliance deadlines.
- Prepare customer communications explaining switching rights and the free assistance a provider must offer during transition.
Session 2Interoperability, Data Portability and Technical Switching Support
- Assess functional equivalence obligations for a destination provider receiving a customer's exported workload.
- Draft data export specifications covering structured formats, metadata and open interoperable standards where available.
- Coordinate switching support commitments with existing service level agreements and business continuity plans.
- Document residual technical limitations that justify a longer transition period under the Act's exceptions.
04Compliance Programme, Enforcement and Cross-Border Coordination
2 sessions · 8 points
Session 1Governance, Documentation and B2G Data Access for Public Bodies
- Build a governance file recording data classification decisions, access logs and refusal justifications for audits.
- Draft a public sector data request response procedure for the exceptional need provisions covering emergencies.
- Set internal escalation routes between product, legal and data protection teams for cross-cutting requests.
- Prepare board-level reporting that tracks compliance milestones against the regulation's staggered deadlines.
Session 2Enforcement Authorities, Penalties and Interaction with GDPR and DMA
- Identify the competent authority responsible for Data Act enforcement in each relevant member state.
- Model financial exposure under national penalty regimes adopted to implement the regulation's enforcement provisions.
- Reconcile Data Act personal data sharing duties with the lawful basis and data minimisation rules of the GDPR.
- Coordinate obligations for designated gatekeepers where Data Act sharing rights interact with Digital Markets Act duties.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
