Data Act Readiness Assessment
Receive a quote tailored to your needs
The EU Data Act (Regulation (EU) 2023/2854) introduces new requirements for manufacturers of connected products. It gives users the right to access the data their products generate and to share that data with a third party of their choice. From 12 September 2026, newly placed connected products must be designed so that this data is accessible by default.
While many organisations view the Data Act primarily as a legal or privacy matter, it also creates a significant product design obligation. For manufacturers, compliance must be embedded into product development, alongside requirements arising from legislation such as the Cyber Resilience Act (CRA) and the Radio Equipment Directive (RED).
Timeline
12 September 2025
Data Act applies. Access, sharing and contract duties live now.
12 September 2026
Design-by-default duty for newly placed connected products.
11 December 2027
CRA fully applicable. RED cyber delegated act repealed.
What is it and what it includes?
The assessment provides a structured evaluation of your readiness to meet the Act's requirements for data access, data sharing, interoperability, and contractual transparency.
The service consists of three key elements:
- Applicability Assessment
Kiwa determines whether your product qualifies as a connected product or related service under the EU Data Act, identifies the relevant obligations, and assesses whether any exemptions apply. This provides a clear understanding of the regulatory requirements that affect your organization. - Gap Assessment
Our experts review your current product design, technical documentation, data governance practices, and contractual arrangements against the requirements of the Data Act. The assessment identifies compliance gaps related to data access, disclosure, sharing, portability, and interoperability, highlighting areas that require attention. - Implications Report and Recommendations
You receive a detailed report outlining what needs to change, the priority of actions, and the expected implementation timeline. The report explains how Data Act obligations interact with other product-related regulatory requirements, such as the Cyber Resilience Act (CRA) and Radio Equipment Directive (RED), enabling a coordinated compliance approach. All findings and recommendations are fully documented to support decision-making and implementation planning. The assessment concludes with practical recommendations to help your organization implement secure, transparent, and compliant data-sharing practices while preparing products and processes for the applicable regulatory deadlines.
Who is it for?
This service is designed for manufacturers, service providers, and organizations operating connected products or data processing services within the EU. It is especially relevant for businesses in IoT, cloud services, industrial equipment, and sectors impacted by the Data Act’s requirements.
While some exemptions exist for smaller organisations, most manufacturers placing connected products on the EU market will need to address both data-sharing requirements and product design obligations under the regulation.
Benefits of the service
- Identify and address compliance gaps
- Enhance data security, transparency, and user rights
- Facilitate seamless data sharing and interoperability
- Reduce legal and operational risks associated with non-compliance
- Improve stakeholder trust and competitive positioning
- Access expert guidance for adapting to evolving EU digital regulations
- Support for fair contract terms and efficient cloud switching
Why choose Kiwa?
Kiwa offers independent, trusted expertise in regulatory compliance and digital transformation. With extensive experience in data governance and EU legislation, Kiwa provides clear, actionable insights tailored to your business. The assessment is delivered by professionals who understand the complexities of the Data Act and its impact across industries.
Kiwa’s approach is thorough, customer-focused, and aligned with best practices, ensuring your organization is ready for upcoming requirements and future-proofed against regulatory changes.
FAQs
What is the EU Data Act and who does it affect?
The EU Data Act is a regulation that sets rules for fair access, sharing, and use of data generated by connected products and services. It applies to manufacturers, service providers, and organizations operating in the EU market.
How can Kiwa help my organization comply with the Data Act?
Kiwa’s assessment identifies compliance gaps, provides practical recommendations, and supports implementation of secure and transparent data management practices tailored to your business.
What are the main risks of non-compliance?
Non-compliance can lead to legal penalties, operational disruptions, and loss of stakeholder trust. Early assessment helps mitigate these risks and ensures readiness for regulatory deadlines.
When should organizations start preparing for the Data Act?
Preparation should begin as soon as possible, as most provisions apply from September 2025. Early action ensures smooth transition and compliance.