DataAct Ready

EU Data Act guides ·

The EU Data Act Compliance Checklist: 5 Documents Most Companies Need

Data Act compliance for a typical SaaS or device company condenses into five concrete deliverables. Here is the checklist, in build order, with what each document must contain.

Strip away the recitals and the Data Act's demands on a typical SaaS or device company condense into a short list of artifacts. If you can produce these five documents, you have covered the ground most enforcement questions and customer requests will touch.

1. A scoping memo and 30-day action plan

One page that states which chapters apply to you (connected product? related service? data processing service? none?), your key gaps, and dated next steps. This is the document that turns "we should look into the Data Act" into an actual plan, and the first thing to show a nervous enterprise customer or an investor running diligence.

2. A cloud switching addendum

For anyone providing SaaS/cloud to EU customers. It must give customers: switching initiation with at most two months' notice, a 30-day transition period, export of their data in a structured machine-readable format, reasonable assistance, and post-switch erasure, and it should already anticipate the withdrawal of switching charges due 12 January 2027.

3. A user data access policy

For connected products and related services: how a user requests the data their product generates, in what format and timeframe you deliver it, how third-party sharing requests are handled, and how trade secrets are protected procedurally rather than by blanket refusal.

4. An export documentation page

A public page describing what data a customer can take out, in which formats, and by what process. It satisfies the transparency duties around switching and porting, and it converts: enterprise buyers read exit documentation before signing, and "leave anytime, here is exactly how" is a stronger close than any lock-in.

5. An unfair-terms contract audit

Your standard MSA screened clause-by-clause against Article 13's blacklist and grey list, with redraft notes for the failures. Cheap to run, and it removes the scenario where a customer's lawyer deletes your liability clause for you in a dispute.

Device makers add one more

Manufacturers shipping hardware into the EU also need an access-by-design engineering review for products placed on the market after 12 September 2026, an interface plan or a documented feasibility justification.

Build order

Scope first (memo), then contract (addendum + audit), then operations (access policy + export page). Most teams can complete the documentation layer in a focused week; only the engineering items stretch longer.

Our free assessment generates your scoping picture in three minutes, and the €49 pack contains adaptable templates for all five documents, pre-filled from your assessment answers.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.