Regulation (EU) 2023/2854 – Data Act
4 minutes


Structured Assessment Logic (SAL) – Your Roadmap to Compliance
SAL Type X – Parameter-driven Regime – Non-NLF-based Parameter-driven Framework
Mapping of the Data Act (EU) 2023/2854
To implement the product-related requirements of the Data Act in a transparent and structured manner, the regulatory assessment process can be represented through a Structured Assessment Logic (SAL). This logic ensures that requirements relating to access to product data and related service data are systematically assessed and supported by documented evidence.
This SAL deliberately focuses on the product-related requirements of the Data Act, in particular the technical and functional requirements arising from Articles 3 and 4. It does not address the contractual provisions of the Data Act, especially Articles 8 to 13 governing the conditions for data sharing and the contractual relationships between data holders, users, and third parties.
The SAL comprises the following steps:
Product qualification – Does the product qualify as a Connected Product under the Data Act?
Identification of data to which access must be granted – Which Product Data and Related Service Data are generated and qualify as “readily available”?
Conformity assessment – Data access functionality (Articles 3, 4 and 5)
The assessment covers the design capability to ensure access to:
provision of data to the user,
provision of data to third parties upon the user's request,
in compliance with requirements on format, quality, security, and availability.
Information obligations – Provision of the information required under Article 3(2) and, where applicable, Article 3(3) of the Data Act
Technical documentation – Which records demonstrate compliance with the product-related requirements of the Data Act?
Note: SAL is not an end in itself. It provides a repeatable methodology that translates regulatory principles into a clear and structured assessment logic.
This diagram illustrates the SAL workflow visually:
Product qualification
↓
Identification of data subject to access obligations
↓
Design capability for enabling data access (users and third parties)
↓
Information obligations
↓
Technical documentation
Overview: Regulation (EU) 2023/2854
Number: (EU) 2023/2854
Title: Regulation on harmonised rules on fair access to and use of data (Data Act)
Publication: OJ L, 22.12.2023
Purpose: Establishing a legal framework for access to and use of data, particularly in relation to Connected Products and Related Services
Public interest: Data access, data portability, promotion of data-driven innovation
Guidance: Data Act FAQs
Scope
A Connected Product, as defined in Article 2(5) of the Data Act, is an item that:
obtains, generates, or collects data concerning its use or environment,
is capable of communicating such data electronically,
and whose primary function is not the processing or storage of data on behalf of third parties.
The key elements are therefore:
data generation or data collection,
communication capability,
and a primary function other than mere data processing.
Typical examples include:
connected household appliances,
intelligent machinery and equipment,
industrial IoT devices,
smart home products.
Accessible Data
The Data Act generally covers:
Product Data,
Related Service Data,
and the metadata necessary to interpret and use those data.
However, only data that are “readily available” to the data holder fall within the access obligations.
Overview Matrix: Which Data must be made available?
Assessment Criterion | Content |
Data Type | Product Data: data concerning the use, performance, or environment of the connected product. Related Service Data: data concerning user actions, interactions, or events connected with a related service. |
Availability ("readily available") | Data that the data holder obtains from the system without disproportionate effort, as a result of the product's actual technical design and operation. |
Level of Data Processing (Enrichment) | Covered: raw data, pre-processed data, and the metadata necessary to interpret and use those data. Not covered: derived, inferred, or highly enriched data resulting from complex analytics or algorithms. |
Special Cases / Delimitations | • No scope where data are never stored or made transferable (pure edge-processing scenarios). • Content itself (e.g. creative audio, video, or textual content) is generally not covered. • Personal data may be covered, but may only be accessed and used in compliance with applicable data protection legislation (GDPR). |
Conformity Assessment – Data access functionality (Articles 3, 4 and 5)
Connected products and related services must be designed in such a way that users can access the product data and related service data generated by their use of the product and, where applicable, request that such data be made available to a third party.
The Data Act does not prescribe a specific technical implementation model. Manufacturers may provide access through direct access mechanisms (Article 3) or through controlled access mechanisms (Article 4), provided that access to the relevant data is effectively ensured.
Direct access means that the user has the technical means to access, stream or download the data in question without having to request the data holder to do so. For instance, a connected product has a digital interface where the user has control over the access mechanism, controlling the interface and workflows, and where the user can directly extract data from the connected product.
Indirect access means that the connected product or related service is designed in such a way that the user is required to ask the data holder for access (i.e. an approval process). An example would be a web portal where the user can submit a request to access data.
Data must be made available in a secure, free of charge, comprehensive, structured, commonly used and machine-readable format.
For data made available pursuant to Articles 4 and 5, access must additionally be provided without undue delay and, where relevant and technically feasible, continuously and in real time.
See in more detail Section 22(a) of the Data Act FAQs - What technical and practical requirements must data holders meet concerning criteria such as data format, quality and latency?
Information Obligations
Before making a Connected Product available and, where applicable, before concluding a contract for the provision of a Related Service, the information required under Articles 3(2) and 3(3) of the Data Act must be provided.
This includes, in particular, information concerning:
the data generated,
the means by which data can be accessed,
the possibilities for data use,
and the involvement of Related Services.
Technical Documentation
Manufacturers should document:
which data are generated,
which data are considered “readily available”,
the chosen access architecture,
how the requirements relating to format, security, and availability are fulfilled,
and how user and third-party access are technically implemented.
Conclusion
The SAL for the Data Act translates the product-related requirements of the Regulation into a structured technical assessment logic. The focus is not on generating new data, but on ensuring that data which are technically available as a result of the product design can be made accessible to users and, upon their request, to third parties in the manner required by law. The central compliance question is therefore: Does the product design enable access to the technically available data?
You might also be interested in these articles:
© 2026 by Dr. Matthias K Bauer


