Compliance Briefing — June 27, 2023
EU lawmakers reached a political agreement on the Data Act, obliging data-rich organisations to enable access, portability, and fairness controls across connected products and industrial data services.
Executive briefing: On June 27, 2023, the European Parliament and Council negotiators reached a political agreement on the Data Act, establishing new obligations for connected product manufacturers, industrial data intermediaries, and cloud service providers. The deal, announced by the European Commission, creates harmonised rules on data access, switching, interoperability, and safeguards for trade secrets when sharing usage data with business partners or public authorities.
Immediate compliance priorities
- Usage data inventory. Catalogue datasets generated by connected products and related services, classifying which business users, partners, or public bodies may request access under Articles 4–8.
- Contractual refresh. Update customer agreements and partner contracts to reflect mandated access rights, compensation terms, and trade-secret protections specified in the agreement.
- Cloud switching readiness. Prepare migration playbooks, APIs, and notice processes that allow customers to switch providers or port data within the timelines outlined for cloud and edge services.
Control alignment
- Data governance. Embed accountability for handling business user access requests, including validation, logging, and escalation of sensitive or critical infrastructure data requests.
- Security and confidentiality. Implement technical controls that balance mandated data sharing with protection of trade secrets and cybersecurity, aligning with Article 8 safeguards.
- Vendor management. Integrate Data Act requirements into procurement, ensuring downstream processors and cloud providers can satisfy interoperability and switching duties.
Enablement moves
- Launch cross-functional workshops to map business processes and digital twins affected by the new access rights and public-sector request mechanisms.
- Develop customer communications and transparency dashboards describing available data formats, APIs, and redress channels.
- Coordinate with industry alliances to monitor forthcoming delegated acts on interoperability standards and SMEs exemptions.
Sources
- European Commission: Political agreement on the Data Act
- Council of the EU: Council and Parliament strike deal on the Data Act
Zeph Tech supports industrial platform teams with data inventory mapping, portability testing, and regulator-ready governance controls for the EU Data Act.
Continue in the Compliance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Third-Party Risk Oversight Playbook — Zeph Tech
Operationalize OCC, Federal Reserve, EBA, and MAS outsourcing expectations with lifecycle controls, continuous monitoring, and board reporting.
-
Compliance Operations Control Room — Zeph Tech
Implement cross-border compliance operations that satisfy Sarbanes-Oxley, DOJ guidance, EU DORA, and MAS TRM requirements with verifiable evidence flows.
-
SOX Modernization Control Playbook — Zeph Tech
Modernize Sarbanes-Oxley (SOX) compliance by aligning PCAOB AS 2201, SEC management guidance, and COSO 2013 controls with data-driven testing, automation, and board reporting.




