Agent skill · Security

eu-data-act-compliance

Assess compliance obligations under the EU Data Act (Regulation (EU) 2023/2854) for connected products, IoT devices, data sharing, cloud switching, B2B fairness, B2G data access, dispute resolution, and international data transfers. Covers scope assessment (manufacturer, data holder, data recipient roles), user data access rights, pre-sale transparency, unfair contract terms, public authority data requests, cloud portability, dispute settlement mechanisms, international transfer restrictions, access-by-design obligations, trade secret protection, and cross-regulation mapping with GDPR, AI Act,

lawve-aigithub.com/lawve-aiGitHub ↗
claude-codeNOASSERTION
Install
npx skills add lawve-ai/awesome-legal-skills --skill eu-data-act-compliance-assessment-werner-plutat --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 11
SKILL.md size: 34 KB
Bundled scripts: none
Path: skills/eu-data-act-compliance-assessment-werner-plutat/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 618
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

Assesses compliance obligations under the EU Data Act for connected products, data sharing, cloud services, and B2G data requests. It guides role identification (manufacturer, data holder, data recipient, etc.), outlines data access rights and third-party sharing, pre-sale transparency obligations, unfair contract terms analysis, and B2G request procedures. It emphasizes that the workflow is a structured compliance process and not legal advice, and it highlights relevant dates and cross-regulation considerations.

How it works

Follow the Data Act Compliance Workflow in sequence:

  • Step 1 - Scope Assessment: determine Data Act roles (manufacturer, related service provider, data holder, user, data recipient, data processing service provider, public body) and note critical exclusions; answer role-determining questions.
  • Step 1b - Data Scope Triage: classify data type, availability, sensitivity, and sector constraints.
  • Step 2 - Connected Product Data Access Rights (Chapters II-III): if you are a data holder, enable user access and third-party sharing; enforce access rights (Article 4) with structure, speed, format, and charging considerations; address GDPR if personal data is involved; outline third-party sharing rights (Article 5-7) and grounds for refusals.
  • Step 3 - Pre-Sale Transparency (Article 3): for manufacturers, disclose data-generation details, accessibility, third-party access, and any fees before contract binding.
  • Step 4 - Unfair Contract Terms in B2B Data Sharing (Chapter IV): evaluate terms against Article 13’s two-tier test and consider Model Contractual Terms (MCTs) while recognizing they are non-binding benchmarks; review termination, liability, and remedies.
  • Step 5 - B2G Data Sharing: Public Authority Requests (Chapter V): apply emergency (Article 15) or exceptional-need (Article 17) grounds; respond without undue delay; ensure proportionality and trade secrets protections; disclose refusals with reasons.
  • Step 6 - Cloud Switching and Portability (Chapters VI-VII): for data processing service providers, ensure customer switching rights, portability, data export in machine-readable formats, interoperability, and cross-border transfer considerations (Article 32).

When to use it

Use when assessing Data Act obligations, designing connected products, drafting data sharing contracts, responding to B2G requests, planning cloud switching capabilities, or evaluating dispute resolution options.

What it can touch

Tools: claude-code. It references technical interfaces like APIs, data formats, and portability requirements, and discusses data access channels and reporting obligations.

Caveats

The workflow emphasizes that Data Act obligations are context-dependent and interact with GDPR and sector-specific rules. Assumptions and contested interpretations should be explicitly identified. It clarifies dates for when requirements apply and notes that this is a compliance workflow, not legal judgment.

From the SKILL.md

# EU Data Act Compliance Assessment Assess your organization's obligations under the EU Data Act (Regulation (EU) 2023/2854) for connected products, data sharing, cloud services, and B2G data requests. **Important:** This skill supports a structured legal-compliance workflow. It does **not** replace legal judgment. Data Act obligations are context-dependent and interact with GDPR, sector regulations, and national implementation measures. Always identify assumptions, open questions, and contested interpretations explicitly. **Key Dates:** - **Entered into force:** 11 January 2024 - **Main requirements apply from:** 12 September 2025 - **Access-by-design obligations apply from:** 12 September 2026 - **Cloud switching fee phase-out:** 12 January 2027 ## Data Act Compliance Workflow Follow this sequence in order. Do not skip the scope assessment. ### Step 1 - Scope Assessment: Which Data Act role(s) does your organization have? The Data Act imposes different obligations depending on your role in the data ecosystem. Assess whether your organization is: 1. **Manufacturer of a connected product** - entity placing a connected product on the market under its name or trademark under the Regu

What's inside
Steps it walks through
  1. Data Act Compliance Workflow
  2. Step 1 - Scope Assessment: Which Data Act role(s) does your organization have?
  3. Step 1b - Data Scope Triage
  4. Step 2 - Connected Product Data Access Rights (Chapters II-III)
  5. Step 3 - Pre-Sale Transparency (Article 3)
  6. Step 4 - Unfair Contract Terms in B2B Data Sharing Contracts (Chapter IV)
  7. Step 5 - B2G Data Sharing: Public Authority Requests (Chapter V)
  8. Step 6 - Cloud Switching and Portability (Chapters VI-VII)
  9. Step 7 - Trade Secret Protection (Articles 5(4), 6, 15(3))
  10. Step 8 - Dispute Resolution (Article 10)
  11. Step 9 - Smart Contracts for Automated Data Sharing (Chapter IX)
  12. Step 10 - Access-by-Design Obligations for New Products (from 12 September 2026)
  13. Step 11 - Cross-Regulation Mapping: GDPR, AI Act, CRA Interaction
  14. Step 12 - DACH-Specific Considerations
Ships with 10 files
  • LICENSE.txt
  • README.md
  • references/b2g-data-sharing.md
  • references/cloud-switching.md
  • references/cross-regulation-mapping.md
  • references/dach-specific.md
  • references/data-access-rights.md
  • references/scope-assessment.md
  • references/templates.md
  • references/unfair-terms-catalogue.md
More from awesome-legal-skills
All skills →
About this skill
What does the eu-data-act-compliance skill do?

Assess compliance obligations under the EU Data Act (Regulation (EU) 2023/2854) for connected products, IoT devices, data sharing, cloud switching, B2B fairness, B2G data access, dispute resolution, and international data transfers. Covers scope assessment (manufacturer, data holder, data recipient roles), user data access rights, pre-sale transparency, unfair contract terms, public authority data requests, cloud portability, dispute settlement mechanisms, international transfer restrictions, access-by-design obligations, trade secret protection, and cross-regulation mapping with GDPR, AI Act,

How do I install it?

Run `npx skills add lawve-ai/awesome-legal-skills --skill eu-data-act-compliance-assessment-werner-plutat --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going