Skip to content

Evidence request lists

EU Data Act

Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Data Act - B2B Data-Sharing Conditions and Unfair Terms (Ch III-IV)

DA-Art.10_11
Dispute settlement and technical protection measures (Articles 10-11)

Article 10 requires Member States to designate or certify dispute-settlement bodies that can resolve disputes between data holders and data recipients about Article 8 + Article 9 + Article 13 compliance. The dispute-settlement bodies operate alternatives to court, are independent and impartial, and decide within 90 days. Article 11 permits data holders to apply appropriate technical protection measures (TPMs) to prevent unauthorised access and use of data, but those TPMs must not impede the lawful Article 4 / Article 5 / Chapter III access regimes. Article 11(3) imposes sanctions on parties using data in breach of agreed conditions.

Artefacts an auditor will ask for
  • Internal procedure to engage Article 10 dispute-settlement bodies (sponsor of disputes / respondent)
  • TPM design review to ensure no impedance of Article 4/5 lawful access
  • Anti-misuse contractual sanctions for breach of agreed data-use conditions
Where this commonly fails
  • TPMs that block legitimate user access under Article 4
  • No anti-misuse clauses in data-sharing agreements
DA-Art.12
Scope of data-holder obligations under sectoral Union law (Article 12)

Article 12 confirms that obligations to make data available imposed by sectoral Union law (e.g. PSD2 access to payment-account data, AVMSD content-data obligations, the proposed European Health Data Space) operate alongside the Data Act FRAND/Article 8 baseline. The sectoral regime is the lex specialis but Article 8 + Article 9 + Article 10 + Article 11 provide horizontal floor requirements.

Artefacts an auditor will ask for
  • Inventory of sectoral Union-law data-access obligations applicable to the entity
  • Mapping showing how Article 8-11 horizontal floor is met for each sectoral obligation
DA-Art.13
Unfair contractual terms unilaterally imposed (Article 13)

Article 13 provides that a contractual term concerning the access to and use of data or the liability and remedies for the breach or termination of data-related obligations which has been unilaterally imposed by an enterprise on another enterprise shall not be binding on the latter enterprise if it is unfair. Article 13 sets a 'grey list' and 'black list' of presumptively unfair terms (excluding or limiting liability for damages, allowing unilateral changes, granting exclusive rights to derived insights without compensation, etc.). The protection applies regardless of the size of the imposing party.

Artefacts an auditor will ask for
  • Internal B2B-contract template review against Article 13(3) and (4) black/grey lists
  • Records of any Article 13 challenges raised by counterparties
  • Negotiation-history evidence demonstrating the term was not unilaterally imposed
Where this commonly fails
  • B2B data-sharing contracts containing Article 13(3) black-listed terms
  • No internal Article 13 review process despite issuing standardised data-sharing terms
DA-Art.8_9
B2B data-sharing conditions and compensation (Articles 8-9)

Article 8 requires that where a data holder is obliged under Union law to make data available to a data recipient, the data must be made available on FRAND (fair, reasonable, non-discriminatory) and transparent terms. Article 9 governs compensation: any compensation for making the data available must be reasonable, non-discriminatory, and where the data recipient is a micro / small / medium-sized enterprise or a not-for-profit research organisation, must not exceed the costs directly related to making the data available.

Artefacts an auditor will ask for
  • B2B data-sharing contract templates aligned with Article 8 FRAND requirements
  • Cost-based compensation model for SME / research recipients per Article 9
Where this commonly fails
  • Data-sharing terms that vary materially across similarly-situated recipients (non-discrimination breach)
  • Compensation above direct costs charged to SME / research recipients

Data Act - B2C/B2B Connected-Product Data Sharing (Ch II)

DA-Art.3
Obligation to make connected-product data accessible by design (Article 3)

Article 3 requires that connected products and related services be designed and manufactured in such a way that product data and related service data, including the relevant metadata necessary to interpret and use them, are, by default, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly accessible to the user. Article 3(2) sets the pre-contractual information that the seller / rentor / lessor of a connected product must provide to the user about the data the product is capable of generating.

Artefacts an auditor will ask for
  • Connected-product data-architecture documentation demonstrating Article 3(1) accessibility by design
  • Pre-contractual information sheet per Article 3(2)
Where this commonly fails
  • Connected products that lock data behind proprietary interfaces without machine-readable export
  • Sale of connected products without Article 3(2) pre-contractual information
DA-Art.4
User right to access product data (Article 4)

Article 4(1) confirms that, where data cannot be directly accessed under Article 3, the data holder shall make readily available data accessible to the user without undue delay, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, of the same quality as is available to the data holder. Article 4(13) prohibits data holders from using non-personal product data to derive insights about the user's economic situation, assets and production methods, or about the user's use of the connected product in any other way that could undermine the commercial position of the user on the markets on which the user is active.

Artefacts an auditor will ask for
  • User-data access procedure aligned with Article 4 timelines + format requirements
  • Internal control preventing use of non-personal product data for derived insights about the user (Article 4(13))
Where this commonly fails
  • No user-access channel for connected-product data
  • Use of non-personal product data to derive competitive insights about the user (prohibited)
DA-Art.5
User right to share data with third parties (Article 5)

Article 5(1) requires the data holder to make available, on the user's request, the readily available data, as well as the relevant metadata, to a third party of the user's choice, without undue delay, easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, of the same quality as is available to the data holder. Article 5(3) excludes designated gatekeepers under the Digital Markets Act ((EU) 2022/1925) from being eligible third parties. Article 5(5) prohibits the data holder from making the data sharing conditional on the third party's compensation.

Artefacts an auditor will ask for
  • Third-party-sharing API or portal aligned with Article 5
  • Internal control to verify that the requested third party is NOT a designated DMA gatekeeper
  • Records of any user requests for third-party data sharing
Where this commonly fails
  • Refusal to share data with a third party at user request without an Article 5 ground
  • Conditional sharing requiring user / recipient compensation (prohibited)
DA-Art.6
Obligations of third-party data recipients (Article 6)

Article 6 sets the obligations of third parties receiving data at user request: they may only use the data for the purposes and under the conditions agreed with the user; they may not use the data to develop a connected product that competes with the connected product from which the data originate; they may not use the data to derive insights about the economic situation, assets and production methods of the data holder; they may not share the data with other third parties without the user's consent; they shall implement appropriate technical and organisational measures to protect the data.

Artefacts an auditor will ask for
  • Data-receipt agreement with user covering Article 6 purposes and prohibitions
  • Internal control preventing competitive use against the data holder
  • Onward-sharing consent records
Where this commonly fails
  • Onward sharing of received product data without user consent
  • Use of received data to develop a competing connected product (prohibited)
DA-Art.7
Scope of B2C and B2B data sharing obligations (Article 7)

Article 7 sets the scope of the Chapter II obligations: they apply to manufacturers of connected products / providers of related services placed on the Union market and to data holders making product data available to data recipients. Micro and small enterprises are exempted unless they are partners or linked enterprises of a larger group. The exemption is calibrated to avoid SME burden.

Artefacts an auditor will ask for
  • SME / micro-enterprise threshold analysis where the entity claims the exemption
  • Connected-product placing-on-market records
Where this commonly fails
  • Claiming the SME exemption without checking the linked / partner enterprise test
  • SME exemption claim that has lapsed due to growth above the threshold

Data Act - Enforcement, Sui Generis Right and Final Provisions (Ch IX-XI)

DA-Art.37
Competent authorities and data coordinators (Article 37)

Article 37 requires each Member State to designate one or more competent authorities responsible for the application and enforcement of the Regulation, and to designate one of them as the 'data coordinator' to coordinate cross-authority and cross-border action. Data coordinators cooperate among themselves and with the European Data Innovation Board (EDIB).

Artefacts an auditor will ask for
  • Identification of the data coordinator and other competent authorities for each Member State the entity operates in
  • Cooperation records with the data coordinator
Where this commonly fails
  • Engagement only with sectoral regulators where the data coordinator is the designated CRA-style horizontal authority
DA-Art.38_39_40
Complaint, judicial remedy and penalties (Articles 38-40)

Article 38 grants users and other persons concerned the right to lodge a complaint with the competent authority. Article 39 grants the right to an effective judicial remedy against binding decisions of the competent authority and against the data holder's compliance with the Regulation. Article 40 requires Member States to lay down effective, proportionate and dissuasive penalties for breaches; for breaches of Articles 4-7 (user rights) and Chapter VI (cloud switching), the penalty regime aligns with the GDPR Article 83(5) ceilings (administrative fines up to EUR 20 million or 4% of worldwide annual turnover).

Artefacts an auditor will ask for
  • Internal complaint-handling procedure for Article 38 complaints
  • Compliance program demonstrating risk management against the Article 40 + GDPR Art.83(5)-aligned penalty regime
Where this commonly fails
  • No internal mechanism to receive and respond to user complaints
  • Penalty-exposure modelling that ignores the GDPR-aligned ceiling for Chapter II and Chapter VI breaches
DA-Art.41_42
Model contractual terms and the European Data Innovation Board (Articles 41-42)

Article 41 requires the Commission to develop, before 12 September 2025, non-binding model contractual terms for data-sharing contracts and standard contractual clauses for cloud computing contracts, to support SMEs in particular. Article 42 confirms the role of the European Data Innovation Board (EDIB, established under the Data Governance Act) in providing technical advice on the Data Act.

Artefacts an auditor will ask for
  • Adoption (or considered non-adoption) of Article 41 model terms in the entity's data-sharing and cloud contracts
  • Engagement with EDIB consultations
DA-Art.43_44
Sui generis database right and relation with other Union law (Articles 43-44)

Article 43 clarifies that the sui generis database right under Article 7 of Directive 96/9/EC does not apply to databases containing data obtained from or generated by the use of a connected product or a related service, to ensure the Article 4 + Article 5 user-access rights are not blocked through the sui generis right. Article 44 provides that the Data Act is without prejudice to other Union law on data access and use, including the GDPR (which prevails for personal data), the Open Data Directive, the DGA, sectoral regulations and competition law.

Artefacts an auditor will ask for
  • Internal mapping of Article 43 (sui generis is unavailable for product-data databases) into IP claims
  • Hierarchy analysis ensuring the GDPR (for personal data), DGA, sector-specific Union law are correctly applied alongside the Data Act
Where this commonly fails
  • Claim of sui generis database right over connected-product data (Article 43 makes the right unavailable for such databases)
  • Application of the Data Act to personal data in conflict with the GDPR (GDPR prevails for the personal-data dimension)
DA-Art.45_46_47_48_49_50
Delegation, committee, amendments, evaluation and entry into force (Articles 45-50)

Article 45 governs the exercise of the delegation of power. Article 46 sets the committee procedure. Article 47 amends Regulation (EU) 2017/2394 (consumer-protection cooperation). Article 48 amends Directive (EU) 2020/1828 (representative actions). Article 49 requires the Commission to evaluate the Regulation by 12 September 2028 and every 3 years thereafter. Article 50 provides that the Regulation entered into force on the twentieth day following its publication in the OJ (11 January 2024) and applies from 12 September 2025 (with Chapter VI cloud-switching obligations applying progressively: gradual-charge withdrawal by 12 January 2027; Chapter VI in full from 12 September 2025).

Artefacts an auditor will ask for
  • Compliance calendar reflecting the staggered application dates: 11 Jan 2024 entry into force, 12 Sep 2025 general application, 12 Jan 2027 zero switching charges, 12 Sep 2028 first evaluation
Where this commonly fails
  • Compliance plan treating 12 September 2025 as the only date
  • Cloud-switching charges levied after 12 January 2027

Data Act - General Provisions (Ch I)

DA-Art.1
Subject matter and scope (Article 1)

Article 1 sets the subject matter and scope of the Regulation: harmonised rules on fair access to and use of data, including (a) data made available by connected products and related services to users; (b) B2B data sharing obligations under Union law; (c) the exceptional-need public-sector access regime; (d) the cloud-switching regime; (e) interoperability essential requirements. Article 1 applies throughout the Union and to non-EU operators that place connected products on the Union market or that offer data processing services in the Union.

Artefacts an auditor will ask for
  • Internal scope analysis mapping the entity's products / services / data flows to each Data Act chapter
  • Extraterritorial-applicability assessment for non-EU operators
Where this commonly fails
  • Treating the Data Act as IoT-only legislation - it also covers cloud switching, B2B contracts and the public-sector access regime
DA-Art.2
Definitions (Article 2)

Article 2 supplies the definitions used throughout the Regulation. Key definitions: 'data' (any digital representation of acts, facts or information); 'connected product' (an item that obtains, generates or collects data concerning its use or environment and is able to communicate it via electronic communications service, physical connection or on-device access); 'related service' (a digital service connected to the product such that, without it, the connected product would be unable to perform any of its functions); 'product data' / 'related service data'; 'readily available data' (data that the data holder can lawfully obtain from the connected product or related service without disproportionate effort); 'user', 'data holder', 'data recipient', 'data processing service', 'gatekeeper' (per the DMA); 'switching destination'.

Artefacts an auditor will ask for
  • Definitions glossary mapping the entity's connected-product / related-service portfolio to Article 2 terms
  • Identification of which Article 2 role applies (user / data holder / data recipient / data processing service)
Where this commonly fails
  • Service description that does not commit to a particular Article 2 role (data holder vs data recipient)

Data Act - International Access and Interoperability (Ch VII-VIII)

DA-Art.32
International governmental access and transfer (Article 32)

Article 32 prohibits the transfer or governmental access to non-personal data held in the Union by a provider of data processing service to a third-country authority unless it complies with the Data Act safeguards: an international agreement (treaty / MLAT) covers the transfer, OR the access is consistent with Union law and Member State law and the provider has reviewed the request, OR EU Article 32(3) cumulative conditions are met (necessity, proportionality, specificity, narrow purpose, judicial authorisation). Foreign-court orders not meeting these safeguards must be refused, with a documented assessment.

Artefacts an auditor will ask for
  • Article 32 assessment procedure for foreign-court orders
  • Records of any refused or partly granted foreign-authority requests
  • Customer-disclosure procedure under Article 32(5) where a request is received
Where this commonly fails
  • Disclosure of customer non-personal data to foreign authority without Article 32 safeguards
  • No documented assessment of foreign requests
DA-Art.33_34_35
Interoperability essential requirements (Articles 33-35)

Article 33 sets the essential requirements for interoperability of data, data-sharing mechanisms and data spaces (semantic interoperability via vocabularies and standards, technical interoperability via APIs and formats, organisational interoperability via roles and contracts, legal interoperability). Article 34 governs interoperability for in-parallel use of data processing services. Article 35 covers interoperability of data processing services more broadly, including open interoperability specifications and European standards adopted under Regulation (EU) 1025/2012.

Artefacts an auditor will ask for
  • Conformity statements against the Article 33 essential interoperability requirements where the entity offers data-space services
  • In-parallel use API documentation per Article 34
  • Adoption of European standards (where adopted) for data-processing-service interoperability
Where this commonly fails
  • Data-space services that lack semantic interoperability (no published vocabulary)
  • In-parallel-use APIs not documented per Article 34
DA-Art.36
Essential requirements for smart contracts (Article 36)

Article 36 imposes essential requirements on smart contracts executing data-sharing agreements: robustness (defence against errors and manipulation), safe termination and interruption (mechanism to cancel a transaction by mutual consent or by court order), data archiving and continuity, access control, consistency with applicable Union law and contractual obligations. Vendors of applications that include smart-contract execution must issue a declaration of conformity.

Artefacts an auditor will ask for
  • Smart-contract architecture documentation against Article 36 robustness + safe-termination + access-control essential requirements
  • Declaration of conformity for the entity's smart-contract-using application(s)
Where this commonly fails
  • Smart-contract designs without an Article 36 declaration of conformity
  • Smart contracts that cannot be safely terminated or interrupted

Data Act - Public Sector Exceptional-Need Access (Ch V)

DA-Art.14_15_16
Exceptional-need public-sector access (Articles 14-16)

Article 14 establishes the public-sector exceptional-need access regime: in exceptional need, the Commission, the ECB, Union bodies and public sector bodies of Member States may request data from data holders. Article 15 defines 'exceptional need' (public emergency including pandemics, severe natural disasters and major industrial accidents; necessity of fulfilling specific public-interest task with no alternative data source). Article 16 explains the relationship with other obligations to make data available to public sector bodies (Article 16 is without prejudice to those other obligations).

Artefacts an auditor will ask for
  • Internal procedure to receive and assess Article 14 requests
  • Documentation of any Article 14 requests received including the Article 15 grounds cited
Where this commonly fails
  • Refusal of an Article 14 request without an Article 17(4) ground
  • Acceptance of an Article 14 request that does not meet the Article 15 exceptional-need test
DA-Art.17_18_19
Requests for data, compliance and PSB obligations (Articles 17-19)

Article 17 sets the formal requirements for Article 14 requests (clear specification, proportionality, Article 15 grounds, publicly available rationale). Article 18 requires the data holder to comply with a duly substantiated request without undue delay, unless an Article 17(4) ground for refusal applies (data unavailable, request not meeting Article 17 requirements, etc.). Article 19 sets the obligations on public sector bodies receiving data: data minimisation, purpose limitation, security, deletion at end of the exceptional-need period, prohibition on commercial use, and on selling / sublicensing.

Artefacts an auditor will ask for
  • Internal Article 17/18 request-handling SLA
  • Records of any Article 17(4) refusals with documented grounds
  • Public-sector-body data-receipt logs and deletion certificates
Where this commonly fails
  • Late or refused responses to Article 17 requests without documented grounds
  • No retention / deletion plan for data received under Article 14 (PSB side)
DA-Art.20_21_22
Compensation, research access and cross-border cooperation (Articles 20-22)

Article 20 governs compensation in exceptional-need cases (cost-based where the data holder is an SME / not-for-profit; reasonable margin otherwise; free for public-health emergencies under Article 15(1)(a)). Article 21 permits public sector bodies to share data received under Article 14 with research organisations carrying out scientific research, subject to confidentiality safeguards. Article 22 establishes mutual assistance and cross-border cooperation between Member State competent authorities for cross-border requests.

Artefacts an auditor will ask for
  • Compensation arrangements for Article 14 data provision
  • Records of any research-organisation onward sharing under Article 21
  • Cross-border-request handling records under Article 22

Data Act - Switching Between Data Processing Services (Ch VI)

DA-Art.23_24
Removing obstacles to switching and technical scope (Articles 23-24)

Article 23 obliges providers of data processing services (cloud, edge, IaaS, PaaS, SaaS) to remove pre-commercial, commercial, technical, contractual and organisational obstacles to a customer switching to another provider of data processing service or to an on-premises ICT infrastructure. Article 24 sets the scope of these technical obligations across the IaaS / PaaS / SaaS layers and across in-scope service categories.

Artefacts an auditor will ask for
  • Service-design review demonstrating Article 23 obstacle removal (data egress, format export, technical equivalence, contractual clauses)
  • Per-service-layer (IaaS / PaaS / SaaS) Article 24 scope determination
Where this commonly fails
  • Service designs that lock customers in through proprietary data formats without export paths
  • Switching exit fees not justified by the gradual-withdrawal schedule in Article 29
DA-Art.25_26_27
Contractual terms, information obligation and good-faith cooperation (Articles 25-27)

Article 25 sets the mandatory contractual terms concerning switching: maximum 30-day notice for the customer to initiate switching, a transitional period of up to 30 days (extendable once to 7 months) for the actual switching, equivalent service-level continuity during transition, written-out details of the data and digital assets the customer can export. Article 26 imposes an information obligation on the provider (publication of online registry of data structures, data formats and metadata standards; description of the customer responsibilities during switching). Article 27 requires good-faith cooperation between the source provider, the destination provider and the customer.

Artefacts an auditor will ask for
  • Standard data-processing-service contract aligned with Article 25 mandatory terms
  • Article 26 online registry / data-structures information published
  • Switching playbook including good-faith cooperation triggers
Where this commonly fails
  • Contracts that exceed the 30-day notice or 30-day (extendable) transitional periods of Article 25
  • Hidden data structures / formats / metadata not disclosed under Article 26
DA-Art.28
Contractual transparency on international access and transfer (Article 28)

Article 28 imposes a contractual transparency obligation on providers of data processing services to inform customers about the jurisdiction of the infrastructure used and about the legal regimes that may affect the data (in particular foreign-court access regimes covered by Chapter VII).

Artefacts an auditor will ask for
  • Per-customer disclosure of the jurisdictions of data-centre / sub-processor infrastructure
  • Reference to Article 32 safeguards in the data-processing-service agreement
Where this commonly fails
  • Service agreements that do not disclose data-residency / sub-processor jurisdictions
DA-Art.29
Gradual withdrawal of switching charges (Article 29)

Article 29 requires the gradual withdrawal of switching charges by 12 January 2027 (3 years after entry into force): from 11 January 2024 to 11 January 2027, providers may charge no more than the costs directly related to and necessary for the switching; from 12 January 2027, no switching charges (except for in-parallel use of data processing services under Article 34) may be applied.

Artefacts an auditor will ask for
  • Switching-charge schedule and roadmap aligned with Article 29: cost-based from 11 Jan 2024 to 11 Jan 2027, zero from 12 Jan 2027
  • Internal accounting tracking the directly-related-costs basis for any charges levied during the cost-based window
Where this commonly fails
  • Switching charges that include margin or indirect costs during the cost-based window
  • Switching charges levied after 12 January 2027 (prohibited)
DA-Art.30_31
Technical aspects of switching and specific custom-built regime (Articles 30-31)

Article 30 governs the technical aspects of switching: providers shall facilitate switching by ensuring that the customer can use exportable data, digital assets, applicable application protocols, equivalent functionalities and equivalent service-level performance with the destination provider. Article 31 sets a specific regime for certain custom-built data processing services where strict functional equivalence is technically infeasible, requiring instead structured cooperation between the source provider, destination provider and customer to design a tailored switching solution.

Artefacts an auditor will ask for
  • Article 30 technical-switching artefacts (data exports, applicable API contracts, runtime configurations, performance baselines)
  • Article 31 cooperation records for custom-built data-processing services
Where this commonly fails
  • Switching offered only as raw data dump without API / runtime equivalence
  • Custom-built services without an Article 31 cooperation protocol
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EU Data Act framework page.